Privacy policy
Last updated: October 6, 2026
This Privacy Policy describes how ClinAdvize (the “Site”, “we”, “us”, or “our”) collects, uses, and discloses your personal information when you visit, use our services, or make a purchase from clinadvize.com or otherwise communicate with us (collectively, the “Services”). “You” and “your” means you as a user of the Services, whether you are a customer, website visitor, or another individual whose information we have collected.
Please read this Privacy Policy carefully. This notice explains our privacy practices; visiting the Site does not constitute consent to optional analytics, marketing, or embedded media. You choose whether to enable these categories through the cookie banner or preferences.
Changes to this privacy policy
We may update this Privacy Policy from time to time to reflect changes to our practices or for operational, legal, or regulatory reasons. We will post the revised policy, update the “Last updated” date, and take any other steps required by applicable law.
What personal information we collect
The information we collect varies depending on how you interact with us and may include:
- Basic contact details, including your name, address, phone number, and email.
- Order information, including billing details, payment confirmation, email address, and phone number.
- Account and shopping information, including account credentials and items you view or add to your cart.
- Customer support information that you choose to include in communications with us.
- Usage data, such as device, browser, network, IP address, and interaction information collected through cookies and similar technologies.
How we collect and use information
We collect information directly from you, automatically through cookies and similar technologies, and from vendors or service providers such as Shopify and payment processors. We use it to provide products and services, process payments and orders, manage accounts, communicate with you, provide customer support, improve the Services, conduct marketing with the required consent, prevent fraud, comply with legal obligations, and protect our rights and users.
Cookies
Optional cookies and embedded media are opt-in. Until you select “Accept” or enable a category in “Manage,” Analytics, Marketing, and Embedded media remain off. “Reject” keeps all optional categories off. Necessary services remain available to operate and secure the Site. Accept and Reject are presented with equal visual weight.
Use “Your Privacy Choices / Cookie Preferences” in the footer of any content page to reopen the same preferences and change or withdraw consent. We store your category choices, a decision timestamp, and a consent version in your browser’s localStorage under ca-cookie-consent. We ask again after 12 months or when the consent version changes. The shopping cart and theme preference also use first-party browser storage to provide the features you request; they are not analytics consent.
We honor Global Privacy Control (GPC) as an opt-out of Analytics and Marketing, including sale/sharing and targeted-advertising uses controlled by those categories. GPC overrides an earlier acceptance. On Analytics withdrawal, we stop analytics events and remove accessible _ga and _ga_* cookies. If an optional tracking SDK has already loaded, the page may reload to stop it completely. Withdrawal does not erase data already transmitted; you can request deletion as described below. Browser controls can also remove or block cookies, but blocking necessary storage may affect requested features.
The tools and resource providers used by this Site are:
- Booking referral context: when your browser provides an external referring URL, we retain a cleaned version in first-party session storage so it can accompany a booking you submit, including in your Shopify customer profile as “Booking Source Link.” Query strings and fragments are removed. This does not load an analytics or advertising service, and an unavailable referral is not guessed. The session-storage context is limited to the current browsing session.
- Google Analytics 4 (GA4), measurement ID G-655BNDFXVJ: Google’s remote analytics script and collection requests load only after Analytics consent. GA4 uses
_gaand_ga_*cookies to measure page views and consented events, device/browser information, approximate location, and referral information. Consent Mode v2 starts withanalytics_storage,ad_storage,ad_user_data, andad_personalizationdenied. Analytics consent grants analytics storage; the three advertising signals are granted only with Marketing consent. We do not currently load a separate Google Ads tag. - Klaviyo: its onsite script for signup popups and personalized marketing loads only after Marketing consent. It may use cookies and similar identifiers when enabled. Newsletter and Playbook forms separately ask for email-marketing consent and submit to our own server; submitting those forms does not automatically enable onsite tracking.
- Replit hosting analytics: our hosting provider supplies cookieless traffic and performance analytics based on network/request data, including IP traffic. These are separate from GA4 and remain active for hosting operations; rejecting optional cookies does not disable infrastructure logging.
- Hosting and load-balancer cookies: where set by our hosting infrastructure, necessary cookies may support request routing, security, and reliable service. They are not enabled as advertising identifiers by our consent controls. First-party functionality and security can operate without optional consent.
