Effective · August 16, 2026
Your data stays yours.
The complete privacy policy and cookie policy for PT—DASH.
1. Who We Are and Scope
PTDASH LLC (“PTDASH,” “we,” “us,” or “our”) operates PT-DASH, a United States business-to-business software-as-a-service platform for outpatient rehabilitation and physical-therapy clinic owners, operators, administrators and other authorized business users. PT-DASH provides business analytics, operational intelligence, benchmarking and decision-support tools. PT-DASH is a business-intelligence tool built to analyze business, financial, operational, staffing and compensation data. It is not an electronic medical record (EMR), clinical documentation system or patient-care platform, and it is not designed for, intended for, or directed at collecting or processing Protected Health Information (PHI) or other patient-identifiable information.
This Privacy Policy describes how PTDASH collects, uses, discloses, stores and otherwise processes Personal Data in connection with the Service and our website. As to the account, billing and marketing data we collect for our own purposes, PTDASH acts as a controller; as to the business data a Customer submits or connects into the Service, PTDASH acts as a processor / service provider on the Customer's behalf.
Business Contact: PTDASH LLC, Bozeman, MT, USA. Email: hello@ptdash.com.
2. Information We Collect
Depending on how the Service is used, we may collect: account and contact information such as name, business email address and authentication information; organization and clinic profile information; business, financial, payer, reimbursement, staffing, scheduling, compensation, operational and KPI information; information imported from Customer-authorized integrations such as QuickBooks Online; Usage Data such as log, device, browser and interaction information; support communications; payment-related transaction information received from payment providers; and information submitted to features such as Dash AI.
We may also collect Personal Data about Authorized Users, employees, contractors or business contacts where that information is included in Customer Data. Customers are responsible for having the rights and authority necessary to provide that information to PTDASH.
3. Customer Data
“Customer Data” means identifiable information, files, records and other content that a Customer or its Authorized Users submit, upload, enter, import, connect or otherwise make available through PT-DASH, excluding PTDASH technology, PTDASH content, Derived Data, Aggregated Data and Benchmark Data as those terms are described in the Terms.
As between PTDASH and the Customer, the Customer retains its rights in identifiable Customer Data. PTDASH processes Customer Data under the rights and licenses granted in the Terms to provide, secure, support, maintain, analyze and improve the Service and to provide requested features and integrations.
4. Aggregated, De-identified, Derived and Benchmark Data
PTDASH may create aggregated, anonymized, de-identified, statistical or derived information from Customer Data and use of the Service (“Aggregated Data,” “Derived Data” and “Benchmark Data,” as further described in the Terms). We may use, and commercialize, such information for analytics, benchmarking, research, product development, proprietary scoring and modeling, service and AI improvement, business intelligence, market analysis and other lawful business purposes, provided the information is not reasonably capable of identifying a Customer or individual.
With respect to any such information that is derived from personal information, PTDASH: (a) takes reasonable measures to ensure the information cannot be associated with, or reasonably linked to, any Customer, consumer, household or individual; (b) publicly commits to maintain and use the information only in aggregated or de-identified form and not to attempt to re-identify it, except solely to test that its de-identification is sufficient; and (c) contractually obligates any recipient of the information to comply with each of the foregoing. This section is intended to satisfy, and will be construed consistently with, Cal. Civ. Code § 1798.140 and analogous requirements under applicable law.
PTDASH may retain and use Aggregated Data, Derived Data and Benchmark Data during and after the term and after an account is closed, and may disclose or commercialize such information in aggregated or de-identified form. We do not represent de-identified or aggregated information as identifying a specific Customer, patient, employee or other individual.
5. Protected Health Information and Health Data — We Do Not Want It
PT-DASH is a business-intelligence and decision-support tool for physical-therapy clinic operators. It is built to analyze business, financial, operational, staffing and compensation data. It is not designed for, intended for, or directed at collecting or processing patient information, and it does not require any patient-identifiable information to work.
You should never enter, upload, paste, connect, import or otherwise submit into the Service any “protected health information” (“PHI”) as defined under the Health Insurance Portability and Accountability Act of 1996 and its regulations (45 CFR Parts 160 and 164) (“HIPAA”), or any other individually identifiable patient health information or “consumer health data” regulated under state laws such as the Washington My Health My Data Act, the Nevada Consumer Health Data Privacy law, the Connecticut Data Privacy Act or similar laws (together with PHI, “Regulated Health Data”). Before submitting clinic information, remove patient names and any other identifiers that could identify an individual patient. The insights PT-DASH provides can be produced entirely from de-identified, aggregate and business/financial data.
