Privacy Notice
Last Update: December 16, 2022
This Privacy Notice describes the personal information ReShape Lifesciences® Inc. (“ReShape”, “we”, “us”, “our”) collects from you as you use ReShapeCare® (the “Services”), with whom we share it, and the choices you have in connection with this.
It is important that you read this Privacy Notice together with any other privacy policy we may provide or direct you to on specific occasions when we are collecting or processing personal information about you so that you are fully aware of how and why we are using and/or sharing your information. This Privacy Notice supplements the following notices and privacy policies and is not intended to override them
· https://www.reshapelifesciences.com/privacy-policy/
· https://www.myreshapecare.com/legal/privacy/
If you do not agree to be bound by this Privacy Notice, you should immediately cease all use of the Services.
APPLICABILITY OF PRIVACY NOTICE
This Privacy Notice applies to your interactions with the Services.
Limited HIPAA Applicability
If, during your interactions with the Services, you are interested in being connected or scheduling an appointment with a bariatric surgeon, ReShape will assist with making this connection or scheduling the appointment with a bariatric surgeon. In providing this specific aspect of the Services, ReShape may collect and store Protected Health Information (as defined by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”)) on behalf of the bariatric surgeon as a business associate. As a business associate, ReShape cannot use or disclose Protected Health Information (“PHI”) in a way that that is prohibited by either HIPAA or the terms of ReShape’s business associate agreement with the bariatric surgeon. For information on how the bariatric surgeon collects, uses, and shares your PHI, please refer to the bariatric surgeon’s notice of privacy practices. HIPAA only applies in the limited situation described in this paragraph. Otherwise, the information you provide to ReShape in connection with the Services is not PHI and is not protected by HIPAA.
INFORMATION YOU PROVIDE TO US
We collect personal information directly from you when you:
- Create an employee wellness user account. When you create an account, or an account is created on your behalf by one of our call center agents with you over the phone, we will collect your identifiers (name, email address, telephone number, physical address), and account login information (username and selected password) in order to administer your account, to communicate with you, and to provide the Services. Once your account is created, we will also collect your demographic information (birthdate, gender, and ethnicity) and your health information (height and weight) and applicable medical conditions in order to provide the wellness coaching Services. If you are creating an account through your employer’s agreement with ReShape, we will collect your employment information (name of employer). We will use this information to ensure your employer is appropriately billed for the Services provided. If you consent, we will also collect additional personal identifiers (gender, birth date, ethnicity), behavioral activity (physical activity, eating habits), mental health indicators (e.g., stress, burnout, social determinates) and health information (health goals, nutrition preferences, sleep tracking data, fitness tracking data, heart rate, blood pressure, and/or glucose level). We will use this information to provide the wellness Services for which you have signed up through the Services. If you consent (opt in) to receive promotional and account-related text messages to your cellular telephone number, we will use your cellular telephone number to send you automated promotional text messages. Message and data rates may apply. Reply “STOP” to any promotional text message to stop us from sending you future promotional text messages, or “HELP” for further assistance. Message frequency varies. Your agreement to receive promotional text messages is not a condition of any purchase from us.
· Create an individual wellness user account. ReShape makes a free trial and paid subscription account of the Services available to prospective customers. When you create an account, or an account is created on your behalf by one of our call center agents with you over the phone,, we will collect information from you, your identifiers (name, email address, telephone number, physical address), and account login information (username and selected password) in order to administer your account, to communicate with you, and to provide the Services. Once your account is created, we will also collect your demographic information (birthdate, gender, and ethnicity, etc.) and your health information (height, and weight, etc.) and applicable medical conditions) in order to provide the wellness coaching Services. If you consent, we will also collect additional personal identifiers (gender, birth date, ethnicity), behavioral activity (physical activity, eating habits), mental health indicators (e.g., stress, burnout, social determinates) and health information (health goals, nutrition preferences, sleep tracking data, fitness tracking data, heart rate, blood pressure, and/or glucose level). We will use this information to provide the wellness Services for which you have signed up through the Services. If you consent (opt in) to receive promotional and account-related text messages to your cellular telephone number, we will use your cellular telephone number to send you automated promotional text messages. Message and data rates may apply. Reply “STOP” to any promotional text message to stop us from sending you future promotional text messages, or “HELP” for further assistance. Message frequency varies. Your agreement to receive promotional text messages is not a condition of any purchase from us.
· Post your Community Center question or response. When you use the Community Center portion of the ReShapeCare program, we collect your identifiers (name and email address) and anything you decide to share, including photos, documents, text submissions, likes, and dates. We use the information you post on our forum or discussion board to facilitate your communications with other users and us. We also use this personal information to notify you of activity on the specific forum question or response.
- Contact us. When you contact us or send us a question or inquiry, we will collect your identifiers (name, email address, and telephone number). We use this personal information to respond to your questions or inquiries, troubleshoot where necessary, communicate with you about, and address any issues you may have.
- Make a payment. If you make a payment through the Services, our third-party payment processor will collect your identifiers (name, email address, physical address), and payment information (payment card number, expiration date, and CVV), but we will only receive your payment and the last four digits of your payment card number. We use this personal information to fulfill your purchases and for accounting purposes.
