EyeLife | Website & Mobile Application
EyeLife ("EyeLife," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and/or use our EyeLife mobile application (collectively, the "Services"). Our Services are designed to bring your eye care records, appointments, prescriptions, and provider communications into one secure platform.
Please read this Privacy Policy carefully. By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by all terms of this Privacy Policy. If you do not agree with its terms, please discontinue use of our Services immediately.
This policy applies to all users of our website, mobile application, and any related services, features, or content offered by EyeLife.
We collect information you provide when you register for an account, use our Services, or communicate with us. This includes:
Because EyeLife is a health-focused platform dealing with medical eye care, we may collect information that qualifies as Protected Health Information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA). This includes but is not limited to:
Please refer to Section 7 (HIPAA and Health Information) for our full practices related to health data.
When you access our website or application, we and our third-party partners automatically collect certain technical information, including:
We use cookies, web beacons, pixels, tags, and similar tracking technologies to collect and store information about your activity on our Services. These technologies help us:
You can manage your cookie preferences through your browser settings. Note that disabling cookies may affect the functionality of certain features of our Services. You may also opt out of interest-based advertising through the Digital Advertising Alliance (DAA) at optout.aboutads.info or the Network Advertising Initiative (NAI) at optout.networkadvertising.org.
We use the information we collect for the following purposes:
We work with third-party advertising and analytics providers, which may include social media platforms and search engines, who use cookies and tracking technologies to help us measure campaign performance and deliver relevant advertisements. These partners operate under their own privacy policies.
We do not share Protected Health Information (PHI) with advertising or analytics providers. Any data shared for advertising purposes is limited to non-health identifiers and general behavioral data that does not reveal your medical conditions or health history. See Section 7 for more detail.
We share your information with trusted third-party service providers who assist us in operating our Services. These parties are contractually obligated to protect your data and may only use it for the purposes we specify. Categories of service providers include:
We work with third-party advertising and analytics partners who assist us in measuring the performance of our marketing efforts and delivering relevant content to prospective users. These partners may receive non-health data such as hashed contact identifiers, device identifiers, and general behavioral event data. They operate under their own privacy policies and are not permitted to use your information for any purpose other than those specified by us.
With your explicit consent, we may share your records and health information with eye care providers, specialists, or other healthcare professionals you authorize through the platform. This is core to the EyeLife product experience and governed by our HIPAA-compliant authorization processes.
If EyeLife is involved in a merger, acquisition, sale of assets, or similar transaction, your information may be transferred as part of that transaction. You will be notified via email and/or a prominent notice on our website of any change in ownership or use of your personal or health information.
We may disclose your information if required to do so by law or in the good-faith belief that such disclosure is necessary to comply with legal process, protect our rights, or prevent harm.
We retain your personal information for as long as your account is active or as needed to provide Services, comply with legal obligations, resolve disputes, and enforce our agreements. Health records may be subject to longer retention requirements under applicable state and federal law. When retention is no longer necessary, we securely delete or anonymize your data.
EU/EEA users should note that we retain personal data only for as long as necessary for the purposes described in this policy, consistent with GDPR requirements. Specific retention periods vary by data category and are available upon request by contacting us at privacy@eyelifellc.com.
You may request deletion of your account and associated non-health personal data at any time by contacting us at privacy@eyelifellc.com. Note that certain data may be retained as required by law or for legitimate business purposes even after an account deletion request.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
To exercise any of these rights, please contact us at privacy@eyelifellc.com. We will respond to your request within the timeframe required by applicable law.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including:
California residents may submit privacy requests by contacting us at privacy@eyelifellc.com or by calling the number listed in Section 14. We will verify your identity before processing your request.
Do Not Sell or Share My Personal Information: To opt out of the sharing of your personal information with advertising partners for purposes of cross-context behavioral advertising, please contact us directly at privacy@eyelifellc.com.
Residents of Colorado, Connecticut, Virginia, Texas, and other states with comprehensive privacy laws may have similar rights as those described above. Contact us at privacy@eyelifellc.com to exercise any applicable rights.
We take the security of your information seriously. We implement administrative, technical, and physical safeguards designed to protect your data from unauthorized access, disclosure, alteration, and destruction. Our security practices include:
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. In the event of a breach involving your personal data, we will notify you as required by applicable law.
To the extent that EyeLife functions as a covered entity or business associate under HIPAA, we are committed to handling Protected Health Information (PHI) in compliance with applicable HIPAA Rules.
