dailybuilt
  • Platform
  • Pricing
  • Writing
  • Get early access
Get early access
Legal

Consumer Health Data Privacy Policy

A standalone policy describing only consumer health data. It applies when you use a booking, intake, or payment page dailybuilt hosts for a business and the appointment itself says something about your health.

Effective July 28, 2026

This is DailyBuilt's Consumer Health Data Privacy Policy under the Washington My Health My Data Act, RCW 19.373 ("MHMDA"). It is a standalone policy. It describes only consumer health data. Our general privacy practices are described in our Privacy Policy, and the terms that apply when you use a page we host for a business are in our End-User Terms and Consumer Privacy Notice.

"DailyBuilt," "we," "us," and "our" mean DailyBuilt, Inc., a Delaware corporation. "You" and "consumer" mean a natural person who is a Washington resident, or whose consumer health data is collected in Washington, acting in an individual or household capacity.


1. What this policy covers, and what it does not

Covered. This policy covers consumer health data that we collect through the pages DailyBuilt hosts for a business that offers health-adjacent or wellness services and that is not a HIPAA covered entity or business associate — for example, a booking page at businessname.dailybuilt.co/book, and the appointment emails, text messages, document-signing pages, and payment pages that follow from a booking on that page.

Not covered — protected health information. MHMDA does not apply to protected health information ("PHI") governed by the Health Insurance Portability and Accountability Act. RCW 19.373.100. When a business on DailyBuilt operates in our Healthcare Edition, it is a HIPAA covered entity, DailyBuilt is its business associate, and the information you provide is PHI. That information is governed by HIPAA and by the Business Associate Agreement between DailyBuilt and that business, not by this policy. If you are unsure which applies, ask the business, or contact us at hello@dailybuilt.co and we will tell you.

Also not covered. Information that is exempt under RCW 19.373.100, including de-identified data, publicly available information, and information governed by the Gramm-Leach-Bliley Act, the Fair Credit Reporting Act, or other laws listed in that section. Information about you in your capacity as an employee or contractor of a business, rather than as an individual consumer, is outside MHMDA's definition of "consumer." RCW 19.373.010.

2. Our role, and why we publish this policy

For nearly everything described here, the business you booked with decides what to collect and why. It chooses the services it offers, writes the intake questions on its booking form, decides who on its staff sees your answers, and decides how long to keep them. DailyBuilt provides the software and processes that data on the business's instructions. In MHMDA terms, the business is generally the regulated entity and DailyBuilt is generally its processor. RCW 19.373.010; RCW 19.373.060.

We publish this policy anyway, and we treat ourselves as a regulated entity for the limited data described in Sections 3.7 and 3.8, because DailyBuilt — not the business — decides the means by which some data is collected on the pages we host: the web analytics we run, the anti-abuse challenge we present, the error diagnostics we capture, and the systems in which all of it is stored. We would rather give you a clear, honest account of that than argue about labels.

What this means in practice. If you send us a request under Section 7, we will act on it directly for the data we control, and for data we hold on a business's behalf we will route your request to that business and support it in responding. Section 7.6 explains exactly how.

3. Categories of consumer health data we collect, and why

The following categories may be linked or reasonably linkable to you and may identify your past, present, or future physical or mental health status, so we treat them as consumer health data under RCW 19.373.010.

3.1 The existence and details of an appointment

What. That you requested, booked, rescheduled, cancelled, or did not attend an appointment with a specific business; the date, time, and time zone; whether it is in person, by phone, or at a location the business specifies, and any address or meeting link; the party size; and whether the appointment was completed.

Why we collect it. To create and hold the appointment you asked for, to show the business its schedule and prevent double-booking, and to send you confirmations, reminders, changes, and cancellations. This is the core of the service you requested.

Why it is health data. The identity of the business can itself indicate a health or wellness need. An appointment record at a physical-therapy studio, a mental-health coach, or a fertility-wellness practice is data that identifies a consumer seeking health services.

3.2 The service you selected

What. The name, description, duration, and price of the service the business listed and you chose, and any resource or staff member assigned to it.

