Last updated September 2018.

Advanta Health Solutions (“we” or “us” or “our”) respects the privacy of our users (“user” or “you”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information. Please read this Privacy Policy carefully. IF YOU DO NOT AGREE WITH THE TERMS OF THIS PRIVACY POLICY, PLEASE DO NOT PROVIDE ANY INFORMATION TO US.

What information we collect from you

GENERAL INFORMATION COLLECTED
We administer exercise incentive programs on behalf of insurers and companies seeking to promote the benefits of physical activity to their members or employees. To administer these programs, we receive, store and transmit information that includes the following personally identifiable information (together referred to as "Information" or "information"):
  • Program Eligibility Information: This information is received from your insurer or employer as an eligibility file that includes your name, gender, mailing address, birthdate, and membership identification numbers.
  • Participant Information: To supplement the eligibility file, you provide additional information during and after enrollment including your fitness facility membership, personal address changes and the bank account to which you would like incentives processed.
  • Engagement Information: As you participate in the incentive program, we collect and maintain information on your physical activity including visits and fitness facility location.

All information is encrypted both in transit and on our servers, which in turn are protected by firewall and other security measures.

COLLECTION OF ADDITIONAL INFORMATION
We may request access or permission to collect the following additional information, either continuously or while you are engaging with the mobile application(s) which is related to our incentive program ("Application"):
  • location-based information from your mobile device in order to provide location-based services;
  • certain features from your mobile device, including your mobile device’s Bluetooth, SMS messages, storage, and other features.
If you wish to change our access or permissions, you may do so in your device’s settings. Please be aware that the Application(s) inherent functionality relies on its ability to detect your location at a fitness facility and this functionality may not work properly without these permissions enabled for the Application.

MOBILE DEVICE DATA
We capture certain of your device information on our Diagnostics screen under Settings such as your mobile device ID number, model, and manufacturer, version of your operating system, version of the Application you are running, available memory and permissions provided to the Application. This device information is stored in our server logs.

PUSH NOTIFICATIONS
We may request to send you push notifications regarding your account or the Application. If you wish to opt-out from receiving these types of communications, you may turn them off in your device’s settings.

INFORMATION PROVIDED BY THIRD-PARTIES
We may also receive information from third parties in one of the following ways:
  • You connect your account to the third party and grant the Application permission to access personal information or partnerships with other companies. This information generally is not stored by us but rather a token is granted to us that will require you to periodically re-verify we should have continued access;
  • Certain third parties provide information related to our provision of services under the incentive program such as detection of your visit to a fitness facility, payment of reimbursements, and support of the Application. This collection of information is more fully described below.

DATA FROM CONTESTS, GIVEAWAYS, AND SURVEYS
We may collect other personal information you may provide when entering contests, giveaways or responding to surveys.

How we use your information
Having accurate information about you permits us to provide you with a smooth, efficient, and customized experience. Specifically, we may use information collected about you to:
  1. Administer sweepstakes, promotions, and contests.
  2. Assist law enforcement and respond to subpoena.
  3. Compile anonymous statistical data and analysis for use internally or with third parties.
  4. Create and manage your account.
  5. Deliver targeted messaging, coupons, content, and other information regarding promotions and the Application to you.
  6. Email you regarding your account.
  7. Generate a personal profile about you to make future visits to the Application more personalized.
  8. Increase the efficiency and operation of the Application.
  9. Monitor and analyze usage and trends to improve your experience with the Application.
  10. Notify you of updates to the Application.
  11. Offer new products, services, mobile applications, and/or recommendations to you.
  12. Perform other business activities as needed.
  13. Prevent fraudulent transactions, monitor against theft, and protect against criminal activity.
  14. Process reimbursement payments and corrections.
  15. Request feedback and contact you about your use of the Application.
  16. Resolve disputes and troubleshoot problems.
  17. Respond to product and customer service requests.
  18. Solicit support for the Application.

With whom we share your information
We do not share your information with others, except as indicated in this Privacy Policy and as follows:
  • We may share your information with agents, service providers, vendors, contractors or affiliates who process the information only on our behalf for the purposes set forth in this Privacy Policy including payment processing, data analysis, email delivery, customer service, hosting services, and marketing assistance.
  • We may share your information based on a good faith belief that such sharing is required by law, or in the interest or protecting or exercising our or others’ legal rights, e.g., without limitation, in connection with requests from law enforcement officials and in connection with court proceedings. This includes exchanging information with other entities for fraud protection.
  • We may share or transfer your information in connection with a prospective or actual sale, merger, transfer or other reorganization of all or parts of our business.
  • We may share your information where you have granted us permission.
  • We may share and use aggregated anonymized data for our own business purposes.

