Website Privacy Policy
Last Updated: June 25, 2026
1. Introduction and Scope
This Privacy Policy (“Policy”) describes how 1upHealth Inc., (“1upHealth”, the “Company”, “we”, “our”, or “us”) collects, uses, discloses, stores, and processes your Personal Data (defined below) through 1upHealth’s platform (the “1up Platform”), together with 1upHealth’s website and web pages (the “Website”), applications, and related interactions (together with the 1up Platform and Website, the “Services”), that post, reference, or incorporate this Policy whether accessed via computer, mobile device, or other device.
This Policy applies to Personal Data that we collect from or about Users, including Personal Data collected through our website and related marketing activities. This Policy does not apply to any Personal Data that is also Customer Data, that we process through the Services on behalf of our Customers, which is governed by our services agreement with the applicable Customer. To the extent said Customer Data includes Personal Data that is also Protected Health Information (“PHI”), our processing of that PHI is governed by the applicable business associate agreement (BAA) and applicable law, including HIPAA, and not by this Policy.
By accessing or using the Services, you acknowledge that you have read and understood this Policy.
2. Personal Data Consent; Withdrawal
By submitting Personal Data to 1upHealth through the Services, you consent to the collection, use, and disclosure of such Personal Data as described in this Policy. Your Personal Data will be collected, processed, and stored by 1upHealth or its Service Providers in the United States only.
You may withdraw your consent at any time for any reason by contacting us at the addresses provided herein (see Contact Us, Section 14, below). If you withdraw your consent, you agree and acknowledge that we may be unable to provide certain Services to you.
3. Definitions
In this Policy:
- “Customer(s)” means the health plan, organization, agency, broker, employer, covered entity, company, or other entity that contracts with 1upHealth for the Services. For purposes of this Policy, references herein to Customer(s) may also include User(s) where contextually applicable.
- “Customer Data” means information, content, records, files, or materials that a Customer or its Users submit, transmit, upload, import, or otherwise make available to 1upHealth through the Services. For purposes of this Policy, references herein to Customer Data does not include any Personal Data covered by this Policy.
- “Covered Entity” means a health plan, healthcare clearinghouse, or healthcare provider that transmits health information in electronic form in connection with a transaction covered by HIPAA.
- “Personal Data” means information that identifies, relates to, or can reasonably be linked to a particular individual, and also includes information referred to as “personally identifiable information” or “personal information” under applicable data privacy laws, rules or regulations. For purposes of this Policy, references herein to Personal Data does not include any Customer Data or PHI that we process through the Services on behalf of our Customers.
- “Protected Health Information” or “PHI” has the meaning given to it under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and includes individually identifiable health information.
- “User” or “you” means an individual who interacts with the Services, including an authorized user of a Customer account, or a visitor to our website. A website visitor is a User even if the visitor is not a Customer or an authorized user of the Services. When you interact with our website or our marketing-related efforts, the information you submit or that we collect is Personal Data covered by this Policy and is not Customer Data or PHI.
4. Personal Data We Collect and How We Collect It
Categories of Personal Data We Collect
We collect only the categories of Personal Data that are necessary to provide the Services. This chart details the categories of Personal Data that we may collect and may have collected over the past 12 months, and the categories of third parties with whom we may share such Personal Data:
Category of Personal Data | Examples of Personal Data Collected | Categories of Third Parties With Whom We Share this Personal Data |
Contact and Professional Information | Name; business email address; business telephone number; job title; employer or organization; department; professional role; mailing address; and other business contact information, etc. | Service Providers; Analytics Partners |
Account and Authentication Information | Username; account identifier; login credentials; single sign-on identifiers; multi-factor authentication status; account role; permissions; customer affiliation; and account preferences, etc. | Service Providers |
Customer and Prospect Information | Organization name; business contact details; products or solutions of interest; requests for information; demo requests; communications with sales personnel; account notes; contract-related information; and relationship history | Service Providers; Analytics Partners |
Communications and Support Information | Email correspondence; support requests; chat messages; meeting notes; feedback; survey responses; troubleshooting information; call recordings or transcripts, if used; and documents or attachments submitted through support channels | Service Providers |
Website and Device Information | Internet address; browser type; operating system; device type; device identifiers; referring URLs; pages viewed; date and time of access; approximate location derived from IP address; and similar technical information, etc. | Service Providers |
Cookie and Analytics Information | Cookie identifiers; website interaction data; session information; traffic-source information; marketing attribution data; and analytics information relating to use of the website | Service Providers |
Service Providers. The Services may contain links to, or integrations with, websites, applications, products, or services operated by third-party vendors or providers (“Service Providers”). Service Providers are independent third parties that we do not own, control, or manage, and this Policy does not apply to their privacy practices. If you or your organization connect to, access, authenticate with, or authorize a Service Provider in connection with the Services, its handling of information is governed by its own terms and privacy policy. We encourage you to review those terms and policies before providing Personal Data to a Service Provider or authorizing it to access your information.
