Privacy Policy

Date of Last Revision:

Oct 13, 2025

This Privacy Policy (“Privacy Policy”) describes the data protection practices of Bask Health, Inc. and its affiliates (collectively, “Bask,” “we,” “our,” or “us”) when you visit any Bask website that links to this Privacy Policy (collectively, our “Websites”), use any affiliated mobile applications (the “Apps”), or otherwise provide data to Bask. We refer to the Websites, Apps, and other services provided by Bask together in this Privacy Policy as the “Services.”

This Privacy Policy describes how we collect and process personal information relating to individual contacts and users who are our customers and prospective customers (each a “Customer”).

THIS PRIVACY POLICY DOES NOT APPLY TO INFORMATION ABOUT OUR CUSTOMERS’ PATIENTS, INCLUDING ANY PROTECTED HEALTH INFORMATION (“PHI”) CUSTOMERS INPUT INTO THE SERVICES OR OTHERWISE SHARE WITH US IN CONNECTION WITH THEIR USE OF THE SERVICES. INFORMATION ABOUT OUR CUSTOMERS’ PATIENTS IS SUBJECT TO THE PRIVACY POLICIES OF THE CUSTOMER.

IF YOU ARE A PATIENT AND HAVE QUESTIONS CONCERNING YOUR PERSONAL INFORMATION, INCLUDING HOW BASK PROCESSES YOUR PERSONAL INFORMATION ON BEHALF OF YOUR CARE PROVIDER, PLEASE CONTACT THE CUSTOMER (THE HEALTH/ WELLNESS BRAND) THAT IS YOUR CARE PROVIDER DIRECTLY.

1. Personal Information We Collect

Personal information that you may provide to us, including:

  • Contact information, such as your first and last name, phone number, and email address.

  • Account information, such as the username and password you use to log into your account.

  • Identification information, such as your date of birth, Social Security number, business details, government identification, and photo.

  • Payment information, needed to complete any transactions with us, including your name, payment card information, and billing information.

  • Feedback or correspondence, such as information you provide when you contact us with questions, feedback, or otherwise correspond with us online.

  • Marketing information, such as your preferences for receiving our communications, and details about how you engage with our communications.

  • Other data not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection.

Personal information we collect automatically: We, our service providers and our business partners may automatically log information about you, your computer or mobile device, and your interactions over time with our Services and our communications. We collect this information using cookies, pixels and other similar technologies. This information includes:

  • Device data, such as your computer’s or mobile device’s operating system type and version, manufacturer and model, browser type, screen resolution, device type (e.g., phone, tablet), IP address, unique identifiers (including identifiers used for advertising purposes), language settings and general location information such as city, state or geographic area.

  • Online activity data, such as pages or screens you viewed, the website you visited before browsing to the Services, navigation paths between pages or screens, information about your activity on a page or screen, access times, and whether you have opened or otherwise engage with our communications, such as our marketing emails or clicked links or files within them. We also employ session replay technologies that allow us to replay and view any actions you take within the Services.

  • Precise location. With your consent, we may collect your location information through the device you use to access the Services. You can disable location sharing through your device settings.

Personal information we obtain from third parties:

  • Social media information. We may maintain pages on social media platforms, such as Facebook, X (formerly Twitter), Instagram, LinkedIn, Slack, GitHub and other third-party platforms. When you visit or interact with our pages on those platforms, the platform provider’s privacy policy will apply to your interactions and their collection, use and processing of your personal information. You or the platforms may provide us with information through the platform, and we will treat such information in accordance with this Privacy Policy.

  • Third-party login information. When you link, connect, or login to the Services with a third party service (such as Google), you direct the service to send us information (e.g., contact information) controlled by that service or as authorized by you via your privacy settings at that service. The information we receive when you authenticate through a third-party service depends on the settings, permissions and privacy policy controlled by that third-party service. You should always check the privacy settings and notices in the relevant third-party services to understand what data may be disclosed to us or shared with us.

