Scope and who is responsible
This Privacy Policy applies to the ConsulTrack website, physical mail, private reports, report-access tools, structured questions, contact form, and related operations (the “Service”). The operator of ConsulTrack (“ConsulTrack,” “we,” “us,” or “our”) is responsible for the processing described here.
This Policy covers information about business contacts, report recipients and visitors, inquiry senders, public reviewers, people named in public business feedback, and authorized internal users. It does not govern third-party websites or platforms that we link to.
The Service is designed for business information, not sensitive information about individuals. Do not send us patient, clinical, customer, employee, applicant, financial-account, government-ID, password, or other sensitive personal information.
Information we process
| Category | Examples |
|---|---|
| Identifiers and business information | Name, email, phone, business name and details, online listing information, and postal address. |
| Public information | Public reviews, ratings, reviewer display names, business responses, listings, websites, source links, and related public metadata. |
| Reports and inferences | Evidence, findings, comparisons, recommendations, and other information derived from business and public-source data. |
| Usage and technical information | Report access and interactions, cookies, IP address, browser/device information, timestamps, request metadata, diagnostic information, and security signals. |
| Submissions and communications | Report answers, inquiry reason, name, email, optional business information or message, support requests, and related correspondence. |
| Administrative and operational records | Internal account, authentication, delivery, support, moderation, security, and audit records. |
Where information comes from
We obtain information from:
- you or your business, when you contact us, use an access code, answer a report question, or communicate with us;
- public sources, including business listings, reviews, ratings, owner responses, and business websites;
- service providers, including public-data retrieval and postal-delivery providers;
- our systems automatically, when a report is opened or used, a request is rate-limited, or an error occurs; and
- authorized internal users, who select businesses, review reports, manage delivery, or add administrative notes.
Public availability does not make information anonymous. Public review text may identify a reviewer or another individual, and we treat it as personal information where applicable law does.
How we use information
We use information to:
- research, create, review, publish, deliver, and maintain private business reports and supporting evidence;
- retrieve public reviews and listings, analyze patterns, compare similar businesses, and develop recommendations;
- answer inquiries, provide support, process privacy requests, and send operational communications or physical reports;
- save report answers and select a prewritten tailored action based on those answers;
- measure whether reports are opened and which questions are viewed or started, so we can evaluate and improve the Service;
- secure report access, prevent abuse, rate-limit requests, debug errors, verify integrity, and maintain audit records;
- improve our methods and produce aggregated or deidentified customer-value and market insights; and
- comply with law, enforce our terms, resolve disputes, and protect rights, safety, and the Service.
Where a law requires a legal basis, we rely as appropriate on performance of a contract, steps requested before a contract, legitimate interests in operating and improving a business research service, consent where requested, and compliance with legal obligations. You may contact us about the balancing of a legitimate interest in a particular case.
Artificial intelligence and automated analysis
We may use artificial intelligence and other automated tools to analyze public business information and assist in preparing reports. Service providers supporting this work may process business identifiers, public feedback, and limited report context.
We seek to limit information used for automated analysis to what is reasonably necessary for the report. Provider processing is subject to contractual controls, legal requirements, and the provider’s own security and privacy practices.
ConsulTrack does not use automated processing to make decisions that produce legal or similarly significant effects about a reviewer, report visitor, or inquiry sender.
Service providers and other disclosures
We disclose information to providers that process it for the purposes described in this Policy. Those categories include:
- Hosting and data services
- Infrastructure used to host the Service, store information, manage access, and support normal operations.
- Processing and automation services
- Services that help retrieve information, operate workflows, and prepare reports and related materials.
- Data and public-source services
- Services used to locate and retrieve publicly available business and customer-feedback information.
- Artificial-intelligence services
- Services that assist with analysis, organization, and preparation of report content.
- Printing and delivery services
- Providers that receive the information reasonably necessary to prepare, address, and deliver physical mail.
- Analytics, security, and diagnostics
- Providers that help measure use, prevent abuse, maintain reliability, and investigate errors or security events.
We may also disclose information to professional advisers; to authorities or other parties when reasonably necessary to comply with law or protect rights, safety, and security; or in connection with a merger, financing, reorganization, bankruptcy, sale, or transfer of all or part of the Service. We may disclose aggregated or deidentified information that cannot reasonably identify an individual.
Cookies, report sessions, and analytics
Report access uses necessary first-party cookies that last up to 30 days in the browser. They help verify report access, preserve a report session and its answers, and protect the Service. Internal administrator access also uses necessary cookies.
We record report usage and interactions and process network, browser, and device information for security, abuse prevention, measurement, and improvement.
We do not currently use advertising cookies, cross-site tracking pixels, or session replay.
Do Not Track and preference signals
Because there is no uniform Do Not Track standard and we do not currently engage in cross-site behavioral advertising, the Service does not respond differently to browser Do Not Track signals. We will honor legally required opt-out preference signals if our practices change in a way that makes them applicable.
Public reviews and business comparisons
We retain public review source information so findings can be checked and reports can remain auditable. That information can include reviewer display names, review text, ratings, dates, business responses, source links, and related public metadata.
Reports generally show evidence excerpts and direct source links without displaying reviewer names. Similar-business findings are presented to report recipients as anonymous or aggregated patterns. This presentation does not mean the underlying information has been anonymized inside our systems.
