Privacy Policy
NorthTrac (“NorthTrac,” “we,” “us,” or “our”) provides a member management and wellness platform that helps physicians, nurses, dietitians, wellness coaches, work-site wellness programs, labs, gyms, and other wellness professionals (“Customers”) capture, plan, and measure the progress of the people they serve (“Clients” or “Members”). This Privacy Policy explains what information we collect, how we use and share it, how we protect it, and the choices and rights you have. It applies to www.northtrac.com, the NorthTrac portals, the NorthTrac mobile apps, our telehealth and video features, and any other service that links to this policy (together, the “Services”).
The short version: we do not sell your personal information, we do not use health information for advertising, the wellness professional you work with controls the health records they keep about you, and we protect that information under HIPAA when it applies.
1. Our role: Customer data vs. NorthTrac data
NorthTrac handles information in two different roles, and your rights depend on which one applies.
- Customer Data. When a Customer uses NorthTrac to manage its Clients, the information the Customer or its Clients enter into the Customer’s account (for example, profiles, assessments, biometrics, coaching notes, messages, food photos, appointments, and survey results) belongs to and is controlled by that Customer. We process Customer Data only on the Customer’s behalf and under our agreement with them, acting as a “service provider,” “processor,” or, where HIPAA applies, a “business associate.” The Customer’s own privacy notice governs how it uses your information. If you are a Client, please contact the wellness professional or organization you work with to access, correct, or delete Customer Data; we will help them respond.
- NorthTrac Data. We are responsible for information we collect for our own purposes, such as visits to www.northtrac.com, sales and support inquiries, Customer account and billing contacts, and usage data we use to secure and improve the Services. This policy fully governs that information.
2. Information we collect
Information you give us
- Account and contact information: name, email address, phone number, organization, job title, username, and password.
- Profile and wellness information entered by you or your wellness professional: date of birth, gender, height, weight, biometric screening results, health risk assessments, goals, activity, nutrition logs and food photos, coaching notes, and survey or quiz answers.
- Communications and content: messages, group posts, comments, files, and the content of support requests.
- Telehealth and video sessions: information needed to set up and connect a session. We do not record sessions unless the Customer turns on a recording feature and the required notices and consents are given.
- Payment information: when you pay through NorthTrac, card details go directly to our payment processor. We receive only limited details such as the card type, last four digits, and billing ZIP code, never the full card number.
- Event and scheduling information: appointment times, locations, attendance, and registration details.
Information collected automatically
- Device and log data: IP address, browser and device type, operating system, app version, pages viewed, referring URLs, dates and times of access, and crash and error reports.
- Cookies and similar technologies: see Cookies and analytics.
- Approximate location inferred from your IP address. We do not collect precise GPS location unless you choose to allow it for a specific feature.
Information from others
- From Customers, such as when your employer, gym, or provider invites you or imports your records.
- From connected devices and apps you choose to link, such as Apple Health (see Apple HealthKit).
- From service providers such as payment processors and lab or screening partners, as directed by a Customer.
3. How we use information
We use information to:
- Provide, operate, maintain, and support the Services, including scheduling, coaching, messaging, telehealth, surveys, challenges, and insights;
- Create and secure accounts, verify identity, and prevent fraud, abuse, and security incidents;
- Process payments and send receipts, service notices, and account messages;
- Respond to questions and support requests;
- Understand how the Services are used so we can fix problems and improve them, using de-identified or aggregated data where we can;
- Send NorthTrac product news and marketing to business contacts, which you can opt out of at any time; and
- Comply with law, enforce our Terms of Service, and protect the rights, safety, and property of our users, Customers, and NorthTrac.
We use Customer Data only to provide the Services to that Customer, as the Customer instructs, and as our agreement with them and applicable law allow. We do not use Customer Data or health information to target advertising, and we do not use it to train artificial intelligence models for anyone other than the Customer it belongs to without that Customer’s permission.
4. How we share information
We do not sell personal information, and we do not “share” it for cross-context behavioral advertising. We disclose information only as follows:
- With the Customer you work with. Information you enter into a Customer’s program is available to that Customer and the staff it authorizes.
- With people you choose. For example, when you post in a group, join a challenge, or message a coach.
- With service providers that host, secure, and support the Services for us, such as cloud hosting (Microsoft Azure, in the United States), email and text message delivery, video conferencing, payment processing, analytics, and customer support tools. They may use information only to perform services for us, must protect it, and sign business associate agreements where HIPAA requires.
- For legal reasons, when we believe in good faith that disclosure is required by law, subpoena, or court order, or is needed to protect someone’s safety, investigate fraud or security issues, or enforce our agreements. Where the law allows, we will tell the affected Customer before disclosing Customer Data so it can seek a protective order.
- In a business transfer, such as a merger, acquisition, financing, or sale of assets, subject to confidentiality obligations and this policy.
- In de-identified or aggregated form that cannot reasonably be used to identify you. We will not try to re-identify such data.
- With your consent or at your direction.
5. Health information and HIPAA
Many NorthTrac Customers are “covered entities” under the Health Insurance Portability and Accountability Act (HIPAA). When we receive, store, or transmit protected health information (PHI) for a covered entity, we act as its business associate under a Business Associate Agreement (BAA). We use and disclose PHI only as the BAA and HIPAA permit, apply administrative, physical, and technical safeguards, and report breaches to the Customer as required. Customers must sign our BAA before entering PHI into NorthTrac.
