Dated 09/18/2023 V 1.0
These policies and procedures are meant to outline requirements that satisfy the related HIPAA requirements. For the full HIPAA policy, please see ‘HIPAA Security and Privacy Manual for Planstin Administration’ (the policy). This can be found here.
For direct definitions of PII, PHI, and PCI-DSS, please refer to Planstin’s Data Classification Policies & Procedures. This can be found here.
Please refer to the policy document, your manager, or your compliance team at compliance@planstin.com with any questions.
This Privacy Policy is designed to inform users of how Planstin Administration, Inc., its affiliates, subsidiaries, or related companies (“we”, “us”, or “our”) gather and use personal information collected by us on or through our Service. For purposes of this Privacy Policy, the “Service” includes: (1) the websites owned or operated by Planstin Administration, Inc. now, or in the future, including, but not limited to, www.planstin.com (collectively, the “Site”); (2) Planstin Administration Inc.’s subdomains and all related services and products provided in connection with the Site.
By using the Service, you accept and hereby expressly consent to the terms of this Privacy Policy and to our use and processing of Personal Information (as defined hereunder) for the purposes set forth herein. “You” or “your” or similar terms refer to you as a user of our Service. By accepting our Privacy Policy during registration, or by using the Service, you expressly consent to our collection, use, disclosure, storage, and processing of your Personal Information (as defined below) in accordance with this Privacy Policy.
This Privacy Policy covers how Planstin Administration, Inc. treats your personally identifiable information that could be used to identify you that Planstin Administration, Inc. collects, receives, maintains, stores, or transmits including, but not limited to, information you transmit or submit in connection with your use of, or interaction with, the Service (“Personal Information”). Your Personal Information includes, but is not limited to, information that individually identifies you or is information about you that can be traced back to you, your IP address, or your location. It may include, but is not limited to, your name, address, email address, phone number, other contact information, and any information you choose to share via the Service.
Planstin Administration, Inc. collects Personal Information that you choose to provide to us, including any Personal Information you provide in connection with your use of the Service, regardless of how you provide it. It is always your choice whether or not to provide us with your Personal Information. If you choose not to provide Personal Information, you may not be able to use certain features or functions of the Service. Whenever you use the Service, Planstin Administration, Inc. also receives and records information on our server logs from your browser, including your IP address, Planstin Administration Inc.’s cookie information, and the pages you request, and relates it to the Personal Information you provide.
Examples of how and why Planstin collects Personal Information include:
When you access our Service from a mobile device, we may collect unique identification numbers associated with your device (including, for example, a UDID, Unique ID for Advertisers (“IDFA”), Google AdID, or Windows Advertising ID), mobile carrier, device type, model and manufacturer, mobile device operating system brand and model, phone number, and, depending on your mobile device settings, your geographical location data, including GPS coordinates (e.g., latitude and/or longitude) or similar information regarding the location of your mobile device, or we may be able to approximate a device’s location by analyzing other information, like an IP address. We and our third-party partners may also use cookies and tracking technologies for advertising purposes.
Cookies, Web Beacons, Research and Analytics, and Other Tracking Technologies
We use technology to automatically or passively store or collect certain information when you visit or interact with the Service. These technologies include “cookies” and “web beacons” (and subsequent technologies and methods later developed which perform a similar function), which are used to collect and store usage information regarding your use of the Service. We use this information for a variety of purposes, including, but not limited to, assessing the performance of, or enhancing your experience with, the Service.
Disabling Cookies
You may set your browser to refuse all or some browser cookies, or to alert you when cookies are being sent. Please refer to your browser “Help” instructions to learn more about cookies and other technologies and how to manage their use. If you elect to refuse or delete cookies, you will need to repeat this process if you use another device or change browsers. The Network Advertising Initiative provides instructions and information on how to opt out of communications: http://www.networkadvertising.org/choices/. You can use your browser settings to decide whether to turn on and off cookies for our Service. To learn how you can manage your Flash cookie settings, visit the Flash player settings page on Adobe’s website. If you disable or refuse cookies, please note that some of the Service may be inaccessible or not function properly.
