Legal
Privacy Policy
Last updated: June 2026
Scope of this policy
This Privacy Policy explains how Trustora, Inc. ("Trustora," "we") handles information when you visit our website or use our platform. It does not cover Protected Health Information (PHI) that an agency uploads under a Business Associate Agreement, which is governed separately as described below.
Information we collect
- Account data: name, work email, phone, role, and agency details.
- Usage data: pages visited, features used, and actions taken in the platform.
- Device and log data: browser, operating system, and IP address, used for security.
- Billing data: handled by our payment processor; we do not store full card numbers.
- Communications: messages you send us for support, sales, or onboarding.
How we use information
To provide and secure the platform, set up and support your agency, process billing, improve our product, send service and account messages, and meet legal obligations. We do not use your information for cross-context behavioral advertising.
Protected Health Information (PHI)
The standard practices in this policy do not apply to PHI uploaded by an agency that has signed our Business Associate Agreement (BAA). For that PHI, the BAA and HIPAA govern. No PHI may be uploaded until a BAA is in place. Trustora will never sell PHI or use PHI for marketing.
How we share information
We share information only with the service providers (subprocessors) that help us run the platform, when required by law or valid legal process, and in connection with a business transfer in which the acquirer agrees to honor this policy. We do not sell, rent, or trade personal data.
Service providers (subprocessors)
We use Amazon Web Services (HIPAA-eligible infrastructure), Stripe (billing), and providers for transactional email and SMS one-time codes and for geolocation-based login security. Each is bound by contract to protect the information they handle for us.
Data retention
We keep account and usage data for as long as your agency uses Trustora and as needed to meet legal, security, and recordkeeping obligations. PHI retention follows the BAA and applicable Minnesota and federal recordkeeping requirements. You can request export or deletion as described below.
Data security
We encrypt data in transit (TLS 1.3) and at rest (AES-256), require a one-time code on every login, isolate each agency's data, restrict access by role, and keep an append-only audit log. No system is perfectly secure, but security is built into how the platform works.
Your rights and choices
You may request access to, correction of, or deletion of your personal data, and you may opt out of non-essential communications. Depending on where you live, you may have additional rights under state privacy laws. To make a request, contact us using the details below.
Cookies
We use essential cookies only, for authentication and preferences. We do not use advertising cookies or cross-site tracking.
Children's privacy
Trustora is a workforce tool for care agencies and is not directed to children. We do not knowingly collect personal information directly from children through the website.
Where data is processed
Trustora is operated in the United States, and information is processed and stored in the United States.
Changes to this policy
We may update this policy as the product and the law evolve. Material changes will be posted here with an updated date.
Contact
For privacy questions, data export, or deletion requests, contact support@trustora.com.
This document is provided for transparency and should be reviewed by a qualified healthcare attorney before publication.