- unpkg CDN: serves React, ReactDOM, and Babel for the Site’s rendering runtime, and Three.js (including its font data), GSAP, and Matter.js for visual effects. These code/resource downloads are used for rendering and animation, not analytics or advertising, and may occur without optional consent. Like other resource providers, the CDN receives request information such as IP address and browser headers.
- Google Fonts: Google’s font stylesheet and font-file services provide Cormorant Garamond and Hanken Grotesk. They load for typography, not analytics or advertising, and receive the network information needed to deliver these resources.
- Google reCAPTCHA: its anti-abuse script is requested when you submit a booking or initiate checkout, rather than on an ordinary page view. It may process device/network signals and set security cookies to prevent automated abuse. It is treated as a necessary security service, not Analytics or Marketing.
- Google reviews and Maps links: review text is served from our own cached API; the browser does not load a Google review widget or Maps embed to display that text. Google-hosted reviewer photos load only with Embedded media consent. Maps links open Google only when you follow them, and Google’s policies then apply.
- Video: the current homepage background video and its poster are hosted with our Site, not embedded from YouTube or Vimeo. This local decorative video loads and plays independently of cookie choices and does not enable analytics or marketing. Visitors who prefer reduced motion see the poster instead. Embedded media consent still controls externally hosted reviewer photos. There are currently no third-party video players or map iframes.
- Shopify: provides product information, product images (which may come from Shopify’s CDN), cart checkout, order processing, and payment-related services when you shop. Product images are requested to display the catalog; checkout may use necessary cookies under Shopify’s own controls. For details, see Shopify’s cookie policy. Our marketing-site preferences do not control a separate Shopify checkout’s cookies or other third-party sites reached through links.
Analytics (Google Analytics 4)
With your Analytics consent, we use GA4 to understand which pages are viewed, how visitors arrived, and which actions they take, such as starting a discovery-call booking. Without that consent, Google’s analytics script is not loaded, analytics events are not sent, and this Site does not set GA cookies. Rejecting optional cookies or sending GPC keeps GA4 off. You can withdraw through the footer preferences at any time.
How we disclose information
We may disclose personal information to vendors and service providers acting on our behalf, business and marketing partners, affiliates, parties you direct or consent to, or as needed for a business transaction, legal obligation, enforcement of terms, or protection of the Services and rights of users or others. We do not use or disclose sensitive personal information to infer characteristics about you.
Children’s data, security, and retention
The Services are not intended for children, and we do not knowingly collect their personal information. No security measure is perfect or impenetrable, and information sent over insecure channels may be at risk. Retention depends on our need to maintain accounts, provide Services, comply with legal obligations, resolve disputes, and enforce agreements.
Your rights and choices
Depending on your state of residence and whether the applicable law covers our processing, US state privacy laws may give you the following rights:
- Know whether we process your personal information and access information about its collection, use, disclosure, and recipients.
- Request correction of inaccurate personal information.
- Request deletion of personal information, subject to legal exceptions.
- Obtain a portable copy of personal information you provided.
- Opt out of sale, sharing for cross-context behavioral advertising, targeted advertising, and certain profiling with legal or similarly significant effects.
- Limit certain uses or disclosures of sensitive personal information, or withdraw consent where processing requires it.
- Use an authorized agent where permitted, and appeal a denial of a privacy request where the law provides an appeal.
To exercise a right or appeal a decision, email support@clinadvize.com with “Privacy request” or “Privacy appeal” in the subject and enough information for us to identify the request. Do not send passwords or payment-card details. We will respond within the period required by applicable law and explain any applicable exception or appeal process. You may also opt out of promotional emails using their unsubscribe link.
We will not discriminate against you for exercising privacy rights. We may need to verify your identity or an authorized agent’s authority before responding.
California privacy rights (CCPA)
Where the CCPA, as amended by the CPRA, applies, California residents may request access to categories and specific pieces of personal information, correction and deletion, opt out of sale or sharing, and limit certain uses of sensitive personal information. Use the contact method above for requests; use the footer preferences or GPC for browser-level opt-outs. We will not discriminate against you for exercising these rights.
International users and GDPR rights
We may transfer, store, and process personal information outside your country, including in the United States. For transfers out of Europe, we rely on recognized transfer mechanisms where required. Users covered by the GDPR may have rights of access, rectification, erasure, restriction, objection, and data portability.
