Updated: May 6, 2026
SUMMARY OF KEY POINTS
This summary provides key points from our privacy notice, but you can find out more details about any of these topics by clicking the link following each key point or by using our table of contents below to find the section you are looking for.
What personal information do we process? When you visit, use, or navigate our Services, including the TandemStride mobile application, TandemStride Connect, and Communities ("Service" and "Services")., we may process personal information depending on how you interact with TandemStride and the Services, the choices you make, and the products and features you use. This may include information you provide to us, Community Content, mood check-ins, reports, reactions, comments, usage data, and related metadata. Learn more about personal information you disclose to us.
Do we process any sensitive personal information? We may process sensitive personal information, including health data, trauma and recovery information, mood check-ins, health-related Community Content, and other information you choose to share, when necessary with your consent or as otherwise permitted by applicable law. As a healthcare technology platform, we handle Protected Health Information (PHI) in compliance with HIPAA regulations and applicable Business Associate Agreements. Learn more about sensitive information we process.
Do we receive any information from third parties? We may receive information from public databases, marketing partners, social media platforms, and other outside sources. Learn more about information collected from other sources.
How do we process your information? We process your information to provide, improve, moderate, secure, and administer our Services, communicate with you, support peer matching and Communities, respond to safety concerns, for security and fraud prevention, and to comply with law. We may use artificial intelligence (“AI”)-enabled tools and service providers to support these activities, and we may also process your information for other purposes with your consent. We process your information only when we have a valid legal reason to do so. Learn more about how we process your information.
In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties, including healthcare providers, peer support networks, service providers, community infrastructure providers, AI-enabled tools, and safety escalation recipients as described in this notice. Learn more about when and with whom we share your personal information.
Do we use AI-enabled tools? We may use AI-enabled tools and service providers to operate, support, secure, personalize, evaluate, improve, and moderate TandemStride, including to support peer matching, summarize information, assist support workflows, detect misuse, moderate Community Content, and evaluate app performance. We will request separate consent where required before using identifiable personal information, health-related information, or PHI for optional AI model training or fine-tuning.
What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information. Learn more about your privacy rights.
How do you exercise your rights? The easiest way to exercise your rights is by submitting a data subject access request, or by contacting us. We will consider and act upon any request in accordance with applicable data protection laws.
TABLE OF CONTENTS
1. WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
In Short:We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
Personal Information Provided by You. The personal information that we collect depends on the context of your interactions with us and the Services, including the TandemStride mobile application, TandemStride Connect, Communities, and related features, the choices you make, and the products and features you use. The personal information we collect may include the following:
Names
Phone numbers
Email addresses
Mailing addresses
Usernames
Passwords
Contact preferences
Trauma experience information
Peer support preferences
Community Content, including posts, journal responses, comments, tags, reactions, and other content you choose to submit through Communities
Daily mood check-in selections, including selections such as Heavy, Balanced, or Hopeful
Reports, report reasons, flagged content, blocking activity, moderation requests, and related safety communications
Information you choose to share about your injury, recovery, symptoms, needs, preferences, lived experience, family experience, peer support goals, and community interactions
Sensitive Information. When necessary, with your consent or as otherwise permitted by applicable law, we process the following categories of sensitive information, including sensitive information you choose to provide through Communities:
Health data
Information about traumatic injuries and recovery
Medical treatment history (when voluntarily shared for peer matching purposes)
Health-related Community Content, mood check-ins, recovery-related journal responses, trauma-related posts or comments, and information that may reveal physical health, mental health, disability, injury, treatment, recovery, social needs, or peer support needs
As a healthcare technology platform, we handle Protected Health Information (PHI) in compliance with the Health Insurance Portability and Accountability Act (HIPAA) and applicable Business Associate Agreements. We maintain appropriate safeguards to protect the confidentiality, integrity, and availability of PHI as required by law and as detailed in our Business Associate Agreement.
Social Media Login Data. We may provide you with the option to register with us using your existing social media account details, like your Facebook, Twitter, or other social media account. If you choose to register in this way, we will collect the information described in the section called "HOW DO WE HANDLE YOUR SOCIAL LOGINS?" below.
