The Sharecare Privacy Notice for California Residents (or "Privacy Notice") explains what types of personal information, also referred to as personal data, we may collect about our users, visitors, and/or employees who reside in the State of California.
While this Privacy Notice is intended to describe the broadest range of our information processing activities globally, those processing activities may be more limited in some jurisdictions based on the restrictions of their laws. For example, the laws of a particular country may limit the types of personal information we can collect or the manner in which we process that information. In those instances, we adjust our internal policies and practices to reflect the requirements of local law.
This Privacy Notice complies with the California Consumer Privacy Act of 2018 ("CCPA") and other applicable privacy laws. If you have questions or do not fully understand this notice, please contact Sharecare’s Privacy and Data Protection Officer by phone at 1-800-655-4032 or by email at firstname.lastname@example.org.
WHAT INFORMATION DE WE COLLECT
"Personal information" means information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. It does not include data where the identity has been removed (deidentified data). If applicable to your use of our services, we may collect, store, and use the following categories of personal information about you as listed below.
|A. Identifiers.||A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, passport number, or other similar identifiers.||YES|
|B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).||A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories.||YES|
|C. Protected classification characteristics under California or federal law.||Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).||YES|
|D. Commercial information.||Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.||NO|
|E. Biometric information.||Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.||YES|
|F. Internet or other similar network activity.||Browsing history, search history, information on a consumer's interaction with a website, application, or advertisement.||YES|
|G. Geolocation data.||Physical location or movements.||YES|
|H. Sensory data.||Audio, electronic, visual, thermal, olfactory, or similar information.||YES|
|I. Professional or employment-related information.||Current or past job history or performance evaluations.||NO|
|J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)).||Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.||NO|
|K. Inferences drawn from other personal information.||Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.||YES|
Note: Personal information does not include:
- Publicly available information from government records
- Deidentified or aggregated consumer information
- Information excluded from the CCPA's scope, like:
- Health or medical information covered by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the California Confidentiality of Medical Information Act (CMIA) or clinical trial data;
- Personal information covered by certain sector-specific privacy laws, including the Fair Credit Reporting Act (FRCA), the Gramm-Leach-Bliley Act (GLBA) or California Financial Information Privacy Act (FIPA), and the Driver's Privacy Protection Act of 1994.
HOW WE COLLECT INFORMATION ABOUT YOU
We obtain the categories of personal information listed above from the following categories of sources:
- Directly from our clients or their agents. For example, from documents that our clients provide to us related to the services for which they engage us.
- Indirectly from our clients or their agents. For example, through information we collect from our clients in the course of providing services to them.
- Directly and indirectly from activity on our website listed below. For example, from submissions through our website portal or website usage details collected automatically.
- From third parties that interact with us in connection with the services we perform. For example, from government agencies when we prepare readiness assessments for projects that receive government funding.
HOW WE USE YOUR INFORMATION
We may use or disclose the personal information we collect for one or more of the following business purposes:
- To fulfill or meet the reason for which the information is provided.
- To provide you with information, products or services that you request from us.
- To provide you with email alerts, event registrations and other notices concerning our products or services, or events or news, that may be of interest to you.
- To carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collections.
- To improve our website and present its contents to you.
- For testing, research, analysis and product development.
- As necessary or appropriate to protect the rights, property or safety of us, our clients or others.
- To respond to law enforcement requests and as required by applicable law, court order, or governmental regulations.
- As described to you when collecting your personal information or as otherwise set forth in the CCPA.
- To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal information held by us is among the assets transferred.
Note: We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
DISCLOSURE OF PERSONAL INFORMATION
Sharecare may disclose your personal information in the following circumstances:
- We may disclose any data about you when, in our opinion, such disclosure is necessary to prevent fraud or to comply with any statute, law, rule or regulation of any governmental authority or any order of any court of competent jurisdiction.
- We may, from time to time, outsource some or all of the operations of our business to third-party service providers. In such cases, it may be necessary for us to disclose your data to those service providers. In some cases, the service providers may collect data directly from you on our behalf. We restrict how such service providers may access, use and disclose your data.
- We employ other companies and individuals to perform functions on our behalf. Examples include processing compensation, providing employee benefits, and performing legal and other professional services. These agents may have access to your data as needed to perform their functions, but they are not permitted to use it for other purposes.