Contact
To ask about our privacy practices or exercise a privacy right, email support@clinadvize.com.
CLINADVIZE BUSINESS ASSOCIATE TERMS NOTICE
Updated October 6, 2026
This Business Associate Notice (“BA Notice”) describes the HIPAA-related obligations and practices of ClinAdvize, LLC (“ClinAdvize”) when ClinAdvize provides services to a client that is a HIPAA Covered Entity and, in performing those services, creates, receives, maintains, or transmits Protected Health Information (“PHI”) on behalf of that client or is provided access to PHI in connection with the performance of such services.
This BA Notice is incorporated into and forms part of ClinAdvize’s Privacy Policy. However, this BA Notice does not independently create a Business Associate relationship where the services provided by ClinAdvize do not involve the creation, receipt, maintenance, or transmission of PHI on behalf of a Covered Entity or otherwise allow or require ClinAdvize to access PHI in connection with the performance of such services.
For purposes of this BA Notice, the applicable ClinAdvize client is referred to as the “Covered Entity” and ClinAdvize is referred to as the “Business Associate” (each a “Party” and collectively, the “Parties”), but only to the extent the relationship meets the requirements for a Business Associate relationship under HIPAA.
Engagement Process
As part of the process of retaining ClinAdvize, each client is required to electronically acknowledge and accept ClinAdvize’s Terms of Service, Subscription Policy, Privacy Policy, and Refund Policy, which collectively govern the client’s purchase and use of ClinAdvize’s services.
When a client engagement requires ClinAdvize to act as a Business Associate under HIPAA, ClinAdvize will also provide the applicable client or clinic with a separate, stand-alone Business Associate Agreement (“BAA”) for execution by both Parties. The executed BAA will govern the Parties’ respective HIPAA obligations with respect to PHI.
1. DEFINITIONS
Capitalized terms not otherwise defined in this BA Notice shall have the meanings assigned to them under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), the Health Information Technology for Economic and Clinical Health Act (“HITECH”), and the regulations promulgated thereunder, as amended from time to time, including 45 C.F.R. Parts 160 and 164 (collectively, the “HIPAA Rules”). Such terms include Breach, Designated Record Set, Disclosure, Electronic Protected Health Information (“ePHI”), Individual, Minimum Necessary, Protected Health Information (“PHI”), Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
“Covered Entity” means a ClinAdvize client that is a covered entity under HIPAA and for which ClinAdvize performs services that may involve the creation, receipt, maintenance, or transmission of PHI on the client’s behalf, or that otherwise involve or require ClinAdvize to access PHI in connection with the performance of such services.
“Business Associate” means ClinAdvize, LLC, a New Hampshire limited liability company, to the extent ClinAdvize, in performing services for a Covered Entity, creates, receives, maintains, or transmits PHI on behalf of the Covered Entity, or is otherwise provided access to PHI in connection with the performance of such services, and the relationship meets the requirements for a Business Associate relationship under the HIPAA Rules.
2. PURPOSE AND SCOPE
This BA Notice is provided in advance of, and applies to the extent ClinAdvize is or will be acting as, a Business Associate of a Covered Entity under the HIPAA Rules. Nothing in this BA Notice independently creates a Business Associate relationship where the services performed by ClinAdvize do not involve the creation, receipt, maintenance, or transmission of PHI on behalf of a Covered Entity or otherwise involve or require ClinAdvize to access PHI in connection with the performance of such services.
Visitors to this website, and clients retaining ClinAdvize, are hereby notified that ClinAdvize, in connection with certain consulting, implementation, vendor coordination, technology, and related services, may create, receive, maintain, transmit, view, or otherwise access PHI as necessary to perform the services for which ClinAdvize has been retained. Such activities may include system setup and configuration, EMR/EHR implementation or migration, workflow and coding guidance, data migration or transfer, laboratory or third-party vendor integration, account setup, troubleshooting, or other consulting or support services.
ClinAdvize will access, Use, or Disclose PHI only to the extent reasonably necessary to perform such services and as otherwise permitted by the applicable BAA and HIPAA Rules.
3. PERMITTED USES AND DISCLOSURES OF PHI
ClinAdvize may Use or Disclose PHI only as necessary to perform the services for which it has been retained, as permitted by the applicable BAA, or as Required by Law. ClinAdvize shall not Use or Disclose PHI in a manner that would violate the HIPAA Privacy Rule if done by the Covered Entity, except as expressly permitted for a Business Associate under the HIPAA Rules.
