b:Rare PRIVACY POLICY

Introduction

b:Rare, Inc. (“b:Rare” “we,” or “us”) owns and operates the websites located at http://www.brarex.com and http://www.brarehealth.com (the “Websites”) and may have previously, now or in the future own and/or operate a brarex and/or brarehealth mobile application (collectively, the “Platform”). Your access and use of the Platform, any part thereof, or anything associated therewith, including its content (“Content”), any products or services provided through the Platform or otherwise by b:Rare, and any affiliated website, software or application owned or operated by b:Rare (collectively, including the Platform and the Content, the “Service”) are subject to this Privacy Policy unless specifically stated otherwise. Capitalized terms not otherwise defined in this Privacy Policy have the same meaning as set forth in the b:Rare Terms and Conditions (“Terms and Conditions”).


We are committed to respecting the privacy of users of the Service. We created this Privacy Policy (“Privacy Policy”) to tell you how b:Rare collects, uses and discloses information in order to provide you with the Service.

As with our Terms and Conditions, by creating, registering, or logging into an account through the Service, or otherwise accessing or using the Service, you are automatically accepting and acknowledging the most recent version of this Privacy Policy. If we make any changes to our Privacy Policy, we will post the revised Privacy Policy and update the “Last Revised” date of the Privacy Policy.

 

If you are using the Service on behalf of an individual other than yourself, you represent that you are authorized by such individual to act on such individual’s behalf and that such individual acknowledges the practices and policies outlined in this Privacy Policy.

No Use by Minors Permitted

 

Our Service is intended for use by individuals who are at least 18 years of age or such older age as may be required by applicable state laws in the jurisdiction in which an individual utilizes the Service. The Service is not designed or intended to attract, and is not directed to, children under eighteen (18) years of age, let alone thirteen (13) years of age. If we obtain actual knowledge that we have collected personal information through the Platform from a person under thirteen (13) years of age, we will use reasonable efforts to refrain from further using such personal information or maintaining it in retrievable form.

 

Furthermore, if you are under eighteen (18) years of age, then you (or your parent or legal guardian) may at any time request that we remove content or information about you that is posted on the Platform. Please submit any such request (“Request for Removal of Minor Information”) to either of the following:

 

By mail:b:Rare, Inc., attn: Privacy Officer, 1900 Camden Ave, San Jose, CA 95124, with a subject line of “Removal of Minor Information. If you send by mail, please send by U.S. Certified Mail, Return Receipt Requested to allow for confirmation of mailing, delivery and tracking.

By email: privacy@brarehealth.com with a subject line of “Removal of Minor Information”

For each Request for Removal of Minor Information, please state “Removal of Minor Information” in the email or letter subject line, and clearly state the following in the body of the request:

 

The nature of your request

The identity of the content or information to be removed

The location of the content or information on the Platform (e.g. by providing the URL)

That the request is related to the “Removal of Minor Information”

Your name, street address, city, state, zip code and email address, and whether you prefer to receive a response to your request by mail or email.

We will not accept any Request for Removal of Minor Information via telephone or facsimile. b:Rare is not responsible for failing to comply with any Request for Removal of Minor Information that is incomplete, incorrectly labeled or incorrectly sent.


Please note that we are not required to erase or otherwise eliminate, or enable erasure or elimination of such content or information in certain circumstances, such as, for example, when an international, federal, state, or local law, rule or regulation requires b:Rare to maintain the content or information; when the content or information is stored on or posted to the Site by a third party other than you (including any content or information posted by you that was stored, republished or reposted by the third party); when b:Rare anonymizes the content or information, so that you cannot be individually identified; when you do not follow the aforementioned instructions for requesting the removal of the content or information; and when you have received compensation or other consideration for providing the content or information.

The foregoing is a description of b:Rare’ voluntary practices concerning the collection of personal information through the Service from certain minors, and is not intended to be an admission that b:Rare is subject to the Children’s Online Privacy Protection Act, the Federal Trade Commission’s Children’s Online Privacy Protection Rule(s), or any similar international, federal, state, or local laws, rules, or regulations.

 

Protected Health Information

 

 

When you set up an account with b:Rare, you are creating a direct customer relationship with b:Rare that enables you to access and/or utilize the various functions of the Platform and the Service as a user. As part of that relationship, you provide information to b:Rare, including but not limited to, your name, email address, shipping address and phone number, that we do not consider to be “protected health information” or “medical information”.

