INTRODUCTION
This Privacy Policy (“Privacy Policy”) describes the data protection practices of Friday Plans Inc. and its affiliates, (collectively, “Friday Plans,” “we,” “our,” or “us”), including when you visit any Friday Plans website that links to this Privacy Policy (collectively, our “Websites,” or “Site”), or otherwise provide data to Friday Plans. We refer to the Websites and other services provided by Friday Plans together in this Privacy Policy as the “Services.” This Privacy Policy is incorporated into our Terms of Use. All capitalized terms used in this Privacy Policy but not defined herein have the meanings assigned to them in the Terms of Use.
Privacy and data protection laws vary around the world and among the individual states, provinces, and districts or zones within certain countries. In some jurisdictions, privacy laws grant you, the data subject, and certain specific rights regarding your personal data. We refer to these types of privacy laws as “Comprehensive Privacy Laws.” Examples of Comprehensive Privacy Laws include the consumer privacy laws of several U.S. states, such as California. We therefore also use this notice to inform you of certain specific rights you have under the Comprehensive Privacy Laws with respect your personal data.
When we refer to “personal data” or “personal information” in this notice, we mean any information, data, or data element, whether in electronic or other form, that, alone or in combination with other elements, can be used to distinguish, trace, or discover your identity. Certain data privacy laws include specific elements or defined terms for what they consider to be personal data. Where such data privacy laws apply to our processing of your personal data, then the terms “personal data” and “personal information” includes the specific elements and defined terms required by such laws.
- Collecting Your Information
- Using Your Information
- Sharing Your Information
- How We Use Cookies
- Security of Your Information
- Policy for Children
- Links to Other Websites and Third Party Practices
- Submitting Information From Outside The United States
- Exercise Your Privacy Rights
- Retention Period
- Contacting Us
We reserve the right to make changes to this privacy policy (“Privacy Policy”) at any time and for any reason. Any changes will be reflected in a revised policy posted on the website www.fridayplans.com and we will alert you that there has been a change by updating the “Revised” date displayed on the Privacy Policy. If Friday Plans determines that such changes materially affect your privacy rights, we will provide additional notice to you.
Collecting Your Information
We may collect information about you in a variety of ways but generally speaking it is done either through (1) the information you provide to us, or (2) the information we collect from you via automated means or (3) information we receive from third parties. The types of information we may collect include, but are not limited to:
Information You Provide To Us
This is personal information you choose to provide in connection with completing request for a consultation or creating an account such as your name, phone number, address, email, or other activities in which you participate on the Site or services:
- Account registration and administration of your account;
- Processing your orders and requests for treatment;
- Questions, communications, or feedback you submit to us via forms, email, chat, or telephone;
- Your participation in research and surveys;
- Requests for customer support and technical assistance, including through online chat functionalities and telephone;
- Uploads or posts to the Services;
- Name, address, telephone number, date of birth, and email address;
- Information that we may receive from Physicians about your medical conditions, allergies, treatment options, physician referrals, prescriptions, and lab results or other related health information, such as your physical and emotional characteristics;
- Log-in credentials;
- Billing information, such as shipping address, credit or debit card number, verification number, expiration date, and identity verification information, collected by our payment processors on our behalf;
- Information about purchases or other transactions with us;
- Information about your customer service and account maintenance interactions with us;
- Demographic information such as your gender and age;
- Any other information you choose to directly provide to us in connection with you use of the Services.
Information We Collect About You
Information our servers automatically collect when you visit, use, or browse the Site, such as your IP address, your operating system, browser version, the address of a referring website, the pages you visit on the Site, the dates and times you visit the Site, device and usage information, such as language preferences, referring URLs, country, location, information about how and when you use our services and other technical information. If you access the Site from a mobile device, information about the type of mobile device you use. For more information about the types of cookies used and their purpose, please refer to the cookie policy section below.