ClinAdvize may Use PHI for its proper management and administration or to carry out its legal responsibilities. ClinAdvize may Disclose PHI for those purposes only if the Disclosure is Required by Law or ClinAdvize obtains reasonable assurances from the recipient that the PHI will remain confidential, will be Used or further Disclosed only as Required by Law or for the purpose for which it was disclosed, and the recipient will notify ClinAdvize of any breach of confidentiality of which it becomes aware.
ClinAdvize shall limit its Uses, Disclosures, and requests for PHI to the Minimum Necessary to accomplish the intended purpose, to the extent the Minimum Necessary standard applies under the HIPAA Rules.
4. SAFEGUARDS AND SECURITY
ClinAdvize shall use appropriate administrative, physical, and technical safeguards to prevent Use or Disclosure of PHI other than as permitted by applicable law and the applicable BAA. With respect to ePHI, ClinAdvize shall comply with the applicable requirements of the HIPAA Security Rule, including 45 C.F.R. Part 164, Subpart C.
ClinAdvize shall maintain policies, procedures, and reasonable security measures appropriate to the nature of the PHI and ePHI it creates, receives, maintains, transmits, or otherwise accesses in connection with services performed for a Covered Entity.
5. REPORTING OF IMPERMISSIBLE USES, DISCLOSURES, SECURITY INCIDENTS, AND BREACHES
ClinAdvize shall report to the applicable Covered Entity any Use or Disclosure of PHI not permitted by the applicable BAA of which ClinAdvize becomes aware, including any Breach of Unsecured PHI as required by 45 C.F.R. § 164.410 and any Security Incident as required by the HIPAA Rules.
ClinAdvize shall provide notice of a Breach of Unsecured PHI without unreasonable delay and in no event later than sixty (60) calendar days after discovery, or within any shorter period required by applicable law or expressly agreed upon in the applicable BAA. The notice shall include, to the extent known, the information required by 45 C.F.R. § 164.410.
The Parties acknowledge that unsuccessful Security Incidents that do not result in unauthorized access, Use, Disclosure, modification, or destruction of ePHI—including routine pings, scans, unsuccessful login attempts, and similar events—may occur in the ordinary course. The applicable BAA may address notice regarding such routine unsuccessful Security Incidents.
6. SUBCONTRACTORS AND INDEPENDENT CONTRACTORS
ClinAdvize shall ensure that any Subcontractor, including any independent contractor acting as a Subcontractor, that creates, receives, maintains, or transmits PHI on behalf of ClinAdvize agrees in writing to the applicable restrictions, conditions, safeguards, and requirements imposed upon ClinAdvize with respect to such PHI, as required by the HIPAA Rules.
7. ACCESS TO PHI
To the extent ClinAdvize maintains PHI in a Designated Record Set, ClinAdvize shall make such PHI available to the Covered Entity, or as directed by the Covered Entity to an Individual, as necessary for the Covered Entity to satisfy its obligations under 45 C.F.R. § 164.524 and the applicable BAA.
8. AMENDMENT OF PHI
To the extent ClinAdvize maintains PHI in a Designated Record Set, ClinAdvize shall make PHI available for amendment and incorporate amendments as directed or agreed to by the Covered Entity as necessary for the Covered Entity to satisfy 45 C.F.R. § 164.526 and the applicable BAA.
9. ACCOUNTING OF DISCLOSURES
ClinAdvize shall document Disclosures of PHI and maintain information concerning such Disclosures as necessary for a Covered Entity to respond to a request for an accounting of disclosures under 45 C.F.R. § 164.528.
10. AVAILABILITY TO THE SECRETARY
ClinAdvize shall make its internal practices, books, and records relating to the Use and Disclosure of PHI received from, or created or received by ClinAdvize on behalf of, a Covered Entity available to the Secretary of the U.S. Department of Health and Human Services as required by the HIPAA Rules.
11. COVERED ENTITY OBLIGATIONS
A Covered Entity shall notify ClinAdvize of any limitation in the Covered Entity’s Notice of Privacy Practices to the extent such limitation may affect ClinAdvize’s permitted Use or Disclosure of PHI.
