Jiro Health Inc. ("Company", "we", "our", or "us") respects your privacy and is committed to protecting it through our compliance with this privacy policy ("Privacy Policy"). This Privacy Policy describes how we collect, process, retain, and disclose personal information about you when providing services to you through our applications, websites, products, and services that link to or incorporate this Privacy Policy by reference (collectively, our "Services") and our practices for using, maintaining, protecting, and disclosing that information. Beyond this Privacy Policy, your use of our Services is also subject to our End User License Agreement.
This Privacy Policy applies only to information we collect:
- Through the Services.
- In communications, including email, text, chat, and other electronic messages, between you and the Services.
- From certain third parties, combined with information we collect (see From Business Partners and Service Providers below).
It does not apply to information collected by:
- Us through any other means, including on any other website operated by Company or any third party that does not link to this Privacy Policy; or
- Any third party, including through any application or content (including advertising) that may link to or be accessible from or through the Services.
We may provide additional or different privacy policies that are specific to certain features, services, or activities.
Please read this Privacy Policy carefully to understand our policies and practices regarding your information and how we treat it. By interacting with our Services or providing us with your information, you agree to the collection, use, and sharing of your information as described in this Privacy Policy. This Privacy Policy may change from time to time (see Changes to Our Privacy Policy below). Your continued use of the Services after we make changes as described here is deemed to be acceptance of those changes, so please check the Privacy Policy periodically for updates.
Children's and Minors' Data
Our Services are not intended for, and we do not knowingly attempt to solicit or collect any personal information from, children under the age of 18. If we learn we have collected or received personal information from a child under 18 years old without verification of parental consent, we will delete that information.
Personal Information That We Collect or Process
"Personal information" is information that identifies, relates to, or describes, directly or indirectly, you as an individual, such as your name, email address, telephone number, home address, or payment information.
The types and categories of personal information we collect or process include:
- Verification information: We require members of the Jiro community to verify and authenticate their identity in order to register an account profile. With your consent, the information that we will collect may include your name, date of birth, social security number and/or other government issued identification numbers (including National Provider Identifier number), copies of your government issued identification card (e.g., license or passport), email address, phone number, mailing address, and certain photographic images, and biometric data. You may also be asked to provide community affiliations (e.g., Military, First Responder, Student, Veteran, etc.), memberships, educational degrees, and professional certifications.
- Account and contact information, including name, address (such as home address, work address, or other address), email address, phone number, username, and other contact information you provide us.
- Account history, including information about your subscription, account, transactions, purchases, order history, or discounts.
- Demographic information, including your age, gender, income level, education, or family or marital status, if you have consented to such information collection.
- Location information, including general geographic location such as country, state or province, or city and precise geolocation, if you have enabled and consented to location information collection.
- Device information, including your IP address, device identifiers, operating system and version, preferred language, hardware identifiers, browser type and settings, and other device information.
- Content and information you elect to provide or that you authorize us to collect (i) as part of your profile, including your personal professional credentials or those of your business, and your W2 or other tax forms for purposes of personalizing and benchmarking compensation data in the industry, or (ii) in any reviews you make through the Services or emails, chats, or other communications sent to us.
- Images, voice recordings, and videos collected or stored in connection with the Services, if you have consented to such information collection.
We also collect:
- Statistics or aggregated information. Statistical or aggregated data does not directly identify a specific person, but we may derive non-personal statistical or aggregated data from personal information. For example, we may aggregate personal information to calculate the percentage of users accessing a specific Services feature.
- Technical information. Technical information includes information about your internet connection and usage details about your interactions with the Services, such as clickstream information to, through, and from our Services (including date and time), products that you view or search for; page response times, download errors, length of your visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), or methods used to browse away from a page.
If we combine or connect non-personal statistical or technical data with personal information so that it directly or indirectly identifies an individual, we treat the combined information as personal information.
