Privacy Policy
Last Updated: August 12, 2026
YAMSOL LLC (“YAMSOL,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit yamsol.com (the “Website”), use our software platforms and mobile applications, or engage us for professional services (collectively, the “Services”).
This Privacy Policy should be read together with our Terms and Conditions. By using our Website or Services, you acknowledge that you have read and understood this Privacy Policy.
Contents
- Scope of This Policy
- Our Role: Business vs. Service Provider
- Information We Collect
- Data Processed Through Our Software
- Health Information and HIPAA
- Location Data
- How We Use Information
- SMS, Email, and Push Notifications
- How We Share Information
- Cookies and Similar Technologies
- Professional Services Clients
- Data Retention
- Data Security
- Your Privacy Rights and Choices
- U.S. State Privacy Rights
- International Users
- Children’s Privacy
- Third-Party Websites and Services
- Changes to This Policy
- Contact Us
1. Scope of This Policy
This Privacy Policy applies to:
- Our Website, including our blog, contact forms, demo request forms, and meeting scheduling tools.
- NEMT (Non-Emergency Medical Transportation) Software, including the Broker Panel, Provider Panel, Corporate Panel, Driver App, and Member App.
- Taxi/Cab Software, including the Provider Panel, Driver App, and Passenger App.
- Other Transportation Solutions, including limousine, paratransit, and school transportation software.
- Professional Services, including web development, mobile app development, graphic design, search engine optimization (SEO), support, and maintenance.
Where we provide software to a transportation company, broker, healthcare facility, or other organization (a “Customer”), that Customer’s own privacy policy also governs how it uses the information of its riders, members, passengers, and drivers.
2. Our Role: Business vs. Service Provider
When we act as a business (controller): We decide how and why information is processed when you visit our Website, contact us, request a demo, subscribe to communications, or become a Customer. We are responsible for that information under this Privacy Policy.
When we act as a service provider (processor): When Customers use our software to manage trips, riders, drivers, and billing, we process that information on the Customer’s behalf and according to the Customer’s instructions and our agreement with them. In these cases the Customer controls the data. If you are a rider, member, passenger, or driver using a platform operated by one of our Customers, please contact that organization directly with privacy questions or requests. We will help our Customers respond to them.
When we act as a Business Associate: When a Customer is a HIPAA covered entity or business associate, we process protected health information (PHI) as a Business Associate under a Business Associate Agreement (BAA). See Section 5.
3. Information We Collect
3.1 Information You Provide to Us
- Contact and Demo Requests: first and last name, work email address, phone number, organization name, job title, country, and the contents of your message.
- Meeting Scheduling: when you book a meeting through our scheduling tool (Calendly), your name, email address, the meeting time you choose, and any notes you add.
- Account Information: for Customers and their authorized users, your name, email, phone number, role, username, password (stored in hashed form), and account preferences.
- Business and Billing Information: company name, billing address, tax identifiers, contracts, invoices, and payment details. Card payments are handled by third-party payment processors. We do not store full payment card numbers on our systems.
- Support Communications: information you share when you contact our support team, report an issue, or give feedback, including screenshots and attachments.
- Project Information: for professional services clients, materials, content, credentials, and specifications you provide so we can deliver your project.
3.2 Information Collected Automatically
- Device and Usage Data: IP address, browser type and version, operating system, device identifiers, referring URLs, pages visited, time spent, and actions taken.
- Log Data: server logs, error and crash reports, performance diagnostics, and security event logs from our Website and software.
- Cookies and Similar Technologies: see Section 10.
3.3 Information from Third Parties
- Trip assignments, member eligibility, and authorization data sent to us by transportation brokers, managed care organizations, health plans, or state Medicaid programs through integrations a Customer has set up.
- Driver credentialing and compliance results from screening partners and verification services a Customer uses.
- Information from business partners, referral sources, event organizers, and publicly available sources, such as company websites and professional networking profiles, used for business development.
Our software processes the following categories of information on behalf of our Customers. The exact data depends on the product and how the Customer configures it.
4.1 Riders, Members, and Passengers
- Name, phone number, email address, home address, and saved locations (such as “Home” and “Office”).
- Pickup and drop-off addresses, appointment dates and times, trip history, and trip status.
- For NEMT: Medicaid or health plan member ID, date of birth, eligibility and authorization details, appointment and facility information, mobility and assistance needs (for example, wheelchair, stretcher, or escort requirements), and other special instructions.
- Digital signatures captured at pickup or drop-off to verify trips.
- Ratings, reviews, feedback, and in-app messages.
