Published using Google Docs
Minded Privacy Policy
Updated automatically every 5 minutes

Privacy Policy

Last updated: September 15, 2020

Introduction

Minded, Inc. ( "Minded" "we," or "us" ) owns and operates the website located at www.tryminded.com (the " Websites") and may have previously, now or in the future own and/or operate a Minded mobile application (collectively, the "Platform"). Your access and use of the Platform, any part thereof, or anything associated therewith, including its content ("Content"), any products or services provided through the Platform or otherwise by Minded, and any affiliated website, software or application owned or operated by Minded (collectively, including the Platform and the Content, the "Service") are subject to this Privacy Policy unless specifically stated otherwise. Capitalized terms not otherwise defined in this Privacy Policy have the same meaning as set forth in the Minded Terms and Conditions ( "Terms and Conditions" ).

We are committed to respecting the privacy of users of the Service. We created this Privacy Policy ( "Privacy Policy" ) to tell you how Minded collects, uses and discloses information in order to provide you with the Service.

As with our Terms and Conditions, by creating, registering, or logging into an account through the Service, or otherwise accessing or using the Service, you are automatically accepting and acknowledging the most recent version of this Privacy Policy. If we make any changes to our Privacy Policy, we will post the revised Privacy Policy and update the "Last updated" date of the Privacy Policy.

If you are using the Service on behalf of an individual other than yourself, you represent that you are authorized by such individual to act on such individual's behalf and that such individual acknowledges the practices and policies outlined in this Privacy Policy.

No Use by Minors Permitted

Our Service is intended for use by individuals who are at least twenty-one (21) years of age or such older age as may be required by applicable state laws in the jurisdiction in which an individual utilizes the Service. The Service is not designed or intended to attract, and is not directed to, children under eighteen (18) years of age, let alone thirteen (13) years of age. If we obtain actual knowledge that we have collected personal information through the Platform from a person under thirteen (13) years of age, we will use reasonable efforts to refrain from further using such personal information or maintaining it in retrievable form.

Furthermore, if you are under sixteen (16) years of age, then you (or your parent or legal guardian if you are under age 13) may at any time request that we remove content or information about you that is posted on the Platform. Please submit any such request ("Request for Removal of Minor Information") to either of the following:

For each Request for Removal of Minor Information, please state "Removal of Minor Information" in the email or letter subject line, and clearly state the following in the body of the request:

We will not accept any Request for Removal of Minor Information via telephone or facsimile. Minded is not responsible for failing to comply with any Request for Removal of Minor Information that is incomplete, incorrectly labeled or incorrectly sent.

Please note that we are not required to erase or otherwise eliminate, or enable erasure or elimination of such content or information in certain circumstances, such as, for example, when an international, federal, state, or local law, rule or regulation requires Minded to maintain the content or information; when Minded maintains the content or information on behalf of your Providers (as defined in our Terms and Conditions) as part of your electronic medical record; when the content or information is stored on or posted to the Site by a third party other than you (including any content or information posted by you that was stored, republished or reposted by the third party); when Minded anonymizes the content or information, so that you cannot be individually identified; when you do not follow the aforementioned instructions for requesting the removal of the content or information; and when you have received compensation or other consideration for providing the content or information.

The foregoing is a description of Minded's voluntary practices concerning the collection of personal information through the Service from certain minors, and is not intended to be an admission that Minded is subject to the Children's Online Privacy Protection Act, the Federal Trade Commission's Children's Online Privacy Protection Rule(s), or any similar international, federal, state, or local laws, rules, or regulations.

Protected Health Information

When you set up an account with Minded, you are creating a direct customer relationship with Minded that enables you to access and/or utilize the various functions of the Platform and the Service as a user. As part of that relationship, you provide information to Minded, including but not limited to, your name, email address, shipping address, phone number and certain transactional information, that we do not consider to be "protected health information" or "medical information".

