Reveon Health — Privacy Policy

Effective Date: September 4, 2026
Legal Entity: Reveon Edge, LLC
Email: support@reveonhealth.com

1. Scope

This Privacy Policy explains how Reveon Edge, LLC ("Reveon," "Reveon Health," "we," "us," or "our") collects, uses, discloses, and protects Personal Information when you visit reveonhealth.com (the "Site"), submit a report-order or request form, purchase or receive a report or related deliverable, use our login-based software or analytics offering (the "Portal"), contact us, or otherwise interact with us. Collectively, these are the "Services."

"Personal Information" means information that identifies, relates to, describes, or could reasonably be linked with an individual or household. It does not include lawfully deidentified or aggregated information.

2. Summary

  • We collect contact and organization details, report-order information, limited payment metadata, communications, and technical or usage data.
  • Do not submit protected health information (PHI) or patient-level information. The Services are not designed to receive PHI.
  • We use information to fulfill and deliver reports, operate and secure the Services, process payments, provide support, and comply with law.
  • We use service providers such as Clerk for authentication, Stripe for payments, AWS for cloud services, and Google services for analytics and site measurement.
  • We do not sell Personal Information or share it for cross-context behavioral advertising.
  • You may have rights to access, correct, delete, or obtain a copy of your information, as described below.

3. Information We Collect

3.1 Information you provide

  • Contact and organization information: name, email address, telephone number, organization, role, and account or single-sign-on identifiers.
  • Report-order and request information: selected product, practice or client name, NPI or organizational identifiers, specialty or taxonomy, geographic market, payers or plans, named competitors, CPT or HCPCS codes, place-of-service details, Snapshot order number, scope preferences, and other information you choose to provide.
  • Payment and transaction information: billing address, tax information, order amount, transaction identifier, payment-method type, last four digits, and payment status. Stripe or another payment provider processes payment credentials; we generally do not receive full card numbers or bank-account credentials.
  • Communications: form submissions, emails, support requests, feedback, survey responses, and records of our communications.

3.2 Information collected automatically

  • Device and usage information: IP address, browser and device type, operating system, pages viewed, links clicked, referring and exit pages, session timestamps, and similar interaction data.
  • Diagnostics and security information: error logs, performance data, security events, feature configuration, and fraud-prevention signals.
  • Cookies and similar technologies: information used for authentication, security, preferences, analytics, and site measurement. See Section 11.

3.3 Information from other sources

  • Identity and authentication providers: for example, verified email addresses and login assertions from Clerk or an identity provider.
  • Payment providers: for example, transaction identifiers, payment-method type and last four digits, billing details, and payment status from Stripe.
  • Customers and professional partners: information an authorized RCM, consulting, contracting, or other professional partner provides to request a report for a named client.
  • Public and business sources: publicly available professional, organization, payer, plan, provider, taxonomy, location, and price-transparency information used to prepare reports or validate an Order.

4. No PHI or Patient-Level Information

Do not submit patient names, dates of birth, home addresses, medical-record numbers, member identifiers, claim-level patient details, diagnoses tied to an individual, or other PHI or sensitive patient information. The Services are designed around organization-level, professional, market, payer, plan, code, and public price-transparency information—not patient records.

Reveon is not agreeing to act as a HIPAA business associate through this Privacy Policy or our standard Terms of Service. No business associate agreement applies unless Reveon signs a separate written agreement expressly covering a defined service. If prohibited information is submitted, we may reject the request, delete or remove the information, and ask for a replacement submission.

5. How We Use Personal Information

We use Personal Information to:

  • review, scope, price, fulfill, quality-check, and deliver report Orders and related services;
  • verify Snapshot purchases and apply eligible upgrade credits;
  • create and administer accounts, authenticate users, and provide optional Portal access;
  • process payments, issue invoices, prevent fraud, and maintain transaction records;
  • communicate about Orders, delivery, support, security, and administrative matters;
  • operate, maintain, troubleshoot, secure, analyze, and improve the Services;
  • enforce our Terms of Service, protect rights and safety, and prevent misuse;
  • comply with legal, tax, accounting, regulatory, and law-enforcement obligations; and
  • send marketing communications where permitted. You may opt out at any time.

We may create aggregated or deidentified information and use it for lawful business purposes, including analytics and service improvement. We do not attempt to reidentify information we maintain as deidentified except to test our deidentification processes or as otherwise permitted by law.