Analytics Tools
We also use analytics tools including Google Analytics to better understand how visitors interact with our Service. These tools provide anonymous information, including, but not limited to, data on where visitors came from, what actions they took while interacting with the Service, and where visitors went when they ceased interacting with the Service.
Google Analytics
We use Google Analytics, a web analytics service provided by Google, Inc. (“Google”) to collect certain information relating to your use of the Service. Google Analytics uses cookies to analyze how users use the Service. You can find out more about how Google uses data by visiting the following website: www.google.com/policies/privacy/partners/. We may also use Google Analytics Advertising Features or other advertising networks to provide you with interest-based advertising based on your online activity. For more information regarding Google Analytics please visit Google’s website, and pages that describe Google Analytics, such as www.google.com/analytics/learn/privacy.html.
Other Tools
There may be other tracking technologies now and later devised and used by us in connection with the Service. Further, third parties may use tracking technologies with our Service. We do not control these tracking technologies, and we are not responsible for them. However, you consent to potentially encountering third-party tracking technologies in connection with your use of the Service and accept that this Privacy Policy does not apply to the tracking technologies or practices of such third parties. In such cases, you must check with the third party to confirm how your information is collected and used.
California Do Not Track Disclosure
We currently do not support the Do Not Track browser setting or respond to Do Not Track signals. Do Not Track (or DNT) is a preference you can set in your browser to let the websites you visit know that you do not want it collecting certain information about you.
In general, we will not rent or sell your Personal Information. Also, we will not share your Personal Information with other people or non-affiliated companies except in connection with providing the Service, when we otherwise have your permission, as permitted, or required by the NPP, or as expressly permitted or required under this Privacy Policy, including under the following general circumstances.
Using Your Personal Information
We, or a third party on our behalf, use information we collect on the Service in a variety of ways in providing the Service and operating our business, including, but not limited to, the following:
Disclosing Your Personal Information
Except as described in this Privacy Policy, we will not disclose Personal Information that we collect on the Service to third parties without your consent. However, we may disclose Personal Information that we collect on the Service to third parties, to the fullest extent permitted by law, for the following reasons:
Use / Disclosure of Information Submitted to Groups
You acknowledge that our Service may include in the future features such as group discussions, discussion boards, forums, profile pages, bulletin boards, instant messaging, polls, and other communication forums (collectively, “Groups”). You acknowledge and agree that any information you submit, post, or disclose to such Groups including, but not limited to, user profile information, user profile pictures, discussion board postings, and any Personal Information included in such postings, may be visible to other users and providers of the Service including, but not limited to, your health coaches, authorized personnel, administrators, and other users of the Service.
IN THE CASE OF YOUR USE OF GROUPS, WE ARE NOT RESPONSIBLE FOR THE USE BY OTHERS OF ANY INFORMATION, INCLUDING PERSONAL INFORMATION, THAT IS DISCLOSED BY YOU OR ON YOUR BEHALF IN SUCH GROUPS. BY DISCLOSING ANY OF YOUR INFORMATION VIA GROUPS, YOU ACKNOWLEDGE AND ACCEPT ANY RISK AND DAMAGE ARISING FROM THE DISCLOSURE OF SUCH INFORMATION.
We take reasonable steps to ensure that all Personal Information collected will remain secure and in its original form (i.e., free from any alteration). We have put in place appropriate physical, electronic, and administrative safeguards in compliance with federal and state law, including HIPAA, to help prevent unauthorized access, maintain data security, and correct use of the Personal Information we collect. We cannot, however, ensure or warrant the security of any Personal Information you transmit to us, and you do so at your own risk. Once we possess your transmission of information, we use commercially reasonable efforts to ensure the security of our systems. However, please note that this is not a guarantee that such information may not be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, or administrative safeguards.
