Legal

Privacy Policy

Effective Date: March 20, 2026 Last Updated: April 20, 2026
Important Notice — HHOcare Does Not Store Protected Health Information (PHI) HHOcare is a workforce compliance tracking tool that records employment requirement dates (certifications, clearances, training) and client contact information. HHOcare does not store medical records, test results, diagnoses, Medicaid/Medicare IDs, physician information, or any data classified as Protected Health Information (PHI) under HIPAA. HHOcare does not sign Business Associate Agreements (BAAs) because our platform is designed to operate outside the scope of HIPAA-regulated data.

Contents

  1. About HHOcare
  2. What We Never Store
  3. Information We Collect
  4. How We Use Your Information
  5. How We Share Information
  6. Data Storage & Infrastructure
  7. Security
  8. Data Retention
  9. Your Rights
  10. Cookies
  11. Children's Privacy
  12. Changes to This Policy
  13. Contact Us

1. About HHOcare

HHOcare ("we," "us," or "our") is a software-as-a-service (SaaS) platform that provides workforce compliance tracking tools to home health agencies ("Agencies," "you"). The platform allows Agencies to track caregiver certification dates, clearance expiry dates, supervisory visit schedules, incident reports, tasks, and related compliance data.

HHOcare is a compliance date tracking tool — we track when employment requirements were completed and when they expire. We do not store the underlying documents, medical records, or clinical information. Agencies retain and manage all original documentation outside the platform.

HHOcare operates as a data processor on behalf of Agencies. Each Agency is the data controller responsible for the data it enters into the platform. By using HHOcare, you agree to the terms of this Privacy Policy.

Our platform is hosted using Hostinger (web server) and Supabase (database infrastructure) in the United States.

2. What We Never Store

HHOcare is designed to operate outside the scope of HIPAA-regulated data. To ensure this, our platform does not store, process, or collect any of the following:

What We Do Track: Compliance requirement completion dates, expiration dates, caregiver employment information (name, phone, role, office, start date), client contact information (name, phone, address), supervisory visit dates, incident report logs, task assignments, and audit trails. This is workforce compliance and HR data — not Protected Health Information (PHI).

3. Information We Collect

We collect information in the following categories:

CategoryExamplesSource
Agency Account Information Agency name, billing contact, plan type, account status Provided by your administrator during account setup
User Account Information Name, email address, role (Admin/Staff), office, profile photo, hashed password Provided by you or your administrator
Caregiver Records Name, caregiver code, role, department, office, county, email, phone, start date, employment type, gender, certification documents and expiry dates Entered by your agency administrators
Client Records Name, phone, address, gender, emergency contact, service start/end dates, member ID, visit history Entered by your agency administrators
Operational Records Supervisory visit logs, incident reports, task assignments, training records, policy acknowledgments Entered by your agency users
Audit & Usage Logs Login timestamps, IP addresses, actions performed, records viewed or modified Automatically generated by the platform
Login History Per-login event records: timestamp, outcome (success/failure), IP address, device / browser user-agent. Used for account-security visibility in the SuperAdmin dashboard. Automatically generated each time a login is attempted. Retained for 180 days, then automatically pruned.
Payment Information Billing email, payment method details (processed via Stripe — we do not store full card numbers) Provided by you during subscription purchase

Note on Client Data: Client records in HHOcare contain contact and service coordination information only (name, phone, address, emergency contact). HHOcare does not collect Medicaid/Medicare identifiers, dates of birth, physician information, or any clinical data. See Section 2: What We Never Store for the complete list.

4. How We Use Your Information

We use information collected through the platform for the following purposes:

We do not sell, rent, or trade your data to third parties for marketing purposes. We do not use member or employee data for advertising or profiling.

5. How We Share Information

We share information only in the following limited circumstances:

RecipientPurposeData Shared
Supabase, Inc. Database hosting and authentication infrastructure All platform data stored in the database
Hostinger International Ltd. Web server and file hosting Application files; web server access logs
Stripe, Inc. Payment processing Billing email, payment method details
Law Enforcement / Legal Process Compliance with valid legal orders, subpoenas, or court orders Only data specifically required by the legal demand
Business Transfer In the event of a merger, acquisition, or asset sale, data may be transferred to the successor entity All platform data; you will be notified in advance

All third-party service providers listed above are contractually bound to process data only as necessary to deliver their services and are prohibited from using your data for their own commercial purposes.