 

However, in using certain components of the Service, you may also provide certain protected health or medical information that may be protected under applicable laws. b:Rare is not a “covered entity” under the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, and its related regulations and amendments from time to time (collectively, “HIPAA”). One or more of the Pharmacies or Medical Groups (as defined in our Terms and Conditions may or may not be a “covered entity” or “business associate” under HIPAA, and b:Rare may in some cases be a “business associate” of a Pharmacy or Medical Group. It is important to note that HIPAA does not necessarily apply to an entity or person simply because there is health information involved, and HIPAA may not apply to your transactions or communications with b:Rare, the Medical Groups, the Providers or the Pharmacies. To the extent b:Rare is deemed a “business associate” however, and solely in its role as a business associate, b:Rare, may be subject to certain provisions of HIPAA with respect to “protected health information,” as defined under HIPAA, that you provide to the Medical Group or the Providers (“PHI”). In addition, any medical or health information that you provide that is subject to specific protections under applicable state laws (collectively, with PHI, “Protected Information”), will be used and disclosed only in accordance with such applicable laws. However, any information that does not constitute Protected Information under applicable laws may be used or disclosed in any manner permitted under this Privacy Policy. Protected Information does not include information that has been de-identified in accordance with applicable laws.

 

The Medical Groups and Providers have adopted a Notice of Privacy Practices that describes how they use and disclose Protected Information. By accessing or using any part of the Service, you are acknowledging receipt of the Notice of Privacy Practices from your Medical Group and Provider(s).

 

By accessing or using any part of the Service, you are agreeing that even if HIPAA does apply to b:Rare, the Medical Groups, the Providers or the Pharmacies, any information that you submit to b:Rare that is not intended and used solely for the provision of diagnosis and treatment by the Medical Group and Providers or prescription fulfillment by the Pharmacies, is not considered Protected Information, and will only be subject to our Privacy Policy and any applicable state laws that govern the privacy and security of such information.


Collection of Information

We collect any information you provide when you use the Service, including, but not limited to:


Personally identifying information such as your name and contact data such as your e-mail address, phone number, and billing and physical addresses

Your login and password and other account (“Account”) registration details

Demographic data (such as your gender, date of birth and zip code)

Computer, mobile device and/or browser information (e.g., IP address, mobile device ID information, operating system, connection speed, bandwidth, browser type, referring/exist web pages, web page requests, cookie information, hardware attributes, software attributes)

Third-party website, network, platform, server and/or application information (e.g., Facebook, Twitter, Instagram)

Usage activity concerning your interactions with the Service and/or third-party websites, networks or applications accessed through the Service (e.g., viewing habits, viewing preferences, viewing history, number of clicks on a page or feature, amount of time spent on a page or feature, identify of third party websites, networks, etc.)

Billing, payment and shipping information

Electronic signature

Photographic or video images submitted for identification or non-diagnosis or treatment purposes

Information about third parties that you refer to us (e.g., name, email, and/or other contact information, relationship)

Statements or content (e.g., comments, videos, photographs, images) and information about such statements or content, which you submit or publish on or through the Service or which are accessed via your public or linked social media pages (e.g., Facebook, Twitter, Instagram)

Any other information you provide when you contact or communicate with us

If you use your mobile device to visit, access or use the Service, then additional categories of information that we collect may include


Your name associated with your mobile device
Your telephone number associated with your mobile device

Your geolocation

Your mobile device ID information

With your express consent, your contacts and/or contact information (e.g., names, telephone numbers, physical addresses, email addresses, photos) stored on your mobile device

With your express consent, information about third-party software applications on your mobile device (including, without limitation, general software apps, downloadable software apps, social media apps)

We also collect certain medical information on behalf of the Medical Groups and your Providers, which may include, but is not limited to:

 

Health and medical data you submit for diagnosis or treatment purposes, including information in any questionnaires or surveys you complete for these purposes

Previous doctors or other healthcare providers you visited

Date of visit

Images or videos you share for diagnosis or treatment purposes

Communications with Providers

How Information Is Collected


b:Rare might collect personal and non-personal information directly from you when you visit, access or use the Service; when you register with or subscribe to the Service or any products or services available through the Service; when you “sign in,” “log in,” or the like to the Service; when you allow the Service to access, upload, download, import or export content found on or through, or to otherwise interact with, your computer or mobile device (or any other device you may use to visit, access or use the Service) or online accounts with third-party websites, networks, platforms, servers or applications (e.g., your online social media accounts, your cloud drives and servers, your mobile device service provider); or whenever b:Rare asks you for such information, such as, for example, when you process a payment through the Service, or when you answer an online survey or questionnaire. In addition, if you or a third party sends b:Rare a comment, message or other communication (such as, by way of example only, email, letter, fax, phone call, or voice message) about you or your activities on or through the Site and/or the App, then b:Rare may collect any personal or non-personal information provided therein or therewith.

