This policy explains what StandbyProof (Casting Karma LLC) collects, why, and your choices. We do not sell your personal information, we don't show third-party ads, and we don't use advertising trackers.
The most important thing: we do not collect patient information
StandbyProof is a facilities and equipment compliance tool. It is not built for patient data, and you must not put Protected Health Information (PHI) into it (see Terms §2). We do not act as a HIPAA business associate, and the information below is about facility staff and equipment — not patients or residents.
What we collect
Account: your name, work email, facility/organization, role, and — only if you enable SMS reminders — your mobile phone number. Passwords are hashed by our authentication provider.
Facility & equipment data: facility name, address, and identifiers (e.g., CCN), and details about your generators, transfer switches, and related equipment.
Your logs & uploads: the tests and inspections you record, plus any notes and photos you attach (of equipment, gauges, and readings — not people or patients).
Payment: handled by our payment processor (Stripe); we never see or store full card numbers.
Usage/technical: device/browser, IP address, and error logs, to keep the service working and secure.
Consent records: which terms version you accepted, when, and the IP/browser used.
How we use it
To provide the service — build your schedule, send the reminders you set, store your logs, and generate your documentation packet — plus to process payments, secure and improve the service, and support you.
SMS reminders
If you opt into text reminders, we use your mobile number solely to send scheduling/compliance reminders. Message and data rates may apply; reply STOP to cancel, HELP for help. We do not sell or share your number for third-party marketing. Consent to texts is not required to buy or use StandbyProof.
Service providers
We use trusted vendors to run StandbyProof, each processing data only to provide their part of the service: our cloud hosting and database provider (Cloudflare), Stripe (payments), our email delivery provider (Resend), and — where SMS is offered — our SMS delivery provider (Twilio). We do not sell or rent your information, and we share it only with these providers, to comply with law, or to protect the service.
Data retention, deletion & your choices
You can edit or delete records, export your data, and delete your account at any time. When you delete your account we remove your profile and data from our live systems, and it ages out of encrypted backups within about 30 days. We keep transaction records as long as tax and accounting law requires (generally up to seven years), and consent records as long as needed to show what was agreed. To make a privacy request, email [email protected] — we respond within 30 days, honor requests for all users regardless of where they live, and never charge you or degrade your service for exercising a privacy right.
Cookies & security
We use the cookies needed to keep you signed in and the service secure. We use encryption in transit and at rest, access controls that keep one facility's data separate from another's, and hashed passwords. No service can promise perfect security, but if a breach ever affects your personal information we'll notify you and any regulator the law requires, without undue delay.
Children
StandbyProof is a business tool for adults (18+) and is not directed to children.
Changes & contact
We'll post material changes here with a new version and date and ask you to accept them at next sign-in.
Privacy requests: [email protected]
General help: [email protected]