BPW Online Data Privacy Policy
Effective Date: August 29, 2024
Introduction
This Privacy Policy (“Privacy Policy“) describes the data protection practices of The BPW Group and its affiliates, including Revive MedSpa, Balance Point Wellness, and BPW Medical Billing Services (collectively, “BPW,”), including when you visit any BPW website that links to this Privacy Policy (including www.bpointwellness.com, www.revivemedspamd.com, www.bpwbilling.com (collectively, our “Websites“); or otherwise provide data to BPW. We refer to the Websites and other services provided by BPW together in this Privacy Policy as the “Services.”
PLEASE READ THIS PRIVACY POLICY CAREFULLY TO UNDERSTAND HOW WE HANDLE YOUR INFORMATION. IF YOU DO NOT AGREE TO THIS PRIVACY POLICY, PLEASE DO NOT USE THE SERVICES.
The Information We Collect and the Sources of Such Information
We obtain information about you through the means discussed below when you use the Services. Please note that we need certain types of information so that we can provide the Services to you. If you do not provide us with such information or ask us to delete it, you may no longer be able to access or use part or all of our Services.
- Information You Provide to Us
We collect a variety of information that you provide directly to us. For example, we collect information from you through:
- Requests for Services
- Processing your requests for treatment, including orders and requests made by your provider in connection with your care
- Questions, communications, or feedback you submit to us via forms or email
- Your participation in surveys
The specific types of information we collect will depend upon the Services you use, how you use them, and the information you choose to provide. The types of data we collect directly from you include:
- Identifiers, such as name, address, telephone number, date of birth, and email address
- Billing information, such as shipping address, credit or debit card number, verification number, and expiration date, collected by our payment processors on our behalf
- Commercial information, such as information about purchases or other transactions with us, including information about your healthcare provider, if applicable
- Demographic information such as your gender, age, marital status, and similar information in connection with the Services
- General geolocation information, such as city, state, or zip code.
- Information about others, such as if you provide a family or friend’s email address or contact information to allow access to your information or name them as an emergency contact
- User-generated content you post in public online forums on our Services or disclose to other users or your healthcare providers
- Sensitive Personal Information
- Health information, such as, but not limited to, information about your symptoms, medical history, diagnoses, treatment history, lifestyle, prescriptions, mental health, drug or alcohol use, genetics, treatment options, and relevant physical characteristics (e.g., your height and weight), as well as medical photos you upload, lab results, and your insurance information.
- Information about your sexual orientation
- Log-in credentials if you create an account on our portal
- Sensitive demographic data, such as race and ethnicity
- Identity verification information (e.g., driver’s license or other government-issued ID card or number) and your signature
- Contents of communications made via the Services
- Any other information you choose to provide us directly in connection with your use of the Services.
- Information We Collect Through Automated Means
We collect certain information about your use of the Services and the devices you use to access the Services, as described in this Section (“usage information”). As discussed further below, we and our service providers (which are third-party companies that work on our behalf) may use a variety of technologies, including cookies, SDKs, and similar tools, to assist in collecting this information. In some instances, such information may be considered sensitive personal information.
Our Websites. When you use our Websites, we collect and analyze information such as your IP address, browser types, browser language, operating system, the state or country from which you accessed the Services, software and hardware attributes (including device IDs) referring and exit pages and URLs, platform type, the number of clicks, files you download, domain names, landing pages, pages viewed and the order of those pages, the amount of time spent on particular pages, the terms you use in searches on our sites, the date and time you used the Services, error logs, and other similar information.
Location Information. When you use the Services, we and our service providers may automatically collect general location information (e.g., IP address, city/state and or postal code associated with an IP address) from your computer or mobile device. This information allows us to enable access to content that varies based on a user’s general location (e.g., to deliver content customized to your location).
Our Use of Cookies and Similar Online Tools. To collect the information discussed in this Section, we and our service providers use web server logs, cookies, tags, SDKs, tracking pixels, and other similar tracking technologies. We use these technologies to offer you a more tailored experience.
- A web server log is a file where website activity is stored.
- An SDK is a set of tools and/or code that we embed in our websites to allow third parties to collect information about how users interact with the Services.
