Privacy Policy

1. About this policy

RitzFMS, Inc. (“RitzFMS,” “we,” “us,” or “our”) provides financial management services for participants in California’s Self-Determination Program. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information through ritzfms.com, the RitzFMS App for iOS and Android, our web portal, and related onboarding, payroll, payment, timekeeping, document processing, communications, and support services (collectively, the “Services”).

This policy covers website visitors, participants, authorized representatives, employees and other service providers, vendors, Independent Facilitators, Regional Center contacts, and personnel whose information we process through the Services. The information we handle depends on your role and the services involved. Not every category below applies to every person.

2. Information we collect

Depending on your relationship with RitzFMS, we collect and maintain the following types of information:

  • Identity and contact information: Names, addresses, email addresses, telephone numbers, dates of birth, participant identifiers, and information establishing a representative’s identity and authority.

  • Account information: Usernames, account identifiers, authentication information, roles, permissions, invitations, and relationships between participants and their employees, providers, or representatives. RitzFMS creates accounts before sending invitations. Accepting an invitation enables access to an existing account. Current sign-in is administered through Microsoft Entra ID.

  • Employment and eligibility information: Onboarding documents, Social Security numbers and other tax identifiers, work authorization and identification documents, qualifications, employment-related screening information, and records needed for payroll, benefits, insurance, and employer responsibilities.

  • Financial and service records: Bank and payment details, pay rates, wages, deductions, tax records, invoices, receipts, reimbursements, budgets, spending plans, service authorizations, approvals, and payment history.

  • Program and health-related information: Disability, health, support needs, and other information contained in participant and program records when necessary to administer authorized services and related payments.

  • Timekeeping and location information: Schedules, service dates, timesheets, clock-in and clock-out records, and precise device location collected at punches as explained below.

  • Communications and submitted content: Support requests, emails, messages, forms, signatures, and uploaded documents, including photographs or scans contained in those documents.

  • Technical and activity information: Account activity, login and security events, and audit records. Technical information processed when you access the Services may also include IP addresses, browser or device details, session information, and error information used to operate and secure the Services.

Some information is sensitive, including government identifiers, account credentials, financial account information, precise location, and health information. Please provide only information relevant to the service or request. If you submit another person’s information, you must have appropriate authority or another lawful basis to do so.

3. Sources of information

We receive information directly from you and from participants, authorized representatives, employers, employees, vendors, Regional Centers, and other parties involved in authorized services. We also receive information from providers supporting identity management, payroll, hosting, document processing, and customer support. We generate account, transaction, approval, and audit records through our operations and collect device information as described in this policy.

4. How we use information

We use personal information to:

  • Create and administer accounts and verify identity, authority, and eligibility.

  • Onboard participants, employees, providers, and vendors.

  • Administer authorized services, spending plans, and budgets.

  • Process timekeeping, payroll, taxes, invoices, reimbursements, and payments.

  • Maintain service records and prepare program and financial reports.

  • Communicate about accounts, requests, pending actions, and service matters.

  • Provide support, correct errors, and resolve questions or disputes.

  • Protect accounts, investigate suspected misuse, troubleshoot systems, and maintain backups and service continuity.

  • Meet applicable legal, contractual, reporting, audit, and recordkeeping obligations.

We do not sell personal information or share it for cross-context behavioral advertising. We do not use participant, employee, or vendor information for unrelated advertising or marketing.

5. Location information and device permissions

The RitzFMS App requests location permission and collects precise GPS location only when you submit a clock-in or clock-out punch. It does not continuously track GPS location or collect GPS location between punches.

Punch location is associated with the relevant timekeeping or service record and used for visit verification, timekeeping accuracy, and review of service or payment questions. It may be disclosed with those records to authorized recipients described in Section 7 when necessary for those purposes.

You can change or revoke location permission through your device settings. Disabling permission may prevent completion of a location-dependent timekeeping function. Contact us if you cannot use that function so we can explain available procedures. Revoking permission does not automatically delete previously collected records.

Any additional device permissions will be explained when requested. We will obtain any consent or authorization required for new collection or uses.

