CozziTech LLC

Privacy Policy

Provider:
CozziTech LLC
Applies to:
cozzitech.com and the ctEVV™ platform
Effective Date:
August 9, 2026
Last Updated:
August 9, 2026

CozziTech LLC ("CozziTech," "we," "us," or "our") respects your privacy. This Privacy Policy covers two distinct things, and it is important to know which part applies to you:

  • Part I describes our public marketing website at cozzitech.com — the pages you are reading right now.
  • Part II describes the ctEVV™ Electronic Visit Verification platform — the caregiver mobile app and the agency web portal. That is regulated software that handles health information, and it is governed by a materially different set of rules than our website.

The two parts are independent. Practices described in Part I do not apply to the ctEVV™ platform, and practices described in Part II do not apply to our website.

Part I — Our Website

This Part applies to cozzitech.com and any CozziTech marketing page, form, or email that links to it. It does not apply to any CozziTech application you sign in to.

1. Information You Give Us Directly

Most of our website can be read without giving us anything at all. You give us information only when you choose to contact us — for example, by submitting our contact or demo-request form, joining a waitlist or early-access list, or emailing us. Depending on the form, that may include:

  • Your name
  • Your email address and, if you provide it, your phone number
  • Your organization or agency name and your role
  • Whatever you choose to write in a message or free-text field

We use this information to respond to you, to schedule and conduct demonstrations, to answer questions about our products and services, and to follow up about the request you made. If you become a customer, we also use it to administer that relationship.

2. Website Analytics

We operate our own first-party analytics on cozzitech.com. Its purpose is narrow: to understand which pages, guides, and topics are actually useful so we can write better ones, and to understand which of our own marketing efforts bring people here. When you view a page, our analytics records:

  • A random visitor identifier and a session identifier. These are randomly generated strings stored in your browser. They are not derived from your name, your email, your IP address, or any characteristic of your device, and they cannot be reversed into an identity.
  • Page activity — the page address, page title, the page you came from within our site, how far down the page you scrolled, roughly how long the page was actively in front of you, and which buttons or links you clicked.
  • Referral and campaign information — the website that referred you (if any) and any campaign tags or advertising click identifiers present in the address you arrived on, so we can tell which of our own campaigns and content are working.
  • Coarse technical context — device category (desktop, tablet, or mobile), browser family, operating system family, viewport size, browser language, and time zone.

2.1 What our analytics deliberately does not do

  • No fingerprinting. We record only the coarse categories listed above. We do not assemble a device fingerprint, and we do not attempt to recognize you when you clear your browser storage.
  • No cross-site tracking and no advertising profiles. Our analytics runs only on our own website. We do not track you across other companies' websites, and we do not build advertising profiles or sell audiences.
  • No capture of what you type. Values you enter into forms are not sent to our analytics. Web addresses are sanitized before they are recorded: parameters that commonly carry sensitive values — including email, phone, name, date of birth, tokens, verification codes, and password or session values — are stripped out, as is the fragment portion of the address.
  • No sale or sharing for cross-context advertising. We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California and other state privacy laws.

2.2 Third-party analytics services

In addition to our own first-party analytics, we may enable third-party website measurement services — for example, a general web analytics provider or a page-quality service that produces aggregate heatmaps and scroll maps. Where we do, we configure them for measurement rather than advertising, including truncation of IP addresses where the service supports it, and we do not authorize them to use our website data to build advertising profiles. These services are used only on our marketing website. They are never present in the ctEVV™ platform.

3. Cookies and Browser Storage

We use a small number of first-party cookies and browser storage entries. We do not place third-party advertising cookies on our website.

What Purpose Lifetime
Visitor identifier A random string that lets us count returning visitors without knowing who they are. Until you clear browser storage
Session state Groups page views into a single visit. A visit ends after 30 minutes of inactivity. Rolling 30 minutes
Attribution Remembers the campaign or referring site you first and most recently arrived from. Up to 90 days
Privacy preference Records the analytics and marketing choices you have made, so we can honor them. Up to 12 months
Internal-traffic flag Marks our own staff and test traffic so it is excluded from reporting. Up to 12 months

You can clear or block these at any time through your browser settings. Doing so does not affect your ability to read the site.

4. Global Privacy Control and Do Not Track

We honor the Global Privacy Control (GPC) signal. If your browser or extension sends a GPC signal — or a Do Not Track signal — we treat it as an opt out of non-essential analytics and of any sharing for advertising purposes, and no opt-out request or form submission is required from you.

5. How We Share Website Information

  • With service providers acting on our behalf. We use a limited number of vendors to operate the website, deliver form submissions and email to us, and measure site performance. They are permitted to use the information only to provide those services to us.
  • To comply with law. We may disclose information if required to do so by law, subpoena, court order, or other valid legal process.
  • To protect rights and safety. We may disclose information when we believe in good faith that disclosure is necessary to investigate, prevent, or take action regarding suspected illegal activity, fraud, or threats to the safety of any person.
  • In connection with a corporate transaction. If CozziTech is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to the commitments in this Policy.

