Privacy policy

Privacy Policy

InVite Health, inc.

Last updated:  September 5, 2023

This Privacy Policy describes how InVite Health, Inc. (the "Site", "we", "us", or "our") collects, uses, and discloses your personal information when you visit our retail stores, purchase our products, use our services, and/or visit and interact with our website, www.invitehealth.com (the "Site"), make any purchase from the Site, or otherwise communicate with us (collectively, the "Services").  For purposes of this Privacy Policy, "you" and "your" means you as the user of the Services, whether you are a customer, website visitor, or another individual whose information we have collected pursuant to this Privacy Policy.

Please read this Privacy Policy carefully.  By using and/or accessing any of the Services, you agree to the terms of the collection, use, and disclosure of your information as set forth in this Privacy Policy.  If you do not agree to this Privacy Policy, please do not use or access any of the Services.

Changes to This Privacy Policy

We may update this Privacy Policy at any time and from time to time, including, without limitation, to reflect changes to our practices or for other operational, legal, or regulatory reasons.  We will post the revised Privacy Policy on the Site, update the "Last updated" date and take any other steps required by applicable law.

How We Collect and Use Your Personal Information

To provide the Services, we collect and have collected over the past twelve (12) months personal information about you from a variety of sources, as set out below.  The information that we collect and use varies depending on how you interact with us.

In addition to the specific uses set out below, we may use information we collect about you to communicate with you, provide the Services, improve and market the Services, comply with any applicable legal obligations, enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.

What Personal Information We Collect

The types of personal information we obtain about you depends on how you interact with our Site and use our Services.  When we use the term "personal information", we are referring to information that identifies, relates to, describes, or can be associated with you.  The following sections describe the categories and specific types of personal information we collect.

Information We Collect Directly from You

Information that you directly submit to us through our Services may include:

- Basic contact details including your name, address, phone number, email.

- Order information including your name, billing address, shipping address, payment confirmation, email address, phone number.

- Account information including your username, password, security questions.

- Shopping information including the items you view, put in your cart or add to your wishlist.

- Customer support information including the information you choose to include in communications with us, for example, when sending a message through the Services.

Some features of the Services may require you to directly provide us with certain information about yourself.  You may elect not to provide this information, but doing so may prevent you from using or accessing these features.

Information We Collect through Cookies

We also automatically collect certain information about your interaction with the Services ("Usage Data").  To do this, we may use cookies, pixels and similar technologies ("Cookies").  Usage Data may include information about how you access and use our Site and your account, including device information, browser information, information about your network connection, your IP address and other information regarding your interaction with the Services.

Information We Obtain from Third Parties

Finally, we may obtain information about you from third parties, including from vendors and service providers who may collect information on our behalf, such as:

- Companies who support our Site and Services, such as Shopify.

- Our payment processors, who collect payment information (e.g., bank account, credit or debit card information, billing address) to process your payment in order to fulfill your orders and provide you with products or services you have requested, in order to perform our contract with you.

- When you visit our Site, open or click on emails we send you, or interact with our Services or advertisements, we, or third parties we work with, may automatically collect certain information using online tracking technologies such as pixels, web beacons, software developer kits, third-party libraries, and cookies.

Any information we obtain from third parties will be treated in accordance with this Privacy Policy.  We are not responsible or liable for the accuracy of the information provided to us by third parties and are not responsible for any third party's policies or practices.  For more information, see the section below, Third Party Websites and Links.

How We Use Your Personal Information

- Providing Products and Services.  We use your personal information to provide you with the Services in order to perform our contract with you, including to process your payments, fulfill your orders, to send notifications to you related to your account, purchases, returns, exchanges or other transactions, to create, maintain and otherwise manage your account, to arrange for shipping, facilitate any returns and exchanges and to enable you to post reviews.

- Marketing and Advertising.  We use your personal information for marketing and promotional purposes, such as to send marketing, advertising and promotional communications by email, text message or postal mail, and to show you advertisements for products or services.  This may include using your personal information to better tailor the Services and advertising on our Site and other websites.

