Privacy Policy
Effective Date: 06/27/2026
1. Introduction
Lone Star ABA Services LLC (“Lone Star ABA,” “we,” “our,” or “us”) is a telehealth-based Applied Behavior Analysis (ABA) practice based in Texas. This Privacy Policy explains how we collect, use, disclose, and protect information through our website at www.lonestaraba.com and in the course of providing services. Our collection and use of Protected Health Information (PHI) is separately governed by our Notice of Privacy Practices, which is provided to patients at intake pursuant to the Health Insurance Portability and Accountability Act (HIPAA) and the Texas Medical Records Privacy Act (Texas Health & Safety Code Chapter 181, also known as HB 300).
2. Information We Collect
Through our website today, the information you provide directly falls into two paths. (a) Waitlist: the email address you submit to join our waitlist (and, if you apply for a role, the email address and resume you send us). Our waitlist form is processed for us by Jotform, the secure form service we use; the email address you enter goes to Jotform and to us, is used only to contact you about enrollment, and is never added to our analytics. (b) Learning Hub: if you sign up for our Learning Hub (free educational tools and resources for parents and caregivers), we collect the limited information described in Section 11A. The categories below describe the full range of information we collect once clinical intake and services begin.
A. Information You Provide Directly
Once clinical intake and services begin, this will include:
- Contact details such as name, phone number, email address, and mailing address.
- Information about your child and family that you submit through intake or contact forms.
- Insurance information you provide for verification of benefits.
- Correspondence with our team (email, messages, call notes).
B. Information Collected Automatically
Our website uses privacy-first analytics built into the site itself: no third-party analytics service and no tracking pixels. We measure things like which pages are visited, how long they are viewed, how far down the page visitors scroll, a general device-size category, the domain of the site that referred the visit, counts of waitlist-button clicks and signup-form starts, and whether the visit is from a new or returning browser, without cookies and without collecting information that identifies you. See Section 5 for detail. As with most websites, our hosting provider keeps standard server logs (such as IP addresses and timestamps) for a short period for security and reliability; those logs stay at the hosting layer and are not part of our analytics.
C. Protected Health Information (PHI)
Once services begin, we collect and maintain PHI as defined by HIPAA. The handling, use, and disclosure of PHI is governed by our separate Notice of Privacy Practices, which patients receive at or before the start of care. This website-facing Privacy Policy does not replace that Notice.
3. How We Use Information
- To respond to inquiries and schedule consultations.
- To verify insurance eligibility and coordinate authorization for services.
- To provide, coordinate, and document clinical care.
- To comply with legal, regulatory, and accreditation obligations.
- To improve our website and services.
4. How We Share Information
We do not sell personal information. Our use and disclosure of Protected Health Information (PHI) for treatment, payment, and healthcare operations is governed by our Notice of Privacy Practices, which controls over this website policy. We may share information with:
- Treatment partnersinvolved in your child’s care, consistent with HIPAA’s treatment, payment, and healthcare operations (TPO) provisions.
- Business Associates that provide services on our behalf (for example, electronic health records, telehealth platforms, secure email, billing). Each is bound by a Business Associate Agreement (BAA) where required.
- Government or regulatory bodies when required by law, subpoena, or to prevent imminent harm.
- Insurance payers as necessary to verify benefits, obtain authorization, and submit claims.
5. Cookies And Analytics
We use first-party, cookieless analytics to understand how our public website is used. We collect only the page visited (its address and title, never the query string); the time of the visit; roughly how long the page was read and how far down the page you scrolled (a percentage, never tied to your name or contact information); the domain of the website that referred you (not the full address or your search terms) and any campaign tags in the link you clicked; a general device size category (phone, tablet, or computer); a count of clicks on our waitlist button and when the signup form is first focused; whether you are visiting for the first time or returning; a simple count of waitlist signups (the count only; your email goes solely to our waitlist form provider, never into our analytics); and a random identifier kept in your browser’s short-term tab storage (not a cookie) that is not linked to your name or anything else about you and is designed to disappear when you close the tab. To tell first-time visitors from returning ones, we also keep a single anonymous marker in your browser’s local storage: it is not a cookie, it holds nothing but a yes/no, it is never linked to your name or anything else about you, and (unlike the tab identifier just described) it stays in your browser between visits so a returning browser can be recognized. In private or incognito browsing it may not be saved, so a return visit can simply be counted as new. Our analytics never collect your name, email, IP address, or any health information, and nothing is shared with any third-party analytics provider. We do not allow third-party advertising or social-media tracking pixels on our domain, and strictly necessary cookies may still be used to operate the site. Our hosting provider’s standard server logs are described in Section 2. If we add features that work differently (for example, a members-only area), we will describe them here before they launch.
