Privacy policy
Eir Services Group, LLC d/b/a Timber Health
Effective date: October 02, 2026 | Last Updated: October 02, 2026 | Version 1.3
1. Introduction and Scope
1. Eir Services Group, LLC d/b/a Timber Health ("Timber Health," "we," "us," or "our") owns, operates, or makes available the websites, mobile interfaces, portals, account tools, communications channels, intake flows, coaching resources, care-coordination services, customer-support services, payment workflows, and related online or offline services that link to this Privacy Policy (collectively, the "Services"). https://timberhealth.co and any successor or affiliated websites or applications are referred to in this Privacy Policy as the "Platform."
2. This Privacy Policy applies to information we collect or process about individuals who access or use the Services, create an account, complete an intake questionnaire, request care coordination, communicate with Timber Health or a care team, purchase or subscribe to products or services, receive coaching or administrative support, visit the Platform, interact with our marketing, or otherwise provide information to us.
3. Capitalized terms not defined in this Privacy Policy have the meanings assigned to them in the Timber Health Terms of Service. This Privacy Policy is incorporated into and forms part of the Terms of Service. By accessing or using the Services, you acknowledge the collection, use, disclosure, retention, and protection practices described in this Privacy Policy. If you do not agree with this Privacy Policy, do not use the Services.
4. If you use the Services on behalf of another individual, you represent that you are authorized to act for that individual and to provide information about that individual, and that the individual has been provided an opportunity to review this Privacy Policy and any applicable consent, authorization, or Notice of Privacy Practices.
This Privacy Policy does not replace any separate Notice of Privacy Practices or privacy notice provided by a Medical Group, Provider, Pharmacy, Laboratory, or other third party. Those parties may have separate legal duties and privacy practices with respect to information they collect or maintain. The Notice of Privacy Practices issued by the independent medical practices in the Arora Health network for the care they provide through the Platform is hosted by Timber Health on their behalf, under its own title, at https://timberhealth.co/hipaa-notice and is linked in the website footer as "Notice of Privacy Practices."
2. Our Role; Independent Providers, Pharmacies, Laboratories, and Vendors
6. Timber Health provides non-clinical technology, care-coordination, administrative, customer-support, coaching, educational, payment, and related services intended to assist eligible users in accessing independent licensed medical providers, pharmacies, laboratories, and other third-party services. Timber Health does not practice medicine, nursing, pharmacy, or any other licensed profession, and does not dispense, compound, prescribe, order, or administer drugs, hormones, peptides, laboratory tests, or other medical products.
7. Medical evaluation, diagnosis, laboratory orders, treatment recommendations, prescribing decisions, dosage decisions, monitoring requirements, adverse-event instructions, and clinical follow-up are provided solely by independent licensed providers and professional entities (collectively, "Medical Groups" and "Providers"), including the independent licensed clinicians in the Arora Health network. Prescription dispensing, compounding, packaging, labeling, counseling, transfer, substitution, and fulfillment are provided solely by independent licensed pharmacies, compounding pharmacies, outsourcing facilities, and pharmacy-related vendors (collectively, "Pharmacies"), including The Pharmacy Hub, a licensed pharmacy located in Miami, Florida. Specimen collection, laboratory analysis, reporting, and related diagnostic services are provided solely by independent laboratories and diagnostic vendors (collectively, "Laboratories").
8. To facilitate the Services, we may collect, receive, store, transmit, and otherwise process information on our own behalf and, in certain circumstances, on behalf of Medical Groups, Providers, Pharmacies, Laboratories, payment processors, identity-verification vendors, fulfillment vendors, telehealth vendors, customer-support vendors, and other service providers. Our role may vary by program, state, vendor relationship, and applicable law.
3. Eligibility and Minors
9. The Services are intended for individuals located in jurisdictions where the Services are available and who are at least eighteen (18) years old, or such older age as may be required by applicable law or by the particular program, product, or service. Certain hormone, testosterone, peptide, prescription, or laboratory programs may be subject to additional age, identity-verification, clinical, and state-law restrictions.
10. The Services are not directed to children under thirteen (13), and Timber Health does not knowingly collect personal information from children under thirteen (13). The Services are not intended for minors under eighteen (18) unless Timber Health expressly offers a specific service for minors and the minor has any legally required consent of a parent, guardian, or other authorized person.
11. If you believe a child or minor has provided information to us without appropriate authorization, please contact us using the information in the "Contact Us" section. We will take reasonable steps to delete or restrict such information where required by law, subject to legal, medical-record, safety, fraud-prevention, and contractual retention obligations.
