In short
We collect what we need to run Sokndall: who you are, the provider and payer data you enter, and basic technical records.
We do not sell personal data, and we never use what you enter to advertise anything.
A handful of companies process data for us — Supabase, Vercel, Polar, Resend, and Google if you sign in with it — and they are all listed below.
You can export everything at any time, and deleting your account deletes it. Questions: privacy@sokndall.com.
Who we are and what this covers
Sokndall makes credentialing and payer enrollment tracking software. This policy covers the marketing site at sokndall.com and the application you sign in to.
For the data you enter about your providers, you are the controller and we are the processor: it is your data, and we handle it on your instructions. For your own account and billing details, we are the controller.
Write to privacy@sokndall.com about anything in this policy.
What we collect
- Account: your first and last name, your work email address and a password, which is stored hashed by Supabase Auth and never in a form we can read. If you sign in with Google instead, we receive your name, email address and profile picture from Google. A profile photo of your own is optional.
- What you enter: your practice or client details, your providers' names, NPIs, CAQH IDs, licence and registration numbers with their dates, payer applications and their history, the notes and phone logs you write, and the documents you upload. No patient data belongs here, and the Terms forbid it.
- Billing: your plan, subscription status and the name and email on the subscription, which come back to us from Polar. Card numbers go to Polar and never reach us.
- Technical: IP address, browser and basic request logs, kept for security and abuse prevention, and a record that an alert or digest email was sent to a given address, so the same email is not sent twice.
How we use it
To run the service: show you your data, work out what expires and what has gone quiet, send the alert and digest emails on the schedule you choose, and keep the account working.
To bill you, through Polar.
To support you when you write in, which sometimes means looking at your account to answer the question you asked.
To keep the service safe: spotting abuse, debugging, and meeting a legal obligation when one applies.
We do not sell personal data. We do not use what you enter for advertising, and we do not use it to train machine-learning models.
Who processes data for us
- Supabase — database, sign-in and file storage. Your data sits in Supabase's US East (Ohio) region.
- Vercel — hosting for the site and the application.
- Polar — payments and merchant of record: it charges the card, handles tax and issues invoices.
- Resend — delivery of the emails we send you: alerts, the weekly digest, password resets and invitations.
- Google — only if you choose to sign in with Google.
- Cloudflare — the bot check on the sign-in and sign-up forms, where it is switched on.
- Centers for Medicare & Medicaid Services — when you look up an NPI, that number is sent to the public NPI Registry (NPPES) to fetch the public record.
These companies are in the United States, and so are we. If you are in the EEA or the UK, that means your data is transferred to the United States, and we rely on the standard contractual clauses our processors offer for those transfers.
We do not add processors quietly. If this list changes, this page changes with it.
Keeping and deleting
Your content is kept while your account exists. Deleting a client deletes its records and files, leaving only a line saying a client of that name was deleted, when and by whom. Deleting the account ends the subscription, removes the stored files and deletes everything under the organization. Neither can be undone, so export first.
If an account ends without being deleted, it stays read-only for 30 days so you can export, and we may delete it after that.
Server and security logs are kept for up to 90 days. The record that an email was sent lives with the account and goes when it goes. Billing records are kept by Polar, and by us where the law requires, for as long as tax rules demand.
How it is protected
Every account is separated from every other account in the database itself, with row-level security, and on Billing Co each client is separated from the rest the same way. There is no path in the application that steps around it.
Uploaded documents live in private storage. A download link is made when you click and expires in a minute; an export's links expire in ten. Nothing is publicly addressable.
Connections are encrypted in transit, passwords must be at least twelve characters and are stored hashed, and sign-in can require a bot check.
The strongest protection is the one in the Terms: there is no patient data here to lose.
If we ever have a breach that affects your data, we tell the account owner by email without undue delay, and describe what happened and what we are doing about it.
Your rights
You can see everything we hold about your account inside the application, correct it there, export it as CSV or ZIP, and delete it by deleting the client or the account.
Depending on where you live, you may also have the right to ask for a copy of your personal data, to have it corrected or deleted, to object to or restrict how we use it, and not to be treated differently for asking. Write to privacy@sokndall.com and we answer within 30 days. We may need to check that you are who you say you are first.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California and other state privacy laws. If that ever changes because of the advertising tags described above, this policy will say so before it happens.
If you are a provider whose details sit in someone's account, that account belongs to the practice or billing company that entered them. Ask them first; we will pass a request on to them and help them answer it.
Children
Sokndall is a business tool and is not directed to anyone under 18. We do not knowingly collect data from children, and if we learn that we have, we delete it.
Changes and contact
When this policy changes we update the date at the top, and we email the account owner before a material change takes effect.
Privacy questions and requests: privacy@sokndall.com. Anything else about the product: support@sokndall.com.
Adapted from the Basecamp open-source policies, used under CC BY 4.0.