Privacy Policy
Updated: September 1, 2022
Provider (“we”, or “us” or “company”) provides this Privacy Policy to explain how we collect, use, share and protect the information you provide and that we collect by administering your pharmacy benefits through the Member Portal, our member support representatives, and our mobile applications. BY USING THE MEMBER PORTAL, MOBILE APPLICATIONS, OR OTHERWISE GIVING US YOUR INFORMATION, YOU AGREE TO THE TERMS OF THIS PRIVACY POLICY. Please review this Policy carefully to ensure your understanding of our privacy practices. If you do not agree to this Privacy Policy, do not access the Member Portal, mobile applications, or give us any of your information. This Privacy Policy is incorporated by reference into our Terms of Service which you can review at Terms of Service. All capitalized but undefined terms in this Policy shall have the meaning ascribed to such terms in the Terms.
1. Information we collect
1.1 INFORMATION YOU PROVIDE
(a) Personally Identifiable Information. To use the Provider Member Portal, and thus become a “Member,” you will be required to provide us with certain Personally Identifiable Information as described below. We may collect some or all of this information through various forms and in various places through the Member Portal, the delivery of the services, or our mobile applications, including account registration forms, contact us forms, or when you otherwise interact with us. If you become a Member, you will be required to create a user profile account with us (“Account”). The current required data fields include, but are not necessarily limited to:
- Name
- Address (Billing & Shipping)
- Email address
- Password
- Home phone number
- Mobile phone number
- Credit card number, expiration date & security code and or information regarding your PayPal, Google Wallet or other digital payment accounts
- Contact information for users of the Services for purposes of receiving information about our products and services, such as prescription benefit, disease management, and specialty pharmacy services.
- Responses to surveys we send to you or your dependents and responses to those surveys
- Information we receive from your employer or health plan sponsor
1.2 INFORMATION WE COLLECT AS YOU ACCESS THE MEMBER PORTAL &MOBILE APPLICATIONS
(a) Generally. In addition to any Personally Identifiable Information or other information that you choose to submit to us, we and our third-party service providers may use a variety of technologies that automatically (or passively) collect certain information whenever you visit the Member Portal or access or use our mobile applications (“Non-Personally Identifiable Information”). Non-Personally Identifiable Information may include the browser that you are using and how and when you use the Member Portal. We may use Non-Personally Identifiable Information for various reasons, such as providing and enhancing the services for you and other users. In addition, we may collect your IP address or other unique identifier that identifies the device from which you access the Member Portal or our mobile applications. This identifier is a number that is automatically assigned to your device and which our computers use to identify you and your device. This information may be non-identifying or may be associated with you. If we associate any Non-Personally Identifiable Information or information that identifies your device with your Personally Identifiable Information, we will treat it as Personally Identifiable Information.
(b) Geo-Location Information. We may collect information as you navigate the Member Portal or use our mobile applications, which may include geographic location.
(c) Cookies. A cookie is a data file placed on a computer or other device when it is used to access the Member Portal or our mobile applications. A Flash cookie is a data file placed on a device via the Adobe Flash plug-in that may be built-in to or downloaded by you to your device. Cookies and Flash cookies may be used for many purposes, including, without limitation, remembering you and your preferences and tracking your visits to our web pages. Cookies work by assigning a number to the user that has no meaning outside of the assigning website.
If you do not want information to be collected through the use of cookies, your browser allows you to deny or accept the use of cookies. Cookies can be disabled or controlled by setting a preference within your web browser or on your device. If you choose to disable cookies or Flash cookies on your device, some features of the Member Portal or our mobile applications may not function properly or may not be able to customize the delivery of information to you.
You should be aware that we cannot control the use of cookies (or the resulting information) by third-parties and use of third-party cookies is not covered by our Privacy Policy.
(d) Web Beacons. Small graphic images or other web programming code called web beacons (also known as “1×1 GIFs” or “clear GIFs”) may be included in our web and mobile pages and messages. The web beacons are tiny graphics with a unique identifier, similar in function to cookies, and are used to track the online movements of Web users. In contrast to cookies, which are stored in a user’s computer hard drive, web beacons are embedded invisibly on Web pages and are about the size of the period at the end of this sentence. Web beacons or similar technologies help us better manage content on the Member Portal or our mobile applications by informing us what content is effective, monitor how users navigate the Member Portal, and manage the users’ experience on the Member Portal.
(e) Embedded Scripts. An embedded script is programming code that is designed to collect information about your interactions with the Member Portal, such as the links you click on. The code is temporarily downloaded onto your device from our web server or a third-party provider, is active only while you are connected to the Member Portal or our mobile applications, and is deactivated or deleted thereafter.