The Service may contain links to Third Party Offerings (as such term is defined in the Terms). Before using any Third-Party Offerings or related services, you must review and accept the terms of use and privacy policies for those sites and/or services. We are not responsible for the privacy policies and/or practices of any Third-Party Offerings, and we are not responsible or liable for the availability, reliability, content, functions, performance, accuracy, legality, appropriateness, services, materials, or any other aspect of such Third-Party Offerings. This Privacy Policy only governs information collected by our Service. When you access any Third-Party Offerings, you do so at your own risk, and you understand and agree that you are solely responsible for reading and understanding any terms of use and/or privacy policies that apply to such Third-Party Offerings. Planstin Administration, Inc. is not responsible for and will not be a party to any transactions between you and a third-party provider of products, information, or services. Planstin Administration, Inc. does not monitor such interactions to ensure the confidentiality of your Personal Information. Any separate charges, data records or obligations you incur in your dealings with Third-Party Offerings are solely your responsibility.
You may review and request changes to your Personal Information or request additional information about our collection, use and disclosure of such information by contacting us at compliance@planstin.com. We try to keep our records as accurate and complete as possible. You can help us maintain the accuracy of your information by promptly notifying us of any changes to your Personal Information. You may update, correct, or delete your profile information and preferences at any time by accessing your account preferences in the Service. Any changes you make will be reflected in active user databases within a reasonable period of time; however, we may retain all information you submit for backups, archiving, prevention of fraud or abuse, analytics, satisfaction of legal obligations, or where we otherwise reasonably believe that we have a legitimate reason to do so. We may not be able to modify or delete your information in all circumstances. In addition, you may request that we provide you with the information we hold about you; however, your rights to access your Personal Information are not absolute. We may deny you access when required and/or permitted by applicable laws or if disclosure would likely reveal personal information about a third party.
Our Service is neither intended for nor designed to attract users who are under the age of 18. If you are under the age of 18, or we are not otherwise able to offer Service functionality to you because you are deemed a minor (for example, you are not an emancipated minor), do not use the Service. However, depending upon the Service functionality available to you, a parent, guardian, conservator, or custodian or similar legally authorized person (“Authorized Person”) may register for access to the Service and use it on your behalf. Upon turning 18, we will cease providing Service access to the Authorized Person and, depending on the Service functionality available to you, we may:
Our Service is not directed to children under the age of 13, and we do not knowingly collect information from children under the age of 13 without obtaining parental consent. If you are under 13 years of age, then please do not use or access the Service at any time or in any manner. If we learn that a person under 13 years of age has used or accessed the Service or any information has been collected on the Service from persons under 13 years of age, then we will take the appropriate steps to delete this information. If you are a parent or guardian and discover that your child under 13 years of age has obtained an account on or otherwise accessed the Service, then you may alert us at compliance@planstin.com and request that we delete your child’s information from our systems.
You may affirmatively opt out of receiving future emails from Planstin Administration, Inc. and may remove your name from our marketing mailing lists. The opt-out provisions do not apply to information collected by cookies or used internally to recognize you and/or facilitate your use of the Service or information we may retain to comply with legal requirements. Opting out will not prevent your access to the Service and you will continue to receive administrative messages about the Service from us. If you no longer consent to us collecting, using, and sharing your Personal Information in accordance with this Privacy Policy, you may disenroll from the Service at any time by emailing Planstin Administration, Inc.’s Compliance Team at compliance@planstin.com.
By using the Service, you agree to the current Privacy Policy, as well as our Terms into which this Privacy Policy is incorporated. Planstin Administration, Inc. reserves the right, in our sole discretion, to modify or amend this Privacy Policy at any time. Use of information we collect is subject to the Privacy Policy in effect at the time such information is used or disclosed. If we make any material changes to the ways in which Personal Information is collected, used or transferred, as determined by Planstin Administration, Inc., we will notify you of these changes by modification of this Privacy Policy, which will be available for your review through the Service and the last revision date will be noted at the beginning or end of this Privacy Policy. You should review this Privacy Policy periodically so that you are up to date on our most current policies and practices. Your continued use of the Service after receiving notice signifies your acceptance of any such changes. If the modified Privacy Policy is not acceptable to you, your only recourse is to cease using the Service.