How We Collect Your Information
We obtain information from the following sources only:
- Directly from you — when you register for an account, complete a form, submit payment information, email us, request a demo, contact support, or otherwise interact with the Services.
- Automatically — through cookies, and website analytical tracking technologies as you use the Services (see Information We Collect Through Automatic Data Collection Technologies directly hereafter).
Information We Collect Through Automatic Data Collection Technologies
The technologies we use for this automatic data collection may include:
- Web Beacons. Pages of our website and/or platform may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit us, for example, to count users who have visited those pages and for other related website statistics.
- Analytics Tools. We use analytics tools provided by our Analytic Partners, including Google Analytics, to help us understand website traffic, usage patterns, referral sources, and interactions with our Services. We use Google Analytics only on public marketing websites.
- Cookies (or browser cookies). A cookie is a small file placed on the hard drive of your computer. We and our Analytic Partners may use cookies, pixels, tags, software development kits, local storage, and similar technologies to automatically collect information about your interactions with our Services. These technologies may collect information such as your IP address, device identifiers, browser type, operating system, referring URLs, pages viewed, links clicked, time spent on pages, and other information about how you access and use the Services. We use these technologies to operate the Services, understand visitor activity, measure performance, improve user experience, and analyze the effectiveness of our marketing efforts. We respect “Do Not Track” signals where required by law. Most web browsers automatically accept cookies. You can modify your browser settings to decline cookies, delete existing cookies, or be notified when a cookie is set. If you disable cookies, some Services may not function properly. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our website. We categorize cookies as follows:
- Strictly Necessary Cookies: Required for the Website to function. These cannot be disabled without affecting core functionality.
- Analytics Cookies: Help us understand how visitors use our Website (e.g., pages visited, time on site, error messages). We use this information to improve the Website experience.
- Functional Cookies: Enable enhanced features and personalization, such as remembering your preferences.
- Advertising/Targeting Cookies: Used to deliver relevant advertising and measure the effectiveness of ad campaigns. We will only deploy these cookies where we have a lawful basis to do so, including your consent where required.
5. Disclosure of Your Personal Data
We may disclose Personal Data that we collect or you provide as described in this Policy to:
- Analytics Partners: vendors and other third parties we engage that help us understand website activity and, where applicable, use of Services. We may use Analytics Partners to analyze website traffic, referral sources, user interactions, and usage trends, and may combine website-collected data with account information about Customers.
- Service Providers: that we have engaged to help us provide, operate, secure, support, maintain, and improve the Services or perform business functions on our behalf. They may include hosting providers, data centers, security and audit firms, payment processors, customer-support tools, email and SMS delivery providers, and other vendors. Each Service Provider is bound by a written agreement that (a) prohibits use of Personal Data for any purpose other than providing services to 1upHealth and (b) requires confidentiality and security protections at least as strict as those described in this Policy.
