Privacy Policy

    Introduction

    Flare MD LLC (“Flare MD,” “we,” “our,” or “us”) operates the website located at www.flaremd.com, along with any related websites, applications, software, or digital tools we own or manage (collectively, the “Platform”). Your use of the Platform, including all information, materials, features, and functionality made available through it (the “Content”), as well as any products or services offered by Flare MD through the Platform or otherwise (collectively, the “Services”), is governed by this Privacy Notice unless another policy is expressly stated. Any capitalized terms not defined here carry the same meaning as described in the Flare MD Terms and Conditions.

    We value and respect the privacy of individuals who interact with our Services. This Privacy Notice explains how Flare MD collects, uses, maintains, and shares information in order to operate our Services and deliver care and support to our users.

    By creating an account, registering for services, logging in, or otherwise accessing or using the Services, you confirm that you have reviewed and accept the current version of this Privacy Notice. We may update this Privacy Notice from time to time to reflect operational, legal, or regulatory changes. When updates are made, the revised version will be posted on the Platform with an updated “Last Updated” date.

    If you access or use the Services on behalf of another person, you represent and warrant that you have the authority to do so and that you have informed that individual of this Privacy Notice and the ways their information may be collected, used, and disclosed in connection with the Services.

    Account Information and Health Data

    When you create an account with Flare MD, you establish a direct customer relationship with Flare MD that allows you to access and use features of our Platform and Services. As part of that relationship, you may provide general personal and account information such as your name, email address, mailing address, phone number, and certain billing or transaction details. Information of this nature is used to operate the Platform and provide services and is not typically considered protected health or medical information under applicable privacy laws.

    In the course of using certain clinical or telehealth components of the Services, you may also choose to share health-related or medical information. Depending on how and where care is delivered, some of this information may be subject to federal or state privacy protections. Flare MD is not itself a health insurer, pharmacy, or traditional healthcare clearinghouse, and therefore may not always be considered a “covered entity” under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”). However, certain affiliated medical practices, pharmacies, or licensed providers who deliver care through or in connection with Flare MD may be covered entities or business associates under HIPAA. In some situations, Flare MD may act in a supporting or administrative capacity that could qualify as a “business associate” to those entities.

    It is important to understand that the presence of health-related information does not automatically mean HIPAA applies to every interaction or communication on the Platform. Where Flare MD receives or handles information in a role subject to HIPAA or applicable state privacy laws, we will use and disclose that information in accordance with those requirements. Any medical or health information that qualifies as protected under applicable laws (collectively, “Protected Information”) will be handled in a manner consistent with those laws. Information that does not meet the definition of Protected Information may be used or shared as described in this Privacy Notice and as permitted by applicable law. Information that has been de-identified in accordance with legal standards is not considered Protected Information.

    By accessing or using the Services, you acknowledge that information you submit for purposes other than direct medical diagnosis, treatment, or prescription fulfillment such as account registration, scheduling, general inquiries, or administrative communications may not be considered Protected Information and may be governed solely by this Privacy Notice and applicable state privacy laws. For clarity, account registration details such as your name, username, email address, mailing address, and phone number are generally treated as standard account information rather than Protected Information.

    Limitations on Use by Minors

    The Services provided by Flare MD are intended for use by individuals who are at least eighteen years of age, or any higher minimum age required by applicable state law in the jurisdiction where the Services are accessed. The Platform and Services are not designed for or directed toward individuals under the age of eighteen. If Flare MD becomes aware that personal information has been collected through the Platform from an individual under eighteen, we will take reasonable steps to discontinue use of that information and avoid retaining it in a retrievable form, except where retention is permitted or required by law.

