This Privacy Policy describes how AutoPaper LLC d/b/a Suprabill and its affiliates under common control ("CLIENT","we","us", or "our") collect, use, disclose, and safeguard personal information obtained through Suprabill-branded digital services, including our website, mobile applications, and any tools we provide for out-of-network (OON) health insurance claim submission and tracking. By using our services and providing your health information, you authorize us to use and share your information with insurers and claims infrastructure providers for claim processing and other purposes consistent with this Privacy Policy.
We collect personal information directly from users who register for an account and use our platform to submit, monitor, or manage health insurance claims. This includes information provided by users, as well as responses or status updates we may receive from insurance payers, healthcare providers, or related third parties involved in processing such claims. In support of these services, we facilitate the collection, documentation, and transmission of claim-related data, which may include medical, insurance, billing, and contact information.
This policy also applies to individuals who visit or interact with our website or digital platforms, even if they do not submit a claim or register an account with us. As we expand our offerings, we may collect additional categories of information—such as analytics derived from website activity, user communications, or optional service features that users choose to enable, and we will update this Privacy Policy as applicable laws may require.
This Policy explains how we handle the personal information we collect or receive, and how individuals whose information we may process (data subjects) can understand and, where applicable, exercise their privacy rights. It also serves as your Notice of Collection under applicable laws, including the California Consumer Privacy Act (CCPA/CPRA), by describing the categories of personal information we collect, the sources from which we obtain it, the purposes for which we use it, and the categories of third parties to whom it may be disclosed, sold, or shared. Where required, we may also provide additional notices at the point of collection that supplement or reference this policy.
This policy will be updated as our services and data practices evolve. Material changes will be reflected on this page, and where required, we will provide additional notice.
Our current services assist individuals with out-ofnetwork (OON) claims. We are not a healthcare provider or insurer, and HIPAA does not apply to our services provided directly to individuals. If Suprabill becomes a business associate of a HIPAA-covered entity (or their business associate), we will comply with HIPAA’s applicable privacy and security requirements. Otherwise, information you provide as an individual is governed solely by the commitments in this Privacy Policy.
We collect and process personal information to provide users with access to our claim submission and tracking services, to communicate with payers, and to support the functioning and improvement of our digital platforms. The information we collect may include data submitted directly by users as well as data received from payers or derived from user interaction with our services.
"Personal information" (also referred to as "personal data" in some jurisdictions) means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. This includes identifiers, insurance and claim-related data, internet activity, and in some cases, sensitive personal information as defined under applicable law.
Category of Personal Information | Examples | Current Use of This Data | Categories of Recipients |
---|---|---|---|
Identifiers | Name, date of birth, email, phone number, address, insurance ID | Collected Processed Shared* |
Insurance payers; claims and other infrastructure providers; affiliates providing operational support |
Sensitive Personal Information | Diagnosis codes, CPT/procedure codes, session notes, insurance policy numbers | Collected Processed Shared* |
Same as above |
Account registration information | Username, login credentials (hashed), communication preferences | Collected Processed |
Not applicable |
Commercial Information | Claim submission history, eligibility determinations, claim statuses | Collected Processed Shared* |
Same as Identifiers |
Financial Information | Payment method (Stripe), transaction confirmations, billing ZIP | Collected Processed Shared* |
Stripe; claims and other infrastructure providers |
Professional Information | Provider name, NPI, service dates | Collected Processed Shared* |
Insurance payers; claims and other infrastructure providers |
Internet/Electronic Activity | IP address, device/browser data, user session activity | Collected Processed Shared* |
Analytics providers; infrastructure vendors |
Geolocation Data | Approximate location based on IP address | Collected Processed Shared* |
Same as above |
Inferences | User preferences derived from feature use or behavior | Collected (Created) Processed |
Internal analytics only |
Aggregated/Deidentified Data | Operational metrics (e.g., claim turnaround time, approval rates) | Collected Processed (anonymized) |
Internal analytics only; not shared or sold |
The disclosures provided in the table above are illustrative, not exhaustive, and are intended to reflect the typical scope of our data practices. Additional categories or examples of personal information may be collected or used, depending on how individuals interact with our services. The table should be read in conjunction with the following important notes and explanatory details:
(a) Shared* refers to disclosures made solely to provide our services as requested and directed by the user. These include disclosures to service providers or contractors under written agreement, as well as to other third parties—such as insurance payers and claims infrastructure providers—when such disclosures are necessary to process claims or deliver the requested services. These are not considered "sharing" or "selling" under the CCPA/CPRA. The table marks these with an asterisk (*) for clarity; no listed disclosures involve selling or sharing, as defined by CCPA/CPRA.