- Security and Fraud Prevention.  We use your personal information to detect, investigate or take action regarding possible fraudulent, illegal or malicious activity.  If you choose to use the Services and register an account, you are responsible for keeping your account credentials safe.  We highly recommend that you do not share your username, password, or other access details with anyone else.  If you believe your account has been compromised, please contact us immediately.

- Communicating with you.  We use your personal information to provide you with customer support and improve our Services.  This is in our legitimate interests in order to be responsive to you, to provide effective services to you, and to maintain our business relationship with you.

Cookies:

Like many websites, we use Cookies on our Site.  For specific information about the Cookies that we use related to powering our store with Shopify, see https://www.shopify.com/legal/cookies.  We use Cookies to power and improve our Site and our Services (including to remember your actions and preferences), to run analytics and better understand user interaction with the Services (in our legitimate interests to administer, improve and optimize the Services).  We may also permit third parties and services providers to use Cookies on our Site to better tailor the services, products and advertising on our Site and other websites.

Most browsers automatically accept Cookies by default, but you can choose to set your browser to remove or reject Cookies through your browser controls.  Please keep in mind that removing or blocking Cookies can negatively impact your user experience and may cause some of the Services, including certain features and general functionality, to work incorrectly or no longer be available.  Additionally, blocking Cookies may not completely prevent how we share information with third parties such as our advertising partners.

How We Disclose Personal Information

In certain circumstances, we may disclose your personal information to third parties for legitimate purposes subject to this Privacy Policy.  Such circumstances may include:

- With vendors or other third parties who perform services on our behalf (e.g., IT management, payment processing, data analytics, customer support, cloud storage, fulfillment, and shipping).

- With business and marketing partners, including Shopify, to provide services and advertise to you.  For example, we use Shopify to support personalized advertising with third-party services.  Our business and marketing partners will use your information in accordance with their own privacy notices.

- When you direct, request us or otherwise consent to our disclosure of certain information to third parties, such as to ship you products or through your use of social media widgets or login integrations, with your consent.

- With our affiliates or otherwise within our corporate group, in our legitimate interests to run a successful business.

- In connection with a business transaction such as a merger or bankruptcy, to comply with any applicable legal obligations (including to respond to subpoenas, search warrants and similar requests), to enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.

We have, in the past twelve (12) months disclosed the following categories of personal information and sensitive personal information (denoted by *) about users for the purposes set out above in "How we Collect and Use your Personal Information" and "How we Disclose Personal Information":

Category:

- Identifiers such as basic contact details and certain order and account information

- Commercial information such as order information, shopping information and customer support information

- Internet or other similar network activity, such as Usage Data

Categories of Recipients:

- Vendors and third parties who perform services on our behalf (such as Internet service providers, payment processors, fulfillment partners, customer support partners and data analytics providers)

- Business and marketing partners

- Affiliates

We do not use or disclose sensitive personal information for the purposes of inferring characteristics about you.

Category of Personal Information

- Identifiers such as basic contact details and certain order and account information

- Commercial information such as records of products or services purchased and shopping information

- Internet or other similar network activity, such as Usage Data

Categories of Recipients

- Business and marketing partners

User Generated Content

The Services may enable you to post product reviews and other user-generated content.  If you choose to submit user generated content to any public area of the Services, this content will be public and accessible by anyone.

We do not control who will have access to the information that you choose to make available to others, and cannot ensure that parties who have access to such information will respect your privacy or keep it secure.  We are not responsible for the privacy or security of any information that you make publicly available, or for the accuracy, use or misuse of any information that you disclose or receive from third parties.

Third Party Websites and Links

Our Site may provide links to websites or other online platforms operated by third parties.  If you follow links to sites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions.  We do not guarantee and are not responsible for the privacy or security of such sites, including the accuracy, completeness, or reliability of information found on these sites.  Information you provide on public or semi-public venues, including information you share on third-party social networking platforms, may also be viewable by other users of the Services and/or users of those third-party platforms without limitation as to its use by us or by a third party.  Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the Services.

Children's Data

The Services are not intended to be used by children, and we do not knowingly collect any personal information about children.  If you are the parent or guardian of a child who has provided us with their personal information, you may contact us using the contact details set out below to request that it be deleted.

