EyeLife logo

Privacy Policy

EyeLife | Website & Mobile Application

Effective Date: June 22, 2026 Last Updated: June 22, 2026

Introduction

EyeLife ("EyeLife," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and/or use our EyeLife mobile application (collectively, the "Services"). Our Services are designed to bring your eye care records, appointments, prescriptions, and provider communications into one secure platform.

Please read this Privacy Policy carefully. By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by all terms of this Privacy Policy. If you do not agree with its terms, please discontinue use of our Services immediately.

This policy applies to all users of our website, mobile application, and any related services, features, or content offered by EyeLife.

1. Information We Collect

1.1 Information You Provide Directly

We collect information you provide when you register for an account, use our Services, or communicate with us. This includes:

  • Full name, date of birth, and gender
  • Email address, phone number, and mailing address
  • Username and password
  • Eye care history, prescriptions, diagnoses, and treatment records
  • Insurance information and billing details
  • Provider names, clinic names, and appointment history
  • Communications you send to us, including support requests and feedback
  • Payment information (processed securely through third-party payment processors)

1.2 Health and Medical Information

Because EyeLife is a health-focused platform dealing with medical eye care, we may collect information that qualifies as Protected Health Information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA). This includes but is not limited to:

  • Eye care diagnoses and conditions (e.g., glaucoma, macular degeneration, diabetic retinopathy)
  • Vision prescriptions and optical records
  • Treatment plans and surgical history
  • Medications and allergies related to eye care
  • Provider notes and clinical documentation
  • Lab results and imaging records (e.g., retinal scans, OCT imaging)

Please refer to Section 7 (HIPAA and Health Information) for our full practices related to health data.

1.3 Information Collected Automatically

When you access our website or application, we and our third-party partners automatically collect certain technical information, including:

  • IP address and approximate location
  • Device type, operating system, and browser type
  • Pages visited, time spent, and navigation paths
  • Referring URLs and exit pages
  • Crash reports and error logs
  • Mobile device identifiers (such as IDFA or GAID)
  • App usage data and feature interaction patterns

1.4 Cookies and Tracking Technologies

We use cookies, web beacons, pixels, tags, and similar tracking technologies to collect and store information about your activity on our Services. These technologies help us:

  • Keep you logged in across sessions
  • Understand how users interact with our website and app
  • Measure the effectiveness of our advertising campaigns
  • Deliver relevant advertisements across third-party platforms
  • Detect and prevent fraud

You can manage your cookie preferences through your browser settings. Note that disabling cookies may affect the functionality of certain features of our Services. You may also opt out of interest-based advertising through the Digital Advertising Alliance (DAA) at optout.aboutads.info or the Network Advertising Initiative (NAI) at optout.networkadvertising.org.

2. How We Use Your Information

We use the information we collect for the following purposes:

2.1 Providing and Improving Our Services

  • Creating and managing your account
  • Storing, organizing, and surfacing your eye care records
  • Sending appointment reminders, prescription renewal alerts, and care notifications
  • Enabling communication with your eye care providers through the platform
  • Processing transactions and billing
  • Troubleshooting technical issues and improving platform performance

2.2 Marketing and Advertising

We work with third-party advertising and analytics providers, which may include social media platforms and search engines, who use cookies and tracking technologies to help us measure campaign performance and deliver relevant advertisements. These partners operate under their own privacy policies.

We do not share Protected Health Information (PHI) with advertising or analytics providers. Any data shared for advertising purposes is limited to non-health identifiers and general behavioral data that does not reveal your medical conditions or health history. See Section 7 for more detail.

