Schedulign

Consumer Health Data Privacy Policy

Effective September 30, 2026

This policy describes how Schedulign LLC (“Schedulign”) collects, uses, shares and protects consumer health data, as Washington's My Health My Data Act (RCW 19.373), Nevada's consumer health data law (NRS 603A.400 to 603A.550) and similar laws in other states, such as Connecticut's, require. “Consumer health data” is personal information that is linked or reasonably linkable to you and that identifies your past, present or future physical or mental health status. Under these laws it can include the fact that you booked a session with a business that helps people assess, measure, improve or learn about their physical or mental health.

1. Information a business collects through Schedulign

Schedulign provides booking pages, intake forms and signed documents to businesses. When you book with a business, answer its booking questions or intake form, or sign its document, that business decides what to ask and why. That business is responsible for that information, and Schedulign processes it only on the business's behalf and on its instructions, under a contract that forbids any other use — as its processor.

  • That business's own consumer health data privacy policy applies to that information. A business that has one links it on its booking pages, intake forms and waivers.
  • To exercise your rights over that information, contact the business: reply to any email it sent you, or use the contact details on its booking page. You can also withdraw your consent to an intake form at any time from the form's link, which deletes the answers you sent through that link and tells the business.
  • If you ask Schedulign about information a business holds, Schedulign passes your request to that business within 5 business days and helps the business answer it.

2. Consumer health data Schedulign collects for its own purposes, and how it is used

Schedulign does not set out to collect consumer health data for its own purposes. It can receive some in these ways only, and uses it only as described:

  • Messages you send: when a support email or a problem report you send includes health information, it is used only to answer you and to fix the problem.
  • Security records: IP addresses kept for up to one day and one-way hashes of email addresses in rate-limit records, and server logs, which, together with the page a request was for, could suggest that you sought a health or wellness service. They are used only to keep the service secure, to prevent and investigate fraud and abuse, and to find and fix errors.

Schedulign does not use consumer health data for advertising, to build profiles, to make decisions about you, or to train artificial intelligence or machine-learning models, and it does not combine one business's information with another's.

3. Where it comes from

  • From you: when you book, answer a business's questions or forms, sign its documents, or write to Schedulign.
  • From the business you book with: when it enters or imports your details, or keeps notes about your sessions.
  • From your browser or device: the security records described above.

4. Consumer health data Schedulign shares, and with whom

Schedulign does not sell consumer health data, and does not share it with third parties or affiliates; Schedulign has no affiliates. It discloses it only:

  • To the business you chose to book with or send it to, because you asked for that business's service.
  • To the processors that run Schedulign, under contracts that limit them to doing so: Railway (hosting and the database), GitHub (encrypted backups and scheduled jobs), Resend (email delivery), Sentry (error monitoring, set up so that a report never carries what a form sent) and Google Workspace (Schedulign's support mailbox). Stripe processes payments for businesses and receives no intake answers.
  • When the law requires it, such as under a valid court order.

Third parties and affiliates with which Schedulign has shared or sold consumer health data: none.

5. How it is processed and protected

  • All traffic is encrypted in transit with TLS, and data is encrypted at rest.
  • Intake form answers are encrypted with AES-256-GCM before they are stored.
  • Inside a business, intake answers reach only the owner, its admins and the team members it allows, and each opening of them is recorded. Schedulign's staff console never shows them, and access to production systems is limited to authorized personnel who need it.
  • Deleted data leaves the live database at once and Schedulign's encrypted backups within 30 days.
  • Data is stored in the United States.

6. Tracking by third parties

No third party collects consumer health data about you over time and across different websites or online services when you use Schedulign: its pages load no analytics, advertising or tracking scripts, pixels or cookies. A business may show a logo or photo hosted on another website; your browser fetches that image from that website, as it does any image on the web.

7. Your rights

Wherever you live, you can ask Schedulign to:

  • Confirm whether it collects, shares or sells your consumer health data, and give you access to it, with a list of all third parties and affiliates with which it was shared or sold and an email address or other online way to contact each.
  • Let you review your consumer health data and correct it.
  • Stop collecting, sharing or selling it, and accept the withdrawal of your consent to its collection and sharing.
  • Delete it. Schedulign deletes it from its live systems at once and from its encrypted backups within 30 days, and tells the processors it disclosed it to, which must delete it too.

To make a request, email admin@schedulign.com with “Health data request” in the subject, or write to Schedulign LLC, 23312 77th Ave SE, Woodinville, WA 98072, United States. You don't need an account. Schedulign confirms that you control the email address involved, may ask for information it needs to confirm who you are, and may accept a request from someone you authorize in writing. Schedulign answers within 45 days of receiving your request; if more time is reasonably necessary, it may extend that once by 45 days, telling you why within the first 45 days. Requests are free up to twice in any 12 months; a request that is manifestly unfounded, excessive or repetitive may be declined or carry a reasonable fee, and Schedulign must show why. Schedulign does not discriminate against anyone for exercising these rights.

8. Appeals

If Schedulign declines to act on your request, you can appeal by replying to its answer, or by emailing admin@schedulign.com with “Appeal” in the subject. Schedulign answers your appeal in writing within 45 days, explaining what it did or did not do and why. If your appeal is denied, you can contact the Washington State Attorney General at https://www.atg.wa.gov/file-complaint or the Nevada Attorney General at https://ag.nv.gov.

9. Sale and geofencing

Schedulign does not sell consumer health data. Schedulign does not collect precise location information, and it does not use a geofence — a virtual boundary around a place — to identify or track anyone, to collect consumer health data, or to send anyone messages or advertisements.

10. Changes to this policy

When this policy changes, the new version is posted here with a new effective date. Before a material change takes effect, Schedulign emails its account holders and posts a notice on this page. Schedulign does not collect, use or share consumer health data in a way, or for a purpose, this policy does not disclose without disclosing it here first and getting your consent.

11. Contact

Schedulign LLC, 23312 77th Ave SE, Woodinville, WA 98072, United States

admin@schedulign.com

See also the Privacy Policy and the Terms of Service.