DenialTracker Privacy Policy

‍

Effective Date: October 1, 2026
Website: https://denialtrackerapp.com
Publisher: DenialTracker LLC (“DenialTracker,” “we,” “us,” or “our”)

1. Introduction

This Privacy Policy explains how DenialTracker LLC collects, accesses, uses, processes, discloses, and retains information in connection with the DenialTracker Google Workspace Add-on, the DenialTracker website, subscription and billing functions, support communications, and related services.

DenialTracker is intended for business and professional users in the United States.

This Privacy Policy applies to systems and information controlled by DenialTracker. It does not replace the privacy policies, security obligations, or contractual terms governing Google Workspace, Stripe, clearinghouses, electronic health record systems, revenue cycle management systems, or other independent third-party services used by a customer.

By creating or activating a DenialTracker subscription or otherwise using the Service, you acknowledge that you have received and reviewed this Privacy Policy.

2. Overview of DenialTracker’s Data Architecture

DenialTracker is designed with separate claim-processing and external business-service environments.

The DenialTracker Google Workspace Add-on processes remittance and claim information through the User’s Google Workspace environment using services such as Google Drive, Google Sheets, Gmail, and Google Apps Script.

DenialTracker separately operates external infrastructure for functions such as Google identity verification, subscription validation, Stripe billing operations, security controls, and limited operational logging.

DenialTracker’s external billing and subscription infrastructure is not designed to receive the contents of 835 files, patient claim records, or other claim-level healthcare information processed by the Add-on.

DenialTracker does not maintain an external repository of customer 835 files or claim-level patient records as part of its normal architecture.

3. Google User Data

DenialTracker accesses Google user data only as reasonably necessary to provide and secure User-facing functionality.

Depending on the permissions granted and features used:

DenialTracker may receive a Google account email address, Google account subject identifier, and, where supplied by Google, information identifying the User’s Google Workspace hosted domain.

DenialTracker does not use Google Workspace claim information for advertising, advertising profiles, data brokerage, or sale of personal information.

4. Google API Limited Use

DenialTracker’s access to and use of information received through Google APIs is limited to providing, securing, maintaining, and improving User-facing DenialTracker functionality consistent with permissions granted by the User.

DenialTracker’s use and transfer of information received through Google APIs is intended to comply with the Google API Services User Data Policy and applicable Google Workspace API user-data requirements, including Limited Use requirements.

DenialTracker does not use Google Workspace data to train general-purpose artificial intelligence or machine-learning models.

DenialTracker does not sell Google Workspace user data or use such information for targeted or cross-context behavioral advertising.

Google user data will not be transferred to third parties except where permitted by applicable Google policies, such as where necessary to provide or secure requested functionality, comply with applicable law, or carry out an action clearly authorized by the User.

5. Human Access to Google Workspace Data

DenialTracker personnel do not ordinarily access or review the contents of customer 835 files, claim-level healthcare information, Google Sheets, or other Google Workspace content.

Human access to Google Workspace user data will occur only where permitted under applicable Google policies and reasonably necessary, such as:

Users should not provide DenialTracker personnel with PHI unless DenialTracker has expressly authorized a specific secure process for doing so.

6. Protected Health Information and Claim Data

DenialTracker may process claim-level information within a User’s Google Workspace environment, and that information may include Protected Health Information (“PHI”).

The DenialTracker Add-on may read 835 files from Google Drive, interpret information contained in those files through Google Apps Script, write resulting information to Google Sheets, and send User-configured reports or notifications through Gmail.

DenialTracker’s external billing, website, and subscription infrastructure is not designed to receive or store the contents of those files or resulting claim-level patient information.

DenialTracker does not intentionally transmit claim-level information to its external billing backend for subscription management, advertising, customer profiling, or unrelated analytics.

7. User-Directed Sharing and Transmission

Users control their own Google Workspace environments.

Users may choose to download files, export spreadsheets, share documents, configure Gmail recipients, forward alerts, connect third-party applications, or otherwise transmit information.

Information may therefore leave a particular Google Workspace environment because of User actions, organizational configuration, or third-party integrations.

