1. Overview
This privacy notice (“Privacy Notice”) describes how MyEyes Corporation (“MyEyes”, “we”, “our”, or “us”): (a) collects, uses, retains, shares, or otherwise processes your data (“process” or “processes”); and (b) describes your rights regarding your personal data and how to exercise those rights. Please read this Privacy Notice carefully to understand our policies and practices regarding your data and how we will treat it.
1.1. Modification of This Privacy Notice
This Privacy Notice may be modified from time to time at our sole discretion. The date this Privacy Notice was “last updated” is at the top of this page. If we make a material change to this Privacy Notice, we will publish the updated Privacy Notice to: myeyes.net/privacy or such other location as we may designate. We advise you to frequently check this Privacy Notice for any changes. We may also provide notice of such changes to you in other ways, at our discretion, such as displaying a notification banner on the homepage of our Site.
YOUR USE OF THE SERVICES, AND CONTINUED USE OF THE SERVICES FOLLOWING ANY CHANGES TO THIS PRIVACY NOTICE, SIGNIFIES YOU HAVE READ, UNDERSTAND, AND AGREE TO BE BOUND BY THE TERMS OF THIS PRIVACY NOTICE, EXCEPT WHERE APPLICABLE LAW REQUIRES YOUR SEPARATE AFFIRMATIVE CONSENT FOR THE PROCESSING OF SENSITIVE PERSONAL DATA OR HEALTH-RELATED DATA. IF YOU DO NOT AGREE WITH THE TERMS OF THIS PRIVACY NOTICE, YOUR CHOICE IS TO NOT USE THE SERVICES.
1.2. When This Privacy Notice Applies
This Privacy Notice applies to the data we collect from or about you when you take the following actions (collectively, the “Platform”):
- visit or interact with our website (“Site”) or our mobile application (“App”);
- interact with us online via email or through advertising;
- interact with us offline via telephone;
- sign up for our marketing communications;
This Privacy Notice also applies when you use our Platform or purchase or use any of our related features, functionality, and services. The Site, the App, the Platform, and all such features, functionality, and services are referred to collectively as the “Services”.
1.3. When This Privacy Notice Does Not Apply
This Privacy Notice does not apply to your data if you:
- are our employee carrying out your obligations as an employee, or our independent contractor carrying out your contractual obligations; apply for a job with us; or if we’ve provided you with an alternate privacy policy at the time of collection;
- if you interact with third-party digital assets that are linked to or accessible from the Site or App.
2. Type of Data Collected; Source of Data
The types of data we collect about you depend on your interactions with us and on our Services. In this section, we describe the categories of data we collect, organized by the sources of this data.
By interacting with the Services, you acknowledge and consent to our use of your data to enable us to provide the Services to you, to improve the Services, and for other uses as stated in this Privacy Notice, in our Terms of Use (the "Terms of Use"), which govern your use of the Services and are available at myeyes.net/terms and in any ancillary agreements you may have entered with us related to our Services. If you do not provide your data when requested, you may not be able to use our Services or certain features of our Services in whole or in part: (a) if that data is necessary to provide you with our Services or such features or (b) if we are legally required to collect the requested data.
2.1. Data You Directly Provide to Us
In addition to any other categories of data we state we are collecting at the time of collection, we may also collect the following data that you provide directly to us:
- Identifying Data. Data by which you may be identified such as your name, address, phone number, and email address;
- Demographic Data. Data that is about you but that as an individual piece of data does not specifically identify you, such as your birthdate, zip code, gender, and age;
- Communications Data. Data contained in your communications with us through our Services, such as when you request additional information about our Services, provide us with feedback, submit forms on the Services, or interact with our Customer Support team (including call recordings), including personal data used to contact you, the date and time of your communications, and the content of your communications;
- Login Data. Data related to your account such as your username (which is your email address) and password;
- Transaction Data. Data related to our Services, such as the type of Services requested or provided (e.g., home equipment rental or purchase, monitoring subscriptions), order details, delivery information, or the amount charged. To complete a transaction, you may be required to provide payment and financial data such as the type of card, card number, expiration date, security code, and billing address. When you provide such data, it is processed directly by a third-party payment processor (Stripe). We do not have direct access to, process, transmit, handle, or store any of your credit or debit card details, and we are not responsible for the payment processor's handling of your payment information;
- More Sensitive Data. With your affirmative consent or as necessary for the provision of the Services, and as permitted by applicable law, we may collect certain sensitive data about you, including health-related data such as eye condition diagnoses (e.g., glaucoma), intraocular pressure (IOP) and other medical measurements, treatment information from prescribing healthcare providers, and health and medical history from Healthcare Partners. We also collect insurance information, referring physician/doctor information, emergency contact information, and prescription/medication information;
2.2. Data Automatically Collected About You
As you navigate through and interact with our Services, including through our Site and App, we, our Service Providers, or other third parties may use cookies, log files, pixel tags, software development kits (SDKs), and other client-side or server-side automatic data tracking technologies (“Automatic Tracking Technologies”), to collect certain data about your equipment, browsing actions, and patterns, including the following types of data:
- Device Data. Data when you interact with the Services such as technical data about your device including device type; unique device identifiers; mobile device model and manufacturer; domain, browser type, version, and language; operating system and system settings; mobile network information; serial number; and similar device data.