As of the Effective Date of this Privacy Policy, we do not have actual knowledge that we "share" or "sell" (as those terms are defined in applicable law) personal information of individuals under sixteen (16) years of age.

Security and Retention of Your Information

Please be aware that no security measures are perfect or impenetrable, and we cannot guarantee "perfect security."  In addition, any information you send to us may not be secure while in transit.  We recommend that you do not use unsecure channels to communicate sensitive or confidential information to us.

How long we retain your personal information depends on different factors, such as whether we need the information to maintain your account, to provide the Services, comply with legal obligations, resolve disputes or enforce other applicable contracts and policies.

Your Rights and Choices

Depending on where you live, you may have some or all of the rights listed below in relation to your personal information.  However, these rights are not absolute, may apply only in certain circumstances and, in certain cases, we may decline your request as permitted by law.

- Right to Access / Know. You may have a right to request access to personal information that we hold about you, including details relating to the ways in which we use and share your information.

- Right to Delete. You may have a right to request that we delete personal information we maintain about you.

- Right to Correct. You may have a right to request that we correct inaccurate personal information we maintain about you.

- Right of Portability. You may have a right to receive a copy of the personal information we hold about you and to request that we transfer it to a third party, in certain circumstances and with certain exceptions.

- Right to Opt out of Sale or Sharing or Targeted Advertising.  You may have a right to direct us not to "sell" or "share" your personal information or to opt out of the processing of your personal information for purposes considered to be "targeted advertising", as defined in applicable privacy laws.  Please note that if you visit our Site with the Global Privacy Control opt-out preference signal enabled, depending on where you are, we will automatically treat this as a request to opt-out of the "sale" or "sharing" of information for the device and browser that you use to visit the Site.

- Right to Limit and/or Opt out of Use and Disclosure of Sensitive Personal Information.  You may have a right to direct us to limit our use and/or disclosure of sensitive personal information to only what is necessary to perform the Services or provide the goods reasonably expected by an average individual.

- Restriction of Processing:  You may have the right to ask us to stop or restrict our processing of personal information.

- Withdrawal of Consent:  Where we rely on consent to process your personal information, you may have the right to withdraw this consent.

- Appeal:  You may have a right to appeal our decision if we decline to process your request.  You can do so by replying directly to our denial.

- Managing Communication Preferences:  We may send you promotional emails, and you may opt out of receiving these at any time by using the unsubscribe option displayed in our emails to you. If you opt out, we may still send you non-promotional emails, such as those about your account or orders that you have made.

You may exercise any of these rights where indicated on our Site or by contacting us using the contact details provided below.

We will not discriminate against you for exercising any of these rights. We may need to collect information from you to verify your identity, such as your email address or account information, before providing a substantive response to the request.  In accordance with applicable laws, You may designate an authorized agent to make requests on your behalf to exercise your rights.  Before accepting such a request from an agent, we will require that the agent provide proof you have authorized them to act on your behalf, and we may need you to verify your identity directly with us. We will respond to your request in a timely manner as required under applicable law.

Complaints

If you have complaints about how we process your personal information, please contact us using the contact details provided below.  If you are not satisfied with our response to your complaint, depending on where you live you may have the right to appeal our decision by contacting us using the contact details set out below, or lodge your complaint with your local data protection authority.

ADDITIONAL INFORMATION FOR CALIFORNIA RESIDENTS


We are required under the California Consumer Privacy Act (“CCPA”) to provide users who reside in the State of California with the additional notices below.


The categories of Personal Information described below is collected by us and disclosed to the categories of third parties described below for business purposes (as used in this section of our Privacy Policy, “Personal Information” has the meaning provided in the CCPA):


Category

Examples

Third Parties to whom we may share Personal Information




Identifiers

Name, postal address, internet protocol address, email address, or other similar identifiers.

Vendors and service providers.


Advertising partners.


Analytics partners.




Categories of Personal Information in California Civil Code Section 1798.80(e).

Name, physical characteristics or description, address, telephone number, education, employment, employment history, credit card number, debit card number, or any other financial information, or medical information.

