YourEMR - Family-controlled emergency information organizer

Legal

YourEMR Privacy Policy

Personal information collected through Accounts, Profiles, purchases, support, and public sharing

1. Scope and controller

This Policy explains how YourEMR LLC, a South Carolina company, handles personal information through the website, Accounts, Profiles, Emergency Views, Public Links, support, Paid Access purchases, and optional Physical QR and NFC Products. Separate providers may publish their own notices.

2. Information collected

Account and authentication information, preferences, recovery state, and timestamps. Profile identity, relationship, age or date of birth, photo, language, and contact information. Consumer Health Data, including conditions, allergies, medications, alerts, devices, providers, documents, care preferences, and emergency notes. Emergency contacts, organizer content, uploaded documents, and user notes. Public Link choices, consent versions, token status, sharing events, and security records. Technical and fraud-prevention data, including device, browser, request, rate-limit, and security metadata. Transactions, prices, taxes, order status, payment-provider identifiers, shipping, tracking, proof approval, refunds, and disputes. YourEMR does not intentionally store full payment-card numbers.

3. Sources

Information comes from the Account holder; a person lawfully managing another Profile; devices and browsers; Netlify for hosting and deployment; Supabase for authentication, database, and storage; Stripe for payment processing; Resend as the intended transactional-email provider; Commit Happens, Netlify, and Google Analytics 4 for analytics on eligible public marketing pages only, route-restricted and production-tested to exclude authenticated, health-data, and token/emergency routes; YourEMR's own production and fulfillment for physical products, performed directly or through an approved production arrangement, with no outside printing or fulfillment vendor currently used; support, security, and legal sources.

4. Purposes

YourEMR uses information to provide and secure Accounts and Profiles; create organizer, print, export, Emergency View, Public Link, and QR features; process purchases; fulfill approved products; send transactional communications; answer support and rights requests; prevent abuse; investigate incidents; maintain consent, tax, contract, and security records; comply with law; and improve eligible public pages using minimized analytics.

5. Disclosures

YourEMR discloses information to contracted processors only for documented services such as hosting, authentication, private storage, abuse prevention, transactional email, payment, support, security, and intentionally selected translation. Physical-product production, personalization, and fulfillment are performed by YourEMR directly or through a production arrangement YourEMR has approved and confirmed may lawfully be used for that purpose, not by a contracted processor. No outside printer, fulfillment vendor, or similar third party currently receives customer order data, artwork, or Profile content for any approved physical product. If YourEMR later approves an outside fulfillment arrangement, that provider will be added to YourEMR's vendor register and this Policy will be updated before that arrangement receives any customer data. Google Cloud Translation is disabled by default and is not an active production recipient of any information as of August 14, 2026. If YourEMR later enables it, translation occurs only after a member affirmatively selects to translate specific emergency text, only that submitted text is sent, server-to-server, solely to perform that translation, and it is never sent in a URL, analytics event, or log. Public Link viewers receive only the user-selected fields while sharing is active.

YourEMR does not sell Consumer Health Data or use it for targeted advertising. It does not use prohibited geofencing around healthcare facilities.

6. Public Links

An active Public Link is unauthenticated. Anyone possessing it may view, copy, screenshot, forward, or retain selected fields. Deactivation or rotation prevents future access through YourEMR but cannot recall outside copies. Public sharing requires separate consent.

7. Cookies and analytics

Essential storage supports authentication, security, preferences, and consent. Commit Happens, Netlify analytics, and Google Analytics 4 may operate only on eligible public marketing pages. They must be excluded from authenticated Accounts, Profiles, checkout, emergency views, Public Links, QR or token routes, and every health-data surface. Query strings, tokens, identifiers, and health content must not be sent to analytics.

YourEMR does not currently use personal information from authenticated or health-data surfaces for cross-context behavioral advertising. YourEMR will state whether its eligible public-page analytics configuration collects information over time or across third-party websites once that configuration question is settled, and will update this Policy at that time. Browser Do Not Track signals are not a uniform legal standard, and YourEMR does not respond to them separately from the Global Privacy Control commitment below. Where a legally recognized opt-out preference signal, including Global Privacy Control, applies to a covered sale, sharing, or targeted-advertising activity, YourEMR will honor it. The present business rule is not to sell Consumer Health Data or use it for targeted advertising.

8. Children and other-person Profiles

Accounts are intended for adults. A child may not create an Account. An adult may create a child, dependent, or other-person Profile only with lawful authority. Contact YourEMR if information appears to be managed without authority.

9. Security

YourEMR uses administrative, technical, and physical safeguards designed for the sensitivity of the information. No system is completely secure. YourEMR does not claim that it is HIPAA compliant or that HIPAA necessarily applies to its direct-to-consumer service.

10. Retention

YourEMR retains active information while needed to provide the Service, then deletes or deidentifies it under the approved schedule. Verified Account or Profile deletion requests are completed in active systems within 30 days; temporary exports are deleted after 7 days; detailed security logs are retained for 12 months; rolling backups are retained no longer than 180 days; and information tied to an expired Paid Access term is retained for 12 months after expiration and then securely deleted or de-identified, consistent with the retention schedule in Document 05, with advance warnings 30 and 7 calendar days before deletion as described there. Billing, consent, tax, fraud, dispute, and legal records may be retained separately for up to seven years when necessary.

11. Rights and choices

Depending on residence and context, a person may request confirmation, access, correction, deletion, portability, recipient information, consent withdrawal, opt-out, or appeal. YourEMR intends to provide core rights nationwide subject to identity, authority, security, and lawful exceptions. Use the authenticated privacy-request tool when available or email support@youremr.net with subject "Privacy Request." Do not email health information, passwords, payment data, identity documents, or Public Links.

12. Changes and contact

The effective date appears at the beginning of this Policy. Material changes receive advance notice and renewed consent when required. Prior versions will be archived. Contact YourEMR LLC at support@youremr.net and YourEMR LLC, 2734 Beaver Run Blvd, Suite B #421, Surfside Beach, SC 29575. Privacy appeals may be submitted through the authenticated request tool or to privacy@youremr.net.

Review the complete current YourEMR legal publication set.