Privacy Policy

Effective Date: February 27, 2018

 

This Privacy Policy describes Rivet Health, Inc.’s (“Rivet”) practices regarding the collection, use and disclosure of the information we collect from and about you when you use Rivet’s web-based and mobile applications and Rivet’s websites (including rivethealth.com and blog.rivethealth.com) that link to this Privacy Policy (the “Services”). By accessing or using the Services, you agree to this Privacy Policy and our Terms and Conditions.

 

IF YOU DO NOT AGREE TO THIS PRIVACY POLICY, PLEASE DO NOT USE THE SERVICES.

 

This Privacy Policy contains the following sections:

  • The Information We Collect
  • How We Use Your Information
  • Cookies and Similar Technologies
  • Online Analytics and Advertising
  • How We Share and Disclose Your Information
  • Your Choices
  • Third Party Links and Services
  • Children’s Privacy
  • International Users
  • Your Rights
  • How Long We Store Your Information
  • Changes to Our Privacy Policy
  • How We Protect Your Information
  • California Privacy Rights
  • Rivet Contact Info

 

THE INFORMATION WE COLLECT

Rivet collects a variety of information that you provide directly to us. We process your information when necessary to provide you with the Services that you have requested when accepting our Terms and Conditions, and/or when we have obtained your prior consent, and/or when we have a legitimate interest to do so. For example, we may have a legitimate interest to process your information for security, testing, maintenance, and enhancement purposes of the Services we provide to you, or for analytics, research, and reporting purposes related to the Services generally. Without your information, we cannot provide you with the Services you have requested or you may be limited in your use of the Services.

 

  1. Information You Provide to Us

Rivet collects information from you through:

  • Account and product registration and administration of your account
  • The Rivet Services that you use
  • Requests or questions you submit to us via forms or email (e.g., support forms, sales forms, user research participation forms)
  • Your communications and dealings with us
  • Your participation in Rivet sweepstakes, contests, or research studies
  • Uploads or posts to the Services
  • Requests for customer support and technical assistance

Information from and about you. The types of information we collect will depend upon the Services you use, how you use them, and what information you choose to provide. The types of data we collect directly from you may include:  (i) name, address, telephone number, email address and other optional information (such as a photograph) that you elect to associate with your account (collectively referred to as your “Profile Information”), (ii) log-in details and password (if you create an Rivet account), (iii) with your permission, calendar information stored on your mobile device, (iv) any email requests or questions you submit to us,  (v) with your permission, demographic information (such as your gender), and (vi) user-generated content you post in public online Rivet forums (e.g., the Rivet Blog).

Content. In using the Services, you may upload or input various types of content, including but not limited to payers, contacts, fee schedules, contract terms, documents, spreadsheets, reimbursement rates, and pricebooks or other materials (together, the “Uploaded Materials” or “Data”). If you are using the Services in connection with an account created by a Rivet Customer (e.g., employer, organization, or an individual), we collect and process the Data you submit on behalf of the Customer. As described more throughout this Policy, our Customers, and not Rivet, determine their own policies regarding storage, access, modification, deletion, sharing, and retention of Data which may apply to your use of the Services. For example, a Customer may provide or remove access to the Services, enable or disable third party integrations, manage permissions, retention and export settings, transfer or assign teams, or share reports. Please check with the Customer about the policies and settings that they have instituted with respect to the Data that you provide when using the Services.

Payment Information. We will utilize a third party credit card payment processing company to collect payment information, including your credit card number, billing address and phone number. The third party service provider, and not Rivet, stores your payment information on our behalf.

Information about others. If you choose to use our invitation service to invite a friend to the Services, we will ask you for that person’s contact information, which may include their email address, telephone number or their social network identity, and automatically send an invitation. Rivet stores the information you provide to send the invitation, to register your friend if your invitation is accepted, and to track the success of our invitation service.

 

  1. Information We Automatically Collect

When you use our Services that connect to the Internet, including, but not limited to, when you access the Services via our websites, your mobile devices, and Rivet software/applications, we automatically collect certain information. As discussed further below, we and our service providers (who are third party companies that work on our behalf to provide and enhance the Services) use a variety of technologies, including cookies and similar tools as defined below, to assist in collecting this information.

