Skip to content
ProvidersDesk

Privacy Policy

LAST UPDATED SEPTEMBER 18, 2026

Who we are

ProvidersDesk is operated by the ProvidersDesk team in the United States.

Contact us at hello@providersdesk.com or through the contact form.

The short version

We do not ask you to create an account, and we do not ask for personal information. The tools work without knowing who you are.

We record which codes get looked up, with nothing identifying attached. We use analytics, and we serve advertising. Both use cookies. Details below, and in the cookie policy.

What we collect

Tool usage

When you look up a code, we record which code it was and nothing else. No IP address, no name, no session identifier tied to you. This tells us which datasets matter and which tools to build next.

Analytics

We use Google Analytics to understand which pages get visited and how people find them. It sets cookies and collects usage data including a truncated IP address, browser type and pages viewed.

Opt out with the Google Analytics Opt-out Browser Add-on.

Advertising

This site displays advertising served by Google AdSense.

  • Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this and other websites
  • Google's use of advertising cookies enables it and its partners to serve ads based on your visit to this site and other sites
  • You can opt out of personalised advertising at Google Ads Settings
  • You can opt out of many third-party vendor cookies at aboutads.info or, in Europe, Your Online Choices
  • Third-party vendors we do not control may also serve ads here

How Google handles this data: How Google uses information from sites or apps that use our services and the Google Privacy Policy.

The contact form

If you send us a message, we receive the name, email address and message you typed, plus the page you came from. That is the only place on this site where you give us personal information, and it is entirely voluntary.

We use it to reply to you and nothing else. Messages are kept in our inbox while they are useful and deleted when they are not. We do not add you to any mailing list.

Server logs

Our web server keeps standard access logs including IP address, browser and requested URL. These are used for security and troubleshooting, kept for a limited period, and not combined with anything else.

What we do not collect

  • No accounts, so no names, emails or passwords, unless you choose to use the contact form
  • No patient information. There is no free-text field on this site into which any could be entered, by design
  • No payment details. Nothing here is paid for
  • We do not sell personal information to anyone

Legal basis, for EU and UK visitors

Under the GDPR and UK GDPR, we rely on:

  • Legitimate interest for security logs and aggregate, non-identifying usage counts
  • Consent for analytics and advertising cookies, which are not set until you agree

You can withdraw consent at any time. See the cookie policy.

Your rights

EU, UK and Switzerland

You have the right to access, correct, delete, restrict or object to processing of your personal data, and the right to data portability. Because we hold no accounts and no personal profiles, there is usually nothing personal of yours for us to export or delete. Email us and we will look.

You also have the right to lodge a complaint with your national data protection authority. A list is maintained by the European Data Protection Board. In the UK, the Information Commissioner's Office.

California

Under the CCPA as amended by the CPRA, California residents may request disclosure of personal information collected, request deletion, and opt out of the sale or sharing of personal information.

We do not sell personal information. To opt out of personalised advertising, use Google Ads Settings or email us. We will not discriminate against you for exercising any of these rights.

Provider data in the NPI lookup

The NPI lookup displays information from the CMS NPPES public file. That data is disclosable under the Freedom of Information Act and published by the federal government for public use. It contains business contact details, not personal ones.

If you are a provider and your NPPES record is wrong, it must be corrected at the source through NPPES. We import what CMS publishes and cannot amend the federal record. Once you update it there, the correction reaches us with the next monthly import.

Data transfers

This site is hosted in the United States. If you access it from outside the US, your information is transferred to and processed in the US. Google's transfer mechanisms are described in the Google privacy frameworks.

Retention

Aggregate usage counts are kept indefinitely because they identify nobody. Server logs are kept for a limited period for security purposes. Analytics retention follows the setting configured in Google Analytics.

Children

This is a professional reference site, not directed at children under 13, and we do not knowingly collect information from them.

Changes

If this policy changes materially, the date at the top of this page changes with it.

Contact

For any privacy question, or to exercise any of the rights above, email hello@providersdesk.com or use the contact form. We respond within a few days.