6. Minors’ Privacy
We provide services to individuals and families under the care of a parent, legal guardian, or authorized caregiver. We do not knowingly collect information directly from minors via our website. Information about a minor is provided by a parent, legal guardian, or authorized caregiver as part of the intake or service process.
Pursuant to the Texas Securing Children Online through Parental Empowerment Act (the “SCOPE Act,” Texas Business & Commerce Code Chapter 509), we do not display targeted advertising to known minors, do not sell personal information of known minors, and do not permit minors to create accounts on this website.
7. Data Security
As we prepare to begin services, we are implementing administrative, physical, and technical safeguards designed to protect your information, consistent with the HIPAA Security Rule. These safeguards include encryption of PHI in transit and at rest, workforce training, role-based access controls, and audit logging. No system is perfectly secure; we cannot guarantee absolute security of any information transmitted to or from us.
Email sent from personal accounts (such as Gmail, Yahoo, or iCloud) is not encrypted end-to-end. Please do not send protected health information by unsecured email. We will provide secure communication channels at intake.
8. Your Rights
Depending on your relationship with Lone Star ABA and applicable law (HIPAA, Texas HB 300, and other state laws), you may have rights to:
- Request access to your or your child’s health records.
- Request an amendment to your records.
- Request an accounting of certain disclosures.
- Request restrictions on certain uses or disclosures.
- Request confidential communications.
- Receive a paper copy of the Notice of Privacy Practices.
- File a complaint with us or with the U.S. Department of Health & Human Services, Office for Civil Rights.
To exercise these rights, contact our Privacy Officer at privacy@lonestaraba.com, 737-241-0143.
9. Texas-Specific Notice (HB 300)
The Texas Medical Records Privacy Act (Chapter 181 of the Texas Health & Safety Code) provides protections that may exceed HIPAA in certain respects, including training requirements, restrictions on sale of PHI, and enhanced penalties. Lone Star ABA maintains a compliance program designed to meet these requirements.
10. Texas Data Privacy & Security Act
Under the Texas Data Privacy and Security Act (Texas Business & Commerce Code Chapter 541, effective July 1, 2024), Texas residents have the right to:
- Confirm whether we are processing your personal data and access that data.
- Correct inaccuracies in your personal data.
- Delete personal data you provided or that we obtained about you.
- Obtain a portable copy of personal data you provided to us.
- Opt out of the processing of your personal data for targeted advertising, sale of personal data, or profiling that produces legal or similarly significant effects.
To exercise these rights, contact our Privacy Officer using the information in Section 8. We will respond within 45 days. You may appeal a denial by replying to our written response within a reasonable time. If your appeal is denied, you may file a complaint with the Texas Attorney General at texasattorneygeneral.gov/consumer-protection.
Many categories of data we hold are exempt from the TDPSA, for example, protected health information governed by HIPAA, and data held by a HIPAA-covered entity. This section applies to non-exempt personal data, such as the email address you submit to join our waitlist. Protected Health Information is handled under our Notice of Privacy Practices.
11. Text Messaging
We send only transactional text messages: appointment reminders, service coordination, and administrative notices. We do not send marketing texts. If you provide your phone number during intake or in the course of services, you consent to receive these messages; your consent is obtained at intake and is not a condition of receiving services. (Our website does not collect phone numbers.) Message frequency varies. Message and data rates may apply. Reply STOP at any time to opt out, or HELP for assistance. Opting out of text messages will not affect your ability to receive services.
11A. Learning Hub Email Signups
Our Learning Hub provides free educational tools, downloadable resources, and informational content for parents, caregivers, and others supporting individuals receiving (or considering) Applied Behavior Analysis services. The Learning Hub is available on our website at lonestaraba.com/learning-hub and through our iOS and Android applications.
The Learning Hub is educational. It is not therapy. Signing up for the Learning Hub, downloading our tools, or interacting with our content does not create a clinician-patient, therapist-client, or BCBA-client relationship between you and Lone Star ABA Services LLC. Use of these resources is not a substitute for individualized professional evaluation, diagnosis, or treatment.
A. What We Collect At Signup
When you sign up for the Learning Hub, we collect: your email address; a hashed (one-way, non-reversible) version of your IP address; a general category describing the kind of device you used (for example, phone or computer); your responses to the consent checkboxes described below; and timestamps for your signup and email verification. We do not collect your name, your child’s name, your ZIP code or other location data, any diagnosis, any insurance information, or any health information through the Learning Hub signup.
