Privacy Policy

Privacy Policy

 

Effective Date: May 11th, 2023

 

Rivet Health, Inc. (“Rivet,” “we,” “our” or “us”) respects your privacy and is committed to protecting it through our compliance with this Privacy Policy. This Privacy Policy describes our practices regarding the collection, use and disclosure of information we obtain from and about you when you use Rivet’s web-based and mobile applications and Rivet’s websites (including rivethealth.com and rivethealth.com/blog) that link to this Privacy Policy (collectively, the “Services”). By accessing or using the Services, you agree to this Privacy Policy and our Terms and Conditions.

 

Please read this Privacy Policy carefully to understand our policies and practices regarding your information and how we will treat it. IF YOU DO NOT AGREE TO THIS PRIVACY POLICY, PLEASE DO NOT USE THE SERVICES.

 

This Privacy Policy may change from time to time (see Changes to Our Privacy Policy below). Your continued use of the Services after we make changes is deemed to be acceptance of those changes, so please check this Privacy Policy periodically for updates. If you have any questions about our privacy practices, please contact us as set forth in the Contact Us section below.

 

THE INFORMATION WE COLLECT

 

For purposes of providing the Services, Rivet collects both information that you provide directly to us and information that is collected automatically. 

 

  1. Information You Provide to Us

 

Rivet collects the following information you may provide as a user of the Services:

  • Account and product registration information
  • Requests or questions you submit to us via forms or email (e.g., support forms, sales forms, user research participation forms)
  • Your communications with us
  • Information provided when you participate in Rivet sweepstakes, contests, or research studies
  • Uploads or posts to the Services
  • Requests for customer support and technical assistance

 

The types of information we collect from you will depend upon the Services you use, how you use them, and what information you choose to provide. The types of data we collect directly from you may include: (i) name, address, telephone number, email address and other optional information (such as a photograph) that you elect to associate with your account (collectively referred to as your “Profile Information”), (ii) log-in details and password (if you create an Rivet account), (iii) any email requests or questions you submit to us, (iv) with your permission, demographic information (such as your gender), and (v) user-generated content you post in public online Rivet forums (e.g., the Rivet blog).

 

In addition, we may collect from you the following types of information:

 

Content. In using the Services, you may upload or input various types of content, including but not limited to payers, contacts, fee schedules, contract terms, documents, spreadsheets, reimbursement rates, and pricebooks or other materials (together, “Data”). If you are using the Services in connection with an account created by a Rivet customer (e.g., employer, organization, or an individual) (each, a “Customer”), we collect and process the Data you submit on behalf of the Customer. As further described in this Privacy Policy, our Customers, and not Rivet, determine their own policies regarding storage, access, modification, deletion, sharing, and retention of Data which may apply to your use of the Services. For example, a Customer may provide or remove access to the Services, enable or disable third party integrations, manage permissions, retention and export settings, transfer or assign teams, or share reportsPlease check with the applicable Customer about the policies and settings it has instituted with respect to the Data that you provide when using the Services.

 

Payment Information. We will utilize a third party credit card payment processing company to collect payment information, including your credit card number, billing address and phone number. The third party service provider, and not Rivet, stores your payment information on our behalf.

 

  1. Information We Automatically Collect

 

When you use our Internet-connected Services, including, but not limited to, when you access the Services via our websites, your mobile devices, and Rivet software/applications, we automatically collect certain information. As described below, we and our service providers (third party companies that help us provide and enhance the Services) use a variety of technologies, including cookies and similar tools, to assist in collecting this information.

 

Log Files

When you use the Services, our servers automatically record certain information in server logs. These server logs may include information such as your web request, Internet Protocol (“IP”) address, browser type and settings, referring/exit pages and URLs, number of clicks and how you interact with links on the Services, metadata associated with uploaded Data, domain names, landing pages, pages viewed, mobile carrier, date and time stamp information and other such information.

 

Device Identifiers

When you access the Services using a mobile device, we collect specific device information, including your MAC address and other unique device identifiers. We also collect information such as the type of device you are using, its operating system, and mobile network information, which may include your mobile phone number. We may associate this device identifier with your account, and we will use data associated with your device identifier to customize our Services to your device and to analyze any device-related issues.

