LovingSteps

Privacy Policy

Effective Date: June 20, 2026

LovingSteps ("LovingSteps," "we," "us," or "our") provides software for ABA therapy practices to manage clients, therapists, guardians, schedules, clinical documentation, authorizations, billing workflows, and related operations.

This Privacy Policy explains how we collect, use, disclose, and protect information when you use our websites, web application, mobile application, and related services. This policy does not replace any Notice of Privacy Practices provided by a healthcare provider or therapy practice that uses LovingSteps.

1. Information We Collect

  • Account information, such as name, email address, role, organization, login credentials, and profile picture.
  • Client and guardian information entered by authorized users, such as names, contact details, relationships, dates of birth, diagnoses, service locations, treatment-related information, session notes, signatures, and care coordination records.
  • Therapist and staff information, such as credentials, schedules, assignments, caseload details, and administrative profile information.
  • Scheduling and operational information, such as appointments, attendance, cancellations, reassignments, authorizations, and workflow status.
  • Billing and claims information, such as insurance, payer, claim, payment, denial, ledger, and EDI-related information.
  • Audio, transcription, and generated note information, if your organization uses audio note capture, transcription, or note generation features.
  • Technical information, such as device/browser information, IP address, logs, authentication events, diagnostics, and usage information needed to operate, secure, and improve the Services.

2. How We Use Information

We use the information we collect to:

  • Provide, operate, maintain, and secure the Services.
  • Authenticate users and enforce role-based access controls.
  • Support clinical, scheduling, billing, documentation, guardian, and administrative workflows.
  • Generate or assist with transcripts, summaries, session notes, reports, and operational dashboards when enabled.
  • Send service-related communications, such as account, reminder, signature, and operational messages.
  • Troubleshoot issues, monitor reliability, prevent misuse, and improve the Services.
  • Comply with legal, contractual, audit, security, and regulatory obligations.

3. How We Share Information

LovingSteps is designed for healthcare-related workflows. When we receive protected health information ("PHI") from or on behalf of a covered healthcare provider, we use and disclose that PHI only as permitted by our agreement with that provider, applicable Business Associate Agreement, and applicable law.

Healthcare providers using LovingSteps are responsible for determining what information they enter into the Services, obtaining required consents, and providing any required patient notices.

  • Your organization and authorized users within your organization, based on configured roles and permissions.
  • Guardians, caregivers, therapists, billing users, or other authorized participants when enabled by your organization.
  • Service providers that help us host, secure, authenticate, store, process, transmit, analyze, or support the Services.
  • Communication providers for email, SMS, or notification delivery.
  • Transcription, AI, or automation providers when your organization uses features that require those services.
  • Payers, clearinghouses, billing partners, or other entities as needed for billing and claims workflows.
  • Legal, regulatory, or safety authorities when required by law or necessary to protect rights, safety, security, or the integrity of the Services.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

4. Data Security

We use administrative, technical, and organizational safeguards designed to protect information, including authentication, access controls, encryption where appropriate, audit logging, and restricted access based on user roles.

No system is perfectly secure. Users are responsible for protecting their credentials, using appropriate access permissions, and promptly notifying us of suspected unauthorized access.

5. Your Rights & Choices

Depending on your role, location, and applicable law, you may have rights to access, correct, delete, export, or restrict certain personal information. Requests involving client records or PHI may need to be directed to the healthcare provider or organization that controls the information.

To submit a privacy request, contact us at privacy@lovingsteps.com.

6. Data Retention

We retain information for as long as needed to provide the Services, comply with legal and contractual obligations, support audits, resolve disputes, maintain security, and meet healthcare, billing, or recordkeeping requirements. Retention periods may vary depending on the type of data and your organization configuration or agreement with us.

7. Children's Privacy

LovingSteps may process information about children when entered by healthcare providers or authorized users for therapy, care coordination, scheduling, documentation, billing, or related operational purposes. We do not knowingly collect children information directly for consumer marketing purposes.

8. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date and provide notice as required by law or contract.

9. Contact Us

LovingSteps, 1852 E Northside Dr, Fort Worth, TX 76106

Email: privacy@lovingsteps.com