All policies

Privacy Policy

How we collect, use, secure, and share your information — and the choices and rights you have.

Effective
July 1, 2026
Version
2026-07-01
Entity
Vitamias, Inc.

1. Scope

This Privacy Policy explains how Vitamias, Inc. handles information collected through our website, booking flow, and portals. Your medical information is also protected health information ("PHI") under the Health Insurance Portability and Accountability Act ("HIPAA"); its use and disclosure are governed by our Notice of Privacy Practices, which controls in the event of any conflict with this policy.

2. Information we collect

  • Account information: legal name, email address, phone number, and date of birth.
  • Health information: intake and screening answers, allergies, medications, conditions, treatment records, and clinician notes.
  • Visit information: service address, ZIP code, appointment times, assigned nurse or partner office, and visit outcomes.
  • Payment information: billing details and the last four digits and brand of your card. Full card numbers are collected and stored by our payment processor, never by Vitamias.
  • Credentialing information (nurses and partner offices): licenses, certifications, insurance, and background-check results.
  • Technical information: IP address, device and browser type, and timestamps, which we log for security and audit purposes.

3. How we use information

  • To provide, schedule, and coordinate your care, and to route your visit to a qualified nurse or partner office.
  • To verify eligibility, including confirming that you are 18 or older.
  • To process payments, issue receipts, and prevent fraud.
  • To communicate with you about your appointments, results, and account.
  • To secure the platform, investigate incidents, and maintain the audit trail HIPAA requires.
  • To meet legal, licensing, tax, and public-health obligations.

4. We do not sell your information

Vitamias does not sell or share your personal information for cross-context behavioral advertising, and we never use your protected health information for marketing without your separate written authorization, which you may revoke at any time.

5. Who we share information with

We disclose information only as needed to deliver care or run the business, and only to recipients bound by confidentiality obligations:

  • Treating nurses, clinicians, and partner offices involved in your visit.
  • Business associates under written HIPAA business associate agreements — for example our hosting, database, email, and payment providers.
  • Regulators, licensing boards, and public-health authorities where the law requires it.
  • A successor entity in connection with a merger or acquisition, subject to the same protections.

6. Security

We maintain administrative, physical, and technical safeguards designed to protect your information, including encryption of data in transit and at rest, role-based access controls so that staff see only the minimum necessary information, per-account data scoping on every query, passwordless sign-in links that expire, audit logging, and workforce privacy training. No system is perfectly secure; if a breach of unsecured PHI occurs we will notify affected individuals as required by the HIPAA Breach Notification Rule.

7. Retention

Medical records are retained for at least the period required by California law and applicable federal regulation. Account, billing, and audit records are retained as long as needed for legal, accounting, and security purposes, then securely destroyed.

8. Your rights

Depending on where you live and the nature of the information, you may have the right to access, correct, delete, or receive a portable copy of your personal information, and to appeal a denial. Rights over your medical record are described in our Notice of Privacy Practices. To exercise a right, contact us using the details below; we will verify your identity before acting and will not discriminate against you for making a request.

9. Children

The platform is intended for adults. We do not knowingly collect information from anyone under 18. If we learn that we have, we will delete it promptly.

10. Contact

Privacy questions and requests may be directed to Vitamias, Inc., Attn: Privacy Officer, 1 Wellness Way, Suite 200, Los Angeles, CA 90015 — privacy@vitamias.health.

You may request a paper copy of this document at any time by writing to Vitamias, Inc., Attn: Privacy Officer, 1 Wellness Way, Suite 200, Los Angeles, CA 90015, or by emailing privacy@vitamias.health.