6. Data Storage & Infrastructure

Your data is stored on infrastructure provided by Supabase (PostgreSQL database) and served via Hostinger (web hosting), both operating within the United States.

Each Agency's data is logically isolated from other agencies through row-level security (RLS) policies enforced at the database level. No agency can access another agency's data.

Data is transmitted over HTTPS (TLS encryption) between your browser and our servers.

HIPAA & PHI: HHOcare does not store Protected Health Information (PHI) as defined by HIPAA (see Section 2). Because our platform is designed to operate outside the scope of HIPAA-regulated data, a Business Associate Agreement (BAA) is not required. Agencies requiring clinical data management and PHI storage should use a HIPAA-compliant EMR system alongside HHOcare.

7. Security

We implement the following security measures to protect your data:

While we take data security seriously, no system is 100% secure. In the event of a data breach that affects your agency's data, we will notify you within 72 hours of discovering the breach to the extent required by applicable law.

8. Data Retention

We retain your agency's data for as long as your account is active. Upon account cancellation or termination:

Login History: Per-login event records (timestamp, outcome, IP address, device user-agent) are retained for 180 days, then automatically deleted by a daily scheduled job. Aggregate counters (last-sign-in timestamp, total login count) follow the general account-data retention rules above.

You may request earlier deletion by contacting us at the address below.

9. Your Rights

As an Agency (data controller), you have the following rights with respect to data stored in your HHOcare account:

Individual employees or members whose data has been entered into the platform by your agency should direct requests regarding their personal data to your agency directly. HHOcare will cooperate with agencies to fulfill such requests upon written instruction.

California Residents (CCPA): California residents have the right to know, delete, and opt out of the sale of personal information. HHOcare does not sell personal information. To exercise your rights, contact us at the email below.

EEA/UK Residents (GDPR): If you are located in the European Economic Area or United Kingdom, you have rights including access, rectification, erasure, restriction, portability, and objection. To exercise these rights, contact us at the email below. Our legal basis for processing is contractual necessity (performance of our SaaS agreement with your agency).

10. Cookies & Tracking

HHOcare uses only the following types of browser storage:

We do not use third-party advertising cookies, tracking pixels, or behavioral analytics tools. We do not use Google Analytics or similar services.

11. Children's Privacy

HHOcare is a business-to-business platform intended for use by adult professionals at home health agencies. We do not knowingly collect personal information from anyone under the age of 18 as a platform user. If you believe a minor has created an account, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

Your continued use of HHOcare after a policy update constitutes your acceptance of the updated terms. If you do not agree to the updated policy, you must stop using the platform and may request deletion of your account.

13. Contact Us

For questions about this Privacy Policy, to exercise your data rights, or to report a security concern, please contact us:

HHOcare
Email: sales@hhocare.com
Platform: hhocare.com

This Privacy Policy is governed by the laws of the Commonwealth of Pennsylvania, United States, without regard to conflict of law principles.

Legal

Terms of Use

Effective Date: April 10, 2026 Last Updated: April 20, 2026
Please Read These Terms Carefully These Terms of Use constitute a legally binding agreement between you and HHOcare. By accessing or using our platform, you agree to be bound by these Terms, our Privacy Policy, and all applicable laws and regulations. If you do not agree, you must immediately cease all use of the platform.

Contents

  1. Eligibility & Acceptance
  2. Description of Service
  3. Accounts & Access
  4. Permitted Use & License
  5. User Obligations
  6. Prohibited Activities
  7. Compliance Disclaimer
  8. Data, Privacy & Healthcare Information
  9. Billing, Subscription & Trial
  10. Intellectual Property
  11. Service Availability & Modifications
  12. Disclaimers & Warranty
  13. Limitation of Liability
  14. Indemnification
  15. Termination & Suspension
  16. Governing Law & Dispute Resolution
  17. Changes to These Terms
  18. General Provisions
  19. Contact Us

1. Eligibility & Acceptance

By accessing or using HHOcare ("the Platform," "Service," "we," "us," or "our"), you represent and warrant that:

If you are accepting these Terms on behalf of an organization, you represent that you have the authority to bind that organization. The term "you" refers to both you individually and the organization you represent.

