Privacy Policy
Effective Date: January 1st, 2026
Last Updated: January 1st 2026
This Privacy Policy explains how PreOncology LLC (“PreOncology,” “we,” “us,” “our”) collects, uses, discloses, and protects information when you use our websites, portals, and online services (the “Services”).
Important: Clinical care (including telehealth) is provided by physicians employed by PreOncology Institute LLC. Information collected as part of clinical care may be protected by HIPAA and governed by the Notice of Privacy Practices (“NPP”) of PreOncology Institute LLC. This Privacy Policy primarily covers information handled by PreOncology LLC as a technology and administrative services provider and website operator.
1. Scope
This Privacy Policy applies to information collected through:
- Our website(s) and member portal(s).
- Online forms, assessments, and questionnaires.
- Customer support communications (email, SMS, chat).
- Scheduling and administrative workflows.
This Privacy Policy does not apply to third-party websites, services, or providers (labs, imaging centers, payment processors, etc.) that may have their own privacy policies.
2. Information We Collect
We may collect the following categories of information:
A. Information You Provide
- Contact details: name, email, phone, mailing address.
- Account details: login credentials, profile information.
- Intake and assessment information: demographics, family history, lifestyle information, screening history, and other information you submit.
- Communications: messages, emails, and support requests.
- Payment details: billing address and limited payment metadata. Payment card data is processed by our payment processor and is not stored on our systems.
B. Information Collected Automatically
- Device and usage data: IP address, browser type, device identifiers, pages viewed, session activity, referral URLs.
- Cookies and similar technologies: to support functionality, analytics, and preferences (see Section 7).
C. Sensitive Information
Some information you provide may be considered sensitive (e.g., health-related information). If you upload genetic or genomic information, it may be sensitive and may be subject to additional protections depending on context and applicable law (see Section 11).
3. How We Use Information
We use information to:
- Provide, operate, and maintain the Services.
- Create and manage accounts and authenticate users.
- Deliver assessments, reports, and service features you request.
- Coordinate scheduling and administrative support.
- Provide customer support and respond to inquiries.
- Process payments and prevent fraud.
- Improve the Services, including analytics and performance monitoring.
- Communicate about the Services (service notices, updates, security alerts).
- Comply with legal obligations and enforce our Terms of Service.
4. Clinical Services and HIPAA (PreOncology Institute LLC)
If you receive Clinical Services (including telehealth), your information may be handled by PreOncology Institute LLC as a covered entity under HIPAA (or by its business associates) and governed by the Institute’s Notice of Privacy Practices.
In some cases, PreOncology LLC may receive or process information on behalf of PreOncology Institute LLC to support operations (e.g., portal functionality, scheduling, billing support). Where applicable, that information is handled under HIPAA-related requirements via business associate arrangements.
5. How We Share Information
We may share information in these situations:
A. Service Providers (Vendors)
We use vendors to help operate the Services (e.g., hosting, analytics, customer support tools, communications/SMS, scheduling, payment processing). Vendors are permitted to use information only to provide services to us and must protect it under contractual obligations.
B. With PreOncology Institute LLC
We may share information with PreOncology Institute LLC to facilitate Clinical Services, scheduling, care coordination, and support, as applicable.
C. Third Parties You Direct
If you request that we share information with a third party (e.g., your physician, a family member, an employer concierge program), we will do so as directed, subject to verification and applicable law.
D. Legal and Safety
We may disclose information to comply with law, court orders, subpoenas, or to protect rights, safety, and security, investigate fraud, or enforce our Terms.
E. Business Transfers
If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to appropriate confidentiality protections. We will notify affected users before personal information is transferred to a new entity that operates under materially different privacy practices than those described in this Privacy Policy.
We do not sell your personal information. (See Section 10 for state-specific rights.)
6. Data Retention
We retain information for as long as necessary to:
- Provide the Services.
- Maintain records for legitimate business purposes (e.g., security, dispute resolution).
- Comply with legal and regulatory obligations.
General retention periods: Account information is retained for the duration of your membership plus seven (7) years, unless a longer period is required by applicable law. Payment records are retained for the period required by tax and financial regulations (typically seven years). Usage and analytics data is retained in identifiable form for up to two (2) years and may be retained in aggregated or de-identified form indefinitely.
Retention periods may differ for clinical records maintained by PreOncology Institute LLC, which are subject to HIPAA and applicable state medical records retention requirements (including Florida’s seven-year minimum and Ohio’s applicable retention periods).
