Privacy Policy

Last updated: 05/28/2025

Privacy Policy

Last updated: 05/28/2025

Privacy Policy

Last updated: 05/28/2025


Privacy Policy

Last updated: [05/28/2025]

GHOAT LLC, a Delaware limited liability company, and its affiliates ("Hundred Health", "Company", "we" or "us") is committed to the privacy of our customers, website visitors, and users of our applications, products, and services. This privacy policy ("Privacy Policy") discloses what Personal Information is gathered about visitors to our website ("Website") and users of our applications, products and services, and successors thereof (collectively with the Website, the "Service(s)"), however accessed, and how that Personal Information is used.

SCOPE OF THIS PRIVACY POLICY

For purposes of this Privacy Policy, "Personal Information" means information that alone or in combination identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.

We obtain and process Personal Information in different capacities. When we collect or process Personal Information for our own purposes, meaning that we determine how and what Personal Information is processed, we are the data controller. This Privacy Policy applies solely to our collection, use, disclosure, and protection of Personal Information where we are the data controller.

We may also collect, store, use and share your Personal Information that is linked or reasonably linkable to you and that identifies your past, present, or future health status or mental health status, as may be applicable ("Consumer Health Data"). This Privacy Policy contains information about how we collect Consumer Health Data, how we use it, what sources it is derived from, to whom we disclose it and how we otherwise process it. In addition, if you are a resident of Connecticut, or Nevada, we provide further information about your Consumer Health Data, as well as the rights you may have related to this data, in our Consumer Health Data Privacy Policy which is incorporated herein by reference.

IF YOU ARE A CALIFORNIA RESIDENT, PLEASE SEE SECTION 1 OF THIS POLICY FOR ADDITIONAL TERMS THAT MAY APPLY TO YOU.

CATEGORIES AND SOURCES OF PERSONAL INFORMATION AND THE PURPOSES FOR WHICH WE COLLECT AND USE THEM

Hundred Health may obtain certain categories of Personal Information from various sources. For example, the information collected will differ based on the content you choose to provide to our Services. The information we collect about you will vary depending on how you interact with Hundred Health and our Services. Described below is a summary describing the types of Personal Information which may be collected and the business purpose for which we collect this Personal Information from you.

Category of Information Source Collected Business Purpose for Collection

Identifiers such as real name, postal address, unique personal identifier, online identifier, Internet Protocol (IP) address, email address, or other similar identifiers. Direct contact with users through the Services, phone, email, web form and social media. As described herein to provide you with Products and Services and for internal purposes.

Customer Records such as name, address, telephone number, employment, financial information, medical information, and other similar information. Direct contact with users through the Services, phone, email and social media; Third Party Providers. As described herein to provide you with Products and Services and for internal purposes.

Commercial Information such as records of products or services purchased, obtained, or considered, or other purchasing or consuming histories and tendencies. The Services, cookies and other tracking technologies, Third Party Providers. As described herein to provide you with Products and Services and for internal and marketing purposes.

Financial Information such as credit card number, bank account information and any other similar financial information. Direct contact with users through the Services, phone, email and Third Party Providers. As described herein to provide you with Products, provide the Services or complete transactions, and for internal purposes.

Biometric Information such as height, weight, voice, and other similar biometric data. Direct contact with users through the Services, including wearables (where enabled), email and Third Party Providers. As described herein to provide you with Products, provide the Services or complete transactions, and for internal purposes.

Demographic Information such as race, ethnicity, religion, sexual orientation, gender identity, gender expression, philosophical beliefs, political views, and age Direct contact with users through the Services, phone, email, social media and Third Party Providers As described herein to provide you with Products and Services and for internal purposes.

Employment Information such as employment history, resume, references, contact information, emergency contact information, professional certifications, associations, disciplines, pay requirements, licenses and certifications held, skills, and experience. Direct contact with users through the Services, phone, email and social media and from Third Party Providers assisting in filling open positions. To process applications for potential employment and for internal employment and benefit purposes.