Application Data. If you use our application(s), we also may collect the following information if you choose to provide us with access or permission:
Mobile Device Data. We automatically collect device information (such as your mobile device ID, model, and manufacturer), operating system, version information and system configuration information, device and application identification numbers, browser type and version, hardware model Internet service provider and/or mobile carrier, and Internet Protocol (IP) address (or proxy server). If you are using our application(s), we may also collect information about the phone network associated with your mobile device, your mobile device's operating system or platform, the type of mobile device you use, your mobile device's unique device ID, and information about the features of our application(s) you accessed.
Push Notifications. We may request to send you push notifications regarding your account or certain features of the application(s). If you wish to opt out from receiving these types of communications, you may turn them off in your device's settings.
This information is primarily needed to maintain the security and operation of our application(s), for troubleshooting, for moderation and safety purposes, and for our internal analytics and reporting purposes.
Health Data and Advertising. We do not use health data, health-related Community Content, PHI, mood check-ins, or other sensitive health-related information for targeted advertising. We may use limited, aggregated, de-identified, or non-identifying information to understand service performance and improve TandemStride, where permitted by applicable law and contract.
Community Content Visibility. Community Content you submit may be visible to other community members and may be viewed, reacted to, commented on, reported, or otherwise engaged with by other users. Do not submit Community Content that you do not want other community members or TandemStride to see. Daily mood check-in selections may be stored individually but are displayed to other users only in aggregate unless we expressly disclose otherwise.
Communities Data. For purposes of this Privacy Policy, "Communities" refers to TandemStride's peer-support community features, including check-ins, journal prompts, posts, comments, reactions, tags, reporting, blocking, and related interactive features. If you use Communities, we collect content you voluntarily submit, including posts, journal responses, comments, tags, reactions, and other Community Content. We also collect your daily mood check-in selections, which are stored individually but displayed to other users only in aggregate. We collect information about how you interact with Communities, including content you create, view, react to, comment on, report, block, or otherwise engage with. We may collect moderation and safety records, including report reasons, flagged content, moderation actions, escalation records, audit records, and related communications. We do not use the text of your posts, journal responses, or comments in our analytics layer unless we expressly disclose otherwise; analytics may include structured metadata and engagement signals.
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
Terms of Use. Your use of the Services, including the TandemStride mobile application, TandemStride Connect, and Communities, is also governed by our Terms of Use and End User License Agreement. The Terms of Use describe user responsibilities, community rules, content restrictions, moderation rights, safety escalation, account restrictions, and other conditions that apply to your use of TandemStride.
Acceptable Use Policy. Community posts, journal responses, comments, reactions, reports, blocking activity, and related moderation activity are subject to the TandemStride Acceptable Use Policy available at https://tandemstride.com/acceptable-use-policy. We may use Community Content, report data, moderation data, blocking data, and related account information to operate Communities, enforce our policies, protect member safety, investigate potential violations, and support clinical safety escalation where appropriate.
Information automatically collected
In Short:Some information — such as your Internet Protocol (IP) address and/or browser and device characteristics — is collected automatically when you visit our Services.
We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.
The information we collect includes:
Log and Usage Data. Log and usage data is service-related, diagnostic, usage, moderation, security, and performance information our servers automatically collect when you access or use our Services and which we record in log files. Depending on how you interact with us, this log data may include your IP address, device information, browser type, settings, and information about your activity in the Services (such as the date/time stamps associated with your usage, pages and files viewed, searches, content creation, views, reactions, reports, blocking activity, moderation events, and other actions you take such as which features you use), device event information (such as system activity, error reports (sometimes called "crash dumps"), and hardware settings).
Information collected from other sources
In Short:We may collect limited data from public databases, marketing partners, social media platforms, and other outside sources.
In order to enhance our ability to provide relevant marketing, offers, and services to you and update our records, we may obtain information about you from other sources, such as public databases, joint marketing partners, affiliate programs, data providers, social media platforms, and from other third parties. This information includes mailing addresses, job titles, email addresses, phone numbers, intent data (or user behavior data), Internet Protocol (IP) addresses, social media profiles, social media URLs, and custom profiles, for purposes of targeted advertising and event promotion. If you interact with us on a social media platform using your social media account (e.g., Facebook or Twitter), we receive personal information about you such as your name, email address, and gender. Any personal information that we collect from your social media account depends on your social media account's privacy settings.
