Privacy policy
Privacy Policy
This Privacy Policy explains how Vital Entry LLC (“Vital Entry,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information when you use our websites, applications, reports, support channels, and other services that link to this Policy (the “Services”). The Services are designed for U.S. business and professional use and proposed healthcare-business locations, not patient care.
Effective and last updated: August 12, 2026
At a glance
- We do not sell personal information or share it for .
- We do not load third-party advertising pixels or third-party analytics scripts on Vital Entry pages.
- We do not collect raw payment-card or bank-account details; a hosted payment provider may collect them directly.
- We do not want patient information, protected health information, or personal health records in the Services.
1. Scope and roles
Vital Entry LLC is a Texas limited liability company and controls personal information collected for our own business purposes through the Services. This Policy does not cover a third party's independent websites or practices, even when we link to them. A hosted checkout provider, for example, may apply its own notice to information it collects directly.
If we process information solely for a business customer under a written agreement, that customer may control it and its notice and our agreement govern. A customer-operated deployment may also have a separate operator and notice. “Personal information” includes similar terms such as personal data, but generally excludes lawfully public and properly information where applicable law does.
2. Information we collect
Information you provide
- Account and contact: email, name, telephone number, preferred contact method, verification status, and account identifiers.
- Location and analysis: selected healthcare profile; proposed business address or, if offered and affirmatively selected, coordinates; ; analysis inputs and results; saved labels and notes; comparisons; and source history.
- Project and support: role, decision type, project stage, help requests, feedback, and communications you direct to us.
- Choices: terms version and acceptance time, separate marketing choice, privacy requests, and related records.
- Transactions: product, amount, currency, tax, credit, checkout and payment status, provider references, purchases, entitlements, refunds, disputes, and reconciliation. We do not receive or store a full card or bank-account number.
Information collected automatically
- Session and security data: opaque session and request identifiers, route templates, timestamps, status codes, and information reasonably needed to deliver, secure, and troubleshoot the Services. Infrastructure providers may process IP address, browser, operating-system, and network information.
- Interactive map display: loading map tiles may send your IP address and the geographic extent visible on the map to . Vital Entry does not put submitted addresses, analysis IDs, report payloads, or analytical overlay in Mapbox request URLs.
- First-party measurement: an opaque browser-session ID, controlled page template and event, healthcare profile, broad device class, campaign or channel label, experiment variant, product code, and controlled error code.
- Attribution: limited campaign parameters and a referring site's origin, not its full path or query string, after checks designed to exclude contact and location data.
Other sources
We may receive transaction status from commerce providers, delivery status from communications providers, address candidates and geography from location-data providers, and fraud or security signals. We also use public or licensed business and professional facts such as facility names, business addresses, licenses, regulatory status, affiliations, ownership relationships, identifiers, and source dates.
If you provide information about another person, you are responsible for having authority and providing any notice or permission required by law.
3. How we use information
We use information to provide and improve the Services; verify locations and generate, save, and compare analyses; authenticate users and manage access; administer purchases, taxes, credits, refunds, disputes, and entitlements; respond to affirmative support or follow-up requests; send service, security, transaction, and permitted marketing communications; measure product use and debug errors; create aggregated or deidentified statistics and benchmarks; improve features, methods, and models using public, licensed, aggregated, or deidentified information; prevent fraud, abuse, and security incidents; enforce agreements and legal rights; comply with legal, tax, accounting, audit, and government requirements; and evaluate or complete a financing, merger, acquisition, reorganization, bankruptcy, or asset transfer.
We may also use information at your direction, with separate consent where required, or for a reasonably compatible purpose permitted by law. We do not use a personal email or telephone number as an input to a healthcare-location demand model.
4. Location and health boundaries
When you submit an exact proposed business address, we may send it to a configured geocoding provider, ask you to confirm a candidate, verify geography against government data, and store the confirmed address, coordinates, geography, match details, and provider history with the analysis. We do not continuously track your device or request background location. If browser geolocation is offered later, your browser will request permission first.
