Privacy
Privacy Policy
This Privacy Policy explains what information PrefCA collects, how we use it, and the choices you have. PrefCA is built so surgical preference cards describe procedures, supplies, and instruments — not patients — which keeps the amount of personal information we handle deliberately small. We review this policy at least once a year and update the date below when we make changes.
Last updated: September 11, 2026
This page is written in plain language to explain how PrefCA works. It is a starting version that is being finalized with legal counsel and may be updated. It is not legal advice, and using PrefCA does not, by itself, satisfy any legal or regulatory obligation you may have. For a countersigned agreement, Business Associate Agreement (BAA), or Data Processing Agreement (DPA), contact legal@prefca.com.
1. Who we are and how to read this policy
PrefCA is a service operated by PrefCA LLC, an Ohio limited liability company. PrefCA is a platform that surgeons and surgical facilities use to build, manage, and share surgical preference cards — the lists of instruments, supplies, and positioning used to set up for an operation.
This policy covers people we interact with directly: account holders and users, billing contacts, prospective customers, and visitors to our website. It explains how we handle the personal information we control.
It also explains a second, important relationship. When a facility or practice uses PrefCA, the content they put into the platform — preference cards, master item lists, and uploaded photos or documents — belongs to that organization. For that content, PrefCA acts as a service provider, handling it on the organization's behalf and only as their agreement with us allows. Each organization's data is scoped to that organization, and the organization, not PrefCA, decides who within it may see or edit that content.
If your information appears inside an organization's PrefCA workspace because your employer or practice uses PrefCA, that organization controls that data. Privacy requests about it should generally go to them, and we will assist them as their service provider.
2. Information we collect
We collect the following categories of information:
- Account and identity information — your name, work email, work phone, role or title, the organization or facility you belong to, and your login credentials.
- Billing information — handled through our third-party payment processor. We receive limited details such as your plan, billing contact, and a payment token or the last four digits of a card; we do not store full payment card numbers.
- Product content you and your organization create — preference cards, master items (instruments, supplies, equipment, medications, implants), comments, and the photos, documents, or videos you upload to a card. We handle this content on your organization's behalf.
- Usage and device information — IP address, device and browser type, log data, the pages and features you use, and information from cookies and similar technologies (see the Cookies section below).
- Communications — messages you send to support, feedback, and survey responses.
PrefCA preference cards are built to describe procedures, supplies, and instruments — not patients. The product does not ask for and is not intended to store patient names, medical record numbers, or other patient identifiers, and users are instructed not to enter them. We design the product to keep patient information out, but we cannot guarantee a user will never type something they shouldn't, so keeping protected health information (PHI) out of PrefCA is also your responsibility.
We do not intentionally collect sensitive personal information (as defined by California law), such as health, biometric, or precise-location data, beyond what is described above.
3. Where we get your information
We collect information from a few sources:
- Directly from you — when you sign up, fill in your profile, or contact support.
- From your organization — when an administrator provisions or invites users or assigns access.
- Automatically — through your use of the service, such as log, device, and usage data, and cookies.
- From our service providers — for example, our payment processor returns the status of a payment.
4. How we use information
We use information to:
- Provide, operate, maintain, and secure the service.
- Sign you in and enforce the access controls and permissions that scope data to your organization.
- Process subscriptions, billing, and trial access.
- Provide support and respond to your questions.
- Send you service messages about your account, security, and billing, and — where permitted — product or marketing messages you can opt out of.
- Improve and develop the product, including through aggregated and de-identified analytics.
- Power AI-assisted features. Some inputs you provide may be processed by AI providers acting as our sub-processors to deliver a feature; you stay in control, and suggestions are editable.
- Detect, prevent, and respond to fraud, abuse, and security incidents.
- Meet our legal obligations and enforce our agreements.
We use your information for the purposes described here and compatible purposes. We do not use it for unrelated purposes without telling you.
7. Sale, sharing, and targeted advertising
PrefCA does not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA). Because we do not sell or share in that sense, you do not need a separate "Do Not Sell or Share My Personal Information" link to stop it — there is nothing of that kind to opt out of.
We do not knowingly sell or share the personal information of anyone under 16, and we do not use automated decision-making or profiling that produces legal or similarly significant effects about you.