- A cookie is a small text file that is placed on your computer or mobile device when you visit a site, that enables us to (1) recognize your computer/device, (2) store your preferences and settings, (3) understand the parts of the Services you have visited and used; (4), enhance your user experience by delivering and measuring the effectiveness of content and advertising tailored to your interests; (v) perform searches and analytics; and (5) assist with security and administrative functions.
- Tracking pixels (sometimes referred to as web beacons or clear GIFs) are tiny electronic tags with a unique identifier embedded in websites, online ads and/or email that are designed to (1) collect usage information like ad impressions or clicks and email open rates; (2) measure the popularity of the Services and associated advertising; and (3) access user cookies.
As we adopt additional technologies, we may also gather information through other methods.
Please note that you can change your settings to notify you when a cookie is being set or updated or to block cookies altogether. Please consult the “Help” section of your browser for more information (e.g., Internet Explorer, Google Chrome, Mozilla Firefox, or Apple Safari). Please note that by blocking, disabling, or managing any or all cookies, you may not have access to certain features or service offerings.
- Information We Collect From Social Media and Other Content Platforms
When you “like” or “follow” us on Facebook, Instagram, Twitter, or other social media platforms, we may collect some information from you, including your name, email address, and any comments or content you post that is relevant to us. We also collect your information if you sign up for one of our promotions or submit information to us through social media platforms.
If you access the Services through a third-party connection or log-in (e.g., through a social network or third-party authentication tool), you may allow us to have access to and store certain information from such third parties, depending on your settings on such services. If you do not wish to have this information disclosed, do not use these connections to access the Services. For a description of how these third parties handle your information, please refer to their privacy policies and terms of use, which may permit you to modify your privacy settings.
- Information We Receive From Other Sources
We work closely with third parties (including, for example, third-party intermediaries, such as physicians, medical professionals, and pharmacies, to provide you with the Services, as well as with advertising networks, analytics providers, marketing partners, and search information providers). Such third parties will sometimes provide us with additional information about you.
Purposes for How We Use Your Information
In connection with providing you with the Services, we may use your information for the following business purposes:
- Provide and Manage the Services:
- Carry out, improve, and manage the Services and, as applicable, facilitate the provision of health care services to you by physicians or other health care providers and ensure that the physicians or health care providers have the services and support necessary for health care operations.
- Provide you with technical support and customer service, and troubleshoot any technical issues or errors.
- Communicate with you about the Services, your use of the Services, or your inquiries related to the Services and send you communications on behalf of physicians or other health care providers utilizing the Services to meet your needs.
- Verify your identity and administer your account, including processing your payments, fulfilling your orders, and verifying the authenticity of your government-issued identification photo.
- Analyze and Improve the Services:
- Engage in internal research to understand the effectiveness of our Services, improve our Services, and better understand our user base. If we publish or provide the results of this research to others, such research will be presented in a de-identified and aggregate form such that individual users cannot be identified.
- Ensure that content from our Services is presented in the most effective manner for you and your computer or device, allow you to participate in interactive features of our Services (when you choose to do so), and as part of our efforts to keep our Services safe and secure.
- Help us better understand your interests and needs by engaging in analysis and research regarding the use of the Services.
- Advertising and Marketing:
- Communicate with you (in accordance with applicable legal requirements) by email, postal mail, or phone about surveys, promotions, special events or our products and Services and those of our subsidiaries, affiliates, and parent companies and any of their related businesses and those of our third-party partners.
- Provide you (in accordance with applicable legal requirements) with more relevant advertisements and personalized content, measure or understand the effectiveness of advertising and content we serve to you and others, and deliver and customize relevant advertising and content to you.
- Legal Purposes:
- Comply in good faith with any procedures, laws, and regulations that apply to us where necessary for our legitimate interests or the legitimate interests of others.
- Establish, exercise, or defend our legal rights where necessary for our legitimate interests or the legitimate interests of others, such as protecting against malicious, fraudulent, or illegal activity.
Combined Information. For the purposes discussed in this Privacy Policy, we may combine the information that we collect through the Services with information that we receive from other sources, both online and offline, and use and disclose such combined information in accordance with this Privacy Policy.