- Usage Data. Data about your visits to and usage of our Services including: usage details (i.e., date/time/duration on a given Site page or App screen), traffic data, logs, general location and time zone based on your IP address, heat maps that show where your mouse is on a Site page, other Communications Data and the resources that you access and use on the Site or App, and navigation paths within the Site or App. This data may include links clicked, Site page views, App screen views, searches, features used, items viewed, time spent on the Site or in the App, and in-app events and interactions.
- Push Notification Data. If you enable push notifications on your mobile device, we may collect data related to your notification preferences and your interactions with notifications we send. You may disable push notifications at any time through your device settings.
The Automatic Tracking Technologies we may use include the following:
- Cookies (or browser cookies). A cookie is a small file placed on the hard drive of your computer. You may refuse to accept browser cookies by activating the appropriate settings on your browser. However, if you select this setting, you may be unable to access certain parts of our Site. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our Site.
- Local Storage. Certain features of our Site may use local storage technologies (such as HTML5 local storage) to collect and store data about your preferences and navigation to, from, and on our Site. Local storage is not managed by the same browser settings as are used for browser cookies.
- Log Files. Log files are software-generated files containing data about the operations, activities, and usage patterns of an application, server, or IT system, such as what was done and at what time.
- SDKs. A Software Development Kit or “SDK” represents a consolidated package of pre-existing code, enhancement tools, and guidance documents that can be installed and used to develop applications for a particular digital asset, including mobile applications. SDKs allow our partners to directly extract data from our Site and App. The data collected has numerous applications including offering us insightful analytics about our Site’s and App’s usage, enabling social media incorporation, introducing new attributes or capabilities to our Site or App, or assisting in tracking and enhancing the efficacy of our online advertisements.
- Web Beacons. Pages of our Site may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit us, for example, to count users who have visited those pages or for other related Site statistics (for example, recording the popularity of certain Site content and verifying system and server integrity).
2.3. Data We Collect from Other Sources
We may receive the data described above from other sources such as service providers and other third parties who help us provide the Services or market our Services to you. These other sources we may receive data from include the following:
- Service Providers. We may use service providers ("Service Providers"), meaning third-party companies or individuals we hire or work with to perform services on our behalf, to provide the Services to you or for any other purpose described in the How We Use Your Data section below.
- Healthcare Partners. We may receive data from healthcare partners ("Healthcare Partners"), meaning healthcare providers, clinics, hospitals, and partner institutions using electronic medical record systems who refer patients to us or coordinate care with us, including patient referral data, health and medical history, and treatment information from prescribing healthcare providers, to facilitate our services.
3. How We Use Your Data
We, along with our Service Providers or other third parties, may use your data for the purposes described below. We may use your data for the following purposes:
- Provide and Improve our Services. To provide the Services to you, including personalizing the content and features that match your activities, preferences, and settings on the Services, and to monitor and analyze trends, usage, and activities in connection with Services.
- Communicate with You. To communicate with you, including when you request additional information from us, or when we contact you about your account, such as reminders about your subscription renewal or a material change to our policies that affect you, or in connection with the Services you have purchased from us.
- Advertise and Market to You. To send advertising or marketing communications about products or services offered by us, and provide news and information that we believe may be of interest to you and to analyze and enhance our marketing communications and strategies. For information about managing your marketing preferences, see the Your Choices About Your Data section below.
- Provide Safety and Security. To detect and protect against malicious, deceptive, or illegal activity, including fraudulent transactions, errors, negligence, violations of any applicable terms, security incidents, and harm to the rights, property, or safety of us and our users, customers, employees, or others.
- Troubleshoot. To identify and debug errors that impair the existing intended functionality of our Services.
- Facilitate Corporate Transactions. In anticipation of or in connection with a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of MyEyes’ assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which the data held by MyEyes is among the assets transferred.
- Obtain Your Consent. In accordance with: (i) the way we describe to you when you provide the data to us; (ii) your instruction or intentional direction; or (iii) any other way when you consent.
- Comply with Legal Obligations. To comply with our legal or regulatory obligations, including our tax obligations and those related to the prevention of fraud and money laundering, and those required for you to benefit from rights recognized by law, or any regulatory requirements or provisions.
