Practice Business Insights

Privacy Policy

Effective August 13, 2026

Practice Business Insights is operated by Ascend Business Insights, LLC, a Georgia limited liability company (“we,” “us,” or “our”). We provide retention and performance analytics to nutrition and wellness practices.

This policy explains what we collect, why we collect it, who we share it with, and how long we keep it. It covers this website and the Practice Business Insights application.

Two different kinds of information

Information about you. If you visit this site, request a demo, or hold an account with us, we handle information about you as described in this policy. We decide how that information is used.

Patient information.When a practice connects its data to our platform, we process patient information strictly on that practice's behalf and on its instructions. Under HIPAA the practice is the covered entity and we are its business associate. Our handling of that information is governed by our Business Associate Agreement with the practice and by HIPAA, not by this policy. We never sell it and never use it for advertising. We use it to produce the analytics that practice has asked for and to support and secure the service, and we do not combine one practice's patient information with another's. Where our Business Associate Agreement permits, we may create de-identified information under the HIPAA standard; once de-identified, it no longer identifies any patient or practice. If you are a patient, see If you are a patient below.

Information we collect

When you visit this website

  • Aggregate usage measurements. We use Vercel Web Analytics to count page views and understand which pages are useful. It does not use cookies, does not build a profile of you, and does not track you across other websites.
  • Server logs. Our hosting provider records standard request information, including IP address, browser type, and the page requested, and retains it for a limited period for security and reliability.
  • Anything you type into a form. Our newsletter, demo request, and contact forms are embedded from GoHighLevel, our marketing CRM. What you submit — typically your name, email address, practice name, and message — goes to that system so we can reply to you. These embedded forms are served by GoHighLevel and may set their own cookies.

When you hold an account with us

  • Account details — your name, email address, practice or clinic name, role, and the plan you are on. Passwords are stored only as salted hashes by our authentication provider; we never see them.
  • Security information — multi-factor authentication enrollment, and a record of devices you have chosen to trust so you are not prompted for a code on every sign-in.
  • Billing information — your subscription status, plan, and billing contact. Card numbers are entered directly with Stripe and are never transmitted to or stored on our systems.
  • Connection credentials — if you connect your Practice Better account, the API credential you supply. It is encrypted at rest and is never exposed to your browser.
  • Audit and activity records — a tamper- resistant log of security-relevant actions such as sign-ins, permission changes, and exports of data. HIPAA requires us to keep these.
  • Product usage events — for example, that a dashboard was viewed, so we can tell which features earn their place.
  • Support and feedback — anything you send us through the in-app feedback form, including any screenshot you attach. Please see Retention and deletion for how long we keep these.
  • Agreement records — a record that you accepted our User Agreement or a Business Associate Agreement, including the version, the date and time, and the email address that accepted it.

Patient information we process for a practice

When a practice connects its Practice Better account or uploads an export, we receive a deliberately narrow slice of its records — only what is needed to calculate retention and practice performance:

  • Patient first and last name, and email address
  • Appointment dates, times, and duration
  • Appointment or service type, such as “Initial Consultation”
  • Appointment status, such as attended, cancelled, or no-show
  • The practitioner seen, and any tags the practice applies to a patient record

We do not receive or store clinical notes, diagnoses, lab results, treatment or nutrition plans, Social Security numbers, insurance information, payment card details, or patient home addresses. We do not contact patients, and the platform is not used to deliver care or clinical advice.

How we use information

We use information about you to:

  • Provide, secure, and support the platform, and authenticate your sign-ins
  • Bill you and manage your subscription
  • Respond when you contact us, and send service notices you need to receive
  • Send marketing email only where you have asked for it, and every such message includes a one-click unsubscribe
  • Diagnose faults, prevent abuse, and improve the product
  • Meet our legal, contractual, and HIPAA obligations

We use patient information only to generate the analytics the practice has asked us to generate, to support and secure the service, and as otherwise permitted by our Business Associate Agreement with that practice.

We do not sell personal information, and we do not share it with advertisers or data brokers. We do not use patient information to train third-party artificial intelligence models.

Cookies

We keep this simple. The application sets cookies that are strictly necessary to run it: they keep you signed in, protect against cross-site request forgery, and remember a device you have chosen to trust for multi-factor authentication. Sessions end automatically after a period of inactivity.

This marketing website sets no advertising or cross-site tracking cookies of its own. Our analytics are cookieless. The marketing forms embedded on this site are served by GoHighLevel and may set cookies of their own when they load.

Who we share information with

We rely on a small number of established service providers to run the business, each only to the extent needed to do its job:

  • Cloud hosting and database

    Runs the application and stores your account data and your practice data.

