Last updated: June 1, 2026
Skipper Software, LLC ("Skipper," "we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our non-emergency medical transportation (NEMT) scheduling platform, including our website, web application, and mobile application (collectively, the "Service").
By accessing or using the Service, you agree to this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
We collect several types of information in connection with the Service:
Name, email address, phone number, and mailing address
Account credentials (email and encrypted password)
Company name and business information
Driver information including license numbers, vehicle details, and certifications
Payment and billing information
Passenger names, dates of birth, and contact information
Medical appointment details and scheduling information
Mobility requirements, accessibility needs, and special accommodations
Transportation records related to medical appointments
Electronic proof of delivery documentation (signatures, odometer readings)
Device information (operating system, device model, unique device identifiers, app version)
Browser type and version when using the web application
Log data (IP addresses, access times, pages viewed, actions taken)
Crash reports and diagnostic data to identify and fix technical issues
Push notification tokens for delivering ride-related alerts
Application usage patterns and feature interactions
Our mobile application collects precise GPS location data from drivers during active transportation trips. Location tracking begins only when a driver explicitly taps "Begin Trip" on an assigned ride and ends when the trip (including any return leg) is completed. This data is used to:
Track trip progress and provide accurate estimated arrival times
Generate route records for proof of delivery documentation
Support dispatching and fleet coordination
Comply with NEMT regulatory reporting requirements
Location data may be collected in the background while the app is not in the foreground, but only during an active trip. Multiple safeguards enforce this boundary to prevent over-collection:
Our servers reject any location update that does not correspond to a trip currently in progress for the submitting driver.
If a driver completes a trip and no further trip is assigned within a short window, background tracking automatically ends.
Signing out of the driver app immediately stops background location collection.
If a dispatcher cancels a trip in progress, location tracking for that trip ends without driver action.
When background tracking is active, the operating system displays a persistent indicator (a notification on Android, a status bar indicator on iOS). You can verify tracking status at any time within the app.
We use the information we collect for the following purposes:
To provide, maintain, and improve the Service
To schedule and coordinate non-emergency medical transportation
To manage driver assignments, routes, and fleet operations
To generate invoices, process billing, and calculate driver pay
To produce electronic proof of delivery (ePOD) documentation
To send notifications related to ride scheduling and status updates
To comply with HIPAA, CCPA/CPRA, and other applicable regulations
To detect, prevent, and address technical issues and security threats
To communicate with you about the Service, including updates and support
We do not sell your personal information. We may share your information in the following circumstances:
With healthcare providers and brokers as necessary to coordinate transportation services
With service providers who assist us in operating the Service (e.g., cloud hosting, payment processing), subject to contractual obligations to protect your data
With your employer or contracting NEMT company, as applicable to your role
When required by law, regulation, legal process, or governmental request
To protect the rights, property, or safety of Skipper, our users, or the public
In connection with a merger, acquisition, or sale of assets, with notice to affected users
We use the following categories of third-party services to operate and improve the Service. These providers process data on our behalf under contractual obligations:
Cloud infrastructure and hosting services
Error monitoring and crash reporting (e.g., Sentry) to diagnose and fix technical issues
Push notification delivery services
Analytics services to understand usage patterns and improve the Service
Application update delivery to provide bug fixes and improvements
We implement appropriate technical and organizational measures to protect your information, including:
Encryption of data in transit using HTTPS/TLS protocols
Encryption of sensitive data at rest
Secure on-device storage of authentication credentials using platform-provided secure enclaves (iOS Keychain, Android Keystore)
Role-based access controls limiting data access to authorized personnel
Regular security assessments and vulnerability testing
Secure authentication mechanisms including token-based authentication with automatic session expiration
Audit logging of access to protected health information
Local data caching on mobile devices is limited to schedule information required for offline operation and is cleared on sign-out
While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to maintaining industry-standard protections.
As a platform handling protected health information (PHI) related to non-emergency medical transportation, Skipper operates in compliance with the Health Insurance Portability and Accountability Act (HIPAA) and the HITECH Act.
We act as a Business Associate when processing PHI on behalf of Covered Entities
We enter into Business Associate Agreements (BAAs) with applicable customers
We implement administrative, physical, and technical safeguards as required by the HIPAA Security Rule
We limit the use and disclosure of PHI to the minimum necessary for the intended purpose
We maintain policies and procedures for breach notification in compliance with HIPAA requirements
We train our workforce on HIPAA privacy and security requirements
To execute a Business Associate Agreement with Skipper, please contact us at legal@skippernemt.com.
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which your information was collected, the business or commercial purposes for collection, and the categories of third parties with whom we share your information.
You have the right to request the deletion of your personal information, subject to certain exceptions (such as data needed to complete a transaction, comply with legal obligations, or maintain security). For step-by-step instructions on deleting your account and the data we remove or retain, see our Account & Data Deletion page.
You have the right to opt out of the sale or sharing of your personal information. As stated above, Skipper does not sell your personal information.
We will not discriminate against you for exercising any of your CCPA/CPRA rights. You will not receive different pricing or quality of service as a result of exercising your rights.
To exercise any of these rights, please contact us at legal@skippernemt.com. We will verify your identity before processing your request and respond within 45 days as required by law.
We retain your personal information for as long as your account is active or as needed to provide the Service. We may also retain and use your information as necessary to comply with legal obligations (including HIPAA record retention requirements), resolve disputes, and enforce our agreements. Transportation records containing PHI are retained in accordance with applicable state and federal regulations.
When your data is no longer required, we will securely delete or anonymize it in accordance with our data retention policies.
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe we may have collected information from a child, please contact us at legal@skippernemt.com.
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date. For significant changes, we may also provide additional notice (such as an email notification or in-app alert). Your continued use of the Service after any changes constitutes your acceptance of the revised Privacy Policy.
If you have any questions about this Privacy Policy, your personal information, or wish to exercise your privacy rights, please contact us at:
Skipper Software, LLC