2. HOW DO WE PROCESS YOUR INFORMATION?
In Short: We process your information to provide, improve, moderate, secure, and administer our Services, communicate with you, support peer matching and Communities, respond to safety concerns, for security and fraud prevention, and to comply with law. We may use AI-enabled tools and service providers to support these activities, and we may also process your information for other purposes with your consent.
Safety and Emergency Limitations. TandemStride may use human review, automated tools, AI-enabled tools, reports, and safety escalation workflows to support community safety, but we do not guarantee that we will monitor all content, identify every safety concern, intervene in every situation, provide crisis services, or contact emergency services. If you believe you or another person may be experiencing an emergency, call 911 or local emergency services.
We process your personal information for a variety of reasons, depending on how you interact with our Services, including:
To facilitate account creation and authentication and otherwise manage user accounts. We may process your information so you can create and log in to your account, as well as keep your account in working order.
To deliver and facilitate delivery of services to the user. We may process your information to provide you with the requested service, including facilitating peer support connections for trauma survivors, operating Communities, and supporting related peer interactions.
To respond to user inquiries/offer support to users. We may process your information to respond to your inquiries and solve any potential issues you might have with the requested service.
To enable user-to-user communications. We may process your information if you choose to engage with our peer support platform, Communities, posts, comments, journal prompts, reactions, check-ins, or related features to connect with other trauma survivors or mentors.
To fulfill and manage your orders. We may process your information to fulfill and manage your orders, payments, returns, and exchanges made through the Services.
To protect our Services. We may process your information as part of our efforts to keep our Services safe and secure, including fraud monitoring, misuse detection, content moderation, safety escalation, abuse prevention, and security monitoring.
To comply with our legal obligations. We may process your information to comply with our legal obligations, including HIPAA regulations and other healthcare laws.
To evaluate and improve our Services, products, marketing, and your experience. We may process your information when we believe it is necessary to identify usage trends, determine the effectiveness of our promotional campaigns, evaluate app performance, support peer matching, improve Communities, and evaluate and improve our Services, products, marketing, and your experience.
For optional AI model-improvement use with consent. If we ask for your consent, we may use information you provide, including health-related information, to help develop, train, evaluate, and improve TandemStride's AI-enabled features. This use is optional. You may continue using TandemStride without agreeing to optional AI model-improvement use, and you may withdraw your consent for future use at any time.
To use AI-enabled tools. We may use AI-enabled tools and service providers to operate, support, secure, personalize, evaluate, improve, and moderate TandemStride. For example, these tools may help us summarize information, support peer matching, improve user experience, assist our team in responding to user requests, detect misuse, moderate Community Content, and evaluate app performance. Our service providers may process information only on our behalf, only as necessary to provide services to TandemStride, and only as permitted by their agreements with us.
To operate Communities. We process Community Content, mood check-ins, reactions, comments, reports, blocking activity, moderation records, and engagement events to provide Communities, display content to community members, support peer interactions, administer community features, and maintain community safety.
5. HOW LONG DO WE KEEP YOUR INFORMATION?
In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this privacy notice, operate and secure the Services, maintain Communities, comply with legal and contractual obligations, support safety and moderation, and satisfy audit, backup, dispute, and retention requirements.
We keep personal information for as long as reasonably necessary to fulfill the purposes described in this privacy notice, provide the Services, operate and secure TandemStride, maintain Communities, comply with legal and contractual obligations, resolve disputes, enforce our legal terms, maintain audit and safety records, and support legitimate business needs. Retention periods may vary by data category, account status, applicable law, contractual obligations, legal holds, safety needs, and technical constraints.
For Protected Health Information (PHI), we maintain, use, disclose, return, destroy, or retain PHI in accordance with HIPAA regulations, applicable Business Associate Agreements, applicable contracts, and applicable law. Upon termination of our services, we will return or destroy PHI as directed by the covered entity to the extent feasible, unless retention is required or permitted by law, contract, legal hold, audit, backup, safety, or technical requirements.
For Communities, we may retain Community Content, mood check-ins, reports, moderation records, safety escalation records, audit logs, and related metadata for as long as needed to operate Communities, maintain platform safety, document moderation and safety decisions, comply with law or contract, support audits and investigations, and enforce our legal terms. If you delete Community Content or request account deletion, Community Content may be removed from active display or deactivated, but copies may remain in backups, audit logs, safety records, reports, moderation records, legal records, community infrastructure provider systems, or records retained for legal, HIPAA, contractual, security, safety, audit, dispute, or platform-integrity purposes.