In addition to the information we collect directly from you, we may also collect certain information from the Medical Group and/or Providers who provide treatment or other services to you in connection with our Service. This information may include, but is not limited to, diagnoses, treatment plans (including prescription details) and notes, and is accessible and visible through certain components of the Service.

 

We may also receive information from third parties that pay for your care or provide you with treatment, laboratory care or prescription medication, which may include, for example, your prescription history, insurance policy, insurance eligibility and coverage, and laboratory test results.

 

Finally, b:Rare might use various tracking, data aggregation and/or data analysis technologies, including, for example, the following:


Cookies, which are small data files (e.g., text files) stored on the browser or device you use to view a website or message. They may help store user preferences and activity, and may allow a website to recognize a particular browser or device. There are several types of cookies, including, for example, browser cookies, session cookies, and persistent cookies. Cookies may record information you access on one page of a website to simplify subsequent interaction with that website, or to help streamline your transactions on related pages of that website. Most major browsers are set up so that they will initially accept cookies, but you might be able to adjust your browser’s or device’s preferences to issue you an alert when a cookie is downloaded, or to block, reject, disable, delete or manage the use of some or all cookies on your browser or device. Cookies can be set by the website owner (i.e., us), or they can be set by third parties (e.g., Facebook, Google, etc.) Cookies are used to help us speed up your future activities or to improve your experience by remembering the information that you have already provided to us. Third party cookies may also be used to enable analytics (e.g. Google Analytics) or advertising functionality (e.g., ad re-targeting on third-party websites) that enables more customized services and advertising by tracking your interaction with our Service and collecting information about how you use the Service.

Flash cookies, which are cookies written using Adobe Flash, and which may be permanently stored on your device. Like regular cookies, Flash cookies may help store user preferences and activity, and may allow a website to recognize a particular browser or device. Flash cookies are not managed by the same browser settings that are used for regular cookies.

Web beacons, which are pieces of code embedded in a website or email to monitor your activity on the website or your opening of the email, and which can pass along information such as the IP address of the computer or device you use to view the website or open the email, the URL page on which the web beacon is located, the type of browser that was used to access the website, and previously set cookie values. Web beacons are sometimes used to collect advertising data, such as counting page views, promotion views or advertising responses. Disabling your computer’s, device’s or browser’s cookies may prevent some web beacons from tracking or recording certain information about your activities.

Scripts, which are pieces of code embedded in a website to define how the website behaves in response to certain key or click requests sent by the user. Scripts are sometimes used to collect information about the user’s interactions with the website, such as the links the user clicks on. Scripts are often times temporarily downloaded to the user’s computer or device from the website server, active only while the user is connected to the Site and/or the App, and deactivated or deleted when the user disconnects from the website.

Analytic tools and services, which are sometimes offered by third parties, and which track, measure and/or generate information about a website’s or program’s traffic, sales, audience and similar information, and which may be used for various reasons, such as, for example, statistical research, marketing research, and content ratings research, and conversion tracking. Examples of the analytic tools and services which b:Rare might use include Google Analytics and Taplytics. b:Rare may also use other third-party analytic tools and services.

Please be advised that if you choose to block, reject, disable, delete or change the management settings for any or all of the aforementioned technologies and/or other tracking, data aggregation and data analysis technologies, then certain areas of the Site and/or the App might not function properly.

 

By visiting, accessing or using the Service, you acknowledge and agree in each instance that you are giving b:Rare permission to monitor or otherwise track your activities on the Service, and that b:Rare may use the aforementioned technologies and/or other tracking, data aggregation and data analysis technologies. Notwithstanding the foregoing, b:Rare does not permit third parties or third-party cookies to access to any communications you have with the Providers, or medical information that you submit to the Providers for diagnosis and treatment purposes.

