Skip to content
VisitWeave
  • Product
  • Who it's for
  • Company
  • Contact

Legal

Privacy Policy

Version
1.0
Last updated
August 12, 2026
Provider
Tawny Dog Software, LLC, doing business as VisitWeave
Provider address
7901 4th St N #34331, St. Petersburg, FL 33702
Privacy contact
support@visitweave.com
Important: Do not send patient information or other Protected Health Information to support@visitweave.com or any other VisitWeave email address.

This Privacy Policy explains how Tawny Dog Software, LLC, doing business as VisitWeave ("VisitWeave," "we," "us," or "our"), collects, uses, discloses, and retains personal information when people visit our website, create or use a VisitWeave account, communicate with us, or otherwise interact with VisitWeave.

VisitWeave is a business-to-business healthcare operations service. Healthcare organizations use VisitWeave for referral staffing and visit scheduling. This Privacy Policy distinguishes between information VisitWeave handles for its own business purposes and information VisitWeave processes for a healthcare customer.

1. Scope and Our Roles

1.1 Information Covered by This Privacy Policy

This Privacy Policy primarily covers personal information that VisitWeave controls for its own business purposes, including:

  • account and profile information;
  • organization and professional contact information;
  • authentication and security information;
  • website, device, and service-usage information;
  • support and business communications;
  • subscription, invoice, and transaction information, if applicable; and
  • legal-document and acceptance records.

1.2 Customer Data and Protected Health Information

When a healthcare organization uses VisitWeave, VisitWeave processes Customer Data on that organization's behalf. Customer Data may include Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA").

For Customer PHI, VisitWeave generally acts as a HIPAA Business Associate or Subcontractor Business Associate, and the VisitWeave Business Associate Agreement ("BAA") governs our handling of that PHI. The healthcare organization controls why the information is collected, which users may access it, and how it is used within the Service.

1.3 This Is Not a HIPAA Notice of Privacy Practices

This Privacy Policy is not a healthcare provider's or health plan's HIPAA Notice of Privacy Practices.

1.4 Customer Privacy Practices

This Privacy Policy does not govern a Customer's own collection, use, or disclosure of information. Customers are responsible for their own privacy notices, HIPAA notices, consents, authorizations, and practices. An Authorized User should direct questions about the Customer's practices to the Customer's privacy or security contact.

2. Personal Information We Collect

The information we collect depends on how you interact with VisitWeave.

2.1 Account and Contact Information

We may collect:

  • name;
  • business email address;
  • telephone number, if provided;
  • job title, professional role, and organization;
  • account display name and profile settings;
  • organization membership and role;
  • legal, billing, privacy, and security contact information; and
  • communication preferences.

2.2 Authentication and Account-Security Information

We may collect or generate:

  • password hashes and authentication-provider identifiers;
  • session tokens and cookie identifiers;
  • passkey public credentials and authentication assertions;
  • two-factor-authentication status and related security metadata;
  • email-verification and password-reset records;
  • invitation and membership records;
  • login dates, source IP addresses, and security events; and
  • account recovery and fraud-prevention information.

A device may use a fingerprint, face scan, or other biometric method to unlock a passkey. That biometric template is generally controlled by the device or operating-system provider; VisitWeave receives an authentication result, not the device's biometric template.

2.3 Organization and Professional Information

During organization onboarding and administration, we may collect:

  • legal entity name and entity type;
  • principal state and business address;
  • organization name and workspace configuration;
  • whether the organization acts as a HIPAA Covered Entity or Business Associate;
  • service states and required addenda;
  • privacy, security, legal, and billing contacts;
  • workforce roles and permissions; and
  • records showing acceptance of Terms, the BAA, and other agreements.

2.4 Commercial and Billing Information

If applicable to the subscription, we may collect:

  • selected plan and licensed features;
  • invoice and payment status;
  • billing contact and billing address;
  • transaction identifiers;
  • tax-exemption information; and
  • records of quotes, orders, renewals, cancellations, and refunds.

If a payment provider processes card or bank information, its notice applies to the information it receives. VisitWeave will identify a payment provider at checkout or in the authenticated Subprocessor information before using that provider.

