LEGAL

Privacy Policy

Last updated: July 6, 2026

1. Scope and controller

This policy describes how CuidaLink (operated by Rubén Gómez Espín, Miami, Florida — contact rubengomezesp@gmail.com) handles personal information on cuidalink.app and its services (marketplace, Solo, Academy, AcademyOS). It is written for U.S. users. It does not cover the independent practices of partner agencies, caregivers, or academies, who are responsible for their own compliance.

2. Information we collect

Families: name, email, phone, city/ZIP, the care need described in the request (which may include health-related details you choose to share), and messages. Caregivers: contact details, professional profile (experience, languages, specialties, availability, service area, rates), training and certificates, and — for Solo users — the client, visit, service, and invoice records you create, plus Stripe Connect onboarding status. Academy learners: enrollment, progress, results, and certificates. Leads and marketing: what you submit through forms, Meta lead ads, or messages you send us first (opt-in only). Technical: IP, device, pages, and cookies (see Cookie Policy). We do not knowingly collect information from children under 13.

3. How we use it

To respond to and qualify requests; coordinate qualified requests with partner agencies; operate profiles, Solo, Academy, and payments; send service and (with consent) marketing communications; measure and improve the platform and campaigns; prevent fraud and protect users; and comply with law. Care-need details may reveal health information: we use them only to qualify and coordinate the request. CuidaLink is not a HIPAA covered entity; do not submit medical records through the platform.

4. Who we share it with

Partner agencies: when you request care, we share what the agency needs to assess availability, scope, pricing, and fit; the agency is an independent controller of what it receives. Service providers: hosting and database (Vercel, Supabase), payments (Stripe), email (Resend/Gmail), analytics and advertising (Google, Meta), AI (Anthropic), and automation (Make), which may process data only to provide their services. Also for legal compliance or in a business transfer, with notice. We do not sell personal information. Advertising events are limited to non-sensitive interactions and never include care-need details; where a state law treats ad pixels as "sharing" or targeted advertising, we honor opt-out requests and Global Privacy Control signals.

5. Your rights and choices

You may request access, correction, deletion, or a copy of your data by writing to rubengomezesp@gmail.com. Unsubscribe from marketing via the link in each email or at cuidalink.app/baja. We honor verified requests regardless of state of residence and will not discriminate against you for exercising your rights. Leads only receive communications about their own request until they opt in to marketing; SMS always requires prior express consent and honors STOP.

6. Retention and security

We keep lead and request data for 24 months after last activity; account data while active plus 12 months; invoices and payment records for 7 years as required by tax law; certificates for as long as verification is offered. We use encryption in transit, role-based access controls, row-level security on our database, and server-side secret isolation. If a breach affecting Florida residents occurs, we will notify as required by the Florida Information Protection Act (Fla. Stat. § 501.171).

7. Changes and contact

The platform is operated and hosted in the U.S. We will post updates here and notify material changes. Contact: CuidaLink · Miami, Florida · rubengomezesp@gmail.com.

CONTACT

Questions about this document?

rubengomezesp@gmail.com
WhatsApp