Privacy Policy

Privacy Policy for Oathtrack sober living software

This Privacy Policy explains how Oathtrack LLC collects, uses, protects, retains, and handles personal information across our website, hosted platform, mobile applications, resident tools, staff tools, communications features, and related services.

Effective Date: May 9, 2026   |   Last Updated: September 7, 2026

At a Glance

  • Oathtrack collects account, contact, billing, usage, support, device, and customer-submitted information to provide and improve the Services.
  • Customer workspaces may include resident, applicant, staff, document, payment, communication, and recovery residence operations data.
  • When customers use Oathtrack to process protected health information, applicable customer agreements and business associate terms govern that processing.
  • Oathtrack does not sell, give away, publish, or provide personal information to third parties for their own marketing or independent use. Information is made available only in the limited ways described in this Privacy Policy.
  • Privacy or Security concerns can be sent to security@oathtrack.com.

How We Think About Privacy

Oathtrack is built for sober living operators, recovery residences, house managers, staff, residents, applicants, and related operational teams. That means privacy is not just a website notice. It is part of how resident records, documents, billing workflows, communication tools, and staff permissions are handled.

Our goal is to use personal information only for legitimate product, support, security, legal, compliance, billing, and business purposes connected to the Services.

1. Scope

This Privacy Policy applies to Oathtrack LLC ("Oathtrack," "we," "us," or "our") and our website located at oathtrack.com, the secure Oathtrack platform, Oathtrack mobile applications, resident tools, staff tools, demo requests, contact forms, support requests, marketing communications, service administration, and related services (collectively, the "Services").

This Privacy Policy does not apply to third-party websites, mobile applications, integrations, payment portals, app stores, or services that we do not control, even if they are linked from or accessible through the Services.

2. Categories of Information We Collect

Depending on how you interact with the Services, we may collect the following categories of information:

  • Account and contact information, such as name, email address, phone number, job title, organization name, login credentials, and similar identifiers.
  • Billing and transaction information, such as subscription details, payment status, invoices, tax-related details, and limited payment metadata received from our payment processors.
  • Service usage and device information, such as IP address, browser type, app version, device identifiers, approximate location derived from IP, referral pages, feature interactions, crash logs, log data, and diagnostic data.
  • Communications and support information, such as messages you send to us, demo requests, support tickets, feedback, chat interactions, survey responses, and administrative communications.
  • Customer-submitted information, which may include resident records, applicant records, staff records, forms, notes, documents, check-ins, schedules, communications, payment records, drug test records, passes, chores, calendars, and other information submitted to the Services by or for our customers.
  • Marketing and analytics information, such as website visit data, campaign attribution, cookie identifiers, preferences about receiving communications from us, and information used to measure website and campaign performance.
  • Security and fraud-prevention information, such as authentication activity, access logs, suspicious activity indicators, and information used to protect the Services and customer workspaces.

3. Sources of Information

We collect information directly from you, automatically through your use of the Services, from the devices and browsers you use, from our customers and their authorized users, from payment processors and service providers, from analytics and advertising partners, and from other third parties lawfully providing information to us.

4. Cookies and Similar Technologies

We and our service providers may use cookies, pixels, SDKs, tags, local storage, analytics tools, and similar technologies to operate the Services, remember preferences, authenticate users, understand traffic and usage patterns, improve performance, troubleshoot issues, detect fraud, measure campaign effectiveness, and support marketing.

We do not use customer workspace data, PHI, resident records, applicant records, staff records, or SMS opt-in consent for third-party advertising. Website analytics and marketing tools are intended for public website and business development activity, not for independent third-party use of customer-controlled platform data.

Some browsers and extensions offer settings that let you reject or limit cookies. If you disable certain cookies or similar technologies, some features of the Services may not function properly.

5. How We Use Information

We may use personal information for the following purposes:

  • to provide, operate, maintain, host, secure, support, and improve the Services;
  • to create and administer accounts, authenticate users, and manage permissions;
  • to process subscriptions, invoices, collections, payment records, and related transactions;
  • to provide customer support, respond to inquiries, and communicate with you about your account or the Services;
  • to personalize content, workflows, settings, and communications within the Services;
  • to monitor usage, analyze trends, troubleshoot technical issues, and develop new features;
  • to send service-related communications, updates, notices, reminders, and administrative messages;
  • to send marketing communications, where permitted by law and subject to your choices;
  • to investigate fraud, abuse, security incidents, violations of our agreements, and unlawful activity;
  • to comply with legal obligations, enforce our rights, and protect the rights, safety, and property of Oathtrack, our customers, users, residents, applicants, staff, and others; and
  • for any other purpose explained at the time the information is collected or as otherwise permitted by law.

