MAPD Tool Back to MAPD Tool →

Privacy Policy

What MAPD Tool collects, what it does with it, and who else touches it.

This Privacy Policy explains what the MAPD Tool platform (the “Service”), operated by Spark AI Partners, collects, what it does with it, and who else touches it. It covers both the agent-facing application and the agency portal.

1. The two kinds of information here

The Service handles two categories of information, and they are governed differently:

2. What we collect

Account information. Your name, email address, company name, username, and a salted hash of your password. We do not store your MAPD Tool password in a recoverable form.

CMS MARx credentials. The MARx username and password you enter. These are stored encrypted (see Section 6) and are decrypted only in memory, at the moment a sign-in is performed on your behalf.

Access to your verification-code email. Described in Section 3, because it deserves its own section.

CRM credentials. Your CRM API key and location identifier, stored encrypted, used to read the contacts you designate and write results back.

Beneficiary information. For each contact you submit for checking, the Service processes and stores: client name, Medicare Beneficiary Identifier (MBI), plan name and plan code, enrollment status, and enrollment effective and end dates as returned by MARx, together with the corresponding values already in your CRM so that changes can be detected. We do not collect Social Security numbers, clinical records, diagnoses, or claims data.

Billing information. Payment card details are collected and stored by our payment processor, Stripe. We never receive or store full card numbers. We retain your subscription status, invoices, and usage counts.

Operational logs. Sign-in times, batch run records, error diagnostics, and feature usage, used to operate and troubleshoot the Service. Logs are filtered to strip beneficiary identifiers before they are written.

3. Access to your verification-code email — in detail

CMS emails a one-time verification code each time your MARx account is signed in to. To sign in on your behalf, the Service must read that code.

What the Service reads. It queries your mailbox for messages from no-reply@idm.cms.gov whose subject contains “One-time verification code,” sent within the preceding day, and extracts the numeric code. No other message is read, opened, stored, indexed, copied, or transmitted anywhere.

What the permission technically allows. We are telling you this plainly rather than leaving it in the fine print: the authorization Google issues for this purpose (gmail.readonly) is a read permission over the mailbox, not a permission limited to CMS messages. Google does not offer a narrower scope. The limitation to CMS messages is enforced by our software, not by the permission itself.

What we are changing. We consider mailbox-wide permission to be more access than this function needs, particularly because an agent's mailbox routinely contains PHI unrelated to the Service. We are replacing it with a mechanism in which you create a forwarding rule that sends only CMS verification messages to a dedicated address we operate, after which the mailbox authorization is revoked and no email account access is held at all. This document will be updated when that change ships.

Revoking. You can revoke email access at any time at myaccount.google.com/permissions or from your Service settings. Automated checks stop working until you configure an alternative.

4. How we use information

We use your information to operate the Service: to authenticate you, to sign in to MARx at your direction, to read and write the CRM records you designate, to bill you, to notify you about runs and failures, and to provide support. We use beneficiary information only to perform the checks you request and to produce the results and optional written summaries you have enabled.

We do not sell information. We do not share it with data brokers. We do not use beneficiary information for advertising, for our own marketing, or to build any product other than the results returned to you. We do not use your data or your clients' data to train artificial-intelligence models, and our AI provider is contractually prohibited from doing so with data submitted through its API.

5. Who else processes information (subprocessors)

We will update this list before adding a subprocessor that handles beneficiary information.

6. Artificial intelligence and PHI

Optional features generate written plan comparisons and client summaries using a large language model provided by Anthropic through its commercial API. Before any request is sent:

Data submitted through the Anthropic API is not used to train models. Where a Business Associate Agreement is required, ours is in place with providers that handle PHI.

7. Security

No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your information or your clients' PHI, we will notify you without unreasonable delay and in any event within the timeframes required by HIPAA and applicable state law, with the information you need to meet your own notification obligations.

8. Retention and deletion

We retain account information, check results, and operational logs for as long as your account is active. You can delete individual reports from within the Service at any time.

On written request, or within 30 days of account termination, we will delete or return the beneficiary information we hold on your behalf, except where retention is required by law. Credentials are deleted immediately on account termination or on your request. Billing records are retained as required for tax and accounting purposes.

To request deletion, email support@sparkaipartners.com from your account address.

9. Your choices

You can revoke email access, disconnect your CRM, remove your MARx credentials, disable automated scheduled checks, or close your account at any time from within the Service. Removing credentials stops all automated activity under them.

10. Children

The Service is not directed to anyone under 18 and we do not knowingly collect information from children.

11. Changes to this Policy

We will post any change here and update the “Last updated” date. If a change materially affects how beneficiary information is handled, we will notify account holders before it takes effect.

12. Contact

Questions, deletion requests, or a request for our Business Associate Agreement: support@sparkaipartners.com