Location Information
When you use the Services, we and our service providers may automatically collect general location information (e.g., IP address, city/state and or postal code associated with an IP address) from your computer or mobile device. This information allows us to enable access to content that varies based on a user’s general location. We do not track your precise geolocation.
Information We Collect From Social Media and Other Content Platforms
When you “like” or “follow” us on Facebook, Instagram, Twitter, or other social media sites, we may collect some information from you including your name, email address, and any comments or content you post relevant to us. We also collect your information if you sign up for one of our promotions or submit information to us through social media sites.
Information We Receive From Other Sources
We work closely with third parties (including, for example, third party intermediaries, such as the physicians, medical professionals, and pharmacies with whom we partner to provide you with the Services and their health care services, sub-contractors in technical, advertising networks, analytics providers, and search information providers). Such third parties will sometimes provide us with additional information about you.
Understanding HIPAA and Your Protected Health Information
The Health Insurance Portability and Accountability Act of 1996, and for the most part similar state laws (collectively “HIPAA”) applies to specific types of “covered entities”; it does not automatically apply to data even if that data is health or medical data.
Covered Entities under HIPAA are healthcare providers (doctors, clinics, dentists etc.), health plans (e.g, insurance companies) and healthcare clearing houses (specialized entities within the healthcare payments supply chain). Friday Plans is an ecommerce platform that does not meet any of those definitions and is therefore not a covered entity under HIPAA. As such, any data you provide to us, even health or medical data, is as between you and Friday Plans protected by this Privacy Policy instead of HIPAA. However, once accessed by or in the possession of the labs, pharmacies and licensed healthcare providers with whom we partner to help you make decisions about treatment options, that data becomes subject to HIPAA because those entities are (with some exceptions) “covered entities” under HIPAA.
What does this mean for you in practical terms?
When you view our Site, sign-up for newsletters or otherwise provide data before you create an account, you are interacting solely and directly with Friday Plans and no data you provide is subject to HIPAA.
Similarly, when you create an account, the basic information you provide, like your name, email address, shipping address, phone number, and some transactional data, is not “protected health information” subject to HIPAA.
When you take the next step after creating an account and begin the process of submitting information about conditions or issues you may want addressed by the products available on our Site, the information you provide will be accessed by a licensed healthcare provider. That access and the subsequent analysis and communications between you and the provider create a provider-patient relationship that Friday Plans is not involved in. The licensed provider will make available to you their Notices of Privacy Practices and other HIPAA required documents that are separate from this privacy policy.
Using Your Information
Over the past 12 months, the information we have collected from you and the information you have provided to us has been used for the following purposes:
Telehealth Services
Friday Plans will use your information as necessary to carry out and manage its telehealth services. This includes, scheduling and conducting appointments with your healthcare provider, providing you with access to your medical records, communicating with you about your care, billing you for our services.
General Use
Friday Plans will use your information as necessary to carry out and manage its Services. This includes, using your information to verify and administer your account, including processing payments and fulfilling orders (if applicable). We will use your information to communicate with you about Friday Plan's Services, your use of the Services or your inquiries related to the Services. Friday Plan will use your information to ensure that content from our Services is presented in the most effective manner for you and for your computer or device, allow you to participate in interactive features of our Services (when you choose to do so), and as part of our efforts to keep our Services safe and secure.
Improve Friday Plan's Services
Friday Plans continuously seeks to improve its Services. To do so, we conduct research to understand the effectiveness of our Services, improve our Services, and to better understand the Friday Plans community. If we publish the results of our research to others, such research will be presented in a de-identified and aggregate form such that individual users cannot be identified.
