Privacy Policy

Lanterlink LLC · California · Last updated 17 August 2026

This policy covers two different things: this website, and the Lanterlink Care Portal that agencies log into. Our role is different in each, so we describe them separately.

The short version. On this website we collect only what you type into a form, and we use it to reply to you. Inside the portal, the records belong to the agency that issued your login — we hold them on that agency’s behalf under a signed agreement, and we do not sell personal information anywhere.

1. This website

If you request a walkthrough, ask about pricing, or start onboarding, we collect the details you enter — typically your name, email address, agency name, and anything you write in a message field. We use that information to reply to you and, if it looks like a fit, to follow up once.

Our web host records standard server logs, which include IP address, browser type, and the time of the request. These are used to keep the site available and secure.

We do not sell your information, and we do not add you to a mailing list because you contacted us.

2. The Lanterlink Care Portal

The portal is used by staff at agencies that have a subscription with us. If you have a login, the agency that issued it — not Lanterlink — decides what is recorded about the people it supports and how long it is kept.

In health-privacy terms, the agency is the Covered Entity and Lanterlink is its Business Associate. We hold the health information stored in the portal under a signed Business Associate Agreement with that agency, and that agreement governs how we may use it.

3. What the portal holds

4. How it is used

To operate the portal, to meet the reporting obligations agencies have to their funders and regulators — visit verification, Regional Center billing, payroll tax — and to answer support requests. We do not sell personal information, and we do not use the health information in the portal to advertise anything.

5. Your rights

California and federal health-privacy rules give people the right to see, correct, or receive a copy of information held about them.

If you are portal staff, use the My Data button in the portal, or contact your agency administrator. If the request concerns someone an agency supports, it goes to that agency — the agency holds the records and decides how the request is handled, and Lanterlink assists it in meeting the deadlines that apply to it.

For anything relating to this website rather than the portal, email privacy@lanterlink.com.

6. How long we keep it

Records inside the portal are kept for whichever period is longest among the rules that apply to that record. The agency that issued your login sets its own policy on top of this; these are the minimums we build to. If the underlying rules change, these periods change with them and we update this page.

RecordKept forWhy
Care and medical records7 years after the person leaves servicesCalifornia medical-records law
Billing claims and service authorizations7 yearsRegional Center audit and state licensing rules
Financial and service records tied to funding5 years from final payment for that state fiscal year, and longer while any audit or appeal is openCalifornia Regional Center record-keeping rules
Security and access audit logs6 yearsFederal health-privacy rules
Pay records and paystubs4 yearsCalifornia payroll record-keeping rules
The in-app activity log (who changed what)400 daysAn operational convenience record, not the compliance audit trail above
Inquiries sent through this websiteOnly as long as needed to answer them

Deletion. An agency can ask us to delete its data earlier, and we will, except where a rule above still requires the record to exist. Before anything is deleted, our tool checks the record against the retention rules it knows about — billing history, service authorizations and pay records — and will not proceed until an administrator reviews each warning and states a reason. That decision is written to the audit trail, so nothing quietly disappears, and the security and access audit log is never deleted at all. We do not keep customer data indefinitely by default.

7. Security

Access to the portal is restricted by role and by agency, actions are audit-logged, and data is encrypted in transit and at rest by our hosting providers, who are themselves under signed agreements covering health information. No system is perfectly secure, and we do not claim otherwise.

8. Changes

If this policy changes materially, we will update the date at the top and, for customers, say so in the portal.

9. Contact

Lanterlink LLC, California
Privacy: privacy@lanterlink.com
General: info@lanterlink.com

Lanterlink LLC · Built in California, for California providers.