Use of third-party services
The Application(s) uses third party services that may collect information used to identify you. The following third party services are used (you may view their individual privacy policies by clicking on the name of the service):
  • Gimbal - Gimbal provides us with beacons for use in fitness facilities. Beacons are small devices that emit a radio signal enabling the app to detect that you have entered your fitness facility.
  • Proximi.io - Proximi is used by the APP to recognize geofences and beacons at your defined fitness facilities. Geofences are detected by using global positioning and location detection from your mobile phone. Any data collected is automatically deleted after six months.
  • Firebase - Firebase’s Messaging component is used to deliver messages and notifications to your phone within the APP.
  • Firebase Analytics - Firebase Analytics provides non-identifiable information on APP usage and user engagement.
  • Fabric - Fabric is an APP development platform that works with Crashlytics to provide us with non-identifiable information about APP performance.
  • Crashlytics - Crashlytics is a tool we use that provides real-time analytics for the APP related to crashes occurring with non-identifiable information like APP version, device type, and operating system which helps us target issue resolution.
  • Walgreens - Walgreens partners with Advanta to provide Balance Reward® Points for steps tracked within the APP. Advanta does not store your Walgreens account information nor have access to any of your Walgreens account details.
  • Salesforce - Salesforce is utilized to track contacts with potential and current clients and members. The platform also facilitates emailing contacts and logging those interactions for better member support.
  • Bank of America – ACH Payments Management services for ACH direct deposit payment of reimbursements.

The providers specified above may change from time to time. We will use reasonable efforts to update this Privacy Policy to reflect such changes.


MARKETING COMMUNICATIONS
From time to time, we may offer you the opportunity to receive information regarding products, services, and information from third parties that we believe may be of interest to you. You may opt to receive such information through a link which you may voluntarily click or through making a specific request to share your information with such third party. If you opt to receive such information by clicking the link or granting consent, we may share your information with the third party. We, and/or the third party, will always include the opportunity to withdraw consent. If you notify us at privacy@advantahealth.com, we will stop providing such third party any access to your information. You should contact the third party directly to stop receiving additional materials based on information provided before your consent was withdrawn.


AFFILIATES
We may share your information with our affiliates, in which case we will require those affiliates to honor this Privacy Policy. Affiliates include our parent company and any subsidiaries, joint venture partners or other companies that we control or that are under common control with us.


SALE OR BANKRUPTCY
If we reorganize or sell all or a portion of our assets, undergo a merger, or are acquired by another entity, we may transfer your information to the successor entity. If we go out of business or enter bankruptcy, your information would be an asset transferred or acquired by a third party. You acknowledge that such transfers may occur and that the transferee may decline honor commitments we made in this Privacy Policy.
We are not responsible for the actions of third parties with whom you share personal or sensitive data, and we have no authority to manage or control third-party solicitations. If you no longer wish to receive correspondence, emails or other communications from third parties, you are responsible for contacting the third party directly.

How you can access your information
Information you provide to us is accessible through the portal website and the Application. At any time you may access this information through the “My Account,” “Payment Account,” “Change Status” and “My Clubs” functions in the Member Portal to make changes or modify permissions you have previously given us.

You can request to discontinue use of the Application(s) by contacting us. After you request to discontinue use of our Application(s), you will not be able to access your account information or sign in. You can reinstate your account at any time providing you are eligible to participate in the program as determined by your insurance provider or employer.

We may retain certain information associated with your account for analytic and record keeping purposes to enable program reporting to your insurer or employer. On termination of the program, however, all Information will be deleted or anonymized as more fully described below.

Your choices with respect to the collection and use of your information
  • You may add or update your information and close your account.
  • You may choose not to provide us with any information, however this may limit or prevent you from using our Application(s) or some of its features.
  • You are able to control what emails and messaging you receive from us. We reserve the right to send you communications relevant to your use of our Application(s) including, but not limited to service notifications, technical issue alerts, and administrative messages, without providing you the opportunity to opt out of them.
  • You may choose to accept or reject cookies through your browser for our sites. Please note that refusal to accept cookies from our sites will prevent you from using various features.

Cookies and other technologies
Cookies are small data text files that are stored on your computer’s hard drive if allowed by your Web browser. You can control which cookies you accept or reject through your browser settings.

We use cookies for the following purposes:
  • To help us recognize you as a previous visitor and to save or remember any preferences that may have been set while your browser was visiting our site. For example, to remember your login information to reduce the number of times you have to login when you visit. A cookie may also record your password if you choose options to keep you signed in or sign you in automatically. Cookies that contain sensitive information such as member IDs, passwords and any other account-related information are encrypted for security.
  • To help us customize your experience on the website by showing you relevant content and promotions applicable to you and your insurance plan. A cookie may also be set by us to identify you to our service providers or partners as you navigate to third-party links.
  • To help us gather analytics about the effectiveness of the website features and offerings including promotions and email communications.
For more information about cookies and how they are used, please visit https://cookiesandyou.com/.