We do not sell, rent, or trade personal information to third parties for their own marketing purposes.

6. Retention

Inquiry and demo-request information is retained for as long as needed to respond to you and to maintain a record of our business relationship, and thereafter as required for legal, tax, and recordkeeping purposes. Analytics records are retained in identifiable-by-random-ID form for no longer than 26 months, after which they are retained only in aggregate form or deleted.

7. Your Rights and Choices

Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of the personal information we hold about you, to opt out of certain processing, and not to be discriminated against for exercising these rights. Residents of California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws, as well as individuals in the EU and UK, have such rights.

To exercise them, email privacy@cozzitech.com. We will verify your request and respond within the time required by applicable law. You may also opt out of analytics at any time by enabling Global Privacy Control in your browser, and you may unsubscribe from any marketing email using the link in that email.

If your question concerns information held inside a CozziTech application that a provider agency operates — for example, a consumer record in ctEVV™ — see Part II; those requests are directed to the agency.

8. Security

Our website is served over encrypted connections, and we maintain administrative and technical safeguards intended to protect information submitted to us. No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

9. Children

Our website is directed to businesses and organizations, not to children. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.

10. International Visitors

The website is operated from the United States. By using it, you understand that your information will be processed in the United States, which may have data protection laws different from those in your country of residence.

Part II — The ctEVV™ Platform

This Part applies to the ctEVV™ mobile application for caregivers and the ctEVV™ web portal for administrators. It does not apply to our marketing website. Originally published as the ctEVV™ Privacy Policy, effective May 23, 2026.

CozziTech LLC provides the ctEVV™ Electronic Visit Verification (EVV) platform, consisting of a mobile application for caregivers and a web portal for administrators (together, the "Service"). This Part explains what information the Service collects, how we use and disclose that information, the choices you have, and the safeguards we apply.

1. Who This Part Applies To

This Part applies to three categories of individuals whose information the Service may process:

  • Caregivers / Workers who log in to the ctEVV™ mobile or web application to record visits.
  • Consumers / Clients (the individuals receiving services) whose records are managed in the Service by a provider agency.
  • Administrators at provider agencies who use the web portal to manage consumers, visits, and reports.

In most cases, the provider agency (not CozziTech) is the "Covered Entity" under HIPAA and is the controller of the consumer information processed in the Service. CozziTech processes that information on the agency's behalf under the BAA in force with that agency.

2. Information We Collect

2.1 Consumer Information

When an agency creates or imports a consumer record, the Service stores information such as:

  • Full legal name, middle name, suffix, and any "also known as" names
  • Date of birth and gender
  • Home address (street, city, state, ZIP, county)
  • Email address(es)
  • Medicaid identifier
  • Program enrollment information, current plan, and assigned support coordinator
  • Diagnosis codes and diagnosis description (ICD-style codes; PHI)
  • A photograph reference for visual identification

2.2 Caregiver / Worker Information

  • Username and a securely hashed password (passwords are never stored in plaintext)
  • Worker identifier and tenant (agency) assignment
  • Role and access-level indicators
  • Account creation timestamp

2.3 Visit and Location Data

To verify the time, place, and delivery of services, the Service collects:

  • Check-in and check-out timestamps
  • Precise GPS coordinates (latitude and longitude) at check-in, at check-out, and at periodic intervals (by default approximately every five minutes) while a visit is open
  • Distance from the consumer's known service address (used to alert workers if they move outside the expected service area)
  • Coordinates captured at the moment of signature
  • Visit notes and visit type (free-form text entered by the caregiver; may contain PHI)
  • Administrative notes flagged for review
  • Electronic signature image (a signature captured on the device)

2.4 Device and Authentication Information

  • Session tokens used to maintain an authenticated session
  • Stored credentials in the device's hardware-backed secure storage only if the caregiver enables biometric sign-in
  • A biometric-enabled flag indicating that the caregiver has chosen to use device-level biometric unlock (such as Face ID, Touch ID, or Android biometric unlock) to re-authenticate
  • Push notification tokens issued by the device platform's push notification service (Apple and Google), used to deliver operational alerts to the mobile app

2.5 Information We Do Not Collect

The Service does not integrate any third-party analytics, advertising, crash-reporting, or behavioral-tracking SDKs. The website analytics described in Part I are not present in the ctEVV™ mobile app or web portal. We do not sell personal information, and we do not use PHI for advertising.