Submit only a proposed business site you are authorized to evaluate, not a home address or another person's current location. Where law treats a submitted location as sensitive personal information, we process it only as reasonably necessary for the requested location service, security, legal compliance, or another purpose covered by separate consent.
Vital Entry is market intelligence, not a healthcare provider, health plan, clearinghouse, or patient service. Do not submit patient information, , diagnoses, treatment details, medical records, genetic data, payer information, or information about a person seeking care. Unless we sign a separate written business associate agreement, the Services are not intended to receive for a customer.
We do not intentionally collect Social Security numbers, government IDs, biometric identifiers, financial-account credentials, or information about children. We may restrict, delete, return, or otherwise handle prohibited or unnecessary sensitive information as reasonably needed to protect the Services and comply with law.
5. How we disclose information
We may disclose relevant categories of information to infrastructure, hosting, storage, backup, security, and support providers; geocoding, mapping, routing, government-data, and market-data providers, including Mapbox for interactive map display; email and other communications providers; hosted checkout, payment, tax, fraud, receipt, and dispute providers; lawyers, accountants, auditors, insurers, and consultants; affiliates under common control; authorities or affected parties when reasonably necessary for law, safety, security, fraud, rights, or enforcement; transaction participants and successors in a corporate event; and recipients you direct or separately authorize.
Providers process information under our agreement with them or their own terms, depending on their role. We may disclose aggregated or deidentified information for any lawful business purpose where applicable law does not treat it as personal information.
6. No sale or behavioral advertising
Vital Entry does not sell personal information for money or other valuable consideration, share it for cross-context behavioral advertising, use it for targeted advertising, or use it to profile an individual for a decision producing legal or similarly significant effects. In the preceding 12 months, we have not sold or shared any category for cross-context behavioral advertising, and we do not knowingly sell or share information of anyone under 16. If these practices change, we will provide required notice and choice before the change takes effect.
7. Sessions and first-party measurement
Unlocking a report or verifying passwordless sign-in creates a server-managed session and an essential , ; production sessions use the Secure attribute. Opaque session and verification tokens are protected in hashed form. Blocking the cookie may prevent account, saved-work, purchase, or protected-report features.
For bounded product measurement, the browser creates a random ID in ; we do not use a tracking cookie or fingerprint your device. Events may include the controlled fields listed in Section 2. They exclude addresses, coordinates, email, phone, names, note content, analysis and checkout IDs, payment details, raw referrer paths, query strings, payer information, and economic inputs.
Measurement is disabled when the browser sends or Do Not Track. Raw events are retained for 90 days, then removed; statistics that no longer identify a browser session may be retained longer. A measurement failure never blocks the Services. Other parties do not collect your activity over time and across different websites through advertising or analytics technology on Vital Entry pages. Limited campaign attribution associated with an analysis is separate from this measurement stream.
8. Retention and deletion
We retain information only as reasonably necessary to provide the Services, maintain business and transaction records, comply with law, resolve disputes, enforce agreements, prevent fraud or abuse, and protect the Services. Raw measurement events are retained for 90 days. Session records last through expiration or revocation and a reasonable security period. Account, analysis, saved-location, project, and support records generally last for the active account, project, or relationship and afterward as needed for these purposes. Consent, terms, transaction, tax, entitlement, audit, refund, dispute, and fraud records may remain longer as evidence and for legal, accounting, security, and claims requirements. Public or licensed professional data may remain while needed for accuracy, source lineage, source rights, and the Services.
Deletion from active systems may not immediately remove limited copies from backups, legal holds, security records, or records we must or may retain. We protect those copies and delete them under applicable cycles. We may keep and use aggregated or deidentified information indefinitely for lawful purposes and will not attempt to reidentify it except to validate deidentification or as law permits.