6. How and With Whom We Disclose Information

We do not sell Personal Information or disclose it for cross-context behavioral advertising. We may disclose Personal Information in the following circumstances:

  • Service providers and processors: vendors that support authentication, payment processing, cloud hosting and storage, form handling, email delivery, customer support, security, analytics, website operation, and professional services. Examples may include Clerk, Stripe, AWS, and Google. They may use information only to perform services for us or as otherwise permitted by their own notices and applicable law.
  • At your direction: a client, professional partner, colleague, or other recipient you designate for delivery or support of an Order. If an RCM, consultant, or contracting firm orders for a client, relevant Order and delivery information may be shared between that partner and client.
  • Professional advisers: lawyers, accountants, auditors, insurers, banks, and other advisers with a legitimate need for the information.
  • Legal and safety purposes: when we reasonably believe disclosure is necessary to comply with law or valid legal process; investigate fraud, security incidents, or violations; enforce agreements; or protect the rights, property, or safety of Reveon, our customers, or others.
  • Business transactions: in connection with a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate confidentiality protections.
  • With consent: for another purpose disclosed to you when we request your consent.

7. Retention

We retain Personal Information only as long as reasonably necessary for the purposes described in this Policy, including to fulfill and support Orders, maintain business and financial records, comply with law, resolve disputes, enforce agreements, and protect the Services. Retention varies by the type of information and our legal or operational needs.

  • Account information: generally while an account remains active and for a reasonable period afterward for support, security, and recordkeeping.
  • Order, billing, report-input, and delivery records: for as long as reasonably necessary to fulfill the Order, provide support, document scope and delivery, apply credits, comply with tax or accounting rules, and address disputes.
  • Logs and telemetry: generally 180 days, unless longer retention is needed for security, fraud prevention, troubleshooting, or legal compliance.
  • Support communications: generally two years, unless a longer or shorter period is appropriate for the request or required by law.

When information is no longer needed, we take reasonable steps to delete, anonymize, or securely dispose of it. Backup copies may remain for a limited period before routine deletion.

8. Security

We use reasonable administrative, technical, and physical safeguards appropriate to the nature of the information, which may include encryption in transit, access controls, logging, vendor oversight, and least-privilege practices. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Use a strong, unique password and enable available security features.

9. Your Choices and Privacy Rights

Depending on where you live and subject to applicable exceptions, you may have the right to request that we:

  • confirm whether we process your Personal Information and provide access to it;
  • correct inaccurate Personal Information;
  • delete Personal Information;
  • provide a portable copy of certain information;
  • identify categories of Personal Information collected, used, or disclosed and categories of recipients;
  • limit or opt out of certain processing, including a sale, targeted advertising, or profiling where applicable; and
  • review an appeal if we deny a request where applicable law provides that right.

We will not discriminate against you for exercising an applicable privacy right. To submit a request, email support@reveonhealth.com. We may need to verify your identity and authority before acting. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and identity. We may retain information needed to document and respond to the request.

Marketing: You may opt out of non-transactional emails using the unsubscribe link or by contacting us. We may still send Order, service, security, or legal communications.

10. Children's Privacy

The Services are intended for business users and are not directed to children under 16. We do not knowingly collect Personal Information from children under 16. If you believe a child has provided Personal Information, contact us so we can take appropriate action.

11. Cookies, Analytics, and Preference Signals

We may use:

  • Strictly necessary cookies for authentication, security, and core functionality;
  • Functional cookies to remember preferences; and
  • Analytics technologies to understand site use and performance, including Google Analytics or Google Tag Manager where configured.

You can manage cookies through your browser and any consent controls we provide. Blocking some cookies may affect functionality. Where consent is required, we will request it before using non-essential technologies.

Some browsers send Do Not Track (DNT) signals, but there is no uniform standard for responding to them. We do not currently respond to DNT signals. Where required by applicable law, we honor recognized opt-out preference signals, such as Global Privacy Control. Because we do not sell Personal Information or share it for cross-context behavioral advertising, such a signal ordinarily will not change those practices.

12. Third-Party Sites and Services

The Services may link to third-party sites or services we do not control. This Policy does not govern those third parties. Review their privacy notices before providing information to them.

13. U.S. Processing and International Users

Reveon is based in the United States, and Personal Information may be processed and stored in the United States and other locations where our service providers operate. Privacy laws in those locations may differ from those where you live. Where required, we use appropriate safeguards for cross-border transfers.

14. Changes to This Policy

We may update this Policy from time to time. We will post the revised Policy and update the Effective Date. If changes are material, we will provide additional notice where required by law. Changes apply prospectively from the stated effective date.

15. Contact Us

Questions, privacy requests, or concerns may be sent to support@reveonhealth.com.