3. How We Use Information

We use the information described above only for the following purposes:

  • To authenticate caregivers and administrators and to keep accounts secure
  • To record, verify, and report electronic visit verification events as required by the agency's payer (for example, a state Medicaid program)
  • To confirm that services were delivered at the correct location and time
  • To enable agency administrators to manage consumer records, schedules, and visit history
  • To deliver operational notifications (for example, reminders to check out, or alerts when a worker has moved beyond the expected service area)
  • To protect the Service against fraud, abuse, and unauthorized access
  • To meet legal, regulatory, and contractual obligations, including those imposed by HIPAA and applicable state EVV regulations

4. Location Services

ctEVV™ requires precise location access on mobile devices in order to function as an EVV system. Location is collected only while a caregiver is signed in and a visit is open, and the device prompts for foreground and (where applicable) background location permission before any coordinates are captured. Caregivers may revoke location permission at any time in their device settings; however, the Service cannot record a compliant EVV visit without location access.

5. How We Share Information

We share information only as described below:

  • With the provider agency that employs or contracts you. All consumer, worker, and visit information is made available to the agency that owns the data, in accordance with the BAA in force with that agency.
  • With service providers acting on our behalf. We use a limited number of vendors to operate the Service, including:
    • Cloud hosting and database providers that store Service data;
    • Platform push notification services (Apple and Google) that deliver operational notifications to the mobile app. Push payloads are designed to avoid carrying PHI.
    Where these vendors handle PHI, they are bound by written agreements that include HIPAA Business Associate obligations or equivalent safeguards.
  • To comply with law. We may disclose information if required to do so by law, subpoena, court order, or other valid legal process, and as permitted under 45 C.F.R. § 164.512.
  • To protect rights and safety. We may disclose information when we believe in good faith that disclosure is necessary to investigate, prevent, or take action regarding suspected illegal activity or threats to the safety of any person.
  • In connection with a corporate transaction. If CozziTech is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to the confidentiality and HIPAA obligations described in this Policy.

We do not sell, rent, or trade personal information or PHI to third parties for their own marketing purposes.

6. Data Security

CozziTech maintains administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of information processed by the Service, consistent with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C). These safeguards include, among others:

  • Encryption of data in transit
  • Storage of caregiver passwords as salted cryptographic hashes — plaintext passwords are never persisted on our servers
  • Authenticated session tokens with limited lifetimes
  • Use of the device operating system's hardware-backed secure storage for any credentials cached on the device
  • Role- and tenant-based access controls within the platform
  • Logging and monitoring of authentication and administrative events

No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. Breach Notification

In the event of a breach of unsecured PHI, CozziTech will notify the affected Covered Entity without unreasonable delay and in any event within the timeframes required by the HIPAA Breach Notification Rule (45 C.F.R. §§ 164.400–414) and the applicable BAA. The Covered Entity is responsible for notifying affected individuals, the Secretary of Health and Human Services, and, where required, the media, unless the BAA expressly delegates that responsibility to CozziTech.

8. Data Retention

Visit records, location data, signatures, and notes are retained for as long as the provider agency's account remains active and for any additional period required by the agency's payer, by applicable state EVV regulations, or by HIPAA record-retention requirements (generally at least six years). When retention periods expire and an agency requests deletion, CozziTech will delete or de-identify the information in accordance with the BAA, except where retention is required by law.

9. Your Rights

If you are a consumer whose information is processed in ctEVV™, your HIPAA-protected rights (including the right to access, amend, and receive an accounting of disclosures of your PHI) are exercised through the provider agency that maintains your record, which is the Covered Entity for HIPAA purposes. Please direct requests to that agency. CozziTech will support the agency in responding to such requests as required by HIPAA and the applicable BAA.

If you are a caregiver, you may request access to or correction of the account information we hold about you by contacting us at the address below or by asking your agency administrator.

Depending on where you live, you may have additional rights under state privacy laws. We will honor such rights to the extent they apply and do not conflict with HIPAA or with our obligations to a Covered Entity.

10. Children's Privacy

ctEVV™ is not directed to children and is not intended to be used by individuals under 13 to create an account. The Service may, however, contain consumer records of minors who receive services through a provider agency; such records are processed at the direction of, and under the legal authority of, the agency that maintains them.

11. International Users

The Service is hosted in and operated from the United States. By using the Service, you understand that your information will be processed in the United States, which may have data protection laws different from those in your country of residence.

Part III — Other CozziTech Products

Some CozziTech products handle information differently enough to warrant their own policy. Where a product has its own policy, that policy governs that product:

For any CozziTech application you sign in to that is operated by your employer or agency, that organization determines what information is entered and who may see it, and CozziTech processes it on that organization's behalf under our agreement with them. Direct requests about your own records to that organization first.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Last Updated" date at the top of this page and, where appropriate, provide additional notice (such as an in-app message or an email to agency administrators). The current version is always available at cozzitech.com/privacy-policy/.

Contact Us

Questions, requests, or concerns about this Policy or about how CozziTech handles information should be directed to:

CozziTech LLC
Attn: Privacy
Privacy: privacy@cozzitech.com
Support: support@cozzitech.com

© 2026 CozziTech LLC. All rights reserved.