Hailo Privacy Policy

Effective Date: August 17, 2026 Supersedes the version dated August 8, 2026


1. Who We Are and What This Policy Covers

This Privacy Policy ("Policy") is issued by Hailo LLC, a California limited liability company with its principal place of business at 25283 Cabot Rd, Ste 212, Laguna Hills, CA 92653 ("Hailo," "we," "us," or "our").

This Policy describes how we collect, use, disclose, and protect personal information in connection with the following products and services (collectively, the "Services"):

This Policy applies to everyone who interacts with the Services: website visitors; clients and their family members; care recipients; caregivers and caregiver applicants; home care agency owners and staff; referral partners; and callers to phone numbers operated through the Services.

This Policy does not replace agency privacy notices. Home care agencies that use Hailo are independent businesses. When an agency uses Hailo to run its operations — for example, to receive your job application, manage your care, store your records, or send you documents for signature — that agency is responsible for its own privacy and employment practices, and its own privacy notice governs in addition to this Policy. Section 3 explains these roles in more detail.


2. Summary of Key Points

This summary is provided for convenience; the full Policy controls.


3. Our Roles: When Hailo Is Responsible for Your Information

Hailo operates in three distinct capacities. Which one applies determines who is primarily responsible for your information and where you should direct requests.

(a) Hailo as the responsible business ("controller"). We act for our own purposes when we operate our websites and marketing pages; when we receive care requests through our "Find Care" tool and marketplace; when consumers, caregivers, or agencies create accounts directly with us; when we bill agencies for our software; and when we operate our own support, help center, and communications. For these activities, this Policy is the operative notice and requests should come to us.

(b) Hailo as a service provider / processor for agencies. When an agency uses the Services to manage its clients, caregivers, applicants, schedules, payroll, invoices, documents, CRM records, or phone lines, we process that information on the agency's behalf and at its direction. The agency determines why and how that information is used. If you are an agency's client, caregiver, employee, or job applicant, the agency is the primary party responsible for your information, and you should direct requests to the agency; we will assist the agency in honoring them.

(c) Hailo as a HIPAA business associate. Where an agency is a covered entity under the Health Insurance Portability and Accountability Act ("HIPAA") and protected health information ("PHI") is processed through the Services, we act as the agency's business associate and handle PHI in accordance with HIPAA and our Business Associate Agreement ("BAA") with that agency. See Section 16.


4. Information We Collect

A. Information You Provide to Us

Clients and family members (the Hailo client app and web experience):

Caregivers and caregiver applicants (the Hailo Caregiver app and agency application forms):

Agency owners and staff:

Website visitors, callers, and leads:

B. Information Collected Automatically

We do not deploy third-party advertising trackers, ad pixels, or third-party analytics SDKs in the Services as of the Effective Date.

C. Information from Other Sources


5. Sensitive Information

We collect the following categories of sensitive personal information, only for the purposes described and never for advertising:

CategoryWho it concernsWhy we collect it
Health information (conditions, medications, allergies, care needs, care notes)Care recipientsTo arrange, deliver, document, and coordinate home care
Social Security number; government IDCaregivers/applicantsBackground screening, identity verification, tax reporting
Driver's license and auto insuranceCaregiversDriving-related care tasks and mileage reimbursement
Precise geolocationCaregiversVisit verification (EVV) at clock-in/out; optional live location for on-demand tasks
Financial account informationCaregivers, agencies, clientsPayments, payouts, and reimbursements (processed by Stripe)
Funding/coverage details (e.g., Medicaid ID)Care recipientsPayer coordination and billing
Call recordings and voicemailsCallersQuality assurance, records of requests, and AI call handling (Section 8)
Work-related health compliance records (e.g., TB tests, vaccinations)CaregiversAgency employment compliance (collected for the agency)
Protected classification data (e.g., gender; ethnicity where an agency's hiring form requests it)Care recipients, applicantsCare matching preferences; agency hiring compliance

Health information receives additional safeguards: it is stored in a segregated health record with restricted access; caregivers can access a care recipient's health details only for care they are assigned to, through a controlled channel; every such access is logged (including who accessed it, when, and from what IP address) in an audit log that cannot be deleted; access by our internal administrators is restricted to the most privileged administrative role; and health information is excluded from AI model context as described in Section 7.


