Privacy Policy
How CareVerify handles information, written to be read rather than skimmed past.
Last updated 2 August 2026
Who we are
In short: CareVerify is a product of Insync Agency LLC, a company registered in Wyoming, United States.
CareVerify is visit verification, scheduling and payroll export software for home care agencies. This policy covers the marketing website at getcareverify.com and the application at app.getcareverify.com.
Two different relationships run through this policy, and the difference matters. When you visit our website or sign up, we are the controller of your information. When your agency uses the application to record visits for your clients, your agency is the controller and we act on your instructions. Under HIPAA those roles are called covered entity and business associate.
What we collect from the marketing website
In short: Very little. A name, an agency name, an email and a phone number if you choose to give them.
Forms on this website collect only what is needed to reply to you: a name, an agency name, an email address and a phone number. We do not ask for client information on this website, and you should never send it to us through a web form or by email.
We also collect ordinary website analytics through Google Tag Manager, covered in our cookie policy. That includes pages viewed, approximate location derived from IP address, referring site, and browser and device type.
What the application collects
In short: The records your agency enters, plus the time and location captured at each visit check-in.
Accounts and access:
- Names, email addresses, phone numbers and roles of your staff
- Authentication records, including sign-in times and devices
- An audit record of every access to a client record
Operational records your agency enters:
- Client names, addresses, care plans and service authorizations
- Caregiver records, availability and certification expiry dates
- Scheduled and completed visits, including tasks and notes
- Time and geographic location captured when a caregiver checks in and out, which is the evidence that makes a visit record defensible
Client names recorded against care visits are protected health information. We handle that information only to provide the service to your agency, never for our own purposes, and never to train models or build profiles.
Location data
In short: Captured at check-in and check-out only. We do not track caregivers between visits.
The caregiver app captures location at the moment of check-in and check-out. It does not run continuous background tracking and it does not record a caregiver's movements between visits. If a caregiver denies location permission or the device cannot get a fix, the check-in still records and is flagged for the office to review.
What we never do
In short: No selling, no advertising, no sharing your records with other customers.
- We do not sell personal information, and we never have
- We do not share your data with other customers. Each agency's records are isolated at the database layer
- We do not use client or visit information to train machine learning models
- We do not run advertising networks on the application
Who we share information with
In short: Only the vendors that run the service, each under contract, listed publicly.
We use third-party services to operate CareVerify. Every one that may touch protected health information does so under a business associate agreement. The full list, what each does and whether it touches PHI, is on our subprocessors page.
We may also disclose information where the law requires it, for example in response to a valid legal request. If that happens we will tell the affected customer unless we are legally prohibited from doing so.
Where your data is stored and accessed
In short: Stored in the United States, and accessed by our team from the United States.
Application data is stored on infrastructure located in the United States. Insync Agency LLC is a US company and our staff access customer data from within the United States when providing support, investigating a fault or maintaining the service. Access is role-restricted and logged.
We state this plainly rather than bury it, because it is a reasonable question for an agency handling protected health information to ask before signing. If we ever add staff or infrastructure outside the United States, we will update this section and tell account administrators before it takes effect.
Some of our subprocessors operate internationally. Where that is the case it is noted in the location column of that page.
Your rights in California
In short: You can ask what we hold, ask for a copy, ask us to correct or delete it, and we will not treat you differently for asking.
Under the California Consumer Privacy Act as amended by the California Privacy Rights Act, California residents may request access to the personal information we hold, a portable copy of it, correction of inaccurate information, and deletion. You may also limit the use of sensitive personal information.
We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of on that front. We will not deny service, charge a different price or provide a lower quality of service because you exercised a right.
Your rights in other states
In short: Comparable rights apply in a growing number of states, and we apply the same process to all of them.
Residents of states with comprehensive privacy laws now in effect, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana among others, have comparable rights of access, correction, deletion and portability, and may appeal a refused request.
Rather than run a different process per state, we apply the same one everywhere. Ask us and we will handle it.
How to exercise a right
In short: Email privacy@getcareverify.com. We respond within 45 days.
Email privacy@getcareverify.com and tell us what you want. We will verify your identity before acting, because acting on an unverified request would itself be a privacy failure.
One important limit. If you are a client or caregiver of an agency that uses CareVerify, your records belong to that agency, not to us. We will pass your request to them and support them in answering it, but we cannot delete an agency's records on the request of someone other than the agency.
How long we keep information
In short: Records stay available for export for 30 days after cancellation and are deleted within 60 days after that.
Home care records carry multi-year obligations, so we do not delete data the moment an account closes. The full schedule is in our data retention policy.
Security
In short: Encryption in transit and at rest, tenant isolation at the database layer, and an audit log of every access to a client record.
Our security page describes the controls in concrete terms. No system is perfectly secure, and we would rather describe what we actually do than claim certifications we do not hold.
Children
In short: The service is not for children and we do not knowingly collect their information directly.
CareVerify is business software sold to home care agencies. We do not knowingly collect information directly from children. Where an agency records care for a minor client, that information is handled as part of the agency's records under their instructions.
Changes to this policy
In short: We will tell you before a material change takes effect, not after.
If we make a change that materially affects how we handle your information, we will email account administrators at least 30 days before it takes effect. The date at the top of this page always reflects the current version.
Contact
In short: Email privacy@getcareverify.com and a person will reply.
Insync Agency LLC, Wyoming, United States. privacy@getcareverify.com
ATTORNEY REVIEW: registered address, state of registration and company registration number to be inserted.
Other policies: Privacy, Terms, BAA, Subprocessors, Data retention, Cookies, Acceptable use, Accessibility, Refunds