1.3 INFORMATION THIRD PARTIES PROVIDE ABOUT YOU
We may, from time to time, supplement the information we collect about you through our Site or App with outside records from third-parties in order to provide our services to you, enhance our ability to serve you, and to tailor our content to you and to offer. For example, we may collect information from third-party Providers that you visit when using the Member Portal and mobile applications.
1.4 INFORMATION COLLECTED BY OUR MOBILE APP
You may access the Member Portal and use the Services by accessing our mobile applications on a mobile device. By doing so, we may collect and use technical data and related information, including but not limited to, technical information about your device, system and application software, and peripherals, that is gathered periodically to facilitate the provision of software updates, product support and other Services to you (if any) related to our mobile applications. In addition, if you use our mobile applications, it may automatically collect and store some or all of the following information from your mobile device, including without limitation:
- Your preferred language and country site (if applicable)
- Your phone number or other unique device identifier assigned to your mobile device – such as the Mobile Equipment ID number
- The IP address of your mobile device
- The manufacturer and model of your mobile device
- Your mobile operating system
- The type of mobile Internet browsers you are using
- Your geolocation
- Information about how you interact with the Mobile Application and any of our web sites to which the application links, such as how many times you use a specific part of the mobile application over a given time period, the amount of time you spend using the application, how often you use the application, actions you take in the application and how you engage with the application
- Information to allow us to personalize the Services and content available through the mobile application
We may use information automatically collected by the mobile applications in the following ways:
- To operate and improve our Member Portal, mobile applications and Provider Service
- To create aggregated and anonymized information to determine which application features are most popular and useful to users, and for other statistical analyses
- To prevent, discover and investigate violations of this Privacy Policy or any applicable terms of Service or terms of use for the mobile applications, and to investigate fraud
1.5 USER INFORMATION.
Unless otherwise noted elsewhere in this Policy, Personally Identifiable Information and Non-Personally Identifiable Information shall be collectively referred to as “User Information”.
2. How We Use The Information Described in This Policy
2.1 TO PROVIDE OUR SERVICE.
We use your personal information to respond to your requests, such as to fulfill your order, contact you with information about your order, send you email alerts, send you newsletters, and provide you with related Member services. We may also use your information to send communications and administrative information to you, as permitted by law and our client agreements, including through the use of push notifications in our apps. We may use personal information to personalize your experience on the Services, including by presenting products and content tailored to you, and for our business purposes, such as data analysis, audits, fraud monitoring and prevention, developing our Services and new products and services, determining the effectiveness of our promotional campaigns, and operating and expanding our business activities.
2.2 PROVIDER BUSINESS PARTNERS.
We may disclose personal information to our service providers, who provide services such as website hosting, data analysis, payment processing, order fulfilment, information technology, specialty &mail pharmacy services, customer service, email delivery, auditing, and other services.
2.3 IP ADDRESS.
We use your Internet Protocol (IP) address to help diagnose problems with our computer server, and to administer our Site. Your IP address is used to help identify you, but contains no Personally Identifiable Information about you.
2.4 REGULATORY OR LEGAL REQUIREMENTS.
If we are requested by law enforcement officials or judicial authorities to provide personal information, we may do so. In matters involving claims of personal or public safety or in litigation where the information is pertinent (including to allow us to pursue available remedies or limit the damages that we may sustain), we may use or disclose personal information, including without court process. We may also use or disclose personal information to enforce our Terms of Service, to protect our operations or those of any of our affiliates, or to protect our rights, privacy, safety, or property and/or that of our affiliates, you, or others. We may use and disclose personal information to investigate security breaches or to cooperate with authorities.
2.5 SOCIAL MEDIA
We may use and disclose your personal information to facilitate social sharing functionality that you initiate. If you choose to connect your social media account with your Services account or otherwise engage in social sharing on the Services, your personal information may be shared with your friends, contacts, or others associated with your social media account, with other Services users, and with your social media account provider. By connecting your Services account and your social media account, you authorize us to share information with your social media account provider, and you understand that the use of the information we share will be governed by the social media site’s privacy policy
2.6 CHANGE OF OWNERSHIP
In the event that Provider or some or all of our business, assets, or stock are sold or transferred (including in connection with any bankruptcy or similar proceedings) or used as security, or to the extent we engage in business negotiations with third-parties, personal information may be transferred to or shared with third-parties as part of any such transaction or negotiation.
