Seasons Alzheimer’s Care & Assisted Living (“Seasons”, “we”, “us”) respects your privacy. This policy explains what information this website collects and how it is used.
Information you send us
When you submit a contact, tour-scheduling, family-guide or career form, we collect the details you provide (such as your name, email address, telephone number and message). This information is stored securely in our website’s private enquiry system and emailed to our office staff so we can respond to you. We use it only to answer your enquiry and coordinate care or employment conversations you have requested. We never sell personal information.
Information collected automatically
We use a cookie to remember your cookie-consent choice. Google Analytics runs only if you choose to allow analytics in our cookie notice; it then collects standard, aggregated usage statistics. With the same consent, we may collect anonymous page-speed measurements to keep the site fast. If you decline, these tools stay off. Our forms are protected by Cloudflare Turnstile, which processes technical signals to block automated spam.
We count clicks on our phone-number and email links to understand which pages help families reach us; these counts contain no personal details.
Health information
This website is informational and does not collect medical records. Any care-related details you choose to share in a message are treated confidentially and used only to respond to you.
Sharing
Information is shared only with the service providers that operate this website and our email on our behalf, and with our own staff. We do not sell or rent personal information, and we do not use third-party advertising networks on this site.
Your choices
You may decline analytics in the cookie notice at any time, and you may ask us to update or delete the enquiry details you have sent us.
Google API Data and Data Protection
Seasons Alzheimer’s Care operates an internal reporting application on this website called Seasons Alzheimer’s Care Reporting. It connects to Google services belonging to Seasons Alzheimer’s Care so that authorised administrators can see how this website is performing. It is used only by authorised Seasons staff, it is never shown to website visitors, and signing in to Google is never required to use this website or to contact us.
What Google data we access
- Google Analytics 4 — read only (
https://www.googleapis.com/auth/analytics.readonly). Aggregate reporting for our own Analytics property: counts of users, sessions, engaged sessions, engagement rate, views, average engagement time and events, broken down by channel group, source and medium, landing page, page path and title, device category, country/region/city, and event name. We cannot edit the Analytics property, its data streams, tracking configuration, event definitions, audiences or users. - Google Search Console — read only (
https://www.googleapis.com/auth/webmasters.readonly). Aggregate search performance for this website: clicks, impressions, click-through rate, average position, and the pages and queries these relate to. We do not change any Search Console property or setting. - Google Business Profile (
https://www.googleapis.com/auth/business.manage, a separate authorisation). Limited to Seasons Alzheimer’s Care’s own business account and its own locations, so we can show our own location details and genuine customer reviews. We do not manage other businesses, change ownership, publish posts, run advertising, or reply to reviews automatically.
We never receive or request a Google account password. We do not access Gmail, Google Drive, contacts, calendars or Google Ads, and we do not access any Google account belonging to a website visitor.
Why we access it
Solely to operate the reporting features an authorised administrator has chosen to use: to display traffic, acquisition, engagement, landing-page, content, device, aggregate-geography and event reports inside the protected administration area; to compare a selected period with the preceding period; to export those results; and to include aggregate figures in our authorised weekly and monthly website-performance reports.
What we store
- Authorisation credentials. The OAuth refresh and access tokens that permit this read-only access are stored on our own hosting account.
- Aggregate reporting figures. Daily aggregate rows (for example sessions and clicks by day and channel) are stored in this website’s database so reports can quote consistent figures.
- Short-lived response cache. Analytics API responses are cached for 15 minutes so that ordinary page views do not repeatedly call Google.
- Generated reports. The weekly and monthly report files we produce are written to a private, non-public folder on the server.
We do not store user-level identifiers, individual event records, advertising identifiers, or any personal data about website visitors obtained from Google.
How we protect this data
- Encryption in transit. All communication with Google’s APIs uses HTTPS/TLS, and the administration screens and the OAuth callback for this website are served over HTTPS.
- Encryption at rest for credentials. The stored Google authorisation credentials are encrypted in our database using AES-256-GCM authenticated encryption. The encryption key is derived from a secret held in a protected server configuration file outside the database, so a copy of the database alone does not yield a usable credential.
- Credentials are never exposed. Tokens and client secrets are never displayed in any administration screen, never written into reports, exports, downloads or logs, and never placed in a web address. Diagnostic screens deliberately report the API operation performed, never the credential used. Credentials are held in non-autoloaded storage so they are not loaded into ordinary page requests.
- Restricted access. Every reporting screen requires an authenticated WordPress administrator with the appropriate capability. Each action is capability-checked and protected by a one-time security token (nonce), and no action that changes data can be triggered by a link alone.
- Data minimisation. We request read-only permissions only, and retrieve only the aggregate dimensions and metrics needed for the reports described above.