6. Cookies and similar technologies

Our website, portal, and sign-in services may use cookies, local storage, or similar technologies to support authentication, maintain sessions, remember settings, and protect the Services. These technologies may be provided by services integrated into the website or portal.

You can manage cookies and storage through your browser settings. Blocking technologies needed for sign-in or security may affect functionality. Browser settings do not, by themselves, stop processing needed to provide services you request or meet recordkeeping obligations.

We do not use personal information for cross-context behavioral advertising. Browser Do Not Track signals do not change the service-related processing described in this policy. We honor legally required privacy choices and applicable opt-out preference signals where they apply to our processing.

7. When we disclose information

We disclose personal information for the purposes described in this policy to the following recipients, as appropriate:

Authorized participants in services. Participants, representatives, employees, providers, vendors, and Independent Facilitators receive information relevant to their authorized responsibilities. Access depends on role, relationship, and permissions. A relationship with a participant does not give someone unrestricted access to another person’s records. The participant-facing portal does not disclose an employee’s home address or background-check history merely because the employee serves that participant.

Regional Centers and oversight bodies. We provide necessary service, budget, timekeeping, payment, and other records to responsible Regional Centers, the California Department of Developmental Services, and other authorized bodies for administration, reporting, audits, and legal requirements.

Service providers. We use providers for cloud hosting and backups, authentication, payroll, customer support, document processing, and communications. Current providers include Microsoft Azure and Entra ID, ADP, Zendesk, and Nanonets. Providers receive information relevant to the functions they perform. Providers processing personal information on our behalf must provide protections at least equivalent to those described in this policy and use the information only for authorized purposes consistent with applicable law.

Legal and professional recipients. We may disclose information to government authorities, auditors, insurers, legal advisers, or other authorized recipients when necessary and lawful to meet our responsibilities, respond to valid legal process, resolve disputes, or protect rights and security.

Other authorized disclosures. We may disclose information with your authorization. Information may also be involved in a lawful reorganization or transfer of our business, subject to applicable confidentiality restrictions and any required notice or consent.

All disclosures remain subject to applicable restrictions on health, employment, and participant information. This policy does not authorize disclosures prohibited by law.

8. Automated document processing

We use optical character recognition and AI-assisted tools, including Nanonets, to extract and organize information from documents used to provide the Services. Document content, including personal information within a document, may be transmitted to these providers for processing.

If you believe extracted information is incorrect, use the available correction tools or contact us. This policy does not replace any separate disclosure, permission, or authorization required before information is submitted to a third-party processing service.

9. Email, text messages, and notifications

We send operational emails about accounts, security, services, requests, and administrative matters. Certain operational emails are necessary while we provide the Services and do not have a general marketing unsubscribe option.

SMS, RCS, and push notifications are optional where offered. If you opt into the RitzFMS Messaging Program, messages may include account verification, request updates, and notices about pending actions. Message frequency varies, and message and data rates may apply.

Reply STOP to supported text messages to opt out or HELP for assistance. You may receive one confirmation of your opt-out. If a channel does not support replies, contact us using the information below. You can manage push permissions in your device settings where available.

We do not share mobile information with third parties for their marketing or promotional purposes. Messaging opt-in information and consent records are disclosed only as necessary to provide and administer messaging services, comply with law, or protect legal rights, subject to applicable restrictions.

Opting out of text messages does not close your account or delete service records. Message delivery depends on carriers and other technical conditions. Do not use these channels for emergency assistance.

10. Retention, account closure, and deletion

We retain personal information for service administration and applicable employment, payroll, tax, payment, program, audit, security, and legal needs. Retention depends on the record type, applicable requirements, outstanding transactions, and any audit, dispute, or legal hold. Different records may have different retention periods and starting dates.

RitzFMS currently retains operational service records and does not automatically delete them after a fixed period. This does not eliminate applicable privacy or deletion rights.

You may request account closure or deletion of personal information by emailing info@ritzfms.com or calling (833) 748-9888 or (626) 667-4914. Identify the request as a “RitzFMS App account deletion” or “privacy request” and provide your name and account contact information. Do not send passwords or full Social Security numbers.

