Privacy
Last Updated: May 12, 2023
At Enduring Management Services, LLC d/b/a Miga ("Miga") your privacy is important to us. Our Privacy Policy describes the information we collect, how we collect the information, the reasons we collect information, and how we share or use the information we collect. This Privacy Policy also describes the choices you have with the information we collect, including how you can manage, update, or request to delete information.
Please take a moment to review this Privacy Policy. You may scroll through this Privacy Policy or use the headings below. It is important that you understand this Privacy Policy. By using our Platform, you are agreeing to the terms of this Privacy Policy. If you have any questions or concerns about this Privacy Policy, you may email privacy@migahealth.com at any time.
Table of Contents
- 1. Who is Miga?
- 2. Key Terms & Definitions and Our Privacy Policy
- 2.1 When does our Privacy Policy apply?
- 2.2 When does our Privacy Policy not apply?
- 2.3 Our Privacy Policy and Terms of Use
- 3. Personal Information
- 3.1 What is Personal Information?
- 3.2 What types of Personal Information do we collect?
- 3.3 How do we collect your Personal Information?
- 3.4 How do we use your Personal Information?
- 3.5 How do we share your Personal Information?
- 3.6 Your choices about how we share your Personal Information
- 3.7 How do I access and correct my Personal Information?
- 4. Who may use the Services?
- 5. Children’s Privacy
- 6. Does Miga respond to Do Not Track signals?
- 7. Data Security
- 8. California’s Shine the Light Law
- 9. Changes to our Privacy Policy
- 10. Contact Us
Who is Miga?
Miga exists to ensure everyone achieves the health they deserve. We do this by connecting our users with independent medical practitioners who offer a virtual cardiometabolic health program that helps our users manage their weight, blood pressure, high cholesterol, diabetes, and tobacco use from home with confidence. This is made possible by a personalized experience that includes a blood pressure monitor, scale, and medications.
Miga is not a medical group or a health care provider. Miga provides its users with the ability to obtain telemedicine consultations provided by independent medical practitioners including, but not limited to, Park Hill Health Services, P.A., Richard Joseph, M.D., P.C., and Park Hill Health Services of New Jersey, P.C. (collectively "Medical Group"), an independent medical group with a network of United States-based health care providers (each, a "Provider"). Medical Group (or your own medical provider if you do not use a Medical Group Provider) is responsible for providing you with a Notice of Privacy Practices describing its collection and use of your health information, not Miga.
Key Terms & Definitions and Our Privacy Policy
It is helpful to start by explaining some of our key terms and definitions used in this Privacy Policy:
- Our "Devices" - Miga devices compatible with our Platform
- "Personal Information" - Any information relating to an identified or identifiable individual
- and any information listed below
- Our "Platform" - Our Website and Devices
- "Privacy Policy" - This privacy policy
- "Products" - Any products available for purchase on our Platform
- Our "Services" - Any services provided through our Platform
- Our "Terms of Service" - Our terms of service located here
- Our "Website(s)" - Our websites, including: www.migahealth.com
- "Miga," "we," "us," or "our" - Enduring Management Services, LLC
When does our Privacy Policy apply?
This Privacy Policy describes the types of information we may collect from you when:
- You visit or use our Platform, including our Website;
- You wear our Devices and record Personal Information;
- We communicate via e-mail and through text; and
- We communicate in person, such as on the phone or through a telehealth visit.
When does our Privacy Policy not apply?
This Privacy Policy does not apply to information collected by any other website operated either by us or by a third party, unless the website is listed above or links to this Privacy Policy. It also does not apply to any website that we may provide a link to or that is accessible from our Platform.