(b) Additional categories of personal information identified under applicable laws (such as the CCPA/CPRA) are not included in the table above if we do not collect, process, or share/sell such information. Examples include: biometric data, sensory recordings, and protected classifications.
(c) If you choose to create an account on our website, we may collect additional information such as your name, email address, login credentials, and any preferences or information you submit through the account interface. Additional terms regarding account registration and use may be provided in our Terms of Use, which govern your interaction with our online services.
(d) Information that has been de-identified or anonymized in accordance with applicable laws is no longer considered personal information. We may use, share, license, or otherwise process such de-identified data for any lawful purpose, including but not limited to research, analytics, benchmarking, product development, service improvement, business intelligence, marketing insights, or the creation of aggregated datasets. We take reasonable steps to ensure that de- identified data cannot be re-associated with any individual.
We collect personal information from a variety of sources, depending on how individuals interact with us and our services. These sources may include:
We collect, use, and otherwise process personal information for a variety of business and operational purposes, depending on the context in which we receive the data. These purposes may include:
We may disclose personal information to third parties for a variety of operational, legal, and commercial purposes, including:
We take reasonable steps to safeguard personal information we collect, including through technical, administrative, and physical controls appropriate to the nature of the data and our operations. We may also share de-identified or aggregated information with third parties for lawful business purposes. Such information does not identify you personally and is not subject to this Privacy Policy so long as we maintain and use it in accordance with applicable deidentification standards.
Where required by law, our processing of personal information is based on one or more of the following legal grounds:
We and certain third-party partners use cookies, pixel tags, and similar tracking technologies to collect information about how visitors interact with our website. These technologies help us improve site functionality, analyze traffic patterns, understand engagement with content, and may also support our advertising and marketing efforts in compliance with applicable laws.
Cookies are small data files stored on your device that can retain information such as a user identifier, session state, or preferences. While cookies cannot access files or data stored on your hard drive or interact with cookies set by other websites, they may be used to associate browser or device activity over time. Pixel tags (sometimes called web beacons) are small pieces of code that can track certain actions on web pages or emails, such as whether a user viewed or clicked specific content.
Some parts of our website use first-party cookies to help us assess how useful our content is, how visitors navigate through our site, and how we can improve the user experience. We may also work with third-party service providers—for example, analytics platforms or infrastructure vendors—who may set cookies or similar technologies to help us understand site performance and usage. We do not currently engage in cross-context behavioral advertising. If this changes, and such activity occurs, it will be reflected in our Categories of Personal Information table as ―shared‖ or ―sold‖ without an asterisk (*), indicating that the disclosure is not solely for service delivery. In that case, we will update this policy and provide any required opt-out mechanisms.
You may be able to manage or restrict the use of cookies and similar technologies through your browser settings, which could allow you to block cookies entirely, be notified when cookies are set, or delete existing cookies. Please note that disabling cookies may impact the functionality of certain features or pages. To learn more about interest-based advertising or to opt out of thirdparty tracking by participating advertising networks, you may visit:
By continuing to use our website, you consent to the use of cookies and tracking technologies as described above. We do not guarantee that browser-level controls or third-party opt-out tools will block all tracking activity, and we disclaim responsibility for the functionality or effectiveness of those tools.
For certain features or sections of our website, you may be required to register an account and select a password. Your Suprabill account will be accessible to anyone who has your login credentials. You are solely responsible for maintaining the confidentiality and security of your username and password, and for any activity conducted under your account. Suprabill is not responsible for unauthorized access resulting from your failure to safeguard your credentials.
We implement physical, electronic, and administrative safeguards to help protect the personal information you provide, as required by applicable law. In areas where sensitive information may be transmitted, we may use industry-standard encryption technologies such as SSL to protect data during transmission. However, due to the inherent nature of the internet, no data transmission or storage system can be guaranteed to be 100% secure. We cannot guarantee the security of any information you transmit to us online.