    There may be circumstances in which Flare MD is not required to delete or eliminate information associated with a minor. For example, applicable international, federal, state, or local laws or regulations may require that certain records be retained. Information may also be maintained when it is held on behalf of licensed medical providers as part of an official medical record. In addition, Flare MD may not be able to remove content or information that has been stored or shared by a third party, including situations where content originally provided by a user has been republished or retained by another party. Information that has been de identified so that it cannot reasonably be linked to an individual may also be retained. Finally, removal requests may not be fulfilled in situations where required procedures are not followed or where an individual has received compensation or other consideration in exchange for providing the content or information.

    Collection of Personal Information

    The types of personal information we collect depend on how you interact with Flare MD, the services you use, and the choices you make while using our Platform. We gather information from a variety of sources and through different methods, including information you provide directly, information collected automatically through your use of the Services, information received from third parties, and information we derive from other data.

    We collect personal information that you voluntarily provide when using our Services. Examples may include the following:

    In certain situations, we may request sensitive personal information when it is necessary to provide services, verify identity, meet regulatory requirements, or support clinical care. This can include government issued identification numbers or images of identification documents submitted for verification or administrative purposes. It may also include photographs or video images submitted for identity confirmation or other non diagnostic purposes when required for service delivery.

    Information collected automatically

    When you use the Flare MD Platform or Services, certain information is gathered automatically to help us operate, maintain, and improve the experience. Examples include the following:

    Information we generate

    We may create or derive additional information based on the data we collect. This can include general insights such as approximate geographic location inferred from an IP address, or preferences and patterns that help us tailor services, communications, and platform functionality.

    Information obtained from third parties

    We may also receive information from outside sources that support service delivery, account management, and marketing or operational activities. These sources may include the following:

    You may choose not to provide certain personal information, and many web browsers or device settings allow you to limit certain types of automatic data collection. However, if you restrict information that is necessary for specific features or services, some parts of the Platform may not function as intended.

    Flare MD provides administrative and technology support in connection with licensed medical providers and, in some cases, partner pharmacies that deliver care or prescriptions through our Services. In that capacity, we may maintain certain information on behalf of those providers, which can include elements of your medical record, communications with clinical staff, treatment history, and related documentation, consistent with applicable law and professional obligations.

    Cookies and Similar Technologies

    Flare MD uses cookies, pixels, mobile identifiers, analytics tools, and comparable technologies to operate our Platform, improve performance, enhance security, and better understand how users interact with our Services. These tools help us collect information such as device details, usage patterns, and other technical data when you visit or use our website or applications.

    What are cookies and related technologies?

    Cookies are small text files stored on your device through your web browser. They allow a website to recognize your browser and remember certain information, such as preferences or session details, over time. Cookies can help keep you signed in, remember your settings, and improve site functionality.

    Pixels or web beacons are small electronic images embedded in websites or emails. When accessed, they allow a server to collect limited information about your device and interaction with the page or message. These technologies help us understand engagement with our website and communications. Some third party content integrated into our Platform may also place or access similar technologies through your browser.

    Mobile devices may also generate identifiers that can be accessed by applications in a manner similar to cookies. These identifiers may be used for analytics, performance monitoring, and limited advertising related functions within mobile environments.

    How these technologies are used?

    Flare MD and certain service providers use these technologies to collect information about your interaction with the Platform, including pages visited, links clicked, time spent on pages, and device or browser information. This data helps us maintain your preferences, enable secure login features, evaluate site performance, understand usage trends, improve services, prevent fraud, and support other legitimate operational needs. In some cases, aggregated or de identified information may be shared with service providers who assist with analytics, hosting, or platform functionality.

    Available controls

    Most web browsers and mobile operating systems provide settings that allow you to manage cookies and similar technologies. You may be able to block or delete cookies through your browser settings, or adjust device level privacy controls. Please note that disabling certain technologies may limit the functionality of some features on the Platform.

    Use of Personal Information

    Flare MD uses personal information for the purposes described in this Privacy Notice and as otherwise disclosed at the time information is collected, subject to any limitations that apply to protected health or medical information under applicable law.