Why we collect it. To book the correct service with the correct provider for the correct amount of time, to price it, and to describe it back to you in confirmations and receipts.

Why it is health data. A service name chosen by a health or wellness business frequently states or strongly implies a condition, treatment, procedure, or intervention.

3.3 Answers to the business's intake questions

What. Your answers to the questions the business chose to put on its booking form. The business writes each question and decides whether it is required. Question formats we support are short text, long text, email address, phone number, number, date, time, single-select, multi-select, yes/no, web address, postal address, and file upload. Because the business writes the questions, the answers can include the reason for your visit, symptoms, goals, conditions, medications, allergies, injuries, prior treatment, or anything else that business asks.

Why we collect it. Solely to deliver your answers to the business you booked with, so it can prepare for and provide the service, and to display them to that business alongside your appointment.

What we do not do. DailyBuilt does not write these questions, does not require any health question to be asked, does not analyze your answers, and does not use them for any purpose of our own.

3.4 Contact and identity details tied to the appointment

What. Your first and last name, email address, mobile phone number if you provide one (it is optional), your time zone, and any note the business adds to your contact record.

Why we collect it. To identify you to the business, to send appointment email and — if you gave a mobile number — appointment text messages, to let you cancel or reschedule from a link we send you, and to match a later booking to the same contact record instead of creating duplicates.

Why it is health data. Standing alone these are ordinary contact details. Linked to a health or wellness appointment, they become data reasonably linkable to you that identifies you as someone seeking health services.

3.5 Messages about the appointment

What. Email we send you on the business's behalf and any reply you send back, including attachments. Replies are received at our reply address (reply.dailybuilt.co), threaded onto your appointment, and shown to the business. If you gave a mobile number, text messages we send you on the business's behalf and, where supported, your replies. We also record delivery outcomes reported by our email and messaging providers, such as delivered, bounced, or opted out.

Why we collect it. To deliver the message you or the business sent, to keep the conversation in one thread the business can see, to stop sending to an address or number that is no longer valid, and to honor opt-outs.

3.6 Payment records, where the business charges for the service

What. Whether an invoice or appointment was paid, the amount, the currency, the date, the description the business wrote, and an identifier from the payment processor. Your card or bank details go directly to the payment processor; DailyBuilt does not receive or store your full card number.

Why we collect it. To show the business whether it was paid, to give you a receipt, and to keep the financial records the business and DailyBuilt are required to keep.

Why it is health data. A payment line item describing a health or wellness service, linked to your name, indicates use of that service.

3.7 Analytics about your visit to the hosted page

What. When you load a booking page we host, our own self-hosted analytics records the page address (including the business's subdomain, which identifies the business), the page title, the address of the site that referred you, your browser, operating system, device type, screen size, and language, and an approximate location — country, region, and city — derived from your IP address. We generate a daily-rotating, salted, one-way hash from your IP address and browser details to recognize a single visit within a single day. We do not store your raw IP address in our analytics records, and this analytics does not use cookies.

Why we collect it. To give the business simple counts of how many people viewed and completed a booking, and to let us see whether the page is working. We do not use it to build a profile of you, and we do not use it for advertising.

Why it is health data. A visit to the booking page of a health or wellness business is, on its face, activity that identifies a consumer seeking health services — even where we do not know your name.

Session recording. A business can additionally turn on session recording and heatmaps for its own page. This is off by default and must be enabled deliberately by the business; it is never available to Healthcare Edition businesses. When it is on, the recording can capture the pages you view, your clicks and scrolling, and your interactions with the booking form, which may include information you type into it. Where a business has enabled recording, the page tells you so before the recorder starts and gives you a control to decline. If you decline, the recorder does not load for that visit. Both the analytics engine and any recordings run on DailyBuilt's own infrastructure. Neither is shared with an advertising network or a third-party analytics company.

3.8 Security, anti-abuse, and error diagnostics

What. To keep automated software from spamming a business's booking form, we present a challenge from our bot-protection provider; that provider receives technical signals from your browser and returns a pass/fail token to us. When a hosted page errors or performs badly, technical diagnostics — the page address, browser and device information, and error details — are sent to our error-monitoring provider. We configure that provider not to send account information, cookies, or request bodies.