2.3 Legal and Safety Purposes

  • Complying with applicable laws and regulations including HIPAA
  • Responding to legal requests, court orders, or government inquiries
  • Detecting and preventing fraud, abuse, or security threats
  • Enforcing our Terms of Service and other agreements

3. How We Share Your Information

3.1 With Service Providers

We share your information with trusted third-party service providers who assist us in operating our Services. These parties are contractually obligated to protect your data and may only use it for the purposes we specify. Categories of service providers include:

  • Cloud hosting and infrastructure providers
  • Payment processors
  • Customer support platforms
  • Email and SMS communication services
  • Analytics and performance measurement tools
  • Security and fraud detection services

3.2 With Advertising and Analytics Partners

We work with third-party advertising and analytics partners who assist us in measuring the performance of our marketing efforts and delivering relevant content to prospective users. These partners may receive non-health data such as hashed contact identifiers, device identifiers, and general behavioral event data. They operate under their own privacy policies and are not permitted to use your information for any purpose other than those specified by us.

3.3 With Eye Care Providers

With your explicit consent, we may share your records and health information with eye care providers, specialists, or other healthcare professionals you authorize through the platform. This is core to the EyeLife product experience and governed by our HIPAA-compliant authorization processes.

3.4 Business Transfers

If EyeLife is involved in a merger, acquisition, sale of assets, or similar transaction, your information may be transferred as part of that transaction. You will be notified via email and/or a prominent notice on our website of any change in ownership or use of your personal or health information.

3.5 Legal Requirements

We may disclose your information if required to do so by law or in the good-faith belief that such disclosure is necessary to comply with legal process, protect our rights, or prevent harm.

4. Data Retention

We retain your personal information for as long as your account is active or as needed to provide Services, comply with legal obligations, resolve disputes, and enforce our agreements. Health records may be subject to longer retention requirements under applicable state and federal law. When retention is no longer necessary, we securely delete or anonymize your data.

EU/EEA users should note that we retain personal data only for as long as necessary for the purposes described in this policy, consistent with GDPR requirements. Specific retention periods vary by data category and are available upon request by contacting us at privacy@eyelifellc.com.

You may request deletion of your account and associated non-health personal data at any time by contacting us at privacy@eyelifellc.com. Note that certain data may be retained as required by law or for legitimate business purposes even after an account deletion request.

5. Your Privacy Rights and Choices

5.1 General Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information (subject to legal limitations)
  • Portability: Request your data in a portable format
  • Objection: Object to certain uses of your data, including for marketing purposes
  • Restriction: Request that we restrict certain processing activities
  • Withdrawal of Consent: Where processing is based on consent, withdraw that consent at any time

To exercise any of these rights, please contact us at privacy@eyelifellc.com. We will respond to your request within the timeframe required by applicable law.

5.2 California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including:

  • The right to know what personal information is being collected and how it is used
  • The right to delete personal information (with exceptions)
  • The right to opt out of the "sale" or "sharing" of your personal information for cross-context behavioral advertising
  • The right to correct inaccurate personal information
  • The right to limit the use of sensitive personal information
  • The right to non-discrimination for exercising your privacy rights

California residents may submit privacy requests by contacting us at privacy@eyelifellc.com or by calling the number listed in Section 14. We will verify your identity before processing your request.

Do Not Sell or Share My Personal Information: To opt out of the sharing of your personal information with advertising partners for purposes of cross-context behavioral advertising, please contact us directly at privacy@eyelifellc.com.

5.3 Other U.S. State Privacy Laws

Residents of Colorado, Connecticut, Virginia, Texas, and other states with comprehensive privacy laws may have similar rights as those described above. Contact us at privacy@eyelifellc.com to exercise any applicable rights.

6. Data Security

We take the security of your information seriously. We implement administrative, technical, and physical safeguards designed to protect your data from unauthorized access, disclosure, alteration, and destruction. Our security practices include:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Role-based access controls and multi-factor authentication for internal systems
  • Regular security audits and vulnerability assessments
  • Employee training on data privacy and security
  • Incident response procedures in the event of a data breach

No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. In the event of a breach involving your personal data, we will notify you as required by applicable law.

7. HIPAA and Health Information

To the extent that EyeLife functions as a covered entity or business associate under HIPAA, we are committed to handling Protected Health Information (PHI) in compliance with applicable HIPAA Rules.