    Service delivery and operations

    We use personal information to provide and support our Services. This includes account setup, appointment scheduling, communications, identity verification, troubleshooting, and improving your experience on the Platform. We may also use information to confirm general location for service availability, personalize content, and support clinical or administrative functions related to care delivery.

    Types of information used may include contact information, demographic details, payment and billing data, uploaded files or communications, device and usage data, inferred preferences, and, when necessary, certain sensitive information such as identification details or health related data provided in connection with services.

    Business and administrative purposes

    Personal information is also used to support core business operations such as billing, payment processing, accounting, recordkeeping, account management, security monitoring, fraud prevention, and compliance with legal or regulatory requirements. We may use information to verify identity, protect our systems, and safeguard the rights and safety of our users, providers, and organization.

    Improvement and development

    We may use information to evaluate and improve our Platform, develop new services or features, analyze trends, and better understand how users engage with our Services. This helps us refine workflows, enhance user experience, and support research and quality improvement initiatives. Where possible, we may use aggregated or de identified information for these purposes.

    The specific categories of personal information used for these activities can include contact and demographic information, account and payment details, communications, device and usage data, inferred preferences, and health related information provided in connection with services, as permitted by applicable law.

    Personalization

    Flare MD may use personal information to better understand your preferences and tailor your experience across the Platform and Services. This can include customizing content, improving usability, and presenting information that is more relevant to your needs and interests.

    Types of information used for personalization may include contact details, demographic information, account and payment information, uploaded content or communications, device and usage data, general location information, and inferred preferences. In certain situations, sensitive information may be used when necessary to provide or support requested services and where permitted by applicable law.

    Customer support

    We use personal information to respond to inquiries, provide support, process requests, and assist with scheduling or service coordination. This includes helping you access services, resolving technical issues, and communicating with you about your account or appointments. In some cases, we may also assist with placing or tracking orders for services or products connected to your care.

    Information used for customer support may include contact and account information, communications, device and usage data, and, when relevant to your request, health related information or identification details.

    Communications

    Flare MD may use personal information to send administrative and service related communications. These may include confirmations, receipts, appointment reminders, technical notices, updates, security alerts, and other operational messages. We may communicate with you by email, phone, text message, or other appropriate channels. In certain cases, communications may be sent on behalf of licensed providers or care teams to support telehealth services, scheduling, or follow up.

    Information used for communications may include contact information, account details, communications content, device information, and other relevant data needed to facilitate service delivery.

    Marketing and outreach

    We may use personal information to share information about new services, offerings, updates, or events related to Flare MD. Where permitted by law, we may also provide information about services offered by selected partners. You may opt out of certain marketing communications at any time using the unsubscribe or preference options provided.

    Marketing related uses may involve contact information, general demographic details, usage data, device information, and inferred preferences. Sensitive information is only used for marketing where permitted by applicable law and never in a manner that would disclose protected medical information without authorization.

    Advertising and promotion

    Flare MD may use certain information to promote our services and measure the effectiveness of outreach and advertising efforts. This can include understanding how users interact with the Platform and evaluating the performance of campaigns. We do not use protected health information for advertising purposes without appropriate authorization where required by law.

    Information used for advertising and analytics may include device and usage data, general location information, and inferred interests. Any use of sensitive information will comply with applicable legal requirements, including obtaining consent where required.

    Combining information

    We may combine information collected from different sources to provide a more consistent and streamlined experience. This allows us to improve functionality, enhance support, and better tailor services to users.

    SMS communications and consent

    By providing your phone number to Flare MD, you agree to receive text messages related to your account, appointments, and service updates. These messages are intended to improve convenience and help ensure timely communication. However, standard SMS messaging is not considered a secure form of communication. While we may use text messaging for ease of access and responsiveness, our preferred and most secure method of communication is through the patient portal messaging system whenever available.

    You may opt out of non essential text messages at any time by replying STOP to any message or by contacting our support team. Message and data rates may apply depending on your mobile carrier and plan.