HIPAA does not create a single universal medical-record retention period. HIPAA does require certain HIPAA documentation to be retained for six years from creation or last effective date. State law, payer requirements, Business Associate Agreements, services agreements, health plan contracts, legal holds, and other obligations may require different or longer retention periods.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
6. DO WE COLLECT INFORMATION FROM MINORS?
In Short: We do not knowingly collect data from or market to children under 18 years of age, and our Services are intended for users who are 18 years of age or older unless we expressly state otherwise and implement required consent, notice, age-gating, and privacy controls.
We do not knowingly solicit data from or market to children under 18 years of age. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent's use of the Services where minor use is expressly permitted by TandemStride. Our Services are intended for users who are 18 years of age or older unless we expressly state otherwise and implement any required consent, notice, age-gating, and privacy controls. If we learn that personal information from users less than 18 years of age has been collected without required consent or controls, we will deactivate the account and take reasonable measures to promptly delete or restrict such data from our records, subject to legal, safety, audit, backup, and technical retention requirements. If you become aware of any data we may have collected from children under age 18, please contact us at support@tandemstride.com.
To comply with the Children's Online Privacy Protection Act (COPPA), TandemStride is not allowed to collect or store information from a minor without any legally required consent and controls. Thus, while using the platform you agree to coordinate care only with the Minor's parent or guardian (e.g., do not invite a Minor directly) and not cause TandemStride to store information directly from the Minor unless TandemStride has expressly authorized that workflow and implemented required consent, notice, age-gating, and privacy controls.
7. WHAT ARE YOUR PRIVACY RIGHTS?
In Short: You may review, change, or terminate your account at any time.
Withdrawing your consent: If we are relying on your consent to process your personal information, which may be express and/or implied consent depending on the applicable law, you have the right to withdraw your consent at any time. If you consent to optional AI model-improvement use, you may withdraw that consent for future use at any time through the controls we make available or by contacting us. You can withdraw your consent at any time by contacting us by using the contact details provided in the section "HOW CAN YOU CONTACT US ABOUT THIS NOTICE?" below.
However, please note that this will not affect the lawfulness of the processing before its withdrawal nor, when applicable law allows, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent, including processing needed to provide, secure, moderate, support, or operate the Services.
Account Information
If you would at any time like to review or change the information in your account or terminate your account, you can:
Contact us using the contact information provided.
Upon your request to terminate or delete your account, we will delete or deactivate your TandemStride account and associated personal information from active systems, subject to legal, HIPAA, contractual, security, safety, audit, backup, dispute, fraud-prevention, moderation, and technical exceptions described in this Privacy Policy. Your authentication account may be deleted separately from Community Content and related records. Community Content you submitted may be deactivated or removed from active display, meaning it is no longer accessible within the app or returned to other users, but it may not be permanently deleted from all community infrastructure provider systems, backups, audit logs, safety records, reports, moderation records, legal records, or records retained for legally permitted purposes at the time of account deletion.
If you have questions or comments about your privacy rights, you may email us at support@tandemstride.com.
8. CONTROLS FOR DO-NOT-TRACK FEATURES
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this privacy notice.
9. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: If you are a resident of a U.S. state with an applicable consumer privacy law, you may be granted specific rights regarding access to and control of your personal information.
What categories of personal information do we collect?
We have collected the following categories of personal information in the past twelve (12) months:
A. Identifiers: Contact details, such as real name, alias, postal address, telephone or mobile contact number, unique personal identifier, online identifier, Internet Protocol address, email address, and account name.
B. Personal information as defined in the California Customer Records statute: Name, contact information, education, employment, employment history, and financial information.
C. Protected classification characteristics under state or federal law: Gender and date of birth.
D. Commercial information: Transaction information, purchase history, financial details, and payment information.
E. Internet or other similar network activity: Browsing history, search history, online behavior, interest data, content views, reactions, reports, blocking activity, moderation events, and interactions with our and other websites, applications, systems, Communities, and advertisements.
F. Geolocation data: Device location.
G. Audio, electronic, visual, thermal, olfactory, or similar information: Images and audio, video or call recordings created in connection with our business activities.