4. Protected Information, HIPAA, Medical Information, and Consumer Health Data
General Distinction Between Account Data and Regulated Health Information
12. When you create an account or interact with Timber Health as a customer, you may provide information such as your name, email address, phone number, billing address, shipping address, account credentials, payment information, device information, and certain transaction information. We generally treat this information as personal information subject to this Privacy Policy. It may not be protected health information under HIPAA simply because it is associated with a health-related service.
13. When you use certain components of the Services, you may also provide, generate, or authorize access to health, medical, prescription, laboratory, biometric, genetic, sexual health, reproductive health, hormone-related, controlled-substance-related, or other sensitive information. Depending on the context, this information may be protected by HIPAA, state medical-privacy laws, consumer health data laws, genetic-privacy laws, biometric-privacy laws, reproductive-health privacy rules, or other federal or state requirements.
HIPAA and Protected Information
(a) Timber Health is not a medical group, healthcare provider, pharmacy, health plan, health insurer, or healthcare clearinghouse, and it is not a covered entity under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended ("HIPAA"). The independent medical practices in the Arora Health network, The Pharmacy Hub, and the Laboratories involved in your care are covered entities under HIPAA for the records they maintain. Timber Health operates the platform and provides non-clinical administrative and support services to the Arora Health medical practices as their business associate under a written business associate agreement, and it handles protected health information ("PHI") received or maintained in that capacity only as that agreement and HIPAA permit. Information you provide before a provider-patient relationship is formed — for example, responses on our website, pre-intake screening answers, and website usage information — is generally not PHI; it is protected instead by the FTC Health Breach Notification Rule, state consumer-health-data laws, and this Privacy Policy.
For purposes of this Privacy Policy, "Protected Information" means PHI when HIPAA applies, and other health, medical, genetic, biometric, reproductive, sexual health, consumer health data, or sensitive information that is subject to specific legal protections under applicable law. Protected Information does not include information that has been de-identified in accordance with applicable law.
(c) To the extent Timber Health receives or maintains PHI as a business associate, Timber Health will use and disclose that PHI only as permitted by the applicable business associate agreement, HIPAA, and other applicable law. To the extent Timber Health processes personal information that is not Protected Information, Timber Health may use and disclose that information as described in this Privacy Policy.
(d) Medical Groups, Providers, Pharmacies, and Laboratories may provide separate Notices of Privacy Practices or privacy notices that describe their uses and disclosures of Protected Information. The Notice of Privacy Practices of the independent medical practices in the Arora Health network is posted at https://timberhealth.co/hipaa-notice Timber Health hosts it on their behalf and, because it is not a covered entity, issues no notice of privacy practices of its own. The Pharmacy Hub and the Laboratories maintain their own notices for the records they hold. By accessing or using the Services, you acknowledge that your information may be subject to those separate notices and that you should review them carefully.
Consumer Health Data
(e) Certain state laws regulate "consumer health data" or similar categories of health-related personal information, including information that identifies, relates to, describes, or is reasonably capable of being associated with a consumer and that identifies the consumer's past, present, or future physical or mental health status, health condition, treatment, diagnosis, medication, biometric data, reproductive or sexual health, gender-affirming care, precise location information that could indicate health-care activity, or other health-related information.
(f) Because Timber Health provides health-related care coordination, coaching, and technology services, information collected through the Services may be consumer health data even when it is not HIPAA-regulated PHI. Section 11 of this Privacy Policy is intended to provide additional consumer health data disclosures where applicable. Timber Health also maintains a standalone Consumer Health Data Privacy Policy, linked in the website footer and available at https://timberhealth.co, which provides the consumer-health-data disclosures required by applicable state law. In the event of any conflict between this Privacy Policy and the Consumer Health Data Privacy Policy with respect to consumer health data, the Consumer Health Data Privacy Policy controls.