- Subscribe to marketing emails. If you subscribe to our marketing emails, we will collect from you, your email address to fulfill your request to receive information we feel may be of interest to you. You can unsubscribe at any time by clicking on the “unsubscribe” link in each email. Please note that we will continue to send you notifications necessary to the wellness Services or requested products. Our communications contain tracking technologies to analyze whether a predefined action took place by a recipient, such as opening our communications, in order to better adapt and distribute our communications. When you opt-in to our marketing communications, you are opting into the use of these technologies. You can disable tracking by disabling the display of images by default in your email program.
- Participate in Wellness Coaching. If you participate in the wellness coaching, we will collect your health information (participation and engagement activity, such as self-reported activities, assessments, and Tracked Health Indicators) that will be used to provide the wellness coaching. “Tracked Health Indicators” includes weight (weight, fat percentage, body mass index), diabetes (glucose, A1C), sleep (duration, quality), nutrition (pictures of meals and possible descriptors), fitness (exercise type and duration), routine (steps), and biometrics (blood pressure).
- ReShape Partner Information. We collect information about individuals within our ReShape Partners organization (“Partner Information”). Partner Information includes information related to the Partner’s account identifiers (name, work email address, work phone number), and employment information (job title). We use Partner Information to support the Partner account, maintain our business relationship with the Partner, respond to Partner inquiries, or perform accounting functions. ReShape Partners may update personal information and password by logging into the ReShape Platform and updating their account. ReShape Partners may contact ReShape support in order to delete their Personal Data. In some cases, we may not be able to delete Partner Information, and in such cases we will tell you why. To the extent EU data protection law applies, the legal basis for this is our legitimate interest in the efficient operation of our business and the Services.
INFORMATION COLLECTED FROM THIRD PARTIES
When you integrate third party services with the Services, we collect your information in the following circumstances:
- Utilize a health tracking device. If you utilize a health tracking device, we will collect from the health tracking device provider your personal identifiers (name, email address, physical address, telephone number), and health information (e.g., biometric data (i.e., height, weight, BMI, blood pressure). We use this information to provide you and/or your health care professional with information about your current health status and to facilitate the wellness services.
INFORMATION COLLECTED VIA COOKIES
In addition to the personal information you provide directly, we may also collect information, including internet and other electronic network activity information, from you automatically via cookies as you use the Services. This information includes:
- Usage information: We use essential, performance, and analytics cookies to collect information about your interaction with our Services, such as what you access, what you click on, the frequency of access, and how much time you spend on the Services. We use this information to: (i) track you within the Services; (ii) enhance user experience; (iii) conduct analytics to improve the Services; (iv) prevent fraudulent use of the Services; and (v) diagnosis and repair Services errors, and, in cases of abuse, track and mitigate the abuse.
- Device information: We use essential, performance, and analytics cookies to collect certain information about the device you use to access the Services, such as hardware model, operating system, and device preferences. We use this information to: (i) track you within the Services; (ii) enhance user experience; (iii) conduct analytics to improve the Services; (iv) prevent fraudulent use of the Services; and (v) diagnosis and repair Services errors, and, in cases of abuse, track and mitigate the abuse.
- Location information: We use essential, performance, and analytics cookies to collect information about your location, which may be determined through your IP address. We use this information to: (i) track you within the Services; (ii) enhance user experience; (iii) conduct analytics to improve the Services; (iv) prevent fraudulent use of the Services; and (v) diagnosis and repair Services errors, and, in cases of abuse, track and mitigate the abuse.
Specifically, our Services utilize the following cookies:
- Strictly necessary cookies. We use strictly necessary cookies to authenticate users, prevent fraudulent use, and to ensure the Services function properly.
- Functional cookies. We use functional cookies to provide enhanced functionality and personalization, to remember your preferences, to diagnose server and software errors, and in cases of abuse, track and mitigate the abuse.
- Analytic cookies. We use Google Analytics to collect information on your use of the Services to improve our Services. In order to collect this information, Google Analytics may set cookies on your browser, or read cookies that are already there. Google Analytics may also receive information about you from applications you have downloaded that partner with Google. We do not combine the information collected through the use of Google Analytics with personally identifiable information. Google’s ability to use and share information collected by Google Analytics about your visits to our Services or to another application which partners with Google is restricted by the Google Analytics Terms of Use and the Google Privacy Policy available Terms of Use and Privacy Policy. To prevent your data from being used by Google Analytics, you can download the Google Analytics opt-out browser add-on.
In general, to disable cookies and limit the collection and use of information through them, you can set your browser to refuse cookies or indicate when a cookie is being sent. When you opt-out an opt-out cookie will be placed on your device. The opt-out cookie is browser and device specific and will only last until cookies are cleared from your browser or device.
HOW WE SHARE YOUR PERSONAL INFORMATION
ReShape may need to make the personal information identified in this Privacy Notice available within ReShape, with service providers, or with other third parties. These instances include:
- Within ReShape. We may share personal information within the ReShape corporate family to the extent necessary in order to efficiently carry out our business and to the extent permitted by law.
