Stay Access, Inc. ("Stay Access," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, applications, and services (collectively, the "Services"). Please read this policy carefully. If you do not agree with its terms, please do not access or use the Services.
We collect information that you provide directly to us, information we collect automatically, and information from third parties.
Information you provide includes: account registration details (name, email, phone, practice name), billing information, patient contact information (when uploaded by practitioners for waitlist and appointment-fill purposes), consent records, and communications you send us.
Information collected automatically includes: IP address, browser type, device identifiers, pages viewed, time spent, and cookies or similar technologies.
We do not intentionally collect protected health information (PHI) from patients directly through public-facing pages. PHI is only collected when a practitioner uploads it as part of using the Services, or when a patient voluntarily provides it through the patient portal after appropriate consent.
We use the information we collect to:
• Provide, operate, and maintain the Services
• Process transactions and send related information
• Send notifications, including appointment reminders and slot-fill alerts
• Improve and personalize the Services
• Monitor and analyze usage and trends
• Detect, prevent, and address technical issues or fraud
• Comply with legal obligations, including HIPAA where applicable
• Communicate with you about products, services, offers, and events (with your consent where required)
We do not sell your personal information. We may share information in the following circumstances:
• Service providers: We share information with vendors and service providers who need access to perform work on our behalf (e.g., cloud hosting, payment processing, SMS delivery, email delivery). These providers are bound by contractual obligations to keep information confidential and use it only for the purposes for which we disclose it.
• Business transfers: If we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction.
• Legal requirements: We may disclose information if required to do so by law or in response to valid requests by public authorities.
• With your consent: We may share information with your consent or at your direction.
When our Services are used by covered entities or business associates subject to HIPAA, we act as a business associate and comply with applicable HIPAA requirements.
We sign Business Associate Agreements (BAAs) with our customers before any PHI is processed. Our BAAs outline the permitted uses and disclosures of PHI, the safeguards we implement, and our obligations to report breaches.
We implement administrative, physical, and technical safeguards consistent with HIPAA Security Rule requirements, including access controls, encryption, audit logging, and workforce training.
You may view, sign, or download your BAA at any time through the Trust & Compliance section of your account.
We retain personal information and PHI for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.
For practitioner accounts, data is retained for the duration of the subscription plus a reasonable period to allow for account reactivation or dispute resolution.
Upon account termination, we will delete or anonymize your information within 30 days, except where we are required to retain it by law or for legitimate business purposes (such as fraud prevention or financial record-keeping).
A certified data destruction certificate is available upon request for enterprise accounts.
We take reasonable measures to help protect your information from loss, theft, misuse, unauthorized access, disclosure, alteration, and destruction.
Key security measures include:
• AES-256 encryption at rest
• TLS 1.3 encryption in transit
• Multi-factor authentication for administrative access
• Role-based access controls
• Regular security audits and vulnerability assessments
• Employee background checks and confidentiality agreements
However, no method of transmission over the internet or electronic storage is completely secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.
Depending on your location, you may have certain rights regarding your personal information, including:
• The right to access the personal information we hold about you
• The right to request correction of inaccurate information
• The right to request deletion of your personal information
• The right to object to or restrict certain processing
• The right to data portability
• The right to withdraw consent where processing is based on consent
To exercise these rights, please contact us at privacy@stayaccess.com. We will respond within the timeframes required by applicable law.
California residents: We do not sell personal information as defined by the California Consumer Privacy Act (CCPA).
We use cookies and similar tracking technologies to collect information about your browsing activities and to remember your preferences.
Types of cookies we use:
• Essential cookies: Necessary for the Services to function properly
• Analytics cookies: Help us understand how visitors interact with our website
• Preference cookies: Remember your settings and choices
You can manage your cookie preferences through your browser settings. Most browsers allow you to refuse cookies or to alert you when cookies are being sent. Note that if you disable cookies, some features of the Services may not function properly.
We use analytics providers such as Plausible or similar privacy-focused tools that do not track individuals across sites.
Our Services are not directed to individuals under the age of 18, and we do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@stayaccess.com. If we learn we have collected personal information from a child without verification of parental consent, we will delete that information promptly.
Our Services may contain links to third-party websites or services that are not owned or controlled by Stay Access. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites or services you visit.
We may update this Privacy Policy from time to time. The updated version will be indicated by a revised "Last updated" date at the top of this page. We encourage you to review this Privacy Policy periodically to stay informed about our practices. Your continued use of the Services after any changes constitutes acceptance of the updated policy.
For material changes, we will notify you via email or through a prominent notice within the Services before the changes take effect.
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Stay Access, Inc.
Email: privacy@stayaccess.com
For HIPAA-related inquiries or to request a Business Associate Agreement, please contact trust@stayaccess.com.
Questions?
If you have questions about this Privacy Policy or how we handle your data, reach out to privacy@stayaccess.com.