6. Limited Operational Access

Oathtrack does not sell, give away, publish, or provide personal information to third parties for their own marketing or independent use. To operate, support, secure, bill for, and administer the Services, limited information may be made available only in the following circumstances:

  • To customers and authorized users, when information is submitted into a customer workspace or is needed for the intended use of the Services.
  • To service providers and subprocessors, including cloud hosting providers, infrastructure vendors, payment processors, customer support tools, messaging vendors, analytics providers, security vendors, and other vendors that perform services for Oathtrack and our customers.
  • To professional advisors, such as lawyers, accountants, insurers, auditors, or similar advisors, when needed for legitimate business, legal, compliance, insurance, audit, or accounting purposes.
  • For legal, compliance, and protection purposes, when necessary to comply with law, enforce agreements, detect or prevent fraud, respond to lawful requests, or protect rights, safety, and security.
  • In connection with a business transfer, such as a merger, acquisition, financing, bankruptcy, reorganization, or sale of all or part of our business or assets, subject to appropriate confidentiality and data protection expectations.
  • At your direction or with your consent, or as otherwise explained to you at the time of collection.

7. Sale, Sharing, and Targeted Advertising

Oathtrack does not sell personal information. We do not give away personal information or provide it to third parties for their own marketing purposes or independent use. Personal information is made available only as described in this Privacy Policy, such as to provide, host, support, secure, bill for, improve, and administer the Services; to work with customers and authorized users; to use service providers and subprocessors; to comply with law; and to protect rights, safety, and security.

Some privacy laws define "sale," "sharing," "targeted advertising," or similar terms broadly enough to include certain advertising, analytics, or tracking technologies. If we use a technology that is treated as a sale, sharing, or targeted advertising under applicable law, we will provide required notices and choices.

8. SMS and Text Messaging

If you opt in to receive SMS or text messages from us or our customers, we collect your phone number and consent records. We use this information to send updates, alerts, reminders, and other communications related to the Services.

We do not share, sell, rent, or provide SMS opt-in consent or phone numbers to third parties for their own marketing purposes. You may opt out of receiving text messages at any time by replying "STOP" to any message you receive.

9. Customer-Controlled Data

In many cases, Oathtrack customers use the Services to manage resident, applicant, staff, house, billing, document, communication, and operational information. When we process personal information on behalf of a customer, that customer may determine why and how the information is used, and our processing is governed by our agreements with that customer.

If you submit information to Oathtrack on behalf of a sober living operator, recovery residence, house manager, or other customer, Oathtrack generally processes that information for the customer that controls the account. That customer is responsible for determining whether the information may be lawfully collected and provided to Oathtrack, for giving any required notices, and for responding to requests concerning that information when required by law.

If you are a resident, applicant, staff member, or other person whose information was provided to Oathtrack by one of our customers, you may wish to contact that customer directly first. If you contact us, we may direct your request to the customer that controls the relevant workspace.

10. HIPAA, PHI, and Business Associate Terms

Depending on how customers use the Services, customer-submitted information may include protected health information ("PHI") or electronic protected health information ("ePHI"). When Oathtrack acts as a business associate for a customer that is a covered entity or business associate under HIPAA, applicable business associate terms and customer agreements govern our permitted uses and disclosures of PHI.

Oathtrack is HIPAA compliant and designed to support HIPAA-conscious operations through administrative, technical, and physical safeguards. HIPAA compliance also depends on each customer using the platform appropriately, managing user access, training staff, maintaining required internal policies, and following privacy and breach-response obligations that apply to its organization.

Where a Business Associate Agreement or similar data protection addendum is required, customers should complete that agreement with Oathtrack before using the Services to create, receive, maintain, or transmit PHI. If there is a conflict between this Privacy Policy and a signed Business Associate Agreement regarding PHI, the Business Associate Agreement controls for that PHI.

For technical safeguards and security details, review the Oathtrack Security and HIPAA safeguards page. Privacy or Security concerns can be sent to security@oathtrack.com.

11. Subprocessors and Operational Vendors

Oathtrack uses carefully selected service providers and subprocessors to host, secure, monitor, bill for, support, communicate through, and maintain the Services. These vendors may process limited information only as needed to perform services for Oathtrack and our customers, and they are not permitted to use personal information for their own marketing or independent purposes.

Subprocessors may include cloud infrastructure providers, database and storage providers, payment processors, messaging vendors, customer support tools, analytics tools, email delivery providers, security monitoring vendors, and professional service providers. We evaluate vendor access based on the nature of the service, sensitivity of the information, security expectations, contractual obligations, and operational need.

12. Sensitive Information

Depending on how customers use the Services, customer-submitted data may include sensitive or high-risk information, including information related to recovery status, treatment history, behavioral notes, location-related check-ins, financial records, identity information, or other protected or sensitive records.

Oathtrack processes such information only as needed to provide the Services, support our customers, maintain security, comply with law, and enforce our agreements. Customers remain responsible for ensuring they have all rights and legal authority required to collect, use, and provide such information to us.

13. Data Retention, Export, and Deletion

We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, maintain records, resolve disputes, enforce agreements, comply with legal obligations, prevent fraud, preserve security, and support legitimate business operations. Retention periods may vary depending on the type of information, the sensitivity of the data, legal requirements, and the nature of the customer relationship.

