Legal

Privacy Policy

Last updated: July 27, 2026

This page is maintained by My Florida NEMT to explain how we collect, use, protect, and share information across our patient, facility, and provider portals at myfloridanemt.com. It is written in plain language and updated as our platform changes.

1. Who we are

My Florida NEMT ("My Florida NEMT," "we," "us") operates a non-emergency medical transportation technology platform connecting patients and healthcare facilities with approved transportation providers across Florida. This Privacy Policy applies to myfloridanemt.com, our patient, facility, provider, dispatch, and admin portals, and any related services (collectively, the "Service").

2. Information we collect

We collect information you provide directly and information generated when you use the Service.

Account & contact information

Name, email address, phone number, mailing/service address, business name (for facilities and providers), role, and password credentials managed through our authentication provider.

Trip & ride request information

Pickup and drop-off addresses, appointment dates and times, service level (ambulatory, wheelchair, stretcher, medical delivery), mobility needs, passenger details, patient email for follow-up communications, notes to the driver, recurring schedule preferences, and round-trip return details.

Provider & driver information

Business licenses, insurance certificates, vehicle registration and inspection records, driver's license and background check documentation, training/course completion records, service areas, pricing preferences, payout account status, and compliance review notes.

Payment information

Payment card details, bank/ACH information for payouts, and billing address are collected and processed by Stripe, our payment processor. See Section 5 for details. We do not store full card numbers on our servers.

Messages & support content

Messages you send through in-app threads, contact forms, feedback submissions, and support emails, including attachments you choose to share.

Usage & device data

IP address, browser type, device identifiers, pages viewed, referring URLs, timestamps, and diagnostic logs used to keep the Service secure and reliable.

Location information

Pickup/drop-off addresses and ZIP codes you enter, and — where applicable and with your permission — approximate location used to match dispatch zones and estimate mileage.

3. How we use information

  • Create and manage patient, facility, provider, and staff accounts.
  • Schedule, route, dispatch, and complete trips and medical deliveries.
  • Generate quotes, calculate fares, process payments, and issue payouts.
  • Verify provider credentials, insurance, and Medicaid eligibility.
  • Send trip confirmations, invoices, receipts, and status notifications by email and in-app messages.
  • Provide customer support and respond to inquiries.
  • Protect the Service against fraud, abuse, and unauthorized access.
  • Comply with legal, regulatory, and contractual obligations.
  • Improve reliability, safety, and user experience.

4. Patient health information & HIPAA

My Florida NEMT handles limited protected health information (PHI) — such as appointment locations, mobility needs, and Medicaid eligibility data — necessary to arrange non-emergency medical transportation. We treat this information with the confidentiality standards expected under HIPAA and related state laws.

  • Access to PHI is role-based and restricted through row-level security in our database.
  • Providers and facilities acknowledge HIPAA obligations in their portal settings before handling patient data.
  • PHI is shared only with the assigned provider, dispatcher, and administrative personnel who need it to complete the trip.
  • Audit logs record administrative actions on sensitive records.

If you are a covered entity or business associate and need a Business Associate Agreement, contact us at myfloridanemt@gmail.com.

5. Payments & Stripe

Payments and provider payouts are processed by Stripe, Inc. When you pay for a trip, save a payment method, or receive a payout, your payment details are collected directly by Stripe and transmitted to Stripe's servers over an encrypted connection.

  • What Stripe receives: card or bank account details, billing name and address, email, amount, currency, and information needed to detect fraud and comply with financial regulations.
  • What we store: a Stripe customer ID, a reference to the saved payment method (last 4 digits and card brand), payment status, invoice/receipt records, payout status, and platform fee amounts tied to each trip. We do not store full card numbers, CVCs, or bank credentials.
  • Provider payouts: providers who receive payouts complete Stripe Connect onboarding. Identity verification and banking information provided during that flow are held by Stripe.
  • Payout timing: standard trips settle on a 48-hour hold; Medicaid trips settle on a Net-15 schedule. Financial records tied to a trip are protected against unauthorized edits.
  • Stripe's own policies: your interactions with Stripe are subject to Stripe's Privacy Policy and Terms of Service.

6. How we share information

We share information only as needed to operate the Service:

  • With assigned providers and dispatchers — the trip details needed to safely complete a pickup, including passenger name, addresses, contact number, and mobility needs.
  • With facilities that booked a trip on a patient's behalf — status updates and completion records for trips they scheduled.
  • With service providers and subprocessors that help us run the platform (see Section 7).
  • With payers, brokers, or Medicaid programs when required to authorize or bill a trip.
  • For legal reasons — to comply with subpoenas, court orders, or applicable law, or to protect the rights, safety, or property of users, the public, or My Florida NEMT.
  • In a business transfer — in the event of a merger, acquisition, or sale, with notice to affected users.

We do not sell personal information. We do not use PHI for advertising.

7. Service providers & subprocessors

We use trusted third parties to operate the Service:

  • Supabase — hosted database, authentication, and file storage.
  • Stripe — payment processing and provider payouts.
  • Resend — transactional email delivery (confirmations, invoices, receipts).
  • Cloudflare — content delivery, DDoS protection, and edge hosting.
  • Google Maps / geocoding services — address lookup and mileage estimates.

Each subprocessor is bound by contractual obligations to safeguard your information and use it only to provide services to us.

8. Cookies & analytics

We use cookies and similar technologies to keep you signed in, remember preferences, and measure how the Service is used. You can control cookies through your browser settings. Blocking essential cookies may prevent you from signing in or completing bookings.

9. Data retention & deletion

We retain information for as long as your account is active and as needed to provide the Service, meet legal and tax obligations, resolve disputes, and enforce our agreements. Trip, payment, and payout records tied to financial or regulatory reporting are retained for the periods required by applicable law.

Unconfirmed reservations that are never approved are automatically removed after 60 days. You may request deletion of your account information as described in Section 11.

10. Security

We use encryption in transit (HTTPS/TLS), encrypted storage at rest through our hosting provider, role-based access control, row-level security policies, restricted admin functions, audit logging, and periodic security reviews. No system is perfectly secure — please use a strong, unique password and notify us immediately if you suspect unauthorized access to your account.

11. Your rights & choices

Depending on where you live, you may have rights to:

  • Access the personal information we hold about you.
  • Correct inaccurate information.
  • Request deletion of your account and associated personal information, subject to legal retention requirements.
  • Opt out of non-essential marketing emails (transactional emails required to operate a trip cannot be opted out of while an active booking exists).
  • Request a copy of your data in a portable format.

To exercise these rights, email us at myfloridanemt@gmail.com from the address on file. We may need to verify your identity before responding.

12. Children's privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13 except as needed to arrange transportation for a minor patient booked by a parent, guardian, or authorized facility. If you believe a child has provided information without proper authorization, contact us and we will delete it.

13. Changes to this policy

We update this Privacy Policy as our platform evolves. Material changes will be posted on this page with a new "Last updated" date and, where appropriate, communicated by email or in-app notification.

14. Contact us

Questions or concerns about this policy or your information? Reach out anytime: