Online Privacy Policy

Last Revised: July 2025

Tandem Telehealth Inc. & Tandem Telehealth Medical Group, PLLC (collectively "Tandem Telehealth," "we," "us," or "our") are committed to protecting your privacy and ensuring you understand how your personal information is collected, used, shared, and safeguarded. This Privacy Policy outlines our privacy practices for information collected through tandemtelehealth.com and our associated online services (collectively, the "Online Services"). By accessing or using our Online Services, you consent to the terms described in this Privacy Policy.

Table of Contents

1. Children’s Privacy

2. Users Outside the United States

3. Personal Information Collected

4. Methods of Information Collection

5. Cookies and Similar Technologies

o Detailed Use of Cookies

o How to Control Cookies

6. Social Media and Third-Party Tools

7. Purpose and Use of Your Information

8. Information Retention

9. Information Sharing and Disclosure

10. Your Privacy Choices and Controls

o Links to External Websites

11. Our Security Measures

12. California Residents’ Privacy Rights

o Right to Know

o Right to Data Portability

o Right to Deletion

o Right to Rectification

o Right to Opt-Out

13. How to Exercise Your Rights

14. Our Response Timeline and Verification Procedures

15. Non-Discrimination Assurance

16. California "Shine the Light" Law Explained

17. Understanding "Do Not Track" Signals

18. Notification of Policy Changes

19. Our Contact Information

1. Children’s Privacy

Our website and other online services are not designed for individuals under the age of 13. Children under 13 are not permitted to provide any personal information through the website or other online channels. We do not knowingly collect personal data from children under 13 years old. If we discover or are notified that we have inadvertently collected personal information from a child under 13 without verified parental or guardian consent, we will promptly delete that information. If you suspect we have any information about a child under 13, please immediately contact us at privacy@tandemtelehealth.com.

2. Users Outside the United States

Tandem Telehealth and its Online Services are exclusively intended for individuals residing in the United States. International users should be aware that any personal information provided will be processed within the United States, subject to U.S. laws and regulations. By using our services from abroad, you consent to this processing arrangement and acknowledge the transfer of your data to the U.S. for handling in accordance with this Privacy Policy.

Personal Information We Collect

We collect several types of personal information from users through our website and online services, including, but not limited to:

• Contact Information: Name, phone number, email address, mailing address, and insurance details.

• Account Information: Information necessary to set up and manage your online account, including username, password, and security questions and answers.

• Demographic Information: Date of birth, age, gender, marital status, household information, and other demographic details relevant to service provision.

• Health Information: Medical history, symptoms, diagnoses, prescribed treatments, medications, and other health-related information essential for our psychiatry and therapy services.

• Financial Information: Payment details including billing name and address, payment card information (card number, expiration date, security code), insurance information, and transaction history processed securely through Bluefin/Payconnex integrated with Charm Health.

• Technical Information: Device information, IP address, operating system, browser type, and data on your interactions and activities on our website, collected via cookies, web beacons, tracking scripts, and similar technologies.

• Location Information: General location data derived from your IP address, such as country and zip code, and precise location from mobile devices where explicitly disclosed.

• Audio and Visual Information: Any audio or visual recordings provided or captured during telehealth sessions or through communications with our services.

• Inferences: Information we infer about your preferences and behaviors based on your interaction with our website and services.

• Other Information: Any additional information you provide voluntarily, such as through our "Contact Us" form or other interactive website features.

We also utilize third-party analytics and operational tools, including but not limited to Google Analytics, Facebook Pixel, and Cloudflare, to enhance user experience, measure website usage, and improve service effectiveness. For more information about these services and how to manage or opt-out of data collection, please refer to the cookie management options provided on our website.

Providing personal information to Tandem Telehealth is voluntary. However, choosing not to provide certain details may affect your ability to fully utilize our services or access particular features of our website.

For California residents, the following categories of personal information have been collected within the past twelve (12) months:

Categories of Personal Information Collected

• A. Identifiers

o Examples: Name, postal address, email address, IP address, insurance details

o Collected: Yes

• B. California Customer Records (Cal. Civ. Code §1798.80(e))

o Examples: Name, address, phone number, insurance and payment card information

o Collected: Yes

• C. Protected Classification Characteristics

o Examples: Age, gender, marital status

o Collected: Yes

• D. Commercial Information

o Examples: Purchase history, services obtained

o Collected: No

• E. Biometric Information

o Examples: Genetic, physiological characteristics

o Collected: No

• F. Internet/Network Activity

o Examples: Browsing history, interactions with website

o Collected: Yes

• G. Geolocation Data

o Examples: General geographic location

o Collected: Yes

• H. Sensory Data

o Examples: Audio or visual recordings from telehealth sessions

o Collected: Yes

• I. Professional or Employment Information

o Examples: Current or past job history

o Collected: No

• J. Education Information

o Examples: Educational records and history

o Collected: No

• K. Inferences

o Examples: Preferences, behavior patterns

o Collected: Yes

Personal information specifically protected by health privacy laws (HIPAA and CMIA), financial privacy laws (FCRA, GLBA, FIPA), and publicly available information is excluded from the CCPA's scope. Refer to our Notice of Privacy Practices for details about protected health information handling.

4. Methods of Information Collection

We collect your personal information through several methods, including:

• Directly from You: Information you voluntarily provide by filling out forms on our website, such as when using our "Contact Us" page, signing up for services, or interacting with customer support.

• Automatically as You Navigate Our Website: Information automatically collected as you interact with our website, which includes browsing history, IP addresses, location data, and information gathered through cookies, web beacons, analytics tools, and tracking scripts.

o Details of Your Website Visits: This includes traffic data, location data, logs, and other communication data, as well as resources you access on our website.

o Device and Connection Information: Information about your computer or device, internet connection, IP address, operating system, and browser type.

• Social Media and Third-Party Platforms: When accessing our website or services through third-party social media accounts or platforms (such as Facebook, Google, or other integrated services), we may obtain information provided by these services based on your privacy settings. This information may be used according to this Privacy Policy.

Please note that our patient portal is governed by its own separate Terms of Use and Privacy Policy, accessible directly through the patient portal interface.

5. Cookies and Similar Technologies

Like most companies, Tandem Telehealth uses cookies and similar technologies (collectively referred to as “Cookies”) on our websites and online services to personalize and enhance your experience. Information automatically collected through these Cookies may include personal information or may be linked with personal information we collect through other means or receive from third parties. Cookies help us improve our website and provide a more tailored and effective service.

The Technologies We Use for Automatic Data Collection Include:

• Browser Cookies: Small files stored on your device's hard drive. You can refuse browser cookies by adjusting your browser settings. However, disabling cookies may limit access to certain parts of our website.

• Flash Cookies: Certain features of our website may use local stored objects (Flash cookies) to store information about your preferences and navigation. Flash cookies are managed differently than browser cookies.

• Web Beacons: Small electronic files (also called clear gifs, pixel tags, and single-pixel gifs) embedded on pages of our website. Web beacons allow us to count users who visit specific pages, measure popularity of content, and verify system and server integrity.

How We Use Cookies

Cookies store small amounts of information downloaded to your device when you visit our site. This information is sent back to our website to recognize your device:

• Essential Cookies: Required for the operation and core functionality of our websites, including network management and secure access.

• Functional and Performance Cookies: Assist us in measuring website performance and enhancing your user experience.

• Marketing and Personalization Cookies: Track user activities and sessions to deliver personalized advertisements and relevant content, and evaluate the effectiveness of our marketing.

• Analytics Cookies: Allow us to measure and analyze website usage, helping us improve user experience continuously by tracking visitor numbers and page interactions.

Third-party cookies on our site include Google Analytics, Facebook Pixel, and Cloudflare.

Managing Your Cookie Preferences

You can control your cookie choices through your browser settings. If you disable cookies, you may not experience full website functionality. Essential cookies are required for website operation and cannot be disabled without affecting functionality.

6. Social Media and Third-Party Tools

Our website and Online Services may include integrations with social media networks and third-party tools, such as Facebook, Twitter, LinkedIn, YouTube, and Google Maps. These third-party services collect their own data and manage their privacy practices independently from Tandem Telehealth. We recommend reviewing the privacy policies of these external providers to fully understand how your data is collected and utilized by them.

7. Purpose and Use of Your Information

We use the information collected for various operational and strategic purposes, including:

• Service Delivery: Providing effective mental health, psychiatric, and therapeutic services, including patient assessments, consultations, treatment plans, and ongoing care management.

• Transaction Processing: Securely managing payment transactions, billing, insurance claims, and financial communications.

• Communication and Engagement: Sending important service notifications, appointment reminders, newsletters, educational content, and marketing communications tailored to your interests.

• Research and Analysis: Conducting internal research, surveys, service audits, analytics, and quality improvement initiatives.

• Regulatory Compliance: Ensuring adherence to all applicable federal, state, and local laws, regulations, and standards, particularly HIPAA and other privacy laws.

8. Information Retention

Your personal data is retained only as long as necessary to achieve the purposes for which it was collected, including legal, regulatory, accounting, or reporting requirements. Once personal information is no longer required, it will be securely deleted, anonymized, or disposed of in accordance with industry standards and regulations.

9. Information Sharing and Disclosure

We commit to never selling your personal data. Information sharing with third parties occurs only under specific, controlled circumstances:

• Operational Providers: Third-party vendors providing essential services like payment processing, data analysis, customer service support, and IT infrastructure.

• Legal and Regulatory Obligations: Disclosure to authorities or regulatory bodies when required by law or legal process.

• Corporate Transactions: During mergers, acquisitions, restructuring, or similar corporate transitions, provided appropriate confidentiality protections are maintained.

