Skip to main content
Caregiver Readiness Passport

Privacy Policy

Last updated: August 16, 2026

Caregiver Readiness Passport (“Caregiver Readiness Passport,” “we, ” “us,” or “our”) operates this Service. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use carereadypassport.com and the related Caregiver Readiness Passport services (the “Service”).

Caregiver Readiness Passport is a caregiver education and readiness platform. Because the Service is designed around Type 1 diabetes caregiver training, use of the Service may reveal or imply sensitive health-related information even though the Service intentionally does not require live glucose data or detailed medical records.

Please also review our Consumer Health Data Privacy Notice, which provides additional information about health-related data and privacy rights.

1. Information we collect

A. Account and contact information

We may collect:

  • Name.
  • Email address.
  • Account role, such as Parent/Admin or Caregiver.
  • Authentication and account-status information.
  • Account creation, verification, login, and logout timestamps.

Authentication is provided through our service providers. We do not store plain-text passwords.

B. Caregiver relationship and training information

To provide the Service, we may process:

  • Caregiver invitations and invitation status.
  • The relationship between a parent account and an invited caregiver.
  • Assigned training courses and modules.
  • Age-band selections used to tailor training, such as Preschool/Young Child, Elementary, or Teen.
  • Device-specific training selections, such as Dexcom G7 or Omnipod 5.
  • Whether optional hands-on procedure modules are assigned.
  • Course progress, completion status, quiz attempts, answers, scores, retries, and timestamps.
  • Practical-verification status when that feature is used.
  • Training acknowledgment and policy-acceptance versions and timestamps.
  • Course expiration, retraining, revocation, and completion records.

C. Health-related context

The Service may process limited health-related context that is necessary to provide Type 1 diabetes caregiver training. Depending on how a parent configures a course, this may include:

  • The fact that training relates to Type 1 diabetes.
  • The age band of the person receiving care.
  • The diabetes devices or emergency products relevant to the training.
  • Parent-selected procedure permissions or training modules.
  • Information a user voluntarily enters in permitted notes or support communications.

We intentionally design the Service to avoid collecting more sensitive medical data than is needed for caregiver education.

D. Information we intentionally do not require

Unless the Service is changed and this Policy is updated, we do not require or intentionally collect through the core product:

  • Continuous glucose monitor data streams or real-time glucose readings.
  • Insulin doses, bolus calculations, or pump-control data.
  • Medical records, laboratory results, insurance information, or medical record numbers.
  • Child user accounts.
  • Child photos or videos uploaded by families.
  • Precise geolocation.
  • Advertising identifiers.
  • Contact-list access.
  • Payment card numbers.

Users should not place unnecessary medical details in free-text fields.

E. Communications

We may process:

  • Caregiver invitation emails.
  • Account verification and authentication emails.
  • Training reminders and expiration notices.
  • Support, privacy, security, or other messages you send to us.
  • Email delivery status and related transactional metadata.

F. Technical and security information

When you use the Service, our systems and hosting providers may automatically process information such as:

  • IP address.
  • Browser type and device type.
  • Operating system.
  • Request timestamps.
  • Security and error logs.
  • Session and authentication cookies.
  • Pages requested and basic diagnostic information necessary to operate and secure the Service.

We do not use this information for behavioral advertising.

G. Third-party training videos and links

Some lessons may include or link to official manufacturer training content hosted by services such as YouTube/Google, Vimeo, Wistia, Dexcom, Omnipod/Insulet, or BAQSIMI's manufacturer. If you choose to load an embedded third-party video or follow a third-party link, the third party may receive technical information such as your IP address, browser information, or cookies under its own privacy practices.

Where practical, we use a click-to-load approach so that third-party video content is not loaded until you choose to view it.

2. How we use information

We use personal information to:

  • Create and secure accounts.
  • Authenticate users and maintain sessions.
  • Let parents invite and manage caregivers.
  • Build and assign training courses.
  • Present age-appropriate and device-relevant training.
  • Record training progress, quiz results, acknowledgments, and completion.
  • Support course expiration, retraining, revocation, and practical verification.
  • Send transactional emails and reminders.
  • Provide user support.
  • Detect, investigate, and prevent security incidents, abuse, or fraud.
  • Maintain application reliability and troubleshoot errors.
  • Comply with applicable legal obligations.
  • Enforce our Terms of Use and protect users and the Service.

We do not use health-related information to determine insurance eligibility, employment eligibility, creditworthiness, or targeted advertising.

3. How we disclose information

We disclose information only as reasonably necessary to operate, secure, and support the Service, or as required by law.

Service providers

Current categories include:

  • Supabase: authentication, database, and related backend services.
  • Vercel: application hosting, deployment, and request handling.
  • Resend: transactional email delivery.
  • Manufacturer/video hosting providers: only when a user loads or follows third-party training media or links.

We require service providers to handle information only for authorized service purposes through the contracts and terms available for those services.

