Privacy Policy

Effective Date: August 20th, 2026

Taylored PT & Wellness, LLC d/b/a Taylored Concierge Rehab ("Company," "we," "our," or "us") operates the Taylored Concierge Rehab website, mobile application, provider portal, patient-facing tools, and related services (collectively, the "Platform").

This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use the Platform, including when you request services, apply as a provider, communicate with us, use scheduling and telehealth features, submit information through our website or application, or interact with AI-assisted documentation tools.

This Privacy Policy applies to information collected through the Platform and related communications. It does not replace any separate Notice of Privacy Practices, informed consent, provider agreement, or other disclosure that may be provided by an independent licensed provider, practice, or other third party.

1. Information We Collect

We may collect the following categories of information:

A. Information You Provide Directly

We may collect information you voluntarily provide, including:

  • first and last name;
  • mailing address;
  • email address;
  • phone number;
  • date of birth;
  • account login and profile information;
  • appointment, scheduling, intake, and service request information;
  • payment and billing information;
  • communications, support requests, and messages you send to us;
  • forms, consents, questionnaires, uploaded documents, and other materials you submit through the Platform.

B. Patient and Health-Related Information

If you use the Platform to request or receive services, we may collect information related to your care, wellness, scheduling, treatment coordination, or service preferences. This may include health-related information you or a provider submit through the Platform.

C. Provider Application and Verification Information

If you apply to join the Platform as a provider, we may collect application and verification information, such as:

  • professional credentials and licensure information;
  • discipline and specialty information;
  • NPI or other identifying professional information, where applicable;
  • service area, scheduling, and availability information;
  • business or payout information;
  • documents submitted as part of the provider application, onboarding, and verification process;
  • sworn attestations and self-disclosures made under penalty of perjury regarding criminal history, registry status, licensure standing, and healthcare-program exclusions;
  • records and results of exclusion-list, registry, licensure, and background screening checks performed as part of provider verification and compliance review.

D. Eligibility, Discount, and Financial-Hardship Information

If you request discounted care, pro-bono (free) care, or other eligibility-based programs, we may collect information you voluntarily provide to support that request. This may include military, veteran, or first responder status, financial-hardship indicators, participation in public-assistance or social-welfare programs (such as SNAP/food assistance, Medicaid, SSI/SSDI, or similar programs), and supporting verification documents you upload (such as a DD-214, military or department ID, or benefits documentation). Please upload only the documentation requested and avoid including unnecessary sensitive information. These documents are stored using private, access-controlled storage and are reviewed only by authorized personnel to verify eligibility. Requesting pro-bono or discounted care is entirely optional; however, if you choose to request pro-bono care or a military/veteran/first responder discount, at least one supporting verification document is required so eligibility can be verified. Our team may request additional documentation or deny eligibility. This information is used solely to evaluate program eligibility.

E. Payment and Transaction Information

Payments, payouts, and related financial processing are facilitated through the Platform's integrated Stripe payment infrastructure. We may receive transaction details, payment status, partial billing information, and payout-related information necessary to operate the Platform, but full payment card data is processed by our payment processor and not stored directly by us except as provided through secure processor tools.

F. Information Collected Automatically

When you use the Platform, we may automatically collect technical and usage information, including:

  • device type and identifiers;
  • browser type;
  • IP address;
  • operating system;
  • application activity and usage logs;
  • timestamps, access logs, and error data;
  • general analytics and performance information.

G. Calendar, Communication, and Telehealth Information

We use integrated tools for scheduling and communications, including Google Calendar, Resend for email, and Twilio for SMS, phone calls, and telehealth video conferencing. When you use these features, we may collect and process scheduling metadata, message delivery data, call or session details, appointment confirmations, and related communication records as reasonably necessary to operate the Platform.

H. AI Scribe Inputs

The Platform's AI scribe feature uses the provider's browser-based speech recognition capability to capture voice input as raw transcript text. This raw transcript text, along with any additional dictated content, note content, patient context, or other submitted information, may then be processed through integrated AI or large language model services for the purpose of generating draft clinical documentation in SOAP format or similar note structures. These tools are intended solely to assist with transcription and draft documentation based on submitted content. They are not intended to diagnose, recommend treatment, provide medical advice, or independently make clinical decisions.

