Privacy Policy
Effective Date: 22nd of May 2026 Last Updated: 22nd of May 2026
Introduction
Kelsey Norton (“I,” “we,” “us,” “our,” or “the Practice”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at https://repairingroots.com/ (the “Website”) and interact with our services, including our contact form and other online tools.
Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our Website. By accessing and using this Website, you acknowledge that you have read, understood, and agree to be bound by all the terms of this Privacy Policy.
1. Information We Collect
A. Information You Provide Directly
Contact Form Information: When you use our contact form to inquire about therapy services or schedule a consultation, we collect:
- Your name
- Your email address
- Your phone number
- Any message or information you include in the form
- Date and time of submission
Email Communications: If you email us directly at [email protected], we collect the information contained in your email correspondence, including:
- Your name and contact information
- The content of your message
- Any attachments you may send
Phone Communications: When you call us at (757) 517-3916, we may record information about the call, including the date, time, and general nature of your inquiry.
Other Inquiries: Any other information you voluntarily provide to us through requests for information about our services, fees, insurance, or clinical supervision services.
B. Information Collected Automatically
Website Analytics: When you visit our Website, we automatically collect certain technical information through Google Analytics, including:
- Your Internet Protocol (IP) address
- Browser type and version
- Operating system
- Pages you visit and the time spent on each page
- Referring website or source
- Click patterns and navigation behavior
- General geographic location (based on IP address)
Cookies and Similar Technologies: We use cookies to enhance your experience and gather analytics data. These include:
- Essential Cookies: Required for basic website functionality and security
- Analytics Cookies: Used by Google Analytics to track website usage and user behavior
You can control cookies through your browser settings. Note that disabling cookies may limit website functionality.
Device Information: We may collect information about the device you use to access our Website, including device type, model, and operating system.
2. How We Use Your Information
We use the information we collect for the following purposes:
A. Providing Services
- Responding to your inquiries and contact form submissions
- Scheduling therapy consultations
- Communicating with you about your appointment
- Providing information about our therapy services, fees, and insurance options
- Responding to requests for clinical supervision information
B. Service Improvement
- Analyzing Website traffic and user behavior through Google Analytics
- Understanding how visitors interact with our Website
- Identifying technical issues and troubleshooting problems
- Improving the design, functionality, and content of our Website
- Enhancing user experience
C. Communication
- Sending you appointment confirmations and reminders
- Following up on inquiries you’ve submitted
- Providing information you’ve requested about our services
- Notifying you of changes to our policies or Website
D. Legal and Security Purposes
- Complying with applicable laws and regulations
- Maintaining records as required by Virginia and Maine licensing boards
- Protecting against fraud and unauthorized access
- Ensuring the security of our Website and systems
- Defending our legal rights if necessary
3. Information We Do NOT Collect
This is important: Our Website contact form is designed for initial inquiries and scheduling only. We do NOT use this form to collect:
- Mental health history or clinical information
- Medical diagnoses or sensitive health information
- Insurance details beyond the type of insurance
- Payment information (payment is handled separately through secure means)
Protected Health Information (PHI): Any sensitive health or clinical information shared with Kelsey Norton during actual therapy sessions is governed by HIPAA regulations and our separate Notice of Privacy Practices provided during your first session—not this Website Privacy Policy. We do not transmit clinical information through our contact form or unsecured email.
4. How We Share Your Information
A. We Do NOT Share Your Information For:
- Marketing or promotional purposes
- Sale to third parties
- Targeted advertising
- Any purpose unrelated to providing our services
B. We Share Information With:
Service Providers (Limited):
- Headway: If you schedule therapy, we use Headway.com for secure clinical record management. Your clinical information is stored according to HIPAA standards. You will provide consent to use Headway during your first session.
- Contact Form Provider: We may use a secure contact form service to process and store initial contact inquiries
- Google Analytics: Non-identifiable, aggregated website usage data only
Legal Requirements:
- Law enforcement, if required by court order, subpoena, or applicable law
- Virginia and Maine licensing boards, if required for regulatory compliance
- As necessary to protect the safety of you or others
Business Transfers:
- If the Practice is sold, merged, or transferred, your information may be transferred as part of that transaction. You will be notified of any such change.
5. Third-Party Services
Google Analytics
Our Website uses Google Analytics to analyze website traffic and user behavior. Google Analytics is a web analytics service provided by Google, Inc. Google uses cookies and similar technologies to collect and analyze information about Website usage.
Data Collected by Google Analytics:
- IP address (anonymized)
- Browser and device information
- Pages visited and time spent
- Referring sources
- Geographic location (general)
Google’s Privacy Practices: Google Analytics data is processed according to Google’s privacy policy. You can learn more at https://policies.google.com/privacy.