    Disclosure of Information

    Flare MD may disclose personal information with your consent, at your direction, or as reasonably necessary to provide services you request. We may also disclose information when required or permitted by law. Any use or disclosure of protected health or medical information will follow applicable federal and state laws and professional obligations.

    We may share information with the following categories of recipients when appropriate:

    Service providers

    We work with vendors and contractors who support our operations, such as technology providers, hosting services, analytics tools, customer support vendors, and security partners. These parties may receive limited personal information only as needed to perform services on our behalf and are expected to safeguard that information.

    Payment processing and financial services

    If you make a payment through the Platform, relevant billing and transaction information may be shared with financial institutions, payment processors, and fraud prevention providers to complete the transaction, prevent fraud, and comply with financial and legal requirements.

    Medical providers and partner pharmacies

    When you request care or related services, we may share information with licensed medical providers, affiliated clinical entities, or pharmacies involved in delivering treatment, prescriptions, or follow up care. This information sharing supports scheduling, consultation, treatment, and payment processing related to your care.

    Legal compliance and safety

    We may access, preserve, or disclose information if we believe it is necessary to comply with applicable laws, regulations, or legal processes. This may include responding to court orders, subpoenas, or lawful requests from government authorities. We may also disclose information to protect the safety of individuals, prevent fraud or misuse of our services, maintain system security, or protect the rights and property of Flare MD or others.

    Analytics and technology providers

    Certain analytics providers may collect technical data through cookies or similar technologies when you use the Platform. This can include device identifiers, IP address, general location data, and usage information. These providers help us understand how the Platform is used and improve performance and functionality. Some analytics tools may aggregate data across multiple websites or services to provide broader insights.

    Some data sharing activities may be considered a sale or sharing of personal information under certain state privacy laws. Where required, we provide mechanisms for you to exercise applicable privacy choices.

    Please note that third party services or links available through the Platform may have separate privacy practices. If you provide information directly to those third parties, their policies will apply.

    We may also disclose information that has been de identified in accordance with applicable law.

    Choice and Control of Personal Information

    You may have choices regarding how your personal information is used. Depending on your location, certain rights may apply under applicable privacy laws.

    You may opt out of promotional emails or text messages by using the unsubscribe instructions provided in those communications or by contacting us directly. Service related communications, such as appointment reminders or account notices, may still be sent as necessary to provide services.

    You may also manage cookies or tracking technologies through your browser or device settings. Some browsers and extensions support tools such as Global Privacy Control signals that indicate a preference to limit certain types of data processing. Where required by law, we will make reasonable efforts to respect such signals.

    Most browsers allow you to delete or block cookies. Disabling cookies may affect certain features of the Platform. Mobile operating systems also provide options to limit advertising tracking or reset advertising identifiers.

    If you submit a request to exercise privacy rights, we may need to verify your identity before responding. In certain cases, requests may be limited or denied where permitted by law, such as when fulfilling the request would conflict with legal obligations, affect the rights of others, or require disclosure of confidential information.

    This Privacy Notice applies to personal information handled by Flare MD and is separate from medical or protected health information that may be subject to additional legal protections.

    Data Retention

    Flare MD retains personal information for as long as reasonably necessary to provide services, comply with legal obligations, resolve disputes, maintain records, and enforce agreements. Retention periods may vary depending on the type of information and applicable legal or regulatory requirements. We may securely delete or de identify information when it is no longer needed, except where retention is required by law or professional obligations.

    Licensed medical providers or pharmacies involved in your care may maintain records according to their own legal and professional retention requirements. Third party service providers may also retain information in accordance with their own policies and applicable laws.

    Transactions and Payments

    If you complete a transaction through the Platform, you may be asked to provide information such as payment details, billing address, shipping address, phone number, or email address. This information is used to process payments, fulfill services, and maintain transaction records. By submitting payment information, you authorize us to share relevant details with payment processors and financial institutions as needed to complete the transaction.