Aggregate/De-Identified Data. We may aggregate and/or de-identify any information collected through the Services so that such information can no longer be linked to you or your device (“Aggregate/De-Identified Information”). We may use Aggregate/De-Identified Information for any purpose, including for research and marketing purposes, and may also disclose such data to any third parties, including advertisers, promotional partners, and sponsors.
Online Analytics and Advertising
- Online Analytics
We may use third-party web analytics services (such as those of Google Analytics -including Google Signals, Google User-ID, and other Google Analytics features- Metabase, Amplitude, and MixPanel) on our Services to collect and analyze usage information through cookies and similar tools; engage in auditing, research, or reporting; assist with fraud prevention; try to locate the same unique users across multiple browsers or devices to better tailor services and features; and provide certain features to you. If you have a Google account with personalized advertising enabled through Google Signals, Google will also be able to gather analytics and engagement information from across the various devices you use to access the Services. To prevent Google from using your information for analytics (including cross-device tracking for personalization purposes), you may install the Google Analytics Opt-out Browser Add-on by clicking here. To opt out of Google Signals, please open your “Settings” app, locate and tap “Google,” select “Ads,” and turn ON “Opt out of Ads Personalization.” You may also be able to disable cross-device tracking through your Android or Apple device-based settings.
If you receive an email from us, we may use certain analytics tools, such as clear GIFs, to capture data, such as when you open our message or click on any links or banners our email contains. This data allows us to gauge the effectiveness of our communications and marketing campaigns.
- Online Advertising
The Services may integrate third-party advertising technologies (e.g., ad networks and ad servers such as Facebook, Google Ad Words, TikTok, and others) that use cookies, pixels, and other technologies to deliver relevant content and advertising for BPW products and research on the Services, as well as on other websites you visit and other applications you use. The ads may be based on various factors, such as the content of the page you are visiting and the information you enter, such as your searches, demographic data, and other information we collect from you. These ads may be based on your current activity or your activity over time and across other websites and online services.
We sometimes provide our customer information (such as email addresses) to service providers, who may “match” this information in de-identified form to cookies (or mobile ad identifiers) and other proprietary IDs in order to provide you with more relevant ads when you visit other websites and mobile applications.
If you are interested in more information about tailored browser advertising and how you can generally control cookies from being put on your computer to deliver tailored advertising, you may visit the Network Advertising Initiative’s Consumer Opt-Out link, the Digital Advertising Alliance’s Consumer Opt-Out link, or Your Online Choices to opt-out of receiving tailored advertising from companies that participate in those programs. To opt out of Google Analytics for display advertising or customize Google display network ads, visit the Google Ads Settings page. To update your advertising preferences with Facebook, click here. To update your advertising preferences with TikTok, click here. We do not control these opt-out links, whether these opt-out links change over time, or whether any particular company chooses to participate in the industry opt-out programs listed above. We are not responsible for any choices you make using these mechanisms or the continued availability or accuracy of these mechanisms.
For additional ways to opt out of online advertising activities, please see the “Your Rights and Choices” section below.
Please note that if you exercise the opt-out choices above, you will still see advertising when you use the Services, but it will not be tailored to you based on your online behavior over time.
- Notice Concerning Do Not Track
Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. We are committed to providing you with meaningful choices about the information collected on our Websites for third-party purposes, and that is why we provide the variety of opt-out mechanisms listed above. However, we do not currently recognize or respond to browser-initiated DNT signals. To learn more about Do Not Track, you can do so here. Please note that “Do Not Track” is a distinct privacy mechanism from the browser-based opt-out signals referenced below in the “Your Rights and Choices” section, which BPW does honor in accordance with applicable law.
How We Disclose Your Information
We may disclose your information for our business purposes in the following ways:
- Affiliates and Subsidiaries.We may disclose the information we collect within any BPW member or group (i.e., our subsidiaries and affiliates, including our ultimate holding company and its subsidiaries) to deliver products and services to you, ensure a consistent level of service across our products and services, and enhance our products, services, and your customer experience.
- Health Care Providers and Services.We disclose your information to health care providers: (i) to schedule and fulfill appointments and provide health care services as part of the Services, (ii) to whom you send messages through our Services, and (iii) for other treatment, payment or health care operations purposes, including pharmacy services, upon your request.
