Effective Date: April 13, 2025
Steppable Inc. ("Steppable," "we," "us," or "our") is committed to protecting the privacy and security of personal information. This Privacy Policy describes how we collect, use, disclose, store, and protect the sensitive information we receive through our platform and related services (collectively, the "Services"). Our mission is to accelerate human development by helping providers create, share, and implement behavior intervention plans. Our Services are designed to support providers in developing, collaborating on, and tracking the implementation of these plans, while also facilitating billing processes for both Medicaid and private insurance reimbursement. This comprehensive approach supports better outcomes for individuals receiving care while ensuring providers can efficiently manage their billing needs. By accessing or using our Services, you ("you," or "user") agree to the terms of this Privacy Policy.
This Privacy Policy applies to information collected from:
Steppable complies with all applicable privacy and security laws, including the Family Educational Rights and Privacy Act ("FERPA") and the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), to the extent those laws apply to the services we provide. We also enter into Business Associate Agreements ("BAAs") with Districts where required by HIPAA regulations.
When users interact with our Services, we may automatically collect:
If required by applicable law, we rely on certain legal bases to process personal information, including:
We share student, parent/guardian, and staff information with authorized District personnel to deliver our Services in accordance with applicable legal and contractual obligations.
We may engage trusted third-party vendors to help us operate our Services (e.g., cloud hosting, analytics, or payment processing). These vendors have access to personal information solely for the purpose of performing tasks on our behalf and are obligated to maintain the privacy and security of such information.
We may disclose personal information where required to comply with a subpoena, court order, legal process, or government request; or to establish or exercise our legal rights; or to defend against legal claims.
In the event of a merger, acquisition, bankruptcy, or other business transaction, personal information may be transferred as part of the transaction. In such cases, we will provide notice to the District and/or affected users as required by law.
We may create de-identified or aggregated data for research, analytics, or statistical purposes. Such data cannot reasonably be used to identify any individual and is not considered personal information under this Privacy Policy.
We retain personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with our legal obligations, resolve disputes, enforce our agreements, or as otherwise directed by the District. Upon request and in line with applicable laws, we will securely delete or de-identify personal information within reasonable timeframes.
Steppable takes reasonable administrative, technical, and physical measures to protect the information we collect, including:
Despite these measures, no data transmission or storage system can be guaranteed to be 100% secure. If we become aware of a data breach, we will notify the affected District and take appropriate remedial action in accordance with applicable laws and regulations.
Our Services are designed to be used under the direction and control of Districts. We do not knowingly collect personal information directly from children under the age of 13 without the express permission of a parent/guardian or the District, as permitted by law. If you believe we have received information directly from a child without proper authorization, please contact us at the information provided in Section 12 below so we can delete such information.
Depending on your jurisdiction, you may have certain rights regarding your personal information, such as the right to:
Parents/guardians and eligible students should direct requests regarding educational records to their District in accordance with FERPA. For HIPAA-related requests, individuals can contact both their District and Steppable if Steppable acts as a Business Associate processing PHI on the District's behalf. We will work with the District to fulfill these requests as required by law.
Our Services are primarily intended for use within the United States. If we transfer personal information outside of the country or region where it was originally collected, we will take steps to ensure appropriate safeguards are in place to protect the data, in accordance with applicable laws.
We may update this Privacy Policy from time to time. If we make material changes, we will notify the District (and/or affected users, where appropriate) via email or through the Services before the changes take effect. The "Last Updated" date at the top of this Privacy Policy indicates when it was most recently revised.
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
We value the trust you place in Steppable to protect sensitive information, and we are committed to maintaining robust privacy and security safeguards in accordance with applicable laws and industry best practices.