7. Cookies and Tracking Technologies
We use cookies and similar technologies to support the Services. These fall into the following categories:
- Strictly Necessary Cookies: Required for site functionality, authentication, and security. These cannot be disabled without affecting your ability to use the Services.
- Analytics Cookies: Used to understand how visitors interact with the Services, measure performance, and improve user experience. These may include tools such as Google Analytics or similar platforms.
- Preference Cookies: Used to remember your settings and preferences across sessions.
- Marketing Cookies: If used, these support advertising and outreach. We will provide an opt-out mechanism if marketing cookies are deployed (see Section 10).
Managing cookies: You can control cookies through your browser settings or, where available, through our cookie preference center. Disabling certain cookies may limit functionality.
Do Not Track: Some browsers offer “Do Not Track” signals. Our Services currently do not respond to all such signals. Where required by applicable state law, we will honor opt-out preference signals (such as the Global Privacy Control).
8. Security
We use administrative, technical, and physical safeguards designed to protect information, including encryption in transit and at rest, access controls, and regular security assessments. However, no system is 100% secure. You are responsible for maintaining the confidentiality of your account credentials and for using secure devices and networks.
9. Children’s Privacy
The Services are not intended for children under 18. We do not knowingly collect personal information from children. If you believe a child has provided information, contact us to request deletion.
10. Your Privacy Rights
Depending on where you live, applicable state consumer privacy laws may give you certain rights regarding your personal information, including the right to:
- Request access to the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of certain information.
- Opt out of certain types of processing, including the sale or sharing of personal information for cross-context behavioral advertising (where applicable).
- Appeal a denial of a request (where required by law).
Florida
If you are a Florida resident and the Florida Digital Bill of Rights (SB 262) applies, you may have additional rights including the right to access, correct, delete, and opt out of certain processing of your personal data. To exercise these rights, contact us using Section 13.
Ohio
Ohio does not currently have a comprehensive consumer privacy law. If Ohio enacts such legislation, we will update this section accordingly. Ohio residents may still exercise any rights available under other applicable law.
California (CCPA/CPRA)
If you are a California resident, you may have rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act:
- Categories collected: identifiers, internet activity, account data, and potentially sensitive data you provide.
- Purposes: operating and improving Services, security, and compliance.
- Disclosure: to service providers and affiliates for business purposes.
- We do not sell personal information. We do not knowingly sell or share information of minors.
- If we engage in “sharing” for cross-context behavioral advertising, we will provide a mechanism to opt out (e.g., “Do Not Sell or Share My Personal Information”).
Other States
If you reside in a state with an applicable consumer privacy law (e.g., Virginia, Colorado, Connecticut, Texas, Oregon, or others), you may have similar rights. Contact us using Section 13 to submit a request, and we will respond in accordance with applicable law.
We may need to verify your identity before fulfilling requests. We will not discriminate against you for exercising your privacy rights.
11. Genetic Information
If you upload or obtain genetic or genomic information through the Services:
- You understand this information may have implications for you and biological relatives.
- You control what you choose to upload and share.
- Where genetic information is part of Clinical Services, it may be governed by HIPAA and the Institute’s NPP.
- Insurance limitations: The Genetic Information Nondiscrimination Act (GINA) prohibits discrimination in health insurance and employment based on genetic information. However, GINA does not apply to life insurance, disability insurance, or long-term care insurance. You should consider these implications before obtaining genetic testing through the Services.
- We will not voluntarily disclose your genetic information to insurers, employers, or other third parties except as required by law, directed by you, or as described in this Privacy Policy.
12. De-Identified and Aggregated Data
We may de-identify or aggregate information so that it no longer reasonably identifies you. De-identified and aggregated data may be used for research, analytics, service improvement, population health insights, and other lawful purposes. De-identified data is not subject to this Privacy Policy, and we maintain appropriate safeguards to prevent re-identification in accordance with applicable law.
13. International Users
If you access the Services from outside the United States, you understand your information may be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.
14. Contact Us
Questions or requests regarding this Privacy Policy:
PreOncology LLC
Address: 110 Front St, Jupiter FL, 33477
Privacy: [email protected]
Support: [email protected]
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version and revise the “Last Updated” date. For material changes, we will provide reasonable advance notice via email or in-app notification. Continued use of the Services after an update means you accept the revised policy.