Display of tailored content
Information you provide to us and data collected by the Application(s) may be used to serve relevant content to you. We may use data you provide in a form, cookies, beacons, geolocation and other technologies to collect information about your fitness activities and use this information to provide tailored messaging approved by your health insurance provider or promotions that match your needs or interests.

Using the mobile phone App
This Privacy Policy does not apply to the third-party online/mobile store from which you install the Application or make payments, which may also collect and use data about you. We are not responsible for any of the data collected by any such third party.

How we protect your information
We take administrative, technical, physical and other measurers to safeguard your information against loss, theft, and misuse, as well as against unauthorized access, disclosure, alteration, and destruction. We also take precautions to protect user data offline. All Information is encrypted on our servers. The servers in turn are protected by firewall and other security measures. Our employees, consultants, and independent contractors who need Information to perform a specific job (for example, a Member Services representative) are granted access to Information and are required to lock their station when not present.

All of our employees, consultants and independent contractors are kept up-to-date on our security and privacy practices. Every quarter and whenever new policies are implemented, our employees, consultants and independent contractors are educated and reminded about the importance of keeping your data secure and safe at all times. The servers which contain Information are stored in a secure environment.

When you choose to provide information to other parties, the information you share may be visible to other users and can be read, collected, or used by them. You are responsible for the information you choose to submit in these instances. For example, if you list your name and email address in a posting, that information is public. Please exercise caution when sharing information or when using any of these features.

Retention of your information
We make it easy for you to keep your information accurate, complete, and up-to-date. We will retain your information for the longer of (i) the period during which the incentive program is offered by your insurer or employer or (ii) the period required by law. Upon the expiration of the retention period, we will either destroy your information, or provide it to the insurer or employer that sponsored the program. We may retain anonymized data for analytic and auditing purposes. However, such anonymized data will not include any Information.

Children’s privacy
We do not provide services to anyone under the age of 18. We do not knowingly collect Information from children under the age of 18. If it is discovered that a child under the age of 18 has provided us with personal information, we will immediately delete this data from our services. If you are a parent or guardian of a minor and are aware that your child has provided us with personal information, please contact us to allow us to take necessary action.

External links
Our websites and Application may contain links to other sites. If you click on a third-party link, you will be directed to that site. These external sites are not operated by us. You are strongly advised to review the privacy policies of these websites before sharing any information with them. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Data storage & transfer
Information you provide to us is stored and processed on servers located in the United States and elsewhere and may be transferred to other locations around the world. By using our services, you consent to the transfer of Information described in this Privacy Policy to locations that may be outside of the country in which you reside. Such locations may be in North America, in one or more European countries or in one or more countries within Asia.

Visiting our website from outside the United States
We do not collect information from individuals located outside the United States.

Your California Privacy Rights
Under California’s "Shine the Light" law, California residents who provide personal information in obtaining products or services for personal, family or household use are entitled to request and obtain from us, once per calendar year, information about the customer information we shared, if any, with other businesses for their own direct marketing uses. If applicable, this information would include the categories of customer information and the names and addresses of those businesses with which we shared customer information for the immediately prior calendar year, e.g. requests made in 2018 will receive information regarding 2017 sharing activities. To obtain this information from us, please email privacy@advantahealth.com with "Request for California Privacy Information" on the subject line and in the body of your message. We will provide the requested information to you at your email address in response. Not all information is covered by the "Shine the Light" requirements and only information on covered sharing (if any) will be included in our response.

Changes to this Privacy Policy
We may make changes to this Privacy Policy at any time and for any reason. We will alert you of changes by updating the “Last updated” date of this Privacy Policy. When we change the Privacy Policy in any material way, we will notify you through the Application(s).

We encourage you to review this Privacy Policy periodically to stay informed of updates. You will be deemed to have been informed and to have accepted the changes in any revised Privacy Policy by your continued use of the Application or any other services by or through us after the date such revised Privacy Policy is posted.

How you can contact us
If you have any questions about our Privacy Policy, do not hesitate to contact us:

Advanta Health Solutions
550 Broad Street, Suite 804
Newark, NJ 07102
privacy@advantahealth.com

Copyright 2019. All Rights Reserved. Privacy Policy.

Advanta Health Solutions | 550 Broad Street, Suite 804, Newark, NJ 07102 Phone: (201) 351-7850 Ext. 2