How We Collect Your Personal and Other Data
You Provide Information to Us
We collect information about you when you interact with our Services, such as when you create or update an account, subscribe, make a purchase or request, participate in surveys, or create, upload, or post content to the Services, including reviews, media such as photos, videos, or audio recordings.
When you make purchases through our Services, your payment is processed by third-party payment processors ("Payment Processors"). These Payment Processors may collect your credit card information, debit card information, billing information, and any other financial information necessary to complete your payment ("Payment Information"). We do not collect, store, or process your Payment Information. The use of your Payment Information and any other personal information by a Payment Processor is governed by their terms and conditions and privacy policy, and any Personal Information we receive about you from our Payment Processors is governed by this Privacy Policy.
Automatically Through Our Services
As you navigate through and interact with our Services, we may use automatic data collection technologies to collect information that may include personal information. Information collected automatically may include usage details, IP addresses, operating system, and browser type, and information collected through cookies, web beacons, and other tracking technologies, including details of your interactions with our Services, such as traffic data, location data, logs, and other communication data, and which resources and Services features that you access and use.
The technologies we use for this automatic data collection may include:
- Cookies. A cookie is a small file placed on your device when you interact with the Services. You may refuse to accept or disable cookies by activating the appropriate setting on your browser or device. However, if you select this setting, you may be unable to access certain features of the Services.
- Web Beacons. Some parts of the Services and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit the Company, for example, to count users who have visited those parts or opened an email and for other related statistics (for example, recording the popularity of certain content and verifying system and server integrity).
We may use these automatic collection technologies to collect information about your online activities over time and across third-party sites or other online services (behavioral tracking).
Using automatic collection technologies helps us to improve our Services and to deliver a better and more personalized experience. You can set your browser to refuse all or some browser cookies or other tracking technology files, or to alert you when these files are being sent. If you disable or refuse cookies or similar tracking files, some Services features may be inaccessible or not function properly. Some browsers include a "Do Not Track" (DNT) setting that can send a signal to the online services you visit indicating you do not wish to be tracked. Because there is not a common understanding of how to interpret the DNT signal, our Services may not respond to all browser DNT signals. Instead, you can use the range of other tools to control data collection and use, including the cookie controls and advertising controls described in this Privacy Policy or within the Services.
When you interact with the Services, there are third parties that may use automatic collection technologies to collect information about you or your device. These third parties may include:
- Ad platforms.
- Analytics companies.
These third parties may use tracking technologies to collect information about you when you use the Services. The information they collect may be associated with your personal information or they may collect information, including personal information, about your online activities over time and across different websites, apps, platforms, and other online services. They may use this information to provide you with interest-based (behavioral) advertising or other targeted content.
We do not control these third parties' tracking technologies or how they may be used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly.
From Business Partners and Service Providers
We may receive personal information about you from other sources and combine that with information we collect directly from you. For example, we may obtain information about you from commercial providers (including but not limited to retail pharmacies, pharmacy benefit managers, brokers, aggregators) and other service providers that we engage to perform services on our behalf, such as email platform providers, content delivery services, payment processors, promotions services, analytics, security and anti-fraud services, and data brokers. We also may receive personal information from business partners that we engage to share consumer information with us, including your personal preferences and demographic information such as age, gender, and income level so that we can better provide you with a personalized experience, including personalized content, offers, and services.
How We Use Your Information
We use information that we collect about you or that you provide to us, including any personal information, to:
- Verification and authentication of your identity.
- Provide you with the Services and any contents, features, information, products, or services that we make available through the Services.
- Fulfill and manage subscriptions and payments.
- Fulfill any other purpose for which you provide it.
- Provide you with notices about your account.
- Improve our Services, including by analyzing your information and creating aggregated data derived from your information to develop, maintain, analyze, improve, optimize, measure, and report on our Services and their features and how users interact with them. Our analysis may include the use of technology like machine learning and large language models, which may include training these models or sharing with third parties for model training.
- Carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection.
- Notify you when Services updates are available and about changes to any products or services we offer or provide through them.
- Provide you with additional information about the Services and other products or services we offer or promote via mail, electronic communications, or sponsored advertising.
- Provide you with tailored responses and/or information by using such personal information to power the tools that support and/or provide the Services, and such tools may include use of an artificial intelligence agent.
- In any other way we may describe when you provide the information.
- In ways that are consistent with, but additional to, the original purpose for which you provide the information, including but not limited to de-identifying and/or aggregating the data in order to enhance the functionality and options available for your account profile.
- For any other purpose with your consent.
The usage information we collect, whether connected to your personal information or not, helps us improve our Services and deliver a better and more personalized experience by enabling us to:
- Estimate our audience sizes and usage patterns.
- Store information about your preferences, allowing us to customize the Services according to your individual needs and interests.
- Recognize you when you return to our Services.
We may also use your information to contact you about goods and services that may be of interest to you. If you do not want us to use your information in this way, please make such selection when or adjust your user preferences in your account profile.
We use location information we collect to better provide the Services to you.
Who We Disclose Your Information To
Jiro will not sell, rent, or trade your Personal Information. Jiro will only transfer your Personal Information with your consent, to third parties in order to assist in verifying your identity or eligibility to create an account to use the Services, and as required for the prevention of fraud.
We may disclose aggregated information about our users, and information that does not identify any individual, without restriction.
We may also disclose identifiable personal information that we collect from you, with your consent or that you provide during the course of account creation or other account activity, as described in this Privacy Policy:
- To Plaid, Inc. ("Plaid"), who may directly send you Short Message Service (SMS) messages, iMessages or other formats of text communications in order to provide a service to you;
- To Plaid, to verify your identity and validate your background when you register for an account to access the Services, and in order to verify your eligibility to receive services and other benefits from us or our partners and other service providers.
By using the Service, you grant the Company the right, power, and authority to act on your behalf to access and transmit your personal and financial information from your relevant financial institution and agree that Plaid may process, transfer and store your personal and financial information. To learn more about how Plaid will process your information, please see Plaid's Privacy Policy.
From time to time, we may provide your Personal Information to other third parties such as government agencies, telecommunications networks, financial institutions or other trusted and reliable sources of information. Our provision of your Personal Information to the foregoing parties is solely to verify your identity and eligibility to establish and maintain an account to access the Services. We will transmit the Personal Information you provide to us using commercially reasonable methods, including industry standard encryption tools, designed to protect such information from unauthorized access.
- To our subsidiaries and affiliates.
- To contractors, service providers, and other third parties we use to support our organization.
- To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by us is among the assets transferred.
- To fulfill the purpose for which you provide it.
- For any other purpose disclosed by us when you provide the information.
- With your consent.
We may also disclose your personal information:
- To comply with any court order, law, or legal process, including to respond to any government or regulatory request.
- To enforce or apply our End User License Agreement and other agreements, including for billing and collection purposes.
- If we believe disclosure is necessary or appropriate to protect the rights, property, or safety of our organization, our customers or others.
The categories of personal information we may disclose include:
- Your phone number.
- Other information needed to verify your credentials, including through background checks.
How We Protect Your Personal Information
We use commercially reasonable administrative, physical, and technical measures designed to protect your personal information from accidental loss or destruction and from unauthorized access, use, alteration, and disclosure. However, no website, mobile application, system, electronic storage, or online service is completely secure, and we cannot guarantee the security of your personal information transmitted to, through, using, or in connection with the Services. In particular, email, texts, and chats sent to or from the Services may not be secure, and you should carefully decide what information you send to us via such communications channels. Any transmission of personal information is at your own risk.
The safety and security of your information also depends on you. You are responsible for taking steps to protect your personal information against unauthorized use, disclosure, and access.