Vendors and service providers.





Characteristics of protected classifications under California or federal law.

Race or color, age (over 40), mental or physical disability, sex (including gender and pregnancy, childbirth, breastfeeding or related medical conditions), or medical condition.

Vendors and service providers.




Commercial Information

Records of products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.

Vendors and service providers.


Advertising partners.


Analytics partners.




Internet or other electronic network activity information.

Information regarding your interaction with an internet website, application, or advertisement

Advertising partners.




Geolocation data.

Physical location.

Advertising partners.




Professional or employment-related information.

Job application or resume information

Vendors and service providers.




Inferences drawn from Personal Information.


consumer profiles reflecting a consumer’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes

Advertising partners.


We may disclose all of the categories of Personal Information described above to third parties as required by law or similar disclosures.

The “Information We Collect” section of our Privacy Policy describes the categories of sources from which we collect your Personal Information. The “How We Use the Information We Collect” section describes the purposes for which we collect your Personal Information.


California residents can exercise the following rights:


You have the right to request a copy of the Personal Information we have collected about you in the previous twelve (12) months.


You have the right to request details about the categories of Personal Information we collect, the categories of sources, the business or commercial purposes for collecting Personal Information, and the categories of third parties with whom we share Personal Information.


Subject to certain exceptions, you have the right to request deletion of the Personal Information we have collected about you.


You have the right to opt out of the sale of your Personal Information.


You have the right to make these requests, but we may not be able to honor a request if we are unable to verify your identity to the extent required by law.


California residents may submit access and deletion requests online by email at privacypolicy@invitehealth.com or by contacting our customer support team through our toll-free number:  (800) 349-0929.  Your authorized agent may submit an access or deletion request on your behalf by sending a written authorization signed by you to:


InVite Health, Inc.

136 Oak Drive

Syosset, New York  11791


We may still require you to directly verify your identity and confirm that you provided the authorized agent permission to submit the request.


The CCPA defines "selling" Personal Information to include providing it to a third party in exchange for valuable services.  We disclose identifiers and other internet activity to certain third parties in exchange for valuable services, such as to advertising partners and analytics partners, which might constitute a "sale" under the CCPA.  Click here to opt out of the sale of your Personal Information.


Subject to certain limitations, you have the right to not receive discriminatory treatment for the exercise of your CCPA privacy rights.


ADDITIONAL INFORMATION FOR VIRGINIA RESIDENTS


We are required under Virginia law to provide additional information to users who reside in Virginia about how information that may be considered "Personal Data " under Virginia Law ("VA Personal Data") is collected, used and disclosed.  You may have additional rights with regard to how we use and disclose your VA Personal Data.  Virginia law deems certain information about you to be "Sensitive Data", and we cannot process Sensitive Data without obtaining your consent unless the processing of such information falls under a legal exception.

Processing.  Consistent with the What Personal Information We Collect; How We Collect and Use Your Personal Information sections above, there are certain categories and specific pieces of VA Personal Data about individuals who reside in Virginia.  In the twelve (12) months prior to the date of this Privacy Policy, we may have collected the following types of categories of VA Personal Data, which may continue to be collected:

Identifiers:  for example, name, address, telephone number, email address, age, date of birth, username and password for our websites, online identifiers, IP address;

Commercial information:  for example, products or services purchased, obtained or considered, other purchasing or consuming histories or tendencies, payment information, health and medical information, health insurance information, loyalty program participation information;

Internet or other electronic network activity information:  for example, computer and connection information, statistics on page views, traffic to and from the websites, ad data and other standard weblog information;

Geolocation information:  including location data and precise location data such as physical location information through the use of our services on your mobile phone or device by, for example using satellite, cell phone tower, WiFi signal, beacons, Bluetooth and near field communication protocols, when you are in or near one of our stores;

Audio, visual, or similar information:  for example, photographs you share, in-store security video, customer service audio recordings;

Inferences drawn from the above categories of VA Personal Data:  for example, consumer preferences, characteristics, predispositions, and behavior; and

Sensitive Data:  for example, precise geolocation (within a radius of 1,750 feet).

