Bump2Tots LLC Privacy Policy
Version: 1.0
Effective Date: September 26, 2025
Last Updated: September 26, 2025
Table of Contents
- Introduction
- Definitions
- Data Collection
- Data Usage
- Data Sharing and Disclosures
- Data Storage and Security
- User Rights and Choices
- Consent Management
- Cookies and Tracking Technologies
- Special Provisions for Healthcare Data
- Communications
- Children’s Privacy
- Updates to Privacy Policy
- Contact Information
- Jurisdiction-Specific Addenda
1. Introduction
1.1 Purpose of the Policy
This Privacy Policy (“Policy”) describes how Bump2Tots LLC (“we,” “our,” or “us”), a mobile-based application focused on supporting parents through every stage of their journey, collects, uses, maintains, protects, and discloses your personal information and protected health information. This Policy applies to all information collected through our website (www.red-gaur-965611.hostingersite.com), mobile application, and any related services, sales, marketing, or events (collectively, the “Platform”).
1.2 Our Commitment to Privacy
At Bump2Tots, we are deeply committed to protecting your privacy and the security of your personal and health information. We understand the sensitive nature of health data and take our responsibility as custodians of this information seriously. Our commitment extends to compliance with all applicable laws and regulations in the jurisdictions where we operate, particularly focusing on U.S. legal frameworks.
1.3 General Approach to Data Protection and Compliance
We implement a comprehensive, multi-layered approach to data protection that includes:
- Technical Safeguards: Advanced encryption, secure servers, and regular security audits
- Administrative Controls: Staff training, access limitations, and comprehensive data handling policies
- Physical Security: Secure facilities for any physical records and hardware containing personal data
- Compliance Programs: Ongoing adherence to healthcare privacy standards including HIPAA, HITECH, and CCPA/CPRA (for California residents)
- Risk Assessment: Regular evaluation of potential vulnerabilities and implementation of preventive measures
By accessing or using our Platform, you agree to this Privacy Policy. If you do not agree with any part of this Policy, please do not use our services.
2. Definitions
2.1 Personal and Healthcare-Related Terms
Personal Data / Personal Information:
Any information relating to an identified or identifiable natural person (“data subject”).
Protected Health Information (PHI):
Any individually identifiable health information transmitted or maintained in any form or medium that relates to the past, present, or future physical or mental health or condition of an individual, or the provision of healthcare to an individual, as defined under HIPAA.
Sensitive Personal Information:
A subset of personal information that includes health information, biometric data, precise geo-location, racial or ethnic origin, religious beliefs, and other categories defined by applicable law as requiring special protection.
De-identified Information:
Information that has been processed to remove or obscure identifiers such that the information cannot reasonably identify an individual.
2.2 Role-Based Terms
- Data Controller: Bump2Tots LLC
- Data Processor: A third party that processes personal data on behalf of Bump2Tots LLC
- Covered Entity: A healthcare provider or organization as defined under HIPAA
- Business Associate: An entity that performs services involving PHI on behalf of a Covered Entity
- User / Patient: Any individual who uses our Platform
- Provider: Healthcare professionals providing services through our Platform
2.3 Technical and Legal Terms
- Processing: Any operation performed on personal data
- Consent: Freely given, informed, and unambiguous agreement
- Data Breach: Unauthorized access, disclosure, or loss of personal data or PHI
3. Data Collection
3.1 Personal Information
We collect personal information that you voluntarily provide when you register, contact us, or use the Platform. This may include full name, date of birth, gender, email address, mailing address, phone number, identification information for verification, profile pictures, authentication credentials, electronic signatures, and communication preferences.
3.2 Health Data
We collect health-related information including medical history, symptoms, allergies, medications, previous treatments, test results, family medical history, lifestyle information, treatment plans, healthcare provider notes, images or videos submitted for diagnostic purposes, and monitoring data from connected medical devices where applicable.
3.3 Technical Data
We automatically collect technical information such as IP address, device and browser information, operating system, geographic location (country and city level), pages visited, system activity, session duration, and analytics data.
3.4 How Data Is Collected
Information is collected directly from users, automatically through cookies and similar technologies, and from authorized healthcare providers or systems.
3.5 Legal Basis for Collection
Under U.S. law, including HIPAA, we collect and process data for healthcare services, healthcare operations, legal compliance, and with user consent where required.
4. Data Usage
We use personal and health information to establish and maintain user accounts, authenticate access, connect users with healthcare providers, facilitate telemedicine consultations, manage appointments, monitor health conditions, provide recommendations, and maintain medical records.
Internal Processing:
Clinical reviews, quality assurance, technical support, platform optimization, training, and record maintenance.
Research and Analytics:
With appropriate safeguards and consent where required, data may be used for research, analytics, and quality improvement initiatives.
Limitations:
We do not sell personal information or protected health information and only use data for purposes disclosed in this Policy.
5. Data Sharing and Disclosures
We may share information with healthcare providers, technology and hosting vendors, analytics services, and regulatory authorities as required by law. All sharing follows the minimum necessary standard and confidentiality obligations.
6. Data Storage and Security
We store information securely using encryption and access controls. Data retention is based on legal, regulatory, and operational requirements. Data is securely deleted or anonymized when no longer required.
7. User Rights and Choices
You may request access, correction, deletion, restriction, or objection to processing of your personal information by contacting privacy@red-gaur-965611.hostingersite.com.
8. Consent Management
Consent is obtained through registration, digital forms, and explicit opt-in mechanisms. Consent may be withdrawn at any time.
9. Cookies and Tracking Technologies
We use cookies and similar technologies to maintain security, improve user experience, analyze performance, and support platform functionality. Cookie preferences can be managed through browser settings.
10. Special Provisions for Healthcare Data
We comply with HIPAA and other applicable healthcare privacy laws, implementing safeguards to protect PHI and manage breach notifications.
11. Communications
We send account notifications, appointment updates, medical information, service announcements, and policy updates. Marketing communications are sent only with explicit consent and include opt-out options.
12. Children’s Privacy
The Platform is not intended for children under 13 years of age. Users between 13 and 18 may access the Platform only with parental or guardian involvement. Enhanced safeguards apply to protect minors’ data.
13. Updates to Privacy Policy
We may update this Privacy Policy periodically. Material changes will be communicated through appropriate channels.
14. Contact Information
Data Protection Officer
Name: Purvi Shah
Title: Chief Privacy Officer, Bump2Tots LLC
Email: dpo@red-gaur-965611.hostingersite.com
General Privacy Contact: privacy@red-gaur-965611.hostingersite.com
15. Jurisdiction-Specific Addenda
We comply with HIPAA, HITECH, CCPA, CPRA, and other applicable U.S. privacy and healthcare laws.
Conclusion
This Privacy Policy demonstrates Bump2Tots LLC’s commitment to protecting personal information and health data while providing telemedicine services.
© 2025 Bump2Tots LLC. All Rights Reserved.