    Can hold patient information, and operates under a Business Associate Agreement with us.

  • Payment processing

    Takes your subscription payment. Card details go directly to the processor and never reach us.

    Receives no patient information.

  • Transactional email

    Sends sign-in, billing, and service notices. Receives your name and email address only.

    Receives no patient information.

  • Marketing and CRM

    Powers the forms on this website and holds the contact details you submit through them.

    Receives no patient information.

Customers who need the specific vendors named — for a security review or a compliance questionnaire — can request the current list from us in writing. We keep it out of this page so that changing a vendor does not require amending a published document.

Your own practice management system is not on this list, because it is yours rather than ours. We read from it only with the credential you give us, and only at your direction.

We never put patient information in email. This is a firm rule rather than a preference: notifications link you into the application to see the detail, instead of describing anything in the message itself.

We may also disclose information if the law requires it, to enforce our agreements, or to protect the rights and safety of our users. If we are ever party to a merger or acquisition, information may transfer as part of that transaction, and any patient information would remain subject to the same HIPAA obligations.

How we protect information

All data is stored in the United States and encrypted in transit and at rest. Multi-factor authentication is mandatory for every account. Each practice's data is isolated at the database layer, not merely in application code, so one practice cannot query another's records. Access to production systems is limited to personnel who need it, sessions log out automatically after a period of inactivity, and security-relevant actions are recorded in an append-only audit log.

No system is perfectly secure, but if a breach affects your information we will notify you, and any affected practice, as required by HIPAA and applicable state law.

Retention and deletion

We keep information about your account for as long as your account is open. You can delete your account at any time from Settings, and you can ask us to delete it by writing to us. When an account is deleted we remove your profile and any practice connection credentials you supplied.

What happens to the practice itself depends on who is left on it. If another administrator remains, the practice and all of its data stay and we remove only your access. If you were its last administrator, we delete the practice and all of the patient data held for it — and we do this even if colleagues who are not administrators still have accounts on that practice, because a practice with no administrator can no longer be managed or reconnected. Everyone who had access is emailed to tell them the practice has been removed. The same applies if you were the only person on the practice at all, whatever your role.

One kind of record deliberately survives account deletion. We want to be plain about it rather than bury it: your acceptance of the User Agreement, and of any Business Associate Agreement, is kept — along with the email address that accepted it and the date. These are the evidence that an agreement was in force, and deleting them would destroy the record of a contract. This is standard practice for signed agreements, and it is the only exception.

Feedback and bug reports you sent us are deleted with your account — the message, and any screenshots attached to it. Those screenshots are pictures of the app taken while you were working, so one can show patient information, and we would rather lose a useful bug report than keep it. If a practice is deleted, the feedback sent about it goes too, including anything your colleagues sent. You can also ask us to delete a single submission at any time, without closing your account, and we will.

We also retain audit logs for the period HIPAA requires, and billing records for as long as tax and accounting law requires.

Where we act as a business associate, deletion and return of patient information at the end of an engagement is governed by the Business Associate Agreement with that practice.

Your choices and rights

  • Access, correct, or delete your account. Most of this you can do yourself in Settings. For anything you cannot, write to us and we will handle it.
  • Export your data. The platform lets you export the underlying data behind any chart or table.
  • Stop marketing email. Use the unsubscribe link in any marketing message. We will still send essential service and billing notices while you have an account.
  • State privacy rights. Depending on where you live you may have additional rights over personal information, including the right to know what we hold and to ask us to delete it. Write to us and we will honor them; we will not discriminate against you for exercising them. Note that information covered by HIPAA is handled under HIPAA rather than under state consumer privacy law.

If you are a patient

If you are a patient of a practice that uses Practice Business Insights, we hold a limited record of your appointments because your practice asked us to analyze its own data. We have no relationship with you directly, and we are not permitted to change or release your records on our own initiative.

Please direct any request to see, correct, or delete your information to your practice. They are the covered entity under HIPAA, their Notice of Privacy Practices governs your records, and we will act promptly on any instruction they give us about your data.

Children

The platform is a business tool sold to practices and is not directed to children, and we do not knowingly collect information from children through this website. Where a practice treats minors, any appointment records it sends us are handled as patient information under its Business Associate Agreement.

Changes to this policy

If we make a material change to how we handle information, we will update the effective date at the top of this page and notify account holders by email or in the application before the change takes effect.

Contact us

Questions about this policy, or a request about your information, can go to info@practicebusinessinsights.com.

Ascend Business Insights, LLC
300 Colonial Center Parkway, Suite 100
Roswell, GA 30076