Parent and caregiver sharing

The Service is designed to share training information between a parent and caregivers that the parent invites or authorizes. For example, a caregiver may see assigned modules, course status, and training instructions relevant to that assignment. A parent may see the caregiver's training progress and completion status.

Legal and safety disclosures

We may disclose information when reasonably necessary to:

  • Comply with law, legal process, or a lawful government request.
  • Protect the rights, safety, or security of users, the public, or the Service.
  • Investigate fraud, abuse, or security incidents.
  • Enforce our agreements.
  • Complete a business transaction such as a merger, financing, acquisition, reorganization, or sale, subject to applicable privacy obligations.

4. We do not sell health data or use it for targeted advertising

We do not sell personal information or consumer health data.

We do not use consumer health data for targeted advertising.

We do not permit third-party advertising networks to build profiles based on Type 1 diabetes training activity.

If these practices ever change, we will update our disclosures and obtain consent where required before the new practice begins.

5. Cookies and similar technologies

The Service uses cookies or similar storage that are necessary for authentication, session management, security, and core functionality.

We do not currently use nonessential advertising cookies or marketing pixels in the Service.

Third-party video providers may use their own cookies if you choose to load their content. See Section 1.G.

6. Data retention

We retain information only for as long as reasonably necessary to provide the Service, maintain training records requested by users, protect security, resolve disputes, and comply with law.

Our internal retention schedule generally provides for:

  • Active account and training data to remain while the relevant account or relationship is active.
  • Expired or revoked invitation metadata to be removed after a limited operational period.
  • Security and audit logs to be retained for a limited security period.
  • Deleted account data to be removed from active production systems promptly after a verified deletion request, subject to limited backup rotation and legal/security exceptions.

If applicable law gives you a shorter or more specific right, we will follow applicable law.

7. Your choices and privacy rights

Depending on where you live, you may have rights regarding your personal information or consumer health data. We also choose to provide several of these controls to U.S. users more broadly.

You may request, as applicable:

  • Confirmation of whether we process information about you.
  • Access to information associated with your account.
  • Correction of inaccurate account information.
  • Deletion of your account and associated information.
  • Withdrawal of consent for future collection or sharing where consent is the legal basis.
  • Information about service providers or third parties with whom relevant data has been shared.
  • An appeal if a qualifying privacy request is denied.

You can use the in-product Privacy & Data controls or submit a request through carereadypassport.com/privacy-request or privacy@carereadypassport.com.

We will take reasonable steps to verify that the person making a request is authorized to do so. You are not required to create a new account solely to submit a privacy request.

See the Consumer Health Data Privacy Notice for additional details.

8. Account deletion

Parents and caregivers can request deletion through the application's Privacy & Data settings or through our privacy request process.

Deletion is intended to remove personal information and health-related training records associated with the requesting user from active systems, subject to:

  • Information that another user has an independent right or need to retain, where appropriate and legally permitted.
  • Security, fraud-prevention, legal-hold, or compliance records that must be retained.
  • Backup systems, which are deleted or aged out according to our backup schedule and applicable law.

If a caregiver is connected to more than one parent in a future version of the Service, deleting one parent's relationship will not automatically delete records that belong to an independent relationship with another parent.

9. Security

We use administrative and technical safeguards designed for the sensitivity of the information we process, including:

  • Authentication controls.
  • Role-based access controls and database Row Level Security.
  • Encryption in transit.
  • Managed infrastructure and database services.
  • Secret-management practices.
  • Automated testing and dependency/security review.
  • Access minimization.
  • Audit and security logging.
  • Incident-response procedures.

No system can guarantee absolute security. Please contact privacy@carereadypassport.com if you believe your account or the Service may have been compromised.

10. Children and minors

The Service is designed for adult parents, guardians, caregivers, and staff. Child users do not create accounts.

Account holders must be at least 18 years old. The Service is not directed to children under 13, and we do not knowingly create accounts for children under 13.

If you believe a child has directly submitted personal information to the Service without appropriate authorization, contact privacy@carereadypassport.com.

11. HIPAA and consumer health information

Health information entered directly into an independent consumer service may not be protected by HIPAA unless the service is acting as a HIPAA covered entity or business associate in a particular relationship. We do not rely on HIPAA as the sole basis for protecting user information. We protect data according to this Policy, our security practices, and applicable consumer privacy and health-data laws.

We do not represent the Service as “HIPAA compliant.”

12. U.S.-only service

The Service is currently intended for users in the United States. We are not offering the Service as a product designed for compliance with non-U.S. privacy regimes at this time.

13. Changes to this Policy

We may update this Policy as the Service or legal requirements change. If a change materially affects how we collect, use, or share health-related information, we will provide appropriate notice and obtain consent when required before applying the new practice.

The “Last updated” date above shows when the Policy was most recently revised.

14. Contact us

Operator: Caregiver Readiness Passport

Privacy: privacy@carereadypassport.com

Support: support@carereadypassport.com

For consumer health data rights, please also see our Consumer Health Data Privacy Notice.