This Privacy Policy does not apply to information collected from users who log-in to the password-protected and secure portions of our Platform ("Secure Platform"). The Secure Platform allows users who obtain the Services ("Customers") to perform certain functions or obtain the Services (such as telehealth visits from Medical Group or Providers). All information collected and stored by us or added by Customers into such Secure Platforms is treated as Protected Health Information ("PHI") as that term is defined by the Health Insurance Portability and Accountability Act ("HIPAA") and/or medical information and governed by applicable state and federal laws that apply to that information. Miga is not subject to HIPAA, but keeps all patient information private and secure at a standard at or above HIPAA requirements. How we use and disclose such PHI is in accordance with the applicable Notice of Privacy Practices provided to you by the Medical Group. We will not use or disclose information collected from the Secure Platform or received from Medical Group or your Provider for advertising, marketing, or other use-based data mining purposes. We will not sell any PHI.
Our Privacy Policy and Terms of Use.
This Privacy Policy is incorporated into our Terms of Use, which also applies when you use our Platform.
Personal Information
What is Personal Information?
Personal information is information from and about you that may be able to personally identify you. We treat any information that may identify you as personal information. For example, your name and e-mail address are personal information.
What types of Personal Information do we collect?
We may collect and use the following categories and specific types of personal information (hereinafter, collectively referred to as "Personal Information"):
- Personal identifiers - a real name, birth date, e-mail address, home address, shipping address, or Patient ID
- Information that identifies, relates to, describes, or is capable of being associated with a particular individual - name, username or online identifier, physical characteristics or description, shipping address, home address, driver’s license number, state ID number, passport number, IP address, email address, date of birth, insurance policy number, telephone number, credit card number, debit card number, health or medical information, weight, body mass index ("BMI"), whether you are a smoker or non-smoker, medical conditions, family medical history, medications currently taking or prescribed, measurement data, average heart rate, heart rate, step count, distance traveled, active and resting energy levels, sleep analysis, blood pressure readings, workout history, your activity levels, and accelerometer data
- Characteristics of protected classifications under California or federal law - Race, Color, Age, National Origin, Genetic Information, Citizenship, Ancestry, Marital Status, Sex (including gender, gender identity, gender expression, pregnancy or child birth), Sexual Orientation, or Disability
- Biometric information - Keystrokes, Sleep Data, Health Data, Exercise Data, Psychological Characteristics (such as mood, sentiment, thoughts, personality type), Genetics, and information related to treatment such as the results of blood and other medical tests
- Internet or other electronic network activity information - IP address, device mode, device ID, OS version, device language, operating system, browser type, and information regarding a consumer’s interaction with an Internet Web site, application, or advertisement
- Geolocation data - Physical location or movements, local time, and local time zone
- User generated content - Information you provide to be published or displayed (hereinafter, "Posted") on public areas of our Website or transmitted to other users of the Website or other third parties
Health Information
Some Personal Information we collect may constitute PHI as defined by HIPAA. As set forth above, your Provider will provide you with a Notice of Privacy Practices describing their collection and use of your health information, not Miga. We will only collect and use PHI for the purposes of providing the Services and we only collect the minimum amount necessary to fully perform and provide the Services on our Platform. We may combine your PHI with Personal Information that we have either obtained from you or through a third-party, such as your Provider, health insurer, employee benefits program, or other health care providers. PHI will not be used for any other purpose, including marketing, without your consent.
How do we collect your Personal Information?
We collect most of this Personal Information directly from you. For example, when we speak to you by phone, text message, and e-mail. Additionally, we will collect information from you when you visit our Website and fill out forms, wear one of our Devices, or purchase our Services.
We may also collect Personal Information in the following ways:
- From your mobile device or smart watch.
- From third-party apps you choose to connect your mobile device to, such as Apple Health or Google Fit.
- When You Use A Premium Feature. When you choose to participate in a premium service, we collect additional information from you related to those services. Some premium features are paid services.
- When you make payments through the Platform. Miga and/or it’s third-party payment processor collect credit and debit card numbers for payment purposes only. We use a Payment Card Industry (PCI) compliant vendor to collect payment information.