Mobile information and SMS consent. If you opt in to text messages from PrefCA, your phone number, your SMS opt-in status, and the consent you gave are used only to send you those messages and to honor your opt-out. We do not sell them, and we do not share them with third parties or affiliates for their marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third party. See our SMS Messaging Terms at https://app.prefca.com/messaging-terms.
8. How long we keep information
We keep personal information for the life of your account — as long as your account is active and we are providing the service to you — and we delete it on request. To make a deletion request, contact privacy@prefca.com; we may need to verify your identity first.
Some information is kept longer where the law requires it or to meet legitimate needs — for example, records needed for tax, accounting, security, fraud-prevention, or dispute-resolution purposes. Backups also age out on a normal cycle rather than disappearing the instant data is deleted, so full deletion can take some time. De-identified or aggregated data, which is no longer personal information, may be kept.
For content your organization created, deletion is generally directed by the organization that owns it, and we delete or return that content according to the customer agreement when an account ends.
9. How we protect information
We use reasonable and appropriate technical and organizational measures to protect personal information, including:
- Encryption of data in transit, and at rest where applicable.
- Access controls and authentication, with data scoped to each organization.
- Least-privilege internal access, logging, and monitoring.
- Security requirements for the vendors we rely on.
The product's design is itself a privacy measure: because preference cards are built to exclude patient identifiers, there is far less sensitive data in the system to begin with.
No method of transmitting or storing data is completely secure, so we cannot guarantee absolute security. If a security incident affects your information, we will notify affected parties and our customers as required by applicable law and our agreements. To report a security concern, contact security@prefca.com.
10. Your privacy rights
Depending on where you live, you may have rights to access, correct, or delete the personal information we hold about you, to receive a copy of it, and to not be discriminated against for exercising these rights. California residents have these rights under the CCPA/CPRA, and we extend comparable rights to residents of other U.S. states with their own privacy laws.
To exercise a right, email privacy@prefca.com. We may ask for information to verify your identity, and you may use an authorized agent where the law allows. We will respond within the timeframe the law requires — generally within 45 days, with the possibility of an extension and notice if a request is complex.
If your information lives inside a customer organization's workspace (for example, because your employer uses PrefCA), we will refer your request to that organization, which controls that data, and assist them as their service provider. We handle requests directly for the information we control, such as account, billing, and website-visitor data.
11. PHI, our HIPAA-aware posture, and BAAs
PrefCA is HIPAA-aware. That means we designed the product to keep patient information out of it and we follow good privacy and security practices. We describe these as practices, not as a certification: there is no HIPAA certification, we do not claim to meet HIPAA on your behalf, and using PrefCA does not, by itself, satisfy your organization's HIPAA obligations.
Because preference cards are built to describe procedures and supplies rather than patients, and users are instructed not to enter patient identifiers, PrefCA generally does not receive or store protected health information (PHI) in the ordinary course, and so generally does not act as a HIPAA business associate for that content.
Some facilities require a Business Associate Agreement (BAA) as a contractual safeguard even where PHI is not expected. We offer a BAA to facilities on request — contact legal@prefca.com or security@prefca.com.
You are responsible for not entering PHI into PrefCA and for your own obligations as a covered entity or business associate. PrefCA does not assume your HIPAA obligations and does not guarantee regulatory compliance on your behalf.
12. Children's information
PrefCA is a professional tool for healthcare professionals and facilities. It is not directed to children under 13, and it is not intended for anyone under 18. We do not knowingly collect personal information from children. If we learn that we have, we will delete it — please contact privacy@prefca.com to report a concern.
13. Where your information is processed
PrefCA is based in the United States, and we process and store personal information in the United States and wherever our infrastructure providers operate. The service is intended for users in the United States. If you use PrefCA from outside the United States, your information will be transferred to and processed in the United States, which may have different data-protection laws than your country.
Business customers with cross-border or other regulatory obligations can request a Data Processing Agreement — contact legal@prefca.com.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will change the "Last updated" date above, and we will tell account holders about significant changes by email or in the app. We review this policy at least once a year. Please check back periodically.
15. Contact us
PrefCA LLC is governed by the laws of the State of Ohio, USA. Reach the right team:
- Privacy questions and rights requests — privacy@prefca.com
- Security concerns and incident reports — security@prefca.com
- BAA, DPA, and legal questions — legal@prefca.com
- Product help — support@prefca.com