10. Your Privacy Choices and Controls

You have multiple controls available to manage your privacy:

• Access and Updates: Request access to, or correction of, your personal information to ensure its accuracy.

• Deletion Requests: Request the deletion of your personal data, within the bounds of legal and regulatory obligations.

• Opt-Out: Choose to opt-out from receiving certain types of communications, marketing materials, and tailored advertising.

• Cookie Preferences: Manage and control your cookie preferences directly within your browser settings.

Links to External Websites

Our Online Services may contain external links to third-party websites. These sites have their own privacy policies and practices, distinct from Tandem Telehealth. Users should review the privacy policies of such external sites independently, as we are not responsible for their data practices.

11. Our Security Measures

We prioritize the security of your personal information and utilize robust physical, technical, and administrative safeguards to protect against unauthorized access, alteration, disclosure, or destruction of your data. These measures include data encryption, secure servers, firewall protection, intrusion detection systems, and regular security audits and assessments. Access to personal data is restricted solely to authorized personnel who require the information to perform their job duties. Despite our stringent security protocols, no data transmission over the internet can be entirely secure; thus, users assume certain risks associated with online interactions.

12. California Residents’ Privacy Rights

Under the California Consumer Privacy Act (CCPA) and subsequent amendments under the California Privacy Rights Act (CPRA), residents of California have distinct privacy rights regarding their personal information:

Right to Know

You have the right to request detailed information about the types and sources of personal data we collect, the purposes for its collection, and the categories of third parties with whom we share it. We will provide specific pieces of information upon request, subject to verification of your identity.

Right to Data Portability

You have the right to obtain your personal information in a format that allows for easy transfer to another service or platform, where technically feasible and compliant with applicable law.

Right to Deletion

You may request the deletion of your personal information from our systems, subject to certain exceptions as provided under law, such as compliance with legal obligations, prevention of fraud, or to fulfill transactions you initiated.

Right to Rectification

You have the right to request corrections to any inaccuracies in the personal information we hold about you. We will take reasonable measures to update or correct data promptly once inaccuracies are verified.

Right to Opt-Out

California residents can opt-out of the sale or sharing of their personal information with third parties. Tandem Telehealth explicitly states that we do not sell your personal data; however, if any future changes occur, you will be clearly notified, and options to opt-out will be made available.

13. How to Exercise Your Rights

To exercise any privacy rights stated above, you can submit your request via email to privacy@tandemtelehealth.com or by mailing a written request to our postal address provided in the contact information section. Clearly specify your request type, include sufficient details to verify your identity, and provide a reliable method for us to contact you.

14. Our Response Timeline and Verification Procedures

We aim to respond to your verified privacy requests within 45 days of receipt. If additional time is necessary (up to an additional 45 days), we will inform you of the extension and reasons for the delay. Verification of your identity is mandatory for the protection of your privacy and security; thus, we may require you to provide specific details or identification documents. In the case of requests submitted by authorized agents, we will require written authorization from the individual concerned, along with proof of the agent’s identity.

15. Non-Discrimination Assurance

Tandem Telehealth commits to not discriminating against any user exercising their privacy rights. This includes assurances that exercising your rights will not result in denial of services, different service quality, or alterations to pricing and terms. We value your privacy rights and support your exercise of those rights without prejudice.

16. California "Shine the Light" Law Explained

Under California's "Shine the Light" law (Civil Code Section 1798.83), residents may request details regarding any disclosure of personal data to third parties for their direct marketing purposes. Tandem Telehealth explicitly declares that we do not share personal information with third parties for their direct marketing purposes. Should this practice change in the future, affected users will be clearly notified and provided with appropriate opt-out options.

17. Understanding "Do Not Track" Signals

Currently, there is no universally agreed-upon standard for interpreting browser-based "Do Not Track" (DNT) signals. Due to the absence of a consistent industry framework, Tandem Telehealth does not respond to DNT signals sent by browsers. However, we remain committed to user privacy and will update our practices accordingly should industry standards emerge.

18. Notification of Policy Changes

We reserve the right to update or modify this Privacy Policy periodically to reflect changes in our practices, services, legal requirements, or technological advancements. Any modifications will be prominently posted with a clearly marked revision date at the top of this policy. Continued use of our services following the posting of updates indicates your acceptance of such changes. Users are encouraged to regularly review this Privacy Policy to stay informed about how we protect their information.

19. Our Contact Information

If you have questions, concerns, or wish to exercise your privacy rights, please reach out directly to:

Tandem Telehealth Privacy Officer

• Email: privacy@tandemtelehealth.com

• Postal Address: 3900 Westerre Pkwy, Suite 300, Richmond, VA 23233

Please ensure you provide sufficient details in your correspondence to facilitate a timely and accurate response. We are committed to addressing your inquiries and ensuring your privacy rights are respected and enforced effectively.

Your continued engagement with Tandem Telehealth’s Online Services serves as acknowledgment and acceptance of all terms outlined in this comprehensive Privacy Policy.