- When You Contact Us. When you contact Miga directly, such as when you contact our Customer Support team, we will receive the contents of your message or any attachments you may send to us, as well as any additional information you choose to provide.
We will also collect information automatically as you navigate through our Platform. We use the following technologies to automatically collect data:
- Cookies. We and our service providers may use cookies, web beacons, and other technologies to receive and store certain types of information whenever you interact with our Platform or Services through your computer or mobile device. A "cookie" is a small file or piece of data sent from a website and stored on the hard drive of your computer or mobile device. Some of the cookies we use are "session" cookies, meaning that they are automatically deleted from your hard drive after you close your browser at the end of your session. Session cookies are used to optimize performance of the Website and to limit the amount of redundant data that is downloaded during a single session. We also may use "persistent" cookies, which remain on your computer or device unless deleted by you (or by your browser settings). We may use persistent cookies for various purposes, such as statistical analysis of performance to ensure the ongoing quality of our Platform and/or the Services. We and third parties may use session and persistent cookies for analytics and advertising purposes, as described herein. On your computer, you may refuse to accept browser cookies by activating the appropriate setting on your browser, and you may have similar capabilities on your mobile device in the preferences for your operating system or browser. However, if you select this setting you may be unable to access or use certain parts of our Platform or the Services. Unless you have adjusted your browser or operating system setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our Platform.
- Meta Pixel (Facebook and Instagram). We use Meta Pixel, a web analytics and advertising service provided by Meta Platforms, Inc. (“Meta”) on our Platform. With its help, we and our customers can keep track of what users do after they see or click on a Facebook or Instagram advertisement, keep track of users who access our Platform or advertisements from different devices, and better provide advertisements to our target audiences. The data from Meta Pixel is also saved and processed by Meta. Meta can connect this data with your Facebook or Instagram account and use it for its own and others’ advertising purposes, in accordance with Meta’s Data Policy which can be found at https://www.facebook.com/about/privacy/. Please click here if you would like to withdraw your consent for use of your data with Meta Pixel https://www.facebook.com/settings/?tab=ads#_=_.
- FullStory. We use a third-party analytics provider called "FullStory" for certain type of use analytics. To learn more about FullStory and how FullStory stores this data, please view FullStory’s privacy policy here: https://www.fullstory.com/legal/privacy/.
- Google Analytics. We use Google Analytics, a web analytics service provided by Google, Inc. ("Google") to collect certain information relating to your use of our Platform. Google Analytics uses cookies, to help our Platform analyze how users use our Website. You can find out more about how Google uses data when you visit our Platform by visiting "How Google uses data when you use our partners' sites or apps", (located at www.google.com/policies/privacy/partners/). For more information, please visit Google and pages that describe Google Analytics, such as www.google.com/analytics/learn/privacy.html.
- Google Ads (AdWords). Google Ads (AdWords) remarketing service is provided by Google Inc. You can opt-out of Google Analytics for Display Advertising and customize the Google Display Network ads by visiting the Google Ads Settings page: http://www.google.com/settings/ads. Google also recommends installing the Google Analytics Opt-out Browser Add-on - https://tools.google.com/dlpage/gaoptout- for your web browser. Google Analytics Opt-out Browser Add-on provides visitors with the ability to prevent their data from being collected and used by Google Analytics. For more information on the privacy practices of Google, please visit the Google Privacy Terms web page: https://policies.google.com/privacy?hl=en.
- Hotjar. Our Platform uses Hotjar’s services, a third party service provider, which helps us better understand our users’ experience (e.g. how much time they spend on which pages, which links they choose to click, what users do and don’t like, etc.) and enables us to build and maintain our Platform and Services with user feedback. Hotjar uses cookies and other technologies to collect data on our users’ behavior and their devices (in particular device's IP address (captured and stored only in anonymized form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), preferred language used to display our website). Hotjar stores this information in a pseudonymized user profile. Neither Hotjar nor we will ever use this information to identify individual users or to match it with further data on an individual user. For further details, please see Hotjar’s privacy policy by clicking on this link. You can opt-out to the creation of a user profile, Hotjar’s storing of data about your usage of our site and Hotjar’s use of tracking cookies on other websites by following this opt-out link.