 

Use of Information

 

In connection with providing the Service, we and our affiliates and service providers may use your information, subject to the limitations addressed in the Protected Health Information Section above, for a number of purposes, including, but not limited to:

 

Verifying your identity;

Confirming your location;

Administering your account;

Fulfilling your requests;

Processing your payments;

Facilitating your movement through Service;

Facilitating your use of the Service and/or products or services offered through the Service;

Communicating with you by letter, email, text, telephone or other forms of communication;

Providing you with information about b:Rare, the Pharmacies, the Medical Groups, the Providers and/or their businesses, products and services by letter, email, text, telephone or other forms of communication;

Providing you with customer support;

Providing you with information about third-party businesses, products and services by letter, email, text, telephone or other forms of communication;

Developing, testing or improving the Service and content, features and/or products or services offered via the Service;

Identifying or creating new products, services, marketing and/or promotions for b:Rare or the Service;

Promoting and marketing b:Rare, the Service, and the products and/or services offered via the Service;

Improving user experiences with the Service;

Analyzing traffic to and through Service;

Analyzing user behavior and activity on or through the Service;

Conducting research and measurement activities for purposes of product and service research and development, advertising claim substantiation, market research, and other activities related to b:Rare, the Service or products and services offered via the Service;

Monitoring the activities of you and others on or through the Service;

Placing and tracking orders for products or services on your behalf;

Protecting or enforcing b:Rare’ rights and properties;

Protecting or enforcing the rights and properties of others (which may include you);

When required by applicable law, court order or other governmental authority (including, without limitation and by way of example only, in response to a subpoena or other legal process); or

b:Rare believes in good faith that such use is otherwise necessary or advisable (including, without limitation and by way of example only, to investigate, prevent, or take legal action against someone who may be causing injury to, interfering with, or threatening the rights, obligations or properties of b:Rare, a user of the Service, which may include you, or anyone else who may be harmed by such activities or to further b:Rare’ legitimate business interests).

We may de-identify your information and use, create and sell such de-identified information, or any business or other purpose not prohibited by applicable law.

 

Disclosure of Information

 

Subject to the limitations described in the Protected Health Information section above, we may disclose your information to third parties in connection with the provision of our Service or as otherwise permitted or required by law. For example, we may disclose your information to:

Our third-party service providers that provide services to enable us to provide the Service, such as the hosting of the Service, data analysis, IT services and infrastructure, customer service, e-mail delivery, and other similar services;

Our third-party service providers that provide services to enable us to run our business and administrative operations, such as legal and financial advisory services, auditing services, analytics and similar services;

Our third-party service providers that provide services to enable us to promote and advertise the Service and the products and/or services offered via the Service, such as ad platforms or ad-retargeting services, as well as comply with contact removal requests or requirements, such as mailing list removal services, do not call registries, and similar services;

The Pharmacies, Medical Group or its Providers to enable them to provide services to you via the Service and to collect payment on their behalf;

Third parties as we believe necessary or appropriate to comply with applicable laws; and

To a third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer, liquidation or other disposition of all or any portion of our business, assets or stock with such third party.

We may de-identify your information and disclose such de-identified information for any purpose not prohibited by applicable law.

Data Retention

b:Rare may retain your information for as long as it believes necessary; as long as necessary to comply with its legal obligations, resolve disputes and/or enforce its agreements; and/or as long as needed to provide you with the products and/or services of the Service or b:Rare. b:Rare may dispose of or delete any such information at any time, except as set forth in any other agreement or document executed by b:Rare or as required by law.

Similarly, the Medical Groups and Providers may retain your information for as long as they believe necessary; as long as necessary to comply with their respective legal obligations, resolve disputes and/or enforce its agreements; and/or as long as needed to provide you with the products and/or services of the Medical Groups and Providers. The Medical Groups and Providers may dispose of or delete any such information at any time, except as set forth in any other agreement or document executed by the Medical Groups or Providers or as required by law.

Transactions

In connection with any transaction that you conduct through the Service (e.g., the purchase or sale of any products or services on or through the Service), you may be asked to supply certain information relevant to the transaction, including, without limitation, your credit card number and expiration date, your billing address, your shipping address, your phone number and/or your email address. By submitting such information, you grant b:Rare without charge the irrevocable, unencumbered, universe-wide and perpetual right to provide such information to third parties (e.g., payment processing companies, buyers on the Service, sellers on the Service) for the purpose of facilitating the transaction.

All credit card, debit card and other monetary transactions on or through the Service occur through an online payment processing application(s) accessible through the Service. This online payment processing application(s) is provided by b:Rare’ third-party online payment processing vendor, Stripe (“Stripe”). Additional information about Stripe, its privacy policy and its information security measures (collectively, the “Stripe Policies”) should be available on the Stripe website located at https://stripe.com/us/privacy or by contacting Stipe directly. Reference is made to the Stripe Policies for informational purposes only and are in no way incorporated into or made a part of this Privacy Policy. b:Rare’ relationship with Stripe, if any, is merely contractual in nature, as Stripe nothing more than a third-party vendor to b:Rare, and is in no way subject to b:Rare’ direction or control; thus, their relationship is not, and should not be construed as, one of fiduciaries, franchisors-franchisees, agents-principals, employers-employees, partners, joint venturers or the like.

