Privacy Policy
We are committed to protecting your privacy. This policy explains how we collect, use, and safeguard your information.
01
Information We Collect
a. Information You Provide
We collect information you provide directly, including:
- Personal identifiers (name, email address, phone number, date of birth, mailing address)
- Health and medical information submitted through intake forms (medical history, current medications, allergies, body measurements, health goals)
- Payment information processed through our third-party payment processor
- Identity verification information as required for telehealth services
- Communications you send to us, including support requests and feedback
b. Information Collected Automatically
When you use our Services, we may automatically collect:
- Device and browser information (IP address, device type, operating system, browser type)
- Usage data (pages visited, features used, click patterns, time spent on pages)
- Cookies, pixels, and similar tracking technologies for analytics and service improvement
- Location data derived from your IP address to verify state eligibility
c. Information from Third Parties
We may receive information from healthcare providers who conduct your telehealth consultations, compounding pharmacies that fulfill your prescriptions, payment processors, and analytics and advertising partners.
02
How We Use Your Information
We use your information to:
- Facilitate telehealth consultations and coordinate prescription fulfillment
- Process payments and manage your subscription
- Communicate with you about your account, appointments, and Services
- Verify your identity and state eligibility for telehealth services
- Comply with legal and regulatory obligations, including pharmacy and telehealth regulations
- Improve and optimize our Services, website, and user experience
- Send you marketing communications (with your consent, where required)
- Detect and prevent fraud, abuse, or unauthorized access
04
Health Information and HIPAA
Certain health information you provide through our Services may be classified as Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act ("HIPAA"). To the extent Fig Health, Inc. acts as a Business Associate under HIPAA, we handle PHI in accordance with applicable HIPAA requirements and our Business Associate Agreements with covered entities.
Your telehealth consultations are conducted on a HIPAA-compliant platform. Healthcare providers who deliver care through our platform are independently responsible for maintaining HIPAA compliance in their clinical practice.
05
FTC Health Breach Notification Rule
To the extent that Fig Health, Inc. collects health information that falls outside HIPAA coverage, we comply with the Federal Trade Commission's Health Breach Notification Rule (16 CFR Part 318). In the event of a breach of unsecured health information, we will notify affected individuals and the FTC as required by applicable law.
06
Cookies and Tracking Technologies
We use cookies and similar technologies for:
- Essential site functionality
- Analytics and performance measurement
- Marketing attribution (with your consent)
You can manage cookie preferences through your browser settings. Disabling cookies may affect functionality of certain Services.
07
Data Security
We implement reasonable administrative, technical, and physical safeguards to protect your information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Access controls and role-based permissions
- Regular security assessments
- Employee training on data handling
08
Data Retention
We retain your personal information for as long as necessary to provide the Services, comply with legal obligations (including medical record retention requirements, which vary by state), resolve disputes, and enforce our agreements. Health and medical records are retained in accordance with applicable state and federal medical record retention laws.
09
Your Rights and Choices
Depending on your state of residence, you may have the right to:
- Access and receive a copy of your personal data
- Correct inaccurate information
- Delete your personal data (subject to legal retention requirements)
- Opt out of the sale of personal data (we do not sell your data)
- Opt out of marketing communications
To exercise any of these rights, contact us at support@startfig.com. We will respond within the timeframe required by applicable law.
10
State-Specific Privacy Rights
California Residents (CCPA/CPRA)
California residents have additional rights regarding their personal information, including the right to know what data is collected and shared, the right to delete, and the right to opt out of sales or sharing. Fig Health, Inc. does not sell personal information. To submit a CCPA request, contact support@startfig.com.
Other State Laws
Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others) may have similar rights. We will honor applicable state privacy law requirements.
11
Children's Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will take steps to delete that information promptly.
12
Third-Party Links
Our Services may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies.
13
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the Effective Date. Your continued use of the Services after changes are posted constitutes acceptance.
14
Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:
- Fig Health, Inc.
- Email: support@startfig.com
- Website: startfig.com
Your first step takes 5 minutes.
5 minutes. No charge if not prescribed. Compounded medications are not FDA-approved.