Why we collect it. To protect the business's booking form from abuse, and to detect and fix failures so bookings do not silently break.

3.9 Categories we do not collect

We do not collect your precise device location, biometric data, or genetic data through the pages described in this policy, and we do not infer health data about you from non-health information. If that ever changes, we will update this policy and obtain your consent before collecting the new category, as RCW 19.373.020(1)(c) requires.

4. Categories of sources

We collect consumer health data from these categories of sources:

  1. Directly from you, when you use a booking, signing, or payment page we host, reply to an email or text message about an appointment, or contact us.
  2. Automatically from your device and browser, when you load a page we host — the analytics, anti-abuse, and diagnostic data described in Sections 3.7 and 3.8.
  3. From the business you booked with, when it creates or edits an appointment on your behalf, adds you as a contact, imports a contact list that includes you, or adds notes to your record.
  4. From our service providers that deliver messages and payments, which report back delivery outcomes, opt-outs, and payment status.

5. Categories of consumer health data we share, and with whom

Categories shared. All of the categories in Sections 3.1 through 3.6 are made available to the business you booked with, because delivering them to that business is the entire purpose of the service. Categories 3.7 and 3.8 are shared with the business only in aggregate form (counts and summaries), except that a business that has enabled session recording can view recordings of visits to its own page.

The categories of third parties, and our affiliates.

Recipient Category What it receives
The business whose page you used The business you chose to transact with Everything in Sections 3.1–3.6, and aggregate analytics for its own page
Cloud hosting and database provider Service provider (processor) All stored data, as the systems that run the Service
Email delivery and inbound-reply provider Service provider (processor) Your name, email address, message content, and attachments
Text-messaging provider Service provider (processor) Your mobile number and message content, where you gave a mobile number
Payment processor Service provider (processor) Payment amount, description, and identifiers, where the business charges for the service
Content-delivery and bot-protection provider Service provider (processor) Technical signals from your browser for the anti-abuse challenge
Error and performance monitoring provider Service provider (processor) Technical diagnostics described in Section 3.8

The current list of our service providers, by name, is published at dailybuilt.co/subprocessors.

Affiliates. DailyBuilt, Inc. has no affiliates, parent, or subsidiaries, so we share consumer health data with no affiliate. If that changes, we will update this policy before sharing with any affiliate.

Two clarifications MHMDA calls for. Under the definition of "share" in RCW 19.373.010, disclosure to a processor acting on our instructions is not "sharing," and neither is disclosure to a third party with whom you have a direct relationship for the purpose of providing a product or service you requested. Both exclusions apply to the table above: the service providers act only on our written instructions and may not use your data for their own purposes, and the business is the party you chose to book with. We list them anyway, because you should be able to see where your information goes.

Legal process and corporate transactions. We may disclose consumer health data where we are legally compelled to do so, or to protect against imminent harm, and we may transfer it as part of a merger, acquisition, or sale of assets, in which case the acquirer remains bound by this policy or gives notice before changing it. Our practices on compelled disclosure are described at dailybuilt.co/legal-process.

6. We do not sell consumer health data

DailyBuilt does not sell consumer health data. We have never sold it, we have no plans to sell it, and we do not exchange it for monetary or other valuable consideration with anyone. RCW 19.373.070 requires a separate, signed, written authorization before any sale of consumer health data. We have never sought or obtained such an authorization from anyone, because we do not sell.

We do not use or share consumer health data for advertising. We do not place advertising pixels, conversion trackers, or tag managers on the pages described in this policy. We do not build or upload advertising audiences from booking, intake, contact, or appointment data. We do not disclose consumer health data to advertising networks, data brokers, or ad-measurement companies. DailyBuilt does offer advertising tools to businesses, but those tools operate on the business's own advertising accounts and on targeting criteria the business enters, such as a geographic radius around its own address — not on data about you.

On pages we host for a Healthcare Edition business, the same rule applies with no exceptions. We serve no third-party advertising, conversion, or analytics tag on those pages, we do not support tenant-supplied tag injection on them, session recording is unavailable, and our first-party analytics run without transmission to any third party. Those pages are governed by HIPAA and by our business associate agreement rather than by this policy (see Section 1), and that agreement and our Security and Trust page state the same rule, so the two do not diverge.