Your use of the Platform constitutes your agreement to these Terms. If you do not agree, you must not use the Platform.

2. Description of Service

HHOcare is a cloud-based software-as-a-service (SaaS) platform that provides workforce compliance management tools to home health agencies ("Agencies"). The Platform enables Agencies to:

HHOcare is a compliance tracking tool. It does not store, process, or manage the underlying documents themselves (e.g., physical clearance certificates, training certificates). Agencies retain and manage all original documentation outside the Platform.

3. Accounts & Access

Account Provisioning. HHOcare operates on a sales-led model. There is no self-serve signup. All agency accounts are provisioned by HHOcare personnel. You will receive an invitation email with a secure activation link to set your password and activate your account.

Account Security. You are responsible for:

Mandatory Two-Factor Authentication (2FA). All users are required to complete email-based two-factor authentication on every login. This requirement cannot be disabled or bypassed. Failure to complete 2FA will prevent access to the Platform.

Password Policy. Passwords must meet minimum complexity requirements (8+ characters, uppercase, number, special character). Passwords expire every 90 days and must be reset to continue using the Platform.

Session Management. Sessions automatically expire after a configurable period of inactivity (default: 30 minutes). Your agency administrator may adjust this timeout within the allowed range.

Credential Sharing. Account credentials are personal and non-transferable. You may not share your login credentials with any other person. Each user must have their own account. HHOcare reserves the right to suspend accounts where credential sharing is detected.

4. Permitted Use & License

Subject to your compliance with these Terms, HHOcare grants you a limited, non-exclusive, non-transferable, revocable license to access and use the Platform solely for your agency's internal business operations related to workforce compliance management.

This license does not include the right to:

5. User Obligations

As a user of HHOcare, you agree to:

6. Prohibited Activities

You agree not to engage in any of the following activities:

HHOcare reserves the right to investigate suspected violations and to suspend or terminate accounts engaged in prohibited activities without prior notice.

7. Compliance Disclaimer

IMPORTANT: HHOcare is a compliance tracking tool, not a legal advisor, compliance consultant, or regulatory authority. The Platform does not provide legal advice, regulatory guidance, or compliance certification of any kind.

You acknowledge and agree that:

8. Data, Privacy & Healthcare Information

Privacy Policy. Our Privacy Policy is incorporated into these Terms by reference. By using the Platform, you agree to the collection, use, and sharing of information as described in the Privacy Policy.

Data Ownership. You retain full ownership of all data you enter into the Platform. HHOcare does not claim any ownership interest in your data. We are granted a limited license to store, process, and display your data solely for the purpose of providing the Service.

Data Isolation. Each agency's data is logically isolated from other agencies through row-level security (RLS) policies enforced at the database level. No agency can access, view, or modify another agency's data.

Healthcare Information. The Platform may be used to store information related to caregiver health records (e.g., TB test dates, physical exam dates) and client information (e.g., Medicaid/Medicare identifiers, physician information). You acknowledge the following:

HIPAA Notice: HHOcare is a workforce compliance management tool and does not represent that its infrastructure meets all HIPAA technical safeguard requirements. Please refer to our Privacy Policy — Data Storage & Infrastructure section for details on our infrastructure providers. Agencies that are covered entities under HIPAA are responsible for making their own determination regarding compliance when using this platform.

Soft Delete & Audit Trail. HHOcare uses soft delete (archival) rather than permanent deletion for all records. This ensures a complete audit trail is maintained. Archived records are hidden from active views but retained in the database for compliance and auditing purposes. Permanent deletion of all agency data is available only upon account termination (see Section 15).

Data Export. Admin users may export agency data at any time using the Export tools available within the Platform. Data is provided in CSV format suitable for import into other systems.

