RepSheets Back to home

Legal

Privacy Policy

Last updated: 2026-06-02

This Privacy Policy describes how [ Company / Legal Entity Name ] ("RepSheets," "we," "us," or "our") collects, uses, and shares information in connection with the "Services": our public website at repsheets.us, the RepSheets administrative web application, and the RepSheets mobile (iPad) application. The website is open to the public; the administrative and mobile applications require a login and are made available to authorized users of our distributor and manufacturer customers.

1. Information We Collect

The public website

Our public website (repsheets.us) does not use cookies, analytics, or tracking technologies, and it has no account or contact forms — the only way to contact us from the site is through email links. The site loads fonts and icons from third-party content-delivery networks, which may receive your IP address and browser information as a normal part of delivering those files. Our hosting provider may keep standard server access logs.

Information you provide (administrative and mobile apps)

Information collected automatically (administrative and mobile apps)

If you enable biometric sign-in (Face ID / Touch ID) in the mobile app, that feature is handled entirely by your device's operating system. We never receive or store your biometric data.

2. How We Use Information

We do not use personal information for advertising, and we do not sell personal information.

3. Analytics

The RepSheets mobile application uses Google Analytics for Firebase, provided by Google LLC, to understand how reps use the app. These analytics events record interactions and counts only — for example, how many times a note is added to a case, how often a photo is attached, or which screens are visited.

Analytics events do not include the content of your work. We do not send note text, patient initials, medical record numbers, case records, photos, signatures, procedure details, or payor information to Google or to any other analytics provider.

Alongside each event, Google receives limited technical information: app version, device model, operating system version, general location inferred from IP address, and a Google-assigned app instance identifier. Where we associate events with a specific user, we use an internal identifier that is meaningless outside our own systems; we do not send names or email addresses.

We have not enabled Google's advertising, ads-personalization, or cross-app measurement features, and we do not permit analytics data to be used for advertising. We do not track you across other companies' apps or websites. Analytics data is retained by Google for [ retention period, matching the GA4 console setting ], after which Google deletes the event-level records.

The mobile application does not use the Advertising Identifier (IDFA) and does not present the App Tracking Transparency prompt, because it does not engage in tracking as Apple defines it.

4. Protected Health Information (HIPAA)

Some case data may constitute Protected Health Information (PHI). RepSheets is designed to support our customers' compliance with HIPAA and minimizes the identifiers it handles — for example, using patient initials and a medical record number rather than full patient names. Where we process PHI on behalf of a customer, that processing is governed by our agreement with that customer, including a Business Associate Agreement where one is required, and we maintain administrative, technical, and physical safeguards intended to protect it.

PHI is stored only in systems covered by our agreements with the infrastructure providers that operate the Services on our behalf. Analytics tooling does not process Protected Health Information. Our analytics implementation records feature-usage counts and screen navigation only, and is configured so that patient identifiers, note content, case records, photos, and signatures are never transmitted to analytics providers.

Requests concerning a specific patient's information should be directed to the healthcare provider or customer organization responsible for that record.

5. How We Share Information

We share information only as needed to operate the Services:

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.

6. Data Retention

We retain account information for as long as your account is active, and for a reasonable period afterward to complete deprovisioning, resolve billing questions, and maintain access records.

Case and usage records are kept as point-in-time business records to support billing, audit, commission, and compliance obligations, and are not altered after the fact. We retain these records for at least [ retention period, e.g. 7 years ] from the date of the case, or longer where our agreement with the relevant customer or applicable law requires it.

Analytics events are retained for [ retention period, matching the GA4 console setting ], as described in Section 3. Server and application logs are retained on a short rolling basis for security and troubleshooting.

7. Data Security

Access to the applications requires authentication through a supported sign-in provider and is limited to authorized users on an approved list. Data is stored with established cloud infrastructure providers, encrypted in transit and at rest. The mobile app enforces an inactivity timeout, and administrative sessions expire. Biometric sign-in data never leaves your device. We apply role-based access controls internally and maintain access logging for systems that hold case data.

No method of transmission or storage is completely secure, but we work to protect information using reasonable safeguards appropriate to its sensitivity.

8. Your Rights and Choices

You may request access to or correction of your account information by contacting us using the details in Section 13.

Accounts and deletion. RepSheets accounts are not self-registered. They are provisioned and deprovisioned by the distributor or manufacturer organization you work for. To have your account closed and your access removed, contact your organization's RepSheets administrator, or write to us at dcraig@jlsimplants.com and we will coordinate with your organization. We will confirm when the account has been closed.

Please note that case and usage records that serve as point-in-time business and compliance records may be subject to retention obligations and may not be deletable on request, even after an account is closed. Closing an account removes your access and your personal account details; it does not delete the case records your organization is obligated to keep.

You may opt out of analytics collection at any time by contacting us at dcraig@jlsimplants.com.

9. California Privacy Rights

If you are a California resident, the California Consumer Privacy Act gives you certain rights regarding your personal information. In the past twelve months we have collected the categories of personal information described in Section 1: identifiers, professional or employment-related information, internet or application activity information, and — in the case data reps enter — medical information, which California treats as sensitive personal information. We collect it for the business purposes described in Section 2, from you and from the sign-in provider you authenticate through, and we disclose it only to the recipients listed in Section 5.

We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit. Subject to verification and to the retention obligations described in Section 6, you may request to know what personal information we hold about you, to correct it, or to delete it, and you may designate an authorized agent to make a request on your behalf. We will not discriminate against you for exercising these rights. To make a request, contact us at dcraig@jlsimplants.com.

Residents of other states with comprehensive privacy laws may have similar rights. We honor verified requests on the same basis described above regardless of where you live.

10. Where Information Is Processed

The Services are intended for use in the United States, and information is stored and processed in the United States. Our analytics and infrastructure providers may process limited technical information on systems located in other countries as part of operating their global services. If you access the Services from outside the United States, you understand that your information will be transferred to and processed in the United States.

11. Children's Privacy

The Services are a professional business tool intended for authorized professional users. They are not directed to children, we do not knowingly collect personal information from anyone under 18, and access requires provisioning by a customer organization. If we learn that we have collected such information, we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where the changes are material, provide additional notice through the applications or to the customer organizations that use them.

13. Contact Us

If you have questions about this Privacy Policy or our data practices, or you would like to exercise a privacy choice, contact us at:

[ Company Name ]
[ Mailing Address ]
dcraig@jlsimplants.com