This California Privacy Rights Notice supplements our Privacy Policy and applies solely to California residents. It describes your rights under the California Consumer Privacy Act of 2018 ("CCPA") and the California Privacy Rights Act of 2020 ("CPRA"), and how to exercise those rights. Terms used but not defined in this Notice have the same meaning as in our Privacy Policy.
1. Categories of Personal Information We Collect
In the past 12 months, we have collected the following categories of personal information:
Identifiers: Name, postal address, email address, phone number, IP address, and similar identifiers. Collected from: you directly, automatically via website. Used for: providing Services, communications, analytics.
Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)): Name, address, telephone number, financial information relevant to financial assistance screening (income, household size). Collected from: you directly. Used for: providing Services, charity care screening.
Protected classification characteristics under California or federal law: We do not intentionally collect characteristics such as race, gender, or disability status. To the extent such information appears in medical records you provide, it is treated as PHI under our HIPAA Notice.
Medical and health information: Medical billing records, diagnosis and procedure codes, Explanation of Benefits documents, insurance correspondence, and medical records. Collected from: you directly and from healthcare providers with your authorization. Used for: providing Services.
Financial information: Income documentation, bank statement summaries, and payment information. Collected from: you directly. Used for: charity care eligibility screening and payment processing.
Internet or other electronic network activity information: Browsing history on our website, pages viewed, interactions with content, and device information. Collected from: automatically via cookies and tracking technologies. Used for: analytics, improving our website, advertising.
Geolocation data: General location based on IP address (city/state level only). Collected from: automatically. Used for: analytics, content personalization.
Professional or employment-related information: Employer name and contact information, where provided. Collected from: you directly. Used for: providing Services.
Inferences drawn from personal information: Profile created from your data to assess which services are most relevant to your situation. Used for: improving our Services.
2. Sources of Personal Information
We collect personal information from: you directly (through our website, intake forms, email, and phone); automatically through your use of our website; healthcare providers, hospitals, and insurance companies with your authorization; and payment processors in connection with transactions.
3. Purposes for Collecting Personal Information
We collect personal information for: providing and improving our Services; communicating with you; processing payments; complying with legal obligations; analytics and research; and, with your consent, marketing. See our Privacy Policy for complete details.
4. Disclosure of Personal Information
In the past 12 months, we have disclosed personal information to the following categories of third parties for business purposes:
Healthcare providers, hospitals, insurers, and collection agencies — as authorized by you and necessary to provide Services. Cloud storage and SaaS vendors — for data hosting, email, CRM, and analytics. Payment processors — for billing and transaction processing.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising in a way that would constitute a "sale" under the CCPA/CPRA.
5. Your California Privacy Rights
As a California resident, you have the following rights:
Right to Know: You have the right to request that we disclose: the categories of personal information we have collected about you; the categories of sources from which we collected it; our business or commercial purpose for collecting it; the categories of third parties with whom we share it; and the specific pieces of personal information we have collected about you.
Right to Delete: You have the right to request deletion of personal information we have collected from you, subject to certain exceptions. We may deny your request if the information is necessary to complete a transaction you requested, detect security incidents, comply with legal obligations, or for certain other lawful purposes.
Right to Correct: Under CPRA, you have the right to request correction of inaccurate personal information we maintain about you.
Right to Opt Out of Sale or Sharing: You have the right to opt out of the sale of your personal information or the sharing of your personal information for cross-context behavioral advertising. As noted above, we do not sell personal information. To opt out of interest-based advertising, use the Digital Advertising Alliance's opt-out tool at optout.aboutads.info.
Right to Limit Use of Sensitive Personal Information: You have the right to limit our use of sensitive personal information (including health information, financial account information, and precise geolocation) to purposes necessary to provide the Services you requested. To exercise this right, contact us at privacy@mederase.com.
Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny you Services, charge you different prices, provide you a different level of quality, or retaliate against you for exercising these rights.
6. How to Submit a Privacy Request
To exercise your rights described above, you may submit a request by:
Email: privacy@mederase.com
Phone: +1 (877) 512-0293 (ask for Privacy)
We will respond to verifiable consumer requests within 45 days. If we need more time (up to 90 days total), we will notify you within the initial 45-day period with the reason for the delay.
We may need to verify your identity before processing your request to protect your information from unauthorized disclosure or deletion. Verification may require you to provide information that matches what we have on file for you.
You may designate an authorized agent to submit a request on your behalf. We may require the agent to provide proof of your written authorization and verify your identity directly.
7. Shine the Light
California Civil Code Section 1798.83 ("Shine the Light") permits California residents to request, once per year, information about personal information disclosed to third parties for their direct marketing purposes during the preceding calendar year. We do not disclose personal information to third parties for their direct marketing purposes. If you have questions, contact us at privacy@mederase.com.
8. Contact
For questions about this California Privacy Rights Notice or to submit a privacy request:
MedErase Inc. — Privacy Officer
3333 Michelson Drive, Irvine, CA 92612
Email: privacy@mederase.com
Phone: +1 (877) 512-0293