
Effective Date: July 6, 2025 Last Updated: July 28, 2026
Triangle Health, its affiliates, and subsidiaries ("Triangle Health," "we," "our," or "us") values your privacy. This Privacy Policy ("Policy") explains how we collect, use, disclose, and handle personal data. It also explains the rights and choices you may have for that information.
In this Policy, "personal data" means the same thing as "personal information." Also, "including" means "including but not limited to."
Each numbered section below starts with a short summary marked "In short." These summaries are here to help you. They are not part of this Policy's terms. If a summary and the full section differ, the full section controls.
California Residents. If you live in California, please see the California Notice at Collection section below. It covers the types of personal data we collect and disclose. It also covers your rights under California privacy laws.
Consumer Health Data Privacy Notice. If you live in Washington or Nevada, please see our Consumer Health Data Privacy Notice. It has more detail on how we handle consumer health data under those states' laws.
For more about your privacy choices, please see the Your Privacy Choices section below.
By using our Services (defined below), you agree that your personal data will be handled as this Policy describes. Your use of our Services, and any dispute over privacy, is subject to this Policy. It is also subject to our Terms and Conditions at https://app.trianglehealth.com/terms. This includes the terms that limit damages and govern how disputes are resolved.
How You Agree. When you create an account, we ask you to check a box saying you agree to this Policy and our Terms and Conditions. Links to both documents appear next to that box, so you can read them first. We keep a record of your agreement. That record includes which version of each document you agreed to, and when. If we make material changes to this Policy, we may ask you to agree again.
2. Personal Information Collected
3. How We May Use Personal Information
4. Disclosures of Personal Information
5. Cookies and Other Tracking Mechanisms
7. External Links and Features
10. Keeping and Deleting Your Data
11. California Notice at Collection
In short: This Policy covers how we handle personal data across our website, app, and services. If HIPAA applies through your healthcare provider, that law and our agreement with the provider control instead. Genetic and family history data can also reveal things about your relatives, so think of them when you share it.
Except as described in the When HIPAA Applies and Additional Notices paragraphs below, this Policy applies to how we handle personal data online and offline. It applies to the groups below.
Visitors to our website where this Policy is posted, including https://app.trianglehealth.com/ (the "Site").
People who sign up for, or create, an account with us (each, a "User").
People who subscribe to our news, information, and marketing messages and materials.
Current, former, and prospective business partners and service providers.
People who communicate, interact, or engage with us, or with the services offered through our Site or other online services.
Together, our Site and these online services are called the "Services" in this Policy.
You may give us personal data about someone other than yourself, such as a patient or family member. If so, you are responsible for following all privacy and data protection laws that apply. Do this before you give us that data. This includes getting consent, if the law requires it.
Data That Can Affect Your Relatives. Some health data is about more than one person. Your genetic data can reveal details about your blood relatives, because families share DNA. Your family health history describes your relatives and their health. When you share this kind of data with us, or direct us to share it with others, that sharing may affect your relatives too — even though they did not share anything themselves. Please keep them in mind when you decide what to share and with whom.
When HIPAA Applies. We may act as a "business associate" to your healthcare provider. If we do, this Policy does not govern our use and disclosure of Protected Health Information. Instead, it is governed by the Health Insurance Portability and Accountability Act (HIPAA). It is also governed by our Business Associate Agreement with that provider.
Additional Notices. We may give you added or supplemental privacy notices. This depends on how you interact or engage with us. If those notices conflict with this Policy, those notices control. For example, this Policy does not apply to personal data about job applicants and candidates for jobs with us. It also does not apply to our employees or contractors.
In short: We collect data you give us, such as your name, contact details, and health history. We also get some data from other companies, and some automatically, such as device and usage data.
We collect personal data directly from you and from third party sources. We also collect it automatically through your use of the Services. Where the law allows, we may combine it with personal data from public or third party sources. What we collect depends on how you use our Services and interact with us.