AI-assisted documentation processing may involve integrated AI or large language model services provided through or supported by the Platform's infrastructure. Such processing is subject to applicable vendor terms, contractual restrictions, and data protection requirements. Except as may be expressly described in applicable vendor agreements or notices, we do not make representations in this Privacy Policy regarding whether third-party AI service providers retain, use, or process submitted content beyond what is required to generate requested outputs.

Voice input and raw transcripts used for AI scribe processing are treated by the Platform as transient processing inputs rather than official finalized clinical documentation. Raw transcripts are automatically cleared within 15 days. The provider-reviewed and finalized clinical note (e.g., a signed SOAP note) is the official documentation retained as part of the patient's clinical record. Intermediate draft content is superseded by the finalized note upon provider review and finalization and is not independently maintained as a separate part of the official patient record.

2. How We Use Information

We may use personal information to:

  • create, maintain, and manage user accounts;
  • operate, maintain, and improve the Platform;
  • facilitate appointment requests, scheduling, telehealth sessions, provider-patient matching, and related communications;
  • process payments, payouts, billing events, refunds, and related records;
  • review and verify provider applications, account status, and eligibility;
  • evaluate provider identity, credentials, licensure, sanctions, compliance, fraud-prevention, and risk-management issues where applicable;
  • maintain provider onboarding, verification, compliance, dispute, and related administrative records;
  • communicate with users regarding services, scheduling, support, updates, or account activity;
  • provide administrative support and customer service;
  • generate, assist with, or organize documentation using AI-assisted scribe features;
  • enforce provider agreements, Platform requirements, and other applicable terms;
  • investigate complaints, suspected misuse, fraud, security incidents, or other conduct affecting the Platform;
  • manage provider account restrictions, suspensions, terminations, or related risk-management actions;
  • maintain security, prevent fraud, detect misuse, and protect Platform integrity;
  • comply with legal, regulatory, contractual, credentialing, tax, accounting, or operational obligations; and
  • send service-related communications and, where permitted by law, promotional communications.

3. Health Information, HIPAA, and Related Privacy Rights

Some information collected or processed through the Platform may relate to health, treatment, wellness, care coordination, scheduling, or clinical documentation.

A. Protected Health Information (PHI)

When information qualifies as protected health information ("PHI") under HIPAA, we treat that information in accordance with applicable HIPAA requirements. In general, PHI means individually identifiable health information that relates to an individual's past, present, or future physical or mental health or condition, the provision of health care to the individual, or payment for the provision of health care, when that information is held or transmitted by a covered entity or business associate.

Not all health-related information collected through a website or application is necessarily PHI in every context. However, we are committed to handling health-related information with appropriate care, security, and confidentiality, and to applying HIPAA-related protections where HIPAA applies.

B. Our Role

The Platform supports independent licensed providers and related administrative, scheduling, communication, telehealth, documentation, and payment functions.

Not all Platform workflows involve PHI or are governed by HIPAA. Depending on the nature of the information, who collected it, the purpose of the processing, and the context in which it is used, certain activities may instead be governed by contractual commitments, general privacy principles, Federal Trade Commission requirements, or applicable state privacy laws.

Provider onboarding, credentialing, identity verification, compliance review, and related operational activities generally involve professional information, personal information, or other sensitive information and may not involve PHI.

Where the Company acts as a business associate or subcontractor under a written agreement with an independent provider, covered entity, or another business associate, we handle PHI in accordance with applicable HIPAA requirements, the terms of that agreement, and other applicable law.

Nothing in this Privacy Policy is intended to alter the allocation of professional responsibility between the Company and independent providers. Independent licensed providers remain responsible for their own clinical judgment, treatment decisions, documentation content, informed consent obligations, licensure compliance, and professional services.

C. Uses and Disclosures of Health Information

Where permitted by applicable law, we or independent providers using the Platform may use or disclose PHI or other health-related information for purposes such as:

  • treatment, including providing, coordinating, or managing care and related services;
  • payment, including billing, collecting payment, facilitating transactions, and maintaining related records;
  • healthcare operations, including quality review, provider onboarding and verification, training, administrative functions, platform support, auditing, compliance, fraud prevention, security, and business management;
  • communications requested by the user, including appointment scheduling, reminders, telehealth access, and care-related administrative communications; and
  • other uses or disclosures authorized by the individual or otherwise required or permitted by law.

