SUPPLEMENTAL PRIVACY NOTICE FOR CALIFORNIA RESIDENTS
HINGE HEALTH, INC. SUPPLEMENTAL PRIVACY NOTICE FOR CALIFORNIA RESIDENTS
Last Updated: February 5th, 2020
We provide this supplemental privacy notice (“Notice”) to comply with the California Consumer Privacy Act of 2018, as amended (“CCPA”). This Notice applies to California residents (“California residents” or “you”) and explains how Hinge Health, Inc. (“Hinge Health,” “we,” or “us”) collects, uses, and discloses information about you when you access or use our website[s], mobile application[s], or other online products and services (collectively, the “Services”), engage with us, contact our customer service team, engage with us on social media, or otherwise interact with us.
This Notice describes how we collect, use, and disclose information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household (“Personal Information”). For purposes of this Notice, Personal Information does not include:
Publicly available information from government records.
De-identified or aggregated consumer information.
Information excluded from the CCPA's scope, like:
Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data; or
Personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FRCA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver's Privacy Protection Act of 1994.
We may change this Notice from time to time. If we make changes, we will notify you by revising the date at the top of the policy and, in some cases, we may provide you with additional notice (such as adding a statement to our website homepage or sending you a notification). We encourage you to review the Notice whenever you access the Services or otherwise interact with us to stay informed about our information practices and the choices available to you.
Your CCPA Rights
Right to Know
Right to Access Specific Information and Data Portability
Right to Delete
How to Exercise Your CCPA Rights
Verification of Consumer Requests
Response Timing and Format
YOUR CCPA RIGHTS
If you are a California resident, you have the right to (1) request more information about the categories and specific pieces of Personal Information we have collected and disclosed for a business purpose in the last 12 months, (2) request deletion of your Personal Information, (3) to opt out of sales of your Personal Information, if applicable, and (4) to not be discriminated against for exercising these rights.
You may make these requests by calling 1-855-902-2777 or visiting this page. The CCPA includes exceptions and exemptions that will limit your ability to exercise your CCPA rights for certain types of Personal Information.
We will verify your request by matching information you have previously provided to us to information you provide as part of your request. You have the right to request that an agent submit a request to exercise your rights on your behalf. We require that your agent be registered with the California Secretary of State and reserve the right to contact you directly if we have any questions or concerns about the agent’s submission. We will not discriminate against you if you exercise your rights under the CCPA.
Hinge Health does not sell your Personal Information.
RIGHT TO KNOW
Under the CCPA, you have the right to request more information about the Personal Information we have collected about you during the past 12 months and what categories of Personal Information we have shared with unaffiliated third parties.
Collection of Personal Information
Information You Provide to Us: We collect information you provide directly to us. For example, we collect information when you engage us or request information related to our Services, fill out a form, communicate with us via third party social media sites, request client assistance, or otherwise communicate with us. The types of information we may collect include:
Identifiers: A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, or other similar identifiers.
Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)): A name, signature, Social Security number, physical characteristics or description, address, telephone number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories.
Protected classification characteristics under California or federal law: Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).
Internet or Other Similar Network Activity: Browsing history, search history, information on a consumer's interaction with a website, application, or advertisement.
Professional or Employment-Related Information: Current or past job history.
Inferences Drawn From Other Personal Information: Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
Other Information We Collect When You Use our Services: When you access or use our Services or transact business with us, we automatically collect information about you, including:
Usage Information: We collect information about your use of the Services, such as the search terms you enter, the information and documentation you upload, etc.
Transactional Information about our Engagement: When you engage us, we collect information about the terms of our Services, our fees and your expectations.
Log Information: We collect information related to your access to and use of the Services, including the type of browser you use, app version, access times, pages viewed, your IP address, and the page you visited before navigating to our Services.
Device Information: We collect information about the computer or mobile device you use to access our Services, including the hardware model, operating system and version, unique device identifiers, and mobile network information.
Location Information: We may derive the approximate location of your device from your IP address. When you first launch our mobile application that collect precise location information, you will be asked to consent to the application’s collection of this information. If you initially consent to our collection of this information, you can subsequently stop the collection of this information at any time by changing the preferences on your mobile device. If you do so, our mobile applications, or certain features thereof, may no longer function properly. You may also stop our collection of this location information by following the standard uninstall process to remove all of our mobile applications from your device.
Information Collected by Cookies and Similar Tracking Technologies: We (and our service providers) use different technologies to collect information, including cookies and web beacons. Cookies are small data files stored on your hard drive or in device memory that help us improve our Services and your experience, see which areas and features of our Services are popular, and count visits. Web beacons (also known as “pixel tags” or “clear GIFs”) are electronic images that may be used in our Services or emails and help deliver cookies, count visits, and understand usage and campaign effectiveness.
Information We Collect from Other Sources: We may also obtain information about you from other sources. For example, we may collect information about you from third parties, including but not limited to insurance eligibility services and third-party administrators, and publicly available sources.
Information We Derive: We may derive information or draw inferences from you based on the information we or our service providers collect. For example, we may make inferences about your preferences, products and services that may interest you, and your patterns and behaviours.
Use of Information We use the information we collect to:
To fulfill or meet the reason you provided the information. For example, if you share your name and contact information to ask a question about our Services, we will use that Personal Information to respond to your inquiry. If you choose to go through our screening process for our Services, we will use that Personal Information to determine your eligibility for our Services. We may also save your Personal Information to facilitate new Services.
To provide, support, personalize, and develop our websites, products, and Services.