Additional Disclosures
- Legal and Safety Disclosures: We may disclose Personal Data when we believe in good faith that disclosure is necessary to: (a) comply with U.S. federal, state, or local law, legal process, subpoena, court order, or government request; (b) enforce our acceptable use policy; (c) investigate, prevent, or respond to suspected fraud, security incidents, or violations of our policies; or (d) protect the rights, safety, or property of 1upHealth, our Customers, our Users, or others.
- Business Transfers: We may disclose or transfer Personal Data in connection with a merger, acquisition, financing, reorganization, or sale of all or substantially all of 1upHealth’s assets. Personal Data may be transferred to the successor entity. Any successor entity will be required, by contract, to honor commitments at least as protective as those in this Policy with respect to Personal Data transferred. If a successor proposes to materially change this Policy in a way that affects you, you will be given advance notice and an opportunity to delete your information before the change takes effect, except where deletion is prohibited by law.
- With your consent: When you use the website or interact with our marketing-related efforts, you may voluntarily provide us with Personal Data; we may disclose that Personal Data for any purpose disclosed to you at the time we collect your information or with your subsequent express consent.
- Aggregated Data: We may use and disclose any Personal Data that is aggregated, anonymized, or de-identified (and that cannot reasonably be re-identified) (“Aggregated Data”) for any lawful purpose. If we combine aggregated or de-identified information with Personal Data, we treat the combined information as Personal Data for as long as it remains combined.
6. Protected Health Information (HIPAA)
1upHealth may collect, store, or transmit PHI on behalf of our applicable Customers; when 1upHealth or a Service Provider handles PHI, it does so as a HIPAA business associate under a written Business Associate Agreement (“BAA”) with the applicable Customer and in accordance with applicable law, including HIPAA. For purposes of this Privacy Policy, any references herein to Personal Data does not include PHI that we process in our capacity as a business associate or subcontractor business associate pursuant to an applicable BAA.
Your HIPAA rights
You have rights under HIPAA, including the right to request access to, amendment of, or an accounting of disclosures of your PHI. To exercise these rights, contact your employer, broker, or insurance carrier (the Covered Entity). For more information on HIPAA and your health-information rights, visit https://www.hhs.gov/hipaa/index.html.
7. Information Security
1upHealth uses administrative, technical, and physical safeguards designed to protect Personal Data, and Customer Data from loss, misuse, unauthorized access, alteration, or destruction. Our safeguards include:
- Encryption in transit of all Personal Data using current industry-standard TLS protocols.
- Encryption at rest of Personal Data using industry-standard encryption algorithms.
- Multi-factor authentication for administrative access to systems containing Personal Data.
- Vulnerability management and penetration testing, including periodic third-party security testing.
- Independent security audits consistent with industry frameworks (such as SOC 2). Customers may request information about our current attestations and certifications under non-disclosure.
- Workforce security training required at least annually for all personnel with access to Personal Data.
- Incident response and breach notification procedures in compliance with applicable law.
8. Data Retention
We retain Personal Data only as long as necessary to provide the Services, comply with our legal and regulatory obligations, resolve disputes, and enforce our agreements. Specific retention periods include:
- Active account data: retained for the duration of the account relationship.
- Marketing contact data: retained until you unsubscribe or request deletion.
- Server logs and security telemetry: retained for up to twenty-four (24) months for security and troubleshooting purposes.
When Personal Data is no longer needed, we delete or de-identify it using industry-standard methods within a commercially reasonable period, subject to this Policy, and subject to applicable legal, regulatory, contractual, and operational requirements.
9. Account and Personal Data Deletion
You may request deletion of your account and associated Personal Data at any time.
- How to request deletion: Email support@1up.health from the email address associated with the User account; Customers may also direct 1upHealth to delete Personal Data on behalf of their Users.
- Deletion Process: Within thirty (30) days of a verified deletion request, we will delete or de-identify the Personal Data associated with the account from our active production systems. The data will be removed from backup systems within ninety (90) days, except where backups are immutable for compliance reasons, in which case the data will be deleted at the next regularly scheduled backup overwrite cycle and will not be restored.