DenialTracker is not responsible for disclosures or transfers independently initiated by a User or systems outside DenialTracker’s control.

8. HIPAA and Healthcare Privacy Responsibilities

Users are responsible for determining whether HIPAA or other healthcare privacy and security requirements apply to their organization or use of DenialTracker.

Where required, Users are responsible for maintaining an appropriate Business Associate Agreement or other required contractual relationship with Google and for configuring their Google Workspace environment in a manner appropriate for the information being processed.

DenialTracker does not represent that use of the Service, by itself, makes a User or organization HIPAA compliant.

DenialTracker is presently designed so that DenialTracker LLC does not receive or maintain User PHI within DenialTracker-controlled external billing, website, or subscription systems and does not ordinarily access claim-level PHI contained in the User’s Google Workspace environment.

Based on the Service’s present design and operating model, DenialTracker does not currently offer a Business Associate Agreement to customers.

Users must not intentionally transmit PHI to DenialTracker-controlled support, website, billing, or other external systems unless DenialTracker has expressly authorized a specific arrangement in writing.

Nothing in this Privacy Policy limits obligations that may apply directly to DenialTracker under applicable law.

9. Information DenialTracker Collects Outside Claim Processing

DenialTracker collects or processes limited non-claim information necessary to operate the business and provide the Service.

This may include:

DenialTracker may also process limited operational and security information such as request identifiers, timestamps, event types, error categories, security events, rate-limit activity, and similar technical information needed to operate and protect the Service.

DenialTracker’s billing systems may receive numerical or account-level usage information necessary to calculate subscription entitlements or usage-based charges. Such billing information is not intended to include patient names, claim contents, diagnosis information, procedure-level PHI, or the contents of 835 files.

Hosting, networking, security, and infrastructure providers may independently process information ordinarily associated with internet requests, such as network or device information, in accordance with their own systems and privacy practices.

10. Authentication Information

When a User accesses protected DenialTracker billing or subscription functionality, DenialTracker may receive a short-lived Google identity token.

The token is used to verify the User’s identity.

DenialTracker’s backend may derive limited identity information from the verified token, including the User’s Google subject identifier, verified email address, and hosted Workspace domain where available.

DenialTracker does not use or store the User’s Google password.

DenialTracker is designed not to log raw Google identity tokens or authorization headers in application logs.

11. Stripe and Payment Information

DenialTracker uses Stripe to process subscription, billing, payment, and billing-management functions.

Stripe may collect information such as name, email address, billing information, payment-method information, transaction information, and fraud-prevention information.

Stripe processes payment credentials according to Stripe’s own systems, terms, and privacy practices.

DenialTracker does not receive or store complete credit-card numbers or card security codes.

DenialTracker may receive or access limited billing information from Stripe, including:

DenialTracker may associate a Google account identifier with a Stripe customer or subscription so that billing resources correspond to the authenticated User or Customer.

12. Website Information

The DenialTracker website may collect information separately from the Google Workspace Add-on.

If a visitor submits a contact form or other website inquiry, DenialTracker may collect the visitor’s name, business or work email address, organization information, and message contents.

Visitors must not include PHI, patient information, 835 files, claim information, or other sensitive healthcare information in public website forms.

Information submitted through the website may be used to respond to inquiries, provide requested information, communicate with prospective customers, maintain business records, prevent misuse, and conduct sales or customer-support activities.

13. Website Analytics

DenialTracker currently uses Google Search Console to understand how the public DenialTracker website is discovered and performs in search results.

DenialTracker does not currently use Google Analytics or similar website analytics services that track visitor interactions across the DenialTracker website.

DenialTracker may introduce additional analytics or performance tools in the future. If DenialTracker begins using such services in a manner that materially changes information collected or processed through the website, this Privacy Policy will be updated accordingly and any notice, consent, or cookie controls required by applicable law will be implemented.

DenialTracker does not use website analytics to obtain or analyze patient claim information, 835 file contents, or PHI processed through the Google Workspace Add-on.

14. Cookies and Similar Technologies

The DenialTracker website may use cookies or similar technologies where necessary for website functionality, security, or performance.

