Privacy Policy
Potential Within Reach, Inc.
Effective Date: May 23, 2026 Last Updated: May 23, 2026
1. Introduction
Potential Within Reach, Inc. (“Potential Within Reach,” “we,” “our,” or “us”) is a Colorado-based professional services practice providing ADHD coaching, executive functioning skill training, and counseling services to children, teens, adults, and families. We are committed to protecting the privacy of every person who visits our website, contacts us, or receives services from our practice.
This Privacy Policy explains what information we collect through our website at potentialwithinreach.com (the “Website”), how we use and protect that information, and the choices you have regarding your personal information.
By using our Website, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use our Website.
2. Scope of This Policy
This Privacy Policy applies to information collected through our Website and our general business operations.
Important note for clients and prospective clients: If you become a client of our practice, the protected health information (PHI) we collect, use, and disclose as part of providing clinical services is governed by our separate Notice of Privacy Practices (NPP) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). You will receive a copy of our Notice of Privacy Practices at the time of your first appointment. You may also request a copy at any time by contacting us using the information at the end of this Policy.
3. Information We Collect
3.1 Information You Provide Directly
We collect information you voluntarily provide when you:
- Submit a contact form, request a consultation, or send us an email
- Schedule an appointment through our online booking portal
- Subscribe to our newsletter or blog updates
- Communicate with us by phone, text, or email
- Leave a comment on our blog
- Apply for a position with our practice
This information may include your name, email address, phone number, mailing address, the contents of your message, and any other information you choose to share with us.
3.2 Information Collected Automatically
When you visit our Website, we and our third-party service providers may automatically collect certain technical information, including:
- Your IP address and approximate location
- Your browser type, operating system, and device information
- The pages you visit on our Website and the time you spend on each page
- The website you came from before visiting ours (referring URL)
- Date and time of your visit
We collect this information using cookies, pixels, and similar tracking technologies (see Section 6 below).
3.3 Information From Third Parties
We may receive information about you from third-party services we use, such as:
- Our scheduling and practice management platform (SimplePractice)
- Online directories where we maintain listings (Psychology Today, ADDitude Magazine)
- Advertising platforms (Google Ads, social media platforms)
- Analytics providers (Google Analytics)
4. How We Use Your Information
We use the information we collect to:
- Respond to your inquiries and provide the services you request
- Schedule consultations and appointments
- Send you appointment reminders and administrative communications
- Improve our Website and the services we offer
- Provide and improve our coaching and counseling services
- Process payments for services rendered
- Comply with legal obligations and protect our legal rights
- Send periodic newsletters or educational content (only if you have opted in)
- Measure the effectiveness of our advertising and marketing efforts
We do not sell your personal information to third parties for their own marketing purposes.
5. How We Share Your Information
We share your information only in the following circumstances:
5.1 Service Providers
We share information with trusted third-party service providers who perform services on our behalf, such as:
- SimplePractice — our HIPAA-compliant practice management, scheduling, electronic health records (EHR), telehealth, and payment processing platform. We maintain a signed Business Associate Agreement (BAA) with SimplePractice.
- Website hosting and security providers
- Artificial Intelligence service providers (SimplePractice built-in tools and UpHeal)
- Email and communication providers
- Analytics and advertising providers (e.g., Google, Meta, LinkedIn)
- Professional consultants, accountants, and legal professionals
These providers are contractually obligated to protect your information and use it only for the purposes for which we have disclosed it to them.
5.2 Legal Compliance
We may disclose information when we believe in good faith that disclosure is necessary to:
- Comply with a law, regulation, court order, subpoena, or other legal process
- Cooperate with law enforcement or government agencies
- Protect the rights, property, or safety of Potential Within Reach, our clients, employees, or others
- Investigate or address suspected fraud, security issues, or violations of our policies
5.3 Business Transfers
If our practice is acquired, merged, or otherwise transferred, your information may be transferred as part of that transaction. We will notify you of any such change.
5.4 With Your Consent
We may share your information with other parties when you give us your explicit consent to do so.
6. Cookies and Tracking Technologies
Our Website uses cookies and similar tracking technologies to enhance your experience, analyze traffic, and improve our services. Cookies are small data files stored on your device when you visit a website.
We use the following types of cookies:
- Essential cookies — required for the Website to function properly
- Analytics cookies — help us understand how visitors interact with our Website (e.g., Google Analytics)
- Advertising cookies — used by Google Ads and similar platforms to measure ad effectiveness and show relevant ads on other websites
You can control cookies through your browser settings. Most browsers allow you to refuse or delete cookies, but doing so may affect the functionality of our Website. You can also opt out of Google Analytics by installing the Google Analytics Opt-Out Browser Add-on, and opt out of personalized Google ads at https://adssettings.google.com.
