Home
TrackDME

Privacy Policy

Last updated: June 28, 2026

1. Who We Are

TrackDME is operated by Willow Glen Equity LLC (“we,” “us,” or “our”). We provide cloud-based equipment tracking software for durable medical equipment (DME) providers and similar businesses. This policy explains what data we collect, how we use it, and your rights regarding that data.

Questions about this policy? Email us at legal@trackdme.com.

2. What We Collect

Account information: When you sign up, we collect your name, email address, and authentication credentials (managed through our authentication provider, WorkOS). We also collect your organization name and website.

Inventory and operational data: Equipment records, barcodes, serial numbers, product categories, location data, and check-in/check-out history that you create in the Service.

Customer (facility) records: Names, addresses, and contact information for the businesses and facilities you deliver equipment to. This is your business contact data, not individual patient information. We do not collect or store patient identifiers, diagnosis codes, or other protected health information.

Team members: Email addresses and role assignments for colleagues you invite to your workspace.

Product images: Photos you upload or that are imported from your website during catalog setup. These are stored in our cloud storage (Vercel Blob).

Usage data: Standard server logs, including IP addresses, browser type, pages visited, and actions taken within the Service. We use this to maintain and improve the platform.

3. How We Use Your Data

  • To provide, operate, and improve the Service.
  • To authenticate users and manage workspace access (via WorkOS).
  • To crawl your company website (at your request) to pre-populate your equipment catalog using AI.
  • To send transactional communications such as account setup confirmations and security notices.
  • To diagnose technical issues and improve reliability.
  • To comply with legal obligations.

We do not sell your data to third parties. We do not use your inventory or customer data to train AI models.

4. Third-Party Services

We use the following sub-processors to deliver the Service:

  • WorkOS — user authentication, organization management, and team invitations.
  • Neon (AWS)— PostgreSQL database hosting. Your operational data is stored in Neon’s cloud infrastructure.
  • Vercel — application hosting, image/file storage (Vercel Blob), and serverless function execution.
  • OpenAI / AI Gateway — used to analyze your website content (at your explicit request) during catalog setup. Page text is sent to the model to extract product categories; your data is not used to train OpenAI models under our business agreement.
  • Intuit QuickBooks (optional) — if you connect the QuickBooks integration, we exchange customer data between TrackDME and your QuickBooks account using OAuth tokens you authorize. You can disconnect this integration at any time.

Each of these providers has its own privacy policy and security practices. We select sub-processors that meet industry-standard security requirements.

5. A Note on HIPAA

TrackDME is designed to track equipment and facilities, not individual patients. We intentionally do not provide fields for patient names, dates of birth, diagnoses, insurance information, or other personal health identifiers.

You should not enter protected health information (PHI) into TrackDME. If your workflows require linking equipment to individual patients, that linkage should be managed in your existing EHR or patient management system, which is subject to your own HIPAA obligations.

TrackDME is not a HIPAA Business Associate and does not execute Business Associate Agreements (BAAs) at this time.

6. Data Retention

We retain your data for as long as your account is active. If you cancel your account, your data remains available for export for 30 days and is then permanently deleted from our systems.

Certain data (such as authentication logs and billing records) may be retained for longer periods as required by law.

7. Security

We use industry-standard measures to protect your data, including encryption in transit (TLS) and at rest, access controls, and regular security reviews. However, no system is completely secure. We encourage you to use a strong, unique password and enable multi-factor authentication.

If you discover a security vulnerability, please report it responsibly to legal@trackdme.com.

8. Your Rights

You have the right to access, correct, export, or delete your data. Most of this can be done directly within the Service. To request account deletion or a full data export, email us at legal@trackdme.com.

California residents have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we have collected and the right to request deletion. We do not sell personal information.

9. Cookies

We use cookies and similar technologies to maintain your session and preferences. We do not use advertising or tracking cookies. You can configure your browser to refuse cookies, but doing so may prevent the Service from functioning correctly.

10. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes via email or through the Service. Continued use of the Service after the effective date of any changes constitutes acceptance of the updated policy.

11. Contact

For privacy-related questions or requests, contact us at legal@trackdme.com.