Internet Activity such as browsing history and information on a consumer's interaction with our Services The Services and Third Party Providers. As described herein regarding cookies, e.g., for internal purposes and for marketing purposes.

Geolocation Data such as imprecise location information, like the city, state and ZIP code associated with your IP address or device The Services and Third Party Providers. As described herein regarding cookies, e.g., for internal, marketing, and other operational and business purposes.

Sensitive Personal Information such as Consumer Health Data, Genetic data, physical and mental health condition, and personal information collected concerning your health data Direct contact with users through the Services, phone, email and Third Party Providers. Internal reporting and analytics purposes, for other purposes in the ordinary course of employment.

To understand how we use and to whom we disclose the Personal Information collected, please see Section 5 and Section 6 below.

HOW LONG DO WE KEEP YOUR INFORMATION

We retain Personal Information only as long as we have a legitimate business purpose to do so. These purposes may include retaining Personal Information in order to:

complete the transaction for which the Personal Information was collected;

continue our ongoing business relationship with you; and

satisfy any legal, regulatory, tax, accounting or reporting requirements.

To determine the appropriate retention period for individual categories of Personal Information we collect, we consider the nature and sensitivity of the Personal Information; the potential risk of harm from unauthorized use or disclosure of the Personal Information; the purposes for which we process that Personal Information and whether we can fulfill those purposes through other means; and applicable legal, regulatory, tax, accounting, reporting and other requirements.

This means, for example, that some data is deleted or anonymized automatically after a set period of time.

HOW WE USE YOUR INFORMATION

Hundred Health will use your Personal Information, including any Consumer Heath Data, for any of the following purposes:

Providing any Services or Products that you request or purchase.

Contacting you regarding the administration of any features or functions of the Services.

Providing you with notices about your User Account.

Carrying out our obligations and enforcing our rights arising from any contracts entered into between you and us, including for billing and collection.

Notifying you about changes to our Services, our policies, terms or any services or products we offer or provide through it.

Sending you marketing and promotional emails.

Responding to your questions or other requests.

Tailoring your experience on the Services or otherwise customizing what you see when you visit and use the Services.

Tracking your return visits to and use of the Services and saving your User Account information.

For research purposes, for marketing/promotional purposes and to provide anonymous reporting for internal and external clients and business partners.

Accumulating and reporting de-identified or aggregate, statistical information in connection with the Services and user activity.

Determining which features and services users like best to help us operate the Services, enhance and improve our Services, Products and to display advertising and marketing information.

Improving and enforcing our security measures.

Enforcing compliance with our terms and conditions and policies.

For any other purpose disclosed to you prior to you providing us your personal information or which are reasonably necessary to provide the Services or other related products and/or services requested.

WHO WE SHARE YOUR INFORMATION WITH

Hundred Health limits the release of information, and we require privacy protections in our business relationships. As further detailed herein, we may share your Personal Information when required by law, or with independent third parties that perform certain agreed upon services that help us provide the Services to you ("Third Party Providers"). We may also share information to protect the interests of individuals or in connection with a sale of our business or a merger or acquisition. The information we disclose about you will vary depending on how you interact with Hundred Health and the Services. Described below is a summary of who we may share your Personal Information with.

Third Party Providers: We may share Personal Information with our Third Party Providers who facilitate the operation of our Services, provide services on our behalf, and perform service-related functions or assist us in analyzing how our Services are used. The Personal Information obtained by these Third Party Providers from their relationship with us is only to be used for performing the services specified in our agreement with them, or as reasonably necessary to perform one or more of the following:

Comply with applicable law, regulation, or legal process;

Detect, prevent or mitigate fraud or security vulnerabilities;

Debug to identify and repair errors impairing existing intended functionalities; and/or

Conduct internal research for technological development and demonstration of our products or services, if such use is reasonably necessary and proportionate to achieve the purpose for which the data was shared.

Laboratory Testing, Clinician and Telehealth Services: If you utilize laboratory testing services, clinician oversight or telehealth services, your Personal Information, including, without limitation Consumer Health Data, may be transmitted to the applicable laboratory or healthcare provider per your instructions. For information about how such health information is used or disclosed, please see the notices, agreements, consents or acknowledgments you execute and receive in the course of utilizing those services.

Within Our Corporate Organization: We may share your Personal Information with our subsidiaries and affiliates in order to provide you with our services and take actions based on your requests.

Corporate Transactions: To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution or sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation or similar proceeding, in which Personal Information held by us about our Services is among the assets transferred, and you agree to and do hereby consent to our assignment or transfer of rights to your personal information.

As Required by Law: Under certain circumstances your personal information may be subject to processing pursuant to laws, regulations, judicial or other government subpoenas, warrants, or orders. We may be required to disclose Personal Information in coordination with regulatory authorities in response to lawful requests by public authorities, including to meet national security or law enforcement requirements, or for public health purposes. We will preserve and disclose any and all information to law enforcement agencies or others if required to do so by law or in the good faith belief that such preservation or disclosure is reasonably necessary to: (a) comply with legal or regulatory process (such as a judicial proceeding, court order, or government inquiry) or obligations that we may owe pursuant to ethical and other professional rules, laws, and regulations; (b) enforce our Terms of Service and other policies; (c) respond to claims that any content violates the rights of third parties; or (d) protect the rights, property, or personal safety of Hundred Health, our employees, our users, clients, and the public.

Sharing of Website Tracking Data: Our websites, like almost all other websites, use cookies and other technologies to make the website work as you expect and to collect and share information. Please see Section 6 below for more information.

Integration of Third-Party Platform, Services and Websites: The Services may be linked to, rely on and be integrated with websites, applications, interfaces, services and platforms operated by other companies, including third-party services. We are not responsible for the privacy practices of such websites, applications, interfaces, services and platforms operated by third parties that are linked to, rely on and/or integrated with the Services or for the privacy practices of third party advertising companies. Once you leave the Services via a link, access a third-party service or click on an advertisement, you should check applicable privacy policies to determine, among other things, how related companies process personal information they may collect about you.

SITE ANALYTICS, COOKIES AND OTHER TRACKING TECHNOLOGIES

We may collect Personal Information using "cookies." Cookies are small data files stored on the hard drive of your computer or mobile device by a website. We may use both session cookies (which expire once you close your web browser) and persistent cookies (which stay on your computer or mobile device until you delete them) to provide you with a more personal and interactive experience on the Website and Services.

We may use two broad categories of cookies: (1) first party cookies, served directly by us to your computer or mobile device, which are used only by us to recognize your computer or mobile device when it revisits our Website or Services; and (2) third party cookies, which are served by various Third Party Providers on our Website and Services, and can be used by such Third Party Service Providers to recognize your computer or mobile device when it visits other websites.

Cookies we use

Our Services uses the following types of cookies for the purposes set out below:

Type of Cookie: Essential Cookies

Purpose: These cookies are essential to provide you with services available through our Services and to enable you to use some of its features. For example, they allow you to log in to secure areas of the Services, identify a referring affiliate and help the content of the pages you request load quickly. Without these cookies, the services that you have asked for cannot be provided, and we only use these cookies to provide you with those services.

Type of Cookie: Functionality Cookies

Purpose: These cookies allow the Services to remember choices you make when you use our Website and otherwise use the Services, such as remembering your language preferences, and remembering your login details. The purpose of these cookies is to provide you with a more personal experience and to avoid you having to re-enter your preferences every time you use the Services.

Type of Cookie: Analytics and Performance Cookies

Purpose: These cookies are used to collect information about traffic to our Services and how users use our Website and Services. The information gathered does not identify any individual visitor. The information is aggregated and anonymous. It includes the number of visitors to the Services, the websites that referred them, the pages they visited on the Services, what time of day they used the Services, whether they have visited our Website or used the Services before, and other similar information. We use this information to help operate the Services more efficiently, to gather broad demographic information and to monitor the level of activity on the Services.

