This is the plain-English privacy policy for CareTrack — the compliance-tracking platform built for North Carolina family care home operators. We wrote it for operators, not lawyers. If anything below is unclear, email us and we’ll explain (contact at the bottom of this page).
1. What CareTrack is
CareTrack helps NC family care home operators track staff credentials and training expirations, get email alerts before credentials lapse, and export compliance reports for North Carolina Department of Health and Human Services (DHSR) inspections. The service is intended for licensed North Carolina family care home operators and their administrative staff.
2. What we collect when you sign up via /caretrack/onboarding
When you create a CareTrack account through the onboarding form on /caretrack/onboarding, we collect exactly the fields shown on that form:
- Full name — the operator or administrator creating the account.
- Facility name — your NC family care home’s licensed name, so we can label your compliance calendar correctly.
- Role — Owner/Operator, Administrator, Caregiver/Staff, or Other. Used only to label your account.
- Email address — used to sign you in and send your compliance alerts and renewal reminders.
- Password — stored as a one-way cryptographic hash (never as plaintext). Only you can sign in.
We do not collect any other information at sign-up. There is no payment information collected at sign-up.
3. What we collect when you use CareTrack
After you sign up, CareTrack stores the staff and training records you enter — the data needed to track NC compliance:
- Staff names, roles, hire dates, and active/inactive status.
- Training records per staff member: training type (administrator CE, Medication Aide, CPR/First Aid, fire drill, posting check, etc.), completion date, and expiration date.
- Generated compliance reports you produce (audit exports for DHSR inspections).
Important: CareTrack is designed for staff credential tracking. It is not, and should not be used as, a system of record for resident clinical information or protected health information (PHI).
4. How we use it
We use the information above only to deliver the CareTrack service:
- Sign you in, show your account, and authenticate requests.
- Track credential expirations and send you renewal email alerts at 60, 30, and 14 days out.
- Generate the audit-export and compliance reports you request.
- Provide customer support when you contact us.
We do not sell your data. We do not share your data with third-party advertisers. We do not run behavioral advertising against your staff roster or facility data. We use no third-party tracking pixels on authenticated CareTrack pages.
5. Where it’s stored
Your account and facility data are stored in a PostgreSQL database, hosted on a managed cloud platform. Application code runs on Render, a managed-hosting provider. Authentication uses signed session tokens; passwords are stored only as one-way cryptographic hashes. All data is transmitted over HTTPS.
Transactional email (compliance reports, password-reset links, demo-request notifications) is delivered through a transactional email provider. Compliance reminder emails sent from the platform are delivered through the same email infrastructure.
6. Retention
Your account and facility data are retained while your CareTrack account is active. If you request account deletion, your facility data is removed from our active systems within 30 days of the request. Backup snapshots are purged on a normal rolling backup cadence (typically within 90 days).
Training records you choose to retain in CareTrack are governed by NC DHSR’s 5-year retention rule for staff employment and training documentation. Operators who wish to keep records longer than their CareTrack subscription can export them at any time from the dashboard as a CSV.
7. Cookies and analytics
CareTrack uses a small set of first-party cookies for authentication and analytics:
ct_sid— a first-party session cookie (HttpOnly, 1-year expiry) used to associate page views into a single visit.caretrack_token— a first-party authentication token stored in your browser when you sign in.
We also collect first-party page-view analytics on our public marketing pages (paths visited, referrer, browser user-agent). This analytics data is associated with the ct_sid cookie but is not linked to your CareTrack account unless you sign in.
We do not set any third-party advertising or cross-site tracking cookies.
8. Your choices
You can:
- Export your data at any time from your CareTrack dashboard as a CSV.
- Update your name, facility name, and role from your account settings.
- Request account deletion by emailing the contact below. Your facility data will be removed from our systems within 30 days.
9. Changes to this policy
If we make material changes to this policy, we’ll update the effective date at the top of this page and notify active CareTrack account holders by email. Continued use of CareTrack after the effective date of a change indicates acceptance of the updated policy.
10. Contact
Questions about this privacy policy, your data, or a deletion request: email support@caretrackapp.com.