VisitOpts

Privacy Policy

Last updated: August 20, 2026

VisitOpts (“VisitOpts,” “we,” “us”) provides Electronic Visit Verification (EVV) and Medicaid-claims software for home-care agencies in Minnesota. This Privacy Policy explains what information we collect through our website, mobile applications, and platform (the “Services”), how we use and share it, and the choices you have.

Much of the information in the Services is Protected Health Information (PHI) that we process on behalf of home-care agencies. For that information we act as a Business Associate under HIPAA, and our handling of it is governed by our Business Associate Agreement (BAA) with each agency and by our HIPAA Notice. Where this Policy and a BAA conflict as to PHI, the BAA controls.

Contents

  1. Information we collect
  2. How we use information
  3. Location data
  4. How we share information
  5. Data retention
  6. Security
  7. Your choices & rights
  8. Children
  9. Changes
  10. Contact us

1. Information we collect

Agency and user account information

When an agency signs up or we create user accounts, we collect names, email addresses, phone numbers, roles, and login credentials for agency administrators and staff.

Caregiver (employee) information

To register caregivers for EVV and payroll, we collect and store caregiver names, email addresses, phone numbers, home address, date of birth, hire date, and Social Security number, along with training/compliance records. This information is required by the state EVV program and is treated as sensitive.

Client (member) information — PHI

On behalf of agencies, the Services store information about the clients (members) who receive care, including names, dates of birth, Medicaid identifiers, home addresses, emergency contacts, authorized services and hours, care notes, and visit records (clock-in/out times, service codes, and verification status). This is PHI.

Location information

When a caregiver clocks in or out of a visit in the mobile app, we collect the device’s GPS location at that moment to verify that the visit occurred at the client’s home, as required for EVV. See “Location data” below.

Payment information

Agency subscription payments are processed by our payment provider (Stripe). We do not store full card or bank-account numbers on our servers; that data is handled by the provider on its secure systems. We retain limited billing metadata (plan, status, last-four, invoices).

Device, log, and usage information

We automatically collect standard technical data such as IP address, device and browser type, app version, and timestamps of actions, used for security, troubleshooting, and audit logging.

2. How we use information

We do not sell personal information, and we do not use PHI for advertising.

3. Location data

The caregiver mobile app collects precise GPS location only at the moment of clock-in and clock-out for a visit — not continuously, and not in the background between visits. The location is used to confirm the visit took place at the client’s address, which is a core requirement of Electronic Visit Verification. The app requests location permission from the caregiver’s device; if permission is denied, EVV verification for that visit may not be possible.

4. How we share information

We share information only as needed to provide the Services and operate our business:

We do not sell or rent personal information or PHI to third parties.

5. Data retention

We retain information for as long as an agency maintains an account and as required to provide the Services and to meet Medicaid record-keeping, EVV, tax, and legal obligations, which may require retaining visit and claim records for multiple years. When retention is no longer required, we delete or de-identify the information. Retention and return/destruction of PHI on termination are governed by the applicable BAA.

6. Security

We protect information with administrative, technical, and physical safeguards, including encryption of data in transit (TLS) and at rest, tenant isolation so each agency can only access its own data, role-based access controls, audit logging of privileged actions, and hosting on HIPAA-eligible AWS infrastructure. No method of transmission or storage is completely secure, but we work to protect information consistent with HIPAA and industry practice.

7. Your choices & rights

Because much of the data is PHI held on behalf of agencies, requests to access, correct, or delete client records should be directed to the agency (the covered entity); we will assist agencies in responding. Agency users can update their own profile information in the app, and caregivers can update certain profile details or request changes through their agency. To exercise choices or ask a privacy question, contact us at info@visitopts.com.

8. Children

The Services are intended for use by home-care agencies and their staff, not by children, and are not directed to children under 13. We do not knowingly collect personal information directly from children. Where a client receiving care is a minor, their information is provided and managed by the agency as PHI under HIPAA.

9. Changes to this Policy

We may update this Policy from time to time. We will post the updated version here with a new “Last updated” date, and material changes will be communicated as appropriate.

10. Contact us

VisitOpts
151 Silver Lake Rd, Unit 2, New Brighton, MN 55112
Email: info@visitopts.com
Phone: +1 (612) 366-0002