We are not a HIPAA Business Associate. Because the Service is not designed to and does not need to create, receive, maintain or transmit PHI on your behalf to carry out a function regulated by HIPAA, PTDASH does not act as a “business associate” (45 CFR 160.103) and does not enter into Business Associate Agreements for the standard Service. Any PHI or Regulated Health Data that nonetheless reaches the Service is unsolicited and incidental, is submitted contrary to our terms, and is not received or maintained by PTDASH on your behalf.
What happens if health data slips in. We may (but are not obligated to) use automated or manual methods to detect, flag, filter, block, quarantine, redact, delete or return content that appears to contain Regulated Health Data. These measures are provided on a best-efforts, “as-is” basis and are not guaranteed to identify or prevent all such data. If we become aware that Regulated Health Data has been submitted, we may quarantine, redact, delete or return it, preserve only information legally required to be retained, and suspend or restrict the account, without liability to you. As between you and PTDASH, you — not PTDASH — are responsible for any legal obligation (including any breach-notification obligation under HIPAA or applicable state law) arising from your submission of Regulated Health Data. You are solely responsible for the data you put into the Service and for ensuring it does not contain Regulated Health Data.
Nothing in this Policy is intended to alter obligations that may apply under law based on the actual facts and circumstances of data submitted to or maintained by the Service.
6. How We Use Information
We use information to provide and operate PT-DASH; authenticate Users; administer subscriptions and payments; connect Customer-authorized third-party services; generate analytics, benchmarks and decision-support outputs; support and communicate with Users; improve product performance and functionality; develop, train, test and improve the Service and our features, models, algorithms and AI functionality (including the Dash AI advisor), using Aggregated Data and de-identified data for model and AI training and improvement unless a Customer has separately consented in writing to the use of identifiable Customer Data for that purpose; prevent fraud, abuse and security incidents; enforce our agreements; protect PTDASH, Customers and third parties; comply with legal obligations; and create Aggregated Data, Derived Data and Benchmark Data as described above.
7. Service Providers and Subprocessors
We use service providers to operate PT-DASH. Depending on implementation, these may include Stripe for payment processing; Vercel for hosting or application infrastructure; Supabase for database, authentication or storage functionality; Sentry for application monitoring; Loops for transactional or digest email; Anthropic for Dash AI functionality; and Intuit / QuickBooks Online where a Customer elects to connect a QuickBooks account. Service providers may process information only as permitted by their agreements with PTDASH and applicable law, and their own services may be subject to separate terms and privacy practices. A data processing addendum is available to Customers on request.
8. Dash AI / Anthropic
When a User submits a request to Dash AI, PT-DASH may transmit the User's prompt and relevant business context to Anthropic's commercial API to generate the requested response. PTDASH configures and uses the commercial API according to the data-handling terms and settings applicable to PTDASH's account, and engages such providers under terms that do not permit them to use Customer Data to train their general-purpose foundation models except as necessary to provide the service to PTDASH.
PTDASH does not authorize a third-party foundation-model provider to train its general-purpose models on identifiable Customer Data submitted through PT-DASH. PTDASH may use Aggregated Data and de-identified data to develop and improve its own features, models and the Dash advisor. PTDASH's public statements about third-party AI training, retention or data use will be kept consistent with the third-party provider's then-current commercial terms and PTDASH's actual configuration, and PTDASH will disclose its AI and model-training practices to the extent required by applicable law. Users should not submit PHI or Regulated Health Data in prompts to Dash AI.
9. QuickBooks Online and Other Connected Accounts
When a Customer connects a third-party service such as QuickBooks Online, the Customer authorizes PTDASH to access and process information within the scope of the permissions granted through that connection. Information may include profit and loss, balance sheet, cash-flow and other authorized business or financial information. PTDASH uses information obtained from a connected account only to provide the Service to that Customer and for the purposes described in these documents, and does not use one Customer's connected-account information to serve or benefit any other Customer except as Aggregated Data or de-identified data as permitted above.
PTDASH may store authorization tokens or credentials required to maintain an integration using reasonable safeguards, including encryption. When a Customer disconnects an integration, PTDASH will use the applicable provider's supported process to stop future access and to revoke or invalidate stored authorization credentials where technically supported. Previously imported information does not necessarily disappear upon disconnection and may remain subject to the Customer's account settings, retention periods, backup cycles and the Terms.
10. Cookies and Usage Technologies
PT-DASH may use necessary Cookies, local storage and similar technologies to authenticate Users, maintain sessions, secure the Service, remember preferences, support payments and integrations, and understand product performance. Where consent is legally required for non-essential Trackers, PTDASH will provide appropriate choices, and PTDASH honors recognized universal opt-out signals (such as the Global Privacy Control) where required by applicable law. See our Cookie Policy for more detail.