Personal Data Collected Directly. We may collect the personal data below directly from you:
Communications and Interactions. This applies when you communicate or interact with us or our Services. Such as when you fill out forms on our Site, engage with our social media pages, or submit content to the Services. It also applies when you engage with our sponsored content. We may collect your name, email address, phone number, or other similar identifiers. We may also collect your message, the nature of your question, and any other details you choose to give us.
Account and Profile Details. This applies when you sign in or create an account for our Services. We may collect your name, email address, phone number, and username. We may also collect any other details used to access your account. The same applies to details you submit through your account.
Health Details. This applies when you share details about your medical history. Please see our Consumer Health Data Privacy Notice for how we collect and use consumer health data.
Purchases and Payments. This applies when you make a purchase or payment through our Services. We may collect details such as payment type, payment card details, billing information, and shipping address. We may also collect purchase details, such as the SKUs and products bought. We may collect any other financial or commercial information needed to enable our Services.
Chat Function. We may collect what you submit through the chat features in our Services. We may record your communications with us for the Services. So may the service providers who run these features for us. These service providers may also keep records of the details given to us.
Marketing Sign-up Details. If you agree to get marketing messages from us, we may collect your contact details and choices. If relevant, we may also collect details about your account and profile. This includes the Services and features you use.
Responses and Feedback. You may take part in surveys, questionnaires, or research we run. Examples: market research, or user satisfaction. If so, we may collect your responses and feedback, and any other details you choose to give us.
Preferences and Other Requests. We may collect details about your choices. This includes how you want us to contact you. It also includes your choices for our Services, and any other choices or requests you give us.
Business Development Details. We may collect personal data to assess and pursue business opportunities. This can cover current, former, and prospective business partners, vendors, and service providers. It includes contact details and other similar identifiers, company and professional details, and communication records.
Personal Data Collected from Third Parties. We may collect and receive personal data from third party sources. Such as business partners, family members and other authorized representatives, and service providers or others who work on our behalf. We may collect the items below from third party sources:
Sign-in Authentication Partners. You may register for or log into the Services using another service. If you do, that service sends us your details to create your account. For example, we may use Google Sign-in to verify users. Our use of data received from Google APIs follows Google's privacy and data use policies.
Lead and Prospect Details. We may receive lead details from third parties. These cover prospective customers who may want our Services. We may also engage third parties to enhance or update our customer records. For example, we may receive certain personal data from data analytics and marketing providers. We use it for marketing and ads, and to reach new customers.
Referral Details. We may let users invite friends or refer other users to our Services. If so, we may collect certain personal data about the people referred.
Personal Data Collected Automatically. We may collect or derive personal data automatically when you use our Services. We may do this through cookies, pixel tags, and other similar tools. This may include:
Device and Browsing Details. When you use our Services, we may collect details about your device and browser. Such as browser type, domain name, page views, access times, date/time stamps, operating system, language, and device type. More examples include unique ID, Internet service provider, referring and exiting URLs, and clickstream data.
Activities and Usage. We may also collect details about your activity in the Services. Such as links clicked, searches, features used, and items viewed. Also time spent in the Services, and your interactions with us there.
Location Details. We may also collect or derive general location details, such as through your IP address.
For more on our use of cookies and similar tools, please see the Cookies and Other Tracking Mechanisms section below.
In short: We use your data to run and improve our Services, support you, and send you updates. Some features send your data to AI providers. They do not keep it or train on it. We do not share health data with third parties for their own ads.
We may collect, use, disclose, and handle personal data for these purposes.
Services and Support. To enable our Services and run our day-to-day work. This includes talking with you about your use of the Services. It also includes troubleshooting, technical support, answering your questions, and fulfilling your requests. Some of our Services may be provided using our artificial intelligence (AI) models and tools.
Account Creation and Management. To let you create and manage an account. This includes letting you create a profile and set preferences.
Analytics and Improvement. To better understand how users access and use the Services. Also for other research and analysis. Such as to assess, develop, and improve our Services and business, and for internal quality control and training.
