Legal

Privacy Policy

What we collect, who processes it, how long we keep it, and how to get it deleted. The short answer to the question most people are actually asking: there are no third-party tracking or advertising pixels anywhere in this product.

Last updated: August 8, 2026

This policy explains how Accurate Billing and Coding, Inc. d/b/a ClaimCarePro (CaringCodex, we, us) handles information in the CaringCodex product: this website, the dashboard, the intake form, and the practice sites we build and host. It covers information about you and your practice. Your patients' health information is not part of this product, and section 11 explains why.

1. The short version

  • No third-party tracking or advertising pixels, ever. Analytics are first-party and server-side.
  • We collect what running the service requires — your account details, the practice profile you give us at intake, and the operational records of the site we build for you.
  • We never see your card number. Square handles payments.
  • Contact-form messages are relayed to your inbox. We store delivery metadata only, never message bodies.
  • Three subprocessors: Amazon Web Services, Square, and Anthropic. They are named in section 6 with what each one does.
  • We do not sell your data, and we do not share it with advertising networks or data brokers.
  • Ask us to delete it and we will — see section 9.

2. No third-party tracking, ever

CaringCodex does not load Google Analytics, the Meta pixel, TikTok, LinkedIn Insight, session recorders, heatmaps, chat widgets, or any other third-party tag — not on this website, and not on the sites we build for practices. This is an architectural rule, not a setting: the platform has no code path that injects a third-party tag into a published page, so there is nothing to switch on later, by us or by anyone else.

We do measure how the service is used, using first-party, server-side analytics: our own servers record which pages were requested, when, and which link or campaign brought the visitor, and we count those requests. That data stays on our infrastructure and is never handed to an ad platform.

We use a small number of first-party cookies — one to keep you signed in, and one that records which link brought you to the site so that we can tell which of our own marketing works. The attribution cookie expires after 90 days, is not readable by scripts, and is not shared with anyone. There are no advertising cookies. Practice sites we build set no analytics cookie at all.

A consequence worth stating plainly: because there is no third-party tag on your practice site, a visitor reading about a medical condition on your website is not being profiled by an ad network on your behalf. That has been the source of a large share of healthcare-website privacy enforcement in recent years, and this product is built to make it structurally impossible.

3. What we collect

Account information

Your name, work email address, practice name, and the sign-in records of your account. Sign-in uses an emailed link rather than a password you have to invent, so we do not store a password for you.

Practice profile information (intake)

What you type into the intake form so that we can build your site: providers and their credentials, NPI numbers, specialties and services, insurance participation, locations, hours, phone numbers for publication, and any logos or photographs you upload. Some of this is also public record — the NPI registry, for instance — and we may pre-fill from public sources so that you have less to type. All of it is business information about your practice. None of it should be information about a patient.

Payment information

Payments are handled by Square. Your card details go from your browser to Square and never reach our systems. What we receive and store is a Square customer identifier, a subscription identifier, the plan and add-ons you bought, and whether each payment succeeded — enough to know what you are entitled to and to send you a receipt.

Support and contact messages

If you email us, or use the contact page, we keep the message and our reply so that we can answer you and so that there is a record of what was agreed.

Usage and technical records

Server logs of requests to our systems and to your site: page requested, timestamp, referring link and campaign parameters, browser user-agent, and IP address. IP addresses are used for security, abuse prevention, and coarse regional traffic counts, and are discarded from analytics aggregates.

Compliance and audit records

Because the product publishes healthcare advertising, we keep an append-only record of content-approval events: what draft was generated, what the compliance check found, who approved it, and when. That record protects both of us if anyone later asks who approved a claim on your site. It is retained for the life of your account and for seven years after it closes.

4. The contact-form relay — metadata only

When a patient submits the contact form on your practice site, the message is relayed to your practice inbox. We store delivery metadata only, never the message body. The metadata is: the time of submission, which site and which form, the destination inbox, whether delivery succeeded, and a spam score. The name, email address, phone number, and free-text message the patient typed are passed through in the email to you and are not written to our database.

That is why the base service does not need a Business Associate Agreement, and it is also why we cannot retrieve a patient message for you after the fact. If a delivery fails, we can tell you that it failed and when — not what it said. Your own inbox is the system of record for patient enquiries.

5. How we use it

  • To build, publish, host, and maintain your site, and to run the plan you bought.
  • To draft copy for your review, and to run compliance checks on that copy.
  • To bill you, and to send receipts and service notices.
  • To answer your questions and provide support.
  • To keep the platform secure and available — detecting abuse, debugging failures, and investigating incidents.
  • To understand which of our own marketing works, using the first-party analytics described in section 2.
  • To comply with the law and to enforce the terms.

We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use your practice profile to train AI models. We do not email you marketing about unrelated products, and any product email we do send has a working unsubscribe link that does not affect your service.