Promotional Communications
We will use your personal information to communicate with you by email, postal mail, phone, or text message about surveys, promotions, special events or our products and Services and those of our affiliates or third-party partners, and any of their related businesses. By creating an account and using this Website, you are giving your express permission to Friday Plans and their agents or vendors the right to contact you with targeted advertising materials by email, text message (SMS), telephone or cellphone, including the use of automated, predictive, programmable, or similar (“robodialers”) dialers or dialing software, or any other means of communication to provide promotional offers. To the extent applicable, you expressly acknowledge that you are solely responsible for all charges billed by your mobile
Marketing/Performance Analysis & Data Analytics
We will use your information to help us better understand your interests and needs, such as by engaging in analysis and research regarding use of the Services. We may use your information to measure or understand the effectiveness of advertising and content we serve to you and others, and to deliver and customize relevant advertising and content to you.
Combined Information
For the purposes discussed in this Privacy Policy, we may combine the information that we collect through the Services with information that we receive from other sources, both online and offline, and use and share such combined information in accordance with this Privacy Policy. We shall never combine the health data of two unrelated users.
Aggregate/De-Identified Data
We may aggregate and/or de-identify any information collected through the Services so that such information can no longer be linked to you or your device (“Aggregate/De-Identified Information”). We may use Aggregate/De-Identified Information for any purpose, including for research and marketing purposes, and may also share such data with any third parties, including advertisers, promotional partners, and sponsors. We may receive monetary and/or other compensation for sharing Aggregate/De-Identified Information with such third parties.
Sharing Your Information
We may share your information with third parties that perform services for or on our behalf for business purposes that include:
Healthcare Providers
We may share your information with healthcare providers in order to schedule and fulfill appointments so that the healthcare providers may provide medical evaluations or personalized consultations. This includes consultants, insurance companies, pharmacies, and other healthcare providers involved in your care.
Affiliates & Related Business Entities
We may share the information we collect with our affiliates or related business entities for the purposes of delivering products or services to you, ensuring a consistent level of service, and to enhance our products, services, and your customer experience.
Service Providers and Third Party Partners
We may allow selected service providers or processors, which will enable them to collect information about how you use the Site over time. This information may be used to, among other things, analyze and track data, determine the popularity of certain content, and better understand your online activity.
Transfer of Assets
If we reorganize or otherwise transfer some or all of the Site or our assets to another organization (such as in the course of a merger, dissolution, or liquidation), your information may be shared with the transferee; however, we will ask the transferee to honor commitments we made in this Privacy Policy.
Targeted Advertising
We do not sell or share your personal data.
Security and Fraud
We allow third parties to receive personal information from our users to provide both security and fraud protection to Friday Plans.
Required By Law
We may share your information as permitted or required by any applicable law in response to a subpoena or other legal process or as we deem necessary to investigate or remedy any actual or potential violation of our policies or to protect the rights, property, and safety of the Friday Plans or others, as we deem appropriate.
Security of Your Information
We have adopted, implemented and maintain an enterprise-wide corporate information security and privacy program that includes technical, organizational, administrative, and other security measures designed to protect, as required by applicable law, against reasonably anticipated or actual threats to the security of your personal information (the “Security Program”). Our Security Program was created with reference to the obligations set forth under the Health Insurance Portability and Accountability Act (“HIPAA”). It includes, among many other things, procedures for assessing the need for, and as appropriate, either employing encryption and multi-factor authentication or using equivalent compensating controls. We therefore have every reason to believe our Security Program is reasonable and appropriate for our business and the nature of foreseeable risks to the personal information we collect. We further periodically review and update our Security Program, including as required by applicable law.
Despite the significant investment we’ve made in, and our commitment to, the Security Program we cannot guarantee that your personal information, whether during transmission or while stored on our systems, otherwise in our care, or the care of our third-party vendors and service providers, will be free from either failed or successful attempts at unauthorized access or that loss or accidental destruction will never occur. Except for our duty under applicable law to maintain the Security Program, we necessarily disclaim, to the maximum extent the law allows, any other liability for any such theft or loss of, unauthorized access or damage to, or interception of any data or communications including personal information.