If DenialTracker introduces analytics, advertising, or other technologies that require additional disclosures or consent, appropriate updates will be made to the website and this Privacy Policy.

Users may control cookies through browser settings and, where available, website consent or preference controls.

Disabling website cookies does not prevent claim processing within the DenialTracker Google Workspace Add-on.

15. Support Communications

If a User contacts DenialTracker for support, DenialTracker may collect the User’s name, email address, organization information, correspondence, and other information voluntarily included in the request.

Users must not send PHI, 835 files, patient names, claim records, screenshots displaying PHI, or other sensitive healthcare information to DenialTracker through ordinary support channels.

If DenialTracker receives PHI through an unintended support channel, DenialTracker may delete the information and request that the User resend the request after removing sensitive information.

Receipt of PHI contrary to this prohibition does not constitute authorization for the User to submit PHI through that channel or a representation that the channel is appropriate for PHI.

16. Marketing Communications

DenialTracker may use business contact information to send product announcements, feature updates, educational materials, promotions, discounts, conference information, and similar marketing communications where permitted by applicable law.

Recipients may unsubscribe using an available unsubscribe mechanism or by contacting DenialTracker.

Opting out of marketing does not prevent DenialTracker from sending transactional, billing, security, legal, or account-related communications necessary to administer the Service.

17. How DenialTracker Uses Information

DenialTracker may use information under its control to:

Claim-level healthcare information processed through the Add-on is not used by DenialTracker’s external billing systems for advertising or unrelated commercial profiling.

18. Sale and Sharing of Personal Information

DenialTracker does not sell PHI, claim information, Google Workspace claim data, or customer account information to data brokers or advertisers.

DenialTracker does not rent or trade patient claim information.

DenialTracker does not use claim-level PHI for behavioral advertising.

DenialTracker does not sell personal information or share personal information for cross-context behavioral advertising as those terms may be defined under applicable U.S. state privacy laws.

19. When Information May Be Disclosed

DenialTracker may disclose limited information to service providers that perform functions on DenialTracker’s behalf, such as payment processing, infrastructure hosting, website hosting, security, and related business operations.

These providers may include Google, Stripe, Render, Webflow, Google Search Console, and other providers reasonably necessary to operate DenialTracker.

DenialTracker may also disclose information where reasonably necessary to:

DenialTracker will not disclose Google Workspace user data in a manner inconsistent with applicable Google policies.

20. Google Workspace

Google independently provides and operates Google Workspace, Google Drive, Google Sheets, Gmail, Google Apps Script, authentication infrastructure, and related services.

Information processed through those services is also subject to the User’s relationship with Google, Google Workspace configuration, organizational policies, and applicable Google terms and privacy practices.

DenialTracker does not control Google’s independent processing of information.

21. Render

DenialTracker currently uses Render to host external backend infrastructure used for identity verification, billing operations, subscription validation, security controls, and related operational functions.

DenialTracker’s Render-hosted backend is not designed to receive 835 file contents or claim-level patient information.

Render may process technical information associated with hosting and network operations in accordance with its own practices.

22. Webflow

DenialTracker currently uses Webflow to host or operate portions of the public DenialTracker website.

Website visitors may therefore interact with infrastructure provided by Webflow.

Information submitted through website forms or processed as part of website operations may involve Webflow or related website infrastructure.

23. Security

DenialTracker uses administrative, technical, and organizational safeguards intended to protect information under its control.

These safeguards include authentication controls, restricted external-backend functionality, encrypted network transport, server-controlled billing configuration, input validation, security-related logging, access restrictions, and measures intended to prevent sensitive claim information from entering the external billing environment.

DenialTracker’s application logging is designed to avoid raw identity tokens, authorization headers, complete payment credentials, claim contents, and PHI.

No information system or internet transmission can be guaranteed to be completely secure. DenialTracker therefore cannot guarantee that unauthorized access, disclosure, alteration, or destruction will never occur.

24. Data Retention

DenialTracker retains personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, taking into account the nature and sensitivity of the information, security needs, accounting and tax requirements, dispute-resolution needs, applicable legal obligations, and applicable limitation periods.

