Privacy Policy

Effective date:
July 21, 2026
Last updated:
July 21, 2026
This Privacy Policy explains how Footprints Mental Health Counseling, P.C. (“Footprints Supervision Manager”, “we”, “us”, or “our”) collects, uses, discloses, and protects information when you use the Footprints Supervision Manager platform, websites, and related services (collectively, the “Services”). We are based in New York, New York, United States and the Services are intended for use in the United States.

1. Scope of This Policy

Footprints Supervision Manager is a multi-tenant software-as-a-service platform used by mental health practices to manage clinical supervision, scheduling, and related workflows. This Policy applies to the personal information we handle as a business (a data controller) — for example, information about the clinicians, supervisors, administrators, and other authorized users who access their practice’s account, and visitors to our marketing pages.

This Policy does not govern protected health information (“PHI”) that a practice stores in the Services about its clients or patients. See Section 3 (Protected Health Information & HIPAA) for how that information is handled.

2. Information We Collect

Information you or your practice provide

  • Account & profile data — name, work email address, role, professional credentials, license information, and workspace (practice) affiliation.
  • Authentication data — credentials and records used to sign you in and keep your account secure.
  • Communications — messages, support requests, and feedback you send to us.

Information collected automatically

  • Usage & device data — IP address, browser type, device identifiers, pages viewed, and actions taken within the Services.
  • Cookies & similar technologies — used to keep you signed in, remember preferences, and understand how the Services are used. See Section 7.
  • Log & audit data — security and audit logs recording access to and changes within the Services, which we maintain to protect the platform and to support HIPAA-required audit trails.

Information from third parties

If you sign in with Google (or another identity provider), we receive basic profile information from that provider — typically your name, email address, and profile details — solely to authenticate you and associate your account with your practice workspace.

If your practice connects a third-party calendar (such as Google Calendar or Microsoft Outlook), we receive limited scheduling data and access tokens needed to synchronize supervision sessions. We request only the minimum access necessary for that feature.

3. Protected Health Information & HIPAA

When a practice uses the Services to store or process PHI about its clients, that practice is the HIPAA Covered Entity and controls that PHI. We act as a Business Associate and process PHI only on the practice’s behalf, under a written Business Associate Agreement (“BAA”) and our Data Processing Addendum (“DPA”).

The BAA and the DPA work together and should be read as a single set of terms governing PHI: the BAA sets out our obligations as a Business Associate under the HIPAA Privacy and Security Rules, and the DPA sets out related data-processing, security, and subprocessor terms. If there is any conflict between the BAA and the DPA regarding PHI, the BAA controls.

We use, disclose, and safeguard PHI as permitted by the BAA and required by the HIPAA Privacy and Security Rules — including access controls, encryption of PHI, audit logging, and workforce safeguards. If you are a client or patient of a practice and have questions about your health information, please contact that practice directly, as it controls your records.

4. How We Use Information

  • Provide, operate, secure, and maintain the Services.
  • Authenticate users and enforce role-based access and tenant isolation.
  • Respond to support requests and communicate about the Services.
  • Monitor, detect, and prevent fraud, abuse, and security incidents.
  • Maintain audit and compliance records, including those required by HIPAA.
  • Improve, troubleshoot, and develop new features (using aggregated or de-identified data where practical).
  • Comply with legal obligations and enforce our agreements.

We do not sell personal information, and we do not use PHI for advertising or for our own marketing.

5. How We Share Information

We share information only as needed to run the Services and as described below. We do not sell personal information.

  • Within your workspace — with authorized users of your practice, according to their assigned roles and permissions.
  • Service providers / subprocessors — vendors that host, secure, or support the Services (for example, cloud hosting and infrastructure), bound by contract and, where PHI is involved, by a BAA.
  • Legal & safety — when required by law, subpoena, or legal process, or to protect the rights, safety, and security of users, the public, or the Services.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy and applicable law.

6. Data Security & Retention

We use administrative, technical, and physical safeguards designed to protect information, including encryption of PHI, tenant isolation (row-level security), role-based access control, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

We retain personal information for as long as your practice’s account is active and as needed to provide the Services. Following termination of your practice’s account, we delete or de-identify personal information within a commercially reasonable period, consistent with the timeframes set out in the BAA and our agreements, and with applicable legal and professional record-retention requirements.

7. Cookies & Tracking Technologies

We use strictly necessary cookies to operate the Services (such as keeping you signed in) and limited analytics to understand usage. You can control non-essential cookies through your browser settings and, where available, through our cookie controls. Because the Services are a professional tool accessed by authorized users, some cookies are required for the Services to function.

8. Your Privacy Rights (U.S. States)

Depending on your state of residence (for example, California, Virginia, Colorado, Connecticut, and other states with comprehensive privacy laws), you may have rights to access, correct, delete, or obtain a copy of certain personal information, and to appeal a denied request. We do not sell personal information or use it for “targeted advertising” as those terms are defined under state law. We will not discriminate against you for exercising any of these rights.

Many of these laws exempt information governed by HIPAA and certain employment-related information. Where an exemption applies, that information is handled under HIPAA and the applicable practice’s policies rather than under this section. To exercise a right, see Your Privacy Choices or contact us using Section 11. If your request concerns records controlled by a practice, we will refer it to that practice.

9. Children’s Privacy

The Services are intended for use by professionals at licensed practices and are not directed to children. We do not knowingly collect personal information directly from children through the Services. Any information about minors is entered by a practice as part of its clinical records and is governed by the practice’s policies and the BAA.

10. Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Services after an update means you accept the revised Policy.

11. Contact Us

If you have questions about this Policy or our privacy practices, contact us at helpdesk@footprintstofeelbetter.com, or by mail at Footprints Mental Health Counseling, P.C., New York, New York, United States.