Last updated · May 2026
Privacy Policy
1. Introduction
Carelynk, Inc. (“Carelynk,” “we,” “us,” or “our”) operates the Carelynk platform, accessible at carelynk.io. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
2. Information We Collect
- Account information (name, email, role, facility)
- Usage data (pages visited, features used, timestamps)
- Care data entered by facility staff (resident information, medication records, incident reports, vitals)
- Device and browser information
3. How We Use Your Information
- To provide and maintain the Carelynk platform
- To send transactional emails (alerts, notifications)
- To improve our services
- To comply with legal obligations
- We do not sell your personal information to third parties
4. HIPAA and Protected Health Information
Carelynk operates as a Business Associate under HIPAA when processing Protected Health Information (PHI) on behalf of covered entities (RCFE operators). We maintain appropriate administrative, physical, and technical safeguards to protect PHI.
5. Data Storage and Security
- Data stored on Supabase (PostgreSQL) with encryption at rest
- All data transmitted over HTTPS/TLS
- Access controls enforced by role-based permissions
- Regular security reviews
6. Data Retention
- Active account data retained while subscription is active
- Upon cancellation, data retained for 90 days then deleted
- Backup data purged within 30 days of deletion
7. Your Rights
- Access your personal data
- Correct inaccurate information
- Request deletion (subject to legal retention requirements)
- Data portability upon request
8. Cookies
- Session cookies for authentication only
- No advertising or tracking cookies
- No third-party analytics cookies
9. Contact Us
For privacy inquiries: hello@carelynk.io