Log Files

When you use the Services, our servers automatically record certain information in server logs. These server logs may include information such as your web request, Internet Protocol (“IP”) address, browser type and settings, referring / exit pages and URLs, number of clicks and how you interact with links on the Services, metadata associated with uploaded Data, domain names, landing pages, pages viewed, mobile carrier, date and time stamp information and other such information.

Device Identifiers

When you access the Services using a mobile device, we collect specific device information, including your MAC address and other unique device identifiers. We also collect information such as the type of device you are using, its operating system, and mobile network information, which may include your mobile phone number. We may associate this device identifier with your account and will use data associated with your device identifier to customize our Services to your device and to analyze any device-related issues.

Location Information

We collect and process general information about the location of the device from which you are accessing the Services (e.g., approximate geographic location inferred from an IP address).

 

  1. Information We Collect From Third Party Integrations

If you choose to use third party integrations through the Services or are required to do so by a Customer, such providers may allow us and our service providers to have access to and store additional information about your interaction with those services and platforms as it related to use of the Services. If you do not wish to have this information shared, do not initiate these connections.

 

  1. Information We Collect from Affiliates and Non-Affiliated Third Parties

Rivet may receive additional information about you, such as demographic information, from affiliates under common ownership and control, and from third parties, such as business partners, marketers, researchers, analysts, and other parties that we may use to supplement the information that we collect directly from you.

 

  1. Collection of Information Across Devices

Sometimes, we may use the information we collect — for instance, usernames, IP addresses and unique mobile device identifiers — to locate or try to locate the same unique users across multiple browsers or devices (such as smartphones or tablets), or work with service providers that do this, in order to save your preferences across devices and analyze usage of the Services.

 

COOKIES AND SIMILAR TECHNOLOGIES

To collect the information in the “Information We Automatically Collect” section above, we and our service providers use Internet server logs, cookies, tags, SDKs, tracking pixels, and other similar tracking technologies. A web server log is a file where website activity is stored. An SDK is a section of code that we embed in our applications and software to allow third parties to collect information about how users interact with the Services. A cookie is a small text file that is placed on your computer or mobile device when you visit a site, that enables us to: (i) recognize your computer and login session; (ii) store your preferences and settings; (iii) understand which web pages of the Services you have visited; (iv), enhance your user experience by delivering and measuring the effectiveness of content and advertising tailored to your interests; (v) perform analytics; and (vi) assist with security and administrative functions. Tracking pixels (sometimes referred to as web beacons or clear GIFs) are tiny electronic tags with a unique identifier embedded in websites, online ads and/or email, and that are designed to provide usage information like ad impressions or clicks, email open rates, measure popularity of the Services and associated advertising, and to access user cookies. As we adopt additional technologies, we may also gather information through other methods.

Please note that you can change your settings to notify you when a cookie is being set or updated, or to block cookies altogether. Please consult the “Help” section of your browser for more information (e.g. Internet Explorer, Google Chrome, Mozilla Firefox or Apple Safari).

 

HOW WE USE YOUR INFORMATION

We use your information (including any information that we collect, as described in this Privacy Policy) for various purposes depending on the types of information we have collected from and about you and the specific Rivet Services you use, including to:

  • complete a purchase or provide the services you have requested;
  • respond to your request for information and provide you with more effective and efficient customer service;
  • provide you with product updates and information about products you have purchased from us;
  • provide you with service notifications via email and within the Services based on your notification selections;
  • contact you by email, postal mail, or phone regarding Rivet and third party products, services, surveys, research studies, promotions, special events and other subjects that we think may be of interest to you;
  • customize the advertising and content you see;
  • help us better understand your interests and needs, and improve the Services;
  • synthesize and derive insights from your use of different Rivet products and services;
  • engage in analysis, research, and reports regarding use of our Services;
  • provide, manage, and improve the Services;
  • protect our Services and our users; and
  • understand and resolve app crashes and other issues being reported.

Data

You can exercise certain control how your Data is used by/shared with others via your settings selections related to the Services. Rivet may view and share your Data only as necessary (i) to maintain, provide and improve the Services; (ii) prevent or address technical or security issues and resolve support requests; (iii) if we have a good faith belief, or have received a complaint alleging, that such Data is in violation of our Terms and Conditions; (iv) as reasonably necessary to allow Rivet to comply with or avoid the violation of applicable law or regulation; (v) to comply with a valid legal subpoena, request, or other lawful process; and (vi) as set forth in the Terms and Conditions with the Customer or as expressly permitted in writing by the Customer. We may also analyze your User Data in aggregate and on an anonymized basis, in order to better understand the manner in which our Services is being used.