Further information about cookies, including how to see what cookies have been set on your computer or mobile device and how to manage and delete them, visit www.allaboutcookies.org.

In addition to cookies, we may employ various Third Party Provider services that may collect Personal Information when you interact with our Services, including IP addresses, digital identifiers, information about your web browsing and how you interact with our Services and ads for a variety of purposes, such as personalization of offers or advertisements, analytics about how you engage with websites or ads and other commercial purposes.

These services are subject to update, but may include: Google Analytics, Twilio Segment and other services.

Statements regarding our practices do not apply to the methods for collecting information used by these Third Party Providers or the use of the information that such parties collect. We do however work with Third Party Providers to make efforts to have you provided with information on their practices and any available opportunity to exercise choice. We make no representations regarding the policies or practices of any such third parties.

YOUR CONSUMER PRIVACY CHOICES

Updating your Personal Information. If your Personal Information changes, or if you no longer desire our service, you may correct, update, amend, delete/remove, or deactivate it by making the change on our member information page or by emailing us at privacy@hundred.com We will respond to your request within a reasonable timeframe.

Opt-Out. Please note that while you can always opt not to disclose Personal Information to us, some Personal Information may be needed to set up a User Account with us or to take advantage of some features of our Services.

Opt-Out of Email Marketing. If for any reason you would no longer like to receive email marketing messages from the Company, you may Unsubscribe by following the instructions contained within our promotional emails. Please allow up to ten (10) days for us to process your request. Please note, if you opt not to receive marketing emails from the Company, you may still receive "transactional" email messages regarding your account, use of the Websites or your order (e.g., order confirmation, shipping information, recall notices, customer service notifications, etc.). To opt-out of receiving our direct mail, you may send us an email at privacy@hundred.com

Do Not Track. Some web browsers incorporate a "Do Not Track" ("DNT") or similar feature that signals to websites that a user does not want to have the user's online activity and behavior tracked. If a website that responds to a particular DNT signal receives the DNT signal, the browser can block that website from collecting certain information about that browser's user. Not all browsers offer a DNT option and DNT signals are not yet uniform. For this reason, the Website may not respond to DNT signals.

Limits on Targeted Advertising. Most browsers automatically accept cookies. You can disable this function by changing your browser settings but disabling cookies may impact your use and enjoyment of the Website. You cannot disable all cookies, such as cookies that are essential to the functioning of the Website. You can manually delete persistent cookies, or cookies that track your activity across websites, through your browser settings. If you wish to limit receipt of targeted advertisements, you may click on the displayed icon on that advertisement to receive more information and you may choose to opt-out.

LEAVING OUR WEBSITE AND/OR LINKING TO THIRD PARTIES

When you leave our Website and go to another linked website, we are not responsible for the content or availability of the linked website. Please be advised that we do not represent either the third party or you, if you enter into a transaction on the third-party site. Further, the privacy and security policies of the linked site may differ from ours. We do not accept any responsibility or liability for their websites, features or policies. Please read their privacy policies before you submit any data to them.

INFORMATION SECURITY

We take the security of your Personal Information seriously. We use reasonable technical, administrative, and physical safeguards to maintain the security and privacy of Personal Information we collect and use. When disclosing Personal Information, you should remain mindful that there is always risk in sending Personal Information using the internet.

DE-IDENTIFIED / AGGREGATED DATA

We may aggregate or de-identify Personal Information we collect through our Services and when operating our business. For example, we may aggregate Personal Information to calculate the percentage of users in a particular zip code. Once information or data has been de-identified and/or aggregated, such information is no longer Personal Information. This means we may use this de-identified / aggregated data for our general business purposes and may share it with third parties.