How We Retain Your Personal Information
We keep the categories of personal information described in this Privacy Policy for as long as reasonably necessary to fulfill the purposes described or for as otherwise legally permitted or required, such as maintaining the Services, operating our organization, complying with our legal obligations, resolving disputes, and for safety, security, and fraud prevention. This means that we consider our legal and business obligations, potential risks of harm, and nature of the information when deciding how long to retain personal information. At the end of the retention period, personal information will be deleted, destroyed, or de-identified.
Protected Health Information and HIPAA Compliance
Some features of the Services may enable the receipt, maintenance, transmission, or use of "Protected Health Information" ("PHI"), as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA"), including the utilization of artificial intelligence and machine learning tools or products ("AI Products") to process PHI. This section explains how we handle PHI and the circumstances in which HIPAA may apply.
We may act as a "Business Associate" under HIPAA when we provide Services to healthcare providers, health plans, or other entities that qualify as "Covered Entities," under HIPAA or to their Business Associates. In those circumstances, our use and disclosure of PHI is governed by a Business Associate Agreement or similar agreement ("BA Agreement"). If you are, or act on behalf of, a Covered Entity or Business Associate and PHI will be transmitted in connection with your use of the Services, such PHI will be handled in accordance with the Company's BA Agreement that has been executed between the relevant Covered Entity or Business Associate and Company, which is incorporated by reference herein, and the applicable BA Agreement controls with respect to PHI.
When HIPAA applies, we use and disclose PHI only:
- As is necessary to perform the Services;
- As permitted or required by the BA Agreement;
- As permitted or required by applicable law.
We do not use PHI for marketing, advertising, or other purposes prohibited by HIPAA.
We implement all safeguards required by applicable law to protect PHI processed by AI Products. Any PHI processed by AI Products in connection with our Services is used solely to provide those Services as described in this Privacy Policy and in accordance with applicable BA Agreements and HIPAA requirements. We do not use PHI for the development, training, or improvement of AI Products, nor do we share any PHI with third parties for such purposes.
If you are, or act on behalf of, a Covered Entity or Business Associate under HIPAA, you are responsible for:
- Determining whether the Services are appropriate for PHI;
- Obtaining all necessary authorizations, consents, or permissions;
- Disclosing PHI to us only after a BA Agreement is in effect and in accordance with HIPAA and such BA Agreement;
- Ensuring your users access the Services in a HIPAA-compliant manner.
If you are a patient or individual whose PHI is processed through the Services, please contact your healthcare provider directly to exercise your rights under HIPAA (including rights of access, amendment, and accounting of disclosures).
Changes to Our Privacy Policy
We may update this Privacy Policy from time to time, and we will provide notice of any such changes to the Privacy Policy as required by law. The date the Privacy Policy was last updated is identified at the top of the page. We will notify you of changes to this policy by updating the "last updated" date and posting the updated Privacy Policy on the Services. We may email or otherwise communicate reminders about this Privacy Policy, but you should check our Services periodically to see the current Privacy Policy and any changes we have made to it.
Your State Privacy Rights
Depending on your state of residency, you may have certain rights related to your personal data, including:
- Access and Data Portability. You may confirm whether we process your personal data and access a copy of the personal data we process. To the extent feasible and required by state law, depending on your state, data will be provided in a portable format. Depending on your state, you may have the right to receive additional information and it will be included in the response to your access request.
- Correction. You may request that we correct inaccuracies in your personal data that we maintain, taking into account the information's nature and processing purpose.
- Deletion. You may request that we delete personal data about you that we maintain, subject to certain exception under applicable law.
- Opt Out of Using Personal Data for Targeted Advertising, Profiling, and Sales. You may request that we do not use your personal data for these purposes.
Important: The exact scope of these rights vary by state, and in many cases may also be subject to certain exceptions which mean we may not have an obligation to fulfill your request.
Contact Information
To exercise your rights or ask questions or comment about this Privacy Policy or our privacy practices, you may contact us at: privacy@jirohealth.com