5. Categories of Personal Information We Collect
14. The categories of personal information we collect depend on how you interact with us, the Services you use, the choices you make, and the requirements of independent Providers, Pharmacies, Laboratories, and other third parties involved in the Services. We may collect the categories described below.
| Category | Examples |
|---|---|
| Communications and content | Emails, chat messages, text messages, call recordings or transcripts where permitted, support tickets, survey responses, reviews, testimonials, uploaded files, photographs, videos, and other content you provide. |
| Internet, device, and usage information | IP address, browser type, operating system, device type, device identifiers, mobile advertising IDs, referring and exit pages, pages viewed, links clicked, session duration, event logs, error logs, cookie IDs, SDK information, and other usage data. |
| Location information | Approximate location derived from IP address, state certifications, shipping address, billing address, and precise geolocation if you enable location-based features or otherwise provide it. |
| Inferences and preferences | Information inferred from your interactions with the Services, such as likely interests, program preferences, product interests, communication preferences, risk flags, or user segments. |
| Professional, employment, or applicant information | Information you provide if you apply for a job, vendor relationship, contractor role, or business relationship with Timber Health. |
Information You Provide Directly
15. We collect information you provide directly when you create an account, complete an intake questionnaire, request services, verify your identity, make a purchase, subscribe to a plan, communicate with a care team, upload content, request customer support, participate in surveys, submit reviews, apply for employment, or otherwise interact with us.
Information Collected Automatically
16. When you access the Platform or interact with our online services, emails, ads, or messages, we and our vendors may automatically collect device, usage, location, and analytics information through cookies, pixels, web beacons, SDKs, mobile IDs, server logs, and similar technologies. In some circumstances, usage data may reveal or infer health-related interests, such as viewing pages about hormone therapy, testosterone, peptides, medication programs, symptoms, sexual health, or laboratory testing.
Information From Third Parties
17. We may receive information from Medical Groups, Providers, Pharmacies, Laboratories, payment processors, identity-verification vendors, shipping and fulfillment vendors, customer-support vendors, advertising and analytics partners, social media platforms, referral partners, data-enrichment providers, public sources, and other third parties, as permitted by law and applicable agreements.
6. Sources of Personal Information
18. We collect personal information from the following sources:
(a) You, including when you provide information through the Platform, intake flows, forms, messages, uploads, calls, emails, SMS messages, surveys, or support requests.
(b) Your devices and browsers, including through cookies, server logs, web beacons, pixels, SDKs, mobile IDs, and similar technologies.
(c) Medical Groups, Providers, Pharmacies, Laboratories, and other healthcare or pharmacy-related third parties involved in the Services.
(d) Service providers and vendors, including payment processors, identity-verification vendors, fraud-prevention vendors, shipping vendors, hosting providers, security vendors, customer-support platforms, analytics providers, and communications vendors.
(e) Advertising, marketing, referral, and social media partners, where permitted by law and your choices.
(f) Publicly available sources and third-party data sources, where permitted by law.
(g) Information we generate or infer from other information, including user preferences, account status, fraud-risk signals, eligibility-routing information, and service analytics.
7. Cookies, Pixels, Mobile IDs, SDKs, and Similar Technologies
19. We and our vendors may use cookies, web beacons, pixels, SDKs, mobile analytics tools, advertising IDs, server logs, local storage, and similar technologies to operate the Services, authenticate users, maintain preferences, secure accounts, detect fraud, analyze performance, understand user behavior, improve the Services, deliver or measure advertising, and personalize content.
20. Cookies are small text files stored on your browser or device. Web beacons and pixels are small electronic files that allow us or third parties to understand whether a page, email, advertisement, or message has been viewed or acted upon. SDKs are code components in mobile or online services that may enable analytics, communications, advertising, crash reporting, and similar functions.
21. We may use strictly necessary technologies, preference and functionality technologies, analytics and performance technologies, security technologies, and advertising or measurement technologies. Some technologies may collect information about your interactions with health-related pages or programs, which may be considered sensitive personal information or consumer health data under certain laws.
22. Your choices may include browser cookie controls, mobile-device settings, advertising ID controls, unsubscribe links, the "Cookie Preferences" link in the footer of every page, Global Privacy Control (GPC), the "Do Not Sell or Share My Personal Information" page linked beside it, and other opt-out tools described in this Privacy Policy. If you disable certain technologies, some features of the Services may not function properly.
Global Privacy Control and Do Not Track
23. Where required by applicable law, we will make reasonable efforts to honor browser-based opt-out preference signals such as Global Privacy Control for opt-outs from sale, sharing, or targeted advertising. Because there is not a uniform legal or technical standard for browser "Do Not Track" signals, we do not respond to Do Not Track signals unless required by law.
