Privacy Policy

Last updated: September 23, 2026

This policy explains what information State Rates Health, LLC ("State Rates," "we," "us") collects when you use our website (staterates.health) and API (api.staterates.health), how we use it, and the choices you have. It applies only to data collected through those services — not to information you provide to us offline or through a third-party site we link to.

By using the service you agree to this policy. If you don't, please don't use the service.

Information We Collect

Information you give us when you sign up or request access. To create an account or receive an API key, we collect your email address, name, and the name of the organization you represent. Accounts may be created through self-service sign-up, which begins a free trial, or provisioned by State Rates on behalf of an organization.

Information about how you use the product. We record that a request happened — which endpoint you called, for which state, when, whether it succeeded, and how long it took — along with which pages you visit. When you are signed in, this is tied to your account. When you are signed out, it is tied only to the random identifier described under Cookies below — we know that someone looked up a rate in Texas, not who. We use this to understand which parts of the product people use, to bill usage, and to improve the service.

Request content. The values submitted with a lookup, whether through the pricing tool or the API, are retained for 30 days following submission. These values include procedure codes, provider identifiers, dates of service, and the other parameters of the request. They are used solely to diagnose lookups that do not return a rate and to support users who contact State Rates about a specific result, and are permanently deleted at the end of the retention period. Any reference or correlation value included with a request is removed before the request is recorded and is not retained. Request content is not written to server logs and is not shared with error-monitoring providers.

Automatic technical information. When you visit the website or call the API, our servers log the request — including the IP address, the endpoint called, and the time of the request. For API traffic, we associate the request with your API key identifier so we can enforce rate limits and quotas. For anonymous website traffic, we use the random visitor identifier and the IP address the same way: to enforce the free lookup limit. We do not log request headers or the raw API key itself.

Error and diagnostic data. When something in the product errors out, we collect a record of the error (stack trace, request path, user identifier) through our error-monitoring provider so we can fix it. Secrets, API keys, and authorization headers are stripped before this data leaves our servers, as are the values you submitted — query strings, request bodies, and the variables held in memory at the point of failure. We do not record browser sessions.

Cookies. We use three first-party cookies: a session cookie set by our authentication provider (Auth0) to keep you signed in; a counter that tracks how many free lookups you have used; and a randomly generated identifier that lets us count visitors, see how the site is used, and enforce the free lookup limit. That identifier is a random value — it is not derived from your name, email, or device, and it tells us nothing about who you are. Clearing your cookies removes all three from your browser, but the free lookup limit itself is counted on our servers and is not reset. We do not use cookies for advertising or cross-site tracking, and we do not load third-party analytics or advertising scripts.

How We Use Your Information

  • To provide the service — sign you in, route you to the states you're entitled to, enforce rate limits and quotas.
  • To communicate with you about your account, renewals, outages, or material changes to the product.
  • To debug, monitor, and improve the product — including understanding which features get used and what queries are common.
  • To comply with our legal obligations, enforce our Terms of Service, and protect the service from abuse.

We do not sell your personal information, and we do not use it for advertising.

Disclosure of Your Personal Data

We share your information only in these situations:

  • With service providers we rely on to operate the product. These providers process data on our behalf and are contractually limited to that purpose. Our current providers are:
    • Auth0 (Okta) — user authentication and session management.
    • Amazon Web Services — hosting, database, and storage.
    • Cloudflare — DNS, content delivery, and denial-of-service protection for the website. Requests to the website pass through Cloudflare before reaching our servers. Requests to the API (api.staterates.health) do not.
    • Resend — delivery of the notification email we receive when you submit the contact form.
    • Sentry — error monitoring and performance diagnostics.
    • Onetimesecret — one-time delivery of API keys at issue time.
    • Stripe — payment processing for paid subscriptions. Your payment card details are submitted directly to Stripe and are never stored on our servers.
  • When required by law. We may disclose information in response to a valid subpoena, court order, or other lawful request, or when we reasonably believe disclosure is necessary to protect the rights, property, or safety of State Rates, our users, or others.
  • In a business transfer. If State Rates is acquired, merged, or sells substantially all of its assets, your information may transfer to the successor entity. We will notify you if this happens.

We do not share, sell, rent, or trade your personal information with third parties for their own marketing purposes.

Aggregated or de-identified information that cannot reasonably be used to identify you may be shared without restriction.

Retention of Your Personal Data

We retain your personal information for as long as we need it to provide the service, comply with our legal obligations, resolve disputes, and enforce our agreements. When data is no longer needed for these purposes, we delete or anonymize it. Usage and diagnostic data is generally retained for shorter periods than account information, except where we need it longer to maintain the security or functionality of the service. Request content is retained for 30 days from the date of submission and is then permanently deleted.

Your Choices

  • Access and correction. Account holders may request a copy of the account information held about them, including any request content still within its retention period, and may request correction of that information, by email to the address below.
  • Deletion. Account holders may request deletion of their account and associated personal information, including any request content still within its retention period. Such requests will be honored unless retention of specific information is required by law. Request content submitted without signing in is not associated with a name or email address and cannot be located for early deletion; it is deleted automatically at the end of its retention period.

We will respond to verified requests within 30 days.

Data Security

We take reasonable administrative and technical measures to protect your information, including encrypted connections (HTTPS), hashed storage of API keys, and scrubbing of secrets from error logs. No system is perfectly secure, and we cannot guarantee that unauthorized access will never occur. You are responsible for keeping your account credentials and API keys confidential.

Links to Other Websites

Our website may contain links to third-party sites. This policy does not apply to those sites, and we are not responsible for their privacy practices. We encourage you to review the privacy policy of any site you visit.

Children

Our service is intended for business use and is not directed to children under 13. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us and we will delete it.

Changes to This Policy

We may update this policy from time to time. When we do, we will revise the "Last updated" date at the top. For material changes, we will notify account holders by email or through the service.

Contact Us

If you have questions about this policy or our privacy practices, email us at [email protected].