6. How We Use Information

We use personal information to:

  1. Provide the Services — create and administer accounts; match care requests with agencies and caregivers; build and manage schedules and care plans; enable clock-in/clock-out and visit documentation; power in-app messaging; generate invoices, payroll, and payouts; and operate the client, caregiver, and agency apps and portals.
  2. Verify visits and support program integrity — confirm that visits occurred at the right place and time (EVV), detect out-of-geofence or manually-adjusted clock events, preserve original time records for audit, and flag anomalies.
  3. Verify identity and qualifications — verify caregiver identity and credentials, run consented background screenings, and check public registries.
  4. Process payments — through Stripe, as described in Section 14.
  5. Communicate with you — send transactional emails (welcome, verification codes, invoices, reminders, password resets, offers, invitations), push notifications (for example, shift reminders), SMS where you have consented, and support responses.
  6. Operate AI features — as described in Section 7.
  7. Maintain safety, security, and integrity — authenticate users (including one-time codes and trusted-device checks), prevent bots and abuse (Cloudflare Turnstile, honeypots, rate limits), detect fraud (including flagging phone numbers associated with abuse), enforce role-based access controls and cross-agency data isolation, and maintain audit logs.
  8. Create records with legal effect — capture and preserve consent records (for example, telephone consent under the TCPA and e-signature consent under the ESIGN Act), and generate sealed, tamper-evident signed documents with signature certificates (Section 13).
  9. Comply with law — meet our legal, tax, EVV, and regulatory obligations, respond to lawful requests, and establish or defend legal claims.
  10. Improve and develop the Services — troubleshoot, analyze aggregate usage, and develop features. We do not use care recipients' health information to train AI models.

We do not use personal information for third-party behavioral advertising, and we do not send marketing on behalf of third parties.


7. Artificial Intelligence Features

The Services include AI features. We design them with specific guardrails, described here so you know what to expect.

(a) AI phone assistants. Our main phone line, and phone lines that agencies configure through the Services, may be answered by an AI voice assistant. The assistant:

Calls handled by AI assistants are processed in real time by our voice AI provider (xAI); per that provider's real-time interface, audio is processed live rather than stored by the provider. We store call records, transcripts (capped in length), and AI-generated call summaries so agencies can follow up on your request. If you object to recording during a call, see Section 8.

(b) Outbound AI calls. Agencies may use the Services to place outbound calls, including AI-assisted calls, only to people who have given prior express written consent to receive them (Section 12). Every outbound program honors opt-out requests, and we maintain a platform-wide do-not-call suppression list: if you ask not to be called, your number is suppressed across the platform.

(c) Atlas, the agency operations assistant. Agencies can use an in-app AI assistant ("Atlas") for operational questions (scheduling, staffing, billing readiness, hiring pipeline, and similar). Atlas is engineered with a health-information boundary: the operational data snapshot provided to the AI model is built through a single controlled pathway that excludes health information; results returned to the model pass through a field-level allow-list; and Atlas's memory feature screens out and refuses to store health details, government identifiers, and clinical information. Atlas requests are processed by third-party AI model providers under contract (see Section 10). Atlas conversations within an agency workspace may be visible to other authorized staff of that agency.

(d) No AI training on your health information. We do not use care recipients' health information to train AI models, and our contracts with AI providers restrict their use of data to providing the service to us.

(e) Human review and automated decisions. AI features assist people — agency staff and our team — and are not used to make legally significant decisions about you without human involvement. Care, hiring, and billing decisions are made by people at the responsible agency.


8. Call Recording, Monitoring, and Transcription


9. Location Information and Electronic Visit Verification (EVV)

Home care programs (including federal and state EVV requirements under the 21st Century Cures Act) require verification that visits occurred. Here is exactly how location works in the Services:


10. How We Share Information

We do not sell personal information for advertising, and we do not share personal information with third parties for cross-context behavioral advertising. We do not share, sell, or provide mobile phone numbers, text-messaging originator opt-in data, or SMS consent to third parties or affiliates for marketing or promotional purposes (see Section 12). We share personal information only as follows:

(a) Between participants in care. Sharing information among the right people is the core function of the Services:

(b) Agencies you ask to be connected with. When you submit a care request through "Find Care," we share it with home care agencies serving your area — see Section 11 for exactly how this works, including what is masked until an agency accepts your request.

