Privacy Policy
This Privacy Policy explains what information Prospect 811 (“we,” “us”) collects when you use prospect811.com (the “Service”), how we use it, and the choices you have. It is part of our Terms of Service.
The short version: we collect what we need to run the Service: your account details, a session cookie, the working data you save, and server logs, plus your email address if you opt in to our mailing list. We don't sell your data, and inside the app there are no ads and no third-party analytics trackers. Our public marketing pages use the Meta pixel for advertising, described below.
1. Information We Collect
- Account information. Your email address, and (if you sign in with Google) your name and profile image as provided by Google. If you sign in with Apple, your name and email address as provided by Apple; if you choose Apple’s Hide My Email, the private relay address Apple generates becomes your account email. If you sign in by magic link, just your email.
- Session data. A session cookie that keeps you signed in, the IP address associated with your session, and the date your account last used the Service (kept on our own server; we use it to understand overall activity and to check in on inactive accounts).
- Your working content. The CRM data you choose to save in the Service: provider statuses, notes, contacts, qualified-lead flags, and territories. If you are on a team, your team’s manager can see your territories (their names and zip lists) and can assign territories to you. Managers can also assign specific providers to you; these appear in your My Providers list marked as assigned, and your statuses and notes on them remain yours to edit. What else a manager sees depends on how your account was created:
- Independent accounts (you created your account yourself, or accepted a team invite): your manager sees your pipeline and field activity only for the providers you explicitly share: their statuses, and the counts and dates of your visits, status changes, notes, and follow-ups for those providers. Your route days and mileage totals are visible, but not route names or stops. Managers can never read the contents of your notes, and you can share or un-share any provider at any time. Assigning a provider to you does not by itself share anything: an assigned provider’s status and your activity on it become visible to your manager only if you choose to share that provider, and your manager cannot see whether an assigned provider was already on your list.
- Managed accounts (created for you by your team’s manager): your manager can see all of the work you log in the account, including the contents of your notes. You are shown this disclosure the first time you sign in. If a managed rep leaves the team, the manager may reassign that account’s CRM records (statuses, notes, visits, and pending follow-ups) to another managed member of the same team; the departing account keeps its records. Independent accounts are never reassigned, exported, or copied at departure: an independent rep’s data leaves with them.
If a team stays over its paid seat count past a grace window, the manager’s team views (pipeline and activity roll-ups, territory and provider assignment, and invites) are paused until the team is back within its seats. This limits what a manager can see and never changes what we collect or what team members can access.
- Expense records (optional). If you use the expense log, we store the entries you save: date, amount, category, vendor, an optional tagged provider, and an optional note. Expense records are financial records private to your account: they are never visible to your team or its manager, regardless of account type, and appear only in your own reports and CSV exports. If you attach a receipt photo, we store the image with the entry and delete it when you delete the entry.
- Contract records (optional). If you use the contracts feature, we store the contract details you save (GPO or buying group, contract number, vendor, dates, segment restrictions, and item prices), and, if you upload a contract document (PDF or spreadsheet), the document file itself. Contract records are confidential business records private to your account: they are never visible to your team or its manager, never combined with other users’ data, and appear only in your own views and CSV exports. Deleting a contract deletes its uploaded document. If you upload a GPO membership roster, we store only the member rows inside the territory you pick (name, address, class of trade, parent organization, tier flags), never the roster file itself, with the same privacy: never visible to your team, never combined with other users’ data, deletable any time. Roster parsing happens entirely on our servers: roster contents are never sent to any third party.
- Doug conversations (optional). If you chat with Doug, our AI assistant, we store your conversations with your account (up to 30 chats) so you can pick them back up; you can delete any chat in the app at any time. We also keep server-side diagnostic logs of Doug’s turns for up to 90 days to fix problems and improve how Doug works, then delete them.
- Push notifications (iOS app, optional). If you install our iOS app and turn on territory alerts, we store the device push token Apple assigns (with its platform and app environment) so we can deliver those notifications, and we send notification content through the Apple Push Notification service. Notification text stays generic (for example, “Your territory brief is ready”) and never contains your CRM data or provider details. You can turn notifications off any time in iOS Settings; stored tokens are deleted with your account.
- Location (optional). If you pick “Current location” as a route start in Day Route, or use Near me now, your device sends its coordinates to our server to plan that route or run that search. If you save a route, its start and end points are saved with it. Location access is optional, asked for only when you use these features, and only while you are using the app.
- Server logs. Standard request logs (pages and endpoints accessed, timestamps, IP address) used for security, debugging, and capacity planning.