Communication. To answer your questions and send you requested materials and newsletters. Also to send details about our Services and our offerings. We may also use it to send you service and account updates. Such as details about the Services, and changes to our terms and policies.
Customization and Personalization. To tailor content we may send or display on the Services. This includes offering location customization, and personalizing your experiences and offerings in other ways.
Marketing and Advertising. For marketing, ads, and promotions. For example, to send you promotional details about our Services. This includes news about new offerings, and any other information you sign up to receive. We do not share any health-related or sensitive personal data with third parties for their own ads or marketing.
Research and Surveys. To run surveys and questionnaires, such as for market research or user satisfaction.
Insight Development and Data Enhancement. To gain insights into how our Services are used. To do this, we may combine personal data collected through the Services with other data. The other data comes from what we or third parties collect in other contexts.
Security and Protection of Rights. To protect the Services and our business. Also to protect our rights or those of our stakeholders. To prevent and detect fraud, unauthorized activity and access, and other misuse. Also where we believe it is needed to investigate, prevent, or take action. Such as illegal activity or suspected fraud. Also threats to the safety or legal rights of any person or third party. Also violations of our Terms of Use.
Compliance and Legal Process. To comply with legal or regulatory duties that apply to us. This includes acting as part of a court case. It also includes responding to a subpoena, warrant, court order, or other legal process. It also includes an investigation or request from law enforcement or a government authority.
Auditing, Reporting, and Other Internal Operations. To conduct financial, tax, and accounting audits. Also to audit and assess our operations. This includes our privacy, security, and financial controls, as well as risk and compliance purposes. We may also use personal data to keep proper business records and enforce our policies and procedures.
General Business and Operational Support. To assess and carry out mergers, acquisitions, reorganizations, and bankruptcies. Also other business deals, such as financings. Also to administer our business, accounting, auditing, compliance, recordkeeping, and legal functions.
AI Features. We use artificial intelligence (AI) tools to enhance, improve, and provide our Services. To deliver AI-powered features, the app sends the data you submit for processing. This includes health data, documents, and messages. It goes to these third party AI service providers:
These services do not keep your data. They do not use your data to train their models. These providers process your data solely to deliver features in the Services. They operate under zero data retention agreements. Each third party AI service provider signs a contract with us. Under it, they must protect data at standards equal to or stronger than those in this Policy. Each is also subject to our vendor management processes.
We may use AI tools for our legitimate business purposes. We use them to process the data you submit, as this Policy describes. The goal is to improve how efficient and accurate our Services are. The data we process through our AI systems gets the same protection and security measures discussed in this Policy. We will update this Policy if we change the third party AI service providers we use.
In short: We share data with vendors who work for us, and with AI providers under strict no-retention deals. We may also share data when the law requires it, or if our company is sold.
We may disclose the personal data we collect for the purposes above, and as set out below.
Third Party AI Service Providers. We disclose personal data to third party AI service providers to power AI features in the Services. This includes health data, documents, and messages you submit. These providers include Google Gemini, Azure OpenAI, OpenAI, LandingAI, Anthropic Claude, Groq, and Perplexity. These providers process data under zero data retention agreements. They do not keep your personal data after processing. They do not use your data to train their models.
Affiliates and Subsidiaries. We may disclose the personal data we collect to our affiliates or subsidiaries. They will use and disclose it as this Policy describes.
Business Partners. We may collect and process data on behalf of a business client. If so, we will disclose it to that client, and share it as that client directs.
Third Party Marketing and Analytics Providers. We may disclose personal data to third party platforms and providers, or make it available to them. We use them to provide certain features or parts of the Services. We also use them as needed to respond to your requests. We may also make personal data available to third parties. These support our marketing, analytics, ads, and campaign management. We do not share any health-related or sensitive personal data with third parties for their own ads or marketing.
Compliance and Legal Obligations. We may disclose personal data to third parties to meet our legal and compliance duties. We may also do so to respond to legal process. For example, we may disclose data in response to subpoenas and court orders. The same applies to other lawful requests by regulators and law enforcement. This includes responding to national security or law enforcement disclosure requirements. Recipients may include regulators, government entities, and law enforcement, as required by law or legal process. It may also include certain disclosures the law requires us to make. Examples include the names of sweepstakes and contest winners.