(c) Service providers (processors). We use a small set of contracted providers to operate the Services. As of the Effective Date:

ProviderPurposePersonal information involved
Google LLC (Firebase / Google Cloud)Cloud hosting, database, file storage, authentication, push notificationsAll Service data, encrypted in transit and at rest
Google LLC (Maps / Places / Geocoding)Address autocomplete; EVV geocodingAddresses; caregiver clock-in/out coordinates
Stripe, Inc.Payments, subscriptions, payouts (Stripe Connect), identity verification (Stripe Identity)Payment details, payout account details, government ID and selfie for identity verification (held by Stripe)
Twilio Inc.Telephony, SMS, call recording; per-agency subaccounts for tenant isolationPhone numbers, call audio and recordings, message content
xAI Corp.Real-time voice AI; post-call transcript analysis; agency knowledge-base searchLive call audio (real-time processing), call transcripts, agency knowledge documents
AI model providers via OpenRouter, Inc.Atlas operations assistantHealth-information-stripped operational data (Section 7(c))
Brevo (Sendinblue)Transactional emailRecipient name, email, message variables (e.g., invoice amounts, links)
Cloudflare, Inc. (Turnstile)Bot protection on public formsAnti-bot token, IP address
Background screening provider(s) (e.g., Checkr, Inc.)Caregiver background checks (with consent)Applicant identity details required for screening
Calendly LLCDemo scheduling (external booking page)Information you enter on Calendly, governed by Calendly's privacy policy

Service providers are bound by contracts limiting their use of personal information to providing services to us, and — where PHI is involved — by BAAs where required.

(d) Integrations an agency enables. If an agency connects an external system (for example, CareSmartz360), we exchange the relevant records (such as prospect and client contact and care details) with that system at the agency's direction. The agency's and integration provider's terms govern that system's use of the data.

(e) Corporate events. If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction, subject to this Policy and applicable law. We will provide notice of any resulting change in control or use.

(f) Legal and safety. We may disclose personal information to comply with law or legal process; to respond to lawful requests from public authorities; to enforce our agreements; to protect the rights, safety, or property of clients, caregivers, agencies, the public, or Hailo; or in an emergency involving danger to a person.

(g) With your direction or consent. We share personal information for any other purpose you direct or consent to.


11. The Hailo Care Marketplace and "Sale" of Personal Information

When you submit a care request through our "Find Care" tool (on the website or by phone through our intake line), you are asking us to connect you with home care agencies. Here is exactly what happens:

  1. Your request is stored securely, with your contact details held server-side and never exposed publicly.
  2. Agencies whose service area covers your ZIP code are notified and shown a masked preview: your initials, your city/region and ZIP code, the care needs, schedule, funding type, and any message you included — but not your name, phone number, email address, or street address.
  3. An agency that wants to serve your request pays us a flat fee (currently $49) to accept it. Only the first accepting agency receives your full name and contact details and, where provided, the care address. The request is then closed to other agencies.
  4. The accepting agency receives your request — including your consent record, if you consented to calls/texts — in its customer relationship system so it can contact you about your care needs.

Because the accepting agency pays us in connection with receiving your contact information, this disclosure may be treated as a "sale" of personal information under some state privacy laws (such as the California Consumer Privacy Act), even though it happens only at your direction, only to fulfill your request, and never for advertising. We therefore provide the following:


12. Communications, Telephone Consent, and Opt-Outs


13. Electronic Signatures and Records

Agencies may use the Services to send you documents (for example, service agreements or onboarding paperwork) for electronic signature. When you use our signature portal:


14. Payments


15. Cookies and Similar Technologies

We keep our tracking footprint deliberately small. As of the Effective Date:


16. HIPAA


17. Data Retention

We retain personal information for as long as needed for the purposes described in this Policy, and we determine retention periods based on: the nature of the relationship (for example, active account vs. closed account); our legal obligations (tax, employment, EVV, and health-record retention laws, which can require multi-year retention); the evidentiary role of the record (consent records, signature audit trails, and access logs are retained long-term because their purpose is proof); and the sensitivity of the data.

Specific practices to know:


18. Security

We use administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including:

No system is perfectly secure. If we learn of a breach affecting your personal information, we will notify you and regulators as required by applicable law and, where applicable, our BAAs.


19. Your Privacy Rights and Choices (All Users)

Regardless of where you live, you may:

To exercise any of these rights, email info@hailocare.com or write to us at the address in Section 1. Account deletion specifically can be completed without emailing us — caregivers can use the Hailo Caregiver app (Profile → Delete account) or hailocare.com/delete-account. We will verify your identity (typically by confirming control of the email or phone number on the account) and respond within the time required by applicable law — and in any event we aim to respond within 30 days. If your information is held in an agency's workspace (Section 3(b)), we will refer your request to the agency and assist it in responding.

We will never discriminate against you — deny services, charge different prices, or provide a different level of service — because you exercised privacy rights. (Note that some requests have functional consequences: for example, deleting a pending care request means agencies cannot contact you about it.)


20. U.S. State Privacy Rights

(a) California (CCPA/CPRA)

This section supplements the rest of this Policy for California residents and serves, together with Section 4, as our Notice at Collection.