3. Account Cancellation
We will retain User Information for as long as an Account remains active. Even after an account is terminated, we may retain certain User Information as necessary to comply with our legal and regulatory obligations, resolve disputes, conclude any activities related to cancellation of an account (such as addressing chargebacks), investigate or prevent fraud and other inappropriate activity, to enforce our agreements, and for other business reasons consistent with applicable law.
4. Intended Members
Our Services are not directed to nor intended for use by minors under the age of 13. We do not intentionally collect Personally Identifiable Information from any person we know to be under 13, and instruct users under 13 not to send any information to or through our services. If we discover that we have collected Personally Identifiable Information from a person under 13, we will delete that information immediately. If you are a parent or guardian of a minor under the age of 13 and believe he or she has disclosed Personally Identifiable Information to us, please contact us.
The Services are designed for users from, and are controlled and operated by Provider from, the United States. By using the Services, you consent to the transfer of your information to the United States, which may have different data protection rules than those of your country.
5. Protected Health Information
To the extent that information collected through the Services is patient information provided to obtain or administer pharmacy services, such information is governed by the Provider Notice of HIPPA Privacy Practices located at Provider Notice of HIPAA Privacy Practices. If you have questions about which policy applies to specific information, please contact us at the member services number on the back of your member benefit card.
6. How we Protect Your Information
User Identifiable Information is stored within our databases using standard, industry-wide, commercially reasonable security practices and procedures such as encryption, firewalls and SSL (Secure Socket Layers). We also implement security measures required by law. However, as effective as such technology and efforts may be, no security system is infallible and impervious from attack or hacking. Therefore, we cannot guarantee the security of our databases, nor can we guarantee that User Information won’t be intercepted while being transmitted to us over the Internet or wireless communication, or accessed when stored on our or our service providers’ servers and any information you transmit to us, you do at your own risk. To help us protect your information, we strongly encourage you to not share your username or password with anyone.
7. Changes to this Policy
From time to time, we may update this Privacy Policy to reflect changes to our information practices. Any changes will be effective immediately upon the posting of the revised Privacy Policy. If we make any material changes, we will notify you by email (sent to the e-mail address specified in your account) or by means of a notice on the Provider website prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices.
8. Your California Privacy Rights
California’s “Shine the Light” law, California Civil Code § 1798.83, requires that certain businesses respond to requests from their California customers (those with whom we have an established business relationship) asking about the business’ practices related to disclosing Personally Identifiable Information to third-parties for the third-parties’ direct marketing purposes. We do not provide Personally Identifiable Information to third-parties for their direct marketing purposes without your express consent (opt-in).
9. Member Settings
You can manage your communications preferences in the Member Portal from your member dashboard. You may control the receipt of push notifications from Provider through your mobile device settings. If you choose to receive communications from us via e-mail or other electronic means, you acknowledge that you are electing to receive such information, which may contain your Protected Health Information as defined by HIPAA, through an unencrypted method of communication. You further acknowledge that the information contained in an unencrypted email and/or text message is at risk of being intercepted and read by, or disclosed to, unauthorized third-parties. You can request the removal or modification of the personal information you have provided to us by sending an email to the appropriate area under “Contact Information”. For your protection, we may only implement requests with respect to the personal information associated with the particular email address that you use to send us your request, and we may need to verify your identity and obtain information on the context in which you provided your personal information before implementing your request. We will try to accommodate your request as soon as reasonably practicable. There may also be residual information that will remain within our databases and other records, which will not be removed.
10. Member Responsibility
By establishing an account with us, you agree that it is your responsibility to:
- 1. Authorize, monitor, and control access to and use of your account, User ID, and password.
- 2. Promptly inform us of any need to deactivate a password or an account by calling member services at the number on your member benefit card.
11. Contact Information
If you have any questions or concerns about this Privacy Policy, please contact member services at the number on your member benefit card.
12. SingleCare Privacy Notice for California Residents
Effective Date: January 1, 2020. Last Reviewed on: January 1, 2022.
This Privacy Notice for California Residents Supplements the information contained in our general Privacy Policy and applies solely to all visitors, users, and others who reside in the State of California (‘consumers’ or ‘you’). We adopt this notice to comply with the California Consumer Privacy Act of 2018 (CCPA) and any terms defined in the CCPA have the same meaning when used in this Notice.
Information We Collect
Our Website collects information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, household, or device (“personal information”). Personal information does not include:
- Publicly available information from government records.
- Deidentified or aggregated consumer information.
- Information excluded from the CCPA’s scope, like
- health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data.
- personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FCRA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver’s Privacy Protection Act of 1994.
In particular, our Website has collected the following categories of personal information from users within the last twelve (12) months:
- Identifiers such as name, email address, street address, phone number, and IP address.
