Midlife Medicine
Privacy Policy
Midlife Medicine SMS Privacy Policy & Terms of Service
Midlife Medicine
Privacy Policy
1. Information We Collect
Website analytics information
- Device type, browser, operating system, screen size, viewport size, and scroll depth.
- Button clicks, appointment or booking link clicks, phone clicks, email clicks, map clicks, outbound link clicks, file downloads, form starts, form submissions, page views, session starts, and engagement time.
- Hashed IP address.
- Approximate location derived from proxy or hosting headers, if available. We do not use this code path to store precise GPS coordinates.
- Consent status or advertising consent status when supplied by a consent mechanism or browser-side setting.
The website uses local storage and session storage for first-party analytics identifiers, including anonymous visitor and session identifiers, stored tracking-link IDs, and stored advertising click IDs when they are present. The portal also uses a session cookie to keep authorized users signed in.
Portal and administrator account information
If you are authorized to access a Midlife Medicine dashboard or portal, we may collect account and security information such as email address, phone number, administrator status, active/inactive status, login time, passkey registration details, login tokens or code hashes, session status, access events, hashed IP address, user agent, and recent account activity.
Lead, advertising, and business analytics information
We may receive or process lead and marketing information from website forms, Google lead forms, Meta lead ads, tracking links, newsletter links, and other marketing or analytics sources when those services are configured. This information may include lead IDs, campaign IDs, ad IDs, form IDs, campaign names, submitted fields, timestamps, source, medium, campaign, and related attribution metadata.
Third-party links and embedded resources
Our website links to or may load resources from third parties, including Practice Better, Spruce Health, Google Maps, OpenStreetMap, Leaflet/unpkg, Instagram, Facebook, YouTube, Menopause Society and other resource sites. Your interaction with those third-party services is governed by their own privacy policies and terms.
2. How We Use Information
We use information for the following purposes:
- To respond to inquiries and contact requests.
- To provide, coordinate, schedule, and administer services.
- To manage patient portal, booking, communication, and secure messaging workflows.
- To send requested mailing-list communications.
- To send SMS or text messages when you have opted in or when otherwise permitted.
- To route website form submissions to appropriate staff.
- To maintain records of website form submissions, leads, and communications.
- To understand how visitors use the website.
- To measure marketing, referral, campaign, and newsletter performance.
- To improve website content, navigation, user experience, and service offerings.
- To prevent spam, abuse, fraud, unauthorized access, and security incidents.
- To authenticate portal users and protect administrative access.
- To troubleshoot, audit, monitor, and maintain our systems.
- To comply with legal, regulatory, professional, contractual, or insurance obligations.
- To enforce our agreements and protect our rights, patients, users, staff, and systems.
We do not intentionally use website analytics events to collect the content of sensitive medical details. However, because our website concerns health-related services, pages visited, form topics, messages, URLs, referrers, and related metadata may reveal health-related interests. Please use the patient portal or other secure clinical channels for sensitive health information.
3. How We Share Information
We do not sell personal information. We do not sell, rent, or share mobile opt-in data or SMS consent information with third parties for their own marketing purposes.
We may disclose information to:
- Service providers and vendors that help us operate the website, portal, communications, scheduling, hosting, analytics, email delivery, SMS delivery, forms, lead routing, spreadsheets, security, and related business systems.
- Practice Better, when you use patient portal, booking, scheduling, intake, or related patient workflows.
- Spruce Health, when used for SMS, phone, fax, secure messaging, email-related communication, or communication workflow support.
- Email and SMTP providers used to send form notifications, login links, login codes, and communication alerts.
- Google services, such as Google Sheets or Apps Script, when used to log website form submissions, and Google lead form or advertising tools when configured.
- Meta/Facebook services, when Meta lead ads, Facebook/Instagram tools, or related lead/ad workflows are configured.
- Marketing, analytics, search, advertising, local presence, newsletter, or reporting tools when configured for Midlife Medicine.
- Legal, regulatory, compliance, professional, security, or law enforcement recipients when required or appropriate.
- Successors or assigns in connection with a merger, acquisition, reorganization, sale of assets, or similar business transaction, subject to appropriate protections.
We may also disclose aggregated, de-identified, or statistical information that does not reasonably identify you.
4. SMS Text Messaging Privacy
If you opt in to receive SMS text messages from Midlife Medicine, we may use your mobile phone number, messaging consent, opt-in records, and messaging information to provide the SMS messaging services you requested or agreed to receive.
No mobile opt-in data or text messaging consent information will be shared, sold, rented, or disclosed to third parties, except as needed to deliver the messaging service, support our communications, protect our rights or users, or comply with applicable law.