In addition to the descriptions above regarding how we may use your data, we may use data that has been aggregated to enhance and personalize your experience with us, for promotional purposes, testing our IT systems, research, data analysis, improving our Site, developing new products and features, and for other purposes described in this Privacy Notice. We may use, without restriction, data that is aggregated or de-identified and is maintained in a form that cannot reasonably be used to infer data about, or otherwise be linked to, a particular individual or household. We do not intend to reidentify such data, except as required by applicable law, as reasonably necessary for fraud prevention or security purposes, or for internal research and product development.
4. Who We Share Your Data With & The Purpose of Disclosure
We may disclose data that we collect from you or that you provide as described in this Privacy Notice to the following categories and for the purposes set forth below:
- Service Providers. We disclose data to unaffiliated companies or individuals we hire or work with that perform services on our behalf, including customer support, web hosting, software developers, information technology services, database management, direct mail and email distribution. These service providers are contractually obligated to use your data only for the purposes for which it was disclosed to them and may have access to data we collect from you to perform the specific services we request from them.
- Other Third Parties. (i) Analytics. We engage third parties to provide analytics services regarding the Services such as assisting us to estimate our audience size and usage patterns by tracking certain data such as pages viewed, time spent on pages, links clicked, and conversion data through Automatic Tracking Technologies. (ii) Healthcare Partners. We may disclose data to Healthcare Partners such as iCare and partner institutions using electronic medical records systems to facilitate our services, in accordance with applicable law, including sharing patient information necessary to coordinate care, process referrals, and provide monitoring results to your healthcare providers.
- Corporate Transaction. Your data may be disclosed or transferred in anticipation of or in connection with a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of MyEyes’ assets or equity (each, a "Corporate Transaction"), whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which data held by MyEyes is among the assets transferred. In such event, we will use commercially reasonable efforts to direct any successor or transferee to use your data in a manner consistent with this Privacy Notice, subject to the terms and conditions of such Corporate Transaction.
- Law Enforcement Authorities and Individuals Involved in Legal Proceedings. We disclose data when we in good faith believe doing so is necessary or appropriate to comply with applicable law or legal process (including an enforceable request from authorities), to respond to claims (including inquiries by you in connection with your purchases from us), enforce or apply our other policies, or to protect the rights, property, or personal safety of us, our users, employees, or others.
- Professional Advisors. We may disclose your data to professional advisors, such as lawyers, bankers, auditors, and insurers, where necessary in the course of the professional services that they render to us.
- Your Consent or at Your Direction. We disclose data to third parties when we have your consent or direction to do so. We may also disclose your data to third parties, such as when you expressly direct us to do so or when you use our products or services to intentionally interact with third parties. In these cases, we disclose your data to carry out your request.
5. How We Protect Your Data
We have implemented commercially reasonable measures designed to secure your data from accidental loss and unauthorized access, use, alteration, and disclosure.
The safety and security of your data also depend on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Services, you are responsible for keeping this password confidential. Do not share your password with anyone.
Unfortunately, the transmission of data via the Internet is not completely secure. Although we use commercially reasonable efforts to protect your data, we cannot guarantee the security of your data transmitted to our Services. Any transmission of data is at your own risk. TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, WE ARE NOT LIABLE FOR ANY UNAUTHORIZED CIRCUMVENTION OF SECURITY MEASURES BY THIRD PARTIES DESPITE OUR COMMERCIALLY REASONABLE EFFORTS TO PROTECT THE SERVICES, NOR FOR ANY DATA LOSS OR BREACH RESULTING FROM YOUR FAILURE TO SAFEGUARD YOUR CREDENTIALS OR FROM EVENTS BEYOND OUR REASONABLE CONTROL.
6. Retention of your Data
We may retain your data for as long as we need it to provide you with the Services and for a reasonable period thereafter, which will vary depending on the nature of the data and our ongoing relationship with you. In addition, we may retain this data if necessary to comply with our legal obligations, resolve disputes, enforce our agreements, or for other legitimate business purposes to the extent permitted by applicable law.
When we process personal data, we determine the retention period taking into account various criteria, such as the type of Services provided to you, the nature and length of our relationship with you, the impact on our Services we provide to you if we delete some data from or about you, and mandatory retention periods provided by law.
7. Your Choices About Your Data
We strive to provide you with choices regarding the personal data you provide to us. Below are options for your personal data.
7.1. Accessing, Correcting, and Deleting Your Data
You may be able to review and change some of your personal data by logging on to your account and correcting the data. If you wish to access, correct, or delete additional data that we hold about you and is not accessible through your account, please contact us at the contact information listed in the How to Contact Us section below and we will try to assist you with your request, subject to applicable law and our ability to verify your identity.