To provide you with email alerts, and other notices concerning our products or Services, or events or news, we believe may be of interest to you.
To provide you with support and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our responses.
To improve our Services and present its contents to you.
For testing, research, analysis and product development.
To help maintain the safety, security, and integrity of our website, products and Services, databases and other technology assets, and business or as necessary or appropriate to protect the rights, property or safety of us, our clients or others.
To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by us is among the assets transferred.
As described to you when collecting your Personal Information or as otherwise set forth in the CCPA.
Sharing of Information We may share information about you as follows or as otherwise described in this Notice:
With payers/providers of our Services (e.g., employers or insurers) so they understand how our Services are being used and to better understand the needs of our users;
With vendors, service providers, and professional advisors that perform services for us, including accountants, tax planners, and attorneys. When we share Personal Information for services to be performed on our behalf, we enter a contract that describes the purpose for such sharing and requires the recipient to both keep that Personal Information confidential and not use, collect or share it for any purpose except performing the contract;
With third parties for their own services and marketing purposes, unless you opt out of this type of sharing by calling 1-855-902-2777 or visiting this page https://www.hingehealth.com/ccpa-request;
In response to a request for information if we believe disclosure is in accordance with, or required by, any applicable law or legal process, including lawful requests by public authorities to meet national security or law enforcement requirements;
If we believe your actions are inconsistent with our user agreements or policies, if we believe you have violated the law, or to protect the rights, property, and safety of Hinge Health or others;
In connection with, or during negotiations of, any merger, sale of company assets, financing or acquisition of all or a portion of our business by another company;
Between and among Hinge Health and our current and future parents, affiliates, subsidiaries, and other companies under common control and ownership; and
With your consent or at your direction.
We may also share aggregated or de-identified information that cannot reasonably be used by those third parties to identify you.
RIGHT TO ACCESS TO SPECIFIC INFORMATION AND DATA PORTABILITY Under the CCPA, you have the right to request that we disclose the following to you:
The categories of Personal Information we collected about you.
The specific pieces of Personal Information we collected about you.
The categories of sources for the Personal Information we collected about you.
The business or commercial purpose for collecting that Personal Information.
The categories of third parties with whom we share that Personal Information.
Once we receive and confirm your verifiable access request, we will disclose the requested information covering the preceding 12 months, unless an exception applies.
RIGHT TO DELETE Under the CCPA, you have the right to request that we delete your Personal Information. Once we receive and confirm your verifiable deletion request, we will delete or de-identify (and direct our service providers to delete or deidentify) your Personal Information from our records unless an exception applies or retaining your Personal Information is necessary for us or our service providers to:
Complete the transaction for which we collected the Personal Information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.
Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
Debug products to identify and repair errors that impair existing intended functionality.
Exercise free speech ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 seq.).
Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent.
Comply with a legal obligation.
Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
HOW TO EXERCISE YOUR CCPA RIGHTS
If you are a California resident, you may exercise your CCPA-provided rights described above by either:
• Visiting https://www.hingehealth.com/ccpa-request; or • Calling us at 1-855-902-2777.
Also, we are not obligated to respond to more than two access requests for the same individual’s personal information within a 12-month period.
VERIFICATION OF CONSUMER REQUESTS Each verifiable consumer request must provide sufficient information to allow us to reasonably verify that you are the person about whom we collected Personal Information or an authorized agent. We cannot respond to your request if we cannot verify and confirm your identity or authority to make the request.
RESPONSE TIMING AND FORMAT We intend to respond to a verified consumer request within 45 days of our receipt. If we require additional time to respond, we will inform you of the reason for additional time needed and anticipated timing for our response. Our response will also explain why we cannot comply with your request, if applicable.
SHINE THE LIGHT California law permits residents of California to request certain details about how their information is shared with third parties for direct marketing purposes. To make such a request, please send an email to email@example.com or write us at: Hinge Health 465 California Street, Suite 1400, San Francisco, CA 94104.
ACCOUNT INFORMATION You may update and correct certain account information you provide to us at any time by logging into your account, emailing us at firstname.lastname@example.org, or call us at 1-855-902-2777. If you wish to delete or deactivate your account, please email us at email@example.com or call us at 1-855-902-2777 [or describe other method, such as through settings in app or the like]. Please note that we may retain certain information as required by law or for legitimate business purposes, including to meet our legal, regulatory, or other compliance obligations.
PROMOTIONAL COMMUNICATIONS You may opt out of receiving promotional emails or text messages from Hinge Health by following the instructions in those emails or text messages. If you opt out, we may still send you non-promotional emails, such as those about your account or our ongoing business relations.
MOBILE PUSH NOTIFICATIONS/ALERTS With your consent, we may send promotional and non-promotional push notifications or alerts to your mobile device. You can deactivate these messages at any time by changing the notification settings on your mobile device.
SOCIAL SHARING FEATURES The Services may offer social sharing features and other integrated tools (such as the Facebook “Like” button), which let you share actions you take on our Services with other media, and vice versa. Your use of such features enables the sharing of information with your friends or the public, depending on the settings you establish with the entity that provides the social sharing feature. For more information about the purpose and scope of data collection and processing in connection with social sharing features, please visit the privacy policies of the entities that provide these features.
Website: www.hingehealth.com Email: firstname.lastname@example.org Toll-free telephone number: 1-855-902-2777 Postal Address: Hinge Health Attn: Compliance 465 California Street, Suite 1400 San Francisco, CA 94104