H. Professional or employment-related information: Business contact details in order to provide you our Services at a business level or job title, work history, and professional qualifications if you apply for a job with us.
I. Inferences drawn from collected personal information: Inferences drawn from any of the collected personal information listed above to create a profile or summary about, for example, an individual's preferences, peer support needs, recovery-related preferences, and characteristics.
J. Sensitive personal Information: Contents of email or text messages, health data, trauma and recovery information, health-related Community Content, mood check-ins, account login information, and other sensitive information you choose to provide.
We will use and retain the collected personal information as needed to provide the Services or for:
Category B - As long as reasonably necessary to provide the Services or as otherwise described in this notice
Category J - As long as reasonably necessary to provide the Services or as otherwise described in this notice
Sensitive personal information may be used, or disclosed to a service provider or contractor, for the purposes described in this notice, including to provide, secure, moderate, support, and improve the Services. You may have the right to limit the use or disclosure of your sensitive personal information where applicable law provides that right.
We may also collect other personal information outside of these categories through instances where you interact with us in person, online, or by phone or mail in the context of:
Receiving help through our customer support channels;
Participation in customer surveys or contests; and
Facilitation in the delivery of our Services and to respond to your inquiries.
How do we use and share your personal information?
Learn about how we use your personal information in the section, "HOW DO WE PROCESS YOUR INFORMATION?"
Will your information be shared with anyone else?
We may disclose your personal information with our service providers pursuant to a written contract between us and each service provider. Learn more about how we disclose personal information to in the section, "WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?"
We may use your personal information for our own business purposes, such as undertaking internal research, technological development, evaluation, safety, security, moderation, and service improvement, as described in this notice. We will request separate consent where required before using identifiable personal information, health-related information, or PHI for optional AI model training or fine-tuning. This is not considered to be "selling" of your personal information.
We do not sell personal information. We may disclose personal information to service providers, contractors, healthcare providers, peer support networks, community infrastructure providers, AI-enabled service providers, and other third parties for the business and operational purposes described in this notice. We will not sell or share personal information in the future belonging to website visitors, users, and other consumers without providing any notice and choice required by applicable law.
California Residents
California Civil Code Section 1798.83, also known as the "Shine The Light" law permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us using the contact information provided below.
If you are under 18 years of age, reside in California, and have a registered account with the Services, you have the right to request removal of unwanted data that you publicly post on the Services. To request removal of such data, please contact us using the contact information provided below and include the email address associated with your account and a statement that you reside in California. We will make sure the data is not publicly displayed on the Services, but please be aware that the data may not be completely or comprehensively removed from all our systems (e.g., backups, etc.).
CCPA Privacy Notice
This section applies only to California residents. Under the California Consumer Privacy Act (CCPA), you have the rights listed below.
The California Code of Regulations defines a "residents" as:
(1) every individual who is in the State of California for other than a temporary or transitory purpose and (2) every individual who is domiciled in the State of California who is outside the State of California for a temporary or transitory purpose
All other individuals are defined as "non-residents."
If this definition of "resident" applies to you, we must adhere to certain rights and obligations regarding your personal information.
Your rights with respect to your personal data
Right to request deletion of the data — Request to delete
You can ask for the deletion of your personal information. If you ask us to delete your personal information, we will respect your request and delete your personal information, subject to certain exceptions provided by law, such as (but not limited to) the exercise by another consumer of his or her right to free speech, our compliance requirements resulting from a legal obligation, or any processing that may be required to protect against illegal activities.
Right to be informed — Request to know
Depending on the circumstances, you have a right to know:
whether we collect and use your personal information;
the categories of personal information that we collect;
the purposes for which the collected personal information is used;
whether we sell or share personal information to third parties;
the categories of personal information that we sold, shared, or disclosed for a business purpose;
the categories of third parties to whom the personal information was sold, shared, or disclosed for a business purpose;
the business or commercial purpose for collecting, selling, or sharing personal information; and
the specific pieces of personal information we collected about you.
In accordance with applicable law, we are not obligated to provide or delete consumer information that is de-identified in response to a consumer request or to re-identify individual data to verify a consumer request.
Right to Non-Discrimination for the Exercise of a Consumer’s Privacy Rights
We will not discriminate against you if you exercise your privacy rights.
