◆ CareView by Villa Marketing
CareView legal

Privacy Policy

Effective July 17, 2026

This policy explains how CareView, operated by Villa Marketing ("CareView," "we," "us"), handles information when authorized organizations and users access the CareView assisted-living operations platform.

CareView is an operations and financial reporting tool. It is not intended to store medical records, protected health information, resident clinical notes, Social Security numbers, payment-card data, or other unnecessary sensitive personal information. Users should not upload that information.

1. Information we process

2. How we use information

We use information to authenticate users; enforce organization, role, and facility permissions; provide dashboards, imports, reports, alerts, scheduled summaries, integrations, and support; detect and fix errors; protect the service; maintain audit records; and comply with legal obligations.

3. Service providers and disclosures

We do not sell personal information or use CareView data for third-party advertising. We disclose information only as needed to operate the service, at an organization's direction, or when legally required. Current service providers include:

We may also disclose information during a business transfer, to protect rights and security, or to respond to lawful process. We require service providers to process data only for the services they provide to us.

4. QuickBooks access and disconnection

CareView requests the QuickBooks Online Accounting scope. It uses that access to read accounting reports, account lists, and classes for authorized dashboards and mappings; CareView does not create or modify QuickBooks transactions. An authorized CareView administrator can disconnect a facility from the Platform page. Disconnection revokes the Intuit token and stops future synchronization. Existing CareView snapshots and reports remain until deleted under the organization's retention instructions.

5. Retention and deletion

We retain account, operational, and integration information while the organization uses CareView and as reasonably needed for security, audit, backup, dispute resolution, and legal compliance. OAuth tokens are retained only while the connection remains active. Organizations may request access, correction, export, or deletion through the contact below. Some information may remain temporarily in backups or where retention is legally required.

6. Security

CareView uses encrypted network connections, Firebase Authentication, role- and facility-scoped access rules, server-only integration credentials, restricted service accounts, audit logs, and managed cloud infrastructure. No system is completely secure, and users are responsible for protecting their accounts and promptly reporting suspected unauthorized access.

7. Your choices and rights

Depending on applicable law, individuals may have rights to access, correct, delete, restrict, or receive a copy of personal information. Most CareView business data is controlled by the customer organization; requests may be routed to that organization for verification and response. Users may also disconnect QuickBooks access and change email-alert recipients through authorized administrators.

8. Children and medical information

CareView is a business service for authorized adult users and is not directed to children. CareView is not a clinical record system and should not be used to upload medical records or protected health information.

9. Changes to this policy

We may update this policy as CareView changes. We will post the revised policy here and update its effective date. Material changes may also be communicated to customer administrators.

Privacy contact
Villa Marketing — CareView
nate.villa246@gmail.com