- Hubspot. We use Hubspot, a service provided by Hubspot, Inc. Hubspot uses web beacons and cookies stored on your computer and enabled to allow us to analyze the use of our Websites. HubSpot evaluates the collected information (e.g. IP address, geographical location, type of browser, duration of the visit, and pages accessed) on our behalf in order to generate reports on the visit and the pages visited. You can find more information on the data collected by HubSpot and its processing in HubSpot’s privacy policy: https://legal.hubspot.com/privacy-policy. You can find more information on the cookies used by HubSpot here and here. If you generally do not want HubSpot to collect data, you can prevent cookies from being stored at any time using your browser settings.
- Mixpanel. Mixpanel is provided by Mixpanel Inc. ("Mixpanel"). You can prevent Mixpanel from using your information for analytics purposes by opting-out. To opt-out of the Mixpanel service please visit Mixpanel’s site. For more information on what type of information Mixpanel collects, please visit Mixpanel’s terms of use.
- Stripe. We use Stripe as our payment processor. In order to allow Stripe to function properly, a cookie is stored on your browser, which assists Stripe in detecting and preventing fraud. These are considered session cookies and typically only remain on your browser for 24 hours. For more information on Stripe, please visit their privacy policy.
- Twitter. We use Twitter Pixel, a remarketing service, provided by Twitter, Inc. for marketing and advertising purposes. To learn more about how Twitter uses your Personal Information, we encourage you to visit Twitter’s privacy policy at https://twitter.com/en/privacy.
- Other third party tools. We use other third party tools which allow us to track the performance of our Platform. These tools provide us with information about errors, app and website performance, and other technical details we may use to improve our Platform and/or the Services. For more information related to these third-party analytics providers please review How do we collect your Personal Information?.
How do we use your Personal Information?
We may use your Personal Information for the following purposes:
- Operate, maintain, supervise, administer, and enhance our Platform or the Services, including monitoring and analyzing the effectiveness of content on the Platform, aggregate site usage data, and other usage of the Platform and/or the Services such as assisting you in completing the registration process.
- Provide our Products and Services to you, in a custom and user-friendly way.
- Provide you with information, Products, or Services that you request from us or that may be of interest to you.
- Promote and market our Platform and/or the Services to you. For example, we may use your Personal Information, such as your e-mail address, to send you news and newsletters, special offers, and promotions, or to otherwise contact you about Products or information we think may interest you. We also may use the information that we learn about you to assist us in advertising our services on third party websites. You can opt-out of receiving these e-mails at any time as described below.
- To provide you notices or about your account.
- Contact you in response to a request.
- To notify you about changes to our Platform and/or the Services or any Products we offer or provide through them.
- Fulfill any other purpose for which you provide it.
- To carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection.
- Anonymize and aggregate information for analytics and reporting.
- To respond to law enforcement requests, court orders, and subpoenas and to carry out our legal and contractual obligations.
- Authenticate use, detect fraudulent use, and otherwise maintain the security of our Platform and the safety of others.
- To administer surveys and questionnaires.
- To provide you information about goods and services that may be of interest to you, including through newsletters.
- Any other purpose with your consent.
How do we share your Personal Information?
We may share Personal Information with third parties in certain circumstances or for certain purposes, including:
- Our business purposes. We may share your Personal Information with our affiliates, vendors, service providers, and business partners, including our data hosting and data storage partners, analytics and advertising providers, technology services and support, and data security advisors. We may also share your Personal Information with professional advisors, such as auditors, law firms, and accounting firms.
- Your healthcare providers or family. With your consent, we may share your information, including information collected from your use of our Platform, with your health care providers and/or family members (e.g., immediate family or friends) that you designate to receive your information.