Security and Protection of Rights. We may disclose personal data where we believe it is needed to protect the Services and our rights and property. The same applies to protecting the rights, property, and safety of others. For example, we may disclose personal data to prevent, detect, investigate, and respond to fraud. The same applies to unauthorized activity and access, illegal activity, and misuse of the Services. We may disclose it to address potential threats to any person or third party. This covers threats to health, safety, or legal rights. We may also disclose it to enforce our Terms of Use. The same applies to detecting, investigating, and acting on violations of them. We may also disclose information, including personal data, related to lawsuits. The same applies to other legal claims or proceedings that involve us. The same applies to our internal accounting, auditing, compliance, recordkeeping, and legal functions.
In Support of Business Transfers. We or our affiliates may be, or may become, acquired by, merged with, or invested in by another company. Our assets may also be, or may become, transferred to another company. This may happen as part of a bankruptcy or insolvency proceeding, or otherwise. In any of these cases, we may transfer the data we collected from you to the other company. We may also share certain personal data as needed before such a deal closes. The same applies to corporate deals such as financings or restructurings. We may share it with lenders, auditors, and third party advisors. This includes attorneys and consultants. We do this as part of due diligence, or as needed to plan for a deal.
Aggregate and Deidentified Information. Despite anything else in this Policy, we may use, disclose, and otherwise process aggregate and deidentified data with third parties. This is information related to our business and the Services. We may do so for quality control, analytics, research, development, and other purposes. Deidentified data has your name and other identifying details removed. It is no longer linked to you. You should know that deidentified data still carries a small risk. Someone could try to combine it with other data to figure out who it describes. This is called reidentification. We do not reidentify deidentified data, except as the law allows. We also require, by contract, that vendors and partners who receive it not try to reidentify it.
Other Disclosures. We may disclose personal data in other ways not described above. If so, we will notify you and, if needed, get your consent.
In short: We and our partners use cookies and similar tools to run the site, measure use, and show ads. We do not use your health information for ads or tracking.
We use cookies, pixels, local storage objects, log files, APIs, and other tools. They automatically collect browsing, activity, device, and similar data within our Services. They also help us target advertising and content. We may also engage third parties or service providers to do the same. For example, we use this data to analyze and understand how visitors interact with our Services. We use it to find and fix bugs and errors in our Services. We use it to assess, secure, protect, optimize, and improve how our Services perform. We use it to conduct analytics and limited marketing related to non-health data. We also use it to personalize content in our Services. We do not use patient health information for marketing, ads, or any cookie-based tracking. This includes diagnoses, treatments, and chat content. You can manage your choices for cookies, targeted ads, and other tracking tools. To do so, please see Your Privacy Choices below.
Cookies. Cookies are letter-and-number IDs. We transfer them to your device's hard drive through your web browser for record keeping. Some cookies make it easier for you to get around our Services. Others enable a faster log-in process. Some support the security and performance of the Services. Others let us track activity and usage data within the Service.
Pixel Tags. Pixel tags (sometimes called web beacons or clear GIFs) are tiny graphics with a unique ID. They are similar in function to cookies. Cookies are stored locally on your device. Pixel tags, by contrast, are embedded invisibly within web pages and online content. In our Services, we may use them to track user activity and manage content. We may also compile usage statistics, among other things. We may also use them in HTML emails we send. They help us track email response rates. They show us when our emails are viewed, and whether they are forwarded.
Local Storage Objects. Local storage is a web storage tool. It lets us store data in your browser. That data stays even after the browser window is closed. Our web servers may use local storage to cache certain data. This makes pages and content load faster when you return to our sites. You can clear data stored in local storage through your browser. Please check your browser help menu for more details.
