Privacy Policy

Effective Date: July 20, 2026

1. Information Collection

SoarTime Pro, operated by BunmiSoar LLC, collects information necessary to provide and improve our workforce management platform for residential care and support agencies.

Account information: name, email address, phone number, and agency affiliation collected during onboarding and account creation.

Operational data: clock-in and clock-out events, timesheet entries, scheduling information, certification records, and role assignments generated through normal use of the Service.

We do not collect or store payment card data. Card information is handled exclusively by our payment processor, Stripe.

2. Use of Data

We use the information we collect to operate, maintain, and improve the Service; to process subscription billing; to communicate with you about your account; to enforce our Terms of Service; and to meet legal and regulatory obligations.

Agency operational data is used solely to deliver the features you request — for example, calculating payroll summaries, tracking certification expirations, and surfacing approval workflows.

We do not sell your personal information to third parties.

3. Stripe as a Sub-Processor

SoarTime Pro uses Stripe, Inc. as its third-party payment processor. When you subscribe to SoarTime Pro or manage your billing, you interact with Stripe's hosted checkout and billing portal.

Stripe collects and processes your payment card and bank account information directly. SoarTime Pro receives only a tokenized confirmation that payment has succeeded or failed — we never receive, store, or transmit raw card numbers, CVVs, or full bank account details.

Payment data is not Protected Health Information (PHI) and is processed by Stripe under Stripe's own privacy and security standards, including PCI-DSS compliance. SoarTime Pro's handling of payment confirmations does not constitute handling of PHI.

You can review Stripe's privacy policy at https://stripe.com/privacy.

4. Data Security

We follow HIPAA-aligned best practices for the protection of residential care workforce data, even where SoarTime Pro is not itself a covered entity or business associate under HIPAA.

All data is encrypted in transit using TLS and at rest using industry-standard encryption.

Access to production data is restricted using role-based access control and is logged in an audit trail. Sensitive fields require elevated privileges and are access-audited.

Payment processing security (PCI-DSS) is maintained by Stripe. SoarTime Pro maintains a PCI-compliant integration and does not store cardholder data.

We monitor for suspicious activity, including anomalous clock-in patterns and unauthorized access attempts, and we retain audit logs to support incident investigation.

5. User Rights

You have the right to access, correct, or export the personal information we hold about you, subject to the role-based controls in your agency.

Agency administrators may export workforce data, manage staff records, and remove staff from their agency. Super Admins may assist with account-level corrections.

You may request deletion of your account and associated personal data, subject to our legal retention obligations and your agency's operational requirements.

To exercise any of these rights, contact us at admin@soartimepro.com.

Questions about this Privacy Policy? Contact us at admin@soartimepro.com.

© 2026 BunmiSoar LLC · Your information is secure and encrypted.