2.5 Device, Network, and Usage Information

We may automatically collect:

  • IP address;
  • browser, device, and operating-system type;
  • application version;
  • language and time-zone settings;
  • request identifiers;
  • pages or routes accessed;
  • feature and button interactions;
  • timestamps, response status, and performance information;
  • authentication, rate-limit, error, and security events; and
  • diagnostic information needed to operate and secure the Service.

We do not use third-party advertising trackers to build advertising profiles from VisitWeave use. We may use internal, non-PHI operational information to maintain reliability, troubleshoot, secure the Service, and understand whether core features function correctly.

2.6 Communications and Support Information

When you communicate with us, we may collect:

  • the sender and recipient;
  • message subject and content;
  • date and time;
  • support-case number;
  • call notes and identity-verification result;
  • attachments that are permitted through an approved secure channel; and
  • information needed to resolve the request.

Do not send PHI through ordinary email. When support requires PHI, use a VisitWeave-approved secure channel.

2.7 Notification Information

If notification features are enabled, we may process:

  • email address;
  • telephone number;
  • mobile push token;
  • notification preference;
  • delivery status; and
  • generic event metadata indicating that an item requires attention.

VisitWeave does not intentionally include PHI in SMS or mobile push-notification bodies.

2.8 Customer Data and PHI Processed on Behalf of Customers

Depending on a Customer's use, Customer Data may include:

  • patient name and telephone number;
  • patient service address and geocoded map coordinates;
  • referral and referring-agency information;
  • requested services and visit types;
  • clinician assignment and staffing information;
  • visit dates, times, time zones, status, completion, and cancellation information;
  • limited operational free-text details;
  • internal record identifiers; and
  • audit metadata associated with protected workflows.

The current Service is not intended for clinical notes, diagnoses, medications, test results, treatment plans, psychotherapy notes, insurance claims, or patient documents and files. Customers are instructed not to enter unsupported clinical or diagnostic information into free-text fields.

2.9 Information We Do Not Intentionally Collect for Our Own Purposes

We do not intentionally collect Customer PHI for advertising, data brokerage, generalized analytics, or unrelated product development. We do not intentionally collect full payment-card numbers in ordinary support communications. We do not require a patient to create a VisitWeave account.

3. Sources of Personal Information

We may obtain personal information:

  • directly from you;
  • from the Customer organization that creates or manages your account;
  • from another Authorized User who invites or administers you;
  • automatically from your browser, device, or use of the Service;
  • from authentication, email-delivery, hosting, security, and infrastructure providers;
  • from public business records when needed to verify an organization; and
  • from legal, regulatory, or law-enforcement sources when required.

Customer PHI generally comes from the Customer and its Authorized Users, not directly from patients.

4. How We Use Personal Information

We use personal information to:

4.1 Provide and Administer the Service

  • create and manage accounts and organizations;
  • authenticate users and maintain sessions;
  • provide referral, staffing, scheduling, reporting, and administrative functionality;
  • configure roles and permissions;
  • fulfill subscriptions and orders;
  • provide customer support; and
  • deliver requested reports and exports.

4.2 Protect the Service and People

  • prevent unauthorized access, fraud, abuse, and attacks;
  • monitor availability and performance;
  • investigate errors and security events;
  • enforce rate limits and access controls;
  • maintain legal and security audit records;
  • verify support callers and administrators; and
  • preserve evidence and respond to incidents.

4.3 Communicate

  • send account-verification, invitation, password-reset, and security messages;
  • provide service, maintenance, legal, billing, and Subprocessor notices;
  • respond to support and privacy requests; and
  • send generic SMS or push notifications when enabled.

4.4 Comply with Law and Agreements

  • maintain BAA and Terms acceptance records;
  • support HIPAA individual-rights requests through Customers;
  • respond to lawful process;
  • maintain tax, corporate, and compliance records;
  • enforce contracts; and
  • establish, exercise, or defend legal claims.