9. Billing, Subscription & Trial

Sales-Led Model. HHOcare operates on a sales-led model. All subscription plans are arranged through the HHOcare sales team. There is no self-serve plan selection or upgrade within the Platform.

Trial Period. New agencies may receive a trial period (typically 7 days) during which full Platform functionality is available. When the trial expires:

Subscription Plans. Subscription plans include limits on the number of administrators, staff users, caregivers, and clients that may be tracked. If you exceed your plan's limits, you will need to upgrade to a higher plan. Plan details and pricing are provided by the HHOcare sales team.

Payment. Payments are processed securely through Stripe, Inc. HHOcare does not store your full credit card numbers. By providing payment information, you authorize HHOcare to charge your payment method on a recurring basis according to your billing cycle.

Non-Payment. If a payment fails, HHOcare will attempt to notify you via email. After three (3) consecutive failed payment attempts, your account may be suspended. Suspended accounts enter read-only mode. Service will be restored upon successful payment.

Refunds. Subscription fees are generally non-refundable. Refunds for partial billing periods are not provided. In exceptional circumstances, refund requests may be submitted to sales@hhocare.com and will be evaluated on a case-by-case basis.

Price Changes. HHOcare reserves the right to change subscription pricing. You will receive at least 30 days' written notice before any price increase takes effect. If you do not agree to the new pricing, you may cancel your subscription before the new pricing period begins.

10. Intellectual Property

HHOcare Ownership. The Platform, including all software, code, design, text, graphics, logos, icons, images, audio, and the compilation thereof (collectively, "HHOcare Materials"), is the exclusive property of HHOcare and is protected by United States and international copyright, trademark, and other intellectual property laws.

Trademarks. "HHOcare," the HHOcare logo (Arctic Cross design), "Home Health Office Care," and all related names, logos, product and service names, designs, and slogans are trademarks of HHOcare. You may not use these marks without our prior written permission.

Restrictions. You may not reproduce, distribute, modify, create derivative works of, publicly display, publicly perform, republish, download, store, or transmit any HHOcare Materials, except as follows:

Your Data. You retain all intellectual property rights in the data you enter into the Platform. HHOcare acquires no intellectual property rights in your data beyond the limited license to process and display it as part of the Service.

Feedback. If you provide suggestions, ideas, or feedback about the Platform, you grant HHOcare a non-exclusive, worldwide, royalty-free, irrevocable license to use, modify, and incorporate such feedback into the Platform without any obligation to you.

11. Service Availability & Modifications

Availability. HHOcare strives to maintain high availability of the Platform. However, we do not guarantee uninterrupted or error-free service. The Platform may be temporarily unavailable due to:

Modifications. HHOcare reserves the right to modify, update, or discontinue any feature or aspect of the Platform at any time. We will make reasonable efforts to notify users of material changes that affect core functionality. Continued use of the Platform after modifications constitutes acceptance of the changes.

Usage Limits. HHOcare may enforce usage limits appropriate to your subscription plan, including limits on the number of users, caregivers, clients, API calls, or data storage. These limits will be communicated as part of your plan terms.

12. Disclaimers & Warranty

THE PLATFORM AND ALL CONTENT, FEATURES, AND SERVICES ARE PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS, WITHOUT ANY WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.

Without limiting the foregoing, HHOcare does not warrant that:

Your use of the Platform and reliance on any information obtained through the Platform is at your own risk. You are solely responsible for any damage to your computer system or loss of data that results from the use of the Platform.

13. Limitation of Liability

TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL HHOCARE, ITS OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, OR AFFILIATES BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO:

These limitations apply regardless of the theory of liability (contract, tort, negligence, strict liability, or otherwise), even if HHOcare has been advised of the possibility of such damages.

Liability Cap: HHOcare's total cumulative liability to you for all claims arising out of or relating to these Terms or the Platform shall not exceed the total amount of fees you actually paid to HHOcare during the twelve (12) months immediately preceding the event giving rise to the claim. If you have not paid any fees, HHOcare's total liability shall not exceed one hundred dollars ($100.00 USD).

Some jurisdictions do not allow the exclusion or limitation of certain damages. In such jurisdictions, our liability shall be limited to the maximum extent permitted by law.