Not every wellness program is covered by HIPAA (for example, some gyms, coaches, and employer programs). Even when HIPAA does not apply, we treat health and wellness information as sensitive: we limit access to people who need it, never sell it, never use it for advertising, and follow the consumer health data laws that apply, such as Washington’s My Health My Data Act and Nevada’s consumer health data law.
Employer wellness programs: if your employer sponsors your NorthTrac program, your employer generally receives only aggregated or de-identified reports unless you agree otherwise or the program terms say differently. Ask your program administrator for details.
6. Apple HealthKit and device data
If you connect a NorthTrac app to Apple Health, we read only the data types you approve (such as step counts) to show your progress and share it with your wellness professional. Consistent with Apple’s rules, we do not use HealthKit data for advertising or data mining, do not sell it or give it to advertisers or data brokers, and do not store it in iCloud. You can turn off access at any time in the Health app or your device settings.
7. Cookies and analytics
We use cookies and similar technologies that are needed to sign you in and keep the Services secure, to remember your preferences, and to understand how our website is used. Our public marketing website uses Google Analytics; you can learn how Google uses this data at policies.google.com/technologies/partner-sites and opt out with the Google Analytics opt-out browser add-on. We do not place advertising pixels or third-party tracking on pages inside signed-in portals where health information is displayed.
You can block or delete cookies in your browser settings, though some features may not work without them. We honor Global Privacy Control (GPC) signals as a request to opt out of any sale or sharing of personal information, where the law recognizes them.
8. Emails, texts, and notifications
We and our Customers send service messages such as appointment reminders, password resets, and security alerts. You can unsubscribe from marketing emails using the link in each email. If you receive text messages, reply STOP to opt out or HELP for help; message and data rates may apply. We do not share mobile phone numbers or text messaging consent with third parties for their marketing. You can manage push notifications in your device settings.
9. How we protect information
We use safeguards designed to protect information, including encryption in transit (TLS) and at rest, access controls based on the principle of least privilege, logging and monitoring, staff confidentiality obligations and training, and hosting in secure U.S. data centers. No system is perfectly secure, so we cannot guarantee absolute security. Please use a strong, unique password and tell us right away at [email protected] if you think your account has been compromised. If a breach affects your information, we will notify the affected Customers and, where required, you and regulators, as the law requires.
10. How long we keep information
We keep NorthTrac Data for as long as needed for the purposes described in this policy, such as keeping your account open, meeting legal, tax, and accounting duties, resolving disputes, and enforcing agreements. We keep Customer Data for as long as the Customer’s agreement requires and then delete or return it according to that agreement, except where the law requires us to keep it longer. Backups are overwritten on a regular cycle.
11. Your choices and rights
Depending on where you live, you may have the right to:
- Know what personal information we have about you and get a copy in a portable format;
- Correct information that is inaccurate;
- Delete your personal information;
- Opt out of the sale or sharing of personal information, targeted advertising, and profiling (we do not do these things);
- Limit the use of sensitive personal information (we already use it only to provide the Services); and
- Appeal our decision about your request.
To make a request about NorthTrac Data, email [email protected] with the subject line “Privacy Request.” We will verify your identity before acting, usually by confirming information linked to your account, and respond within the time the law requires. You may use an authorized agent, who must provide proof of permission. If we deny your request, you may appeal by replying to our decision; if you are not satisfied with the appeal, you may contact your state attorney general. We will not discriminate against you for using your privacy rights.
For Customer Data, we will send your request to the Customer that controls it and help them respond. HIPAA also gives patients of covered entities rights to access and amend their health records, which you exercise through your provider.
12. Additional U.S. state privacy disclosures
This section supplements the policy for residents of California and other states with comprehensive privacy laws. In the past 12 months we have collected these categories of personal information for the business purposes in Section 3: identifiers; customer records; commercial information (purchases); internet and network activity; approximate geolocation; audio or video only if a Customer enables session recording; professional information for business contacts; and sensitive personal information (account log-in credentials and health information). We disclose these categories to the recipients listed in Section 4 for business purposes only. We have not sold or shared personal information, and we have no actual knowledge of selling or sharing personal information of consumers under 16. Information governed by HIPAA is exempt from many state privacy laws and is protected under HIPAA instead.
13. International users
NorthTrac is operated in and hosted in the United States and is intended for use in the United States. If you use the Services from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country. Customers outside the United States are responsible for making sure their use of NorthTrac meets their local requirements.
14. Children
The Services are intended for adults 18 and older and are not directed to children. We do not knowingly collect personal information from children under 13. If a Customer serves minors, it is responsible for getting the consent of a parent or guardian and complying with applicable law. If you believe a child has given us personal information without the proper consent, contact us and we will delete it.
15. Third-party sites and services
The Services may link to or integrate with websites and services we do not control, such as social networks, payment providers, and device platforms. Their privacy practices are governed by their own policies, and we encourage you to read them.
16. Changes to this policy
We may update this policy from time to time. We will post the new version here and change the “Last updated” date. If we make material changes, we will give notice by email, in the Services, or on this page before the changes take effect. We will not use previously collected personal information in a materially different way without your consent where the law requires it.
17. Contact us
Questions or requests about this Privacy Policy or our privacy practices can be sent to:
NorthTrac Privacy · [email protected]