 

Location Information

We collect and process general information about the location of the device from which you are accessing the Services (e.g., approximate geographic location inferred from an IP address). 

 

Additional information we may collect includes the following:

  1. Information We Collect from Third Party Integrations

 

If you choose to use third party integrations through the Services or are required to do so by a Customer, such third party providers may allow us and our service providers to have access to and store additional information about your interaction with those services and platforms as it relates to use of the Services. If you do not wish to have this information shared, do not initiate such integrations. 

 

  1. Information We Collect from Affiliates and Non-Affiliated Third Parties

Rivet may receive additional information about you, such as demographic information, from affiliates under common ownership and control, and from third parties, such as business partners, marketers, researchers, analysts, and other parties that we may use to supplement the information that we collect directly from you. 

 

  1. Collection of Information Across Devices

We may use the information we collect — for instance, usernames, IP addresses and unique mobile device identifiers — to locate or try to locate the same unique users across multiple browsers or devices (such as smartphones or tablets), or work with service providers that do this, in order to save your preferences across devices and analyze usage of the Services.

 

COOKIES AND SIMILAR TECHNOLOGIES

 

To collect information automatically, we and our service providers use Internet server logs, cookies, tags, SDKs, tracking pixels, and other similar tracking technologies. A web server log is a file where website activity is stored. An SDK is a section of code that we embed in our applications and software to allow third parties to collect information about how users interact with the Services. A cookie is a small text file that is placed on your computer or mobile device when you visit a site, that enables us to: (i) recognize your computer and login session; (ii) store your preferences and settings; (iii) understand which web pages of the Services you have visited; (iv), enhance your user experience by delivering and measuring the effectiveness of content and advertising tailored to your interests; (v) perform analytics; and (vi) assist with security and administrative functions. Tracking pixels (sometimes referred to as web beacons or clear GIFs) are tiny electronic tags with a unique identifier embedded in websites, online ads and/or email, and that are designed to provide usage information like ad impressions or clicks, email open rates, measure popularity of the Services and associated advertising, and to access user cookies. As we adopt additional technologies, we may also gather information through other methods.

 

Please note that you can change your settings to notify you when a cookie is being set or updated, or to block cookies altogether. Please consult the “Help” section of your browser for more information (e.g. Internet Explorer, Google Chrome, Mozilla Firefox or Apple Safari).

 

HOW WE USE YOUR INFORMATION

 

We use your information we collect for various purposes depending on the types of information we have collected from and about you and the specific Rivet Services you use, including to:

  • complete a purchase or provide the Services you have requested;
  • respond to your request for information and provide you with more effective and efficient customer service;
  • provide you with product updates and information about products you have purchased from us;
  • provide you with service notifications via email and within the Services based on your notification selections;
  • contact you by email, postal mail, or phone regarding Rivet and third party products, services, surveys, research studies, promotions, special events and other subjects that we think may be of interest to you;
  • customize the advertising and content you see;
  • help us better understand your interests and needs, and improve the Services;
  • synthesize and derive insights from your use of different Rivet products and services;
  • engage in analysis, research, and reports regarding use of our Services;
  • provide, manage, and improve the Services;
  • protect our Services and our users; and
  • understand and resolve app crashes and other issues being reported.

 

Control of Your Data

You can exercise certain control regarding how your Data is used by/shared with others via your settings selections related to the Services. Rivet will view and share your Data only as necessary (i) to maintain, provide and improve the Services; (ii) prevent or address technical or security issues and resolve support requests; (iii) if we have a good faith belief, or have received a complaint alleging, that such Data is in violation of our Terms and Conditions; (iv) as reasonably necessary to allow Rivet to comply with or avoid the violation of applicable law or regulation; (v) to comply with a valid legal subpoena, request, or other lawful process; and (vi) as set forth in the Terms and Conditions with the Customer or as expressly permitted in writing by the Customer. We may also analyze your Data in aggregate and on an anonymized basis, in order to better understand the manner in which our Services is being used.

 

Combined Information

For the purposes discussed in this Policy, we may combine the information that we collect through the Services with information that we receive from other sources, both online and offline, and use such combined information in accordance with this Privacy Policy.

 

Aggregate/De-Identified Data

We may aggregate and/or de-identify information collected through the Services so that such information can no longer be linked to you or your device (“Aggregate/De-Identified Information”). We may use Aggregate/De-Identified Information for any purpose, including without limitation for research and marketing purposes, and we may also share such data with any third parties, including advertisers, promotional partners, sponsors, event promoters, and/or others.

 

ONLINE ANALYTICS AND ADVERTISING

  1. Analytics

We use third party web analytics services (e.g., Google Analytics) on our Services to collect and analyze the information we obtain, and to engage in auditing, research and reporting. The information (including your IP address) collected by various analytics technologies (described in the “Cookies and Similar Technologies” section) will be disclosed to or collected directly by these service providers, who use the information to evaluate your use of the Services, including by noting the third party website from which you arrive, analyzing usage trends across Rivet products and mobile devices, assisting with fraud prevention, and providing certain features to you.

 

If you receive email from us, we may use certain analytics tools, such as clear GIFs, to capture data such as when you open our message or click on any links or banners our email contains. This data allows us to gauge the effectiveness of our communications and marketing campaigns.

 

  1. Online Advertising

Third parties or affiliates may deliver Rivet advertising and other online marketing on non-Rivet websites and services. To do so, these parties may set and access first-party cookies delivered from a Rivet domain, or they may use third party cookies or other tracking mechanisms. For example, a third party provider may use the fact that you visited the Rivet website to target online ads for Rivet services to you on non-Rivet websites. Or a third party ad network might collect information on the Services and other websites to develop a profile of your interests and target advertisements to you based on your online behavior. These technologies may collect information about your online activities over time and across third-party websites or other online services (behavioral tracking).

 

The parties using these technologies may offer you a way to opt out of ad targeting as described below. If you are interested in more information about behavioral advertising and how you can generally control cookies from being put on your computer to deliver such advertising, you may visit the Network Advertising Initiative’s Consumer Opt-Out link or the Digital Advertising Alliance’s Consumer Opt-Out link to opt-out of receiving tailored advertising from companies that participate in those programs. To opt out of Google Analytics for display advertising or customize Google display network ads, you can visit the Google Ads Settings page. Please note that we do not control any of the above opt-out links or whether any particular company chooses to participate in these opt-out programs. We are not responsible for any choices you make using these mechanisms or the continued availability or accuracy of these mechanisms.

  1. Notice Concerning Do Not Track.

Your browser settings may allow you to automatically transmit a “Do Not Track” signal to online services you visit. Note, however, there is no uniform or consistent standard or definition for responding to, processing, or communicating Do Not Track signals. At this time the Services do not function differently based on a user’s Do Not Track signal. For more information on Do Not Track signals, see All About Do Not Track.

 

HOW WE SHARE YOUR INFORMATION

 

Rivet may share your information in the following ways:

