This Privacy Policy explains how Visitry, Inc. ("Visitry," "we," "us," or "our") collects, uses, discloses, and protects information when you use our website, our clinician mobile application, our web portals for clinicians, agency partners, and administrators, and any related services (collectively, the "Services").
Visitry is a clinician-powered therapy network operating in Florida. We connect licensed physical therapists, occupational therapists, and their assistants with home health agencies and, in some cases, with patients directly under our own clinic license. Because we operate in healthcare, some of the information we handle is Protected Health Information ("PHI") governed by the federal Health Insurance Portability and Accountability Act ("HIPAA"). Our HIPAA-specific practices are described in our separate Notice of Privacy Practices. This Privacy Policy covers all other information and should be read together with that Notice.
If you do not agree with this Privacy Policy, please do not use the Services. Questions can be sent to privacy@visitry.com.
1. Who this policy applies to
This Privacy Policy applies to four groups:
- Clinicians — licensed PTs, OTs, PTAs, and OTAs who apply to or work through the Visitry network as independent contractors.
- Agency partners — home health agency staff and schedulers who use the Visitry portal to post visits and coordinate care.
- Patients — individuals who receive therapy services arranged or delivered through Visitry. Most information we hold about patients is PHI; see the Notice of Privacy Practices.
- Website visitors — anyone who browses visitry.com, submits a contact or application form, or uses the public clinician fit quiz.
2. Information we collect
2.1 Information you provide directly
The specific information we collect depends on your role:
- Account information — name, email address, phone number, and a password. If you sign in via a magic link, we generate a short-lived, single-use token tied to your email.
- Clinician profile information — mailing address, date of birth, professional license number, National Provider Identifier (NPI) where applicable, discipline (PT / OT / PTA / OTA), service territory, specialties, languages spoken, availability preferences, and emergency contact details.
- Credentials and verification documents — copies of your driver's license, professional license, liability insurance certificate, auto insurance, CPR/BLS card, tax documents (W-9), and similar documents required to onboard as a contractor or to maintain eligibility with agency partners.
- Payment and tax information — bank routing and account numbers for ACH payments, and tax identification information required for 1099 reporting. Sensitive fields are encrypted as described in Section 7.
- Signed documents and e-signatures — contractor agreements, competency assessments, onboarding attestations, and related documents executed through our e-signature provider.
- Agency information — agency contact details, staff user accounts, and information agencies upload about the patients they refer.
- Patient information — name, address, phone, medical record number (MR#), city, ZIP code, visit notes, visit history, and clinical frequency plans. This information is typically provided to us by the referring agency and treated as PHI.
- Communications — support emails, form submissions, feedback you provide on articles or AI answers, and similar content.
2.2 Information collected automatically
- Device and connection data — IP address, browser type and version, operating system, device type, and referring URL. This information is logged with most meaningful actions in our audit log.
- Usage data — pages viewed, features used, timestamps, and error reports. We use this to operate and improve the Services.
- Mobile push tokens — when you enable push notifications in the Visitry mobile app, we store the token issued by Apple or Google (via Expo) so we can send you visit reminders and related alerts.
- Location data (mobile) — the mobile app may request permission to access your device location to show nearby visits on a map. You can deny or revoke this permission in your device settings; core functions of the app work without it. We do not continuously track clinician location.
- Map queries — when a map loads, limited map viewport data (zoom level, visible area, and visit coordinates derived from ZIP code) is sent to Google Maps to render the map. We do not send exact patient addresses to Google Maps.
- Cookies and similar technologies — we use a strictly necessary session cookie to keep you signed in. We do not currently use third-party advertising cookies, analytics pixels, or cross-site trackers.
2.3 Information from third parties
We may receive information about you from:
- Agencies that refer patients or staff to us, in order to match clinicians with visits and maintain eligibility.
- Clinicians who refer you to our network, if you are invited through our clinician referral program.
- Credential-verification and background-check providers, for onboarding and compliance.
- Automated document-validation tools (AI), which extract data from documents you upload (e.g., expiration dates); see Section 6.
3. How we use information
We use the information we collect to:
- Operate the Services, including account creation, authentication, and session management.
- Match clinicians with visits, route care to the right discipline, and coordinate schedules.
- Process payments to clinicians and invoicing with agencies.
- Verify credentials, run background checks, and maintain compliance with agency-specific requirements.
- Send transactional messages (visit confirmations, reminders, password resets, magic links, onboarding prompts).
- Provide customer support and respond to inquiries.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Comply with legal obligations, including tax reporting and healthcare regulations.
- Improve the Services through aggregated usage analysis and AI-assisted document handling (Section 6).