Third Party Analytics and Tools. We use third party tools, such as Google Analytics. Third party companies operate these tools. These companies may use cookies, pixels, and similar tools to collect usage data about our Services. They give us reports and metrics. These help us assess use of our Services. They also help us improve performance and user experience. To learn more about Google's privacy practices, please review the Google Privacy Policy at https://www.google.com/policies/privacy/partners/. You can also download the Google Analytics Opt-out Browser Add-on at https://tools.google.com/dlpage/gaoptout. It prevents your data from being used by Google Analytics.
Targeted Advertising. We work with third parties to personalize content and show ads within our Services. Such as ad networks, channel partners, mobile ad networks, analytics and measurement services, and others ("third party ad companies"). They also manage our ads on third party sites, mobile apps, and online services. We may share certain data with these third party ad companies. We and they may use cookies, pixel tags, and other tools. These collect usage and browsing data within our Services, as well as on third party sites, apps, and services. Such as IP address, location details, and device ID. Also cookie and ad IDs, other identifiers, and browsing data. We and these third party ad companies use this data to provide you more relevant ads and content. This happens within our Services and on third party sites and apps. We also use it to assess the success of such ads and content.
Cross-Device Tracking. We and our third party providers may use the data we collect. This covers data from our Services and from other third party sites and services. It helps us and these third parties identify other devices that you use (e.g., a mobile phone, tablet, or other computer).
In short: You can update your profile, opt out of marketing, manage push alerts, and control cookies and targeted ads. Anyone in the U.S. can also ask us for a copy of their data, free of charge.
We offer several ways for you to manage your privacy choices. You can also submit privacy requests about your personal data. Some of these choices are browser and device specific. This means you need to set the choice on each browser and device you use to access our Services. Also, you may delete or block cookies. If so, you may need to set these choices again. Do this for each browser and/or device you use to access our Services.
These options include:
Account and Profile Details. You can review and update some of the personal data we keep about you. To do so, log into your account and update your profile information directly within our Services.
Access and Copies of Your Data. You can see and download your health records in the app at any time. You can also ask us for a copy of the personal data we keep about you. This right applies to every User in the United States — not just California residents. To ask, email us at privacy@trianglehealth.com. We will verify your identity first. Then we will send you your copy free of charge.
Marketing Communications. We may send you marketing emails or similar messages from time to time, as allowed by law. You may opt out of these messages. To do so, follow the steps given in the message. If you opt out of marketing content, we may still send you messages about your account. The same applies to any services you asked for or received from us. Also, you can manage your contact choices in your account settings.
Push Notifications. You can manage the type of push notifications you receive from us. To do so, adjust your device settings, or modify the settings within our Services.
Cookie Settings. You can stop cookies from tracking your activity on our Site, or your visits across many sites. To do so, set your browser to block certain cookies, or to notify you when a cookie is set. You can also delete cookies. The "Help" portion of the toolbar on most browsers explains how. It explains how to block new cookies, how to get notified when you receive one, and how to delete cookies. If you disable cookies, you will still be able to browse the Site. But some features may not function.
Browser Signals/Do Not Track. Our Site currently does not respond to "Do Not Track" signals. You may, however, disable certain tracking as discussed in this section (e.g., by disabling cookies). You also may opt out of targeted ads. To do so, follow the instructions in the Industry Ad Choice Programs section below.
Industry Ad Choice Programs. Participating third party ad companies collect data about your visits to our Site. They also collect data about your visits to third party sites. They use it to display more relevant targeted ads to you. You can control how they use this information. If you are in the U.S., you can learn more, and opt out of targeted ads from participating third party ad networks, at http://aboutads.info/choices (Digital Advertising Alliance). Opting out of these ad networks does not opt you out of all ads. You may continue to receive generic or "contextual" ads on our Site. You may also keep getting targeted ads on other sites. These come from companies that do not take part in the above programs.
In short: We link to other companies' sites. Their privacy rules, not ours, apply there.
Our Service may contain links to third party sites or features. It may also provide certain third party connections or integrated services. This Policy does not govern any access to and use of such linked sites, features, or third party services. We are not responsible for the data practices of such third parties. This includes their collection, use, and disclosure of your personal data. You should review the privacy policies and terms of any third party. Do this before you go to those sites, or use those third party features or services.