We encourage you to take precautions to protect your personal information while online, including regularly updating your passwords, using complex combinations of letters and numbers, and ensuring your browser and operating system are up to date.
Our website is not directed to children under the age of 13, and we do not knowingly collect personal information directly from children under 13. However, we may receive information about minors, including children under 13, when submitted by a parent or legal guardian in connection with an out-of-network claim or related request. Such information is processed solely for the purpose of providing the requested services on behalf of the parent or guardian.
If we become aware that we have inadvertently collected personal information directly from a child under 13 without appropriate parental consent, we will delete it in accordance with applicable law and without liability to you or anyone else. We reserve the right to take reasonable steps, including restricting access or suspending accounts, if we determine that a user has repeatedly submitted information in violation of this policy or applicable children's privacy laws.
Our website may contain links to third-party websites that are not owned or operated by Suprabill. We do not transmit personal information about you to those websites, and we are not responsible for their privacy practices or content. If you choose to leave our site and visit a third-party website, your information will be governed by that site's privacy policy and terms of use, which may differ from ours—even if the third party is a service provider used by Suprabill.
For example, if you apply for a position with Suprabill through a platform such as Indeed.com, your application may be processed under that platform's own privacy policy. We encourage you to review the privacy policies of any third-party websites before providing them with your personal information.
Some web browsers and extensions offer a "Do Not Track" (DNT) setting or Global Privacy Control (GPC) signal intended to indicate a user's preference not to be tracked across websites. At this time, there is no universally accepted standard for interpreting DNT or GPC signals, and our website does not currently respond to them.
To reduce or block tracking technologies, you may use private browsing modes (such as "Incognito" or "Private" windows), adjust your browser settings, or use third-party tools to manage cookies and trackers. However, your browser provider or third-party services may still collect information independently, and we do not control their behavior. Please consult your browser's support documentation for more information.
We retain personal information for as long as reasonably necessary to fulfill the purposes for which it was collected, including to provide our services, comply with legal obligations, enforce agreements, resolve disputes, and support internal compliance and improvement efforts. The specific retention period for any given category of data may vary depending on the nature of the information, the context in which it was collected, and applicable legal or regulatory requirements.
We may also retain de-identified or aggregated information for internal analytics, service evaluation, or other lawful purposes. When personal information is no longer needed for its original purpose and is not subject to a legal or contractual retention requirement, we will take reasonable steps to delete, de-identify, or securely dispose of it.
We may update this Privacy Policy from time to time at our sole discretion or as required by law. All changes will take effect upon posting the revised version to this page, unless otherwise stated. Your continued use of our platform following any changes constitutes your acceptance of the updated policy.
We encourage you to review this page periodically to stay informed about our data practices. If we make material changes to how we collect, use, or share your personal information, we may also notify you through additional means, such as email or a notice on the website.
If you have any questions or concerns about how we collect, use, or disclose personal information, you may contact us by e-mail at: [email protected]. Please allow up to five business days for a reply.
California Residents Only.
This section applies only to individuals who are residents of California, to the extent our operations are subject to the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and related regulations.
If you are a California resident, you may have the following rights regarding your personal information, subject to certain exceptions and limitations under applicable law:
As a California resident, you may exercise your privacy rights, request access to or correction of the personal information we have collected about you, or contact us for more information about our privacy practices. To submit any California privacy rights requests, please contact us via[email protected].
You may submit your California rights requests using any of the methods listed above. For certain requests, California law requires us to verify the identity and authority of the individual making the request in order to protect your privacy and personal information. Depending on the nature and sensitivity of the request, we may ask you to provide two or more pieces of information that match data already in our records before we can process the request.
If you wish to submit a California rights request through an authorized agent, you may do so by designating the agent in writing and contacting us through any of the methods listed above. To help us verify and process the request, please provide the following information:
If any required information is missing or cannot be verified, we may request additional documentation before processing the request. We may also ask for further verification depending on the nature or sensitivity of the request, in accordance with applicable law.
Suprabill does not have actual knowledge of any sale of the personal information of consumers under 16 years of age.
If you have questions and concerns about how we collect, use and disclose personal information, please contact us:
[email protected]