    Payments made through the Platform are typically processed through a third party payment processor. That processor maintains its own privacy and security practices and handles payment data according to its policies. Flare MD does not control the privacy practices of third party payment processors and is not responsible for their policies or procedures.

    Jurisdiction and Applicable Law

    Flare MD Services are intended for use within the United States and only in jurisdictions where our services are offered and permitted under applicable law and our Terms and Conditions. This Privacy Notice and our collection, use, and disclosure of personal information are governed by the laws of the United States and applicable state laws.

    California Privacy Rights

    If you are a California resident and the processing of your personal information is subject to the California Consumer Privacy Act and related regulations, you may have certain rights regarding your personal information.

    Notice at collection

    You have the right to receive notice of our data practices at or before the time personal information is collected. This includes the categories of personal information collected, the purposes for which the information is used, whether the information is shared or disclosed, and how long it is retained. These details are provided throughout this Privacy Notice.

    Right to know and access

    You may request information about the personal data we have collected about you, including categories of information, sources of collection, purposes of use, and categories of third parties with whom the information has been shared. You may also request access to specific pieces of personal information, subject to applicable legal limitations.

    Right to correction and deletion

    You may request correction of inaccurate personal information or request deletion of personal information, subject to certain exceptions permitted by law. For example, we may retain information when necessary to comply with legal obligations, complete transactions, maintain records, or provide requested services.

    Right to opt out of certain sharing

    You may request to opt out of certain types of data sharing that may be considered a sale or sharing of personal information under applicable law. Some website analytics and advertising related disclosures may fall within these definitions. Where required, we provide tools or links that allow you to exercise these choices, including recognized browser based privacy signals where applicable.

    We do not knowingly sell or share the personal information of individuals under the age of sixteen.

    Right to limit use of sensitive personal information

    You may have the right to limit certain uses of sensitive personal information to what is necessary to provide requested services or as otherwise permitted by law. Where applicable, you may exercise this right through available preference tools or by contacting us.

    Authorized agents and verification

    You may designate an authorized agent to submit requests on your behalf where permitted by law. We may require verification of your identity and authorization before processing certain requests. Verification may include confirming account information or requesting additional details to ensure the request is valid.

    You have the right not to be discriminated against for exercising any applicable privacy rights.

    California residents may also have rights under state law to request information about certain types of disclosures for direct marketing purposes. Flare MD does not disclose personal information to third parties for their independent direct marketing purposes as defined by applicable law.

    Security and Miscellaneous Information

    We take reasonable administrative, technical, and physical measures to protect the information under our control. However, no system can guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials and for all activity that occurs under your account. If you believe your account has been compromised, please contact us promptly.

    You may choose not to provide certain information when using the Services, but this may limit available features or prevent use of certain functions. You may also opt out of certain communications, such as marketing emails or text messages, by following the instructions provided in those messages. Even if you opt out of promotional communications, we may still send service related or legally required communications.

    Flare MD may update this Privacy Notice from time to time. When updates are made, the revised version will be posted with an updated effective date. If material changes are made, we may provide additional notice or request acknowledgment where required by law. Your continued use of the Services after updates are posted indicates acceptance of the revised Privacy Notice.

    Contact Us

    If you have questions about this Privacy Notice or our privacy practices, you may contact us at: [email protected]

    HIPPA Privacy Statement: Flare MD Notice of Privacy Practices for Protected Health Information

    This Notice of Privacy Practices describes how Flare MD and affiliated licensed providers may use and disclose protected health information, also referred to as PHI, to support treatment, payment, and healthcare operations, and for other purposes permitted or required by law. This Notice also explains your rights regarding your health information. Where Flare MD acts on behalf of or in coordination with licensed medical providers, we follow applicable federal and state privacy laws and maintain reasonable safeguards to protect PHI.

    We are required by law to maintain the privacy of PHI, provide you with this Notice of our legal duties and privacy practices, and follow the terms of this Notice as currently in effect.