- Other health-focused mobile apps. With your consent, we may share your profile information and data collected from your connected devices with other health-focused mobile applications installed on your mobile device to help you track your health and wellness information. If you share your information with these apps, your Personal Information, including your health information, will be used in accordance with privacy policies for those separate apps, not this Privacy Policy.
- With your consent. We may share your Personal Information if you request or direct us to do so.
- Compliance with law. We may share your Personal Information to comply with applicable law or any obligations thereunder, including cooperation with law enforcement, judicial orders, and regulatory inquiries.
- Business Transfer. We may share your Personal Information to a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of a bankruptcy, liquidation, or similar proceeding, in which Personal Information held by us about our users are among the assets transferred.
- To enforce our rights. We may share your Personal Information to enforce any applicable terms and conditions and Terms of Use, and to ensure the safety and security of our Services and our users.
- De-identified information. We may also disclose de-identified information, so that it cannot be reasonably used to identify any individual, with third parties for marketing, advertising, research, or similar purposes.
- To improve our Platform. We may use your Personal Information for internal testing, research, analysis, and product development, including to develop and improve our website/application, and to develop, improve, or demonstrate our products and services.
- To market our products and services. We may share your Personal Information with affiliates and third parties to market our products and services.
- Third Party Analytics. We use Google Analytics and Mixpanel to understand and evaluate how visitors interact with our Platform and/or the Services. These tools help us improve our Platform and/or the Services, performance, and your experience.
Your choices about how we share your Personal Information.
This section of our Privacy Policy provides details and explains how to exercise your choices. We offer you choices on how you can opt out of our use of tracking technology, disclosure of your Personal Information for our advertising to you, and other targeted advertising. We do not control the collection and use of your information collected by third parties. These third parties may aggregate the information they collect with information from their other customers for their own purposes. You can opt out of third parties collecting your Personal Information for targeted advertising purposes in the United States by visiting the National Advertising Initiative's (NAI) opt-out page and the Digital Advertising Alliance's (DAA) opt-out page.
Each type of web browser provides ways to restrict and delete cookies. Browser manufacturers provide resources to help you with managing cookies. Please see below for more information.
- Google Chrome
- Internet Explorer
- Mozilla Firefox
- Safari (Desktop)
- Safari (Mobile)
- Android Browser
- Opera
- Opera Mobile
For other browsers, please consult the documentation that your browser manufacturer provides.
If you do not wish to have your e-mail address used by Miga to promote our own Products and Services, you can opt-out at any time by clicking the unsubscribe link at the bottom of any e-mail or other marketing communications you receive from us or logging onto your Account Preferences page. This opt out does not apply to information provided to Miga as a result of a product purchase, or your use of our Platform and/or the Services. You may have other options with respect to marketing and communication preferences through our Platform.
You may also see certain ads on other websites because we participate in advertising networks. Ad networks allow us to target our messaging to users through demographic, interest-based, and contextual means. These networks track your online activities over time by collecting information through automated means, including through the use of cookies, web server logs, and web beacons. The networks use this information to show you advertisements that may be tailored to your individual interests.
How do I access and correct my Personal Information?
You can review and change your Personal Information by logging into our Services and visiting either the "About You" or "Health Details" sections of our Platform. You may also contact us using the information at the bottom of the page to inform us of any changes or errors in any Personal Information we have about you to ensure that it is complete, accurate, and as current as possible or to delete your account. We cannot delete your personal information except by also deleting your account with us. We may also not be able to accommodate your request if we believe it would violate any law or legal requirement or cause the information to be incorrect.
Who may use the Services?
This Privacy Policy applies to all personal uses of our Platform globally and you should not use the Platform and/or the Services if you do not agree to the Privacy Policy and Terms of Use. By using or downloading the Platform, you agree that your Personal Information, including any information about your health that you provide directly to us or that we collect through your use of the Platform and/or the Services, may be transferred to and stored in the United States.