- Interim Use: From the moment we receive your request until deletion is complete, your data continues to be protected by this Policy and is not used for any purpose other than completing the deletion and meeting our legal obligations.
- Retained Data: We may retain limited Personal Data as required by law, regulation, or our legitimate business needs (such as fraud prevention, tax records, or pending legal matters), provided that retained Personal Data continues to be protected by this Policy.
10. Your Rights and Choices
Depending on your jurisdiction, you may have rights regarding your Personal Data, including:
- The right to access the Personal Data we hold about you.
- The right to correct inaccurate or incomplete information.
- The right to request deletion of your Personal Data (see Section 9, above).
- The right to receive your Personal Data in a portable format and transmit it to another controller.
- The right to opt out of marketing communications.
- The right to withdraw consent where processing is based on consent.
- The right to object to processing in certain circumstances.
- The right not to receive discriminatory treatment for exercising these rights.
To exercise these rights, submit a verifiable request to support@1up.health providing: (a) information sufficient to identify you; (b) reasonable proof of your identity; and (c) a description of the right or information your request relates to. We will respond as soon as reasonably practicable and within the timeframes required by applicable law.
You may also at any time:
- Update or modify your account information by logging in and visiting your account settings.
- Opt-out of marketing communications (see Contact Us, Section 14, below).
- Manage cookies through your browser settings (see Information We Collect Automatically, Section 4, above).
11. Use of the Services by Minors
The Services are not intended to be marketed to individuals under the age of 18. We do not knowingly collect Personal Data from children under 18. If we learn that we have collected Personal Data from a child under 18, we take all possible means to delete this information.
12. United States-based Operations
The Services are operated from the United States, and Personal Data collected through the Services is collected, stored, and processed in the United States only. 1upHealth is a U.S.
company subject to U.S. federal and state law. We do not voluntarily disclose Personal Data to foreign governments or to entities outside the United States, except as required to provide a Service that you or the Customer has expressly requested in writing.
13. Changes to This Policy
We reserve the right to update this Policy from time to time, as may be reasonably necessary. The “Last Updated” date at the top of this Policy reflects the date of the most recent revision.
14. Contact Us
If you have questions about this Privacy Policy, wish to exercise a privacy right, request account deletion, report a security concern, or file a complaint, please contact us:
Privacy and Data Rights Requests
For privacy questions, data rights requests
compliance@1up.health
Account Support
For account-related assistance, support inquiries, or account deletion requests:
support@1up.health
Security Inquiries
To report a security concern or vulnerability:
security@1up.health
We will respond to verified privacy and data rights requests in accordance with applicable law.
You also have the right to file a complaint with a regulatory or governmental authority in your jurisdiction. For HIPAA-related concerns, you may contact the U.S. Department of Health and Human Services Office for Civil Rights.
15. California Privacy Rights
California Civil Code Section § 1798.83 permits users of our Website who are California residents to request certain information regarding our disclosure of Personal Information to third parties for their direct marketing purposes. To make such a request, please contact compliance@1up.health.
16. Other State Privacy Rights
Depending on where you live and subject to applicable law, you may have certain rights regarding your Personal Data. These rights may include the right to:
- confirm whether we process your Personal Data and access such Personal Data;
- correct inaccuracies in your Personal Data;
- request deletion of your Personal Data;
- obtain a copy of your Personal Data in a portable and readily usable format;
- opt out of the processing of your Personal Data for purposes such as targeted advertising, the sale of Personal Data, or certain profiling in furtherance of decisions that produce legal or similarly significant effects (note that 1upHealth does not sell your Personal Data);
- limit or opt out of certain uses or disclosures of sensitive Personal Data, where applicable; and
- appeal our decision if we deny your privacy rights request.
These rights may apply to residents of states with consumer privacy laws, including but not limited to, as applicable, residents of Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia.
To exercise your rights, you may contact us at compliance@1up.health. We may need to verify your identity before processing your request. We will respond to your request within the time period required by applicable law. If we deny your request, you may have the right to appeal our decision by contacting us at compliance@1up.health and stating that you are appealing our decision.