Last updated: August 1, 2026 · Version: 1
1. Scope and the roles we play
This Platform Privacy Policy (the "Policy") explains how Stack Systems Inc. dba Stack PT, a Delaware corporation ("Stack PT," "we," "us," or "our"), collects, uses, and discloses information when a Practice, Practitioner, Team Member, Patient, Responsible Party, or other authorized user uses the Stack PT web application, mobile applications, and related services (collectively, the "Services").
This Policy is a notice, not a contract. The Terms of Service and, for a Practice, the Business Associate Agreement (the "BAA") govern use of the Services. If this Policy conflicts with the BAA as to the use or disclosure of protected health information, the BAA controls. Capitalized terms not defined in this Policy have the meanings given in the Terms.
Patient information is controlled by the Practice
The Practice that invites a Patient to the Services provides the Patient's care, controls the Patient's clinical record, and determines how that record is used and disclosed. When Stack PT creates, receives, maintains, or transmits protected health information ("PHI") for a Practice, we do so as that Practice's Business Associate under the BAA and applicable law. We are not the Patient's health-care provider.
Accordingly, a Patient who wants to access, correct, amend, obtain a copy of, or ask about their clinical record or PHI should contact their Practice. If Stack PT receives such a request directly, we will direct the Patient to the Practice.
We also process certain information in our own capacity, such as account, security, support, billing, and device information, to operate and protect the Services. This Policy describes both roles and does not alter the Practice's responsibility for its own privacy notice or legal obligations.
This Policy does not cover the Marketing Site
This Policy does not govern visitors to stackpt.app or another Stack PT marketing page that links to our Marketing Site Privacy Policy. That separate notice covers demos, early-access requests, and other prospect or marketing interactions. Do not submit patient or health information through a marketing form.
2. Information We Collect
"Personal Information" means information that identifies, relates to, describes, or can reasonably be linked to an individual or household. The information we collect depends on the role you have, the Services you use, and the features your Practice enables.
Information provided through the Services
We may collect the following categories of Personal Information.
- Account, identity, and professional information, such as name, email address, telephone number, account credentials and authentication data, profile photo, professional role, Practice affiliation, and, where applicable, licensure, practice, or billing information.
- Patient, care, and record information, such as contact and demographic information, appointments, intake forms, clinical notes, treatment plans, exercise programs, outcomes, secure messages, documents, and other information a Practice or Patient adds to the Services. This information may be PHI.
- Patient Content and recordings, such as videos, images, audio recordings, voice, exercise-performance recordings, transcripts, attachments, and text a Patient, Practice, or Team Member uploads, records, or generates through the Services. This information may be PHI.
- Payment and transaction information, where billing or payment features are enabled, such as invoices, charges, payment status, refunds, packages or memberships, payment-method information, and transaction identifiers. Payment card information is processed through the payment processor for the applicable feature.
- Communications, support, and feedback, such as the content of messages, support requests, survey responses, and feedback you send to us or through the Services.
Information collected automatically
When you access the Services, we and service providers acting on our behalf may collect:
- Device, log, and diagnostic information, such as IP address, browser type, operating system, device type, app version, identifiers, language and time-zone settings, dates and times of access, pages or screens viewed, actions taken, referring and exit URLs, and error, crash, and performance information; and
- Approximate location information inferred from an IP address. We do not use precise location information unless we give a separate notice at the time we collect it.
We use cookies, local storage, SDKs, log files, and similar technologies as described in Section 7.
Information from Practices, other users, and connected services
We may receive information about you from a Practice, its Team Members, a Responsible Party, or another user who is authorized to provide it. For example, a Practice may create a Patient profile, schedule an appointment, invite a Team Member, or add care-related information to a Patient record.
If you choose to connect a third-party account or integration, we receive the information that the connected service makes available under the permissions you grant. This may include basic account and authentication information from Google Sign-In and, where a Practice or user enables and authorizes a Google, Gmail, Google Calendar, Apple, Microsoft, payment, telehealth, or other integration, the information needed to provide that integration. The information we receive depends on the integration and its permissions and may include email addresses, messages and message metadata, calendar events, contacts, availability, and transaction information.