- Among forum participants. If you post in a ReShape forum or discussion board, your username, and any information you include in your post will be shared with other users of the Services. To delete your post, please contact welcome@reshapecare.com.
- With service providers. We may share your personal information with service providers that assist us in provision of the Services. These service providers include our website and mobile application developer, marketplace provider, payment processor, communications provider, our video chat provider.
- In the event of a corporate reorganization. In the event that we enter into, or intend to enter into, a transaction that alters the structure of our business, such as a reorganization, merger, acquisition, sale, joint venture, assignment, consolidation, transfer, change of control, or other disposition of all or any portion of our business, assets or stock, we would share personal information with third parties, including the buyer or target (and their agents and advisors) for the purpose of facilitating and completing the transaction. We would share personal information with third parties if we undergo bankruptcy or liquidation, in the course of such proceedings.
- For legal purposes and to prevent harm. We will share personal information where we are legally required to do so, such as in response to court orders, law enforcement or legal processes; to establish, protect, or exercise our legal rights or contractual obligations; to defend against legal claims or demands; to detect, investigate, prevent, or take action against illegal activities, fraud, or situations involving potential threats to the rights, property, or personal safety of any person; or to comply with the requirements of any applicable law.
- With your consent. Apart from the reasons identified above, we may request your permission to share your personal information for a specific purpose. We will notify you and request consent or authorization before you provide the personal information or before the personal information you have already provided is shared for such a purpose. You may revoke your consent at any time.
ReShape may also share anonymized and aggregated data (“De-Identified Information”) in public reports about exercise and activity. ReShape may also disclose De-Identified Information for general research purposes and in research collaborations with third parties, such as universities, hospitals, or other laboratories to determine the prevalence of particular conditions among users or to determine whether a user might be suitable for research or clinical trials. ReShape may also use De-Identified Information for commercial collaborations with private companies for purposes such as product design or enhancement of programs we provide.
YOUR INFORMATION CHOICES
· Correct or view your personal information: You may access your ReShape account profile to correct or view certain personal information of yours in our possession and which is associated with your profile.
· Location settings: You can prevent your mobile device from sharing your location data by adjusting the permissions on your mobile device or within the Services.
· Marketing emails: You may opt-out of receiving marketing emails from us by clicking the “unsubscribe” link provided with each email. Please note that we will continue to send you emails necessary to the Services or any assistance you request.
· Marketing text messages: You may opt out of receiving marketing text messages from us by responding “STOP” to any of our text messages.
· Push notifications: If you have enabled push notifications, you may disable these at any time by updating your device settings.
· Opt Out of Other Cookies: All session cookies are temporary and expire after you close your web browser. Persistent cookies can be removed by following your web browser’s directions. To find out how to see what cookies have been set on your computer or device, and how to reject and delete the cookies, please visit: https://www.aboutcookies.org/. Please note that each web browser is different. To find information relating to your browser, visit the browser developer’s website or mobile application. If you reset your web browser to refuse all cookies or to indicate when a cookie is being sent, some features of our website and mobile application may not function properly. If you choose to opt out, we will place an "opt-out cookie" on your computer. The "opt-out cookie" is browser specific and device specific and only lasts until cookies are cleared from your browser or device. The opt-out cookie will not work for essential cookies. If the cookie is removed or deleted, if you upgrade your browser or if you visit us from a different computer, you will need to return and update your preferences.
· Uninstall the Application: You can stop further collection of your personal information through the Mobile Application by uninstalling the Mobile Application.
NEVADA RESIDENTS
If you are a consumer in the State of Nevada, you may request to opt-out of the current or future sale of your personal information. We do not currently sell any of your personal information under Nevada law, nor do we plan to do so in the future. However, you can submit a request to opt out of future sales by contacting us at welcome@reshapecare.com. Please include “Opt-Out Request Under Nevada Law” in the subject line of your message.
DO NOT TRACK
We do not support Do Not Track (DNT).
CHILDREN’S PRIVACY
The Services are not intended for individuals under the age of eighteen (18). If we learn that we have collected or received personal information from individuals under the age of eighteen (18), we will delete the personal information. If you believe we have personal information on individuals under the age of eighteen (18), please contact us at the contact information provided below.
SECURITY OF YOUR INFORMATION
We implement and maintain reasonable security procedures and practices to protect the personal information we collect from unauthorized access, destruction, use, modification, or disclosure. These security practices include encryption and access controls. However, no security measure or modality of data transmission over the Internet is 100% secure and we are unable to guarantee the absolute security of the personal information we have collected from you.
CHANGES TO THIS PRIVACY Notice
We may amend this Privacy Notice in our sole discretion. We will post the changes to this page and will indicate the date the changes go into effect. We encourage you to review our Privacy Notice to stay informed. If we make changes that materially affect your privacy rights, we will notify you via prominent posting on the Services and/or via email and obtain your consent, if required.
CONTACT US
If you have any questions about this Privacy Notice, please contact us at welcome@reshapecare.com.