All that said, as part of our Security Program, we have specific incident response and management procedures that are activated whenever we become aware that your personal information was likely to have been compromised. Those procedures include mechanisms to provide, when circumstances and/or our legal obligations warrant, notice to all affected data subjects within the timeframes required by law, as well as to give them such other mitigation and protection services (such as the credit monitoring and ID theft insurance) as may be required by applicable law. We further require in the contracts with our vendors and business partners that they notify us immediately if they have any reason to believe that an incident adversely affecting personal information we provided to them has occurred.
Policy for Children
We do not use the Site to solicit information from or market to children under the age of 18. By using the Site, you represent that you are at least 18 years of age. We encourage parents and legal guardians to monitor their children’s internet usage and to instruct their children never to provide personal information through the Site or any other website without parental consent. If you believe a child has provided personal information to us via the Site, please contact us and we will use reasonable efforts to locate and delete the information.
Links to Other Websites and Third Party Practices
The Site may contain links to third party websites. It is our intent to provide links only to other quality websites. However, we have no control over these linked websites or, for that matter, any third parties. Any information collected by websites, other than the Site, is not covered by this Privacy Policy. We are not responsible for the content or privacy and security practices and policies of any third parties, including other websites that may be linked to or from the Site. We encourage you to read the provisions of privacy policies on other websites before providing them with your personal information.
Submitting Information From Outside The United States
We control and operate the online and mobile resources from within the United States of America (the “U.S.”). Information collected through the Site may be stored and processed in the United States or any other country in which our vendors or we maintain facilities. Although we do not actively block or monitor visitors from other countries, the Site is directed only at visitors from the U.S. As such, this Privacy Policy is consistent with U.S. law and practice and is not adapted to other laws (including European data security and privacy laws). Friday Plans will apply the applicable laws of the U.S., including as embodied in this Privacy Policy in place of data protections under your home country’s law. That is, you freely and unambiguously acknowledge that this Privacy Policy, not your home country’s laws, controls how we will collect, store, process, and transfer your personal information. Similarly, the English language version of this Privacy Policy is the controlling version regardless of any translation you may attempt.
Exercise Your Privacy Rights
Friday Plans takes privacy seriously. Where applicable under a Comprehensive Privacy Law, data subjects have certain rights which they can request for Friday Plans to fulfill. These requests can be made by either the data subject or an authorized agent. These rights include:
- The Right to Know. You have the right to request that Friday Plans disclose the personal data that Friday Plans has collected about you. If you wish to receive a copy of your medical record, please reach out to your medical provider directly;
- The Right to Amend. You have the right to correct any information that Friday Plans stores about you;
- The Right to Delete. You have the right to request that Friday Plans delete information that it maintains about you, subject to certain exceptions;
- The Right to Opt Out Of Your Personal Information Being Sold or Shared. We do not sell or share your personal information.
In order to exercise any of the rights detailed above, please contact us at legal@fridayplans.com. We will use your email as proof of verification unless otherwise prohibited. Exercising your rights under this section will not result in any discrimination by Friday Plans. We will treat you the same as any other user. If you disagree or dispute a decision that has been made on the scope or application of the rights described in this clause, you may appeal this decision by contacting legal@fridayplans.com.
We will respond to your request to exercise any of the above rights in writing (including via email), or orally if requested, as soon as practicable and in any event not more than within one month after receipt of your request. In exceptional cases, we may extend this period by up to two months and we will tell you why. If you would like to exercise any of these rights, please contact us using the contact details provided above.
Retention Period
Friday Plans shall only store personal information for as long as it is required. This is determined by considering the purposes for which it was obtained in accordance with applicable laws. Our retention period is based on (1) the nature of our relationship with the data subject and (2) any legal obligations we are bound to fulfill.
Contact Us
If you have questions or comments about this Privacy Policy, please email us at: legal@fridayplans.com. If you prefer, you may also contact us via at:
Friday Plans Inc.
1395 Brickell Ave #800
Miami, FL 33131