We do not use Google user data for advertising.
Google Workspace data has additional limits. If we receive information from a Google Workspace API, including the Gmail or Google Calendar APIs, our use of that information will comply with the Google API Services User Data Policy, including its Limited Use requirements. In particular, we will not use that data to create, train, or improve a machine-learning or artificial-intelligence model other than a personalized model used for the applicable user's requested user-facing feature, to the extent Google permits that use.
3. How We Use Information
We use Personal Information, including PHI where the BAA and applicable law allow, to:
- create and administer accounts; authenticate users; provide role-based access; and provide the Services requested by a Practice or user;
- support care-related workflows selected by a Practice, such as patient access, scheduling, appointments, messages, forms, clinical documentation, exercise programs, billing, and payments;
- process transactions, prevent payment fraud, provide support, respond to questions, and communicate about account, security, billing, and service matters;
- operate, maintain, troubleshoot, secure, monitor, and improve the Services;
- detect, investigate, and prevent security incidents, fraud, abuse, and other harmful or unlawful activity;
- comply with law, legal process, and professional or regulatory obligations; enforce our agreements; and establish, exercise, or defend legal claims; and
- carry out another purpose disclosed at the time of collection or authorized by the applicable user or Practice.
Improving the Services and artificial intelligence
Under the BAA, Stack PT may use PHI to operate, evaluate, maintain, secure, improve, and develop the Services, including to develop, train, test, validate, and improve algorithms, models, features, and clinical content that comprise or support the Services.
We do not use PHI to market, sell, or develop a product or service outside the Services, including a product offered under a different brand or for a different profession. We do not disclose PHI for these improvement activities except to Subcontractors that are bound to protect it under the BAA. We apply the minimum-necessary standard to these uses.
The Services may generate or assist with clinical documentation, exercise content, or other outputs. Those tools support the Practice; they do not provide care or replace a Practitioner's independent professional judgment.
De-identified and aggregated information
We may de-identify PHI in accordance with applicable law and the BAA. Once information is properly de-identified, it is no longer PHI and may be used or disclosed for lawful purposes, including analytics and improvement of our products and services.
Where permitted by the BAA, we may also use PHI to provide Data Aggregation services for a Practice's health-care operations. In that case, results are provided only to the covered entities whose PHI was aggregated and only about their own health-care operations; this does not permit us to disclose one Practice's PHI to another Practice.
4. How We Disclose Information
We may disclose Personal Information as follows:
- To the Practice and its authorized users. We make Patient and Practice information available to the Practice, Practitioners, Team Members, and Responsible Parties that the Practice authorizes, according to the permissions configured in the Services.
- To Patients and Responsible Parties. We make information available to a Patient or Responsible Party where the Practice has enabled or authorized that access.
- To service providers and Subcontractors. We use providers that help us host, store, secure, support, maintain, process payments for, communicate about, analyze, and provide the Services. Where a provider creates, receives, maintains, or transmits PHI for us, it is a Subcontractor and is bound by a written agreement with protections required by the BAA.
- To connected services at a user's or Practice's direction. When a Practice or authorized user connects an integration, we may send information to that service as directed through the integration. The Practice is responsible for deciding whether the connection may receive PHI and, where required, for having an appropriate agreement with that service.
- For legal, safety, and enforcement reasons. We may disclose information to comply with applicable law, a valid legal process, or a government request; to protect the rights, safety, and property of Stack PT, users, or others; to investigate fraud or a security incident; or to enforce our agreements.
- In a corporate transaction. We may disclose or transfer information in connection with a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law and the BAA.
- With consent or at your direction. We may disclose information where you ask us to do so or otherwise consent, subject to the Practice's authority over Patient records and PHI.
We do not sell PHI or use or disclose PHI for marketing except as permitted by the BAA and applicable law. We do not publish a public list of Subcontractors; a Practice may request the information available under the BAA.