However, in using certain components of the Service, you may also provide certain health or medical information that may be protected under applicable laws. Minded is not a "covered entity" under the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, and its related regulations and amendments from time to time (collectively, " HIPAA"). One or more of the Pharmacies or Medical Groups (as defined in our Terms and Conditions) may or may not be a "covered entity" or "business associate" under HIPAA, and Minded may in some cases be a "business associate" of a Pharmacy or Medical Group. It is important to note that HIPAA does not necessarily apply to an entity or person simply because there is health information involved, and HIPAA may not apply to your transactions or communications with Minded, the Medical Groups, the Providers or the Pharmacies. To the extent Minded is deemed a "business associate" however, and solely in its role as a business associate, Minded, may be subject to certain provisions of HIPAA with respect to "protected health information," as defined under HIPAA, that you provide to Minded, the Medical Group or the Providers (" PHI"). In addition, any medical or health information that you provide that is subject to specific protections under applicable state laws (collectively, with PHI, "Protected Information" ), will be used and disclosed only in accordance with such applicable laws. However, any information that does not constitute Protected Information under applicable laws may be used or disclosed in any manner permitted under this Privacy Policy. Protected Information does not include information that has been de-identified in accordance with applicable laws.

The Medical Groups and Providers have adopted a Notice of Privacy Practices that describes how they use and disclose Protected Information. By accessing or using any part of the Service, you are acknowledging receipt of the Notice of Privacy Practices from your Medical Group and Provider(s).

By accessing or using any part of the Service, you are agreeing that even if HIPAA does apply to Minded, the Medical Groups, the Providers or the Pharmacies, any information that you submit to Minded that is not intended and used solely for the provision of diagnosis and treatment by the Medical Group and Providers or prescription fulfillment by the Pharmacies, is not considered Protected Information, and will only be subject to our Privacy Policy and any applicable state laws that govern the privacy and security of such information.

Collection of Information

We collect any information you provide when you use the Service, including, but not limited to:

If you use your mobile device to visit, access or use the Service, then additional categories of information that we collect may include:

We also collect certain medical information on behalf of the Medical Groups and your Providers, which may include, but is not limited to:

How Information Is Collected

Minded might collect personal and non-personal information directly from you when you visit, access or use the Service; when you register with or subscribe to the Service or any products or services available through the Service; when you "sign in," "log in," or the like to the Service; when you allow the Service to access, upload, download, import or export content found on or through, or to otherwise interact with, your computer or mobile device (or any other device you may use to visit, access or use the Service) or online accounts with third-party websites, networks, platforms, servers or applications (e.g., your online social media accounts, your cloud drives and servers, your mobile device service provider); or whenever Minded asks you for such information, such as, for example, when you process a payment through the Service, or when you answer an online survey or questionnaire. In addition, if you or a third party sends Minded a comment, message or other communication (such as, by way of example only, email, letter, fax, phone call, or voice message) about you or your activities on or through the Site and/or the App, then Minded may collect any personal or non-personal information provided therein or therewith.

In addition to the information we collect directly from you, we may also collect certain information from the Medical Group and/or Providers who provide treatment or other services to you in connection with our Service. This information may include, but is not limited to, diagnoses, treatment plans (including prescription details) and notes, and is accessible and visible through certain components of the Service.

We may also receive information from third parties that pay for your care or provide you with treatment, prescription medication, which may include, for example, your prescription history, insurance policy, insurance eligibility and coverage, and laboratory test results.

Finally, Minded might use various tracking, data aggregation and/or data analysis technologies, including, for example, the following:

Please be advised that if you choose to block, reject, disable, delete or change the management settings for any or all of the aforementioned technologies and/or other tracking, data aggregation and data analysis technologies, then certain areas of the Platform might not function properly.

By visiting, accessing or using the Service, you acknowledge and agree in each instance that you are giving Minded permission to monitor or otherwise track your activities on the Service, and that Minded may use the aforementioned technologies and/or other tracking, data aggregation and data analysis technologies. Notwithstanding the foregoing, Minded does not permit third parties or third-party cookies to access to any communications you have with the Providers, or medical information that you submit to the Providers for diagnosis and treatment purposes.

Use of Information

In connection with providing the Service, we and our affiliates and service providers may use your information, subject to the limitations addressed in the Protected Health Information Section above, for a number of purposes, including, but not limited to:

We may de-identify your information and use, create and sell such de-identified information, or any business or other purpose not prohibited by applicable law.

Disclosure of Information

Subject to the limitations described in the Protected Health Information section above, we may disclose your information to third parties in connection with the provision of our Service or as otherwise permitted or required by law. For example, we may disclose your information to:

We may de-identify your information and disclose such de-identified information for any purpose not prohibited by applicable law.

Data Retention

Minded may retain your information for as long as it believes necessary; as long as necessary to comply with its legal obligations, resolve disputes and/or enforce its agreements; and/or as long as needed to provide you with the products and/or services of the Service or Minded. Minded may dispose of or delete any such information at any time, except as set forth in any other agreement or document executed by Minded or as required by law.