Combined Information

You consent that, for the purposes discussed in this Policy, we may combine the information that we collect through the Services with information that we receive from other sources, both online and offline, and use such combined information in accordance with this Privacy Policy.

Aggregate/De-Identified Data

We may aggregate and/or de-identify information collected through the Services so that such information can no longer be linked to you or your device (“Aggregate/De-Identified Information”). We may use Aggregate/De-Identified Information for any purpose, including without limitation for research and marketing purposes, and may also share such data with any third parties, including advertisers, promotional partners, sponsors, event promoters, and/or others. By using the Services, you consent to such use.

 

ONLINE ANALYTICS AND ADVERTISING

  1. Analytics

We use third party web analytics services (e.g., Google Analytics) on our Services to collect and analyze the information discussed above, and to engage in auditing, research and reporting. The information (including your IP address) collected by various analytics technologies described in the “Cookies and Similar Technologies” section will be disclosed to or collected directly by these service providers, who use the information to evaluate your use of the Services, including by noting the third party website from which you arrive, analyzing usage trends across Rivet products and mobile devices, assisting with fraud prevention, and providing certain features to you.

If you receive email from us, we may use certain analytics tools, such as clear GIFs to capture data such as when you open our message or click on any links or banners our email contains. This data allows us to gauge the effectiveness of our communications and marketing campaigns.

 

  1. Online Advertising

Third parties or affiliates may administer Rivet banner advertising programs and other online marketing on non-Rivet websites and services. To do so, these parties may set and access first-party cookies delivered from a Rivet domain, or they may use third party cookies or other tracking mechanisms. For example, a third party provider may use the fact that you visited the Rivet website to target online ads for Rivet services to you on non-Rivet websites. Or a third party ad network might collect information on the Services and other websites to develop a profile of your interests and target advertisements to you based on your online behavior. These parties that use these technologies may offer you a way to opt out of ad targeting as described below. You may receive tailored advertising on your computer through a web browser.

If you are interested in more information about tailored browser advertising and how you can generally control cookies from being put on your computer to deliver tailored advertising, you may visit the Network Advertising Initiative’s Consumer Opt-Out link or the Digital Advertising Alliance’s Consumer Opt-Out link to opt-out of receiving tailored advertising from companies that participate in those programs. To opt out of Google Analytics for display advertising or customize Google display network ads, you can visit the Google Ads Settings page. Please note that we do not control any of the above opt-out links or whether any particular company chooses to participate in these opt-out programs. We are not responsible for any choices you make using these mechanisms or the continued availability or accuracy of these mechanisms.

 

  1. Notice Concerning Do Not Track.

There is no uniform or consistent standard or definition for responding to, processing, or communicating Do Not Track signals. At this time the Services do not function differently based on a user’s Do Not Track signal. For more information on Do Not Track signals, see All About Do Not Track.

 

HOW WE SHARE YOUR INFORMATION

Rivet will share your information in the following ways:

  • Affiliates and Subsidiaries. We may share all information we collect within the Rivet family of companies.
  • Service Providers. We may provide access to or share your information with select third parties who perform services on our behalf. These third parties provide a variety of services to us, including without limitation billing, sales, marketing, provision of content and features, advertising, analytics, research, customer service, shipping and fulfillment, data storage, security, fraud prevention, payment processing, and legal services.
  • Third Party Integrations. When you initiate a connection with a third party integration through the Services (e.g., OneDrive, Unito, Wufoo, Slack), we will share information about you that is required to enable your use of the third party integration through the Services.
  • Business Transfers. If the ownership of all or substantially all of our business changes, we may transfer your information to the new owner so that the Services can continue to operate. In such case, your information would remain subject to the promises and commitments contained in this Privacy Policy until such time as this Privacy Policy is updated or amended by the acquiring party upon notice to you. If such transfer is subject to additional mandatory restrictions under applicable laws, Rivet will comply with such restrictions.
  • Public Forums. The Services make it possible for you to upload and share comments or feedback publicly (i.e., outside of the Rivet mobile and web app) with other users, such as on the Rivet blog. Any information that you submit through such public features is not confidential, and Rivet may use it for any purpose (including in testimonials or other Rivet marketing materials). Any information you post openly in these ways will be available to the public at large and potentially accessible through third party search engines. Such information can be read, collected and/or used by other users, and it could be used to send you unsolicited messages. Accordingly, please take care when using these features of the Services.
  • Aggregate/De-Identified Information. From time to time, Rivet may share Aggregate/De-Identified Information about use of the Services, such as by publishing a report on usage trends. As stated above, this Policy places no limitations on our use or sharing of Aggregate/De-Identified Information.
  • Consent. We may also disclose your information to third parties with your consent to do so. For example, we will display your Profile Information on your profile page and elsewhere on the Services in accordance with the preferences you set in your account. You can review and revise your Profile information at any time.