5. Your Choices and Privacy Requests
Patient records and PHI
The Practice controls Patient records. If you are a Patient or Responsible Party and want to access, correct, amend, obtain, delete, or ask a question about a Patient record or PHI, contact the Practice that invited you to the Services. The Practice determines whether and how to act on the request under applicable law. Stack PT will support the Practice as required by the BAA.
Patient access to the Services derives from the Practice's invitation and may end when the Practice revokes it or its agreement with Stack PT ends. This does not change the Practice's obligations to retain or provide access to clinical records.
Account, communication, and connected-account choices
You may update certain account information and notification preferences through the Services. You can opt out of marketing emails using the unsubscribe link in the email and of marketing text messages by replying STOP. You may not opt out of essential account, security, billing, or care-related communications while you use the Services, although channel-specific settings may be available.
You may disconnect a connected account through the relevant Service setting or the connected service's controls. Disconnecting stops future access through that connection; it does not delete information already processed or retained as described in this Policy, the BAA, or applicable law.
To request deletion of Google user data that Stack PT retains, contact us at legal@stackpt.app. We will address the request as required by applicable law, the BAA, and the Google API Services User Data Policy.
U.S. state privacy rights
Depending on where you live and the law that applies, you may have rights regarding Personal Information that Stack PT holds in its own capacity, such as rights to request access, correction, deletion, or information about our processing, or to opt out of certain processing. These rights may not apply to PHI or to information we process solely on a Practice's behalf.
To make a request, email legal@stackpt.app with the subject line "Privacy Request." We may ask for information needed to verify your identity and authority to make the request. Where applicable law permits, an authorized agent may make a request for you; we may verify both the agent's authority and your identity. If we deny a request for which applicable law provides a right to appeal, we will tell you how to appeal.
6. Retention and Security
We retain Personal Information for as long as reasonably necessary to provide the Services, maintain security and records, meet legal obligations, resolve disputes, and enforce our agreements. The period depends on the nature of the information, the role in which we process it, and the applicable legal and operational requirements.
Clinical-record retention is the Practice's responsibility. After a Practice's agreement ends, we make the Practice's data available for export for the period specified in the Terms, currently sixty-five (65) days, and then handle PHI as required by the BAA. We may retain information where the BAA or applicable law permits or requires retention, including properly de-identified information.
We use reasonable administrative, technical, and organizational safeguards designed to protect Personal Information. No system or transmission is perfectly secure, so we cannot guarantee absolute security.
7. Cookies, Local Storage, and Similar Technologies
We and service providers acting on our behalf use cookies, local storage, SDKs, log files, and similar technologies to authenticate users, keep the Services working, preserve settings, protect accounts, understand performance and errors, and analyze use of the Services. We do not use platform cookies or similar technologies for cross-context behavioral advertising.
Most browsers and devices let you remove or block some cookies or similar technologies. Controls vary by browser and device, and blocking them may prevent some Service features from working correctly. If a universal opt-out signal or other preference mechanism becomes applicable to the Services under state law, we will provide and honor it as required.
8. Children and Minor Patients
The Services may be used by minor Patients. Stack PT does not independently verify a Patient's age or parental authority. The Practice is responsible for identifying minor Patients and obtaining the parent or guardian consent required for the minor's use of the Services and collection of the minor's information, unless applicable law permits the Practice to provide care or services to that minor without that consent.
If you are a parent or guardian with a question about a minor Patient's information or access to the Services, contact the Practice. This section does not change any obligation Stack PT may have under applicable law.
9. Third-Party Services
The Services may link to or integrate with third-party websites, applications, and services. Their privacy practices are governed by their own notices and terms, not this Policy. We are not responsible for those third parties' privacy or security practices.
10. Changes to This Policy
We may update this Policy to reflect changes in the Services, our practices, or applicable law. We will post the updated Policy and revise the "Last updated" date above. If a change requires additional notice under applicable law or the Terms, we will provide that notice.
11. Contact Us
For questions about this Policy or Stack PT's platform privacy practices, contact us at legal@stackpt.app. For technical or account support, use support@stackpt.app or the support channel available in the Services.