Effective Date: [Month Day, Year]
Last Updated: [Month Day, Year]
The Creed Collective respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit www.creedcocollective.com, communicate with us, submit a website form, purchase a product or gift card, join our mailing list, or otherwise interact with our online services.
In this Privacy Policy, “The Creed Collective,” “we,” “us,” and “our” refer to:
The Creed Collective
The Suite Spot
2000 W. Main Street, Suite J
Saint Charles, Illinois 60174
Email: heather@creedcocollective.com
Phone: [Insert business phone number]
This Privacy Policy applies to information collected through our public website, online forms, mailing-list registration, gift-card and product links, and similar online interactions.
This Privacy Policy does not replace any separate Notice of Privacy Practices that may apply to protected health information maintained by us as a healthcare provider.
When information is collected and maintained as part of your medical record or treatment relationship, our Notice of Privacy Practices and applicable healthcare privacy laws may govern that information instead of, or in addition to, this Privacy Policy.
We may collect information you voluntarily provide, including:
If you submit an appointment or consultation request, you may choose to provide information related to your health, symptoms, medications, wellness goals, treatment interests, or medical history.
Please do not send highly sensitive medical information through a general website contact form unless the form is specifically identified as secure and intended for that purpose.
Information collected through a secure patient portal, medical intake system, or during the provision of healthcare services may be governed by our Notice of Privacy Practices and applicable healthcare laws.
Payments may be processed by third-party payment, financing, booking, e-commerce, or gift-card providers. These providers may collect payment-card information and other financial details directly from you.
We generally do not receive or store your complete payment-card number when a third-party payment processor handles the transaction.
When you use our website, we or our service providers may automatically collect information such as:
We may use collected information to:
We seek to collect and retain only information reasonably needed for legitimate business, healthcare, legal, and operational purposes. The FTC recommends that businesses understand what personal information they maintain, retain only what is necessary, protect it appropriately, dispose of it securely, and prepare for potential security incidents.
Our website may use cookies, pixels, tags, local storage, and similar technologies.
These technologies may be used to:
You may be able to control cookies through your browser settings or through a cookie-consent tool displayed on the website.
Disabling certain cookies may affect website functionality.
We may use website analytics providers to understand traffic, visitor behavior, page performance, and website effectiveness.
We may also use advertising or social-media tools that collect information about interactions with our website. These tools may use cookies or similar technologies.
Before enabling advertising pixels or analytics tools on pages involving healthcare services, booking, patient portals, symptoms, or treatments, we will evaluate whether those technologies are appropriate for the information involved.
Consumer health information may be subject to HIPAA, the FTC Act, the FTC Health Breach Notification Rule, or other privacy requirements depending on the entity and the way information is collected and used.
We may disclose information to:
Companies that provide services on our behalf, such as:
These providers may access information only as reasonably necessary to perform services for us and subject to applicable contractual and legal obligations.
Where permitted by law, information may be disclosed to laboratories, pharmacies, medical suppliers, collaborating providers, or other entities involved in requested healthcare services.
Protected health information is handled according to our Notice of Privacy Practices and applicable law.
We may disclose information when reasonably necessary to:
Information may be transferred in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar business transaction, subject to applicable law.
We may disclose information when you direct us to do so or provide consent.
We do not sell protected health information.
We do not exchange medical information for monetary payment except as permitted by law and addressed in any applicable authorization or Notice of Privacy Practices.
Insert one of the following after confirming the website’s actual advertising practices:
Option A — No sale or sharing:
We do not sell personal information or share personal information for cross-context behavioral advertising.
Option B — Advertising tools are used:
Certain analytics or advertising technologies may constitute “selling,” “sharing,” or targeted advertising under some state privacy laws. Where required, we provide methods to opt out of those activities.
When you subscribe to our mailing list, request information, or provide consent, we may send:
You may unsubscribe from promotional emails by using the unsubscribe link in the message.
You may opt out of promotional text messages by replying STOP. Message and data rates may apply.
Opting out of marketing communications will not prevent us from sending necessary appointment, transactional, legal, or safety-related communications.
Email and standard text messaging may not always be secure. Do not use ordinary email or text messages to send urgent or highly sensitive medical information.
We use reasonable administrative, technical, and physical safeguards intended to protect personal information.
However, no website, email system, transmission method, or storage system can be guaranteed completely secure. You provide information electronically at your own risk.
If a security incident occurs, we will evaluate and provide notifications as required by applicable law. The Illinois Personal Information Protection Act applies to entities handling nonpublic personal information and establishes obligations relating to security breaches involving covered personal information.
We retain information for as long as reasonably necessary to:
Medical-record retention may be governed by separate healthcare and professional requirements.
Depending on your relationship with us and applicable law, you may request that we:
Some requests may be limited by legal, healthcare-record, regulatory, security, or record-retention obligations.
Submit website privacy requests to:
heather@creedcocollective.com
Subject line: Privacy Request
We may take reasonable steps to verify your identity before processing a request.
If HIPAA applies to your information, you may have rights involving access, amendment, confidential communications, restrictions, accounting of disclosures, and complaints. HHS explains that covered providers generally must allow individuals to access protected health information maintained in designated record sets, subject to limited exceptions.
Those requests should be handled according to our separate Notice of Privacy Practices, not solely through this website Privacy Policy.
Our website may link to third-party services, including:
We do not control the privacy or security practices of independent third parties. Their own privacy policies and terms apply when you use their services.
Our website is intended for adults and is not directed to children under 13.
We do not knowingly collect personal information online directly from children under 13 without legally required authorization. If you believe a child has submitted personal information through our website, contact us so we can review and address the information.
Our website is operated from the United States and is primarily intended for individuals located in the United States.
Information may be processed and stored in the United States, where privacy laws may differ from those in your jurisdiction.
We may update this Privacy Policy periodically.
The updated version will be posted on this page with a revised “Last Updated” date. Material changes may also be communicated through other reasonable methods.
Questions about this Privacy Policy may be directed to:
The Creed Collective
The Suite Spot
2000 W. Main Street, Suite J
Saint Charles, Illinois 60174
Email: heather@creedcocollective.com
Phone: [Insert business phone number]
For questions involving medical records or protected health information, refer to the contact information in our Notice of Privacy Practices.