Privacy Policy
The short version. VITADesk is scheduling software used by nonprofit organizations that offer free tax preparation. When you book an appointment, the organization you booked with is the owner of your information. We store it on their behalf, use it only to run the appointment, and never sell it or share it for marketing. Text messaging consent and mobile phone numbers are never shared with third parties or affiliates for marketing or promotional purposes.
1. Who we are and who this covers
VITADesk is made and operated by LCO Software Inc. ("LCO", "we"). This policy covers vitadesk.org, the organization booking pages on subdomains of vitadesk.org and on custom domains organizations connect to VITADesk, the admin application at app.vitadesk.org, and messages VITADesk sends on an organization's behalf.
Two kinds of people use VITADesk. Organizations (a United Way, a community action agency, a college, a church) subscribe to VITADesk to run their appointment desk. Clients book appointments with an organization. For client information, the organization is the data controller and LCO is the processor acting on its instructions. The organization's own privacy practices apply as well.
2. What we collect
From clients booking an appointment
- Name, phone number and/or email address, preferred language, and whether you file singly or jointly
- The appointment itself: location, date, time, status, and any notes the organization's staff add
- Answers to any intake questions the organization has chosen to ask
- If the organization has turned those features on: an intake form (IRS Form 13614-C) you complete online, a photo of an identification document you choose to upload, and documents you choose to upload for a drop-off or virtual appointment
- Messages you send to the organization by text and the messages sent to you
- Technical information: IP address, browser type, and pages visited, used for security and to make the site work
From organizations and their staff
- Organization name, addresses of service locations, staff names, emails and phone numbers, and sign-in credentials
- Billing details, handled by Stripe. We keep the last four digits of a card and the billing status; we never store full card numbers.
- Activity within the admin application, kept in an audit log so the organization can see who changed what
We do not collect Social Security numbers, tax returns, or financial account details, and VITADesk is not designed to hold them. Organizations that enable document upload agree to the retention limits in section 7.
3. How we use it
- To book, confirm, remind, reschedule, cancel, and check in appointments
- To verify that a phone number or email address is correct, so staff can reach the right person
- To send the messages described in section 4 and to show staff the replies
- To let organizations run their desk: day sheets, reports, and counts of appointments by location, language, and outcome
- To keep the service secure, prevent abuse, and fix problems
- To bill organizations for their subscription
We do not use client information for advertising, and we do not build profiles of clients across organizations.
4. Text messages
VITADesk sends text messages on behalf of organizations only to people who have agreed to receive them. When booking, a client may check a box to receive appointment texts. Staff may also enter a client's consent given by phone. Messages include booking confirmations, reminders before an appointment, notices when an organization changes or cancels an appointment, replies to questions about an appointment, and offers when a waitlisted seat opens. Message frequency varies with your appointments. Message and data rates may apply.
A one-time verification code sent to confirm a phone number is not part of the messaging program and does not enroll you in it.
You can stop texts at any time by replying STOP. Reply HELP for help. Replying STOP does not cancel your appointment; you can still manage it online or by calling the organization.
Mobile phone numbers and text messaging consent are not shared with third parties or affiliates for marketing or promotional purposes. Text message content and phone numbers are shared only with the carrier and messaging providers needed to deliver the messages.
5. Who we share it with
- The organization you booked with. Its staff see your appointment and the information you gave to book it.
- Service providers that run VITADesk on our behalf and are bound to use the data only for that purpose: cloud hosting and database services (Vultr), text message delivery (Telnyx, and Twilio as a fallback), email delivery, payment processing for organizations (Stripe), and automated message understanding (Anthropic, described in section 6).
- Connected systems an organization chooses to link, such as its volunteer management or sign-in system. The organization controls these connections.
- When required by law, or to protect the rights and safety of clients, organizations, or the public.
We do not sell personal information and we do not share it with data brokers or advertisers.
6. Automated handling of replies
When a client replies to a text with something other than a simple keyword, VITADesk may use an automated language model to understand the request (for example, that "I can't make it tomorrow" means the client wants to cancel or move the appointment). The system, not the model, then takes any action, and anything that changes an appointment is confirmed with the client first. The text of the reply and the details of the client's appointment are sent to Anthropic's API for this purpose under terms that prohibit using the data to train models. Organizations can turn this feature off; replies then go to staff to answer by hand.
7. How long we keep it
- Appointment records, including cancelled ones, are kept so organizations can report on their season. Organizations can ask us to delete a client's records at any time.
- Verification codes are deleted when they expire, within minutes.
- Text and email message logs are kept for 18 months.
- Uploaded identification photos and documents are deleted automatically on the organization's retention schedule, which defaults to 30 days after the appointment is completed and can be shortened but not extended beyond one season.
- Organization accounts that go unused are kept for 18 months, with warnings, and then deleted.
8. Security
Data is stored in the United States. Connections are encrypted in transit. Uploaded documents are stored encrypted in a private bucket that is never reachable by public link; every access is logged. Staff accounts use individual credentials and are limited to the locations they work. We limit our own access to what is needed to operate and support the service. No system is perfectly secure, and we will notify affected organizations promptly if we learn of a breach involving their data.
9. Your choices and rights
Clients can see, change, and cancel their appointments through the link in their confirmation, and can opt out of texts by replying STOP. To access, correct, or delete your information, contact the organization you booked with, or contact us at hello@vitadesk.org and we will work with the organization to respond. Depending on where you live, you may have additional rights under law; we honor them on request. We do not discriminate against anyone for exercising their rights.
10. Children
VITADesk is used by adults to book tax appointments. We do not knowingly collect information from children under 13. Dependents may be named on an intake form, but the account and appointment belong to the adult client.
11. Changes and contact
We will post any changes to this policy on this page and update the effective date. Material changes affecting clients will also be sent to organizations so they can inform their clients.
LCO Software Inc.
Email: hello@vitadesk.org