Email practices
We send transactional email only
Every message EMR Chart sends is triggered by a specific action taken by a specific person inside the product. We do not operate marketing lists, and we do not send bulk email.
Messages we send
| Subject | What triggers it | Contents |
|---|---|---|
| Verify your EMR Chart email | A person registers a new practice workspace at emrchart.com | Single-use verification link, expires in 1 hour |
| Reset your EMR Chart password | An existing user requests a password reset for their own account | Single-use reset link, expires in 30 minutes |
| You are invited to EMR Chart | An administrator of a practice invites a staff member | Single-use activation link, expires in 72 hours |
| Activate your EMR Chart portal | Clinic staff issue portal access to a patient of that practice | Single-use activation link, expires in 72 hours, no clinical content |
Message bodies contain a product name, a short instruction, and a single link to emrchart.com. They never contain patient names, dates of birth, diagnoses, appointment details, or attachments.
What we never send
- Newsletters, promotions, offers, or product announcements
- Bulk campaigns of any kind
- Mail to purchased, rented, scraped, or imported contact lists
- Mail to addresses that have bounced or filed a complaint
- Clinical or appointment content in the message body
How recipients come to us
A recipient can only receive mail from EMR Chart in one of three ways: they registered a workspace themselves and asked to verify their own address, an administrator at their own practice invited them as a staff member, or clinic staff issued portal access to a patient of that practice. Address entry is a deliberate act by an authenticated person with an existing relationship to the recipient.
Sender identity and authentication
- All mail is sent from noreply@emrchart.com on the verified domain emrchart.com
- SPF, DKIM, and a DMARC policy are published for the domain
- Aggregate DMARC reports are monitored so we can detect any attempt to send mail as our domain
- The sending credential is restricted to a single From address and cannot be used to send as anyone else
Bounce, complaint, and suppression handling
Delivery events are processed automatically, in real time, before we attempt any further mail to an address:
- A permanent bounce or a complaint immediately adds the recipient to our suppression list. Suppressed addresses are excluded from every future send.
- Suppression is stored as a one-way hash of the address, so the list itself does not expose recipient identities.
- We do not automatically retry a message after a bounce. A new invitation must be issued deliberately by an administrator.
- Transient bounces are recorded for monitoring and do not trigger automated re-sending.
- Sender reputation metrics, including bounce and complaint rates, are reviewed as part of routine operations.
How to stop receiving mail from us
Because these messages exist to protect account access, they have no marketing unsubscribe. To stop them entirely, ask the practice that invited you to deactivate your account, or write to us and we will add your address to the suppression list directly. Suppression takes effect immediately and applies to all future sends.
Reports of abuse, unexpected mail, or suspected spoofing of our domain can be sent to the address on our contact page. We respond to abuse reports as an operational priority.