We do not use AI scribe features to diagnose, independently recommend treatment, or provide medical advice. Those tools are intended only to assist with transcription and draft documentation based on submitted content.

D. HIPAA-Related Rights

Where HIPAA applies, individuals may have rights regarding their PHI, including rights to request access, request amendments or corrections in appropriate circumstances, and receive information about certain disclosures, subject to applicable law and exceptions.

If you would like to make a privacy-related request concerning health information, you may contact us using the information listed in this Privacy Policy. Depending on the nature of the request and our role, we may respond directly or direct the request to the appropriate provider or covered entity.

E. Relationship to Other Notices

This Privacy Policy is intended to provide a public-facing explanation of our privacy and health-data practices. It does not replace any separate Notice of Privacy Practices, informed consent, provider agreement, telehealth consent, or other disclosure that may be provided by an independent provider, practice, or other covered entity where required by law.

4. How We Share Information

We may share personal information only as reasonably necessary for business, operational, legal, security, and service-related purposes.

A. Platform Infrastructure and Data Hosting

We use Base44 and Google Cloud infrastructure to host, store, secure, back up, transmit, and operate Platform data. Depending on the workflow, this infrastructure may create, receive, maintain, or transmit health-related information, including patient profiles, appointments, clinical notes, care coordination information, and other Platform records.

B. AI and Documentation Assistance Services

We may use integrated AI or large language model services made available through or supported by the Platform's infrastructure to assist with transcription, summarization, note drafting, documentation support, or related workflow functions. Depending on the workflow, such services may process clinical transcripts, draft note content, and limited patient context necessary to generate requested outputs.

C. Scheduling, Communications, and Telehealth Services

We use services such as Google Calendar, Resend, and Twilio to support scheduling, email, SMS, telehealth, phone, reminders, confirmations, and related communications. These services may process limited identifying, scheduling, appointment, service, or communication information, such as names, dates, times, service types, telehealth links, and message content. As part of routine scheduling and communication workflows, these services generally do not receive full clinical records unless a user or provider intentionally includes additional information in a communication.

D. Payment and Transaction Services

We use Stripe and related payment infrastructure for payment processing, payouts, invoicing, refunds, transaction records, and related billing functions. These services generally process financial, operational, and transaction-related data, such as payment status, invoice amounts, generic service descriptions, internal identifiers, and payout information. They do not receive full clinical records as part of routine payment processing.

E. Other Service Providers and Legal Disclosures

We may also share information with:

  • independent providers or provider applicants, where needed to facilitate requested services, provider onboarding, scheduling, credential review, or marketplace functions;
  • vendors or service providers engaged for credentialing, compliance, identity verification, background screening, fraud prevention, audit, risk management, or security functions, where reasonably necessary to evaluate provider eligibility, maintain Platform integrity, or comply with legal obligations;
  • professional advisors, insurers, auditors, legal counsel, or similar service providers;
  • regulators, law enforcement, courts, or governmental authorities where required by law or where reasonably necessary to protect rights, safety, users, or the Platform; and
  • a successor or affiliated entity in connection with a merger, acquisition, financing, restructuring, or sale of assets.

F. Written Data-Protection Terms

Where applicable, we maintain business associate agreements or comparable written data-protection terms with vendors or service providers that create, receive, maintain, or transmit PHI or other protected data on behalf of the Platform.

We do not sell personal information for money.

We do not sell biometric data.

We do not knowingly share personal information for cross-context behavioral advertising.

5. Cookies, Logs, and Analytics

We may use cookies, local storage, session tools, and internal analytics features built within our Platform infrastructure to:

  • keep users logged in;
  • remember settings and preferences;
  • understand Platform performance and usage;
  • troubleshoot errors;
  • improve functionality and user experience; and
  • maintain security and fraud prevention measures.

You may be able to control some cookies or similar technologies through your browser or device settings. Some Platform features may not function properly if those settings are disabled.