Billing and transaction records may be retained as reasonably necessary for accounting, taxation, payment disputes, fraud prevention, and legal obligations.

Account and subscription information may be retained while a User maintains a relationship with DenialTracker and for a reasonable period afterward.

Security and operational records may be retained as reasonably necessary to investigate incidents, maintain system integrity, detect abuse, and document security activity.

Support communications and website inquiries may be retained as reasonably necessary to respond to Users, maintain business records, resolve disputes, and improve support.

Marketing contact information may be retained until it is no longer reasonably needed or until a User exercises an applicable opt-out or deletion right, subject to retention necessary to honor the opt-out.

DenialTracker does not maintain an external repository of User 835 files or claim-level patient records as part of its normal architecture.

25. Cancellation, Uninstallation, and Google Workspace Data

Canceling a DenialTracker subscription or uninstalling the Add-on does not automatically delete Google Sheets, 835 files, Gmail messages, or other information stored in the User’s Google Workspace environment.

That information remains under the User’s control and subject to the User’s Google Workspace settings and Google’s services.

Users are responsible for retaining, exporting, deleting, or otherwise managing their own Workspace files and records.

DenialTracker may retain limited non-PHI billing, account, security, support, usage, and legal records after cancellation as described in this Privacy Policy.

26. Privacy Requests

Depending on applicable law and the nature of information DenialTracker maintains, individuals may have rights to request access to, correction of, or deletion of certain personal information.

Users may also request information regarding DenialTracker’s handling of their information or opt out of applicable marketing communications.

Requests may be submitted to csnoke@denialtrackerapp.com.

DenialTracker may need to verify the identity and authority of the requester before fulfilling a request.

Certain information may be retained despite a deletion request where retention is reasonably necessary or legally permitted for billing, taxation, fraud prevention, security, dispute resolution, legal compliance, or other legitimate purposes.

Requests concerning claim information stored in Google Drive, Google Sheets, or Gmail ordinarily must be handled through the User’s own Google Workspace environment because DenialTracker does not maintain an external copy of those records.

27. U.S. State Privacy Rights

Residents of certain U.S. states may have additional privacy rights under applicable law, which may include rights relating to access, correction, deletion, portability, information about disclosures, or certain opt-outs.

The availability and scope of these rights depend on the applicable law and whether that law applies to DenialTracker or the processing activity.

Where required by applicable law:

Privacy requests may be submitted to csnoke@denialtrackerapp.com.

28. Children’s Privacy

DenialTracker is a business software product intended for authorized adult Users acting on behalf of healthcare practices, billing organizations, revenue cycle management organizations, and other businesses.

The Service is not directed to children under 18 and is not intended for children to create accounts or use independently.

The fact that a healthcare organization may use DenialTracker in connection with reimbursement records relating to pediatric patients does not make those patients Users of the DenialTracker Service.

29. United States Service

DenialTracker is presently offered for use by customers in the United States.

DenialTracker does not currently market the Service as a product specifically designed for organizations subject primarily to non-U.S. privacy regimes.

A person accessing the public website from outside the United States does so subject to applicable law and the limitations described in this Privacy Policy.

30. Business Transfers

If DenialTracker LLC is involved in a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, business records and information may be transferred as part of that transaction subject to applicable law.

To the extent information constitutes Google Workspace user data obtained through Google-authorized scopes, DenialTracker will not transfer that information as part of a merger, acquisition, financing, reorganization, or sale of assets except in accordance with applicable Google policies, including obtaining explicit prior User consent where required.

Any successor operating DenialTracker will remain responsible for information in accordance with applicable law and privacy commitments that continue to apply.

31. Changes to This Privacy Policy

DenialTracker may update this Privacy Policy as its Service, technology, vendors, business practices, or legal obligations change.

The revised Policy will identify its effective date.

Material changes may also be communicated through the website, Service, email, or another reasonable method.

Where applicable law requires additional notice or consent, DenialTracker will provide it.

32. Contact Information

Questions, privacy requests, or concerns regarding this Privacy Policy may be directed to:

DenialTracker LLC
Email: csnoke@denialtrackerapp.com
Website: https://denialtrackerapp.com

‍