8. How We Use Personal Information
24. Subject to the limitations described in the sections on Protected Information and Consumer Health Data, we may use personal information for the purposes described below.
| Purpose | Examples |
|---|---|
| Provide and coordinate Services | Create and administer accounts; operate the Platform; route intake information; facilitate telehealth access; coordinate Providers, Pharmacies, Laboratories, and vendors; process orders; manage subscriptions; arrange shipping; provide coaching and administrative support. |
| Provider, pharmacy, and lab coordination | Transmit information to and from Medical Groups, Providers, Pharmacies, Laboratories, and related vendors for evaluation, prescription fulfillment, compounding, dispensing, laboratory testing, monitoring, refill management, adverse-event handling, and care coordination. |
| Identity, eligibility, and compliance | Verify identity and age; confirm state location or availability; support controlled-substance, testosterone, pharmacy, compounding, laboratory, fraud-prevention, sanctions, and legal-compliance workflows. |
| Payments and transactions | Process payments; collect amounts on behalf of third parties where applicable; manage subscriptions, cancellations, refunds, renewals, chargebacks, invoices, taxes, and accounting. |
| Customer support and communications | Respond to questions; send confirmations, reminders, service notices, support messages, refill reminders, account alerts, shipping updates, safety notices, surveys, and communications on behalf of Providers, Pharmacies, or Laboratories where applicable. |
| Safety, quality, and service improvement | Monitor service quality; troubleshoot; audit workflows; improve content, coaching, support, and technology; conduct analytics; maintain logs; train personnel; and evaluate performance. |
| Security and fraud prevention | Protect accounts, systems, and users; detect and prevent fraud, abuse, spam, credential stuffing, unauthorized access, diversion, prescription misuse, and other illegal or prohibited activity. |
| Marketing and advertising | Send promotional communications where permitted; measure campaigns; personalize offers; conduct non-PHI advertising and analytics; and honor opt-out and consent choices. We do not use Protected Information for advertising or marketing except as permitted by law and with any required authorization. |
| Legal and regulatory compliance | Comply with law; respond to legal process; maintain records; enforce agreements; defend legal claims; report adverse events, breaches, or safety issues where required; and cooperate with regulators or law enforcement where permitted or required. |
| Research and de-identified data | Create and use de-identified or aggregated information for analytics, research, product development, operations, safety, and business purposes, subject to applicable law and de-identification commitments. |
9. How We Disclose Personal Information
25. Subject to the limitations described in this Privacy Policy and applicable law, we may disclose personal information to the following categories of recipients.
| Recipient Category | Disclosure Purpose |
|---|---|
| Medical Groups and Providers | To facilitate evaluations, diagnosis, treatment, prescriptions, monitoring, refill decisions, adverse-event review, and other clinical services. |
| Pharmacies and pharmacy vendors | To facilitate prescription review, compounding, dispensing, labeling, counseling, shipping, transfers, substitutions where permitted, refill management, and pharmacy compliance. |
| Laboratories and diagnostic vendors | To facilitate laboratory orders, specimen collection, testing, reporting, and related diagnostic services. |
| Service providers and processors | Hosting, cloud storage, security, IT, customer support, call centers, communications, telehealth tools, EHR/EMR vendors, payment processors, identity verification, fraud prevention, analytics, legal, accounting, and other vendors working for us or at our direction. |
| Payment processors and financial institutions | To process payments, verify payment information, prevent fraud, manage chargebacks, issue refunds, and comply with payment-card rules. |
| Shipping, logistics, and fulfillment vendors | To package, ship, track, deliver, replace, or recall products or kits and provide shipment updates. |
| Advertising and analytics partners | To measure usage and campaigns, support advertising, personalize non-PHI marketing, and operate cookie or pixel technologies, subject to your choices and applicable law. |
| Affiliates and corporate entities | To operate shared services, manage common systems, conduct analytics, comply with law, and support corporate transactions, where permitted. |
| Business transaction parties | In connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, due diligence, or similar corporate transaction, subject to appropriate protections. |
| Legal, safety, and compliance recipients | Regulators, courts, law enforcement, auditors, insurers, legal counsel, compliance consultants, and other parties where disclosure is required or permitted by law or necessary to protect rights, safety, and security. |
| Third parties you authorize | Any person or entity you direct, authorize, or consent for us to disclose information to, including caregivers, family members, pharmacies of choice, or other providers. |
26. We may disclose de-identified, aggregated, or pseudonymized information as permitted by law. We may also disclose information to enforce our agreements, investigate potential violations, prevent harm, detect or prevent fraud, or protect the rights, property, or safety of Timber Health, users, Providers, Pharmacies, Laboratories, vendors, or the public.