Similarly, the Medical Groups and Providers may retain your information for as long as they believe necessary; as long as necessary to comply with their respective legal obligations, resolve disputes and/or enforce its agreements; and/or as long as needed to provide you with the products and/or services of the Medical Groups and Providers. The Medical Groups and Providers may dispose of or delete any such information at any time, except as set forth in any other agreement or document executed by the Medical Groups or Providers or as required by law.

Transactions

In connection with any transaction that you conduct through the Service (e.g., the purchase or sale of any products or services on or through the Service), you may be asked to supply certain information relevant to the transaction, including, without limitation, your credit card number and expiration date, your billing address, your shipping address, your phone number and/or your email address. By submitting such information, you grant Minded without charge the irrevocable, unencumbered, universe-wide and perpetual right to provide such information to third parties (e.g., payment processing companies, buyers on the Service, sellers on the Service) for the purpose of facilitating the transaction.

All credit card, debit card and other monetary transactions on or through the Service occur through an online payment processing application(s) accessible through the Service. This online payment processing application(s) is provided by Minded' third-party online payment processing vendor, Stripe (" Stripe"). Additional information about Stripe, its privacy policy and its information security measures (collectively, the " Stripe Policies") should be available on the Stripe website located at https://stripe.com/us/privacy or by contacting Stipe directly. Reference is made to the Stripe Policies for informational purposes only and are in no way incorporated into or made a part of this Privacy Policy. Minded' relationship with Stripe, if any, is merely contractual in nature, as Stripe nothing more than a third-party vendor to Minded, and is in no way subject to Minded's direction or control; thus, their relationship is not, and should not be construed as, one of fiduciaries, franchisors-franchisees, agents-principals, employers-employees, partners, joint venturers or the like.

Jurisdictional Issues

The Service may only be used within certain states within the United States as described in our Terms and Conditions. Accordingly, this Privacy Policy, and our collection, use, and disclosure of your information, is governed by U.S. law.

Third Parties

This Privacy Policy does not address or apply to, and we are not responsible for, the privacy, information or other practices of any third parties, including, without limitation, the Medical Group or its Providers, the manufacturer of your mobile device, and any other third-party mobile application or website to which our Service may contain a link. These third parties may at times gather information from or about you. We do not control and are not responsible for the privacy practices of these third parties. We encourage you to review the Medical Group's Notice of Privacy Practices and the privacy policies of each website and application you visit and use.

Summary of Information Practices

The following table summarizes our personal information collection, use, and sharing practices in the preceding 12 months since we last updated this Policy. As reflected in this table, we may share your personal information with a variety of outside entities.

Category of Personal Information Collected

Examples

Categories of Sources

Commercial/Business Purpose

Categories of Third Parties with Whom Hims Shares Personal Information

Identifiers

Full name, email address, phone number, account login and password, purchase information, billing address, physical addres

You, our and third-party cookies and other tracking technologies on our website, and service providers.

Facilitating use of Services and/or products or services, processing payments, marketing, customer, or analytic services, protecting against malicious, deceptive, fraudulent or illegal activity, and enabling or effecting, directly or indirectly, a commercial transaction

Service providers, Medical Groups, Providers, Pharmacies, third parties that assume control over all or part of the business in connection with a merger, acquisition, bankruptcy, or similar event, affiliates, professional advisors, law enforcement authorities, and those involved in legal proceedings, with consent

Unique identifiers or personal identifiers        

IP address, online identifiers, mobile device ID, dates of medical visit        

You, your mobile device, and our and third-party cookies and other tracking technologies on our website        

Processing or fulfilling orders and transactions, debugging to identify and repair errors that impair existing intended functionality, providing customer or analytic services, and enabling or effecting, directly or indirectly, a commercial transaction        

Service providers, Medical Groups, Providers, Pharmacies, data analytic providers, payment processors, affiliates, professional advisors, law enforcement authorities, and those involved in legal proceedings, with consent

Internet and other network activity        

Browsing activity        

Your mobile devices and computers used to access our Site        

Marketing, customer, or analytic services and enabling or effecting, directly or indirectly, a commercial transaction        

Service providers, data analytic providers, affiliates

emographic information

Gender, date of birth, zip code

You

Marketing, customer, or analytic services, processing or fulfilling orders and transactions