6. Retention of Information

We retain personal information for as long as reasonably necessary to:

  • provide the Platform and requested services;
  • maintain account, appointment, transaction, and support records;
  • review and maintain provider application, verification, compliance, and administrative records;
  • comply with legal, tax, accounting, regulatory, dispute-resolution, security, and contractual obligations; and
  • enforce our agreements and protect our rights.

Health-related, account, transaction, provider verification, and administrative records may be retained for different periods depending on the nature of the information and applicable legal, clinical, contractual, or operational requirements.

Raw transcripts used for AI scribe processing are treated by the Platform as transient processing inputs rather than official finalized clinical documentation and are automatically cleared within 15 days. The provider-reviewed and finalized clinical note is the official documentation retained as part of the patient's clinical or Platform record in accordance with applicable record-retention, legal, contractual, clinical, billing, or operational requirements. Intermediate draft content is superseded by the finalized note upon provider review and finalization and is not independently maintained as a separate part of the official patient record.

We may retain provider application, credentialing, verification, compliance, dispute, payout, and related administrative records for as long as reasonably necessary to evaluate eligibility, maintain Platform integrity, comply with legal or contractual obligations, resolve disputes, and enforce applicable agreements.

We may delete, de-identify, anonymize, or securely dispose of information when retention is no longer reasonably necessary or required.

7. Security

We use reasonable administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, disclosure, misuse, loss, or alteration. These safeguards may include:

  • SSL/TLS encryption;
  • encryption at rest where appropriate;
  • secure authentication controls;
  • role-based access controls (RBAC);
  • row-level security (RLS), where supported;
  • access limitations based on user role and operational need;
  • vendor and infrastructure controls;
  • logging, monitoring, and routine updates.

Where applicable, these safeguards are also designed to protect electronic protected health information in a manner consistent with applicable HIPAA security obligations.

While we take reasonable steps to protect information, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.

8. Your Choices and Rights

Depending on where you live and subject to applicable law, you may have the right to request access to, correction of, deletion of, or information about certain personal information we maintain about you. You may also have the right to appeal certain request decisions or limit certain uses or disclosures where required by law.

Where HIPAA applies, you may also have certain rights with respect to your PHI, including rights to request access to records, request corrections or amendments in appropriate circumstances, and request information about certain disclosures, subject to applicable law.

To submit a privacy-related request, contact us at:

clientsupport@tayloredconciergerehab.com

We may take reasonable steps to verify your identity before responding to a request.

You may opt out of promotional email communications by using the unsubscribe link in those communications. We may still send you non-promotional service, account, transactional, security, or legal communications.

9. Children's Privacy

The Platform is not intended for minors to independently create accounts or use services without the involvement of a parent or legal guardian.

A parent or legal guardian must create, authorize, and manage any account or service request involving a minor. Minors may not independently create accounts, submit service requests, or consent to services through the Platform.

If we learn that we collected personal information directly from a child or minor in a manner not permitted by applicable law, we will take reasonable steps to delete that information unless retention is legally required.

10. Third-Party Services and Integrations

The Platform may rely on or link to third-party services, integrations, or websites. We are not responsible for the privacy, content, or security practices of third-party services outside our control. Your use of third-party services may be governed by their own terms, notices, and privacy policies.

11. Communications

We may contact you by email, SMS, phone, in-app message, or similar methods for service-related purposes, including account verification, appointment reminders, scheduling updates, telehealth links, security alerts, transactional confirmations, support communications, and other operational notices.

Where permitted by law, we may also send marketing or promotional communications. You may opt out of promotional communications, but you may continue to receive service-related or legally required notices.

12. Data Breach and Incident Response

We maintain reasonable administrative, technical, and physical safeguards designed to protect personal information. In the event of a security incident involving personal information, we will investigate the incident and provide notice to affected individuals and, where required, applicable authorities in accordance with applicable law.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, operations, data practices, technology, or legal requirements. When we make material changes, we may update the effective date, post the revised Privacy Policy on the Platform, and take additional steps where required by law.

14. Contact Information

If you have questions or concerns about this Privacy Policy, please contact us:

Taylored PT & Wellness, LLC

d/b/a Taylored Concierge Rehab

448 Cummings St #179

Abingdon, Virginia 24210

Email: clientsupport@tayloredconciergerehab.com

Phone: (888) 963-1912

Effective Date: August 20th, 2026