B. Three Consent Choices At Signup
You will be asked to make three separate choices:
- Transactional emails (required to receive the tools you signed up for). These cover confirmations, the six-digit verification code we send to verify your email, password-reset messages if applicable in the future, and other account-event notifications.
- Marketing emails(optional). If you opt in, we will email you occasionally about new tools, new content, and Learning Hub updates. “Occasionally” means we do not commit to a fixed cadence and will not send you frequent or high-volume marketing email. You may withdraw this consent at any time using the one-click unsubscribe link in any marketing email, and doing so does not affect your access to the Learning Hub.
- Billing-related notices (reserved for future use). The Learning Hub is currently free. If we introduce paid features in the future, you would need to separately consent to receive billing-related notices at that time. This consent is reserved and not active today.
C. We Do Not Sell Or Share Your Learning Hub Email Address
We do not provide it to advertising networks, data brokers, or social-media platforms, and we do not use third-party tracking pixels or analytics services in the Learning Hub. Email sending is performed by our email service provider, which acts on our behalf under a written agreement.
D. Beta Program Disclosures
The Learning Hub is in active development. By signing up, you acknowledge: (a) features may change, be modified, be temporarily unavailable, or be discontinued, and we do not guarantee that any specific tool, content item, or account data will persist; (b) the Learning Hub is free during this beta period, and we may begin charging for some features in the future; (c) if paid features are introduced, beta participants will receive notice in advance and may be eligible for special pricing.
E. What Happens If A Learning Hub Signup Later Becomes An ABA Client
If you sign up for the Learning Hub and later enter into a clinical service agreement with Lone Star ABA, your Learning Hub email address does not automatically migrate into your clinical record, and we do not use your Learning Hub marketing consent as a substitute for the HIPAA marketing authorization required under 45 CFR § 164.508(a)(3). At service intake we will check whether your email is on the Learning Hub list and, if you wish to continue receiving Learning Hub marketing email after services begin, we will either obtain a separate written HIPAA marketing authorization or move you to a transactional-only segment.
F. Language Access
The Learning Hub signup screen, the verification email, and the welcome email are available in English and Spanish.
12. Data Retention
We retain clinical records for a minimum of seven (7) years after the last date of service, or longer if required by law, payer contract, or professional licensure rules. Because we serve minors, applicable Texas law may require us to retain a minor’s records for a longer period (in some cases extending past the age of majority), and we retain records for at least as long as the law requires. Website inquiry data (such as contact form submissions that do not become client records) is retained for up to twenty-four (24) months and then deleted or de-identified. Website analytics events contain no information that identifies you; we keep them only to produce usage statistics such as visit counts, new-vs-returning visitors, traffic sources, device category, scroll depth, and waitlist engagement. Backup copies may persist for a limited additional period before being overwritten.
Learning Hub retention specifics. Email addresses submitted to the Learning Hub but never verified (no six-digit code completed) are deleted within thirty (30) days. If you unsubscribe from Learning Hub marketing email, we retain a one-way hash of your email address on a suppression list for twenty-four (24) months to honor your unsubscribe request as required by the CAN-SPAM Act, and we drop the other fields from your record. Learning Hub accounts that show no engagement (no email opens, no clicks, no downloads) for twelve (12) months are auto-suppressed. Operational audit-log entries describing parent-facing events (signups, verifications, unsubscribes) are retained for ninety (90) days; administrator-facing audit-log entries (admin views of the signup list, configuration changes) are retained for six (6) years to support our HIPAA Security Rule documentation obligations.
13. Breach Notification
In the unlikely event of a breach affecting your personal information or protected health information, we will notify affected individuals and, where required, regulators as required by the HIPAA Breach Notification Rule (45 CFR §§ 164.400 to 414) and the Texas Identity Theft Enforcement and Protection Act (Texas Business & Commerce Code § 521.053). We will provide any required notice within the timeframes required by applicable law.
14. Do Not Track And Privacy Signals
Our analytics are first-party and cookieless, we do not track visitors across other websites, and we do not allow advertising networks, social-media platforms, or data brokers to collect information about your activity across other websites through our site: the things Do Not Track was designed to prevent. Because there is no cross-site tracking here to turn off, our site does not change its behavior in response to DNT browser signals. The same is true of newer privacy signals like Global Privacy Control (GPC): we do not sell personal information or share it for cross-site advertising, so there is nothing for these signals to opt you out of.
15. Changes To This Policy
We may update this Privacy Policy periodically. Material changes will be posted here with an updated effective date. Continued use of our website after changes constitutes acceptance of the revised policy.
16. Contact
Lone Star ABA Services LLC
Phone: 737-241-0143
Email: info@lonestaraba.com
Please do not include detailed health information in messages to these general addresses; we will provide secure communication channels at intake.