Some of the information that you provide to Planstin Administration, Inc., or that is created through your use of the Service, may be considered “Protected Health Information” or “PHI” as defined in the Health Insurance Portability and Accountability Act (“HIPAA”). PHI is subject to Planstin Administration, Inc.’s Notice of Privacy Practices (the “NPP”). The NPP describes how Planstin Administration, Inc. uses and discloses your PHI and also describes your rights with respect to your PHI. To the extent that this Privacy Policy conflicts with the NPP, the NPP will prevail. In addition, to the extent a capitalized term is undefined in this Privacy Policy, it will have the same meaning as prescribed to it in our Terms of Service (the “Terms”). To the extent that this Privacy Policy conflicts with the Terms, this Privacy Policy will control. BY USING THE SERVICE, YOU ACKNOWLEDGE RECEIPT OF THE PLANSTIN ADMINISTRATION, INC. NPP.
In addition, your use of the Service may involve our receipt of PHI. PHI is Personal Information that relates to
This Privacy Policy describes how we protect your privacy as a visitor or general user of our Service. You have additional rights under federal and state law with respect to PHI. For more information on those rights, and how the Planstin Administration, Inc. uses and discloses your PHI, refer to the NPP.
In addition to the permitted uses of Personal Information that are set forth in this Privacy Policy, we may use your Personal Information to:
In addition to the permitted disclosures of Personal Information that are set forth in this Privacy Policy, and to the extent permitted by applicable law, we may, in our sole discretion and as we deem necessary or otherwise appropriate, disclose your Personal Information to an appropriate health care provider to address concerns regarding the safety and well-being of a user.
For California residents, this section describes the rights you may have under California law. These disclosures are intended to supplement this Privacy Policy with information required by California law. To understand what Personal Information we may have collected about you, from where we collected it, and what we do with it, please see Sections 3 and 4 of this Privacy Policy above.
We disclose the following categories of personal information for business or commercial purposes to the categories of recipients listed below:
Your Rights
Under California law, you have a right to notice, upon collection, of the categories of Personal Information collected and the purposes for which the Personal Information will be used. We have provided this notice through this Privacy Policy. In addition, California residents have additional rights, subject to certain limitations, including:
Exercising Your Right to Access, Correction, or Deletion
To submit a request to access, correct, delete your information, or exercise your right as a consumer or as an authorized agent, send an email to compliance@planstin.com. Once we receive a request, we will take steps to verify your request and will ask for information that is reasonable in light of the nature of your request.
If an authorized agent is used to make a request on your behalf, we require the authorized agent to provide proof that you gave them permission to submit the request on your behalf. We may also require you to verify your identity directly with us.
Limit Use of Sensitive Personal Information
You can opt out of certain uses of your Sensitive Personal Information by sending an email to compliance@planstin.com.
Sale of Personal Information
Planstin Administration, Inc. does not sell or share Personal Information in exchange for money. However, we may share Personal Information with our partners to understand how you use our Service, to customize your experience when you use our Service, to market to you, to improve our products and services, and to provide advertisements on other websites that we or our partners believe will be of interest to you. In addition, Planstin Administration, Inc. uses cookies and similar technologies to enhance Service navigation, analyze Service usage, and assist in marketing efforts (including targeted advertising). In some cases, sharing for these purposes may be considered a “sale” of information under California law.
The categories of Personal Information disclosed that may be considered a “sale” under California law are Identifiers, Device Information, Internet or Other Network Activity, and Inferences.
The categories of third parties to whom Personal Information was disclosed that may be considered a “sale” under California law are: Third-Party Partners, Third-Party Sellers, and Analytics, Advertising and Social Media Platforms and Networks.
We do not sell, or have actual knowledge of any sale of, the Personal Information of minors under 16 years of age.
Questions
If you have any questions about these privacy rights, please contact us at the contact information below.
Planstin Administration, Inc., 1506 S Silicon Way #2B, St. George, UT 84770, or email compliance@planstin.com.
For Colorado residents, this section describes the rights you may have under Colorado law as of July 1, 2023. These disclosures are intended to supplement this Privacy Policy with information required by Colorado law. To understand what Personal Information we may have collected about you, from where we collected it, and what we do with it, please see Sections 3 and 4 of this Privacy Policy above. We do not use your Personal Information to make decisions with legal or similar significant effects for you based on the automated processing of your Personal Information. In addition, the table below describes for each purpose for which we process Personal Information, the categories of Personal Information we process and share with third parties and the categories of third parties with whom Personal Information is shared:
Your Rights
Beginning on July 1, 2023, and subject to certain limitations, Colorado residents have the rights below:
Exercising Your Right to Access, Portability, Correction, or Deletion
To submit a request to access (including a request to obtain Personal Information in a portable format), correct, delete your information, or exercise your rights as a consumer or as an authorized agent, send an email to compliance@planstin.com. Once we receive a request, we will take steps to verify your request. We will ask for information that is reasonable in light of the nature of your request.