In short: Our Services are for adults. A parent or guardian may add a child's health data where the law allows.
Our Services are not designed for children. We do not knowingly collect personal data from children under 18. However, a User may use our Services to give health details about a minor child. This must be permitted by law and done with appropriate authorization. You may be a parent or legal guardian who believes we collected your child's data in violation of the law. If so, please contact us using the contact details in the Contact Us section below.
In short: We encrypt your data in transit and in storage, and limit who can access it. No system is perfectly secure. If a breach affects your health data, we will tell you, as the law requires.
We have put safeguards in place. They are intended to protect personal data from loss, misuse, unauthorized access, disclosure, alteration, or destruction. These safeguards include the following.
Encryption in transit. We encrypt your data while it travels between your device and our systems.
Encryption in storage. We also encrypt your data where it is stored. This includes our databases and the documents you upload.
Access controls. We limit who can see your data. Our systems use roles and permissions. People and staff can only see the data they need for their role.
Sign-in verification. When you sign in, we confirm it is really you. For example, we may send a one-time code to your email.
Please be aware that despite our efforts, no data security measures can guarantee security.
If There Is a Security Breach. Despite these safeguards, a breach could still happen. Suppose your unsecured health data in our Services is accessed, used, or disclosed without your permission. If that happens, we will notify you. We follow the FTC Health Breach Notification Rule (16 C.F.R. Part 318). We also follow other federal and state breach laws that apply. We will notify you without unreasonable delay, and no later than 60 days after we discover the breach. Our notice will describe what happened and what data was involved. It will describe what we are doing in response. It will also describe steps you can take to protect yourself, and how to contact us with questions. When the law requires, we will also notify the Federal Trade Commission and other authorities. For breaches that affect many people, the law may also require us to notify the media.
In short: You can disconnect a data source, like Medicare, at any time. We then stop collecting from it. You can also delete your data or your whole account. If your account sits unused for 18 months, we warn you. After 24 months, we may close it and delete its data.
Disconnecting a Data Source. You may connect outside data sources to our Services. Examples: your doctor's office, your health plan, or Medicare through its Blue Button service. You can disconnect (revoke) any source at any time in your account settings. When you disconnect a source, we stop collecting new data from it right away. Disconnecting is not the same as deleting. The data we already collected stays in your account, so you keep your records. If you want that data gone too, you can delete it in the app. You can also ask us at privacy@trianglehealth.com.
Deleting Your Data or Account. You can ask us to delete your personal data at any time. You can also delete your whole account. When you delete your account, we delete your personal data within 30 days. Two limits apply. First, we may keep data the law requires us to keep, such as tax, audit, and medical record retention obligations. We keep that data only as long as the law requires. Second, we may keep data in deidentified form, as this Policy describes. Copies in secure backups may take a short added time to clear from our systems.
Inactive (Dormant) Accounts. If you do not use your account for 18 months, we will email you a warning. If you do not sign in within 6 months after that warning, we may close your account. When we close a dormant account, we delete its personal data on the same schedule as a deleted account. To keep your account active, just sign in.
In short: California residents have extra rights. These include seeing, fixing, or deleting their data, and opting out of "sales" or "sharing." Email privacy@trianglehealth.com to use them.
This section of the Policy provides added detail for California residents. It describes our practices under the California Consumer Privacy Act of 2018 and its regulations (the "CCPA"). This law was amended by the California Privacy Rights Act of 2020. We may provide you with other privacy notices. This depends on how you interact or engage with us. Those notices give added detail about our privacy practices.
This section applies to "personal information" as defined in the CCPA. This is true whether it is collected online or offline. It does not apply to our handling of personal data that is exempt under the CCPA.