Miga operates subject to state and federal regulations, and the Platform and/or the Services may not be available in your state. You represent that you are not a person barred from enrolling for or receiving the Services under the laws of the United States or other applicable jurisdictions in which you may be located. Access to and use of the Platform and/or the Services is limited exclusively to users located in states within the United States where the Platform and/or the Services is available. The Platform and/or the Services are not available to users located outside the United States. Accessing the Platform and/or obtaining the Services from jurisdictions where content is illegal, or where we do not offer the Platform and/or the Services, is prohibited.
Children’s Privacy
Miga understands the importance of protecting children’s privacy in the interactive online world. Our Platform is not designed for, or intentionally targeted at, children 13 years of age or younger. It is not our policy to intentionally collect or maintain information about anyone under the age of 13. No one under the age of 13 should submit any Personal Information the Platform, and if we learn that we have collected or received Personal Information from a child under 13, we will delete that information. If you are the parent or guardian of a child under 13 years of age whom you believe might have provided us with their Personal Information, you may contact us using the information at the bottom of the page to request the Personal Information be deleted.
We do not knowingly collect or sell Personal Information from children under the age of 18. If you are under the age of 18, do not use or provide any information on or to the Platform or through any of its features. If we learn we have collected or received Personal Information from a child under the age of 18 regardless of any parental consent, we will delete it. If you are the parent or guardian of a child under 18 years of age whom you believe might have provided use with their Personal Information, you may contact us using the information at the bottom of the page to request the Personal Information be deleted.
Does Miga respond to Do Not Track signals?
Some web browsers have a "Do Not Track" feature. This feature lets you tell websites you visit that you do not want to have your online activity tracked. These features are not yet uniform across browsers. Our Platform is set up to respond to those signals.
Data Security
We have taken steps and implemented administrative, technical, and physical safeguards designed to protect against the risk of accidental, intentional, unlawful, or unauthorized access, alteration, destruction, disclosure, or use. The Internet is not 100% secure and we cannot guarantee the security of information transmitted through the Internet. Where you have been given or you have chosen a password, it is your responsibility to keep this password confidential.
The sharing and disclosing of information via the internet is not completely secure. We strive to use best practices and industry standard security measures and tools to protect your data. However, we cannot guarantee the security of Personal Information transmitted to, on, or through our Services. Any transmission of Personal Information is at your own risk. We are not responsible for the circumvention of any privacy settings or security measures contained on our Platform, in your operating system, or mobile device.
California’s Shine the Light Law.
California Civil Code Section 1798.83 (California’s "Shine the Light" law) permits users of our Platform and/or the Services that are California residents and who provide Personal Information in obtaining products and services for personal, family, or household use to request certain information regarding our disclosure of Personal Information to third parties for their own direct marketing purposes. If applicable, this information would include the categories of Personal Information and the names and addresses of those businesses with which we shared your Personal Information with for the immediately prior calendar year (e.g. requests made in 2021 will receive information regarding such activities in 2020). You may request this information once per calendar year. To make such a request, please contact us using the information below.
Changes to our Privacy Policy
We may update our Privacy Policy periodically to reflect changes in our privacy practices, laws, and best practices. If we make changes to our practices with regards to the Personal Information we collect from you, we will notify you by e-mail to the e-mail address specified in your account and/or through a notice on the Platform. The date this Privacy Policy was last revised is identified at the top of the page. You are responsible for ensuring we have an up-to-date active and deliverable e-mail address for you, and for periodically accessing the Platform and reviewing this Privacy Policy to check for any changes.
Contact Us
If you have any questions, concerns, complaints or suggestions regarding our Privacy Policy or otherwise need to contact us, you may contact us at the contact information below.
Enduring Management Services, LLC 548 Market St PMB 50727, San Francisco, CA 94104-5401 privacy@migahealth.com (415) 851-3224