1. Introduction
This Privacy Policy describes how TripFlow, Inc. ("we," "us," or "our") collects, uses, and discloses information through our SaaS platform and mobile application. We operate as a service provider to Non-Emergency Medical Transportation (NEMT) companies ("Customers") and as a Business Associate under HIPAA regulations.
2. Information We Collect
- Account Data: We collect names, email addresses, and phone numbers provided by your employer to create and manage your account.
- Mobile Messaging Data: When you use SMS-based authentication or receive an account security message, we process your mobile number, messaging consent and opt-out status, message delivery information, and related messaging records.
- Location Data: We collect precise real-time and background geographic location data. This tracking is active only while the User is marked "On Duty" within the Application to verify NEMT trip compliance.
- Protected Health Information (PHI): We process passenger names and pickup/drop-off locations solely to facilitate medical transportation at the direction of our Customers.
- Device Information: We collect device IDs, IP addresses, and operating system versions to maintain security audit logs and troubleshoot technical issues.
We use IP addresses to estimate an approximate city, region, and country for login security, session history, and detection of unusual sign-in activity. IP-based location information is approximate and may be inaccurate. This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com.
3. How We Use Information
- Service Delivery: To facilitate routing, dispatching, and trip logging for NEMT providers.
- Authentication and Account Security: To send transactional messages that you request or that are necessary to protect your account, such as one-time passcodes, two-factor authentication codes, new-device verification, password-reset codes, and security alerts. TripFlow does not use its authentication messaging program to send marketing or promotional messages.
- Compliance and Billing: To provide the "at-scene" and "drop-off" timestamps required by transportation brokers and healthcare payers.
- Platform Improvement: We may use de-identified, aggregated data to analyze and improve our routing algorithms and system performance.
- Security: To monitor for unauthorized access and maintain a HIPAA-compliant audit trail.
4. Data Sharing and Disclosure
- With Your Employer: All driver location and trip activity recorded during "On Duty" sessions is shared directly with the NEMT provider managing your account.
- Service Providers: We share data with trusted vendors that support our operations, including Amazon Web Services (AWS) for secure cloud hosting, Stripe for payment processing, and Telnyx for delivering transactional security and Customer-directed messages. These providers may use the information only to perform services for TripFlow or our Customers.
- Brokers: Trip data is exchanged with third-party brokers (e.g., ModivCare, MTM, EcoLane, TransLink) via file import/export or API integration as authorized by your employer.
- No Sale of Data: We do not sell personal data or PHI to third parties for marketing or any other purposes.
- Mobile Information and Messaging Consent: Your mobile information will not be sold or shared with third parties or affiliates for promotional or marketing purposes. Text messaging originator opt-in data and consent will not be sold, rented, or shared with any third parties for their own marketing or promotional purposes. We may disclose this information to messaging platform providers, phone companies, carriers, and other vendors only as necessary to deliver and support the messaging services you requested.
5. Data Security
We implement industry-standard security measures to protect your information, including AES-256 encryption for data at rest and TLS encryption for data in transit. Access is restricted to authorized personnel based on the principle of least privilege.
6. SMS Authentication and Provider Messaging
TripFlow's own text messaging program is limited to authentication and account security. Depending on the security options enabled for your account, messages may include one-time passcodes, two-factor authentication codes, login or new-device verification, password-reset codes, and security alerts. Message frequency varies based on your account activity. Message and data rates may apply.
By affirmatively selecting SMS authentication or requesting a code after receiving the SMS disclosure, you consent to receive the requested transactional security messages from TripFlow. Consent to receive SMS messages is not a condition of purchasing TripFlow services. You may reply STOP to opt out of messages from the sending number or HELP for help. You may also contact support@tripflownemt.com. Opting out may prevent you from using SMS as an authentication method; another available authentication method may be required to access your account. See our Terms of Use for additional SMS program terms.
NEMT providers that use TripFlow to send their own operational notifications do so under a separate messaging program using a telephone number registered to that provider. Before messaging is enabled, the provider must complete applicable 10DLC brand and campaign registration, receive approval, and associate its sending number with the approved campaign. The provider is the sender of those messages and is responsible for obtaining and honoring recipient consent, providing its own required notices, processing opt-out and help requests, and complying with applicable law and carrier requirements. A provider may not use TripFlow to send marketing or promotional text messages.
7. Your Rights and Data Retention
- Purge Policy: We retain data for the duration of the Customer's subscription plus 30 days, after which all personal data and location logs are purged from our active systems.
- Deletion Requests: Users may request the deletion of their personal data by contacting support@tripflownemt.com. Note that HIPAA-regulated trip logs may be retained as required by law.
- State Privacy Rights: We comply with applicable state privacy laws, including the California Consumer Privacy Act (CCPA) and the Minnesota Consumer Data Privacy Act (MCDPA). Residents may have specific rights regarding data portability, access, and deletion.
8. Miscellaneous Disclosures
- Children's Data: We do not knowingly collect or solicit personal information from individuals under the age of 18.
- Cookies: Our web platform uses essential cookies and tracking technologies solely to maintain user sessions and security.
- Breach Notification: In the event of a data breach involving PHI, we will notify affected Customers within 72 hours of discovery. TripFlow will coordinate with the Customer to ensure that affected individuals are notified in a reasonable timeframe as required by applicable state and federal laws.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify users of material changes by posting the updated policy on our website and, where required, through the Application or via email.