A public review may contain health anecdotes, names, or other sensitive information volunteered by its author. We do not seek such information, and we do not use public reviews to make decisions about an individual. If you believe a report or stored public review presents a privacy or safety concern, contact us so we can review it.
No sale or targeted advertising
We do not sell personal information for money or other valuable consideration. We do not share personal information for cross-context behavioral advertising, and we do not use personal information to serve targeted advertisements. We do not offer financial incentives for personal information.
Disclosures to the service providers described above are made so they can perform services for us and are not treated by us as sales. If these practices change, we will update this Policy and provide any required opt-out methods before the new practice begins.
How long we retain information
We do not use one fixed retention period for every category. We consider the purpose for collection, source traceability, report and audit integrity, security, legal requirements, disputes, and whether information can be aggregated or deidentified.
- Report-access and answer-session cookies expire after up to 30 days in the browser. The underlying report link may remain active until it is revoked, rotated, or the Service changes.
- Public-source, analysis, report, answer, delivery, and audit records may be retained while we operate the Service and afterward as reasonably needed to preserve report integrity, comply with law, resolve disputes, or enforce agreements.
- Business contact information and inquiries are retained while needed to deliver or support reports, respond to requests, manage mail preferences, maintain business records, and handle disputes or legal obligations.
- Usage, security, and diagnostic records are retained while reasonably useful for protection, measurement, troubleshooting, and audit purposes.
Some records may be retained as needed for source and report integrity, security, disputes, or legal obligations. A deletion request may be limited by applicable exceptions, but we will evaluate requests under applicable law. We may retain aggregated or deidentified information that no longer reasonably identifies an individual.
How we protect information
We use administrative, technical, and organizational safeguards designed for the nature of the Service. These include measures intended to limit access, protect report credentials and stored information, maintain system integrity, and detect or reduce misuse.
No system, transmission, or storage method is completely secure. A private report is protected by a bearer code rather than verified identity, so anyone who obtains the code may be able to open it. Keep codes private and contact us if you believe one is exposed.
Your privacy rights and choices
Depending on where you live and subject to legal exceptions, you may have the right to ask us to:
- confirm whether we process personal information about you;
- provide access to or a portable copy of certain personal information;
- correct inaccurate personal information;
- delete certain personal information;
- restrict or object to certain processing, including processing based on legitimate interests;
- withdraw consent for future processing that relies on consent;
- opt out of sale, targeted advertising, or certain profiling if we ever conduct those activities; or
- appeal a refusal where applicable.
You may also ask us not to send future physical reports to a business address. We will not discriminate against you for exercising a privacy right.
Submit a request through the ConsulTrack contact form. Choose “I have a general question” and begin the message with “Privacy request.” Describe your relationship to the information and the right you want to exercise. We may request information reasonably necessary to verify identity, authority, and the scope of the request. An authorized agent may make a request where permitted by law, subject to verification.
You can also contact the original platform about review content at its source. Removing a source review does not automatically remove a previously captured report record; contact us separately if you want us to evaluate our copy.
California privacy disclosures
California residents are entitled to the disclosures required by the California Online Privacy Protection Act. The categories of personal information we collect are described in “Information we process”; the sources are in “Where information comes from”; the purposes are in “How we use information”; and the categories of third parties are in “Service providers and other disclosures.”
During the preceding 12 months, we may have collected the categories described in this Policy and disclosed them for business purposes to hosting and operational providers, data and artificial-intelligence services, printing and delivery providers, analytics and security providers, professional advisers, and legal-compliance recipients. We have not sold those categories or shared them for cross-context behavioral advertising.
If the California Consumer Privacy Act applies to ConsulTrack and your information, you may have rights to know, access, correct, delete, and obtain information about collection and disclosure; to opt out of sale or sharing; to limit certain uses of sensitive personal information; and to receive equal service and pricing. We do not currently sell or share personal information as those terms are used for California opt-out rights, and we do not use sensitive personal information to infer characteristics.
We will update this Policy when our practices materially change. Details for submitting and verifying a request appear in “Your privacy rights and choices.”
International use and transfers
ConsulTrack is operated from the United States, and its providers may process information in the United States and other countries. Those countries may have privacy laws different from the law where you live.
Where applicable law requires a transfer mechanism or additional safeguards for an international transfer, we will use an appropriate mechanism. If you are in the European Economic Area, United Kingdom, or another jurisdiction with similar rights, you may contact us about the applicable legal basis, safeguards, or transfer mechanism.
Children’s privacy
The Service is intended for adults acting in a business context and is not directed to children under 18. We do not knowingly collect personal information directly from children. If you believe a child submitted personal information through the Service, contact us so we can investigate and take appropriate action.
Public reviews may incidentally mention a child. We do not seek that information or use it to make decisions about the child.
Policy changes and contact
We may update this Policy as the Service or law changes. We will post the revised version with a new effective date. If a change materially expands how we use previously collected personal information, we will provide additional notice or seek consent where required rather than applying the change quietly or retroactively.
For privacy questions, requests, complaints, or mailed-report opt-outs, use the ConsulTrack contact form. Choose “I have a general question” and identify the request clearly. Do not include sensitive personal, patient, employee, or customer information.