7.2. Automatic Tracking Technologies
We and other third parties may use Automatic Tracking Technologies on the Site and App. While we take reasonable steps to work with third parties that respect your privacy, this Privacy Notice does not govern the data practices of those third parties. We encourage you to review the privacy notices of any third-party services that may collect data through our Site or App. To the extent that third-party Automatic Tracking Technologies constitute a sale or sharing of your personal data under applicable law, you may exercise your opt-out rights as described in this Privacy Notice or by using any preference signals we honor.
You may be able to block or disable Automatic Tracking Technologies on your device at any time by changing your preferences or options menus in your browser. You may also be able to reject or delete the Automatic Tracking Technologies that are stored on your device. However, blocking, disabling, or deleting Automatic Tracking Technologies may result in some parts of the Services being inaccessible or not functioning properly.
Each browser provides different mechanisms for managing Automatic Tracking Technologies. Look at your browser’s help menu to determine the best way to modify your browser’s Automatic Tracking Technologies storage. You can usually find these settings in the “Options” or “Preferences” menu of your browser. You can use the “Help” or similar option in your browser for more details. To specifically find out more about cookies, including how to see what cookies have been set and how to block and delete cookies, please visit: https://www.aboutcookies.org/.
The Services also use Google Analytics, which uses cookies or other Automatic Tracking Technologies to help us analyze how users interact with and use the Services, compile reports on activity, and provide other services related to activity and usage. Google Analytics may collect information such as your IP address, time of visit, whether you are a return visitor, and referring website. To learn more about how Google Analytics collects and processes data you may visit http://www.google.com/policies/privacy/partners. For more information on how to opt out of Google Analytics tracking across all websites you use, visit: https://tools.google.com/dlpage/gaoptout.
7.3. Our Email Marketing to You
If you do not wish to receive our marketing emails, you may unsubscribe by following the unsubscribe instructions at the bottom of the email or by contacting us through the contact information in the How to Contact Us section at the bottom of this Privacy Notice. Please allow up to ten (10) business days for your request to be processed. After you unsubscribe, however, you may continue to receive product or service-related and other non-marketing emails. If you have provided more than one email address to us, you may continue to be contacted unless you request to unsubscribe each email address you have provided.
7.4. Do Not Track Signals
Some web browsers (including Safari, Internet Explorer, Firefox, and Chrome) incorporate a “Do Not Track” (“DNT”) or similar feature that signals to websites that a user does not want to have his or her online activity and behavior tracked.
Please note that we do not recognize or respond to any DNT signal which your browser might transmit through the DNT feature your browser might have. However, we will honor Global Privacy Control ("GPC") signals or other legally mandated opt-out preference signals to the extent required by applicable law. If you wish to disable Automatic Tracking Technologies on our Site, you should not rely on any “DNT” feature your browser might have.
8. Links to Other Third-Party Sites
We may provide links to digital assets such as websites, applications, or services that we do not own or operate (“third-party digital assets”). Those links are provided for your convenience. If you follow the link and visit those third-party digital assets, they too may collect data about you. We do not own or control any third-party digital assets, and we are not responsible for the practices employed by third-party digital assets linked to or from our Site or App. We recommend that you review the privacy notices of other third-party digital assets before authorizing third-party access to your data.
9. Children Under the Age of 13
Our Services are not directed at or intended for children under 13 years of age. No one under the age of 13 may provide any data to or on the Services. We do not knowingly collect data from children under 13. If you are under 13, do not use or provide any data on the Site or App or through any of its features, or register in connection with the Services. If we learn we have collected or received data from a child under 13 without verification of parental consent, we will take reasonable steps to delete that data as soon as practicable, unless retention is required by applicable law. For users between the ages of 13 and 17, we may require parental or guardian consent before collecting or processing personal data, as required by applicable law. If you believe we might have any data from or about a child under 13, please contact us through the contact information in the How to Contact Us section below.
10. International Visitors
We are based in the United States. When we obtain data about you, we may process such data outside of the country in which you reside, including in the United States. We rely on applicable legal mechanisms to lawfully transfer data across borders, which may include your consent, contractual safeguards, or other transfer mechanisms recognized under applicable law. By using the Services, you acknowledge the transfer to and processing of your data in countries outside of your country of residence, which may have different data protection laws than those in the country where you reside.
11. Disabilities
This Privacy Notice is available to consumers with disabilities. To access this Privacy Notice in an alternative downloadable format, please visit myeyes.net/accessible.
12. Additional Notice for Health Data
If you reside in the states of Washington, Nevada, or other jurisdictions with applicable consumer health data privacy laws, please refer to our Consumer Health Data Privacy Notice (a supplemental notice addressing state-specific health data requirements) at myeyes.net/consumerhealth to learn more about our processing of health-related data.
13. How to Contact Us
To ask questions or comment about this Privacy Notice and our practices in general, contact us at:
Physical Address
MyEyes Corporation
2681 E Parleys Way, Suite 204
Salt Lake City, UT 84109
United States of America
Email
legal@myeyes.net