- As we continue to develop our business, we might sell or buy companies, subsidiaries, or business units. In such transactions, data generally is one of the transferred business assets but remains subject to the promises made in any pre-existing privacy statement (unless, of course, the person consents otherwise). Also, in the unlikely event that Sharecare or all of its assets is acquired, your data may be one of the transferred assets.
- We release data when we believe release is appropriate to comply with the law; enforce or apply our policies and other agreements; or protect the rights, property, or safety of Sharecare, employees, or others. Obviously, however, this does not include selling, renting, sharing or otherwise disclosing personally identifiable data from employees for commercial purposes in violation of the commitments set forth in this Privacy Statement.
- Please be advised that Sharecare does not sell, and has not sold personal information in the last twelve (12) months. For purposes of this policy, sold means the disclosure of Personal Information to a third-party for monetary or other valuable consideration. Likewise, Sharecare does not have any future plans to sell personal information.
- We do not knowingly collect or solicit personal information from minors under the age of 16. If we learn we have collected or received personal information from a child under 16 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 16, please contact us at email@example.com.
ACCESS TO PERSONAL INFORMATION WE COLLECT
You can ask to see the personal information that we hold about you. If you want to review, verify or correct your personal information, please go to our request form or submit a request via email to firstname.lastname@example.org.
When requesting access to your personal information, please note that we may request specific information from you to enable us to confirm your identity and right to access, as well as to search for and provide you with the personal information that we hold about you. More information regarding our verification process can be found on our request form. You may designate an authorized agent to request information on your behalf, provided that the authorized agent complies with our verification procedures to ensure your permission has been obtained.
Your right to access the personal information that we hold about you is not absolute. There are instances where applicable law or regulatory requirements allow or require us to refuse to provide some or all of the personal information that we hold about you. In addition, the personal information may have been destroyed, erased or made anonymous. In the event that we cannot provide you with access to your personal information, we will inform you of the reasons why, subject to any legal or regulatory restrictions.
CORRECTION OF COLLECTED PERSONAL INFORMATION
We endeavor to ensure that personal information in our possession is accurate, current and complete. If an individual believes that the personal information about him or her is incorrect, incomplete or outdated, he or she may request the revision or correction of that information. We reserve the right not to change any personal information we consider is accurate.
If it is determined that personal information is inaccurate, incomplete or outdated, we will use reasonable efforts to revise it and, if necessary, use reasonable efforts to inform agents, service providers or other third parties, which were provided with inaccurate information, so records in their possession may be corrected or updated.
RETENTION OF COLLECTED INFORMATION
Except as otherwise permitted or required by applicable law or regulatory requirements, we will retain your personal information only for as long as we believe it is necessary to fulfill the purposes for which the personal information was collected (including, for the purpose of meeting any legal, accounting or other reporting requirements or obligations).
You may request that we delete the personal information about you that we hold. There are instances where applicable law or regulatory requirements allow or require us to refuse to delete this personal information. If we cannot delete your personal information, we will inform you of the reasons why, subject to any legal or regulatory restrictions.
REQUESTS TO ACCESS, DELETE, CORRECT INFORMATION, OR WITHDRAWAL OF CONSENT
Please submit requests to access, delete, or correct your personal information via to the Sharecare Legal Department at email@example.com. Any request by you to us to delete your personal information may not result in deletion of any information submitted by you to a third-party provider. If you require the third-party to delete any of your personal information, you must contact the third party directly to request such deletion.
In certain circumstances you may have provided express consent in connection with your providing certain personal information to us of for a specific use of your personal information. In certain countries you may have a right to withdraw that consent. Please submit requests to withdraw your consent to firstname.lastname@example.org.
If you have questions or concerns regarding the handling of your personal information, or want to report concerns or complaints, including information about potential data breaches involving personal information to the Legal Department, please contact email@example.com.
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
- Deny you goods or services.
- Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
- Provide you a different level or quality of goods or services.
- Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
SECURITY OF COLLECTED INFORMATION
We are committed to protecting the security of the personal information collected, and we take reasonable physical, electronic, and administrative safeguards to help protect the information from unauthorized or inappropriate access or use.
Effective Date: 12/31/2019