INTERNATIONAL USERS

Our Website and Services are operated in the United States and intended for users located in the United States. Like almost every website, our Website can be accessed by an international audience. If you are located outside of the United States, please be aware that information we collect, including Personal Information, will be transferred to, processed, stored and used in the United States. The data protection laws in the United States may differ from those of the country in which you are located, and your Personal Information may be subject to access requests from governments, courts, or law enforcement in the United States according to laws of the United States. In addition, such data may be stored on servers located outside your resident jurisdiction and in jurisdictions which may have less stringent privacy practices than your own. Currently, only those persons that live in the United States may order our Services.

CALIFORNIA PRIVACY RIGHTS

If you are a California resident, you have the rights outlined in this section, and in accordance with the California Consumer Privacy Act ("CCPA"), as amended. Please see the "Exercising Your Rights" sub-section below for instructions regarding how to exercise these rights. If there are any conflicts between this section and any other provision of this Privacy Policy and you are a California resident, the portion that is more protective of your Personal Information shall control. If you have any questions about this section or whether any of the following applies to you, please contact us at privacy@hundred.com.

Right to Access

You have the right to request certain information about our collection and use of your Personal Information over the past twelve (12) months. Assuming verification of your identity, we will provide you with the following information:

The categories of Personal Information that we have collected about you.

The categories of sources from which that Personal Information was collected.

The business or commercial purpose for collecting, selling, or sharing your Personal Information.

The categories of third-parties with whom we have shared your Personal Information.

The specific pieces of Personal Information that we have collected about you.

If we have disclosed your Personal Information for a business purpose over the past twelve (12) months, we will identify the categories of Personal Information shared with each category of third-party recipient.

If we have sold your Personal Information over the past twelve (12) months, we will identify the categories of Personal Information purchased by each category of third-party recipient.

Right to Deletion

You have the right to request that we delete the Personal Information that we have collected from you (or your household). Note that this deletion right does not include Personal Information we have collected from third-party sources. Furthermore, under the CCPA, this deletion right is subject to certain exceptions: for example, we may need to retain your Personal Information to provide you with services or complete a transaction or other action you have requested. If your deletion request is subject to one of these exceptions, we may deny your deletion request.

Exercising Right To Access and/or Right to Deletion

If you are a California resident, and to exercise the rights described above, you (or someone acting under your express authorization) must send us a request that (a) provides sufficient information to allow us to verify that you are the person about whom we have collected Personal Information, and (b) describes your request in sufficient detail to allow us to understand, evaluate, and respond to it. If someone is submitting a request on your behalf, they must further (c) provide proof that they are authorized to act for you in this regard. In some cases, we may request additional information (such as your phone number or email address) in order to verify your request. If we cannot verify your identity, we will be unable to process your request to know/access, correct or delete.

Each request that meets both of these criteria will be considered a "Valid Request". We may not respond to requests that do not meet these criteria. We will only use Personal Information provided in a Valid Request to verify you and complete your request. You do not need an account to submit a Valid Request.

We will work to respond to your Valid Request within forty-five (45) days of receipt. If we are not able to respond to your request within forty-five (45) days, we will let you know that we may need additional time to respond, up to ninety (90) total days. We will not charge you a fee for making a Valid Request unless your Valid Request(s) is excessive, repetitive, or manifestly unfounded. If we determine that your Valid Request warrants a fee, we will notify you of the fee and explain that decision before completing your request.

Emailing us at: privacy@hundred.com

Right to Opt-Out of "Sale" or "Sharing" of Personal Information

The CCPA defines "sale" to include sharing or disclosing of Personal Information with a third-party for monetary or other valuable consideration. This may include when we share information about you that is associated with device identifiers with third-parties for targeted advertising purposes, and as generally described above. The CPRA further defines "sharing" as disclosing, making available, transferring, or communicating a consumer's Personal Information to a third party for "cross-context behavioral advertising", whether or not for monetary or other valuable consideration.