10. Advertising, Analytics, Sale, Sharing, and Targeted Advertising
27. We may work with analytics and advertising partners to understand how users interact with the Platform, measure marketing campaigns, improve the Services, deliver relevant content, and advertise Timber Health programs or services. These partners may use cookies, pixels, device identifiers, IP addresses, hashed contact information, and other online identifiers.
28. Some privacy laws define "sale," "sharing," or "targeted advertising" broadly to include certain disclosures of online identifiers or usage data to advertising or analytics partners, even when no money is exchanged. Depending on the technologies used and applicable law, our use of cookies, pixels, or similar tools may be considered a sale, sharing, or processing for targeted advertising.
29. Timber Health does not sell Protected Information. Timber Health does not sell consumer health data unless permitted by applicable law and supported by any required written authorization or affirmative consent. Timber Health does not use PHI for advertising or marketing except as permitted by HIPAA and other applicable law and with any required authorization.
30. If we use advertising or analytics technologies on health-related pages, those technologies may collect sensitive information or consumer health data. We will provide consent, opt-out, or other controls where required by law. You may opt out of the sale or sharing of personal information and of targeted advertising at any time through the "Do Not Sell or Share My Personal Information" page, linked in the footer of every page beside "Cookie Preferences": in the Cookie Preferences center (for that browser or device), by enabling Global Privacy Control, which we recognize automatically, or by an account-level request, which we honor as soon as feasible and no later than fifteen (15) business days after we receive it. Users may also use applicable privacy controls, mobile advertising ID settings, and the contact methods described in this Privacy Policy.
11. Consumer Health Data Privacy Notice
31. This section is intended to provide additional disclosures for consumer health data laws where applicable, including laws that regulate consumer health data outside the scope of HIPAA. It applies only to information that qualifies as consumer health data under an applicable law and that Timber Health controls or processes in a manner subject to that law. This section supplements, and should be read together with, the standalone Timber Health Consumer Health Data Privacy Policy available at https://timberhealth.co.
Categories of Consumer Health Data We May Collect
(a) Information about health conditions, symptoms, diagnoses, medications, prescriptions, allergies, contraindications, medical history, treatment preferences, adverse events, and care plans.
(b) Information about testosterone replacement therapy, hormone therapy, peptides, weight, body composition, sexual health, reproductive health, fertility, gender, and related health characteristics where relevant to Services requested by the user.
(c) Laboratory orders, test results, biomarkers, hormone levels, metabolic markers, specimen information, and monitoring requirements.
(d) Information derived from communications with Providers, Pharmacies, Laboratories, care teams, coaches, customer support, or administrative personnel.
(e) Photographs, videos, device outputs, or other files submitted for identity verification, treatment support, injection coaching, progress tracking, or administrative support.
(f) Health-related browsing, search, clickstream, page-view, purchase, subscription, or program-interest information if it identifies or could reasonably be associated with a consumer and health condition, treatment, product, or service.
(g) Precise geolocation if enabled or provided and if it reveals or could reveal health-related activity.
(h) Inferences drawn from the above information, such as program eligibility, likely health interests, or service preferences.
Purposes for Collecting and Using Consumer Health Data
(i) To provide and coordinate the Services you request.
(j) To facilitate access to independent Providers, Pharmacies, Laboratories, and related vendors.
(k) To route information for clinical evaluation, laboratory orders, prescription fulfillment, compounding, dispensing, monitoring, refill review, and adverse-event support.
(l) To verify identity, age, location, eligibility, and compliance requirements.
(m) To provide customer support, coaching, reminders, education, account administration, and care-coordination communications.
(n) To process payments, subscriptions, cancellations, refunds, and service transactions.
(o) To protect safety, security, fraud-prevention, controlled-substance compliance, and legal compliance.
(p) To improve, audit, and troubleshoot the Services, and to create de-identified information as permitted by law.
(q) To conduct advertising or analytics only as permitted by applicable law, with any required consent, and subject to opt-out rights.
32. We may collect consumer health data from you, your devices, Medical Groups, Providers, Pharmacies, Laboratories, service providers, payment processors, identity-verification vendors, referral partners, and other third parties you authorize. We may disclose consumer health data to Medical Groups, Providers, Pharmacies, Laboratories, service providers, processors, payment processors, shipping vendors, security vendors, legal and compliance recipients, and other recipients as described in Sections 8 and 9, where permitted by law and subject to required consent or authorization.