7. Your rights and how to exercise them

RCW 19.373.040(1) gives you the rights below. They are free of charge, and we will not discriminate against you for exercising them.

7.1 Your rights

Confirm and access. You may ask us to confirm whether we are collecting, sharing, or selling consumer health data about you, and to give you access to that data. Your response will include a list of all third parties and affiliates with whom we have shared or sold that data, and an active email address or other online mechanism you can use to contact each of them.

Withdraw consent. You may withdraw your consent to our collection and sharing of consumer health data about you.

Delete. You may ask us to delete consumer health data about you.

7.2 How to make a request

Send your request to hello@dailybuilt.co with the subject line "Consumer Health Data Request." Tell us which right you are exercising, the name of the business whose page you used, and the email address or mobile number you used to book. You may also make the request directly to that business — see Section 7.6.

You do not need a DailyBuilt account to make a request, and we will not ask you to create one.

7.3 How we verify you

We will ask you to demonstrate control of the email address or mobile number associated with the appointment, ordinarily by responding to a message we send to it, and we may ask you to confirm one non-sensitive detail such as the business name or the appointment date. We will not ask for more information than is reasonably necessary to verify you, we will use what you give us only to verify the request, and we will delete it afterward except where we must keep a record that the request was made and handled. If we cannot verify you, we will tell you so and explain why, and you may appeal under Section 7.5.

An authorized agent may act for you if you provide us with written authorization signed by you; we may still contact you to confirm.

7.4 How quickly we respond

We will respond to a confirm-and-access request or a withdrawal-of-consent request within 45 days of receiving it. Where reasonably necessary, we may extend that period once by an additional 45 days, and we will tell you about the extension, and the reason for it, within the first 45 days. RCW 19.373.040(1)(g).

For a deletion request, we will delete the data without undue delay and in all cases within 45 days of receiving it, extendable once by a further 45 days where reasonably necessary, and we will notify our affiliates, processors, contractors, and other third parties with whom we have shared the data, each of whom must honor your request. RCW 19.373.040(1)(c), (1)(g).

7.5 What happens when you withdraw consent or ask us to delete

Withdrawal of consent stops our further collection and sharing of consumer health data about you going forward. Because collecting your appointment details is how the appointment exists, withdrawing consent will usually mean the business can no longer hold or service your appointment, and the business may cancel it. We will tell you what will stop working before we act, where we can.

Deletion removes the data from our active systems within the period stated in Section 7.4. When we delete, the record is immediately removed from every product surface and from our ordinary query paths, and is scheduled for permanent destruction. Permanent destruction runs on the schedule in Section 10. Three limits apply, and we state them plainly:

  1. Records other law requires us or the business to keep. Financial and tax records of a payment (seven years), audit and security records (six years), and any record subject to a legal hold, may be retained for the period that law or the hold requires, and are destroyed when that period expires. We will delete the rest, and we will tell you specifically what we kept and why. Everything else is permanently destroyed, not merely hidden.
  2. A minimum record of the request itself. We keep the fact of your deletion request and the minimum information needed to ensure your data stays deleted and to prove we honored it.
  3. Encrypted backup media. RCW 19.373.040(1)(c)(iii) expressly allows deletion from archived or backup systems to be delayed, for up to six months from the point we authenticate your request. Our backups run on a rolling seven-day window, so in practice a backup copy of a deleted record expires well inside that allowance and is never restored to active use in the meantime.

7.6 When we act for a business rather than for ourselves

For most of the data in this policy, DailyBuilt holds it on behalf of the business you booked with, and that business decides what happens to it. When you send us a request that concerns data we process on a business's behalf, we will:

  1. act directly and immediately on the data we control ourselves — the analytics in Section 3.7 and the diagnostics in Section 3.8;
  2. forward your request to that business without undue delay, and support it in responding, as our contract with it requires;
  3. tell you that we have done so, identify the business, and give you its contact information, so you can follow up directly and so the 45-day clock is not lost while your request is in transit.

