Privacy Policy

Effective Date: October 2026

Who We Are

Our website address is: https://cm2care.com. This website and its associated booking tools are operated by Concierge Medical Care & Mobility LLC DBA Concierge Medical Mobility (“CM2 Care,” “we,” “us,” or “our”). We are a specialized Non-Emergency Medical Transportation (NEMT) provider offering Door-Through-Door mobility support across the Greater Phoenix Valley.

Mailing Address:

Concierge Medical Care & Mobility LLC

PO Box 16, Cave Creek, AZ 85327

Dispatch Phone: (602) 529-4474

Email: dispatch@cm2care.com

NEMT, HIPAA, & Mandatory Non-Disclosure Agreements (NDAs)

As a provider partnering with private individuals, healthcare facilities, and case managers, we enforce rigorous privacy standards:

  • HIPAA Compliance: All digital communications, telecommunication systems, dispatch platforms, and data storage infrastructure strictly adhere to Health Insurance Portability and Accountability Act (HIPAA) standards.
  • Mandatory NDAs: In addition to HIPAA compliance, we execute Non-Disclosure Agreements (NDAs) for every single ride. This guarantees complete confidentiality regarding our Guests’ identities, locations, travel dates, and mobility needs.
  • Onboard Safety & Privacy: For the safety of our Guests and staff, company vehicles feature continuous real-time GPS tracking and visual-only cabin and windshield recording systems. Cabin audio recording is strictly disabled to protect Guest privacy.

Information We Collect & How We Collect It

1. Transit & Mobility Requests

When you request a quote, book a ride, or register a facility account, we collect:

  • Guest contact information (name, phone number, email address, emergency contacts).
  • Pickup and drop-off addresses, door/gate access codes, and requested travel schedules.
  • Mobility classifications (Ambulatory, Wheelchair, Powerchair, Bariatric) and specific equipment requirements.
2. Comments

When visitors leave comments on the site, we collect the data shown in the comments form, as well as the visitor’s IP address and browser user agent string to assist with spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to verify usage. The Gravatar service privacy policy is available at https://automattic.com/privacy/. Upon approval of your comment, your profile picture is visible to the public in the context of your comment.

3. Media

If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

4. Cookies
  • Comment Cookies: If you leave a comment on our site, you may opt-in to saving your name, email address, and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies last for one year.
  • Login & Session Cookies: If you visit our login page, we set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser. When you log in, we set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies are removed.
  • Content Editing Cookies: If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you edited. It expires after 1 day.
5. Embedded Content From Other Websites

Articles or portals on this site may include embedded content (e.g., videos, maps, scheduling widgets, embedded forms). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

Who We Share Your Data With

We never sell, rent, or trade personal data or Guest transit information to third-party marketers. We only share data under these operational conditions:

  • Partner Facilities & Case Managers: If a trip is arranged through a partner clinic, hospital, or care facility, digital post-trip Mobility & Encounter Records (MER) are synced directly to their secure client portal upon trip completion.
  • HIPAA-Compliant Business Associates: Data is transmitted through our secure dispatch software (including Bambi NEMT) under formal Business Associate Agreements (BAAs).
  • Password Resets: If you request a password reset for a facility or booking account, your IP address will be included in the reset email.
  • Emergency Assistance: If a Guest experiences an acute crisis during transit, relevant details will be shared with emergency personnel (911).

How Long We Retain Your Data

  • Comments & Metadata: If you leave a comment, the comment and its metadata are retained indefinitely so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.
  • User Accounts: For users that register on our website or booking portal, we store the personal information provided in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
  • Transit & MER Records: Mobility & Encounter Records (MER) and ride transaction logs are retained in accordance with state and federal healthcare record retention standards.

What Rights You Have Over Your Data

If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obligated to keep for administrative, legal, compliance, or security purposes.

Where Your Data Is Sent

Visitor comments may be checked through an automated spam detection service. All booking intakes and Guest transit data are transmitted through encrypted, HIPAA-compliant channels.