Privacy policy
What we collect, why we collect it, who we share it with, how long we keep it, and how to make it stop.
What we collect
This is the complete list. There is no category not named here.
- Matching request data
- Service category, timing, and ZIP code. The street address where the visit would happen, and an apartment or unit if you give one. Your first and last name, and one contact detail — either a phone number or an email address — plus whether you asked to be called or texted.
- Consent record
- The version and exact text of the consent you accepted, the time you accepted it, the page you were on, the language you were reading, and the form version.
- Attribution data
- UTM parameters, Google and Meta click identifiers, the landing page path, and the referring site's origin.
- Technical data
- Your IP address is used transiently for rate limiting and is NOT stored. Your user agent may be recorded with a consent record.
- What we never collect
- Symptoms, diagnoses, medical history, date of birth, insurance member number, government identifiers, and payment details. The form has no field that could carry them. It does ask for a street address, because a provider who travels to you cannot do so without one.
Why we collect it
- To check whether a participating provider covers your ZIP code and requested service.
- To pass your request to that provider so they can respond.
- To keep a record of what you consented to, so we can answer accurately if you ask.
- To understand which marketing sources bring people here.
- To protect the form from automated abuse.
Who receives your information
When your request matches, it goes to that one participating provider. Not several — one. The Matching and Lead-Sharing Disclosure lists the fields transmitted, item by item.
If nothing matches, nothing is sent to anyone.
We also use service providers who process data on our behalf: a hosting provider, a database provider, an email delivery provider, a bot-protection provider, an analytics provider, and a workflow-automation and messaging provider that alerts our own staff when a request arrives. They act on our instructions and may not use your information for their own purposes.
We do not sell your information to data brokers, list buyers, or advertisers.
How a provider may contact you
By phone, text message, or email, using the details you supplied and honouring the preference you selected where they can. Message and data rates may apply.
Consent is not a condition of purchasing any service. You may withdraw it at any time by telling the provider to stop and by contacting us.
Once a provider has received your request, they hold their own copy under their own privacy obligations, which are not ours. We cannot delete their copy.
How long we keep it
TODO: a definite retention period has not been set. The database migration contains a commented 24-month deletion job that is not yet active. Do not publish this page until a period is chosen, because a policy that is silent on retention is a policy that promises nothing.
Consent records may be retained longer than the request itself where required to evidence consent.
Your choices and rights
- Request a copy of what we hold about you.
- Request deletion of our copy, understanding that a copy already delivered to a provider is beyond our reach.
- Opt out of any sharing that qualifies as a sale or a targeted-advertising share under applicable state law.
- Withdraw consent to electronic communications.
- Ask us to correct inaccurate information.
- Texas residents have rights under the Texas Data Privacy and Security Act. Residents of other states may have rights under their own laws. TODO: counsel to confirm which state regimes apply and add the required disclosures.
Security, and its limits
Data is transmitted over TLS. The lead table has row-level security enabled with no permissive policy, so it is reachable only by a server-side service credential. Outbound webhooks are signed when a signing secret is configured. Personal fields are masked in the administrative interface by default.
No system is completely secure and we do not claim otherwise. We are not a HIPAA covered entity or business associate, and this platform is not HIPAA compliant. The most meaningful protection we offer is that we never collect protected health information in the first place.
Children
This site is not directed at children and we do not knowingly collect information from anyone under 13. An adult may submit a request concerning a minor; in that case the adult is the person contacting us.
Contact
TODO: supply a privacy contact email and postal address before publication.
Written by: San Antonio Mobile Health Editorial TeamWritten and maintained by the San Antonio Mobile Health editorial team. We are not clinicians. Pages covering clinical topics are held out of search results until a named, credentialed reviewer has approved them.
Last reviewed: August 4, 2026
Last fact-checked: August 4, 2026
Related pages
- Data Request
Request a copy of the information this platform holds about you. Draft pending attorney review.
- Data Deletion Request
Request deletion of the information this platform holds about you, and understand what deletion cannot reach. Draft pending attorney review.
- Cookie Notice
Which cookies and similar technologies this site uses, what each is for, and how to control them. Draft pending attorney review.
- Mobile Healthcare Privacy Questions
Where your information goes: what the provider holds, what this platform holds, what HIPAA does and does not cover, and how to ask for deletion.