Categories of Personal Data Collected and Disclosed. Depending on how you use the Services, we may collect the following categories of personal data. We have also collected these categories in the prior 12 months.
| Categories of Personal Information Collected | Categories of Third Party Disclosures |
|---|---|
| Identifiers. Such as name, alias, email, phone number, and username. Also unique personal identifier, online identifier, IP address, or other similar identifiers. | - Advisors and agents. - Advertising networks. - Data analytics providers. - Internet service providers, operating systems, and platforms. - Parties you Authorize, Access or Authenticate. |
| Other personal information. Such as gender and date of birth. | - Internet service providers, operating systems, and platforms. - Parties you Authorize, Access or Authenticate. |
| Customer Records. Such as account information and customer records that contain personal information. Examples: name, account name, other characteristics or descriptions, email, address, and phone number. Also other contact information, communications preferences, billing and payment information, and other information you provide in order to use our Services. | - Advisors and agents. - Data analytics providers. - Internet service providers, operating systems, and platforms. - Parties you Authorize, Access or Authenticate. |
| Commercial Information. Such as records of products or services purchased, obtained, or considered. Also other purchasing or use histories or tendencies. | - Advisors and agents. - Data analytics providers. - Internet service providers, operating systems, and platforms. - Parties you Authorize, Access or Authenticate. |
| Internet and electronic network activity information. Such as browsing history, clickstream data, and search history. Also information regarding interactions with our Site, advertisements, or emails. This includes other usage data related to your use of our Services or other online services. | - Advertising networks. - Data analytics providers. - Internet service providers, operating systems, and platforms. - Parties you Authorize, Access or Authenticate. |
| Geolocation Data. Such as general location information about a particular individual or device. | - Data analytics providers. - Internet service providers, operating systems, and platforms. |
| Audio, Visual, and Other Electronic Data. Such as information collected via call recordings if you are interacting with us. Also recorded meetings and videos, and photographs. | - Internet service providers, operating systems, and platforms. - Parties you Authorize, Access or Authenticate. |
| Professional information. Such as job title, company name, business email, business phone number, and other similar professional-related information. | - Parties you Authorize, Access or Authenticate. |
| Protected Classifications. Includes characteristics of protected classifications under applicable federal and state laws. Such as disability information, and information you voluntarily provide (e.g. gender, marital status). | - We do not disclose this category of personal information. |
| Sensitive Personal Information. Account log-in, financial account, debit card, or credit card number, in combination with any required security or access code or credentials allowing access to an account. Genetic and health data. Biometric data. Personal information collected and analyzed concerning a consumer's health. | - Affiliates and subsidiaries. - Internet service providers, operating systems, and platforms. - Third party AI service providers (under zero data retention agreements). - Parties you Authorize, Access or Authenticate. |
We have also disclosed the above categories of personal data to our service providers. We did so for business purposes in the past 12 months.
Source of Personal Data. We generally collect personal data from these categories of sources:
Directly or indirectly from you.
Our affiliates and subsidiaries.
Adult representatives authorized by you.
Purposes of Collection, Use, and Disclosure. The How We May Use Personal Information section above describes our purposes. In general, we collect and otherwise process personal data for the business or commercial purposes below. We may also do so as you otherwise direct, or with your consent.
Services and support.
Account creation and management.
Analytics and improvement.
Communication.
Customization and personalization.
Marketing and ads.
Research and surveys.
Insight development and data enhancement.
Security and protection of rights.
Compliance and legal process.
Auditing, reporting, and other internal operations.
General business and operational support.
Sensitive Personal Information. Despite the purposes described above, we do not collect, use, or disclose "sensitive personal information" beyond the purposes authorized by the CCPA.
Retention of Personal Data. We keep your personal data for as long as needed or permitted, consistent with law. How long we keep it depends on the reason we obtained it. When deciding how long to keep it, we consider whether we have legal duties. Such as laws that require us to keep records for a set period before we can delete them. We also consider whether we have taken any legal positions. Such as a legal hold, or another need to preserve the data. Rather than delete your data, we may also deidentify it by removing identifying details. In some cases we commit to keep and use personal data only in deidentified form. Where we do, we agree not to reidentify that data, except as permitted by the law that applies.