7. Third-Party Services and Links
Our Website integrates with or links to several third-party services, each governed by its own privacy policy:
- SimplePractice (booking, EHR, telehealth, payment processing) — https://www.simplepractice.com/privacy/
- Google Analytics — https://policies.google.com/privacy
- Google Ads — https://policies.google.com/technologies/ads
- Facebook / Meta (social media presence, advertising) — https://www.facebook.com/policy.php
- LinkedIn (social media presence, advertising) — https://www.linkedin.com/legal/privacy-policy
- X / Twitter (social media presence) — https://twitter.com/en/privacy
- YouTube (embedded videos) — https://policies.google.com/privacy
- Psychology Today directory listing — https://www.psychologytoday.com/us/privacy-policy
We are not responsible for the privacy practices of these third-party services. We encourage you to review their privacy policies before sharing any information with them.
8. Protected Health Information and HIPAA
If you are a current or prospective client of our practice, any health information you share with us in the context of receiving services — including information shared during consultations, intake forms, sessions, or through our SimplePractice client portal — is “Protected Health Information” (PHI) under HIPAA and is governed by our separate Notice of Privacy Practices.
Our Notice of Privacy Practices describes:
- How we may use and disclose your PHI
- Your rights with respect to your PHI (including the right to access, request amendments to, and receive an accounting of disclosures of your records)
- Our legal duties regarding your PHI
- How to file a complaint if you believe your privacy rights have been violated
You will receive our Notice of Privacy Practices at your first appointment. You may also request a copy by contacting us at any time. Information collected through general Website browsing (such as IP address and analytics data) is not considered PHI under HIPAA unless it is associated with your identifiable health care information.
9. Data Security
We take reasonable administrative, technical, and physical safeguards to protect your information from unauthorized access, use, alteration, or destruction. These include:
- Use of HIPAA-compliant platforms (SimplePractice) for all client communications, scheduling, records, and telehealth sessions
- Encryption of data in transit and at rest where applicable
- Restricted access to client information on a need-to-know basis
- Contractual confidentiality obligations for all independent contractors and service providers
- Secure password practices and account access controls
No method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security. If you have reason to believe your interaction with us is no longer secure, please contact us immediately.
10. Children’s Privacy
We provide coaching and counseling services to minors, but those services are arranged through and consented to by the minor’s parent or legal guardian (with limited exceptions under Colorado law for minors age 12 and older who may consent to mental health services).
Our Website is intended for use by adults. We do not knowingly collect personal information directly from children under the age of 13 through our Website without verifiable parental consent. If you believe a child under 13 has provided us with personal information through our Website, please contact us and we will take steps to delete the information.
11. Your Privacy Rights
11.1 Colorado Privacy Act (CPA)
If you are a Colorado resident, you have the following rights regarding your personal data under the Colorado Privacy Act:
- Right to access — You may request to know what personal information we have collected about you.
- Right to correct — You may request that we correct inaccurate personal information.
- Right to delete — You may request that we delete personal information we have collected about you, subject to certain legal exceptions (including our obligation to retain clinical records under state and federal law).
- Right to data portability — You may request a copy of your personal information in a portable format.
- Right to opt out — You may opt out of the processing of your personal data for purposes of targeted advertising or the sale of personal data. We do not sell personal data.
To exercise any of these rights, please contact us using the information in Section 14. We will respond within the timeframe required by law (typically 45 days).
11.2 Clinical Records
If you are a current or former client, your rights regarding your clinical records (PHI) are described in our separate Notice of Privacy Practices and are governed by HIPAA and Colorado law.
11.3 Marketing Communications
You may opt out of any marketing emails by clicking the “unsubscribe” link in the email or by contacting us directly. We will continue to send you administrative or appointment-related communications as needed. At times we will send e-newsletters and promotional announcements about additional service offerings — for example, therapy and coaching groups, e-courses, webinars, or informative content.
12. Data Retention
We retain your information for as long as necessary to fulfill the purposes described in this Policy and to comply with our legal, regulatory, and professional obligations.
- Website inquiry data is generally retained for up to two years after our last communication with you, unless you become a client.
- Client clinical records are retained in accordance with Colorado state law and applicable professional standards (typically a minimum of seven years from the date of last service for adult clients, and longer for minor clients).
- Financial and billing records are retained as required by applicable tax and accounting laws.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our services, or legal requirements. When we make material changes, we will update the “Last Updated” date at the top of this Policy and post the revised Policy on our Website. We encourage you to review this Policy periodically.
14. Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have a privacy concern, please contact us:
Potential Within Reach, Inc. Attn: Aaron Smith, LCSW — Privacy Officer 8751 E. Hampden Ave., Suite B9 Denver, CO 80231
Phone: (303) 731-6765 Email: aaron@potentialwithinreach.com