We will not use "we are only the processor" as a reason to leave your request unanswered.

7.7 If we deny your request — appeal

If we refuse to act on your request, we will tell you why in writing, and we will tell you how to appeal.

To appeal, reply to our decision email with the word "Appeal" in the subject line, or write to hello@dailybuilt.co with the subject "Consumer Health Data Appeal." A person who was not involved in the original decision will review it. We will respond in writing within 45 days of receiving your appeal, explaining the reasons for our decision.

If we deny your appeal, you may submit a complaint to the Washington State Attorney General:

  • Online: https://www.atg.wa.gov/file-complaint
  • Consumer Protection Division, Office of the Attorney General, 800 Fifth Avenue, Suite 2000, Seattle, WA 98104

We will include that information in every appeal denial, as RCW 19.373.040(1)(h) requires.

8. We do not use geofencing

DailyBuilt does not implement a geofence around any facility. We do not operate a geofence around any entity that provides in-person health care services, and we do not use any geofence to identify or track consumers seeking health care services, to collect consumer health data, or to send notifications, advertisements, or messages relating to consumer health data or health care services. RCW 19.373.080. The Service does not offer point-and-radius location targeting, and enforces a minimum targeting radius.

We also do not collect precise device location on the pages described in this policy. Our hosted pages are served with a browser policy header that disables the browser geolocation interface, so those pages cannot request your device's precise location at all. The approximate country, region, and city described in Section 3.7 is derived from your IP address and is not precise location.

9. How we protect consumer health data

We restrict access to consumer health data to the DailyBuilt personnel and processors for whom access is necessary to provide the service, to further a purpose described in this policy, or as permitted by RCW 19.373.050. Data is encrypted in transit and at rest, access is logged, and every processor listed in Section 5 is bound by a written contract that limits it to processing on our documented instructions and prohibits using your data for its own purposes.

Our broader security practices are described at dailybuilt.co/security.

10. How long we keep it

We keep consumer health data only as long as needed for the purposes in Section 3, and we apply retention floors that set the earliest point at which a record can be permanently destroyed. Measured from the record's anchor date, those floors are seven years for financial records, six years for audit and security records, three years for communication and operational records, and one year for configuration records. Opt-out and suppression records, and anything under a legal hold, have no automatic expiry — keeping a record that you opted out is how we keep you opted out. The full schedule is published in Section 9 of our Privacy Policy. Where the business you booked with instructs us to keep its records for a defined period, we follow that instruction, subject to the retention periods the law requires for financial records. You can ask us to delete sooner under Section 7.

11. Nevada consumers

Nevada residents: see our Nevada Consumer Health Data Notice.

12. Changes to this policy

If we change this policy, we will post the updated version at this address and change the effective date at the top. We will not collect, use, or share categories of consumer health data that are not disclosed in this policy, and we will not use consumer health data for purposes not disclosed in this policy, without first disclosing the new category or purpose and obtaining your affirmative consent. RCW 19.373.020(1)(c)–(d).

We keep prior versions of this policy and will provide one on request.

13. Contact us

Consumer health data requests: hello@dailybuilt.co, subject line "Consumer Health Data Request."

All other questions about this policy: hello@dailybuilt.co.

DailyBuilt, Inc. c/o Corporation Service Company, 251 Little Falls Drive, Wilmington, DE 19808 hello@dailybuilt.co

If you booked through a page hosted for a business, that business is also a point of contact for these rights, and its contact information appears on the page you used and in the emails you received.

dailybuilt

The thinking layer for your whole business. Customers, bookings, payments, messaging, and your website in one login, one bill. In early access from Miami.

Platform
FeaturesHow it worksPricing
Company
Why we’re building itWritingFAQ
Contact
Get early accesshello@dailybuilt.coLinkedIn
Legal
TermsPrivacyEnd-User TermsConsumer Privacy NoticeDPAAcceptable UseSMS TermsBilling & RefundsCopyright & DMCASecurityAccessibilityCookiesLegal ProcessMeta Data DeletionSubprocessors
Consumer Health Data Privacy
dailybuilt
© 2026 DailyBuilt, Inc. All rights reserved.