11. Security and Incident Notification
PTDASH uses reasonable administrative, technical and organizational safeguards appropriate to the nature of the Service and information processed, including encryption of data in transit and of sensitive stored credentials. No online system is completely secure, and PTDASH does not guarantee that unauthorized access, loss, misuse or disclosure will never occur.
If PTDASH confirms a security incident that compromises the security, confidentiality or integrity of Personal Data or Customer Data, PTDASH will provide notice without undue delay and as required by applicable law and will provide information reasonably available about the incident. Any such notice is not, and will not be construed as, an acknowledgment of fault or liability.
12. Retention and Deletion
PTDASH retains Personal Data and Customer Data for as long as reasonably necessary to provide the Service, administer accounts, maintain legitimate business records, comply with legal obligations, resolve disputes, enforce agreements, protect the Service and complete normal backup cycles. Customers may request deletion of eligible identifiable Customer Data by contacting PTDASH at hello@ptdash.com or using available account controls.
Deletion requests do not require PTDASH to delete Aggregated Data, Derived Data or Benchmark Data that no longer reasonably identifies the Customer or an individual, or information that PTDASH must retain under law, for security, dispute-resolution or legitimate recordkeeping purposes.
13. Business Transfers
Information and rights associated with PT-DASH — including Customer Data, Aggregated Data, Derived Data and Benchmark Data — may be disclosed or transferred to, and used by, a successor or acquiring entity in connection with an actual or proposed merger, financing, acquisition, sale of assets, reorganization, bankruptcy, change of control or similar transaction, subject to applicable law and the contractual restrictions applicable to identifiable Customer Data. Where required by applicable data-protection law, PTDASH and the successor entity will enter into or novate any necessary data-processing terms so that processing may continue without interruption.
14. U.S. State Privacy Rights
Depending on where an individual resides and whether a particular privacy law applies to PTDASH or the relevant processing, the individual may have rights to request access, correction, deletion or a portable copy of Personal Data, and may have additional rights relating to certain processing activities, including the right to opt out of any “sale,” “sharing,” “targeted advertising” or certain “profiling.” PTDASH will respond to verified requests as required by applicable law and, where a request is denied, will provide an opportunity to appeal as required by applicable law. Requests may be submitted to hello@ptdash.com. PTDASH honors recognized universal opt-out signals (such as the Global Privacy Control) where required by law.
PTDASH does not sell identifiable Personal Data for money. If PTDASH engages in an activity that legally constitutes a “sale,” “sharing” or “targeted advertising” under an applicable state privacy law, PTDASH will provide the notices and choices required by that law. Many state privacy laws exempt business-to-business and employment-context data; where an exemption applies, the corresponding rights may not.
15. Children's Data
PT-DASH is a business service and is not directed to children. Users must be at least 18 years old and authorized to use the Service on behalf of a business or organization.
16. Geographic Scope
The Service is offered from the United States and intended for business Customers located in the United States. It is not directed to individuals or businesses outside the United States, and we make no representation that the Service or these documents are appropriate or available for use outside the United States.
17. Changes to this Privacy Policy
PTDASH may update this Privacy Policy from time to time. The current version will identify its Effective Date. PTDASH will provide additional notice or obtain consent where required by applicable law.
Cookie Policy
1. What This Policy Covers
PT-DASH uses Cookies and similar technologies (collectively, “Trackers”) to operate, secure and improve the website and Service.
2. Necessary Technologies
Necessary Trackers may be used for authentication, session management, fraud prevention, security, payment functionality, account preferences and other features necessary to provide the Service. These are used because they are essential to operate the Service.
3. Analytics and Third-Party Technologies
PT-DASH may use limited first-party analytics and monitoring technologies to understand product performance and secure the Service. Third-party providers used by PT-DASH (for example, payment, hosting, authentication, monitoring and communications vendors) may set or access Trackers according to the configuration of the Service and their applicable policies. PT-DASH does not use advertising Trackers.
4. Your Choices
Where applicable law requires consent for non-essential Trackers, PTDASH will provide a mechanism to make or update privacy choices, and PTDASH honors recognized universal opt-out signals (such as the Global Privacy Control) where required by law. Users may also control Cookies through browser or device settings, although blocking necessary technologies may cause parts of PT-DASH to function improperly.
5. Relationship to Privacy Policy
The Privacy Policy contains additional information about PTDASH's processing of Personal Data and is incorporated into this Cookie Policy where applicable.