    Permitted Uses and Disclosures of PHI

    PHI may be used or disclosed for the following purposes, as allowed by law.

    Treatment

    PHI may be used and shared among healthcare professionals involved in your care to provide, coordinate, or manage treatment and related services. This may include communication with other providers or pharmacies involved in your care.

    Payment

    PHI may be used or disclosed to obtain payment for services provided. This can include billing activities, eligibility verification, and communication with insurers, payors, or payment processors when applicable.

    Healthcare operations

    PHI may be used for operational purposes such as quality improvement, credentialing, licensing, training, auditing, care coordination, and other administrative or business functions necessary to operate healthcare services.

    Legal requirements

    PHI may be used or disclosed when required by federal, state, or local law.

    Public health and safety

    PHI may be disclosed to public health authorities for activities such as preventing or controlling disease, reporting certain conditions or injuries, or notifying individuals who may be at risk of exposure to a communicable disease.

    Health oversight

    PHI may be disclosed to authorized oversight agencies for activities such as audits, inspections, or investigations.

    Judicial or administrative proceedings

    PHI may be disclosed in response to a lawful court order, subpoena, or similar legal process when permitted by law.

    Law enforcement

    PHI may be disclosed to law enforcement when required by law or in specific situations permitted under privacy regulations.

    Research

    PHI may be used or disclosed for research when appropriate approvals and privacy protections are in place.

    Organ or tissue donation

    If applicable, PHI may be shared with organizations involved in organ procurement or transplantation.

    Workers compensation and similar programs

    PHI may be disclosed to support claims or benefits related to work related injuries or illnesses.

    Military, correctional, or government functions

    PHI may be disclosed in certain situations involving military service members, veterans, or individuals in correctional settings, when required by law.

    Your Rights Regarding PHI

    You have certain rights regarding your health information.

    Access and copies

    You have the right to inspect and request copies of PHI maintained about you, subject to limited exceptions. Requests may need to be made in writing and reasonable fees may apply as permitted by law.

    Amendments

    You may request corrections to PHI you believe is inaccurate or incomplete. We may deny the request in certain circumstances, such as when the information is accurate or was not created by us.

    Accounting of disclosures

    You may request a record of certain disclosures of PHI made within a specified period, as required by law.

    Restrictions

    You may request limitations on certain uses or disclosures of PHI. While we will consider such requests, we may not be required to agree in all situations.

    Confidential communications

    You may request that we communicate with you about PHI using alternative methods or locations when reasonable.

    Paper copy of this Notice

    You may request a paper copy of this Notice at any time, even if you have received it electronically.

    Breach notification

    You have the right to be notified if a breach of unsecured PHI affecting you is discovered.

    Transmission and Security of PHI

    We take reasonable steps to protect PHI, including the use of secure technologies and administrative safeguards consistent with applicable privacy and security requirements. While we strive to protect information transmitted electronically, no method of transmission can be guaranteed to be completely secure.

    Changes to This Notice

    We may update this Notice from time to time. Any revised version will apply to PHI we maintain as well as information collected in the future. The current version will be available through our website or upon request and will include the effective date.

    Complaints

    If you believe your privacy rights have been violated, you may file a complaint with us or with the United States Department of Health and Human Services. You will not be penalized or retaliated against for filing a complaint.

    Contact Information

    If you have questions about this Notice, your rights, or our privacy practices, please contact:

    Flare MD Email: [email protected]

    State Specific Privacy Protections

    Certain states provide additional privacy protections for medical information. Where applicable, Flare MD and affiliated providers comply with those state laws in addition to federal requirements.

    For example, some states provide additional protections for mental health records, substance use treatment records, HIV related information, genetic testing information, and other sensitive health data. In those states, written authorization or additional safeguards may be required before certain disclosures occur. If you reside in a state with additional protections, you may have additional rights regarding your PHI. You may contact us for more information about state specific privacy rights that may apply to you.