- Protected report storage. Generated report files are stored in a private directory that is not publicly accessible and returns an access-denied response to anyone on the internet.
- Audit logging. Administrative actions affecting this integration are recorded in an internal activity log that records the action taken, never the Google data or the credential.
- Monitoring and backups. Automated health checks verify that the integration is functioning, that credentials remain encrypted, and that no credential has leaked into diagnostic output. Server backups are held by our hosting provider under their access controls.
How long we keep it
- Access tokens are short-lived, expire approximately one hour after issue, and are replaced automatically.
- Refresh tokens are retained only while the connection remains in place, and are deleted as soon as the integration is disconnected.
- Cached API responses are retained for 15 minutes and can be cleared immediately at any time.
- Aggregate reporting rows are retained so that periods can be compared year on year. They do not expire automatically; an administrator can delete all of them at any time using the control described below.
- Generated report files are retained in private storage, and any download link we issue for one stops working after 90 days.
Sharing
We do not sell Google user data. We do not transfer it to data brokers. We do not use it for advertising or for personalised advertising, and we do not use it for any credit, lending or insurance decision. We do not use it to train artificial-intelligence or machine-learning models. We do not share it with anyone except the service providers strictly necessary to operate this website — principally our hosting provider — who are bound by confidentiality and security obligations and may not use the data for their own purposes. We may also disclose data where we are legally required to do so.
Limited Use
Seasons Alzheimer’s Care Reporting’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not allow humans to read this data except where it is necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymised.
Your controls
- Disconnect reporting from this website. An administrator can disconnect at any time from the website’s Data Sources screen, which deletes the stored credentials from this website. This is a local action and does not by itself withdraw the permission recorded in the Google Account.
- Delete imported Google reporting data. A separate control permanently deletes the stored aggregate reporting rows. It states what will be removed and requires explicit confirmation.
- Delete cached Google API data. A separate control clears every cached API response immediately.
- Withdraw access at Google. The owner of the Google account can withdraw this application’s access independently and at any time at Google Account → Third-party apps & services. Withdrawing access stops all further reading of Google data.
- Ask us. To request deletion of Google-derived reporting data we hold, or to ask any question about this section, contact getinfo@seasonsalzcare.com. We may retain limited records where we are required to for legal or security reasons.
If something goes wrong
Access to this integration is restricted to authorised administrators. If we suspect unauthorised access to Google data or to the credentials that permit it, we investigate promptly, revoke and replace the affected credentials, and notify affected parties and the relevant authorities where we are legally required to do so.
Job Applicants
If you apply for a role using the job application form at /career/, we collect the details you enter and the documents you attach.
What we collect and why
Your name, email address, phone number, current city and state, preferred work location, availability and shift preferences, a summary of your relevant experience, any licence or certification details you choose to give, your answers to role-specific questions, your résumé, and an optional cover letter. We collect this only to consider your application for employment.
We do not ask for, and you should not send, a Social Security number, date of birth, banking or payment details, passwords, medical or disability information, or immigration documents through the application form. If any further documentation is required, we will request it later in the process.
How it is protected
- The form is submitted over HTTPS/TLS.
- Résumés and cover letters are stored outside the public media library, in a directory that denies direct web access, disables directory listing and disables script execution. Requesting a stored file directly returns an access-denied response.
- Stored files are given randomised names, so a document cannot be found by guessing a URL.
- Documents can only be downloaded by a signed-in administrator through an authenticated handler protected by a capability check and a one-time token. Résumés are not attached to notification emails.
- Application records are held in a private database table. They are never published, never included in search results, feeds or sitemaps, and are not exposed through any public interface.
- Access is restricted to authorised Seasons administrators.
How long we keep it
Applications and their documents are retained for up to 24 months from submission and are then deleted automatically by a scheduled task, together with the uploaded files. An administrator can delete an individual application sooner at any time. This period is configurable, and the figure stated here reflects the setting currently in use.
Sharing
Applicant information is used only for recruitment by Seasons Alzheimer’s Care. It is not sold, not transferred to data brokers, not used for advertising, and not used to train artificial-intelligence models. It is not shared outside Seasons except with the service providers strictly necessary to operate this website — principally our hosting and email providers — or where we are legally required to disclose it.
Your choices
You may ask what we hold about you, ask for a correction, or withdraw your application at any time. Contact getinfo@seasonsalzcare.com and quote the application reference shown when you applied. We may retain limited records where we are required to for legal or security reasons.
Submitting an application does not guarantee an interview or employment. Seasons will never ask you for a password, payment or banking details as part of this application process.
Contact
Questions about this policy: getinfo@seasonsalzcare.com or (210) 584-4238, Seasons Alzheimer’s Care & Assisted Living, San Antonio, Texas.
Last updated: July 30, 2026.