Consumer Health Data Consents, Authorizations, and Restrictions
33. Where applicable law requires affirmative consent to collect, use, share, or sell consumer health data, we will request such consent or authorization in the manner required by law. We do not sell consumer health data unless permitted by applicable law and supported by any required written authorization. We do not use geofencing to identify, track, collect data from, or send notifications to consumers within or near health care facilities in a manner prohibited by applicable consumer health data laws.
Consumer Health Data Rights
34. Depending on your state of residence and applicable law, you may have rights to confirm whether we collect, share, or sell consumer health data about you; access such data; obtain a list of third parties or affiliates with whom we have shared or sold such data; withdraw consent; request deletion; and appeal a denial. To exercise these rights, contact us as described in the "Contact Us" section. We may need to verify your identity and may decline or limit requests where permitted by law, including where deletion would conflict with legal obligations, medical-record retention, fraud-prevention, safety, security, or compliance requirements.
12. De-Identified, Aggregated, and Pseudonymized Information
35. We may de-identify, aggregate, or pseudonymize information so that it cannot reasonably be used to identify you, as permitted by applicable law. We may use and disclose de-identified or aggregated information for analytics, research, product and service improvement, operational, safety, compliance, training, business, marketing, and other lawful purposes.
36. Where we maintain information in a de-identified form, we will maintain and use it in de-identified form and will not attempt to re-identify it except as permitted by law, such as to test whether the de-identification process is effective. De-identified information may not be subject to the same rights as identifiable personal information.
13. Artificial Intelligence and Automated Tools
37. Timber Health may use automated tools, algorithms, artificial intelligence, machine learning, or AI-supported systems to support non-clinical operations, such as customer support, account administration, intake routing, fraud detection, quality assurance, transcription, summarization, content organization, personalization, analytics, or workflow efficiency.
38. Timber Health does not use AI to practice medicine, make clinical decisions, prescribe medications, diagnose conditions, determine treatment, or replace the professional judgment of licensed Providers. Any clinical decision must be made by a licensed Provider or other authorized professional acting within the scope of applicable law.
39. Information processed through AI-supported tools may be stored or processed by vendors that provide those tools, subject to applicable agreements and privacy protections. Do not submit emergency information through the Services. For emergencies, call 911 or seek in-person emergency care immediately.
14. Communications, SMS, Calls, Email, and E-SIGN
By providing your contact information and using the Services, you consent to receive electronic communications from Timber Health and, where applicable, communications sent on behalf of Providers, Pharmacies, Laboratories, or vendors involved in the Services. Communications may include agreements, notices, disclosures, consents, confirmations, account notices, appointment reminders, refill reminders, laboratory reminders, shipping updates, safety notices, administrative messages, customer-support responses, and other information related to the Services.
If you opt in to receive SMS or MMS messages, you authorize Timber Health and its service providers to send recurring text messages to the phone number you provide. Message frequency may vary. Message and data rates may apply. You may opt out of promotional text messages by replying STOP or following instructions in the message. You may receive non-promotional or transactional messages even if you opt out of promotional communications, to the extent permitted by law. The Timber Health SMS & Messaging Terms, available at https://timberhealth.co/sms-terms and linked in the website footer, describe both text-message programs — care and account messages, and the optional marketing program — the STOP, HELP, and START replies, and the timing and frequency limits that apply to marketing texts; they should be read together with this Section.
If you provide a telephone number, you authorize Timber Health and its vendors to contact you by call or text for service-related purposes, including through automated technologies where permitted by law and your consent. We may record calls or retain transcripts for quality assurance, training, support, compliance, and recordkeeping where permitted by law.
You agree that electronic communications satisfy any legal requirement that communications be in writing. You are responsible for maintaining current contact information and monitoring communications sent through the Services, email, phone, text, or your account.
15. Payments, Transactions, and Fraud Prevention
40. When you make a purchase, subscribe to a plan, or otherwise conduct a transaction through the Services, we and our payment processors may collect and process payment information, billing information, transaction information, and fraud-prevention information. Payment information is processed by our designated payment processor, Stripe, Inc. ("Stripe"), and by the card networks and financial institutions involved in your transaction. Their privacy practices are governed by their own privacy policies.
41. Timber Health may collect payments on its own behalf and, where applicable, on behalf of Medical Groups, Providers, Pharmacies, Laboratories, or other third parties involved in the Services. We may disclose transaction information to payment processors, financial institutions, fraud-prevention vendors, professional entities, Pharmacies, Laboratories, accountants, auditors, legal counsel, and other parties as necessary to process payments, prevent fraud, manage chargebacks, comply with law, and provide the Services.