To use an authorized agent to make a request on your behalf, we may need the authorized agent to provide proof that you gave the authorized agent permission to submit the request on your behalf. We may also require you to verify your identity directly with us.
If we deny your request, you may appeal your request within 30 days from when your request was denied by contacting the Privacy Officer at the contact information below. You have the right to contact the Colorado Attorney General if you have concerns about the results of your appeal.
Planstin Administration, Inc., 1506 S Silicon Way #2B, St. George, UT 84770, or email compliance@planstin.com.
Sale of Personal Information
Planstin Administration, Inc. does not sell or share Personal Information in exchange for money. However, we may share Personal Information with our partners to understand how you use our Service, to customize your experience when you use our Service, to market to you, to improve our products and services, and to provide advertisements on other websites that we or our partners believe will be of interest to you. In some cases, sharing for these purposes may be considered a “sale” of information under Colorado law. In addition, Planstin Administration, Inc. uses cookies and similar technologies to enhance Service navigation, analyze Service usage, and assist in marketing efforts (including targeted advertising).
Questions
If you have any questions about these privacy rights, please contact us at the contact information below.
Planstin Administration, Inc., 1506 S Silicon Way #2B, St. George, UT 84770, or email compliance@planstin.com.
For Connecticut residents, this section describes the rights you may have under Connecticut law as of July 1, 2023. These disclosures are intended to supplement this Privacy Policy with information required by Connecticut law. To understand what Personal Information we may have collected about you, from where we collected it, and what we do with it, please see Sections 3 and 4 of this Privacy Policy above. We do not use your Personal Information to make decisions with legal or similar significant effects for you based on the automated processing of your Personal Information.
Your Rights
Beginning July 1, 2023, and subject to certain limitations, Connecticut residents have the rights below:
Exercising Your Right to Access, Portability, Correction, or Deletion
To submit a request to access (including a request to obtain Personal Information in a portable format), correct, delete your information, or exercise your rights as a consumer or as an authorized agent, send an email to compliance@planstin.com. Once we receive a request, we will take steps to verify your request. We will ask for information that is reasonable in light of the nature of your request.
To use an authorized agent to make a request on your behalf, we may need the authorized agent to provide proof that you gave the authorized agent permission to submit the request on your behalf. We may also require you to verify your identity directly with us.
If we refuse your request, we will notify you providing our reasons. You may appeal your request within 30 days from when your request was denied by contacting the Privacy Officer at the contact information below. If the appeal is denied, we will provide a way for you to contact the Connecticut Attorney General to submit a complaint.
Planstin Administration, Inc., 1506 S Silicon Way #2B, St. George, UT 84770 or email compliance@planstin.com.
Sale of Personal Information
Planstin Administration, Inc. does not sell or share Personal Information in exchange for money. However, we may share Personal Information with our partners to understand how you use our Service, to customize your experience when you use our Service, to market to you, to improve our products and services, and to provide advertisements on other websites that we or our partners believe will be of interest to you. In some cases, sharing for these purposes may be considered a “sale” of information under Connecticut law. In addition, Planstin Administration, Inc. uses cookies and similar technologies to enhance Service navigation, analyze Service usage, and assist in marketing efforts (including targeted advertising).
Questions
If you have any questions about these privacy rights, please contact us at the contact information below.
Planstin Administration, Inc., 1506 S Silicon Way #2B, St. George, UT 84770 or email compliance@planstin.com.
For Utah residents, this section describes the rights you may have under Utah law as of December 31, 2023. These disclosures are intended to supplement this Privacy Policy with information required by Utah law. To understand what Personal Information we may have collected about you, from where we collected it, and what we do with it (including who we disclose it to), please see Sections 3 and 4 of this Privacy Policy above.
