Certicare
Start my intake

Effective date: July 19, 2026

This policy explains information collected through Certicare’s public website, intake and service workflow, and communications. Medical information maintained by Certicare may also be protected by the Notice of Privacy Practices in Section 6. If the two policies differ for protected health information, the Notice of Privacy Practices and applicable law control.

5.1 Information we collect
  • Information you provide, such as name, date of birth, contact details, emergency contact information, current location, identity-verification information, structured questionnaire responses, health history, symptoms, medications, allergies, job or leave information, uploaded records, forms, follow-up messages, and communication preferences.
  • Transaction information, such as service selected, amount, payment status, refund status, and limited card-related information supplied by Stripe. Certicare does not need to store your full payment-card number.
  • Technical and usage information from public informational pages, such as browser type, device type, approximate region, referring page, pages viewed, cookie identifiers, and security logs.
  • Communications, including emails, telephone information, complaints, records requests, and separate authorizations you provide.
5.2 How we use information
  • Provide, document, coordinate, secure, and improve requested services, including clinician-reviewed asynchronous online evaluations.
  • Verify identity, age, contact and emergency contact information, and New York physical presence at the time of care; prevent fraud; collect payment; issue refunds; and respond to support or privacy requests.
  • Communicate clinical information, deliver documents, and meet legal, professional, accounting, security, and recordkeeping obligations.
  • Analyze public website performance and create de-identified or aggregated operational information that does not identify a patient.
5.3 Service providers

Certicare currently uses Stripe for payment processing and may use Google Drive, Doximity, and Proton services to store, transmit, or manage information. The platform is being updated, and vendors may change. Vendors receive only information reasonably needed for their role and are subject to contracts and legal safeguards where required. If a vendor handles protected health information for Certicare as a business associate, Certicare will require an appropriate business associate agreement before that use.

5.4 Cookies, analytics, and advertising technologies

Public informational pages may use cookies or similar tools from Google Analytics or Google Ads, Meta, Reddit, or TikTok to understand visits, measure outreach, or support advertising. These tools may receive technical identifiers and public-page activity. Certicare’s policy is to block advertising and analytics trackers from intake, upload, payment, confirmation, authenticated, and clinical pages.

Certicare may record a generic purchase-conversion event only if technical validation confirms that the event contains no name, email, phone number, form content, diagnosis, service label, URL parameter, patient identifier, or other protected health information. We do not permit an advertising vendor to receive protected health information and then de-identify it. A cookie banner or privacy policy is not authorization to disclose protected health information.

You can use browser controls and any cookie-preference tool we provide to limit nonessential cookies. Blocking cookies may affect some public-site features. Browser “do not track” signals are not interpreted consistently; we will respond to legally required opt-out signals when applicable.

5.5 When we disclose information

We may disclose information to clinicians, workforce members, and service providers who need it for treatment, operations, payment, security, or support; as directed by you in a valid authorization; to comply with law or a lawful process; to protect rights, safety, and systems; or in connection with a lawful business reorganization subject to appropriate protections. Medical disclosures are also governed by Section 6.

OUR COMMITMENT

Certicare does not sell protected health information and does not use protected health information for advertising. We do not disclose your medical request to an employer without a separate, case-specific authorization or another lawful basis.

5.6 General promotional email

Unless you opt out, and where legally permitted, Certicare may send general, non-clinical promotional emails. Commercial email will identify the sender, use an accurate subject line, include Certicare’s postal address, and provide a clear unsubscribe method. We will honor a valid marketing opt-out within 10 business days. Transactional, security, policy, records, and clinical messages may continue when needed.

Certicare will not use a diagnosis, requested service, medical document, or other protected health information to select or tailor marketing without the written authorization required by law. If the recipient list or message would itself use protected health information for marketing, we will obtain that authorization or not send the communication.

5.7 Retention

Adult medical records are retained for at least six years from the last service, or longer when another law, professional duty, contract, audit, legal hold, or safety need requires it. For each clinician-reviewed asynchronous online evaluation, the medical record retains the complete questionnaire, follow-up communications, clinical assessment, medical decision-making and reasoning, and final disposition, including any documentation, plan, referral, conversion, or direction to another care setting. Certicare does not offer deletion of information that must be retained during that period. Payment, tax, security, consent, authorization, and website records may be retained for the period reasonably necessary for their purpose and applicable law. Information no longer required is securely deleted or de-identified according to operational procedures.

5.8 Security

We use reasonable administrative, technical, and physical safeguards appropriate to the information and service. No internet, email, or storage system is completely secure. Protect your email account and device, use a strong unique password where available, and notify us promptly if you suspect unauthorized access or receive a message that appears fraudulent.

5.9 Your choices and requests

You may unsubscribe from promotional email, adjust cookie preferences where offered, and exercise medical-information rights under Section 6. Send website privacy questions and records or privacy requests to privacy@certicare.org. We may verify your identity before acting.

5.10 Adults only, changes, and contact

Certicare services are for adults age 18 and older and are not directed to children. We may update this policy prospectively and will post the new effective date. Material changes will be presented with a new intake when appropriate. Contact: Certicare, 418 Broadway, Albany, NY 12207, 518-254-8905, privacy@certicare.org.