Right to Limit Use and Disclosure of Sensitive Personal Information
If the business collects any of the following:
social security information, drivers' licenses, state ID cards, passport numbers
account login information
credit card numbers, financial account information, or credentials allowing access to such accounts
precise geolocation
racial or ethnic origin, religious or philosophical beliefs, union membership
the contents of email and text, unless the business is the intended recipient of the communication
genetic data, biometric data, and health data
data concerning sexual orientation and sex life
you have the right to direct that business to limit its use of your sensitive personal information to that use which is necessary to perform the Services.
Once a business receives your request, they are no longer allowed to use or disclose your sensitive personal information for any other purpose unless you provide consent for the use or disclosure of sensitive personal information for additional purposes.
Please note that sensitive personal information that is collected or processed without the purpose of inferring characteristics about a consumer is not covered by this right, as well as the publicly available information.
To exercise your right to limit use and disclosure of sensitive personal information, please email support@tandemstride.com or submit a data subject access request.
Verification process
Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. These verification efforts require us to ask you to provide information so that we can match it with information you have previously provided us. For instance, depending on the type of request you submit, we may ask you to provide certain information so that we can match the information you provide with the information we already have on file, or we may contact you through a communication method (e.g., phone or email) that you have previously provided to us. We may also use other verification methods as the circumstances dictate.
We will only use personal information provided in your request to verify your identity or authority to make the request. To the extent possible, we will avoid requesting additional information from you for the purposes of verification. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes. We will delete such additionally provided information as soon as we finish verifying you.
Other privacy rights
You may object to the processing of your personal information.
You may request correction of your personal data if it is incorrect or no longer relevant, or ask to restrict the processing of the information.
You can designate an authorized agent to make a request under the CCPA on your behalf. We may deny a request from an authorized agent that does not submit proof that they have been validly authorized to act on your behalf in accordance with the CCPA.
You may request to opt out from future selling or sharing of your personal information to third parties. Upon receiving an opt-out request, we will act upon the request as soon as feasibly possible, but no later than fifteen (15) days from the date of the request submission.
To exercise these rights, you can contact us by submitting a data subject access request, by email at support@tandemstride.com, by using any applicable in-app privacy controls we make available, or by referring to the contact details at the bottom of this document. If you have a complaint about how we handle your data, we would like to hear from you.
Colorado Residents
This section applies only to Colorado residents. Under the Colorado Privacy Act (CPA), you have the rights listed below. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law.
Right to be informed whether or not we are processing your personal data
Right to access your personal data
Right to correct inaccuracies in your personal data
Right to request deletion of your personal data
Right to obtain a copy of the personal data you previously shared with us
Right to opt out of the processing of your personal data if it is used for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ("profiling")
To submit a request to exercise these rights described above, please email support@tandemstride.com or submit a data subject access request.
If we decline to take action regarding your request and you wish to appeal our decision, please email us at support@tandemstride.com. Within forty-five (45) days of receipt of an appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions.
Connecticut Residents
This section applies only to Connecticut residents. Under the Connecticut Data Privacy Act (CTDPA), you have the rights listed below. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law.
Right to be informed whether or not we are processing your personal data
Right to access your personal data
Right to correct inaccuracies in your personal data
Right to request deletion of your personal data
Right to obtain a copy of the personal data you previously shared with us
Right to opt out of the processing of your personal data if it is used for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ("profiling")
To submit a request to exercise these rights described above, please email support@tandemstride.com or submit a data subject access request.
If we decline to take action regarding your request and you wish to appeal our decision, please email us at support@tandemstride.com. Within sixty (60) days of receipt of an appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions.
Utah Residents
This section applies only to Utah residents. Under the Utah Consumer Privacy Act (UCPA), you have the rights listed below. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law.
Right to be informed whether or not we are processing your personal data
Right to access your personal data
Right to request deletion of your personal data
Right to obtain a copy of the personal data you previously shared with us
Right to opt out of the processing of your personal data if it is used for targeted advertising or the sale of personal data
To submit a request to exercise these rights described above, please email support@tandemstride.com or submit a data subject access request.
Virginia Residents
Under the Virginia Consumer Data Protection Act (VCDPA):
"Consumer" means a natural person who is a resident of the Commonwealth acting only in an individual or household context. It does not include a natural person acting in a commercial or employment context.