9. Security
We use reasonable administrative, technical, and organizational safeguards designed for the information and Services, including controls intended to limit access, protect server-managed session secrets, bound application inputs and logs, and separate identity, analysis, measurement, and commerce records. No transmission or storage method is completely secure, and we cannot guarantee that information will never be accessed, used, or disclosed improperly. You are responsible for controlling your email account, browser, device, and any access you share.
10. Choices and U.S. privacy rights
Marketing is separate and optional. You may unsubscribe through a message link or by contacting us; withdrawal is prospective and does not stop service, security, transaction, or legal messages. Registration, qualification, and payment do not themselves request sales or analyst follow-up. Global Privacy Control and Do Not Track disable bounded measurement in the sending browser.
Depending on residence and applicable law, you may have rights to confirm processing; access or know categories, sources, purposes, recipients, and specific pieces; correct; delete; obtain a portable copy; withdraw sensitive-data consent; opt out of sale, targeted advertising, or qualifying profiling; appeal; and receive service without unlawful discrimination.
Email support@vitalentry.com with the subject Privacy Request, your state, and the request, or write to Vital Entry LLC, Attn: Privacy, c/o Pasha Law PC, 2000 West Loop South, Suite 1350, Houston, TX 77027. Do not send sensitive identity documents unless asked through an appropriate method. We may verify through the email, session, account, transaction, or other information reasonably related to our interaction. We will not require a new account solely for a request. We may limit or deny an unverifiable, inapplicable, or legally excepted request and may charge only where law permits.
An authorized agent must provide proof of authority, and we may verify directly with you where permitted. Appeal a denial at the same address with the subject Privacy Appeal. We will respond as applicable law requires. Because we do not currently sell, share for behavioral ads, use targeted ads, or conduct qualifying profiling, there is currently nothing to opt out of for those practices.
11. State notice at collection
Depending on how you use the Services, categories collected in the preceding 12 months include: identifiers and customer records; commercial information; internet or electronic-network activity; geolocation; professional or business information; inferences from analysis inputs and public or licensed data; and, only if a submitted precise location is linked to an individual, sensitive geolocation. Sources are you, your organization, browsers and devices, operational providers, and public or licensed sources. Sections 3, 5, and 8 describe the purposes, business-purpose recipient categories, and retention criteria.
Business-purpose disclosures may include identifiers, customer records, commercial information, network activity, geolocation, professional information, inferences, and sensitive geolocation when relevant, only to the recipient categories in Section 5. We do not intentionally collect protected-classification data, biometrics, sensory data, nonpublic education records, government IDs, passwords, financial credentials, genetic data, or consumer health or patient data. We do not use sensitive personal information for purposes that trigger a right to limit under California law. We have not sold or shared any category for cross-context behavioral advertising in the preceding 12 months.
12. Children
The Services are not directed to children under 13, and business accounts and paid features are intended for adults authorized to act for a business. We do not knowingly collect from a child under 13. Contact us if you believe a child submitted information so we can investigate and take appropriate action.
13. U.S. processing
The Services are designed for U.S. business users and U.S. proposed business locations. We and providers may process information in the United States and other places where we or they operate, whose laws may differ from yours. We do not presently market the Services to consumers in the European Economic Area, United Kingdom, or Switzerland.
14. Policy changes
We may update this Policy prospectively as the Services, providers, and law change. We will post the updated Policy and date. For material changes, we will provide prominent, email, or other notice required by law and obtain consent before a materially different, incompatible use where law requires. Prior versions govern earlier practices to the extent required.
15. Contact Vital Entry
For questions, concerns, complaints, privacy requests, or appeals, contact Vital Entry LLC, Attn: Privacy at support@vitalentry.com or c/o Pasha Law PC, 2000 West Loop South, Suite 1350, Houston, TX 77027. Do not send patient information, card details, government identification, or other sensitive documents by ordinary email.
Effective and last updated August 12, 2026