14. Indemnification

You agree to indemnify, defend, and hold harmless HHOcare, its officers, directors, employees, agents, and affiliates from and against any and all claims, liabilities, damages, losses, costs, and expenses (including reasonable attorneys' fees) arising out of or in connection with:

This indemnification obligation shall survive the termination of your account and these Terms.

15. Termination & Suspension

Termination by You. You may request cancellation of your account at any time by contacting sales@hhocare.com. Upon cancellation:

Termination by HHOcare. HHOcare may terminate or suspend your account at any time, with or without cause, including but not limited to:

Immediate Suspension. HHOcare may immediately suspend access without prior notice if we reasonably believe your account is being used in a manner that threatens the security, integrity, or availability of the Platform or other users' data.

Effect of Termination. Upon termination, your license to use the Platform immediately ceases. Sections that by their nature should survive termination (including but not limited to Sections 7, 10, 12, 13, 14, and 16) shall survive.

16. Governing Law & Dispute Resolution

Governing Law. These Terms shall be governed by and construed in accordance with the laws of the Commonwealth of Pennsylvania, United States, without regard to its conflict of law provisions.

Arbitration. Any dispute, claim, or controversy arising out of or relating to these Terms or the Platform shall be resolved through binding arbitration administered by the American Arbitration Association (AAA) in accordance with its Commercial Arbitration Rules. The arbitration shall take place in Pennsylvania. The arbitrator's decision shall be final and binding and may be entered as a judgment in any court of competent jurisdiction.

Class Action Waiver. You agree that any dispute resolution proceedings will be conducted on an individual basis only, and not as part of a class, consolidated, or representative action. You waive any right to participate in a class action lawsuit or class-wide arbitration against HHOcare.

Time Limitation. Any claim or cause of action arising out of or relating to these Terms or the Platform must be filed within one (1) year after the cause of action accrues. Claims filed after this period are permanently barred.

Exceptions. Notwithstanding the above, either party may seek injunctive or other equitable relief in any court of competent jurisdiction to prevent the actual or threatened infringement of intellectual property rights or unauthorized disclosure of confidential information.

17. Changes to These Terms

HHOcare reserves the right to modify these Terms at any time. When we make material changes:

Your continued use of the Platform after the effective date of revised Terms constitutes your acceptance of the changes. If you do not agree to the revised Terms, you must stop using the Platform and may request cancellation of your account.

18. General Provisions

Entire Agreement. These Terms, together with the Privacy Policy, constitute the entire agreement between you and HHOcare regarding your use of the Platform and supersede all prior or contemporaneous agreements, understandings, or representations.

Severability. If any provision of these Terms is found to be invalid, illegal, or unenforceable by a court of competent jurisdiction, the remaining provisions shall continue in full force and effect.

Waiver. The failure of HHOcare to enforce any right or provision of these Terms shall not constitute a waiver of such right or provision. Any waiver must be in writing and signed by HHOcare.

Assignment. You may not assign or transfer these Terms or your rights hereunder without HHOcare's prior written consent. HHOcare may assign these Terms without restriction, including in connection with a merger, acquisition, or sale of assets.

No Joint Venture. Nothing in these Terms creates a partnership, joint venture, employment, or agency relationship between you and HHOcare. You are a customer of HHOcare, not an employee, partner, or agent.

Force Majeure. HHOcare shall not be liable for any failure or delay in performance resulting from causes beyond its reasonable control, including but not limited to natural disasters, acts of government, internet disruptions, pandemics, or third-party service provider outages.

Electronic Communications. By using the Platform, you consent to receive communications from HHOcare electronically (via email and in-platform notifications). You agree that all agreements, notices, and communications provided electronically satisfy any legal requirement that such communications be in writing.

Customer Conduct. We reserve the right to terminate the account of any user who engages in abusive, threatening, or harassing behavior toward HHOcare staff, without refund or prior notice.

19. Contact Us

For questions about these Terms of Use, to report a violation, or to request account changes, please contact us:

HHOcare
Email: sales@hhocare.com
Platform: hhocare.com

These Terms of Use are governed by the laws of the Commonwealth of Pennsylvania, United States.