- Send marketing communications you have opted in to receive (you can opt out at any time).
We do not sell your personal information, and we do not use PHI for marketing purposes.
4. How we share information
We share information in the following circumstances:
- With agency partners — when a clinician accepts a visit, we share the clinician's name, discipline, license status, and contact details with the referring agency so the visit can be coordinated. Agencies share patient referrals with us for the same purpose.
- With other clinicians in a patient's care team — for example, when a follow-up visit is pre-assigned to a PTA/OTA working with the evaluating clinician.
- With service providers that process data on our behalf — listed in Section 5. These vendors are contractually required to use your information only to perform services for us.
- With government authorities or in legal proceedings — when required by subpoena, court order, or other legal process, or to protect the safety of any person, the public, or our rights.
- In a corporate transaction — in connection with a merger, financing, acquisition, reorganization, or sale of assets, your information may be transferred to the successor entity, subject to this policy.
- With your consent — for any purpose you have authorized.
We do not sell, rent, or trade your personal information, and we do not share it with advertisers for behavioral advertising.
5. Service providers and sub-processors
The following providers support the Services and may process your information on our behalf. Where HIPAA applies, we execute a Business Associate Agreement with the vendor before transmitting PHI.
| Vendor | Purpose | Categories of data |
|---|---|---|
| Neon (managed PostgreSQL, hosted on AWS) | Primary application database | All account, clinical, operational, and audit data |
| Render | Web and API hosting | Runtime logs, in-flight request data |
| Cloudflare R2 | Encrypted file storage | Credential documents, headshots, invoice PDFs, onboarding artifacts |
| Resend | Transactional email (login links, password resets, notifications) | Name, email address, non-PHI notification content |
| Google Workspace | Administrative email and internal operations | Names and contact details; any patient information contained in administrative correspondence (PHI) |
| BoldSign | E-signature of contractor and compliance documents | Name, address, signature, signed document contents |
| Expo (Expo Push Notifications) | Mobile push notification delivery | Device push token, notification title and body |
| Anthropic (Claude API) | Credential-document validation; knowledge base question answering; clinician fit quiz | See Section 6 |
| Google Maps Platform | Map tiles and geocoding for the mobile and portal maps | ZIP-code-derived coordinates and map viewport data (not exact patient addresses) |
| Expo Application Services (EAS) | Mobile app build and distribution | Code and build artifacts only |
This list may be updated as our vendor relationships change. We will revise this page and update the "Last updated" date to reflect material changes.
6. Artificial intelligence
We use AI in limited, purpose-specific ways. We do not use AI to make autonomous decisions that finally determine your eligibility to work with a specific agency or to be paid. AI output is either (a) processed further by a human reviewer or (b) clearly labeled as AI assistance.
- Credential document validation. When you upload a credential (e.g., professional license, insurance certificate, driver's license), the document is sent to Anthropic's Claude API so that an AI model can extract key fields such as expiration dates and document numbers. This data and the extracted fields are stored in our database; a human reviewer may override AI results during approval.
- Knowledge base assistance. When a clinician asks a question in our internal knowledge base, the question and a small amount of user context (first name, discipline, territory, and eligibility summary) are sent to the Claude API together with relevant article excerpts. We instruct the AI to answer only from those excerpts and not to invent clinical content. Queries and answers are logged for quality and safety review.
- Public clinician fit quiz. An unauthenticated conversational tool on our website sends your answers to the Claude API to generate a fit assessment. This quiz does not request or require PHI.
We do not send Protected Health Information — including patient names, medical record numbers, addresses, or clinical notes — to AI providers. The AI features described above operate on clinician, credential, and knowledge-base data, not patient PHI. We have configured our API usage so that providers do not retain our inputs and outputs for model training. Should we ever introduce a feature that transmits PHI to an AI provider, we will execute a Business Associate Agreement with that provider before doing so and update this policy accordingly.
7. How we protect information
We apply layered safeguards to protect your information:
- Encryption in transit. All connections to the Services use TLS. We serve HTTP Strict Transport Security (HSTS) headers in production.
- Field-level encryption at rest. Sensitive patient-identifying fields (such as address and phone number) are encrypted with AES-256-GCM using a key that is not stored in the database. Our underlying database, file storage, and mobile secure-storage layers apply additional platform-level encryption at rest.
- Authentication. Passwords are hashed with bcrypt (12 rounds). Mobile sessions use signed JWTs stored in the device's secure enclave. Magic links are single-use and expire within 15 minutes. Sessions expire after 30 days of inactivity.
- Access controls. Every API request is authorized against the requester's role and — for clinician data — against ownership. Patient identity is revealed only after a clinician has accepted a visit.