16. Data Retention and Medical Records
42. We retain personal information for as long as reasonably necessary to provide the Services, maintain your account, fulfill transactions, comply with legal and regulatory obligations, resolve disputes, enforce agreements, prevent fraud, maintain security, protect legal rights, and conduct legitimate business purposes. Retention periods vary depending on the type of information, sensitivity, purpose of collection, legal requirements, user expectations, and technical controls available.
43. Information maintained by or on behalf of Medical Groups, Providers, Pharmacies, and Laboratories may be subject to medical-record, pharmacy-record, laboratory-record, controlled-substance, tax, accounting, adverse-event, safety, or other legal retention requirements. Deletion requests may not result in deletion of information that must be retained by law or that is necessary for medical records, pharmacy records, fraud prevention, safety, or compliance.
44. When information is no longer needed, we may delete, anonymize, aggregate, or otherwise dispose of it in accordance with applicable law and our retention practices. Backups and archived copies may persist for a limited period before deletion or overwrite.
17. Security
45. We use reasonable administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, use, disclosure, alteration, and destruction. Safeguards may include access controls, encryption, logging, monitoring, secure transmission, vendor diligence, personnel training, incident-response procedures, and other measures appropriate to the sensitivity of the information.
46. No website, application, system, or method of transmission or storage is completely secure. We cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials, using strong passwords, keeping devices secure, and promptly notifying us if you suspect unauthorized access to your account or communications.
47. If we become aware of a breach or security incident involving personal information, Protected Information, or consumer health data, we will investigate and provide notices as required by applicable law, which may include state breach-notification laws, HIPAA where applicable, and the FTC Health Breach Notification Rule where applicable.
18. Your Choices and Privacy Rights
Account and Communication Choices
48. You may update certain account information through your account settings or by contacting us.
49. You may opt out of promotional emails by using the unsubscribe link or contacting us. We may still send service-related, legal, safety, billing, account, or transactional communications.
50. You may opt out of promotional text messages by replying STOP or following the instructions in the message. Service-related text messages may continue where permitted by law. See the SMS & Messaging Terms at https://timberhealth.co/sms-terms.
51. You may adjust cookie, device, and advertising settings through the "Cookie Preferences" link in the footer of every page, your browser and device settings, Global Privacy Control, or industry opt-out tools, and you may opt out of the sale or sharing of personal information and of targeted advertising through the "Do Not Sell or Share My Personal Information" page linked beside it.
52. You may choose not to provide certain information, but doing so may prevent you from using some or all Services, including services requiring identity verification, clinical intake, payment, shipping, or pharmacy fulfillment.
Privacy Rights Requests
53. Depending on where you reside and the laws that apply, you may have rights to request access to personal information, confirmation of processing, correction of inaccurate information, deletion, portability, restriction, opt-out of sale or sharing, opt-out of targeted advertising, opt-out of profiling in furtherance of decisions that produce legal or similarly significant effects, limit use or disclosure of sensitive personal information, withdraw consent, and appeal a denial of a privacy request.
54. To exercise a privacy right, contact us using the methods in the "Contact Us" section or use any privacy request mechanism we make available. We may verify your identity before responding. We may deny, limit, or delay requests where permitted by law, including where the request conflicts with legal obligations, medical-record retention, pharmacy-record retention, security, fraud prevention, safety, legal claims, or the rights of others. If we deny your request and applicable law provides an appeal right, you may appeal by replying to our decision or submitting an appeal to compliance@timberhealth.co with the subject line "Privacy Appeal."
Authorized Agents
55. Where permitted by law, you may designate an authorized agent to submit a privacy request on your behalf. We may require proof of authorization, verification of your identity, and confirmation that the agent is authorized to act for you.
19. California Notice at Collection and California Privacy Rights
56. This section applies to California residents where the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA"), applies. It supplements the rest of this Privacy Policy and is intended to provide notice at collection.
57. Categories collected. We may collect the categories of personal information and sensitive personal information described in Section 5, including identifiers, customer records, protected classifications, commercial information, internet or network activity, geolocation data, audio or visual information, professional information, inferences, and sensitive personal information such as health information, government identifiers, account credentials, precise geolocation, racial or ethnic origin where collected, biometric information where used for identity verification, sexual health information, reproductive health information, and contents of communications not directed to us.