7.1 Notice of Privacy Practices

If you receive health-related services through EyeLife, you may receive a separate HIPAA Notice of Privacy Practices (NPP) which describes in detail how we use and disclose your PHI, your rights as a patient, and how to file a complaint if you believe your privacy rights have been violated.

7.2 Use and Disclosure of PHI

We use and disclose PHI only as permitted or required under HIPAA, including:

  • For treatment, payment, and healthcare operations (TPO) purposes
  • With your written authorization for any other purpose
  • As required by law (e.g., public health reporting, legal proceedings)
  • In emergency circumstances to prevent serious harm

7.3 Separation of PHI from Advertising Data

We maintain strict operational separation between PHI stored for healthcare purposes and non-PHI data used for advertising and marketing. Diagnoses, treatment records, prescription data, and all other PHI are never transmitted to advertising or analytics platforms. Any data shared with such platforms is limited to hashed contact identifiers and general behavioral events that do not reveal health status.

7.4 Business Associate Agreements

Where required by HIPAA, we enter into Business Associate Agreements (BAAs) with third-party vendors who may access, store, or process PHI on our behalf.

7.5 Patient Rights Under HIPAA

As applicable under HIPAA, you have the right to:

  • Access your PHI held by EyeLife
  • Request amendments to your PHI
  • Receive an accounting of disclosures of your PHI
  • Request restrictions on certain uses and disclosures
  • Receive communications via alternative means or locations
  • File a complaint with EyeLife or the U.S. Department of Health and Human Services (HHS) Office for Civil Rights

8. Advertising Practices

EyeLife engages in digital advertising to reach prospective users. Our advertising efforts are conducted in compliance with applicable platform policies and privacy laws. We do not use health condition data, diagnoses, or prescription information to target advertising to users. Our advertising audiences are built using general behavioral data, geographic targeting, and hashed contact information where permitted, not medical profiles.

9. Children's Privacy

Our Services are not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13 without verified parental consent. If you believe we have inadvertently collected information from a child under 13, please contact us immediately at privacy@eyelifellc.com and we will take steps to delete such information. For users between 13 and 17, a parent or legal guardian must review and agree to this Privacy Policy on their behalf.

10. Third-Party Links and Services

Our Services may contain links to third-party websites or integrate with third-party platforms such as insurance portals or provider scheduling systems. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party service you access through our platform.

11. International Users

EyeLife is based in the United States. If you access our Services from outside the United States, your information may be transferred to and processed in the United States, which may have different data protection laws than your home country. By using our Services, you consent to the transfer and processing of your information in the United States in accordance with this Privacy Policy.

Users in the European Economic Area (EEA), United Kingdom, or Switzerland should refer to Section 12 below for your full set of rights and protections under the General Data Protection Regulation (GDPR) and applicable national laws.

12. European User Rights (GDPR)

This section applies to users located in the European Economic Area (EEA), the United Kingdom (UK), and Switzerland. EyeLife is committed to complying with the General Data Protection Regulation (GDPR) and applicable national data protection laws for these users.

12.1 Data Controller

EyeLife acts as the data controller for personal data collected through our website and mobile application. If you are an EU/EEA user with questions about how we process your data, you may contact our designated privacy contact at privacy@eyelifellc.com.

12.2 Legal Bases for Processing

We only process your personal data when we have a valid legal basis to do so. Depending on the specific processing activity, we rely on one or more of the following legal bases:

  • Contract Performance: Processing necessary to provide the Services you have signed up for, including account management, record storage, and appointment features
  • Legal Obligation: Processing required to comply with applicable law, including HIPAA, tax obligations, and regulatory requirements
  • Legitimate Interests: Processing for purposes such as fraud prevention, security, service improvement, and internal analytics, where those interests are not overridden by your rights
  • Consent: Processing based on your freely given, specific, and informed consent, including for certain marketing communications and the use of non-essential cookies and tracking technologies. You may withdraw consent at any time without affecting the lawfulness of prior processing
  • Vital Interests: In rare emergency circumstances, to protect your life or the life of another person

We do not rely on legitimate interests as a basis for processing health data or other special category data. Special category data, including health information, is processed only with your explicit consent or where otherwise permitted under Article 9 of the GDPR.