- Customer records such as telephone number and identification card number.
- Characteristic information such as age and gender.
- Commercial information such as prescriptions filled.
- Online activity such as search history and pages visited.
- Physical location such as ZIP codes, as well as actual location when granted access.
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers. | Identifiers include name, email address, street address, phone number, and IP address. | YES |
| B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)). | Personal information such as telephone number | YES |
| C. Protected classification characteristics under California or federal law. | Characteristic information such as age and gender are collected as part of signup and profile creation. | YES |
| D. Commercial information. | Commercial information such as prescription fill history and pharmacies visited are collected and stored. | YES |
| E. Biometric information. | Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data. | NO |
| F. Internet or other similar network activity. | Online activity includes search history, pages visited. | YES |
| G. Geolocation data. | Physical location such as ZIP codes entered to see pharmacies nearby, as well as actual location when visitors grant access. | YES |
| H. Sensory data. | Audio, electronic, visual, thermal, olfactory, or similar information. | NO |
| I. Professional or employment-related information. | Current or past job history or performance evaluations. | NO |
| J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)). | Education records directly related to a student maintained by an educational institution or party acting. | NO |
| K. Inferences drawn from other personal information. | Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. | NO |
We obtain the categories of personal information listed above from the following categories of sources:
- Directly from you. For example, via forms you complete as part of signup.
- Indirectly from you. For example, from observing your actions on our Website.
Use of Personal Information
- To create, maintain, customize, and secure your account with us.
- To provide you with support and to respond to your inquiries, including to investigate and address your concerns and monitor and improve our responses.
- To personalize your Website experience and to deliver content and product and service offerings relevant to your interests via email or text message (with your consent, where required by law).
- To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
- As described to you when collecting your personal information or as otherwise set forth in the CCPA.
- To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by us about our Website users is among the assets transferred.
We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
Sharing Personal Information
We may disclose your personal information to a third party for a business purpose. When we disclose personal information for a business purpose, we enter a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract.
We share your personal information for a business purpose with the following categories of third parties:
- Service providers.
- Parent or subsidiary organizations.
- Partners.
- Social media companies.
- Internet cookie data recipients like Google Analytics.
Disclosures of Personal Information for a Business Purpose
In the preceding twelve (12) months, Company has disclosed the following categories of personal information for a business purpose:
- Category A: Identifiers.
- Category B: California Customer Records personal information categories.
- Category C: Protected classification characteristics under California or federal law.
- Category D: Commercial information.
- Category F: Internet or other similar network activity.
- Category G: Geolocation data.
Sales of Personal Information
In the preceding twelve (12) months, Company has not sold personal information.
Your Rights and Choices
The CCPA provides consumers (California residents) with specific rights regarding their personal information. This section describes your CCPA rights and explains how to exercise those rights.
Access to Specific Information and Data Portability Rights
You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past 12 months. Once we receive and confirm your verifiable consumer request, we will disclose to you:
- The categories of personal information we collected about you.
- The categories of sources for the personal information we collected about you.
- Our business or commercial purpose for collecting that personal information.
- The categories of third parties with whom we share that personal information.
- If we disclosed your personal information for a business purpose, a list identifying the personal information categories that each category of recipient obtained.
Deletion Request Rights
You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies.
We may deny your deletion request if retaining the information is necessary for us or our service provider(s) to:
- Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- Debug products to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq).
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent.
- Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
- Comply with a legal obligation.
- Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
We do not provide these deletion rights for B2B personal information.
Exercising Access, Data Portability, and Deletion Rights
To exercise the access, data portability, and deletion rights described above, please submit a verifiable consumer request to us by either:
- Calling us at (888) 211-1608.
- Emailing us at legal@rxsense.com. Please include the following fields in your email:
- Full name.
- Email address
- Date of birth
- Full address.
- Phone number (Optional).
Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child. To designate yourself as an authorized agent, please attach a verifiable notarized document granting you permission to submit any such request on the minor’s behalf.
You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must:
- Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative, which may include fields listed above.
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you.
Making a verifiable consumer request does not require you to create an account with us. [However, we do consider requests made through your password protected account sufficiently verified when the request relates to personal information associated with that specific account.]
We will only use personal information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
For instructions on exercising sale opt-out rights, see Personal Information Sales Opt-Out and Opt-In Rights.
Response Timing and Format
We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing.
If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option.
Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
Suggest that you may receive a different price or rate for services or a different level or quality of services.
Deny you services.
Charge you different prices or rates for services, including through granting discounts or other benefits, or imposing penalties.
Provide you a different level or quality of services.