 

YOUR CHOICES

We provide you with a number of choices with respect to the information we collect and use as discussed throughout this Privacy Policy. For example, you may instruct us not to use your contact information to contact you by email, postal mail or phone regarding products, services, promotions and special events that might appeal to your interests by contacting us at privacy@rivethealth.com. In commercial email messages, you can also opt out by following the instructions located at the bottom of such emails. Please note that, regardless of your request, we may still use and share certain information as permitted by this Privacy Policy or as required by applicable law. For example, you may not opt out of certain operational or service-related emails, such as those reflecting our relationship or transactions with you. Through your account interface, you may opt out of certain receiving categories of Services-related notices that are not deemed by Rivet to be integral to your use of the Services.

 

THIRD PARTY LINKS AND SERVICES

The Services contain links to third party websites such as social media sites, and also contain third party integrations. If you choose to use these sites or integrations, you may disclose your information not just to those third-parties, but also to their users and the public more generally depending on how their services function. Because these third party websites and services are not operated by Rivet, Rivet is not responsible for the content or practices of those websites or services. The collection, use, and disclosure of your personal and other information will be subject to the privacy policies of the third party websites or services, and not this Policy. We urge you to read the privacy and security policies of these third-parties.

 

CHILDREN’S PRIVACY

The Services are intended for general audiences and not for children under the age of 13. If we become aware that we have collected personal information (as defined by the Children’s Online Privacy Protection Act) from children under the age of 13, we will take reasonable steps to delete it as soon as practicable.

 

YOUR RIGHTS

If you want to learn more about the information collected through the Services, or if you would like to access or rectify your information and/or request deletion of information we collect about you, or restrict or object to the processing of your information, please contact us using the contact information below. Where you have provided consent, you may withdraw your consent at any time, without affecting the lawfulness of the processing that was carried out prior to withdrawing your consent. If you are dissatisfied with the way we process your information, you may lodge a complaint with the data protection authority (“DPA”) in your jurisdiction.

 

HOW LONG WE STORE YOUR INFORMATION

We will retain your information for the period necessary to fulfill the purposes outlined in this Policy unless a longer retention period is required or permitted by law.

 

CHANGES TO OUR PRIVACY POLICY

We reserve the right to amend this Policy at any time to reflect changes in the law, our data collection and use practices, the features of our Services, or advances in technology. Such changes and any amended policy will become effective upon posting upon our Website. We encourage you to regularly review this Privacy Policy on our Website for the latest information on our privacy practices.

 

HOW WE PROTECT YOUR INFORMATION

Rivet takes technical and organizational measures to protect your personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access. However, no method of transmission over the Internet, and no means of electronic or physical storage, is absolutely secure, and thus we cannot ensure or warrant the security of that information. If you have any questions about security on our Services, you can contact us at privacy@rivethealth.com.

 

CALIFORNIA PRIVACY RIGHTS

California law gives residents of California the right under certain circumstances to request information from us regarding the manner in which we share certain categories of personal information (as defined by applicable California law) with third parties for their direct marketing purposes. However, Rivet does not share your personal information with third parties for their own direct marketing purposes.

 

SUBJECT TO TERMS AND CONDITIONS

Use of the Services is subject to Rivet’s Terms and Conditions and this Privacy Policy should be read in conjunction with this. In the event of a conflict or disagreement between this Privacy Policy and the Terms and Conditions, the Terms and Conditions will prevail.

 

RIVET CONTACT INFO

The data controller of your information is Rivet. If you wish to contact us or have any questions about or complaints in relation to this Privacy Policy, please contact us at privacy@rivethealth.com.