A Covered Entity shall notify ClinAdvize of any change in, or revocation of, an Individual’s authorization or permission to Use or Disclose PHI to the extent such change may affect ClinAdvize’s Use or Disclosure of PHI.
A Covered Entity shall notify ClinAdvize of any restriction on the Use or Disclosure of PHI to which the Covered Entity has agreed under 45 C.F.R. § 164.522 to the extent such restriction may affect ClinAdvize.
A Covered Entity shall not request ClinAdvize to Use or Disclose PHI in any manner that would not be permissible under the HIPAA Rules if performed by the Covered Entity, except to the extent a Business Associate is expressly permitted to do so.
12. PERFORMANCE OF COVERED ENTITY OBLIGATIONS
To the extent ClinAdvize is expressly retained and authorized to carry out one or more of a Covered Entity’s obligations under the HIPAA Privacy Rule, ClinAdvize shall comply with the requirements of the Privacy Rule applicable to the Covered Entity in the performance of those delegated obligations.
13. TERM AND TERMINATION
The HIPAA-related obligations described in this BA Notice apply for so long as ClinAdvize is acting as a Business Associate of a Covered Entity. The specific effective date, term, termination rights, and obligations of the Parties shall be governed by the applicable stand-alone BAA.
Upon termination of the applicable Business Associate relationship, ClinAdvize shall, if feasible and as required by the applicable BAA and HIPAA Rules, return to the Covered Entity or destroy PHI received from the Covered Entity or created, maintained, or received by ClinAdvize on its behalf.
If return or destruction is infeasible, ClinAdvize shall continue to protect the retained PHI and limit further Uses and Disclosures to those purposes that make return or destruction infeasible, consistent with the HIPAA Rules and applicable BAA.
14. STATE LAW AND MORE STRINGENT REQUIREMENTS
The Parties shall comply with applicable federal and state privacy, confidentiality, security, and breach-notification laws governing the PHI at issue. To the extent applicable state law provides greater privacy protection or affords an Individual greater rights than HIPAA and is not preempted, the more protective applicable requirement shall control.
15. NO SALE OR UNAUTHORIZED MARKETING OF PHI
ClinAdvize will not sell PHI or receive remuneration in exchange for PHI.
ClinAdvize will not Use or Disclose PHI for ClinAdvize’s own marketing purposes. ClinAdvize may assist a Covered Entity with communications or marketing activities involving PHI only when such services are within the scope of ClinAdvize’s engagement and are permitted by the applicable BAA, the HIPAA Rules, and other applicable law.
16. REGULATORY CHANGES
ClinAdvize may update this BA Notice as reasonably necessary to reflect changes in HIPAA, HITECH, implementing regulations, or other applicable privacy and security laws.
Any executed BAA between ClinAdvize and a Covered Entity shall be amended as reasonably necessary to maintain compliance with applicable law.
17. INTERPRETATION; SURVIVAL
This BA Notice is intended to describe ClinAdvize’s practices and obligations when acting as a Business Associate and shall be interpreted consistently with the HIPAA Rules.
Obligations concerning PHI that are required by HIPAA or an applicable BAA to continue following termination of a Business Associate relationship shall survive termination as required by law or the applicable BAA.
Nothing in this BA Notice is intended to create rights in any third party except as required by applicable law.
18. RELATIONSHIP TO CLINADVIZE TERMS AND STAND-ALONE BAA
This BA Notice is incorporated into ClinAdvize’s Privacy Policy and should be read together with ClinAdvize’s Terms of Service and other applicable website policies.
This BA Notice does not expand the scope of services ClinAdvize has agreed to provide, require ClinAdvize to receive or access PHI when PHI is unnecessary to the services being provided, or authorize either Party to Use or Disclose PHI beyond what is permitted by applicable law.
When ClinAdvize will act as a Business Associate in connection with a client engagement, ClinAdvize will provide the applicable client or clinic with a separate, stand-alone BAA for execution by both Parties. The executed BAA will govern the Parties’ specific obligations concerning PHI and will control over this BA Notice in the event of a conflict concerning HIPAA or PHI.
19. CONTACT
Questions regarding this Business Associate Notice or requests concerning ClinAdvize’s stand-alone Business Associate Agreement may be directed to Support@clinadvize.com.
Effective: 2026-10-06 · Last updated: 2026-10-06