4.5 Maintain and Improve Non-PHI Operations

We may use account information and technical information that is not Customer PHI to troubleshoot, secure, maintain, and improve the Service. We do not use Customer PHI or de-identified Customer Data for general product analytics, benchmarking, or product improvement unless a Customer signs a separate addendum that expressly permits that use.

4.6 Artificial Intelligence

VisitWeave does not currently offer an AI feature that processes Customer PHI. We do not use personal information or Customer Data to train or improve a generalized AI or machine-learning model.

A future AI feature that processes Customer Data will be opt-in and governed by a separate addendum and feature-specific notice. The provider used for that feature must be contractually restricted from retaining prompts and outputs beyond the processing need or using Customer Data for model training.

5. How We Disclose Personal Information

We may disclose personal information as described below. We do not sell personal information or share it for cross-context behavioral advertising.

5.1 Customer Organizations and Authorized Users

A Customer controls its organization workspace. Organization Administrators may view and manage account, membership, role, security, and activity information concerning Authorized Users. Authorized Users may see information based on their assigned permissions.

5.2 Service Providers and Subprocessors

We may disclose personal information to providers that help us host, secure, operate, back up, monitor, or communicate about the Service. These providers may include:

  • data-center and cloud-infrastructure providers;
  • object-storage and backup providers;
  • authentication and security infrastructure;
  • email-delivery services;
  • monitoring and audit infrastructure; and
  • professional advisers where necessary.

Providers may use information only for the contracted service or as law permits. A provider that handles Customer PHI is subject to the BAA flow-down requirements. Current Customers can view the PHI-handling Subprocessor register through an authenticated in-application page.

5.3 Legal and Safety Disclosures

We may disclose information when we reasonably believe disclosure is necessary to:

  • comply with law, subpoena, court order, or governmental request;
  • protect rights, safety, or property;
  • investigate fraud or a security incident;
  • enforce agreements; or
  • establish, exercise, or defend a legal claim.

When a request concerns Customer Data, we will notify the Customer before disclosure unless notice is prohibited or emergency circumstances make prior notice impracticable. We will disclose only the information legally required.

5.4 Corporate Transactions

We may disclose information in connection with due diligence, financing, reorganization, merger, acquisition, or sale of assets. A recipient must protect the information and honor applicable contractual and legal restrictions. A transaction does not eliminate BAA obligations concerning Customer PHI.

5.5 With Direction or Consent

We may disclose information when you or the Customer directs us to do so, when needed to complete a requested transaction, or with legally valid consent.

5.6 No Independent Transmission to Healthcare Organizations

VisitWeave does not currently provide a product function that independently transmits Customer PHI to another healthcare organization. Authorized Customer users control any sharing or export of Customer Data.

6. No Sale, Targeted Advertising, or Data Brokerage

VisitWeave does not:

  • sell personal information or Customer PHI;
  • share personal information for cross-context behavioral advertising;
  • use Customer PHI for targeted advertising;
  • operate as a data broker;
  • create advertising profiles from Service use; or
  • monetize Customer PHI apart from charging for the Service.

Because we do not sell or share personal information for targeted advertising, we do not provide a "Do Not Sell or Share" link. If our practices change, we will update this Privacy Policy and provide any legally required choices before the new practice begins.

Where legally required, we will recognize a valid browser-based opt-out preference signal concerning sale or targeted advertising. Because we do not engage in those activities, such a signal generally will not change our current processing.

7. Cookies, Local Storage, and Similar Technologies

VisitWeave uses cookies, secure storage, or similar technologies that are reasonably necessary to:

  • authenticate users;
  • maintain sessions;
  • protect against cross-site request forgery and abuse;
  • remember security and interface preferences;
  • support invitations and organization selection; and
  • operate the Service.

We do not use third-party advertising cookies in the Service. If we introduce nonessential analytics or tracking technology, we will update this policy and provide consent or opt-out controls where required.

You can configure a browser to reject cookies, but blocking necessary cookies may prevent authentication or core Service functionality.

8. Report Exports and Downloads

Authorized users may export reports containing Customer Data. VisitWeave generates the export in volatile server memory and transmits it directly in the authenticated HTTPS response. We do not intentionally store the generated file contents in the application database, object storage, or server filesystem.