Deidentified Information.  We may also maintain and use information that does not identify an individual and cannot reasonably be used to identify an individual which is derived from VA Personal Data.  We will not attempt to reidentify deidentified VA Personal Data unless permitted by law.   

Purposes.  VA Personal Data may be collected for the business and commercial purposes described in the What Personal Information We Collect; How We Collect and Use Your Personal Information sections as described above.  Specifically, we may collect VA Personal Data to respond to your inquiries, fulfill your requests and improve your experience; for marketing, advertising, and promotional purposes; for reporting and analytics; to improve the effectiveness of our services, conduct research and analysis, or for other internal operations purposes; to detect, prevent or investigate potential security breaches, fraudulent transactions and monitor against theft.

Sale and Targeted Advertising.  As described above in the What Personal Information We Collect; How We Collect and Use Your Personal Information, we may share the following categories of VA Personal Data with third parties who are considered "third parties" as defined under Virginia law.  In the twelve (12) months prior to the date of this Privacy Policy, we may have shared your VA Personal Data with third parties for purposes of "targeted advertising," which may constitute a "sale" of VA Personal Data under Virginia law, and may continue to share the following categories of VA Personal Data for "targeted advertising":

Identifiers:  for example, online identifiers, IP address;

Commercial information:  for example, products or services purchased, obtained or considered, other purchasing or consuming histories or tendencies;

Internet or other electronic network activity information:  for example, computer and connection information, statistics on page views, traffic to and from the websites, ad data and other standard weblog information; and

Inferences drawn from VA Personal Data:  for example, consumer preferences, characteristics, predispositions, and behavior.

The categories of third parties to which we may share the above-described categories of VA Personal Data include online advertising networks, marketing companies, financial services partners and social media companies.

Rights.  If you are a Virginia resident, you have the right to ask us for and access, including in a portable, readily usable format, the following types of information regarding the VA Personal Data we have collected about you:

Specific pieces of VA Personal Data we have collected about you;

Categories of VA Personal Data we have collected about you;

Categories of sources from which such VA Personal Data was collected;

Categories of VA Personal Data we sold or disclosed for a business purpose about you; and

The business or commercial purpose for collecting or selling your VA Personal Data.

You also have the right to request correction or deletion of your VA Personal Data and to opt out of the use of your VA Personal Data for purposes of targeted advertising, sale, and automated processing.  In addition, you have the right to appeal our refusal to act on your request.

Responding to Requests.  For requests for access, correction, deletion, or appeal, we will acknowledge receipt and provide a response as soon as possible.  For requests to opt out of the use of your VA Personal Data for purposes of targeted advertising, sale, and automated processing, we will comply within fifteen (15) business days after receipt of your request.

We may charge a reasonable fee to comply with your request, to the extent permitted by applicable law.  Upon request, we will provide this a copy of this Privacy Policy in alternative formats.  In some cases, the law may allow us to refuse to honor certain requests.  If this ever happens, we will endeavor to provide you with an explanation of the refusal.

How To Contact Us

If you have any questions regarding this Privacy Policy or our privacy practices, please call (800) 349-0929 or email us at privacypolicy@invitehealth.com or contact us at:

InVite Health, Inc.

136 Oak Drive

Syosset, New York  11791

We may periodically update this Privacy Policy without prior notice to reflect changes in our personal information practices.  We will post a notice on our website of significant changes to this Privacy Policy and indicate when it was most recently updated.

International Users

Please note that we may transfer, store and process your personal information outside the country you live in, including the United States.  Your personal information is also processed by staff and third-party service providers and partners in these countries.

If we transfer your personal information out of Europe, we will rely on recognized transfer mechanisms like the European Commission's Standard Contractual Clauses, or any equivalent contracts issued by the relevant competent authority of the UK, as relevant, unless the data transfer is to a country that has been determined to provide an adequate level of protection.

Contact

Should you have any questions about our privacy practices or this Privacy Policy, or if you would like to exercise any of the rights available to you, please call (800) 349-0929 or email us at privacypolicy@invitehealth.com or contact us at:

InVite Health, Inc.

136 Oak Drive

Syosset, New York  11791