1. Scope of this policy
This policy covers Elevate IV Solutions ("we," "us," "our") and applies to elevateivsolutions.com, our client and provider mobile apps, our booking and contact forms, our text and email communications, and the information our nurses collect during a visit.
Your health information gets stronger protection than everything else here. Section 5 and our HIPAA Notice of Privacy Practices cover that specifically, and where the two documents differ, the HIPAA notice controls for health information.
2. Information we collect
| Category | Examples | Why |
|---|---|---|
| Identity & contact | Name, email, phone number, service address | To schedule, reach you, and get a nurse to the right door |
| Health information | Medical history, medications, allergies, pregnancy status, Good Faith Exam answers, treatment notes, consent signature | To determine whether treatment is safe and to document care |
| Appointment | Services selected, add-ons, date and window, visit history, nurse assigned | To deliver and record your care |
| Payment | Last four digits and card brand, amount, receipt, membership and credit balances | To charge for services and maintain your balance |
| Location | Service address geocode; live nurse location while en route | To route the nurse and show you an accurate ETA |
| Communications | Chat messages, form submissions, texts, emails, call notes | To answer you and keep a record of what was said |
| Content you submit | Reviews, testimonials, photos you share | To publish with your permission |
| Device & usage | Device type, OS version, app version, pages viewed, push token, crash logs | To keep the apps working and fix problems |
We never store your full card number. Card data goes directly to our PCI-compliant payment processor. What reaches our systems is a token, the last four digits, and the amount.
3. Where the information comes from
- From you — booking forms, intake, chat, phone calls, reviews, and account settings
- Automatically — device and usage data when you browse the site or use the apps
- From your nurse — clinical observations and treatment notes recorded during your visit
- From service providers — payment confirmations from our processor, and delivery status from our messaging providers
4. How we use your information
- Schedule, route, and deliver your appointment, and send arrival ETAs and tracking
- Screen for safety and document the Good Faith Exam and treatment
- Process payments, tips, memberships, credits, gift cards, and referral rewards
- Respond to your questions through chat, text, email, or phone
- Maintain your visit history so a future nurse knows your background
- Improve our services, menu, and apps, and diagnose technical problems
- Send marketing offers only if you opted in, and honor opt-outs promptly
- Publish a review or photo you submitted, with the attribution you chose
- Meet legal, licensing, tax, and clinical recordkeeping obligations
We do not use your health information to target advertising, and we do not build advertising profiles about you.
5. Health information & HIPAA
Health information you give us in connection with treatment is protected health information (PHI) and is handled under HIPAA. That means it is accessible only to the clinical and administrative staff who need it for your care, it is encrypted in our systems, and it is never disclosed for marketing without your written authorization.
Your full rights over that information — access, amendment, an accounting of disclosures, restriction requests, and how to file a complaint — are described in our HIPAA Notice of Privacy Practices.
6. When we share information
We share your information only in these situations:
- With your care team — the nurse assigned to your visit and our supervising physician, so they can treat you safely.
- With service providers — the vendors listed in section 7, who process data on our behalf under contract, and who may not use it for their own purposes.
- With your direction — if you ask us to send records to your physician, or you publish a review.
- For legal reasons — to comply with a subpoena, court order, licensing board request, or public health reporting requirement, or to protect someone from serious harm.
- In a business transfer — if the practice is sold or merged, your information would move with it, subject to this policy and HIPAA.
7. Service providers we use
| Provider | Purpose | What they receive |
|---|---|---|
| Stripe | Payment processing | Card data, amount, contact for the receipt |
| GoHighLevel | CRM, scheduling, chat, and messaging | Contact details, appointment records, conversations |
| Twilio | SMS delivery | Phone number and message content |
| Cloudflare | Website hosting, database, and security | Site and application data, request logs |
| Apple & Google | App distribution and push notifications | Device push token and notification content |
| Mapping & routing services | Address geocoding and ETAs | Service address and coordinates |
Each provider that handles PHI does so under a Business Associate Agreement requiring HIPAA-level safeguards.
8. We do not sell your data
We do not sell, rent, or trade your personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the past twelve months and have no plans to start.
9. Cookies & analytics
Our website uses cookies that are necessary for it to function — keeping your cart, remembering your session, and keeping the admin area secure — plus Google Tag Manager and Google Analytics 4, which tell us which pages people visit, which buttons they tap (call, book, app download), and when a booking, contact form, or checkout starts, so we can improve the site and measure advertising.
You can block or delete cookies in your browser settings. Blocking necessary cookies will break booking and cart functionality. We honor Global Privacy Control signals where your browser sends them.
10. Email, SMS & push notifications
Transactional messages — booking confirmations, arrival ETAs, messages from your nurse, and receipts — are part of the service you requested and are sent when you have an active appointment.
Marketing messages require your opt-in. Reply STOP to any marketing text or use the unsubscribe link in any email to stop them. Push notifications can be turned off in your phone's system settings at any time.
Message and data rates may apply. We do not share your phone number with third parties for their own marketing.
11. Mobile app data & permissions
Our apps ask for these permissions, all of which are optional and can be revoked in your device settings:
- Notifications — to tell you when your nurse is on the way and when she arrives
- Location — to prefill your service address and, for nurses, to power live tracking during an active visit only
- Camera and photos — only if you choose to attach a photo to a review or a message
The provider app collects a nurse's location only while she is en route to or on an active visit, and we do not track staff outside of working visits.
The apps contain no third-party advertising SDKs and no cross-app tracking.
12. How we protect your data
- Everything travels over TLS-encrypted connections
- Sensitive health fields are encrypted at rest with per-field encryption
- Access is role-based — staff see only what their role requires
- Administrative accounts require authentication and are logged
- Staff complete HIPAA training and sign confidentiality agreements
- Payment card data never touches our servers
No system is perfectly secure. If a breach affects your information, we will notify you as required by HIPAA and Arizona law.
13. How long we keep information
| Type | Retention |
|---|---|
| Clinical and treatment records | At least 6 years, per Arizona medical record requirements |
| Payment and tax records | 7 years |
| Marketing contact preferences | Until you opt out, then a suppression record so we don't re-add you |
| Chat and support conversations | 2 years |
| Analytics and device logs | Up to 12 months |
14. Your privacy rights
Regardless of where you live, you can ask us to:
- Access the personal information we hold about you
- Correct anything that is inaccurate
- Delete information we are not legally required to retain
- Port a copy of your data in a portable format
- Opt out of marketing at any time
- Restrict certain uses or disclosures of your health information
Email jennifer@elevateivsolutions.com or call (480) 392-8827. We verify your identity before acting, respond within 30 days, and never charge or retaliate for a request. Note that clinical records subject to a legal retention period cannot be deleted until that period lapses.
15. Children's privacy
Our services are directed to adults. We do not knowingly collect information from anyone under 13 online. Minors may be treated only with a parent or guardian present and consenting, and any resulting record is handled as the guardian's to access. If you believe a child provided us information online, contact us and we will delete it.
16. Changes to this policy
We will update this policy as our practices or the law change. The effective date at the top always reflects the current version, and we will post material changes here before they take effect.
Contact us
If anything in this document is unclear, or you want to exercise a right described above, reach out and a real person will answer.
- Elevate IV Solutions
- 1525 S Higley Rd. Suite 104 PMB 1022
- Gilbert, AZ 85296
- (480) 392-8827
- jennifer@elevateivsolutions.com