1. Overview
This policy describes how Eazelo (“we”) handles information when you use our website, verification tools, portal, and reports (the “Service”). The Service verifies United States healthcare provider credentials against official public records; it is designed for professional information, not patient data — please never submit protected health information.
2. Information we collect
- Account information. Email address, name if you provide one, and a password we store only as a salted hash.
- Verification activity. The provider details you submit for checks (names, NPIs, license numbers, practice locations), the resulting reports, saved history, submitted doctors, and call plans.
- Usage and security data. IP address (used for free-check allowances, rate limiting, and abuse prevention), browser and device information, and service logs.
- Session storage. We use browser local storage to keep you signed in; we do not use third-party advertising cookies.
- Payments. Paid tiers are processed by Stripe. We receive subscription status and a customer reference; we never see or store full card numbers.
- Communications. Emails you send us and your marketing-email preference, which is opt-in and can be withdrawn at any time.
3. Provider information in reports
Reports contain information about healthcare providers drawn from official public sources such as the NPPES/NPI registry, CMS datasets, and state licensing boards, cited with source URLs and timestamps. This is professional, public-record information about licensed providers, not consumer or patient data.
4. How we use information
- to run checks, generate reports, and maintain your saved history and plans;
- to enforce usage allowances and protect the Service from abuse;
- to send transactional email such as password resets (delivered via Amazon SES) and, only with your consent, occasional product updates;
- to respond to support requests and improve the Service;
- to comply with legal obligations.
We do not sell personal information, and we do not use your data to train third-party AI models.
5. When we share information
We share information only with service providers that operate the Service on our behalf — hosting and databases (Railway), payment processing (Stripe), transactional email (Amazon SES/AWS), and error monitoring — each bound to use it only for the service they provide. We may also disclose information if required by law, or as part of a merger or acquisition with notice on this page.
6. Retention and your controls
Public reports and their verification records expire on the schedule shown in the product. Account data is kept while your account is active. From the portal you can export your data and delete your requests, reports, plans, or account; deletion requests can also be sent to support@eazelo.ai. Residual copies may persist briefly in backups before aging out.
7. Security
We use TLS in transit, hashed passwords, tenant isolation, role-based access controls, audit logging, and least-privilege credentials. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as required by law.
8. Where data is processed
The Service is operated from the United States and is intended for use in the United States.
9. Children
The Service is not directed to anyone under 18, and we do not knowingly collect their information.
10. Changes and contact
We will post any changes to this policy here with an updated date. Questions or requests: support@eazelo.ai. See also our Terms of Service.