- Service Providers.We provide access to or disclose your information to select third parties who use the information to perform services on our behalf. They provide a variety of services to us, including billing, content/service enhancements, partner labs, sales, marketing, advertising, analytics, research, customer service, shipping and fulfillment, data hosting and storage, IT and security, fraud prevention, payment processing, and auditing, consulting, and legal services. These entities may also include healthcare organizations, pharmacies, and other third parties we use to support our business or in connection with the administration and support of the Services.
- Advertising Networks. Please see the “Online Advertising” section above for details about how we disclose information to advertising partners.
- Joint Product/Marketing Partners.These are entities that jointly offer or provide services or products with us. These entities collect and use data in accordance with their own terms and privacy policies.
- Protection of BPW and Others.By using the Services, you acknowledge and agree that we may access, retain and disclose the information we collect and maintain about you if required to do so by law or in a good faith belief that such access, retention or disclosure is reasonably necessary to: (a) comply with legal process (e.g. a subpoena or court order); (b) enforce our Terms of Use, this Privacy Policy, or other contracts with you, including investigation of potential violations thereof; (c) respond to claims that any content violates the rights of third parties; (d) respond to your requests for customer service; and/or (e) protect the rights, property or personal safety of BPW, its agents and affiliates, its users and/or the public. This includes exchanging information with other companies and organizations for fraud protection, and spam/malware prevention, and similar purposes.
- Business Transfers. As we continue to develop our business, we may buy, merge, or partner with other companies. In such transactions (including in contemplation of such transactions), user information may be among the transferred assets. If a portion or all of our assets are sold or transferred to a third party, customer information (including your email address) would likely be one of the transferred business assets. If such transfer is subject to additional mandatory restrictions under applicable laws, we will comply with such restrictions.
- Public Forums/User Interactions.Certain features of our Services make it possible for you to disclose comments publicly or with other users. Any information that you post publicly is not confidential, and we may use it for any purpose (including testimonials or other marketing materials). For example, if you submit a product review on one of our Websites, we may display your review (along with the name provided, if any) on other BPW Websites and on third-party websites. Any information you post openly in these ways will be available to the users you disclosed it to and potentially the public at large and may be accessible through third-party search engines. Accordingly, please take care when using these features. We are not responsible for how others use the information about you that you disclose to them through the Services.
- We may also disclose your information in other ways you direct us to and when we have your consent.
- Aggregate/De-Identified Information.We reserve the right to create Aggregate/De-Identified Data from the information we collect through the Services and our disclosure of such Aggregate/De-Identified Data is in our discretion.
Your Rights and Choices
Depending on the state in which you live, you may have legal rights with respect to your information. The types of requests you may be able to make are as follows:
- Information about the categories of information we process, our uses of your information, our sources of such information and our disclosure of such information
- Access to the information that BPW has collected about you and a copy of certain information in a portable format
- Correct certain information we have about you
- Deletion of the information we have about you.
You may make a request by emailing us at feedback@bpointwellness.com. Before we disclose, correct or delete information in response to any of these requests, we will need to verify your identity. Depending on the nature of your request, we may contact you for further information if appropriate to verify your identity. Note, however, that BPW will never ask you for sensitive personal or financial information when verifying your identity, and no BPW employee will ask you to tell them your password. If you are an authorized agent submitting a request on their behalf, we may require proof of the written authorization you have received before processing the request.
Certain information may be exempt from such requests under applicable law. For example, if the request prevents us from completing a transaction you initiated, interferes with our legal obligations, or affects legal matters, including a BPW user’s rights to data contained in their account, we cannot verify your identity or compliance with your request is not legally required and would involve disproportionate cost or effort. But in any event, we will respond to your request within a reasonable timeframe and provide you with an explanation. If we deny your request in whole or in part, the laws in your jurisdiction may provide you with the right to appeal our response. If applicable, we will provide you with information about your appeal options in our response to you.
BPW will not discriminate against anyone who makes a rights request, but in some cases, we will not be able to provide our Services to you without that information.
Depending on applicable law, you may have the right to appeal our decision to deny your request. We will provide information about how to exercise that right in our response denying the request. You also may have the right to lodge a complaint with a supervisory authority.