12.3 Your GDPR Rights

If you are located in the EEA, UK, or Switzerland, you have the following rights under applicable data protection law:

  • Right of Access (Article 15): Request a copy of the personal data we hold about you and information about how we process it
  • Right to Rectification (Article 16): Request correction of inaccurate or incomplete personal data
  • Right to Erasure (Article 17): Request deletion of your personal data where there is no compelling reason for us to continue processing it
  • Right to Restriction of Processing (Article 18): Request that we limit the processing of your data in certain circumstances
  • Right to Data Portability (Article 20): Receive your personal data in a structured, machine-readable format and transmit it to another controller
  • Right to Object (Article 21): Object to processing based on legitimate interests or for direct marketing purposes at any time
  • Rights Related to Automated Decision-Making (Article 22): Not be subject to solely automated decisions that produce significant legal or similarly significant effects, without human review
  • Right to Withdraw Consent: Where processing is based on consent, withdraw that consent at any time by contacting us or using the opt-out mechanisms provided

To exercise any of these rights, please contact us at privacy@eyelifellc.com. We will respond within 30 days of receiving your request as required by GDPR. We may need to verify your identity before processing your request. There is no fee to exercise your rights, although we may charge a reasonable fee for manifestly unfounded or excessive requests.

12.4 International Data Transfers

When we transfer personal data from the EEA, UK, or Switzerland to the United States, we ensure appropriate safeguards are in place. We rely on the European Commission-approved Standard Contractual Clauses (SCCs) for such transfers, and equivalent mechanisms for UK and Swiss data where required. You may request a copy of the relevant transfer safeguards by contacting us at privacy@eyelifellc.com.

12.5 Data Protection Officer

EyeLife has designated a privacy contact responsible for overseeing data protection compliance. You may reach this contact at privacy@eyelifellc.com.

12.6 Right to Lodge a Complaint with a Supervisory Authority

If you are located in the EEA, UK, or Switzerland and believe that our processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with the data protection supervisory authority in your country of residence, place of work, or place of the alleged infringement. Key supervisory authorities include:

  • United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
  • Ireland: Data Protection Commission (DPC) — dataprotection.ie
  • Germany: Federal Commissioner for Data Protection and Freedom of Information (BfDI) — bfdi.bund.de
  • France: Commission Nationale de l'Informatique et des Libertés (CNIL) — cnil.fr
  • Other EEA member states: A full list of supervisory authorities is available at edpb.europa.eu

We encourage you to contact us first at privacy@eyelifellc.com so we have the opportunity to address your concern directly before you escalate to a supervisory authority.

12.7 Health Data Under GDPR

Health data is classified as special category data under GDPR Article 9 and is subject to heightened protections. EyeLife processes health data of EU/EEA users only where:

  • You have given explicit consent for one or more specified purposes
  • Processing is necessary for the purposes of preventive or occupational medicine, medical diagnosis, or provision of health care
  • Processing is necessary for reasons of public interest in the area of public health
  • Processing is required by applicable law

We do not share the health data of EU/EEA users with advertising or analytics platforms under any circumstances.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last Updated" date at the top of this policy and, where required by law, by sending you an email notification or displaying a prominent notice within the app or on our website. Your continued use of our Services after any changes become effective constitutes your acceptance of the revised policy.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.

14. Contact Us

If you have questions, concerns, or requests related to this Privacy Policy or our data practices, please contact us:

EyeLife LLC
16413 S 36th St.
Phoenix, AZ 85048
Email: privacy@eyelifellc.com
Website: eyelifellc.com

For HIPAA-related concerns or to submit a privacy complaint, you may also contact the U.S. Department of Health and Human Services Office for Civil Rights at www.hhs.gov/ocr.

For EU/EEA users wishing to lodge a formal complaint with a supervisory authority, please refer to Section 12.6 above.

© EyeLife LLC · Confidential