Your Rights
Beginning December 31, 2023, and subject to certain limitations, Utah residents have the rights below:
Exercising Your Right to Access, Portability, Correction, or Deletion
To submit a request to access (including a request to obtain Personal Information in a portable format), correct, delete your information, or exercise your rights as a consumer or as an authorized agent, send an email to compliance@planstin.com. Once we receive a request, we will take steps to verify your request. We will ask for information that is reasonable in light of the nature of your request. If we deny your request, you may appeal your request within 30 days from when your request was denied by contacting the Privacy Officer at the contact information below.
Planstin Administration, Inc., 1506 S Silicon Way #2B, St. George, UT 84770, or email compliance@planstin.com.
Sale of Personal Information
Planstin Administration, Inc. does not sell or share Personal Information in exchange for money.
Questions
If you have any questions about these privacy rights, please contact us at the contact information below.
Planstin Administration, Inc., 1506 S Silicon Way #2B, St. George, UT 84770, or email compliance@planstin.com.
For Virginia residents, this section describes the rights you may have under Virginia law as of January 1, 2023. These disclosures are intended to supplement this Privacy Policy with information required by Virginia law. To understand what Personal Information we may have collected about you, from where we collected it, and what we do with it (including who we disclose it to), please see Sections 3 and 4 of this Privacy Policy above. We do not use your Personal Information to make decisions with legal or similar significant effects for you based on the automated processing of your Personal Information.
Your Rights
Beginning January 1, 2023, and subject to certain limitations, Virginia residents have the rights below:
Exercising Your Right to Access, Portability, Correction, or Deletion
To submit a request to access (including a request to obtain Personal Information in a portable format), correct, delete your information, or exercise your rights as a consumer or as an authorized agent, send an email to compliance@planstin.com. Once we receive a request, we will take steps to verify your request. We will ask for information that is reasonable in light of the nature of your request. If we deny your request, you may appeal your request within 30 days from when your request was denied by contacting the Privacy Officer at the contact information below.
Planstin Administration, Inc., 1506 S Silicon Way #2B, St. George, UT 84770, or email compliance@planstin.com.
Sale of Personal Information
Planstin Administration, Inc. does not sell or share Personal Information in exchange for money.
Questions
If you have any questions about these privacy rights, please contact us at the contact information below.
Planstin Administration, Inc., 1506 S Silicon Way #2B, St. George, UT 84770, or email compliance@planstin.com.
The Service may only be used within certain jurisdictions within the United States as set forth in the Terms. Accordingly, this Privacy Policy, and our collection, use, and disclosure of your information, is governed by U.S. law, and by using the Service, you acknowledge that the Service will be governed by U.S. law. Using the Service from outside the United States is prohibited under our Terms and may subject you to termination of your use of the Service under such Terms. In no event will Planstin Administration, Inc. or any of its officers, directors, employees, consultants, subsidiaries, agents, and affiliated entities, including Planstin Administration, Inc. be liable for any losses or damages arising from your use of the Service outside of the United States, and you waive any claims that may arise under the laws of your location outside the United States. Notwithstanding the foregoing, we do not represent or warrant that the Service is appropriate or available for use in any particular jurisdiction. If you choose to use the Service from the European Union or other regions of the world with laws governing data collection and use that may differ from U.S. law, then please note that you are transferring your personal information outside of those regions to the United States for storage and processing. Also, we may transfer your data from the United States to other countries or regions in connection with storage and processing of data, fulfilling your requests, and operating the Service. By providing any information, including PII, PHI, and/or PCI-DSS on or to the Service, you consent to such transfer, storage, and processing.
If you have questions or suggestions, please contact:
Planstin Administration, Inc., 1506 S Silicon Way #2B, St. George, UT 84770 or email compliance@planstin.com.
Change Date: 08/18/2023
Description: Internal Policy Creation
Changed By: Aubrey Brenner & Sam Blount
Approved By: Derrick Udy & Leo Garcia
I WANT TO...
LOGIN
CLAIM INFORMATION
Payer ID: 65241
Planstin Administration
P.O. Box 21747
Eagan, MN 55121
© 2023 Planstin Administration - All Rights Reserved