Opt out of sale of and disclosure of information for online targeted advertising. As explained in the Online Analytics and Advertising section above, and subject to applicable laws as discussed further below, BPW allows third parties to receive certain information such as cookies, IP address, device identifiers, hashed contact information, browsing behavior, and/or other activity to enable the delivery of targeted advertising to you. These activities may qualify as the “sale” of personal information or “sharing” or processing of personal information for targeted advertising, as defined in applicable law.
Residents of certain states may opt out of the sale of personal information or sharing or processing of their personal information through cookies, pixels, and similar online tools for targeted advertising. If you have a legally recognized browser-based opt-out preference signal turned on via your device browser (such as Global Privacy Control), we recognize such preference in accordance with and to the extent required by applicable law. Note, that if you use a cookie blocker such as Ghostery, it may block the visibility of this tool. You can also use an authorized agent to submit a request to opt out on your behalf if you provide the agent written permission to do so. We may require the agent to submit proof that you have authorized them to submit an opt-out request. In addition to advertising activities using cookies and pixels, we may also share user email addresses with advertising partners to provide you with more relevant advertising.
If you opt-out, you may still receive advertising. It just may not be tailored to your interests. Please note that if you use different browsers, devices, or services, you will need to opt-out on each browser or device where you want your choice to apply.
Marketing preferences
You may instruct us not to use your contact information to contact you by email, postal mail, or phone regarding products, services, promotions and special events that might appeal to your interests by contacting us using the information below. In commercial email messages, you can also opt-out by following the instructions located at the bottom of such emails. Please note that, regardless of your request, we may still use and disclose certain information as permitted by this Privacy Policy or as required by applicable law. For example, you may not opt out of certain operational emails, such as those reflecting our relationship or transactions with you.
Third-Party Services and Notice About Health Information
This Privacy Policy does not address, and we are not responsible for, the privacy, information, or other practices, including data privacy and security process and standards of any third parties, including physicians and other health care providers using the Services, the manufacturer of your mobile device and other IT hardware and software, and any other third party mobile application, website, or service to which our Services may contain a link. These third parties may, at times, gather information from or about you. We have no control over the privacy practices of these third parties. The collection, use, and disclosure of your information will be subject to the privacy policies of the third-party websites or services and not this Privacy Policy. We urge you to read the privacy and security policies of these third parties.
How We Protect Your Information
BPW takes a variety of technical and organizational security measures to protect your information against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access. However, no method of transmission over the Internet, and no means of electronic or physical storage, is absolutely secure. As such, you acknowledge and accept that we cannot guarantee the security of your information transmitted to, through, or on our Services or via the Internet and that any such transmission is at your own risk. Where we have given you (or where you have chosen) a password that enables you to access the Services, you are responsible for keeping this password confidential. We ask you not to provide your password to anyone. Anyone may view the information you disclose in public areas.
Retention of Your Information
We keep your information for no longer than necessary for the purposes for which it is processed. The length of time for which we retain information depends on the purposes for which we collected and used it, the nature and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure of the information, the purposes for which we process the information, and our legitimate interests, and/or as required to comply with applicable laws.
Children
We do not knowingly collect personal data from anyone under the age of 13 through our Services, and our Services are not directed to children under the age of 13. If we discover we have received any “personal information” (as defined under the Children’s Online Privacy Protection Act) from a child under the age of 13 in violation of this Privacy Policy, we will take reasonable steps to delete that information as quickly as possible.
Revisions to Our Privacy Policy
We reserve the right to change this Privacy Policy at any time to reflect changes in the law, our data collection and use practices, the features of our Services, or advances in technology. We will make the revised Privacy Policy accessible through the Services, so you should review it periodically. The date this Privacy Policy was last revised is identified at the top of the document. You are responsible for periodically monitoring and reviewing any updates to the Privacy Policy. If we make a material change to the Privacy Policy, we will provide you with appropriate notice in accordance with legal requirements. Your continued use of our websites after such amendments (and notice, where applicable) will be deemed your acknowledgment of these changes to this Privacy Policy.
Contacting Us
If you have any questions about this Privacy Policy or BPW’s privacy practices, please contact us at BPW Group. 11350 McCormick Rd. Exec Plaza 1, Suite 800, Hunt Valley, MD 21031. 410-800-2169