LAST UPDATED: 12.10.25
Carta Healthcare, Inc. ("Carta Healthcare," "we," "our," or "us") respects your privacy and is committed to protecting it through our compliance with this policy.
This Privacy Policy describes the types of information we may collect from you or that you may provide when you visit the website www.carta.healthcare (our "Website") and our practices for collecting, using, maintaining, protecting, and disclosing that information.
Important Note Regarding Patient Data (HIPAA):
This Privacy Policy applies specifically to the data collected via our public-facing Website (e.g., marketing forms, job applications, and browsing data). It does not apply to Protected Health Information (PHI) that we process on behalf of our hospital and health system clients through our products (such as Atlas, Voyager, and Lighthouse). The processing of PHI is governed by the Health Insurance Portability and Accountability Act (HIPAA) and the specific Business Associate Agreements (BAAs) we have in place with our clients.
We collect several types of information from and about users of our Website, including:
As you navigate through and interact with our Website, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions, and patterns, including:
We use cookies (small files placed on the hard drive of your computer), web beacons, pixels, and similar tracking technologies to help us improve our Website and deliver a better and more personalized service. We use the following types of cookies: (1) strictly necessary cookies required for website functionality; (2) performance/analytics cookies to understand how visitors use our site; (3) functionality cookies to remember your preferences; and (4) targeting/advertising cookies to deliver relevant advertisements. You may refuse to accept browser cookies by activating the appropriate setting on your browser or by using our cookie preference center [INSERT LINK]. However, if you disable strictly necessary cookies, you may be unable to access certain parts of our Website
We use information that we collect about you or that you provide to us:
We do not sell your Personal Information to third parties. We may disclose aggregated information about our users, and information that does not identify any individual, without restriction.
We may disclose Personal Information that we collect or that you provide as described in this Privacy Policy:
While we are a B2B healthcare technology company, we recognize that residents of certain states, including California (under CCPA/CPRA), Virginia (under VCDPA), Colorado (under CPA), Connecticut (under CTDPA), Utah (under UCPA), and other states with comprehensive privacy laws, have specific rights regarding their personal information.
Depending on your jurisdiction, you may have the right to:
To exercise these rights, please contact us at [Insert Privacy Email Address, e.g., privacy@carta.healthcare].
California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (as amended by the California Privacy Rights Act):
Categories of Personal Information We Collect
In the past 12 months, we may have collected the following categories of personal information:
Purposes for Collection
We collect and use this information to:
Disclosure of Personal Information
We may disclose personal information to:
We do not sell personal information for monetary or other valuable consideration. However, our use of certain cookies, pixels, and analytics tools that allow third parties to collect information about your online activity over time and across different websites or applications may be considered "sharing" for cross-context behavioral advertising purposes under California law. You can opt out of this sharing as described in the "Cookies and Online Tracking" section below.
Your Rights Under CCPA/CPRA
As a California resident, you have the right to:
How to Exercise Your Rights
You may submit a request by:
We will verify your identity before fulfilling your request. You may also designate an authorized agent to make a request on your behalf.
We have implemented measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure. Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted to our Website. Any transmission of personal information is at your own risk.
Our services are not directed to individuals under 18, except with parental consent. We do not knowingly collect personal information from minors without such consent.
Our Website may contain links to third-party websites (e.g., news articles, partner websites, or social media platforms). We are not responsible for the privacy practices or content of those third-party sites. We encourage you to read the privacy policies of any website you visit.
It is our policy to post any changes we make to our Privacy Policy on this page. The date the Privacy Policy was last revised is identified at the top of the page. You are responsible for ensuring we have an up-to-date active and deliverable email address for you, and for periodically visiting our Website and this Privacy Policy to check for any changes.
To ask questions or comment about this Privacy Policy and our privacy practices, contact us at: