Privacy at a glance

Price searches

In the current public price search, ZIP code, procedure or CPT code, health-plan selection, and deductible information are filtered in the browser against data already delivered to the device. CashPayMed’s application does not submit those price-search fields to a server to perform the search.

This description applies to the current release. This policy must be updated before CashPayMed changes how those searches work.

Hospital and public-record searches

The hospital directory first attempts to match a hospital, city, state, or ZIP using information in the browser.

When a local match is unavailable, the browser may send a hospital or organization name, a five-digit ZIP code, or a public record identifier to a Supabase-hosted CashPayMed search function. These values are included in the request URL and may be received by Supabase and the network services carrying the request.

Do not use a search field for a patient name, medical-record number, insurance member number, billing-account number, or other confidential information.

Browser storage

CashPayMed may save the selected light or dark theme in the browser’s local storage under cpm-theme. That preference remains on the device until it is changed or cleared through the browser.

Removed Ask and feedback feature

The former Ask and feedback controls, optional email field, and related network code have been removed from this candidate.

A feedback feature must not be reintroduced until it uses a CashPayMed-controlled endpoint with an approved notice, data minimization, retention schedule, deletion process, abuse controls, and security review.

Hosting and network information

CashPayMed pages are currently delivered through Vercel. Like other hosting systems, Vercel may receive an IP address, browser and device information, requested page or asset, referrer, date and time, and security or error information.

CashPayMed has not completed provider-by-provider verification of the exact retention periods for all hosting metadata. CashPayMed therefore does not promise that every hosting provider deletes every request record within a particular period.

Public-record service

Some hospital and ranking pages request public records from a Supabase-hosted service. Supabase may receive the requested URL, public search value or record identifier, IP address, browser information, and request time.

CashPayMed does not have verified evidence supporting a fixed deletion period for all Supabase-controlled operational records.

Fonts

This candidate uses a system serif fallback and does not request a third-party font. Typography may render differently by device until a licensed, byte-pinned local font package is independently approved.

Analytics

This candidate does not load a web analytics script or emit a custom search event. Hosting and public-data services may still create operational request logs as described above; runtime retention and redaction require separate owner and provider verification.

Email and voluntary information

If a person emails CashPayMed, CashPayMed and its email provider receive the sender’s address, message, attachments, and related delivery information.

Send only the public record and source details needed to investigate a correction or site problem. Do not send medical records, bills containing patient identifiers, insurance cards, Social Security numbers, account numbers, or payment-card information.

A fixed deletion schedule for correction email and provider-controlled mail logs has not yet been verified. CashPayMed keeps correspondence only as needed to investigate the report, maintain data accuracy, address security or legal requirements, and document material source decisions.

How information is used

CashPayMed may use received information to:

Selling, advertising, and disclosure

Information may be handled by service providers needed to operate the site, deliver public data, or receive email. CashPayMed may also disclose information when reasonably necessary to comply with law, protect the service, investigate abuse, or protect the rights and safety of others.

Following an external source link causes the browser to contact that third-party website. Its privacy practices apply after the link is opened.

Security

CashPayMed uses technical and operational safeguards appropriate to a public-information site, but no website or email system can guarantee absolute security.

CashPayMed is not a patient portal. Do not use it to transmit confidential medical, insurance, billing, or identity information.

Choices and requests

A visitor may use the current price search without creating an account. Browser settings can clear the saved theme and restrict third-party requests made when a visitor opens an external source or when a hospital-record query uses the public-data service.

For a privacy question or request, use the contact page and include only the information needed to understand the request.

Changes

CashPayMed may update this policy when the service, data flow, providers, or retention practices change. The effective date will change when a material revision is published.