We may retain non-content audit metadata concerning an export, such as the Customer organization, actor, report template, export format, row count, and masking notices.

After an export is delivered to a user's browser or device, the Customer is responsible for securing, retaining, transmitting, and deleting the file. Do not send an export containing PHI by ordinary email.

9. Retention

We retain information only as long as reasonably necessary for the purposes described in this policy, the BAA, our contracts, or law. Standard periods include:

9.1 Customer PHI

  • Active Customer PHI is maintained while the Customer uses the Service.
  • Following Service termination, Customer has a thirty-calendar-day transition period to request or download an export.
  • Customer PHI is deleted from active production systems by the end of that period unless earlier deletion is requested or retention is legally required.
  • After deletion from active production systems, Customer PHI may remain in protected backup copies until those copies are overwritten or deleted under VisitWeave's then-current backup retention practices, subject to the BAA and Applicable Law.

9.2 Audit and Log Information

  • Compact legal-audit events are generally retained for one year.
  • Ordinary application and infrastructure logs are generally retained for thirty days.
  • Retention may be extended for an active incident, recovery operation, legal hold, or legal requirement.

Legal-audit records use approved identifiers and event metadata designed to reduce direct patient information. An opaque internal identifier is not necessarily legally de-identified if it can be linked back to a patient.

9.3 Accounting-of-Disclosures Records

Records maintained specifically to support a HIPAA accounting of disclosures are retained for six years from the applicable disclosure. These records are stored separately from ordinary logs using an immutable-retention design and integrity evidence.

9.4 Contract and Compliance Records

BAA versions, electronic acceptance records, and required HIPAA documentation are retained for at least the period required by law, generally six years from creation or the date last in effect, whichever is later.

9.5 Account, Support, Billing, and Corporate Records

We retain account, support, billing, tax, and corporate records for the subscription relationship and for a reasonable period afterward to comply with law, resolve disputes, prevent fraud, and enforce agreements. We may retain a minimal suppression or identity-verification record after honoring a deletion request when necessary to avoid recreating deleted data or to document compliance.

10. Security

VisitWeave maintains administrative, physical, and technical safeguards designed to protect personal information and Customer PHI. Safeguards include, as appropriate:

  • encryption of Customer PHI at rest and in transit;
  • role-based and least-privilege access;
  • employee-only production PHI access;
  • secure remote access;
  • access logging and review;
  • environment separation;
  • no real patient data in development, test, or staging environments;
  • vulnerability and dependency management;
  • backups and restoration testing;
  • incident-response procedures; and
  • workforce confidentiality and security training.

No system is perfectly secure. You are responsible for protecting your credentials, devices, email account, and sessions and for notifying us promptly of suspected unauthorized access.

11. Support Access to PHI

VisitWeave support personnel do not have application access to Customer PHI. When troubleshooting requires PHI access through controlled operational tools, including direct database access, an Organization Administrator must request and authorize that access. Access is limited to the support purpose and least privilege reasonably necessary, is audited, and expires when the support case closes or after twenty-four hours, whichever occurs first.

VisitWeave may access Customer PHI without prior Customer authorization only when reasonably necessary to investigate or contain a security incident, prevent imminent harm, or comply with law, as permitted by the BAA.

Before discussing PHI by telephone, we may send a one-time code to the email address already associated with the user's VisitWeave account. We do not ask for passwords, passkey secrets, or recovery codes by email.

12. United States Processing

VisitWeave is designed for United States customers. VisitWeave's hosting, workforce access, and PHI-handling Subprocessors are restricted to the United States under the BAA. We may move processing between United States regions without notice.

Access by a Customer user while outside the United States is not supported. Customer is responsible for restricting user access based on its policy and law.

13. Your Privacy Rights

Depending on your state, your relationship with VisitWeave, and legal exceptions, you may have rights concerning personal information that VisitWeave controls for its own purposes. These rights may include the right to:

  • confirm whether we process your personal information;
  • access or obtain a copy of personal information;
  • correct inaccurate personal information;
  • request deletion;
  • obtain portable information where required;
  • opt out of sale, targeted advertising, or certain profiling;
  • limit certain uses of sensitive personal information;
  • appeal a denied request; and
  • receive equal service without unlawful discrimination for exercising a right.