Sales and Sharing of Personal Data. The CCPA defines "sale" as disclosing or making available personal data to a third party, in exchange for money or other valuable consideration. "Sharing" includes disclosing or making available personal data to a third party for cross-context behavioral advertising.
We do not disclose personal data to third parties in exchange for money. Even so, we may be seen as "selling" or "sharing" personal data under the CCPA. This is because we use third party ad or analytics cookies and other tools. We "sell" or "share" the following categories of personal data:
Identifiers.
Internet or other electronic network activity information.
We disclose these categories to third party ad networks, analytics providers, and social networks. We do so for marketing and ads. We do not sell or share personal data about people we know are under the age of 16.
California Privacy Rights. The CCPA provides California residents with specific rights over personal data. Some conditions and exceptions apply. California residents have the rights below for their personal data.
Right to Know (Access & Portability). You have the right to request the items below.
(i) The categories of personal data we collected about you.
(ii) The categories of sources from which the personal data is collected.
(iii) Our business or commercial purposes for collecting, selling, or sharing personal data. Also the categories of third parties to whom we have disclosed personal data.
(iv) A copy of the specific pieces of personal data we have collected about you.
Right to Correct. You have the right to ask us to correct inaccurate personal data.
Right to Delete. You have the right to ask us to delete your personal data.
Right to Opt-Out of Sales and Sharing. You have the right to opt out of "sales" and "sharing" of your personal data. The CCPA defines those terms. To exercise these rights, use the link at the bottom of our website. It is called Do Not Sell or Share My Personal Information/Your Privacy Choices. You can also opt out of "sales" and "sharing" of your personal data with an opt-out preference signal. Your browser or device may transmit an opt-out preference signal that our site detects. An example is the "global privacy control" — or GPC — signal. If so, we will act on it. We will opt that browser or device out. This covers the cookies or other tools on our site that result in a "sale" or "sharing" of your personal data. You may come to our site from a different device or browser. Or you may clear your cookies. If so, you will need to opt out again for that browser and/or device. You can also use an opt-out preference signal there.
Right to Limit Use and Disclosure. You have the right to limit use of sensitive personal data under the CCPA.
Right to Non-Discrimination. We will not discriminate against you for exercising any of the rights in this section.
Exercising Your Privacy Rights. If you are a California resident, you may exercise your CCPA rights in any of the ways below:
Verification. Before responding to your request, we must first verify your identity. We do this using the personal data you recently gave us. You must provide us with your full name and email address. We will take steps to verify your request. We do this by matching the details you give with the records we have. In some cases, we may ask for more details. We do this to verify your identity, or where needed to process your request. We may be unable to verify your identity after a good faith attempt. If so, we may deny the request. We will then explain the basis for the denial.
Authorized Agents. You may name someone as an authorized agent to submit requests and act for you. Authorized agents must give proof of their authorization in their first message to us. We may also require that you, the consumer, directly verify your identity. The same applies to the authority of the authorized agent.
Shine the Light Law
California's "Shine the Light" law (Cal. Civ. Code § 1798.83) gives certain rights to California residents. It applies if they give us certain personal data. They may ask us what personal data (if any) we shared with third parties. This covers sharing for those parties' own direct marketing use. We will provide this information free of charge. Such requests may be made once per calendar year. They cover any relevant third party sharing in the prior calendar year. To submit a "Shine the Light" request, email us using the Contact Us details below. Include a current California address in your request. Also include your attestation that you are a California resident.
In short: We may update this Policy. For big changes, we will try to notify you first.
This Policy is current as of the effective date above. We may change this Policy from time to time, so please check back. We will post any updates to this Policy on this page. We may make material changes to how we collect, use, or disclose personal data. This means data we have collected before. If so, we will endeavor to give you prior notice as the law requires. Such as by emailing you, or by posting prominent notice on our website or within the Services.
If you have any questions or concerns about this Policy or our privacy practices, you may contact us at privacy@trianglehealth.com.