Customers may request assistance with exporting or deleting customer-controlled workspace data, subject to account status, product functionality, legal obligations, backup cycles, security requirements, and any applicable customer agreement. Residents, applicants, staff members, and other individuals whose information is controlled by an Oathtrack customer should usually contact that customer first. If a request is sent to Oathtrack, we may route the request to the customer that controls the relevant workspace.

Deletion from active systems does not always mean immediate deletion from backups, logs, audit records, fraud-prevention records, billing records, legal files, or records we are required or permitted to retain. Backup and archival copies are protected and removed according to ordinary retention, rotation, and security processes.

Data Type Primary Purpose Typical Retention Approach
Account and contact information Account administration, authentication, support, customer communication, and billing coordination. Retained while the account or customer relationship is active and for a reasonable period afterward for legal, audit, security, and business records.
Customer-submitted workspace data Providing resident, staff, applicant, document, billing, communication, and recovery residence management workflows. Generally retained according to customer configuration, customer agreements, legal obligations, backup cycles, and service administration needs.
Billing and transaction records Subscription administration, invoicing, collections, accounting, tax, and dispute resolution. Retained as needed for accounting, tax, legal, audit, and business recordkeeping obligations.
Security, log, and diagnostic data Security monitoring, fraud prevention, troubleshooting, product reliability, and incident response. Retained for periods appropriate to security, troubleshooting, legal, and operational needs.
Marketing and website analytics data Website measurement, campaign performance, communication preferences, and business development. Retained while useful for the purpose collected or until you opt out where applicable, subject to legal and operational needs.

14. Data Security

We use administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. These safeguards include access controls, encryption, monitoring, secure hosting practices, backup routines, and operational security processes.

We encourage customers to apply minimum-necessary access practices, maintain appropriate user roles, remove users who no longer need access, protect credentials, train staff, and review account activity. Customer configuration and staff behavior are important parts of privacy and security in any shared SaaS environment.

However, no method of transmission over the internet, no mobile environment, and no method of electronic storage is completely secure. For that reason, we cannot guarantee absolute security.

15. Security Incident Notice

If we determine that a security incident requires notice under applicable law or an applicable customer agreement, we will provide notice to affected customers or individuals as legally required. Notice may include information about the nature of the incident, the categories of information involved, steps we have taken, and recommended protective measures, depending on what is known and what the law requires.

Privacy or Security concerns can be sent to security@oathtrack.com.

16. Your Choices and Rights

Depending on your relationship with Oathtrack and where you live, you may have rights to request access to personal information, request correction of inaccurate information, request deletion, request a portable copy of certain information, object to or restrict certain processing, withdraw consent where processing is based on consent, opt out of certain marketing communications, or appeal our decision on a privacy request. Some rights are subject to exceptions and limitations under applicable law.

You may update certain account information by logging into your account. You may opt out of non-essential marketing emails by using the unsubscribe link in the message. If you would like to make a privacy-related request, contact us using the information at the end of this Privacy Policy. If we process your information solely on behalf of one of our customers, we may direct your request to that customer.

17. U.S. State Privacy Disclosures

Residents of certain U.S. states may have additional privacy rights under applicable law, which can include the right to know whether we process personal information, access categories or specific pieces of personal information, correct inaccuracies, delete personal information, obtain a portable copy of certain information, opt out of targeted advertising, opt out of certain profiling activities, opt out of the sale or sharing of personal information as those terms are defined by law, and appeal the denial of a privacy request. We will not unlawfully discriminate against you for exercising applicable privacy rights.

If a browser-based opt-out preference signal or universal opt-out mechanism is legally required and technically supported for the processing at issue, we will honor it to the extent required by applicable law. We may need to verify your identity and authority before acting on a request.

18. Children

The Services are not directed to children under 13, and we do not knowingly collect personal information directly from children under 13 through public-facing portions of the Services. If you believe a child has provided personal information to us in violation of law, please contact us so that we can review and take appropriate action.

19. International Transfers

Oathtrack is based in the United States, and personal information may be transferred to, stored in, or processed in the United States or other jurisdictions where we or our service providers operate. Those jurisdictions may have data protection laws that differ from the laws of your jurisdiction. Where required by law, we will implement appropriate safeguards for cross-border transfers.

20. Third-Party Services

The Services may contain links to third-party websites, app stores, payment portals, integrations, or services. We are not responsible for the privacy, security, or content practices of those third parties. We encourage you to review the privacy policies of any third-party service you choose to use.

21. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will post the updated version with a revised effective date or last updated date and may provide additional notice through the Services or by email where appropriate. Your continued use of the Services after the updated Privacy Policy becomes effective means the updated Privacy Policy applies to your future interactions with the Services.

22. Contact Us

If you have questions about this Privacy Policy or would like to submit a privacy request, you may contact Oathtrack at info@oathtrack.com or by phone at (484) 925-1580.

Privacy or Security concerns can be sent to security@oathtrack.com.

Questions about privacy or data handling?

We are happy to talk through privacy, data handling, security, HIPAA, and implementation questions with your team.

info@oathtrack.com   |   security@oathtrack.com   |   (484) 925-1580