We do not sell personal information, share it for cross-context behavioral advertising, or use it for legally significant profiling.

13.1 Submitting a Request

For non-PHI personal information, submit a request to support@visitweave.com. Include enough information to identify your account and the right you want to exercise, but do not include PHI or patient information in the email.

We may need to verify identity and authority before completing a request. We will use information only as needed for verification and will respond within the period required by applicable law.

13.2 Authorized Agents

Where law permits an authorized agent to submit a request, we may require evidence of the agent's authority and may verify the request directly with the individual.

13.3 Appeals

If we deny a request and Applicable Law provides an appeal right, you may appeal by replying to the decision or emailing support@visitweave.com with the subject "Privacy Appeal." Do not include PHI.

13.4 Requests Concerning Customer PHI

If your request concerns patient, referral, visit, or other health information in a Customer workspace, contact the healthcare organization responsible for that workspace. The Customer is responsible for verifying you and deciding the request. VisitWeave will assist the Customer according to the BAA, including providing requested information or technical amendment assistance within the contractual periods.

13.5 Customer-Managed Account Information

A Customer may be able to access, correct, deactivate, or retain information about its Authorized Users. If your account was provided by an employer or healthcare organization, contact that Customer first for account-related requests.

14. Children's Information

The Service is not directed to children as account users or consumers, and patients do not create VisitWeave accounts. We do not knowingly allow a child to create an independent VisitWeave account.

A Customer may lawfully process referral and scheduling information about a minor patient through the Service. In that situation, VisitWeave processes the information for the Customer under the BAA, and the Customer is responsible for required notices, permissions, parental or personal-representative rights, and other legal requirements.

15. Email, SMS, and Mobile Push Privacy

15.1 Email

We use email for account verification, password reset, invitations, legal notices, security notices, billing, and non-PHI support. We design automated email to exclude Customer PHI.

Do not send patient names, referral details, visit details, reports, screenshots containing PHI, or other PHI to a VisitWeave email address.

15.2 SMS and Push

SMS and mobile push notifications, if enabled, contain only a generic notice that an item requires attention and a link or prompt to open the authenticated Service. They do not intentionally contain patient identity, address, service, visit time, referral details, or other PHI.

A device's lock-screen settings may display notification content to others. Because VisitWeave notifications are generic, they are designed to minimize that risk, but users should still secure their devices.

16. Artificial Intelligence and Automated Decision-Making

VisitWeave does not currently use AI to make medical, employment, insurance, or other legally significant decisions and does not offer a Customer PHI-processing AI feature. We do not use Customer Data for model training.

Any future AI feature that processes Customer Data will be optional and subject to separate notice and contractual terms. If an applicable privacy law grants rights concerning automated decision-making, we will provide the required information and controls before offering a covered feature.

17. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in law, the Service, or our practices. We will update the "Last Updated" date and provide additional notice when a change is material.

A change to this Privacy Policy does not amend the BAA. A material change to how VisitWeave processes Customer PHI requires the process stated in the BAA and, where applicable, Customer acceptance of an amendment.

18. Contact Us

For privacy questions or requests concerning non-PHI personal information:

Tawny Dog Software, LLC dba VisitWeave 7901 4th St N #34331 St. Petersburg, FL 33702 Email: support@visitweave.com

Do not include PHI or patient information in email. If your question concerns health information held for a healthcare organization, contact that organization. VisitWeave will provide a secure channel when direct PHI communication is necessary and authorized.

Role Summary

  • For account, website, business-contact, and VisitWeave corporate information: VisitWeave generally determines the processing purposes described in this Privacy Policy.
  • For Customer Data and Customer PHI: the Customer generally determines the purpose and permitted users, and VisitWeave processes the information to provide the Service under the Terms and BAA.
  • For patient privacy rights: the healthcare Customer is the primary contact; VisitWeave assists the Customer as required.
VisitWeave

From referral to completed visit.

PrivacyTerms of ServiceContact support
VisitWeavehello@visitweave.com