Privacy Policy
Last Updated: November 16, 2025
At HWARP (operated by Caretrics), we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our competitive intelligence service.
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, business name, payment information
- Report Inputs: Your clinic name, website URL, Google Business Profile URL, location, competitor information
- Communications: Email correspondence, support requests, feedback
1.2 Automatically Collected Information
- Usage Data: Pages viewed, features used, time spent, clickstream data
- Device Information: IP address, browser type, operating system, device identifiers
- Cookies: Session cookies, authentication tokens, analytics cookies
1.3 Public Data We Analyze
For report generation, we collect publicly available data about businesses you specify:
- Google Business Profile information (ratings, reviews, categories)
- Website content and metadata
- Social media profiles and activity
- Online reviews and testimonials
We only access data that is publicly available and respect robots.txt and terms of service.
2. How We Use Your Information
We use collected information for:
- Service Delivery: Generate competitive intelligence reports, process payments
- Communication: Send report delivery emails, updates, support responses
- Improvement: Analyze usage patterns, improve algorithms, fix bugs
- Marketing: Send promotional emails (with opt-out option)
- Legal Compliance: Comply with laws, prevent fraud, enforce Terms of Service
3. How We Share Your Information
We do NOT sell your personal information. We may share data with:
3.1 Service Providers
- Stripe: Payment processing
- Resend: Email delivery
- Supabase: Database hosting
- Vercel: Application hosting
- OpenAI: AI analysis (anonymized data only)
- Firecrawl: Web data extraction
All service providers are contractually obligated to protect your data and use it only for specified purposes.
3.2 Legal Requirements
We may disclose information if required by law, court order, or to protect our rights, property, or safety.
3.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.
4. Data Retention
- Account Data: Retained while your account is active, plus 90 days after deletion
- Reports: Stored indefinitely for your access; deleted upon request
- Payment Records: Retained for 7 years for tax and legal compliance
- Analytics Data: Aggregated and anonymized after 2 years
5. Your Privacy Rights
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update inaccurate or incomplete information
- Deletion: Request deletion of your account and data
- Opt-Out: Unsubscribe from marketing emails
- Portability: Receive your data in machine-readable format
- Object: Object to processing of your data for certain purposes
To exercise these rights, contact us at privacy@hwarp.com.
6. Cookies and Tracking
We use cookies for:
- Essential Cookies: Authentication, security, session management (required)
- Analytics Cookies: Google Analytics for usage tracking (optional)
- Marketing Cookies: UTM parameters for ad attribution (optional)
You can control cookies through your browser settings. Disabling cookies may affect functionality.
7. Data Security
We implement industry-standard security measures:
- Encryption in transit (TLS/SSL) and at rest (AES-256)
- Secure authentication with bcrypt password hashing
- Row-level security (RLS) in database
- Regular security audits and penetration testing
- Limited employee access on need-to-know basis
No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
8. Children's Privacy
HWARP is not intended for children under 13. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your data in compliance with applicable laws.
10. GDPR Compliance (EU Users)
If you are located in the European Economic Area (EEA), you have additional rights under GDPR:
- Right to be informed about data processing
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Rights related to automated decision-making and profiling
Our lawful basis for processing is consent and contractual necessity (service delivery).
11. CCPA Compliance (California Users)
California residents have rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to opt-out of sale of personal information
- Right to deletion of personal information
- Right to non-discrimination for exercising CCPA rights
We do NOT sell your personal information.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or prominent notice on our website. Your continued use after changes constitutes acceptance.
13. Contact Us
For privacy-related questions or to exercise your rights:
Email: privacy@hwarp.com
Support: support@hwarp.com
Website: hwarp.com
By using HWARP, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your information as described herein.