Skip to content
TargetFlo — ABA therapy center operations software

Legal

Privacy Policy

Effective date: [Effective date] · Last updated: [Effective date]

Template notice. This privacy policy is a structured placeholder for TargetFlo and must be reviewed and finalized by legal counsel before publication. Bracketed items are to be completed.

TargetFlo (“TargetFlo,” “we,” “us,” or “our”) provides operations software for ABA therapy centers. This Privacy Policy explains how we collect, use, and share information when you visit https://targetflo.com (the “Site”) and when customers use the TargetFlo application (the “Service”).

1. Scope of this policy

This policy applies to two distinct audiences, and the rules differ for each:

  • Website visitors — people who browse the marketing Site, read the blog, or submit the contact or demo form.
  • Customers and authorized users — ABA organizations that subscribe to the Service and the staff, external providers, and parents or guardians those organizations invite to use it.

Protected health information (“PHI”) processed inside the Service on behalf of a customer is governed by the Business Associate Agreement (“BAA”) between TargetFlo and that customer, not by this policy alone. See Section 5 and our HIPAA notice.

2. Information we collect

2.1 From website visitors

  • Information you provide. When you submit the contact or demo form we collect your name, work email address, organization, number of locations, and the message you write. We ask you not to include PHI in these forms.
  • Usage information. Standard server logs and analytics may record your IP address, browser type, device, pages viewed, referring URL, and timestamps.

2.2 From customers and authorized users

  • Account information. Names, work email addresses, roles, location assignments, and authentication data for staff and administrators.
  • Customer data. Referral, client, guardian, insurance, document, task, training, and communications records that a customer enters into or connects to the Service — including data received from integrations such as fax providers, Google Workspace, and eligibility clearinghouses. Much of this is PHI and is handled under the BAA.
  • Service usage and audit data. Log-in events, record access, changes, and other activity captured in audit trails to support security and compliance.

3. How we use information

We use information to:

  • Respond to inquiries and demo requests and communicate with prospective customers.
  • Provide, operate, secure, and support the Service for customers.
  • Maintain audit trails, detect misuse, and meet security and legal obligations.
  • Understand how the Site is used so we can improve content and performance.
  • Send product updates and marketing about TargetFlo, from which you may opt out at any time.

We do not use customer PHI to train artificial-intelligence models. AI features in the Service (such as OCR and compose assist) process documents to perform the requested function for the customer; the planned MCP assistant is limited to non-PHI operational aggregates.

4. Cookies and analytics

The Site uses strictly necessary cookies (for example, to remember your light or dark theme preference) and may use privacy-respecting analytics to measure page views and traffic sources. [Describe analytics provider, cookie categories, and consent mechanism, if any.] You can control cookies through your browser settings; disabling cookies may affect some Site functionality.

The Service uses session cookies required for authentication and security. These are not used for advertising.

5. Protected health information

The marketing Site is not designed to receive PHI. Do not submit client names, dates of birth, diagnoses, insurance identifiers, or referral documents through Site forms or email.

Within the Service, TargetFlo acts as a business associate of its customers, who are covered entities or business associates under HIPAA. PHI is processed only as permitted by the applicable BAA and the customer’s instructions. TargetFlo’s architecture isolates PHI in a dedicated schema, applies role-based access controls and audit logging, encrypts data in transit and at rest, and enforces a PHI guard on SMS messaging. Details are described on the Security & Compliance and HIPAA pages.

6. How we share information

We do not sell personal information. We share information only:

  • With service providers that host, store, deliver email for, or otherwise support the Site and Service under contractual confidentiality and, where PHI is involved, subcontractor BAAs. [List categories or providers, e.g., cloud hosting, email delivery, error monitoring.]
  • With integrations you connect. When a customer connects a fax provider, Google Workspace, or an eligibility clearinghouse, data flows to and from that provider as directed by the customer.
  • For legal reasons, when required by law, subpoena, or to protect the rights, safety, or property of TargetFlo, our customers, or others.
  • In a business transfer, such as a merger or acquisition, subject to the commitments in this policy and any applicable BAA.

7. Data retention

Website inquiry data is retained for as long as needed to respond and for a reasonable period afterward for follow-up, unless you ask us to delete it. Customer data is retained for the duration of the subscription and returned or destroyed in accordance with the customer agreement and BAA after termination. [Specify retention periods and post-termination export window.] Audit logs may be retained longer where required for security or legal compliance.

8. Security

We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption in transit and at rest, role-based access, audit trails, and separation of PHI from operational data. No system is perfectly secure; if we become aware of a security incident affecting your information we will notify affected customers as described in the BAA and applicable law.

9. Your rights and choices

  • Access, correction, and deletion. You may request access to, correction of, or deletion of personal information we hold about you as a website visitor by contacting us at hello@targetflo.com.
  • Marketing opt-out. Use the unsubscribe link in any marketing email or contact us.
  • Authorized users and patients. If you are a staff member, parent, or guardian using the Service through an ABA organization, please direct requests about your information to that organization. TargetFlo will support the customer in responding as required by the BAA.
  • [Add jurisdiction-specific rights, e.g., state privacy laws, where applicable.]

10. Children

The Site is not directed to children and we do not knowingly collect personal information from children through the Site. Information about minors receiving ABA services is entered into the Service by customers and their authorized users and is handled as PHI under the BAA.

11. Changes to this policy

We may update this policy from time to time. We will post the revised version on this page with a new effective date and, for material changes affecting customers, provide notice as required by the customer agreement.

12. Contact

Questions about this policy or our privacy practices: hello@targetflo.com, or use the contact page. [Add mailing address.]


Related: Terms of Service · HIPAA Notice & BAA · Security & Compliance