Service providers, data analytic providers, affiliates

Audio, electronic, visual, thermal, olfactory, or similar information

Electronic signature, photographic or video images

You

Identification verification or non-diagnosis or treatment purposes, on behalf of Medical Groups/Providers for diagnosis or treatment purposes

Medical Groups and Providers

ommercial Activity

Information about goods or services purchased, obtained, or considered,

Your mobile device

Processing or fulfilling orders and transactions, marketing, customer or analytic services

Service providers, data analytic providers, affiliates

Health and Medical Information

Medical history and other information, symptoms, prescription history, insurance policy, insurance eligibility and coverage, laboratory test results, previous doctors visited

You or Medical Group and/or Providers

Processing or fulfilling orders and transactions

Medical Groups and Providers

Financial Information (Information under California Civil Code 1798.80)

Payment information

You

Processing or fulfilling orders and transactions

Payment processors, buyers on Service, sellers on Service

Geolocation information

Geolocation

Your mobile devices and computers used to access our Site

Confirming location

Medical Groups and Providers

Professional or Employment-related Information

Job history, educational history, employer

Applicants or non-applicant email addresses or signature blocks

Process and evaluate applications for positions with Hims

Service providers such as HR vendors

If you are a California resident, you have the right to know what personal information we collect, use, disclose or sell about you under the CCPA. Additionally, you have the right to access and delete your personal information.

To exercise these privacy rights and choices, please follow the instructions below:

We reserve the right to charge a fee where permitted by law, for instance, if your request is manifestly unfounded or excessive. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

Verification: Please note, we will take steps to verify your identity before fulfilling any of the above requests. If you maintain an account with us, we will verify your identity through existing authentication practices for the account (e.g., login and password). If you are not a registered member, we will verify your identity by matching two or three data points that you provide with data points that we maintain and have determined to be reliable for the purposes of verification (e.g., browser or device ID).

Authorized Agents:  Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your or your minor child's personal information. In order to designate an authorized agent to make a request on your behalf, you must provide written proof that you have consented to this designation unless the agent has power of attorney pursuant to California Probate Code sections 4000-4465. You must also verify your identity directly with us by providing a copy of your government issued identification.

Response Timing and Format: If you are a Minded customer with an online account, we will deliver our written response to that account online or via email. If you are not a Minded customer or do not have an online account, we will deliver our written response by mail or electronically, at your preference. The response will also explain the reasons we cannot comply with a request, if applicable. Please note, that if you are submitting a request regarding information you provided to a Medical Group, a Provider, or a Pharmacy, your request should be directed to that entity.

Anti-Discrimination Right: We will not discriminate against you for exercising any of your CCPA rights. But note that some of the functionality and features available to you may change or no longer be available to you upon deletion of your personal information or opt-out of sale of your personal information.

We do not sell your personal information for money, but we use cookies and similar technologies. Please see section on cookies.

We do not and will not sell the personal information of minors under 16 years of age without affirmative authorization.

Miscellaneous

We strive to use reasonable physical, technical and administrative measures to protect information under our control. However, you must keep your Account password secure and your Account confidential, and you are responsible for any and all use of your Account. If you have reason to believe that the security of your Account has been compromised, please notify us immediately in accordance with the "Contacting Us" section below.

When using the Service, you may choose not to provide us with certain information, but this may limit the features you are able to use or may prevent you from using the Service all together. You may also choose to opt out of receiving certain communications (e.g., newsletters, promotions) by emailing us your preference. Please note that even if you opt out, we may still send you Service-related communications. We do not currently respond to web browser "do not track" signals or other mechanisms that provide a method to opt out of the collection of information across the networks of websites and online services in which we participate. If we do so in the future, we will describe how we do so in this Privacy Policy.Minded may supplement, amend, or otherwise modify this Privacy Policy at any time. Such supplements, amendments and other modifications will be posted on this or a similar page of the Service, and shall be deemed effective as of the "Last Updated" date; provided, however, that Minded will notify you and/or require you to accept the updated Privacy Policy if the supplemented, amended or otherwise modified Privacy Policy implements material changes from Minded' then-current Privacy Policy. It is your responsibility to carefully review this Privacy Policy each time you visit, access or use the Service.

Contacting Us

If you have any questions about this Privacy Policy, please contact us by email at privacy@tryminded.com or by regular mail at:

Minded, Inc.

122 Grand Street

New York, NY 10013