Scope
This Privacy Policy is an agreement between you and SlimCell, LLC, doing business as THINNR ("THINNR"). It is provided to help you understand what information we collect, how we store it, and how we use it. By using THINNR.net or any other THINNR website, app, or service (collectively, the “THINNR Services”), you consent to the processing of your Personal Information (defined below) and non-personally identifiable data in the United States according to this policy. If you disagree with any part of this policy or other policies listed on the THINNR Services, please do not use them.
Definitions
Personal Information: Information that can identify you, such as your name, address, email, phone number, social security number, insurance ID numbers, and identifiable health information. It does not include anonymized data that cannot identify an individual.
Protected Health Information: As defined by HIPAA, this includes any information about an individual's physical or mental health, healthcare provision, or payment for healthcare that can identify the individual.
About THINNR
THINNR licenses software to healthcare providers who use it to offer education, digital health support, monitor patient health, manage progress, collect payments, and more. THINNR does not own the data or any Protected Health Information submitted through its services. This data is controlled by our healthcare provider clients and is subject to their policies and applicable laws, such as HIPAA.
Information Collection
Non-Personally Identifiable Information: Includes browser type, IP address, and aggregate traffic information, used for administrative purposes and service improvement.
Personal Information: Collected when you register, use the service, interact with it, upload data, or when provided by your healthcare provider or third parties.
Payment Information
When making payments through the THINNR Service, you may need to provide financial information to our third-party payment processor, Stripe, Inc.
Use of Cookies
We use cookies on the THINNR Services. By using these services, you accept our use of cookies. You can manage cookies through your browser settings. We use:
Strictly Necessary Cookies: Essential for website functionality.
Analytics Cookies: Collect anonymous data to improve services.
Use of Collected Information
Primary Purpose: To provide requested products and services, notify you of changes, and communicate with you.
Other Uses: Include communications, surveys, anonymized data for research, and business purposes.
Disclosure of Personal Information
Vendors and Service Providers: We may share information with vendors involved in providing the THINNR Service.
Healthcare Providers: Your healthcare provider will have access to your Personal Information and Protected Health Information.
Legal Requirements: We may disclose information as required by law or to prevent fraud or illegal activities.
Mergers and Acquisitions: Your information may be transferred in the event of a business transaction.
With Your Permission: We may disclose information according to your instructions.
Access and Correction of Information
Contact your healthcare provider to access, correct, amend, or delete Personal Information. For other inquiries, contact support@thinnrweightloss.com.
Security
We implement reasonable measures to protect the information we collect and store. However, no security system is impenetrable, and we cannot guarantee absolute security. We will notify you in case of a security breach affecting your information.
Additional Google Data Restrictions
If you grant the App access to your Google data, it will only use this data to provide email services and will not transfer it unless necessary, nor use it for ads. Human access to this data is restricted.
International Users
The THINNR Service is administered in the U.S. and intended for U.S. users. By using the service, you consent to the transfer and processing of your information in the U.S.
Third-Party Privacy Practices
We are not responsible for the privacy practices of third-party websites linked from the THINNR Services. Review their privacy policies to understand their data collection and use practices.
Children's Privacy
We do not knowingly collect information from children under 13. If we become aware of such collection, we will delete the information promptly.
California Privacy Rights
California residents can request information about our sharing of Personal Information with third parties for direct marketing purposes once per year. To request this information, email support@thinnrweightloss.com.
Changes to Privacy Policy
We may update this policy at any time. The revised policy will be effective upon posting. For material changes, we will notify you on our website and possibly via email. Review this policy periodically for updates.
THINNR HIPAA Compliance Statement
SlimCell, LLC (THINNR) is dedicated to and has implemented numerous safeguards to ensure its devices, services, websites, and data systems (collectively "Products") comply with the regulations and conditions outlined in the Health Insurance Portability and Accountability Act of 1996 (HIPAA). This Statement is not a substitute for a Business Associate Agreement, which must be signed upon becoming a client of THINNR.THINNR is committed to ongoing improvement to ensure its Products incorporate cutting-edge information technology privacy and security measures. We are dedicated to keeping all Protected Health Information (PHI) entrusted to us private and secure. We have established policies and procedures to maintain the confidentiality of this data.As a "Business Associate" as defined by HIPAA, and by assignment of the HIPAA covered entity, THINNR is subject to the following controls:Administrative Safeguards (HIPAA 164.308)
THINNR has implemented formal practices to ensure appropriate assignment of data access permissions and proper handling of that data. All THINNR staff are trained on HIPAA policies.Physical Safeguards (HIPAA 164.310)
THINNR and its data center are physically secure. Access to the building and offices is controlled via a private access code. All devices and computers in the office are secured with unique passwords for each staff member. THINNR's primary physical safeguard is to avoid retaining sensitive data in any public or private location other than those designated for database management.Technical Safeguards (HIPAA 164.312)
Our hosting server provider complies with the HIPAA Security Rule and the HITECH Act, having implemented the standards published by the OCR in the HIPAA Security Rule Crosswalk to the NIST Cybersecurity Framework. The server has been tested and certified by security professionals from Kaiser Permanente, Morgan Stanley, and various HIPAA-focused consulting groups. Our hosting server has passed multiple penetration tests conducted by independent firms on behalf of its customers, with frequent ongoing testing. The server is audited quarterly by independent security teams associated with its customers. Additionally, our hosting server conducts an annual risk assessment as required by HIPAA.The platform relies heavily on Amazon Web Services (AWS), utilizing its hardware and numerous services in a complex orchestration that ensures stability for you and 24/7 monitoring by us. This security leader in the Cloud infrastructure space is compliant with numerous certifications and audits, and your data is safeguarded by NIST standards and CIS benchmarks.We are committed to keeping all PHI and sensitive information secure and ensuring our systems and procedures are up to date and compliant with all related regulations. For further information, refer to our Privacy Policy or contact us at support@thinnrweightloss.com