LEGAL
Reptrac LLC ("Reptrac," "we," "us," or "our") provides RepTracPro, a field-sales and territory-relationship platform delivered through our website at reptrac.com (the "Site"), our web application, and our mobile apps (together, the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have.
This policy covers two kinds of relationships:
Visitors and prospects who use our Site (for example, to request a demo).
Customers and their users — organizations that subscribe to RepTracPro, and the reps, managers, and admins who use it.
For much of the information processed inside RepTracPro, our customer (the organization that subscribes) decides what data is entered and why. In those cases the customer is the "controller" of that data and Reptrac acts as a "processor" — and, where applicable, a HIPAA "business associate" — that handles the data on the customer's behalf under our customer agreement. If you are a rep, manager, patient, or referral contact with a question about data held in a specific organization's account, please contact that organization directly. See HIPAA and Protected Health Information below.
The short version
We collect what we need to run the Service and to respond to you. We do not sell personal information.
Inside the product, customers enter data about their reps, the clinics/accounts they visit, and referrals. Some referral records include a patient's or prospect's name and contact details.
We do not collect or store medical records, diagnoses, or clinical notes.
We encrypt data in transit and at rest and isolate each customer's data.
Where a customer's use of RepTracPro involves protected health information (PHI), we will enter into a Business Associate Agreement (BAA) and protect that information alongside our customer.
Information we collect
1. Information you provide to us
Demo and contact requests (Site): your name, work email, company, team size, and anything you write in the message field.
Account and profile: name, email, optional phone number, role, the organization and territories you belong to, and your password (stored only as a salted hash) or your Google sign-in identifier.
Support and communications: messages you send us and their contents.
2. Information created when you use RepTracPro
Customers and their users enter and generate operational data, including:
Activities: visits, calls, lunch-and-learns, drop-offs, emails, and similar — with timestamps, the rep, the account, and any notes.
Clinics/accounts and contacts: business names, addresses, contact people, phone numbers, priority levels, and rotation schedules.
Referrals: referral type, status, estimated value, and patient or prospect identifiers such as a name and contact details that a rep or a connected intake form provides.
Schedules, assignments, dashboards, and reports generated from the above.
We treat patient and prospect identifiers as sensitive information. We do not collect diagnoses, treatment information, or clinical records.
3. Information collected automatically
Device and log data: IP address, browser/app type and version, device identifiers, screens or pages viewed, and timestamps.
Cookies and analytics: we use cookies to keep you signed in and to remember preferences, and we use Google Analytics to understand how visitors use our Site. Google Analytics sets cookies and collects information such as your IP address, device and browser type, and pages viewed; that information is processed by Google as described in Google's Privacy Policy. You can opt out of Google Analytics using Google's opt-out browser add-on. Because we use cookie-based analytics, we present a cookie-consent banner where required, and you can manage non-essential cookies through it.
Biometric sign-in (Face ID / Touch ID) is handled entirely on your device by Apple or Google. We never receive your biometric data.
4. Information from third parties and integrations
Authentication: if you sign in with Google, we receive basic profile information from Google to create your session.
Intake-form integrations (e.g., JotForm): when a customer connects a public referral form, the referral details submitted on that form — which may include a patient's or prospect's name and contact information — are sent to RepTracPro through a secure webhook and stored in that customer's account.
How we use information
We use information to:
provide, operate, secure, and improve the Service;
create and manage accounts and authenticate users;
respond to demo requests, support questions, and other communications;
generate dashboards, reports, and exports for customers;
monitor for fraud, abuse, and security incidents; and
comply with our legal obligations.
We do not sell personal information, and we do not use the operational data customers enter into RepTracPro for advertising.
How we share information
We share information only as needed to run the Service:
Within your organization: data entered in a customer's account is available to authorized users of that customer, according to the roles and permissions the customer configures.
Service providers (subprocessors) who host and support the Service under contract, including Supabase (database, authentication, storage), Vercel (application hosting), Resend (transactional email), and Google (Google Analytics, and Google Sign-In where used). These providers may process data only on our instructions.
Legal and safety: when required by law, to enforce our terms, or to protect rights, safety, and security.
Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this policy.
Where a BAA is in place, our handling and disclosure of PHI is further limited by that BAA.
HIPAA and Protected Health Information
RepTracPro tracks relationships, visits, and referrals — not medical records. We do not collect or store diagnoses, treatment details, or clinical notes. However, the identifiers a customer enters with a referral (for example, a patient's name and contact information) can constitute protected health information ("PHI") under the U.S. Health Insurance Portability and Accountability Act ("HIPAA") when the customer is a covered entity or a business associate.
Today, RepTracPro is used primarily within our own affiliated clinics. As we make clinic-specific referral links and intake forms available to additional customers, those forms may capture patient referral information. Accordingly:
A BAA is available. Where a customer's use of RepTracPro involves PHI, Reptrac LLC will enter into a Business Associate Agreement (BAA) with that customer and will act as the customer's business associate with respect to that PHI. Contact [email protected] to request a BAA.
What we commit to. Under a BAA, we protect PHI as required by HIPAA: we encrypt it in transit and at rest, restrict and log access, isolate each customer's data, use it only to provide the Service, and notify the customer of a breach as the BAA requires.
Shared responsibility. HIPAA compliance is shared. We provide a secure, BAA-backed platform; the customer remains responsible for its own HIPAA obligations — including having the right and any necessary authorizations to collect and enter patient information, deciding what to record, training its users, and managing who has access.
If a BAA conflicts with this policy, the BAA controls with respect to PHI.
We do not claim to be "HIPAA certified" (no such government certification exists). Our commitment is the concrete protection described here and in any BAA.
Data retention
We retain personal information for as long as an account is active and as needed to provide the Service, then delete or de-identify it within 90 days after an account is closed — unless a longer period is required by law or by a customer agreement or BAA. Customers may request export or deletion of their data as described in their agreement.
Security
We use administrative, technical, and physical safeguards designed to protect information, including TLS encryption in transit, encryption at rest in our managed PostgreSQL database, row-level security to isolate each customer's data, role-based access controls, and least-privilege access for our team. No system is perfectly secure, but we work to protect your information and to strengthen our safeguards over time.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, or to object to or restrict certain processing.
Visitors/prospects: contact [email protected] to exercise these rights for information you gave us directly.
Data inside a customer's account (including patients and referral contacts): because the customer controls that data, please direct your request to the relevant organization; we will support our customer in responding.
We will not discriminate against you for exercising these rights.
Children's privacy
The Service is intended for business use and is not directed to children. We do not knowingly collect personal information directly from children. A customer may, in the course of a referral, enter information about an individual who is a minor; the customer is responsible for having the authority and any consents required to do so.
International users
We operate in the United States and process and store information there. If you access the Service from outside the United States, you understand your information will be processed in the U.S. For visitors in the EEA/UK, our legal bases for processing include performance of a contract, our legitimate interests in operating the Service, your consent (where requested), and compliance with legal obligations.
Changes to this policy
We may update this policy from time to time. We will post the updated version here, revise the "Last updated" date, and, where appropriate, provide additional notice.
Contact us
Reptrac LLC 6021 Fairmont Pkwy, Suite 250 Pasadena, TX 77505 Email: [email protected]