Categories collected. In the preceding 12 months we have collected the following categories of personal information (as defined in Cal. Civ. Code § 1798.140), from the sources and for the purposes described in Sections 4 and 6:

CCPA categoryExamples in our ServicesDisclosed to (business purpose)Sold or shared?
IdentifiersName, email, phone, address, IP address, account IDsService providers; agencies and caregivers involved in your careSold only as described in Section 11 (care-request routing, at your direction); never shared with third parties or affiliates for marketing or promotional purposes (for mobile numbers and SMS consent, see Section 12)
Customer records (§ 1798.80(e))SSN (caregivers), government ID, insurance, bank/payment referencesService providers (Stripe, screening providers); employing agencyNo
Protected classificationsGender; date of birth; ethnicity (agency hiring forms)Responsible agencyNo
Commercial informationCare requests, subscriptions, invoices, purchasesService providers; responsible agencyCare-request details: see Section 11
Internet/network activityLog data, form submission metadata, user-agentService providersNo
Geolocation (incl. precise)Caregiver clock-in/out GPS; care addressService providers (geocoding); responsible agencyNo
Audio/visualCall recordings, voicemails, visit photos, profile photos, ID imagesService providers (Twilio, xAI); responsible agencyNo
Professional/employmentCaregiver credentials, work history, screening status, payrollResponsible agency; service providersNo
EducationCertifications and training recordsResponsible agencyNo
InferencesCare-matching preferences; AI call summariesResponsible agencyNo
Sensitive personal informationSSN; driver's license; precise geolocation; health information; financial account details; message contentsAs above, strictly for service deliveryNo

Sensitive personal information is used only for the purposes permitted by § 1798.121(a) (providing the requested services, security, verification, and legal compliance) and not to infer characteristics, so a "Limit the Use of My Sensitive Personal Information" right does not currently apply; if that changes, we will provide the required link.

Your California rights: to know/access, to delete, to correct, to opt out of sale or sharing (Section 11), to limit sensitive-information use where applicable, and to non-discrimination. Submit requests as described in Section 19 (caregiver account deletion may also be completed self-serve as described there); you may use an authorized agent with signed permission, and we will verify both your identity and the agent's authority. We do not use dark patterns in our consent or rights flows. Metrics required by § 999.317(g), if applicable, are available on request.

Retention: see Section 17; we disclose retention criteria per category there.

"Shine the Light" (Civ. Code § 1798.83): we do not disclose personal information to third parties for their direct marketing purposes.

(b) Other State Privacy Laws

If you reside in a state with a comprehensive privacy law (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others), you have similar rights of access, correction, deletion, portability, and the right to opt out of targeted advertising (which we do not do), sale (Section 11), and profiling in furtherance of decisions producing legal or similarly significant effects (which we do not perform without human involvement). You may appeal a refusal by replying to our decision email with "Appeal" in the subject; we will respond within the statutory appeal period, and you may contact your state Attorney General if you disagree with the result.

(c) Consumer Health Data (Washington My Health My Data Act, Nevada SB 370, and similar laws)

Some information we collect — for example, health conditions and care needs submitted with a care request — may be "consumer health data" under these laws where they apply and where HIPAA does not.


21. Children's Privacy

The Services are intended for adults. You must be at least 18 to create an account, and we do not knowingly collect personal information directly from anyone under 18 or sell the personal information of anyone under 16. A care recipient under 18 may be the subject of care records only where an adult client (such as a parent or guardian) or a responsible agency establishes and manages the care relationship; that adult or agency is responsible for having the authority to provide the minor's information. If you believe a child has provided us personal information directly, contact us and we will delete it.


22. International Users

The Services are operated from the United States, are directed to users in the United States, and are hosted on U.S. infrastructure. If you access the Services from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from those of your jurisdiction.


23. Third-Party Sites and Services

The Services link to third-party sites and services (for example, Calendly for demo booking, app stores, state registries, and community resources on our resources pages). Those third parties operate under their own privacy policies, and this Policy does not apply to them.


24. Changes to This Policy

We may update this Policy from time to time. If we make material changes — especially any change to the categories of information collected, the purposes of use, or the recipients — we will update the Effective Date above and provide prominent notice (for example, in-app notice or email) before the change takes effect. Where a change requires your consent under applicable law, we will obtain it.


25. How to Contact Us

Hailo LLC Attn: Privacy 25283 Cabot Rd, Ste 212 Laguna Hills, CA 92653 Email: info@hailocare.com Support: support@hailocare.com Phone: (213) 377-3979

If you have an unresolved privacy concern that we have not addressed satisfactorily, you may contact your state Attorney General or, for HIPAA matters, the U.S. Department of Health and Human Services, Office for Civil Rights.