- Fare, payment method, and payment status information processed through third-party payment processors.
4.2 Drivers
- Name, contact information, profile photo, and employee or contractor ID.
- Driver’s license details, vehicle information (make, model, plate, VIN, inspection records), insurance documents, certifications, training records, and other credentialing or compliance documents.
- Precise GPS location while the Driver App is in use or the driver is on duty (see Section 6).
- Trip logs, manifests, timestamps, odometer readings, completed safety checklists, signatures, photos, and incident reports.
- Fare cards, earnings, and performance metrics.
4.3 Brokers, Providers, Facilities, and Corporate Users
- Administrator and staff user accounts, roles, and permissions.
- Trip requests, scheduling and dispatch records, network and provider data, rates, invoices, claims, and billing records.
- Reports, analytics, and audit logs.
4.4 Mobile App Permissions
Our mobile apps may ask for the following device permissions. You can manage them in your device settings, but turning some off may limit features.
- Location: to show trip routes, dispatch drivers, provide ETAs, and verify pickups and drop-offs.
- Camera and Photos: to capture documents, vehicle inspection photos, proof of trip, or profile pictures.
- Notifications: to send trip updates, reminders, and dispatch alerts.
- Phone and Messaging: to let riders, drivers, and dispatchers contact each other about a trip.
5. Health Information and HIPAA
Our NEMT software may process protected health information (PHI) as defined by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations. When it does:
- We act as a Business Associate and sign Business Associate Agreements with covered-entity and business-associate Customers when required.
- We use and disclose PHI only as allowed by the BAA and HIPAA, and only to provide the Services.
- We follow the “minimum necessary” standard and limit PHI access to authorized personnel with a legitimate need.
- We maintain administrative, physical, and technical safeguards designed to meet the HIPAA Security Rule, including access controls, encryption, audit logging, and workforce training.
- We notify affected Customers of breaches of unsecured PHI as required by HIPAA and our BAAs.
We never sell PHI or use it for marketing. Individuals who want to access, amend, or get an accounting of disclosures of their PHI should contact their healthcare provider, health plan, or transportation broker. We will help that organization respond.
6. Location Data
Real-time location is central to transportation software. We collect and process location data as follows:
- Drivers: the Driver App collects precise GPS location, including in the background, while a driver is logged in, on duty, or assigned to a trip. This is used for dispatch, live tracking, ETAs, route history, mileage, billing verification, and safety. We do not track drivers once they are logged out or off duty.
- Riders and Passengers: the Member and Passenger Apps may use your location, with your permission, to set pickup points, show nearby vehicles, and share trip progress.
- Dispatch and Administration: authorized Customer staff can view live vehicle locations and historical trip routes in the web panels.
Location data is shared with mapping and routing providers only as needed to deliver these features. It is not sold or used for advertising.
7. How We Use Information
We use information for the following purposes:
- Providing the Services: operating, hosting, and maintaining our software, including scheduling, dispatch, routing, live tracking, trip verification, billing, and reporting.
- Responding to You: answering inquiries, scheduling demos, preparing proposals, and providing customer support.
- Account Management: creating and managing accounts, authenticating users, and handling invoices and payments.
- Communications: sending trip notifications, service announcements, security alerts, and, where permitted, marketing communications about our products and services.
- Improvement and Development: analyzing usage, troubleshooting, and developing new features. Where possible we use aggregated or de-identified data.
- Security and Fraud Prevention: monitoring for, preventing, and investigating unauthorized access, fraud, abuse, and security incidents.
- Compliance: meeting legal, regulatory, contractual, and audit requirements, including Medicaid, HIPAA, and transportation regulations, and enforcing our Terms and Conditions.
We use Customer data processed through our software only to provide and support the Services for that Customer, as described in our agreement with them. We do not use it for our own marketing.
8. SMS, Email, and Push Notifications
Our software can send trip-related SMS text messages, phone calls, emails, and in-app or push notifications, such as booking confirmations, reminders, driver arrival alerts, and trip status updates. These are sent on behalf of the Customer providing your transportation.
- Message frequency varies with your trip activity. Message and data rates may apply.
- You can opt out of SMS messages at any time by replying STOP. Reply HELP for help.
- We do not sell, rent, or share mobile phone numbers or SMS opt-in consent with third parties or affiliates for their marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third parties, except service providers that deliver the messages for us.
- You can unsubscribe from our marketing emails using the link in each email. We will still send transactional and account messages.
- You can turn off push notifications in your device settings.