Jurisdictional Issues

The Service may only be used within certain states within the United States as described in our Terms and Conditions. Accordingly, this Privacy Policy, and our collection, use, and disclosure of your information, is governed by U.S. law. Third Parties

This Privacy Policy does not address or apply to, and we are not responsible for, the privacy, information or other practices of any third parties, including, without limitation, the Medical Group or its Providers, the manufacturer of your mobile device, and any other third party mobile application or website to which our Service may contain a link. These third parties may at times gather information from or about you. We do not control and are not responsible for the privacy practices of these third parties. We encourage you to review the Medical Group’s Notice of Privacy Practices and the privacy policies of each website and application you visit and use.

Retention, Review, and Change of Information Collected

You may request at any time that b:Rare provide you with an opportunity to review and change your personal information (i.e., information that would allow someone to specifically identify you or contact you physically or online such as your name, physical address, telephone number, email address or SSN) collected through the Service or to no longer use your personal information to provide you with any products or services. Please submit any such request (“Request Concerning Personal Information”) to any one of the following:

By mail: b:Rare, Inc., attn: Privacy Officer, 1900 Camden Ave, San Jose, CA 95124, with a subject line of “Your Personal Information.”

By email: privacy@brarex.com, with a subject line of “Your Personal Information.”

For each Request Concerning Personal Information, please state “Your Personal Information” in the email or letter subject line, and clearly state the following in the body: 

the nature of your request;

that the request is related to “Your Personal Information;”

your name, street address, city, state, zip code and email address; and

whether you prefer to receive a response to your request by mail or email.

We will use reasonable efforts to deal with your request within a reasonable time. If you send a Request Concerning Personal Information by mail, then please do so by U.S. Certified Mail, Return Receipt Requested to allow for confirmation of mailing, delivery and tracking. b:Rare will not accept a Request Concerning Personal Information via telephone or facsimile. b:Rare is not responsible for any Request Concerning Personal Information that is incomplete, incorrectly labeled, or incorrectly sent.

You are solely responsible for the accuracy and content of your personal information, and for keeping your personal information current and correct.

California Residents

Residents of the State of California have the right to request from certain businesses with whom the California resident has an established business relationship a list of all third parties to which the business, during the immediately preceding calendar year, has disclosed certain personally identifiable information for direct marketing purposes. We are only required to respond to a customer request once during any calendar year. To obtain this information, you should send a written request to legal@brarex.com with the subject heading “California Privacy Rights.” In your request, please attest to the fact that you are a California resident and provide a current California address for our response. Please be aware that not all information sharing is covered by the California Privacy Rights requirements and only information on covered sharing will be included in our response.

Miscellaneous

We strive to use reasonable physical, technical and administrative measures to protect information under our control. However, you must keep your Account password secure and your Account confidential, and you are responsible for any and all use of your Account. If you have reason to believe that the security of your Account has been compromised, please notify us immediately in accordance with the “Contacting Us” section below.

When using the Service, you may choose not to provide us with certain information, but this may limit the features you are able to use or may prevent you from using the Service all together. You may also choose to opt out of receiving certain communications (e.g., newsletters, promotions) by emailing us your preference. Please note that even if you opt out, we may still send you Service-related communications. We do not currently respond to web browser “do not track” signals or other mechanisms that provide a method to opt out of the collection of information across the networks of websites and online services in which we participate. If we do so in the future, we will describe how we do so in this Privacy Policy.

b:Rare may supplement, amend, or otherwise modify this Privacy Policy at any time. Such supplements, amendments and other modifications will be posted on this or a similar page of the Service, and shall be deemed effective as of the “Last Updated” date; provided, however, that b:Rare will notify you and/or require you to accept the updated Privacy Policy if the supplemented, amended or otherwise modified Privacy Policy implements material changes from b:Rare’ then-current Privacy Policy. It is your responsibility to carefully review this Privacy Policy each time you visit, access or use the Service.

 

 Contacting Us

If you have any questions about this Privacy Policy, please contact us by email at privacy@brarex.com or by regular mail at:
b:Rare, Inc.
1900 Camden Ave 
San Jose, CA 95124
Attn: Privacy Officer
Last Updated: November 2, 2019