58. Purposes. We collect and use these categories for the purposes described in Section 8.
59. Retention. We retain these categories for the periods described in Section 16
60. Sale/share. We do not sell Protected Information. We do not knowingly sell or share personal information of consumers under sixteen (16). Certain disclosures of online identifiers, usage data, or similar information to advertising or analytics partners may be considered a sale or sharing under the CCPA. You may opt out through the "Do Not Sell or Share My Personal Information" page linked in the footer of every page, by enabling Global Privacy Control, or by contacting us.
61. Sensitive personal information. We use sensitive personal information to provide and coordinate Services, verify identity, ensure safety and compliance, process payments, prevent fraud, communicate with you, and as otherwise permitted by law. We do not use or disclose sensitive personal information for purposes requiring a right to limit unless we provide the required notice and opportunity to limit or obtain required consent.
62. California rights. Subject to exceptions, California residents may have the right to know/access, correct, delete, obtain portability, opt out of sale or sharing, limit certain uses or disclosures of sensitive personal information, and be free from discrimination for exercising CCPA rights. California residents may also make Shine the Light requests regarding certain disclosures for direct marketing purposes.
20. Consumer Health Data Rights and Other State Privacy Rights
63. Depending on your state of residence and the applicability thresholds and exemptions in state law, you may have privacy rights under consumer privacy laws, consumer health data laws, biometric privacy laws, genetic privacy laws, breach-notification laws, medical-information privacy laws, and other privacy statutes. These laws may apply to residents of California, Colorado, Connecticut, Delaware, Iowa, Maryland, Minnesota, Montana, Nebraska, Nevada, New Hampshire, New Jersey, Oregon, Tennessee, Texas, Utah, Virginia, Washington, and other states as laws take effect or are amended.
64. State privacy laws may provide rights to confirm processing, access, correct, delete, obtain a portable copy, opt out of sale, opt out of targeted advertising, opt out of certain profiling, limit sensitive data processing, withdraw consent, and appeal. Consumer health data laws may provide additional rights to consent to collection or sharing, withdraw consent, request deletion, obtain a list of third parties with whom consumer health data has been shared or sold, and restrict sale of consumer health data.
65. We will process state-law requests in accordance with the law that applies to your request. Some information may be exempt from certain state privacy laws, including PHI governed by HIPAA, information maintained as medical records by Providers, pharmacy records, payment records, information subject to federal or state retention laws, and information maintained for fraud prevention, security, or legal compliance.
21. International and Jurisdictional Issues
66. The Services are intended for use only by individuals located in the United States and only in jurisdictions where the Services are available. We make no representation that the Services are appropriate or available outside the United States. If you access the Services from outside the United States, you do so at your own risk and are responsible for compliance with local law.
67. Information collected through the Services may be processed and stored in the United States and other jurisdictions where our vendors or service providers operate, subject to applicable law and contractual safeguards. If an international privacy law applies to your information, you may have additional rights, and you may contact us using the information below.
22. Third-Party Websites, Integrations, and Services
68. The Services may contain links to third-party websites, apps, portals, payment processors, identity-verification tools, Provider portals, Pharmacy portals, Laboratory portals, social media platforms, or other third-party services. We do not control and are not responsible for the privacy practices, security, or content of third-party services.
69. If you provide information to a third party or authorize us to disclose information to a third party, that information may be governed by the third party's privacy policy, terms, consents, authorizations, or Notices of Privacy Practices. You should review those documents carefully.
23. Changes to This Privacy Policy
70. We may update this Privacy Policy from time to time to reflect changes in our Services, technologies, vendors, data practices, legal requirements, or business operations. The updated Privacy Policy will be posted on or made available through the Services, and the "Last Updated" date will be revised.
71. If we make material changes, we will provide notice or obtain consent where required by law. Your continued use of the Services after an updated Privacy Policy becomes effective constitutes your acknowledgment of the updated Privacy Policy, to the extent permitted by law.
24. Contact Us
If you have questions about this Privacy Policy, wish to exercise a privacy right, or need to contact Timber Health regarding privacy or data security, please contact us at:
Eir Services Group, LLC d/b/a Timber Health
Attn: Privacy Officer
5900 Balcones Drive, Suite 100, Austin, TX 78731
Email: compliance@timberhealth.co
Phone: +1 (201) 283-8474
Website/Privacy Request Portal: https://timberhealth.co
If you have questions about clinical records, medical care, prescription records, laboratory records, or a Notice of Privacy Practices issued by a Medical Group, Provider, Pharmacy, or Laboratory, you may need to contact that entity directly. Timber Health may assist with routing your request where appropriate and permitted by law.