If you receive health-related services through EyeLife, you may receive a separate HIPAA Notice of Privacy Practices (NPP) which describes in detail how we use and disclose your PHI, your rights as a patient, and how to file a complaint if you believe your privacy rights have been violated.
We use and disclose PHI only as permitted or required under HIPAA, including:
We maintain strict operational separation between PHI stored for healthcare purposes and non-PHI data used for advertising and marketing. Diagnoses, treatment records, prescription data, and all other PHI are never transmitted to advertising or analytics platforms. Any data shared with such platforms is limited to hashed contact identifiers and general behavioral events that do not reveal health status.
Where required by HIPAA, we enter into Business Associate Agreements (BAAs) with third-party vendors who may access, store, or process PHI on our behalf.
As applicable under HIPAA, you have the right to:
EyeLife engages in digital advertising to reach prospective users. Our advertising efforts are conducted in compliance with applicable platform policies and privacy laws. We do not use health condition data, diagnoses, or prescription information to target advertising to users. Our advertising audiences are built using general behavioral data, geographic targeting, and hashed contact information where permitted, not medical profiles.
Our Services are not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13 without verified parental consent. If you believe we have inadvertently collected information from a child under 13, please contact us immediately at privacy@eyelifellc.com and we will take steps to delete such information. For users between 13 and 17, a parent or legal guardian must review and agree to this Privacy Policy on their behalf.
Our Services may contain links to third-party websites or integrate with third-party platforms such as insurance portals or provider scheduling systems. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party service you access through our platform.
EyeLife is based in the United States. If you access our Services from outside the United States, your information may be transferred to and processed in the United States, which may have different data protection laws than your home country. By using our Services, you consent to the transfer and processing of your information in the United States in accordance with this Privacy Policy.
Users in the European Economic Area (EEA), United Kingdom, or Switzerland should refer to Section 12 below for your full set of rights and protections under the General Data Protection Regulation (GDPR) and applicable national laws.
This section applies to users located in the European Economic Area (EEA), the United Kingdom (UK), and Switzerland. EyeLife is committed to complying with the General Data Protection Regulation (GDPR) and applicable national data protection laws for these users.
EyeLife acts as the data controller for personal data collected through our website and mobile application. If you are an EU/EEA user with questions about how we process your data, you may contact our designated privacy contact at privacy@eyelifellc.com.
We only process your personal data when we have a valid legal basis to do so. Depending on the specific processing activity, we rely on one or more of the following legal bases:
We do not rely on legitimate interests as a basis for processing health data or other special category data. Special category data, including health information, is processed only with your explicit consent or where otherwise permitted under Article 9 of the GDPR.
If you are located in the EEA, UK, or Switzerland, you have the following rights under applicable data protection law:
To exercise any of these rights, please contact us at privacy@eyelifellc.com. We will respond within 30 days of receiving your request as required by GDPR. We may need to verify your identity before processing your request. There is no fee to exercise your rights, although we may charge a reasonable fee for manifestly unfounded or excessive requests.
When we transfer personal data from the EEA, UK, or Switzerland to the United States, we ensure appropriate safeguards are in place. We rely on the European Commission-approved Standard Contractual Clauses (SCCs) for such transfers, and equivalent mechanisms for UK and Swiss data where required. You may request a copy of the relevant transfer safeguards by contacting us at privacy@eyelifellc.com.
EyeLife has designated a privacy contact responsible for overseeing data protection compliance. You may reach this contact at privacy@eyelifellc.com.
If you are located in the EEA, UK, or Switzerland and believe that our processing of your personal data violates applicable data protection law, you have the right to lodge a complaint with the data protection supervisory authority in your country of residence, place of work, or place of the alleged infringement. Key supervisory authorities include:
We encourage you to contact us first at privacy@eyelifellc.com so we have the opportunity to address your concern directly before you escalate to a supervisory authority.
Health data is classified as special category data under GDPR Article 9 and is subject to heightened protections. EyeLife processes health data of EU/EEA users only where:
We do not share the health data of EU/EEA users with advertising or analytics platforms under any circumstances.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last Updated" date at the top of this policy and, where required by law, by sending you an email notification or displaying a prominent notice within the app or on our website. Your continued use of our Services after any changes become effective constitutes your acceptance of the revised policy.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.
If you have questions, concerns, or requests related to this Privacy Policy or our data practices, please contact us:
For HIPAA-related concerns or to submit a privacy complaint, you may also contact the U.S. Department of Health and Human Services Office for Civil Rights at www.hhs.gov/ocr.
For EU/EEA users wishing to lodge a formal complaint with a supervisory authority, please refer to Section 12.6 above.