We will review your request and verify identity and authority as appropriate. We will process verified account and data deletion requests, subject to applicable legal requirements and permitted retention exceptions, and explain any information retained and the reason for retaining it. We will explain the expected completion timeframe and confirm when an approved deletion is completed. Account access and underlying service records are handled separately. Disabling access is not the same as deleting an account or its data. Retained records remain subject to applicable confidentiality and use restrictions.

Required payroll, tax, employment, payment, or program records may remain after an account is closed. Backup copies may also persist subject to applicable retention and legal requirements. Closing an account does not itself terminate employment, cancel services, settle payments, or eliminate recordkeeping obligations.

11. Access, corrections, and other privacy requests

You can review information and change available editable fields or permissions through your account, subject to your role and authority. Official payroll, tax, payment, and audit records may require a reviewed correction or adjustment that preserves the original entry and change history.

Contact us to request access, a copy, correction, deletion, or help with permissions or consent. Where processing depends on consent, you may contact us to withdraw it. Withdrawal does not undo prior lawful processing or prevent retention or processing required or otherwise permitted by law.

We may request information needed to verify your identity and an agent’s or representative’s authority. An existing account or contact method, additional evidence, or independent confirmation may be needed depending on the sensitivity of the request. We may limit or deny a request that cannot reasonably be verified, subject to applicable law. Verification information is used for verification, request handling, and required documentation.

We respond within applicable legal time limits. You do not need to create a new account to submit a request. Please request a secure submission method before sending sensitive supporting documents.

12. California privacy rights

To the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to RitzFMS and the information involved, California residents may have rights to know and access personal information, obtain information about its sources and disclosures, correct inaccuracies, request deletion, and exercise applicable rights concerning sale, sharing, or certain uses of sensitive information.

The categories of information, sources, purposes, recipients, and retention practices are described above. We do not sell personal information or share it for cross-context behavioral advertising. We use sensitive information for service delivery, verification, security, and legal or administrative responsibilities described in this policy.

You or an authorized agent may submit a request using the contact information below. We will not unlawfully discriminate or retaliate against you for exercising applicable privacy rights. Rights are subject to applicable exceptions, including certain recordkeeping duties and protections for other people’s information. Health information subject to specific confidentiality laws may be governed by different rights and procedures.

13. Health information and minors

We handle health-related and participant information subject to applicable confidentiality requirements, including HIPAA where it applies to our activities. This general Privacy Policy is not a HIPAA Notice of Privacy Practices and does not replace a notice or authorization required by law. Some requests may require coordination with the organization responsible for the relevant health records.

Accounts are intended to be operated by adults. Parents, guardians, or other appropriately authorized adults manage accounts for participants who are minors. Although children do not independently operate accounts, we process information about minor participants to administer their services. Participant employees must be at least 18.

Contact us if you believe a child is operating an unauthorized account or information was submitted without appropriate authority. A parent’s prior access does not automatically establish continuing authority after a participant becomes an adult.

14. Security and access from other locations

Our safeguards include encryption for app communications, field-level encryption for protected database fields, role-based access controls, audit logging, and database backups. No system or transmission method can guarantee absolute security.

The Services support California programs. Authorized personnel may access information from outside California or the United States. The location of a user or staff member does not change the confidentiality obligations applicable to the information.

Keep your credentials private and notify us promptly if you suspect unauthorized access. We will provide or coordinate security-incident notices when required by applicable law.

15. Other services and changes to this policy

Links to independently operated websites or services may be subject to those organizations’ privacy notices. This does not remove our responsibilities for information disclosed by RitzFMS or handled by providers on our behalf.

We may update this policy as our practices, Services, or requirements change. We will post the updated policy with its effective date and provide additional notice or obtain consent where required. Future features or uses of information are not authorized merely by their possible development.

16. Contact us

For privacy questions, requests, complaints, or an accessible version of this policy, contact:

RitzFMS, Inc. — Privacy Requests
2707 E Valley Blvd, #307
West Covina, CA 91792
Email: info@ritzfms.com
Toll-free: (833) 748-9888 (833-RITZ-888)
Business telephone: (626) 667-4914
Website: https://ritzfms.com