Last Updated: September 29, 2026
At Nutrition Fact Point ("we," "us," "our"), we recognize that your health information is among the most sensitive data you share. This Privacy Policy explains how we collect, use, protect, and disclose information gathered through our website, mobile applications, telehealth services, and in-person wellness visits across the United States.
By using our services, you consent to the practices described in this policy. We encourage you to read it carefully.
1. Information We Collect
1.1 Personal Information You Provide
- Identity Data: Name, date of birth, gender, government-issued IDs (when required)
- Contact Data: Billing address, shipping address, email, phone number, emergency contact
- Account Data: Username, password, security questions, preferences
- Payment Data: Credit/debit card numbers, bank account details (processed by PCI-compliant third parties)
1.2 Health Information (Protected Health Information / PHI)
As a health services provider, we collect and maintain PHI as defined by HIPAA:
- Medical history, diagnoses, and treatment records
- Lab results, imaging, and diagnostic reports
- Prescriptions and medication lists
- Genetic testing results and biomarker data
- Telehealth session recordings (with your consent)
- Insurance information and claims
1.3 Automatically Collected Data
- Technical Data: IP address, browser type, device identifiers, operating system
- Usage Data: Pages visited, time spent, click patterns, referring URLs
- Location Data: General geographic location derived from IP address
- Cookies and Similar Technologies: See Section 7
2. How We Use Your Information
We use your information for the following purposes:
- Treatment & Care Delivery: To provide, coordinate, and manage your healthcare
- Payment Processing: To process payments, submit insurance claims, and manage billing
- Healthcare Operations: Quality improvement, staff training, audits, and business administration
- Communication: Appointment reminders, follow-ups, and care coordination
- Marketing (with consent): Wellness content, newsletters, and promotional offers
- Legal & Compliance: To meet HIPAA, state, and federal healthcare regulations
- Research (de-identified): To improve treatments and develop new wellness programs
3. HIPAA Compliance & Your Rights
As a HIPAA-covered entity, we are required to protect your PHI and provide you with specific rights:
- Right to Access: Request copies of your medical records
- Right to Amend: Request corrections to your health information
- Right to an Accounting: Receive a list of disclosures of your PHI
- Right to Restrict: Request limits on how we use or disclose your PHI
- Right to Confidential Communications: Receive communications through preferred channels
- Right to a Paper Copy: Obtain a printed version of this Notice
- Right to File a Complaint: With us or the U.S. Department of Health and Human Services
4. How We Share Your Information
We do not sell, rent, or trade your personal or health information. We may share data only as follows:
- Treatment Providers: Specialists, labs, pharmacies involved in your care
- Business Associates: Vendors who perform services on our behalf under signed BAAs (Business Associate Agreements)
- Insurance Companies: For claims processing and pre-authorizations
- Legal Requirements: Court orders, subpoenas, or public health mandates
- Emergency Situations: To prevent serious harm to you or others
- With Your Written Authorization: For any other purpose you explicitly approve
5. Data Security
We implement industry-leading security measures to protect your information:
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- SOC 2 Type II certification
- Multi-factor authentication (MFA) for all staff and users
- Regular penetration testing and vulnerability scans
- Annual HIPAA security risk assessments
- Strict employee access controls and background checks
6. Data Retention
We retain your health information in accordance with state and federal requirements — typically 7 years for adults and until age 25 plus 7 years for minors. Marketing and account data are retained until you request deletion or unsubscribe.
7. Cookies & Tracking Technologies
We use essential cookies for site functionality and optional analytics cookies (with consent) to improve our services. You can manage cookie preferences through your browser settings or our cookie banner. We do not sell data collected via cookies to third parties.
8. Children's Privacy
Our services are not directed to children under 13. For minors receiving care, a parent or legal guardian must create and manage the account. We comply with COPPA and state minor consent laws.
9. California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights including:
- Right to know what personal information is collected
- Right to delete personal information (subject to healthcare retention laws)
- Right to opt-out of sale (we do not sell personal information)
- Right to non-discrimination for exercising your rights
To exercise these rights, contact our Privacy Officer using the details below.
10. International Users
Our services are intended for US residents. If you access our services from outside the United States, your data will be transferred to and processed in the US, where data protection laws may differ from your country.
11. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be posted with a revised "Last Updated" date and, where required, communicated via email or website notice. Continued use after changes constitutes acceptance.
12. Contact Us
13. Filing a Complaint
If you believe your privacy rights have been violated, you may file a complaint with:
- Our Privacy Officer — at the address above
- U.S. Department of Health and Human Services, Office for Civil Rights
200 Independence Avenue, S.W.
Washington, D.C. 20201
hhs.gov/ocr/complaints
We will not retaliate against you for filing a complaint.