Privacy Policy
1. Who we are
GoodLife Health is a Direct Primary Care telehealth platform operated by GoodLife Health LLC and an affiliated professional entity for the licensed practice of medicine in Arizona, California, and additional U.S. states (collectively, "GoodLife Health," "we," "us," or "our"). Our principal place of business is in Arizona.
This Privacy Policy describes how we collect, use, and share information when you visit goodlifehealth.ai, sign up for our services, or interact with our patient portal.
2. Information we collect
Information you provide directly
- Account information: name, email address, phone number, date of birth, mailing address, and state of residence.
- Identity verification: government-issued ID, photo, and verification data processed through Stripe Identity.
- Eligibility and intake information: answers you provide during your eligibility check and clinical intake, including weight, height, health goals, medical history, current medications, and lifestyle factors.
- Payment information: credit card or other payment information, processed and stored by Stripe (we do not store full payment card numbers on our systems).
- Communications: messages you send through the patient portal, support requests, and survey responses.
Information collected automatically
- Device and usage data: IP address, browser type, operating system, referring URL, pages visited, time spent on pages, and click patterns.
- Cookies and similar technologies: see Section 5.
- Analytics: we use privacy-respecting analytics tools to understand how visitors use our site in aggregate.
Information from third parties
- Affiliate partners: when you reach us through an affiliate or marketing partner, we may receive limited information about your referral source.
- Pharmacy partners: for clinical care, our partnered licensed pharmacy may share fulfillment and dispensing information with us.
3. How we use information
We use the information we collect to:
- Determine your eligibility for membership and clinical care
- Provide clinical services, including consultations, lab interpretation, prescriptions, and ongoing care management
- Process payments and manage your membership
- Communicate with you about your account, appointments, lab results, and clinical care
- Send transactional emails (account confirmations, billing receipts, appointment reminders)
- Send marketing communications about our services, where permitted by law and subject to your preferences
- Improve our platform, content, and patient experience
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations and respond to lawful requests
4. How we share information
We share information only as described in this section. We do not sell personal information.
Service providers and Business Associates
We share information with vendors that help us operate the platform. Where these vendors handle Protected Health Information, we sign HIPAA Business Associate Agreements ("BAAs") with them. Our key vendors include:
| Vendor | Purpose | BAA |
|---|---|---|
| Supabase | Patient data platform and audit log infrastructure | Yes |
| Vercel | Web application hosting | Yes |
| Elation Health | Electronic Health Record (legal chart of record) | Yes |
| Anthropic | AI infrastructure (de-identified data only) | Yes (Enterprise) |
| Stripe | Payment processing and identity verification | Yes |
| Twilio | SMS notifications | Yes |
| Licensed pharmacy | Prescription fulfillment | Yes |
| Customer.io | Marketing and lifecycle email (non-PHI only) | No (non-PHI architecture) |
Marketing partners
For marketing and lifecycle communications, we share only non-PHI marketing identifiers (such as email address, name, signup date, membership tier, and lifecycle stage) with Customer.io. Clinical information, lab results, and protocol data are never shared with marketing platforms.
Legal and safety
We may disclose information when required by law, in response to valid legal process, to protect our rights and safety, or to prevent fraud or harm. We will only disclose Protected Health Information as permitted by HIPAA.
Business transfers
If GoodLife Health is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will notify you and require any successor to honor this Privacy Policy or provide notice of changes.
5. Cookies and tracking technologies
We use cookies and similar technologies to operate our site, remember your preferences, and understand site usage. You can manage cookies through your browser settings. Disabling some cookies may limit functionality.
We do not use third-party advertising cookies that track you across unaffiliated sites. We do not participate in cross-site behavioral advertising.
6. Data retention
We retain personal information for as long as needed to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. Medical records are retained in accordance with state and federal law, typically a minimum of seven years from the date of last treatment, and longer for minors. Marketing information is retained until you opt out or request deletion.
7. Your rights and choices
- Access and correction: you may access and update your account information through the patient portal.
- Marketing opt-out: you may unsubscribe from marketing emails using the unsubscribe link in any email. Transactional and clinical communications cannot be opted out of while you remain a member.
- Account deletion: you may request deletion of your account. Medical records may be retained as required by law.
- HIPAA rights: for rights related to Protected Health Information, including access, amendment, accounting of disclosures, and restrictions, see our HIPAA Notice of Privacy Practices.
8. California residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect, the right to request deletion, the right to correct, and the right to opt out of sale or sharing of personal information. We do not sell personal information.
To exercise your CCPA rights, contact us at info@goodlifehealth.ai. We will verify your identity before responding.
Note: medical information governed by HIPAA and California's Confidentiality of Medical Information Act (CMIA) is excluded from CCPA in most cases.
9. Children
GoodLife Health services are for adults aged 18 and older. We do not knowingly collect personal information from children under 18. If we learn we have collected information from a child under 18, we will delete it.
10. Security
We implement administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, access controls, audit logging, and regular security reviews. No system is perfectly secure; we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.
11. International users
GoodLife Health services are intended for users located in the United States. If you access our site from outside the U.S., your information will be transferred to and processed in the United States.
12. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the patient portal or by email at least 30 days before they take effect. The "Last Updated" date at the top reflects the most recent version.
13. Contact us
Questions about this Privacy Policy:
GoodLife Health
Email: info@goodlifehealth.ai
Attn: Privacy Officer