"Personal data" means any information that is linked or reasonably linkable to an identified or identifiable natural person. "Personal data" does not include de-identified data or publicly available information.
"Sale of personal data" means the exchange of personal data for monetary consideration.
If this definition of "consumer" applies to you, we must adhere to certain rights and obligations regarding your personal data.
Your rights with respect to your personal data
Right to be informed whether or not we are processing your personal data
Right to access your personal data
Right to correct inaccuracies in your personal data
Right to request deletion of your personal data
Right to obtain a copy of the personal data you previously shared with us
Right to opt out of the processing of your personal data if it is used for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ("profiling")
Exercise your rights provided under the Virginia VCDPA
You may contact us by email at support@tandemstride.com or submit a data subject access request.
If you are using an authorized agent to exercise your rights, we may deny a request if the authorized agent does not submit proof that they have been validly authorized to act on your behalf.
Verification process
We may request that you provide additional information reasonably necessary to verify you and your consumer's request. If you submit the request through an authorized agent, we may need to collect additional information to verify your identity before processing your request.
Upon receiving your request, we will respond without undue delay, but in all cases, within forty-five (45) days of receipt. The response period may be extended once by forty-five (45) additional days when reasonably necessary. We will inform you of any such extension within the initial 45-day response period, together with the reason for the extension.
Right to appeal
If we decline to take action regarding your request, we will inform you of our decision and reasoning behind it. If you wish to appeal our decision, please email us at support@tandemstride.com. Within sixty (60) days of receipt of an appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If your appeal is denied, you may contact the Attorney General to submit a complaint.
10. DO WE MAKE UPDATES TO THIS NOTICE?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this privacy notice from time to time. The updated version will be indicated by an updated "Revised" date and the updated version will be effective as soon as it is accessible. If we make material changes to this privacy notice, including changes involving Communities, AI-enabled tools, service providers, account deletion, retention, or the Terms of Use, we may notify you by prominently posting a notice of such changes, directly sending you a notification, or presenting an in-app notice or consent flow where appropriate. We encourage you to review this privacy notice frequently to be informed of how we are protecting your information.
11. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have questions or comments about this notice, you may email us at support@tandemstride.com or contact us by post at:
TandemStride, Inc. 1250 Waterfront Place, Suite 500 Cleveland, OH 44114 United States
12. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
Based on the applicable laws of your country or state, you may have the right to request access to the personal information we collect from you, change that information, delete it, or withdraw certain consents. To request to review, update, or delete your personal information, please fill out and submit a data subject access request or use any applicable in-app account controls we make available. Account deletion and content deletion may be subject to the retention exceptions described in this notice.
13. HIPAA COMPLIANCE AND PHI PROTECTION
TandemStride is committed to protecting the privacy and security of Protected Health Information (PHI) in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA). As a business associate of healthcare providers and other covered entities where applicable, we have implemented administrative, physical, and technical safeguards designed to protect PHI from unauthorized access, use, or disclosure.
Our collection, use, and disclosure of PHI are governed by our Business Associate Agreements (BAAs) with healthcare providers and other covered entities where applicable. We will use or disclose PHI only as permitted by the applicable BAA, our Terms of Use, this Privacy Policy, and applicable law. We may use service providers and subcontractors, including infrastructure, support, analytics, moderation, and AI-enabled service providers, to provide the Services, provided that we use appropriate contractual safeguards, including a BAA where required. For more information about our HIPAA compliance program, please review our Business Associate Agreement.
4. HOW DO WE HANDLE YOUR SOCIAL LOGINS?
In Short: If you choose to register or log in to our Services using a social media account, we may have access to certain information about you.
Our Services offer you the ability to register and log in using your third-party social media account details (like your Facebook or Twitter logins). Where you choose to do this, we will receive certain profile information about you from your social media provider. The profile information we receive may vary depending on the social media provider concerned, but will often include your name, email address, friends list, and profile picture, as well as other information you choose to make public on such a social media platform.
We will use the information we receive only for the purposes that are described in this privacy notice or that are otherwise made clear to you on the relevant Services. Please note that we do not control, and are not responsible for, other uses of your personal information by your third-party social media provider. We recommend that you review their privacy notice to understand how they collect, use, and share your personal information, and how you can set your privacy preferences on their sites and apps.