- Mailing list (optional). If you request our free guide or join our mailing list, we store the email address you enter, the signup time, the IP address it came from, and which page you signed up from. Every marketing email includes an unsubscribe link, and unsubscribing stops all marketing email. This list is separate from your account, and we never sell it.
- Billing information (paid accounts). Payments are processed by Stripe. We receive and store your Stripe customer ID, subscription plan, and payment status. We never see or store your full card number.
- Correspondence. Emails you send us for support.
We do not collect information about you from data brokers or other third-party sources, and the app itself contains no advertising or third-party analytics scripts. Our public marketing pages (the home, features, how-it-works, data, pricing, FAQ, comparison, guide, and interactive demo pages, the market pages under /markets, the top-providers directory pages under /top, and the free lookup tool pages under /tools) use the Meta pixel, a measurement script from Meta Platforms, Inc., to measure our advertising and build advertising audiences from visits to those pages. If you submit your email address in an opt-in form on one of those pages, the pixel also shares it with Meta in hashed (non-readable) form to improve match quality. Meta calls this advanced matching. The pixel runs only on those public pages, never inside the app itself, and it never sees the provider data you work with. You can limit how Meta uses this data through your Meta ad preferences. If you browse any of these pages inside our iOS app, the pixel is removed from the page we serve: no Meta pixel or other tracking script runs in the app.
2. How We Use Information
- To provide and operate the Service: signing you in, saving your work, and showing it back to you;
- To bill for paid subscriptions and manage your plan;
- To secure the Service: detecting abuse, enforcing seat limits, and investigating misuse;
- To fix problems and improve the Service using aggregate, non-identifying usage patterns;
- To send transactional email: login links, receipts, and important service or terms updates;
- To send account holders occasional product news about the Service: new datasets, new features, and tips for getting more out of it. You agree to these when you create an account. Every product-news email includes an unsubscribe link, and unsubscribing stops them without affecting your account. Beyond that, we do not send marketing email without your consent.
3. What We Share (and With Whom)
We do not sell or rent your personal information. We share it only with the service providers that make the Service run, and only for that purpose:
| Provider | Purpose | What they process |
| Google | Optional sign-in | Your Google account email, name, photo |
| Apple | Optional sign-in (Sign in with Apple) and iOS push notification delivery | Your Apple account email (or its private relay address) and name at first sign-in; device push tokens and generic notification content for iOS alerts |
| Resend | Login, transactional, product-news, and (if you opt in) mailing-list email | Your email address and message contents |
| Stripe | Payments | Billing details and payment method (held by Stripe) |
| Cloudflare | Network and DDoS protection | Request traffic, IP addresses |
| Mapbox | Drive-route optimization and road distances | Provider practice locations (public data), sent from our servers, not your identity or account details |
| OpenAI | Generating Doug’s replies | Your message to Doug, your rep profile (products, codes, territory), and the page you asked from, sent from our servers. Model training is disabled on this traffic. See “Doug and AI” below. |
| Anthropic | Receipt scanning and contract-document reading (optional): reading the amount, date, and vendor off a receipt photo, or the contract fields and item prices out of a contract document, when you choose to scan one | Only the receipt image or contract document itself, sent from our servers, not your identity, your account details, or any provider you tag. You review the extraction before anything is saved. |
| Esri | Map imagery (base tiles) | Map-tile requests from your browser (IP address); no account information |
| Your CRM (HubSpot, Zoho, or Salesforce) | Receiving the prospect lists you choose to push (see “CRM Integrations” below) | The lead fields you push, sent from our servers to your own CRM account at your direction. Your CRM processes this data under your agreement with them, not as our service provider. |
We may also disclose information if required by law, or to protect the rights, safety, or property of Prospect 811, our users, or the public. If Prospect 811 is involved in a merger, acquisition, or sale of assets, account data may transfer with the business; this Policy would continue to apply to it.
4. Doug and AI
Doug, the AI assistant inside the Service, answers questions using the same public Medicare data as the rest of the app, plus the working content you’ve saved. When you chat with him, your message (along with your rep profile and the page you asked from) is sent to our AI model provider (OpenAI) to generate the reply. Receipt and contract-document scanning use Anthropic the same way (see the table above).
- No model training. Neither we nor our AI providers use your data to train AI models. Model training is disabled on this traffic.
- Human review, disclosed. Our team reviews individual Doug conversations to fix problems and make him better. Improving Doug this way means refining the instructions he follows: it never means training an AI model, and your data never appears in anyone else’s account.
- No shared memory. Doug has no memory shared between accounts. What he knows about you comes from your own account’s data, at the moment you ask.