- Rate limiting. Authentication endpoints, public application forms, and AI endpoints are rate-limited to deter abuse.
- Audit logging. Sensitive actions — including logins, credential uploads and downloads, visit status changes, profile edits, and administrative actions — are written to an internal audit log with actor, timestamp, IP, and user agent.
- File validation. Uploaded files are validated by MIME type and magic-byte inspection. Only PDF, PNG, JPEG, WebP, and HEIC (converted to JPEG) are accepted.
No system is perfectly secure. You can help protect your account by choosing a unique password, keeping your device software current, and contacting us immediately at security@visitry.com if you suspect unauthorized access.
8. How long we keep information
We retain personal information for as long as your account is active and for as long as we need it to deliver the Services and to comply with legal, tax, accounting, and healthcare obligations.
- Account records are retained for the life of the account and then for the period required by state and federal law applicable to healthcare records, contractor records, and tax records.
- Patient / PHI records are retained for at least the period required by applicable federal and Florida state law (generally 6 years after the last date of service) and may be retained longer if legally permitted or required.
- Audit logs are retained for at least six years, consistent with HIPAA documentation retention requirements.
- Session and authentication tokens expire automatically as described in Section 7.
When we no longer have a legitimate business or legal reason to retain information, we delete or de-identify it. Deletion from live systems may not remove information from backups or disaster-recovery archives immediately; such copies are deleted on our standard backup rotation schedule.
9. Your choices and rights
You have the following choices with respect to your information:
- Access and update. You can view and update most profile information from within the clinician portal or the Visitry mobile app. For information you cannot edit directly, contact us.
- Request a copy of your data. You can request a copy of the personal information we hold about you by emailing privacy@visitry.com. We may verify your identity before responding.
- Request correction or deletion. You can request that we correct inaccurate information or delete personal information, subject to legal and operational limits. We cannot delete records we are legally required to retain (for example, certain clinical records and tax records).
- Close your account. You can ask us to close your account. We will deactivate the account and, where possible, delete personal information that we are not legally required to retain. Some records (audit logs, invoices, clinical documentation) will remain.
- Marketing opt-out. You can unsubscribe from marketing emails at any time using the link in the message. We will still send transactional messages that are necessary to operate the Services.
- Push notifications and location. You can disable push notifications and location access in your device settings at any time.
Your rights under HIPAA are described in our Notice of Privacy Practices.
10. California residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you additional rights with respect to personal information we collect about you. Note that most healthcare-related information we hold is either PHI subject to HIPAA or information collected in connection with clinical services, both of which are generally exempt from the CCPA.
For personal information not subject to those exemptions, you have the right to:
- Know what personal information we collect, use, and share.
- Access the specific pieces of personal information we hold about you.
- Request deletion of personal information, subject to exceptions.
- Request correction of inaccurate personal information.
- Opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined under California law.
- Limit the use and disclosure of sensitive personal information to what is necessary to provide the Services.
- Be free from retaliation for exercising your privacy rights.
To exercise these rights, email privacy@visitry.com. You may also designate an authorized agent to submit a request on your behalf; we will ask for proof of that authorization. We will verify your identity before acting on a request, and we will not discriminate against you for exercising any right.
Categories of personal information collected in the last 12 months: identifiers (name, email, phone, address, IP), California Customer Records data (contact information, financial and employment-related information), protected classification characteristics (date of birth), professional or employment-related information, geolocation data (ZIP-derived visit coordinates and — with consent — mobile device location), internet or other network activity (usage logs), and inferences drawn from the above to operate the Services. We have disclosed these categories to the service providers listed in Section 5 for the purposes described there. We have not sold or "shared" personal information for cross-context behavioral advertising.
11. Children's data
The Services are designed for adults — licensed clinicians, agency staff, and adult home-health patients. We do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, please contact us at privacy@visitry.com and we will promptly delete it.
12. International users
Visitry operates in the United States and our Services are intended for use within the United States. If you access the Services from outside the United States, you understand that your information will be processed in the United States. Data-protection laws in the United States may differ from those in your country.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of the page. If the change is material, we will also notify you by email or through a conspicuous notice in the Services before the change takes effect. Your continued use of the Services after the effective date of an updated policy constitutes acceptance of the changes.
14. Contact us
Questions, requests, or complaints about this Privacy Policy can be sent to:
Visitry, Inc.
Attn: Privacy Officer
802 E Whiting St
Tampa, FL 33602
United States
privacy@visitry.com
HIPAA-specific questions, requests for accounting of disclosures, and complaints about our use of Protected Health Information should be directed to our Privacy Officer using the contact information in our Notice of Privacy Practices.