9. How We Share Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only as described below:
- With Customers: data processed through our software is available to the Customer that controls it and to the users that Customer authorizes, such as dispatchers, billing staff, and drivers.
- Within the Transportation Network: as directed by a Customer, we share trip details between brokers, transportation providers, drivers, facilities, and payers, for example to assign a trip, verify that it was completed, or submit a claim.
- Service Providers: companies that perform services for us under contracts that limit their use of the data, including cloud hosting, databases, mapping and routing, SMS and voice, email delivery, payment processing, scheduling (Calendly), content management (Sanity), website analytics (Google Analytics), app crash reporting and push notifications (Google Firebase), customer support, and security monitoring. Service providers that handle PHI sign BAAs where required.
- Compliance and Auditing Partners: credentialing, compliance, and auditing organizations, when a Customer asks us to or when contracts or regulations require it.
- Legal Requirements: when we believe in good faith that disclosure is required by law, subpoena, court order, or government request, or is needed to protect the rights, property, or safety of YAMSOL, our Customers, users, or the public.
- Business Transfers: in connection with a merger, acquisition, financing, reorganization, or sale of all or part of our business. Any successor remains bound by the commitments in this Privacy Policy and our Customer agreements.
- With Your Consent: for any other purpose we tell you about when you give your consent.
We may share aggregated or de-identified information that cannot reasonably identify any individual, such as industry benchmarks.
10. Cookies and Similar Technologies
We use cookies, local storage, and similar technologies on our Website and web panels for the following purposes:
- Strictly Necessary: to keep you signed in, remember your session, secure the platform, and load pages correctly.
- Functional: to remember preferences and support embedded tools such as meeting scheduling.
- Analytics and Performance: to understand how visitors use the Website and improve it. We use Google Analytics, which collects information such as pages viewed, time on site, approximate location, and device and browser details. Google’s use of this data is described at How Google uses information from sites that use its services. You can opt out with the Google Analytics Opt-out Browser Add-on.
Mobile Apps: our mobile apps use Google Firebase services, including Firebase Crashlytics and Firebase Cloud Messaging, to deliver push notifications, report crashes and errors, and measure app performance. These services may collect device identifiers, app instance IDs, device model, operating system version, crash logs, and app usage events. We do not send PHI to Firebase analytics, and we do not use these tools for advertising.
Third-party services embedded in our Website, such as Calendly, Google Fonts, and image hosting providers, may set their own cookies or collect technical data under their own privacy policies. You can control or delete cookies in your browser settings. Blocking strictly necessary cookies may stop parts of the Services from working.
Do Not Track and Global Privacy Control: We treat a Global Privacy Control (GPC) signal as a request to opt out of any “sale” or “sharing” of personal information for that browser, as required by applicable law. Because there is no common industry standard for “Do Not Track” signals, we do not currently respond to them.
11. Professional Services Clients
When we provide web development, mobile app development, graphic design, SEO, or related services, we may need access to your systems, websites, hosting accounts, analytics accounts, source code, or end-user data. In these engagements:
- You remain the owner and controller of your data and your end users’ data.
- We access and use that data only to perform the agreed work, and we treat it as Confidential Information under our Terms and Conditions and project agreement.
- We store credentials securely, limit access to the team members working on your project, and return or delete project data and access credentials when the engagement ends or when you ask.
- You are responsible for publishing your own privacy policy and for getting any consents your end users must give for the websites and apps we build for you.
12. Data Retention
We keep personal information only as long as needed for the purposes described in this Privacy Policy, including to:
- Provide the Services while an account or contract is active.
- Meet legal, tax, accounting, and regulatory record-keeping requirements. For example, Medicaid and NEMT trip and billing records must be kept for the periods required by state Medicaid rules, payer and broker contracts, and other applicable laws.
- Resolve disputes, enforce agreements, and keep security logs.
When a Customer agreement ends, we return or delete Customer data as the agreement specifies, unless the law requires us to keep it. Website inquiries and sales communications are generally kept for as long as there is an active business relationship, plus a reasonable period afterward. When information is no longer needed, we delete it securely or de-identify it.
13. Data Security
We use administrative, technical, and physical safeguards designed to protect information from unauthorized access, loss, misuse, or alteration. These include:
- Encryption of data in transit (TLS/HTTPS) and at rest.
- Role-based access controls, least-privilege permissions, and strong password requirements.
- Audit logging and monitoring of access to sensitive data.
- Secure, access-controlled cloud hosting with regular backups.
- Secure development practices, code reviews, and vulnerability remediation.