- You confirm every write. Doug never changes your CRM records on his own: he proposes, and nothing is saved until you tap to confirm.
- Retention. Your chats are stored with your account (up to 30) and you can delete them in the app; server-side diagnostic logs of Doug turns are deleted after 90 days.
5. CRM Integrations (HubSpot, Zoho, Salesforce)
On the Team tier you can connect the Service to your own CRM and push your prospect lists into it as contacts or leads. Connecting uses OAuth: you sign in to your CRM and approve the access yourself, and we store the resulting access credentials encrypted on our servers. We never see or store your CRM password.
- What we send, and when. Data moves only when you click push. A push sends the provider records you selected (name, practice, address, phone, specialty, NPI, and your Prospect 811 status) from our servers into your connected CRM account. Repeat pushes update the same records instead of creating duplicates, keyed on NPI where your CRM has our NPI field.
- What we read from your CRM. Only what the integration needs to operate: your account identity at connect time, the fields and status values available in your CRM (to set up the status mapping and detect what your account supports), and the per-record results of pushes we make (to confirm each write landed). We do not sync, browse, export, or retain your other CRM data.
- Salesforce specifics. Connecting Salesforce authorizes our app in your company's Salesforce org with the
api and refresh_token scopes. Pushes create or update Lead records as you, under your org's own permissions, sharing rules, and validation rules; they also write your mapped status into the standard Lead Status field, and into the Prospect 811 fields if your admin installed our package (see the Salesforce admin guide). Your Salesforce admin can see, block, or revoke the app at any time from Salesforce Setup.
- Per-customer isolation. Data from a connected CRM is used only for your account's own connection. We never combine CRM data across customers, use it for benchmarks or profiles, or use it to train AI models.
- Disconnecting. You can revoke the integration's access at any time from your CRM's own settings (in Salesforce, from Setup; in HubSpot or Zoho, from their connected-apps pages), which cuts off its access to your CRM. The credentials we hold are stored encrypted, and we delete them on request: email [email protected] from your account email (see section 9). Records already pushed live in your CRM under your control; deleting them there is up to you.
6. About the Provider Data in the Service
The healthcare-provider information displayed in the Service (names, NPIs, practice addresses, phone numbers, billing statistics) comes from public datasets published by the U.S. government, including CMS Medicare provider utilization files and the NPPES registry. It is professional/business information about healthcare providers, published for public use: it is not data we collected about our users, and it contains no patient information.
7. Cookies
We use a first-party, HTTP-only session cookie to keep you signed in. It is essential to the Service and is deleted when you log out. If you reach the Service through a referral link, a shared link, one of our free tools, or a link in one of our emails, we may also set a first-party, HTTP-only attribution cookie: it holds only a short tag identifying the link, page, or referrer that brought you here (for example “digest”), never personal data; it expires after 30 days; it is read only by our own server, to record where a signup or purchase came from; and it is never shared with an ad network or any other third party. Inside the app we do not use advertising, tracking, or third-party cookies. Our public marketing pages set Meta pixel cookies for advertising measurement, as described in section 1.
8. Data Retention
- Account information and Your Content are kept while your account is active.
- Sessions expire after 30 days; expired sessions and used login links are purged routinely.
- Server logs are retained for a limited period for security and debugging, then deleted.
- Doug chats are kept with your account until you delete them; server-side diagnostic logs of Doug turns are deleted after 90 days.
- CRM connection credentials are stored encrypted, and we delete them on request, including as part of an account-deletion request (see section 9). Revoking the integration from your CRM's side cuts off its access to your CRM whether or not you also ask us to delete the stored credentials.
- Billing records are retained as required for tax and accounting purposes.
9. Your Rights and Choices
You can access the data you've stored in the Service at any time by signing in. To request a copy of your data, correct your account information, or delete your account and all associated data, email [email protected] from your account email. We respond to verified requests within 30 days. Depending on where you live (e.g., California, the EU/UK), you may have additional statutory rights. We honor access, correction, and deletion requests from all users regardless of location.
10. Security
All traffic to the Service is encrypted over HTTPS. Sessions use secure, HTTP-only cookies. Access to production data is limited to those who operate the Service. No system is perfectly secure. If we learn of a breach affecting your personal information, we will notify you as required by law.
11. Children
The Service is a business tool for adults. It is not directed to anyone under 18, and we do not knowingly collect information from children.
12. Changes to This Policy
If we make material changes, we will notify you in the app or by email before they take effect. The “Last updated” date at the top reflects the current version.
Contact
Privacy questions or requests: [email protected]
← Back to Prospect 811 · Terms of Service · Refund Policy