Message and data rates may apply. Message frequency varies. You may text STOP to opt out of SMS messages. You may text HELP for help. Carriers are not liable for delayed or undelivered messages.
My SMS platform provider, Spruce Health, supplied me with model verbiage to use in conjunction with my standard agreement paperwork in order to collect opt-in consent for SMS texting which can be reviewed below in the "SMS Text Messaging Terms of Service" and "SMS Text Messaging Privacy Policy." When I submitted my registration, I indicated that I had incorporated that language, or substantially similar language, into my standard agreements; therefore, the SMS platform provider has submitted this attestation, on my behalf: Our standard terms of service and privacy policy describe our SMS text messaging program. Users receive SMS messages only after providing separate, affirmative consent to opt in, as described in "Details of How My Organization (Midlife Medicine) Obtains SMS Opt-In."
Additional Information More information about Midlife Medicine's SMS communications and privacy practices is available at:
|
5. Cookies, Local Storage, and Similar Technologies
Our website and portal may use cookies, local storage, session storage, pixels, tags, or similar technologies.
The public website currently uses first-party browser storage for analytics identifiers and campaign attribution. These identifiers help us understand return visits, sessions, campaign performance, and form attribution. The portal uses a session cookie to support authenticated access. If additional analytics, advertising, or security tools are enabled, those tools may use similar technologies according to their own privacy terms.
You can control cookies and site storage through your browser settings. Blocking cookies or storage may affect analytics and may also prevent certain portal or login features from working correctly. If a consent mechanism is presented and you deny analytics consent, our website tracking script is designed to respect that denial.
6. Security
We use administrative, technical, and organizational safeguards designed to protect information. Current safeguards in the reviewed code include HTTPS, portal session controls, access logging with hashed IP addresses, password hashing or token hashing where applicable, encrypted API credential storage, passkey support, rate limits for certain public endpoints, form origin checks, webhook signature or key checks, and restricted production documentation endpoints.
No website, portal, email system, SMS system, or internet transmission is completely secure. Please use the patient portal or designated secure communication channel for sensitive medical information.
7. Data Retention
We retain information for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law, professional obligations, contractual obligations, accounting requirements, security needs, or dispute resolution.
Website analytics and attribution records may be retained for business reporting and performance measurement. The reviewed company model includes a default analytics retention setting of 730 days, although actual retention may vary based on configuration, legal needs, backups, and operational requirements.
Clinical, billing, patient portal, and protected health information records may be retained under separate health care, legal, professional, and HIPAA-related retention requirements.
8. Your Choices
You may:
- Choose not to submit a website form.
- Use the patient portal or secure communication channel for sensitive clinical information.
- Contact us to update or correct contact information.
- Unsubscribe from marketing or mailing-list emails where an unsubscribe option is provided, or contact us directly.
- Opt out of SMS messages by texting STOP.
- Request help with SMS messages by texting HELP.
- Use browser settings to delete or block cookies, local storage, and session storage.
- Avoid clicking tracking links or advertising links if you do not want campaign identifiers included in the destination URL.
Depending on applicable law and the nature of the information, you may have rights to request access, correction, deletion, restriction, or a copy of certain information. Some requests may be limited by legal, medical record, security, accounting, or operational obligations.
9. Health Information and HIPAA
Midlife Medicine provides health-related services. Certain information may be protected health information under HIPAA or other health privacy laws when it is created, received, maintained, or transmitted by Midlife Medicine in its role as a health care provider.
This Privacy Policy describes website, portal, communications, marketing, and operational privacy practices. It does not fully describe all uses and disclosures of protected health information. For protected health information, please refer to Midlife Medicine's HIPAA Notice of Privacy Practices, if applicable, or contact us for more information.
10. Children's Privacy
Our website and services are not directed to children under 13, and we do not knowingly collect personal information from children under 13 through the public website. If you believe a child has provided information through the public website, please contact us.
11. Third-Party Websites and Services
Our website may link to third-party websites, portals, maps, social media pages, video platforms, professional resources, booking tools, payment or scheduling tools, and communication platforms. We are not responsible for the privacy practices of third-party services. Please review their privacy policies and terms before providing information to them.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be identified by its effective date or last updated date. Your continued use of the website or related services after an update means the updated Privacy Policy applies to information collected after the update, to the extent permitted by law.
13. Contact Us
Midlife Medicine
766 Walker Road, Suite A
Great Falls, VA 22066
Phone/Text: (571) 546-3461
Email: hello@midlifemedicine.com
For clinical or patient-specific matters, please use the patient portal or the secure communication channel we have directed you to use.