Opt-Out: You can opt out of Google Analytics tracking using the Google Analytics Opt-Out Browser Add-on: https://tools.google.com/dlpage/gaoptout
6. Data Security
We implement reasonable physical, technical, and organizational measures to protect your information from unauthorized access, alteration, disclosure, or destruction. These measures include:
- Secure Sockets Layer (SSL) encryption for data in transit
- Password-protected access to our systems
- Regular security assessments and updates
- Limited access to personal information (staff only on a need-to-know basis)
- Secure disposal of records
Important Limitation: No method of transmission over the internet or electronic storage is completely secure. While we implement appropriate security measures, we cannot guarantee absolute security. You acknowledge that any transmission of your information is at your own risk.
7. Data Retention
We retain your information for as long as necessary to provide our services and comply with legal obligations:
- Contact Form Inquiries: Retained for 3 years or as required by Virginia/Maine licensing regulations
- Clinical Records (if you become a client): Retained according to HIPAA requirements (typically 6 years after last treatment date)
- Website Analytics: Automatically aggregated and anonymized by Google Analytics
If you request deletion of your information, we will comply within 30 days unless legal requirements require retention.
8. Your Privacy Rights
Depending on your location, you may have certain rights regarding your information:
California Residents (CCPA/CPRA)
You have the right to:
- Request access to the personal data we hold about you
- Request deletion of your personal data
- Opt out of any sale or sharing of personal data (we do not sell or share your data)
- Non-discrimination for exercising your rights
Virginia, Colorado, Connecticut, and Utah Residents
You may have rights to access, correct, delete, and opt out of certain processing of your personal data.
European Union Residents (GDPR)
If you access our Website from the EU, you have rights including:
- Right to access your data
- Right to rectification (correction)
- Right to erasure (“right to be forgotten”)
- Right to restrict processing
- Right to data portability
- Right to withdraw consent
How to Exercise Your Rights
To exercise any of these rights, please contact us at:
Email: [email protected] Phone: (757) 517-3916 Mailing Address: 4410E East Claiborne Square, Suite 305, Hampton, VA 23666
Please include “Privacy Rights Request” in the subject line. We will respond to valid requests within 30 days.
9. Children’s Privacy
Our Website and services are not intended for children under the age of 18. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected information from a minor without appropriate parental consent, we will delete such information promptly.
Parents or guardians who believe their child has provided information to us should contact us immediately at [email protected].
10. HIPAA Compliance Notice
Important: This Privacy Policy applies to our Website only. If you become a client and receive therapy services from Kelsey Norton:
- Your clinical records and Protected Health Information (PHI) are governed by HIPAA regulations and our separate Notice of Privacy Practices
- You will receive a detailed Notice of Privacy Practices at your first appointment
- Clinical communications may occur through secure channels (such as TherapyNotes) rather than unsecured email
- We maintain HIPAA-compliant business associate agreements with service providers
- Your rights under HIPAA include access to your records, requesting amendments, and receiving an accounting of disclosures
For questions about HIPAA privacy practices, please contact Kelsey Norton directly.
11. Links to Third-Party Websites
Our Website may contain links to third-party websites, including:
- Psychology Today directory profile
- Headway portal
- Other resources and referral sites
Important: This Privacy Policy applies only to our Website. We are not responsible for the privacy practices of third-party websites. We encourage you to review the privacy policies of any linked sites before providing your information.
12. Contact Form and Unsecured Communication
Warning About Email Security: Please note that email, while convenient, is not a fully secure form of communication. Avoid including sensitive health information, diagnoses, medications, or insurance details in your initial contact.
For confidential clinical information, please discuss secure communication methods during your first appointment.
13. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- Changes in our practices
- Updates to applicable laws and regulations
- Changes to our Website or services
- Other operational changes
We will notify you of material changes by:
- Posting the updated Privacy Policy on our Website
- Updating the “Last Updated” date at the top of this policy
- Sending you an email notification if we collect your email address
Your continued use of the Website following notification of changes constitutes your acceptance of the updated Privacy Policy.
14. Contact Information
If you have questions about this Privacy Policy, our privacy practices, or wish to exercise your privacy rights, please contact:
Kelsey Norton, LPC-S, CCTP II
Email: [email protected]
Phone: (757) 517-3916
Mailing Address: 4410E East Claiborne Square, Suite 305 Hampton, VA 23666
Response Time: We will respond to privacy inquiries within 10 business days.
15. Your Consent
By using our Website, you consent to our Privacy Policy. If you do not agree with this policy, please do not use our Website.
Additional Information
Virginia Therapist Licensing
Kelsey Norton is licensed as a Licensed Professional Counselor (LPC-S, CCTP II) by the State of Virginia. License Number: 0701012811
For questions about licensing or to verify credentials, you can contact the Virginia Board of Counseling at http://www.dhp.virginia.gov.
Regulatory Compliance
This Privacy Policy is designed to comply with:
- Health Insurance Portability and Accountability Act (HIPAA)
- Virginia Privacy Laws
- California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
- General Data Protection Regulation (GDPR)
- Other applicable state and federal privacy laws
End of Privacy Policy
This Privacy Policy was last updated on 22nd of May 2026. Please check back periodically for updates.