There are circumstances where disclosure of Personal Information with third-parties is not considered to be a sale. For example, we may disclose Personal Information with service providers who work on our behalf if the service provider agrees not to use that Personal Information for other purposes. In addition, you may intentionally direct us to disclose information to a third-party, which is also not a sale.

The CCPA gives California residents the right to direct a business that sells or shares Personal Information about that consumer to third-parties not to sell or share such information. To this end, if you desire to opt out, please send an email to: privacy@hundred.com with the subject line "California Do Not Sell Request" as well as the name and email associated with the Personal Information.

Once you have submitted an opt-out request, we will not ask you to reauthorize the sale or sharing of your Personal Information for at least twelve (12) months. However, you may change your mind and opt back in to Personal Information sales at any time by emailing us at: privacy@hundred.com

Right to Correct Inaccurate Personal Information

The CCPA provides California residents with the right to request the correction of inaccurate Personal Information kept by businesses. Upon submission of a valid request by a California resident, and verification by us of the same, we shall use commercially reasonable efforts to correct inaccurate Personal Information identified by you.

No Discrimination For Exercising Your Rights

We will not discriminate against you for exercising your rights under the CCPA. We will not deny you our goods or services, charge you different prices or rates, or provide you a lower quality of goods and services if you exercise your rights under the CCPA. However, we may offer different tiers of our services as allowed by applicable data privacy laws (including the CCPA) with varying prices, rates, or levels of quality of the goods or services you receive related to the value of persona data that we receive from you.

Authorized Agents

Authorized agents may also submit requests to us in the same way that individuals can submit requests. We may request that any authorized agents verify their identity, including by providing information about themselves, such as their name, email, phone number, and address. We may also contact consumers directly to confirm the authority of the authorized agent.

California Shine the Light Act

California Civil Code Section 1798.83 permits customers of a Company who are California residents to request and obtain from us once a year, free of charge, information about the personal information (if any) we disclosed to third parties for the third parties' direct marketing purposes in the preceding calendar year. If applicable, this information would include a list of the categories of personal information that was shared and the names and addresses of all third parties with which we shared information in the immediately preceding twelve (12) calendar months. If you are a California resident and would like to make such a request, please submit your request in writing to: GHOAT LLC 825 K Street, Fl. 2, Sacramento, CA, 95814 or email at: privacy@hundred.com

California Invasion of Privacy Act

By using the Services or accessing the Website, you hereby consent to our collection, use, and disclosure of your information consistent with this Privacy Policy, to the extent such information falls under any provision of the California Invasion of Privacy Act.

If there are any conflicts between this section and any other provision of this Privacy Policy and you are a California resident, the portion that is more protective of your Personal Information shall control.

ADDITIONAL INFORMATION FOR RESIDENTS OF OTHER STATES

If you are a resident of a state in the United States not otherwise mentioned in this Privacy Policy (e.g. any state other than California), we shall use our best efforts to honor your request to either delete, restrict the use of your Personal Information and opt-out of the sharing of your Personal Information with third parties. If you have any questions about this section or would like to make such request(s), please contact us at privacy@hundred.com

CHILDREN'S PRIVACY

We do not direct or target any of our Site, products, or services to children under the age of 13. If we learn that we have collected the Personal Information of anyone under the age of 13, we will take appropriate steps to delete this information. If you are a parent or guardian of someone under the age of 13 and discover that your child has submitted Personal Information to us, please contact us at privacy@hundred.com We will make reasonable efforts to remove such information from our databases.

NOTIFICATION OF CHANGES

We may revise this Privacy Policy from time to time. If we decide to change our Privacy Policy, we will post the revised policy here. If we make any material changes, we will notify you by email (sent to the e-mail address specified in your account) or by means of a notice on the top of this Privacy Policy or the top of the Website.

CONTACT INFORMATION

If you have any questions about the Privacy Policy or how we process Personal Information, please contact us at: GHOAT LLC 825 K Street, Fl. 2, Sacramento, CA, 95814, or email at: privacy@hundred.com