6. Subprocessors

These are the third parties that process data on our behalf. Each is bound by a contract limiting them to what we ask them to do. If we add one, we update this list before the change takes effect.

Amazon Web ServicesHosting and storage
Runs the platform, the database, your published site, and our backups, in United States regions.
SquarePayments
Processes subscription and setup charges. Card details go from your browser to Square. We receive a customer and subscription identifier and the status of each payment, never your card number.
AnthropicAI copy drafting
Turns the practice profile you supply into draft website copy for your review. Only business information about your practice is sent — never patient information. Under Anthropic's commercial terms, what we send and receive is not used to train their models.

Notably absent: there is no analytics vendor, no advertising platform, no CRM, and no chat or session-recording vendor on this list, because the product does not use any.

7. Who else sees it

Beyond those subprocessors, we disclose information only:

  • To you and the people you authorize on your account.
  • Where you direct us — for example, connecting your site to a Google Ads or Google Business Profile account that you control.
  • When the law requires it — a valid subpoena, court order, or legal process. Where we are permitted to tell you first, we will.
  • To protect people — to investigate fraud, security incidents, or threats of harm.
  • In a business transfer — if the business is sold or merged, information moves with it, and this policy continues to apply until you are told otherwise.

ClaimCarePro also provides medical billing services to some practices under a separate agreement. Those two systems do not share a database. Information moves between them only through a consented, read-only lookup that you switch on, and billing information about patients never enters CaringCodex.

8. Retention, and the 30-day window after you cancel

  • While your subscription is active, we keep your account and practice profile information so the service can run.
  • When you cancel, your site stays up for 30 days and you can download the whole thing as a static export from the dashboard at any point in that window.
  • After the 30 days, the site goes offline. We delete your practice profile content, uploaded assets, and published pages from our production systems within 30 days of that point, and from encrypted backups within a further 90 days as the backup rotation expires.
  • Records we keep longer: invoices and payment records for seven years, because tax law requires it; and the content-approval audit record described in section 3, also for seven years. Both are append-only by design and hold no patient information.
  • Contact-form delivery metadata is kept for 12 months, then deleted.
  • Server logs are kept for 90 days.

9. Access, correction, and deletion

Email jacob@claimcarepro.com and ask. You can request a copy of the information we hold about you, a correction to anything that is wrong, or deletion of your account and its content. We respond within 30 days, and there is no charge.

Most account and practice information can also be corrected by you directly in the dashboard, which is faster than asking us. Deletion requests are honored except where we are required to keep a record — the invoices and audit records in section 8 — in which case we will tell you exactly what was kept and why.

Depending on where you live, you may have additional statutory rights, including the right to opt out of the sale or sharing of personal information and the right not to be discriminated against for exercising your rights. We do not sell or share personal information, so there is nothing to opt out of, and we apply the access, correction, and deletion rights above to everyone regardless of location.

10. How we protect it

Data is encrypted in transit and at rest. Access to production systems is restricted to the people who operate the service, is authenticated individually, and is logged. Sign-in uses emailed links rather than reusable passwords. Each practice's data is isolated so that one customer cannot read another's, and that isolation is enforced by the platform's access controls rather than by application code remembering to check. No system is perfectly secure, but if a breach affects your information we will tell you promptly and tell you what we know.

11. Health information and Business Associate Agreements

The standard CaringCodex website does not create, receive, maintain, or transmit protected health information on our systems — contact-form messages are relayed to your inbox and we store only delivery metadata, never the message body. That means a Business Associate Agreement is not required for the base service.

Please do not put patient information into the intake form, into email to us, or into any field of the product. If you add a capability that is designed to handle protected health information, we execute a BAA with you first and that capability stays off until the agreement is signed. Email jacob@claimcarepro.com for our HIPAA and security overview.

12. Children

CaringCodex is a business service sold to healthcare practices. It is not directed to children, and we do not knowingly collect personal information from anyone under 13. If a pediatric practice's contact form is used to enquire about a child, that message is relayed to the practice and never stored by us — the same rule as every other message. If you believe a child has given us personal information directly, email jacob@claimcarepro.com and we will delete it.

13. Where data lives

The service is intended for healthcare practices in the United States, and data is stored and processed in United States regions of Amazon Web Services. Our subprocessors may provide support from other countries under contractual safeguards. We do not currently market the service outside the United States.

14. Changes to this policy

When this policy changes we update the “Last updated” date at the top of the page and post the new version here. For changes that materially affect how we handle your information — a new subprocessor, a new category of collection, a longer retention period — we email the address on your account at least 14 days before the change takes effect.

15. How to reach us

Privacy questions, requests, and complaints go to jacob@claimcarepro.com. We answer in writing within one business day, and we do not route privacy questions through a phone tree, because there isn't one.

Accurate Billing and Coding, Inc. d/b/a ClaimCarePro
Clearwater, Florida, United States