  • Affiliates and Subsidiaries. We may share information we collect within the Rivet family of companies.
  • Service Providers. We may provide access to or share your information with select third parties who perform services on our behalf. These third parties provide a variety of services to us, including without limitation billing, sales, marketing, provision of content and features, advertising, analytics, research, customer service, shipping and fulfillment, data storage, security, fraud prevention, payment processing, and legal services.
  • Third Party Integrations. When you initiate a connection with a third party integration through the Services (e.g., OneDrive, Unito, Wufoo, Slack), we will share information about you that is required to enable your use of the third party integration through the Services.
  • Business Transfers. If the ownership of all or substantially all of our business changes, we may transfer your information to the new owner so that the Services can continue to operate. In such case, your information will remain subject to the promises and commitments contained in this Privacy Policy until such time as this Privacy Policy is updated or amended by the acquiring party upon notice to you. If such transfer is subject to additional mandatory restrictions under applicable laws, Rivet will comply with such restrictions.
  • Public Forums. The Services make it possible for you to upload and share comments or feedback publicly (i.e., outside of the Rivet mobile and web app) with other users, such as on the Rivet blog. Any information that you submit through such public features is not confidential, and Rivet may use it for any purpose (including in testimonials or other Rivet marketing materials). Any information you post openly in these ways will be available to the public at large and potentially accessible through third party search engines. Such information can be read, collected and/or used by other users, and it could be used to send you unsolicited messages. Accordingly, please take care when using these features of the Services.
  • Aggregate/De-Identified Information. From time to time, Rivet may share Aggregate/De-Identified Information about use of the Services, such as by publishing a report on usage trends. As stated above, we may use or share Aggregate/De-Identified Information without limit.
  • Consent. We may also disclose your information to third parties with your consent to do so. For example, we will display your Profile Information on your profile page and elsewhere on the Services in accordance with the preferences you set in your account. You can review and revise your Profile information at any time.

 

THIRD PARTY LINKS AND SERVICES

 

The Services contain links to third party websites such as social media sites, and also contain third party integrations. If you choose to use these sites or integrations, you may disclose your information not just to those third parties, but also to their users and the public more generally depending on how their services function. Because these third party websites and services are not operated by Rivet, Rivet is not responsible for the content or practices of those websites or services. The collection, use, and disclosure of your personal and other information will be subject to the privacy policies of the third party websites or services, and not this Policy. We urge you to read the privacy and security policies of these third parties.

 

YOUR CHOICES AND RIGHTS

 

We provide you with a number of choices with respect to the information we collect and use. For example, you may instruct us not to use your contact information to contact you by email, postal mail or phone regarding products, services, promotions and special events that might appeal to your interests by contacting us at privacy@rivethealth.com. In commercial email messages, you can also opt out by following the instructions located at the bottom of such emails. Please note that, regardless of your request, we may still use and share certain information as permitted by this Privacy Policy or as required by applicable law. For example, you may not opt out of certain operational or service-related emails, such as those reflecting our relationship or transactions with you. Through your account interface, you may opt out of certain receiving categories of Services-related notices that are not deemed by Rivet to be integral to your use of the Services.

 

If you want to learn more about the information collected through the Services, or if you would like to access or rectify your information and/or request deletion of information we collect about you, or restrict or object to the processing of your information, please contact us using the contact information below (Contact Us section). Where you have provided consent, you may withdraw your consent at any time, without affecting the lawfulness of the processing that was carried out prior to withdrawing your consent.

 

HOW LONG WE STORE YOUR INFORMATION

 

We will retain your information for the period necessary to fulfill the purposes outlined in this Privacy Policy unless a longer retention period is required or permitted by law.

 

CHILDREN

 

The Services are intended for a general audience and are not directed to children under 13 years of age. Rivet does not knowingly collect personal information as defined by the Children’s Online Privacy Protection Act (“COPPA”) in a manner that is not permitted by COPPA. If you are a parent or guardian and believe Rivet has collected such information in a manner not permitted by COPPA, please contact us as at privacy@rivethealth.com and we will remove such information to the extent required by COPPA.

 

HOW WE PROTECT YOUR INFORMATION

 

Rivet takes technical and organizational measures to protect your personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access. However, no method of transmission over the Internet, and no means of electronic or physical storage, is absolutely secure, and thus we cannot ensure or warrant the security of your information. If you have any questions about the security of our Services, you can contact us at privacy@rivethealth.com.

CHANGES TO OUR PRIVACY POLICY

 

We reserve the right to amend this Privacy Policy at any time to reflect changes in the law, our data collection and use practices, the features of our Services, or advances in technology. Such changes and any amended policy will become effective upon posting upon our website. Your continued use of the Services indicates your consent to the Privacy Policy then posted. We encourage you to regularly review this Privacy Policy on our website for the latest information on our privacy practices.

 

CONTACT US

 

If you wish to contact us or have any questions about or complaints in relation to this Privacy Policy, please contact us at privacy@rivethealth.com.