- Confidentiality obligations and privacy and security training for our workforce.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential. If you suspect unauthorized access to your account, contact us right away at info@yamsol.com. If a data breach occurs, we will notify affected Customers, individuals, and regulators as required by law and our contracts.
14. Your Privacy Rights and Choices
Depending on where you live, you may have some or all of the following rights over your personal information:
- Access: to confirm whether we process your personal information and to get a copy of it.
- Correction: to correct inaccurate personal information.
- Deletion: to ask us to delete your personal information, subject to legal exceptions.
- Portability: to receive your information in a portable, commonly used format.
- Opt-Out: to opt out of marketing communications, and of targeted advertising, sale, or profiling where those apply.
- Withdraw Consent: where we rely on your consent, to withdraw it at any time.
How to Make a Request: email us at info@yamsol.com or call (804) 718 0908. We will verify your identity before acting on your request, and we may ask for information to confirm it. You may use an authorized agent, who must give proof of their authority. We respond within the time required by applicable law, usually within 45 days.
Deleting Your App Account: if you use one of our mobile apps, you can ask us to delete your account and the personal information linked to it by emailing info@yamsol.com from the email address on the account, with the subject line “Account Deletion,” or by asking the organization that provides your transportation. We will delete or de-identify your data, except for records we or the Customer must keep for legal, billing, or safety reasons, which we will keep only for as long as required.
Requests About Customer Data: if your information is in our software because a transportation provider, broker, healthcare organization, or employer uses our platform, please send your request to that organization. If you contact us, we will forward your request to the relevant Customer where we can identify it.
Non-Discrimination: we will not discriminate against you for exercising any of your privacy rights.
15. U.S. State Privacy Rights
Residents of certain U.S. states, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others with comprehensive privacy laws, have the rights described in Section 14, subject to the limits and exemptions in those laws. Some state laws exempt PHI governed by HIPAA and information processed in a business-to-business context.
California Residents: under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), we disclose that in the past 12 months we have collected the following categories of personal information: identifiers; contact information; commercial information; internet or network activity; geolocation data; professional or employment-related information; and, through our NEMT software, sensitive personal information such as health-related information and government identifiers (for example, driver’s license numbers). We collect these from the sources described in Section 3 and use them for the business purposes described in Section 7. We disclose them to the categories of recipients described in Section 9. We do not sell or share personal information, and we do not use or disclose sensitive personal information for any purpose that would trigger the right to limit its use under the CCPA. You also have the right to know about, and the right to correct, the personal information we hold about you.
Appeals: if we decline your request, you may appeal by replying to our decision or emailing info@yamsol.com with the subject line “Privacy Appeal.” If you are not satisfied with the outcome of your appeal, you may contact your state Attorney General.
16. International Users
YAMSOL LLC is based in the United States, and our Services are intended primarily for U.S. organizations. If you access our Services from outside the United States, your information may be transferred to, stored, and processed in the United States and in other countries where we or our service providers and team members operate. Data protection laws in those countries may differ from the laws where you live.
Where the laws of the European Economic Area, United Kingdom, or similar regimes apply, we process personal information on the following legal bases: to perform a contract with you; our legitimate interests in operating and improving our business; compliance with legal obligations; and your consent, where required. Where required, we use appropriate safeguards, such as Standard Contractual Clauses, for international transfers. You may also have the right to object to or restrict processing and to lodge a complaint with your local data protection authority.
17. Children’s Privacy
Our Website is not directed to children under 13 (or under 16 where applicable), and we do not knowingly collect personal information directly from children through it. Some Customers, such as school transportation and NEMT providers, may use our software to arrange rides for minors. In those cases the Customer collects the information, under its own legal obligations, and usually from a parent, guardian, school, or healthcare provider. We process that information only on the Customer’s behalf. If you believe a child has given us personal information directly without appropriate consent, please contact us and we will delete it.
18. Third-Party Websites and Services
Our Website and Services may link to or integrate with third-party websites, apps, and services, such as broker portals, payment processors, mapping services, app stores, and social media platforms. We do not control them, and their own privacy policies govern how they handle your information. Please review those policies before giving them your information.
19. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, technology, or legal requirements. When we do, we will update the “Last Updated” date at the top of this page. If we make material changes, we will notify you through the Services, by email, or by a prominent notice on our Website before the changes take effect. Your continued use of the Services after an update means you accept the revised Privacy Policy.
If you have questions, concerns, or requests about this Privacy Policy or our privacy practices, please contact us:
YAMSOL LLC
Attn: Privacy
12804 Willow Point Dr, Fredericksburg, VA 22408
Email: info@yamsol.com
Phone: (804) 718 0908