  • Other sources. We may obtain personal information (e.g., demographic information) from other third parties, such as marketing partners, publicly-available sources, and data providers. We also work closely with certain third parties (including, for example, third party intermediaries, such as the medical professionals, pharmacies, advertising networks, analytics providers and search information providers with whom we partner to provide the Services). Such third parties will sometimes provide us with additional information about you.

2. How We Use Personal Information

We use personal information for the following purposes or as otherwise described at the time of collection:

To provide, operate and maintain the Services. We use personal information to operate, maintain, and provide you with our Services, including to facilitate payments and optimize your user experience.

To facilitate your login to the Services via third-party identity and access management providers. We use personal information to enable you to access our Services through third-party providers, increasing access options and efficiency of using the Services.

To establish and maintain your user account on the Services. We will use your personal information to facilitate the creation, operation, and maintenance of your user account as part of the Services for purposes of personalizing your user experience. To communicate with you about the Services. We will use your personal information to respond to your requests, questions and feedback, and communicate with you about our Services, including by sending announcements, updates, security alerts and support and administrative messages.

To communicate with you about the Services. We will use your personal information to respond to your requests, questions and feedback, and communicate with you about our Services, including by sending announcements, updates, security alerts and support and administrative messages.

To improve, monitor, personalize, and protect our Services. We use your personal information to improve and keep our Services safe for our users, this includes:

  • Understanding your needs and interests, and personalizing your experience with the Services and our communications.

  • Troubleshooting, testing and researching, and keeping the Services secure.

For research and development. We may use personal information for research and development purposes, including to analyze and improve the Services and our business. As part of these activities, we may create or use aggregated, de-identified, or other anonymized data from personal information we collect. We make personal information into anonymized data by removing information that makes the data personally identifiable to you. We may use this anonymized data and share it with third parties for our lawful business purposes, including to analyze and improve the Services and promote our business.

For marketing and advertising. We, our service providers, and our third-party marketing and advertising partners may collect and use personal information for the following marketing and advertising purposes:

  • Direct marketing. We may from time-to-time send you direct marketing communications as permitted by law, including, but not limited to, sending you newsletters and notifying you of special promotions, offers and events that we think may be of interest to you as permitted by law, including by email. You may opt out of our marketing communications as described in the “Opt-out of marketing communications” section below.

  • Interest-based advertising. We may engage third-party advertising partners, including third party advertising companies and social media companies, to display our ads around the web. These companies may use cookies and similar technologies to collect information (including the automatically-collected data described above) about your interactions over time across our Services, our communications, and other online services, and use that information to serve online ads that may interest you.

  • Surveys and promotions. We may allow you to participate in surveys and promotions. If you do, we will collect and use your personal information to facilitate your participation.

For compliance and protection. We use your personal information to comply with our legal obligations and to defend ourselves against legal claims or disputes, including to:

  • Comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities.

  • Protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims).

  • Audit our internal processes for compliance with legal and contractual requirements and internal policies.

  • Enforce the terms and conditions that govern our Services.

  • Prevent, identify, investigate and deter fraudulent, harmful, unauthorized, unethical or illegal activity, including cyberattacks and identity theft.

3. How We Disclose Personal Information

We may disclose your personal information in the following ways:

Affiliates and Subsidiaries. We may share information we collect within any Bask member or group (i.e., our subsidiaries and affiliates, including our ultimate holding company and its subsidiaries) to deliver products and services to you, ensure a consistent level of service across our Services, and enhance our Services and your customer experience.

Service providers. We may disclose your personal information to third party companies and individuals that provide services on our behalf or help us operate our Services (such as hosting, information technology, customer support, ecommerce platform, email delivery, and website analytics services).

Advertising partners. We may disclose your personal information to third-party advertising companies, for the interest-based advertising purposes described above, which may collect information on the Services through cookies and other automated technologies.

Professional advisors. We may disclose your personal information to professional advisors, such as lawyers, auditors, bankers, and insurers, where necessary in the course of the professional services that they render to us.

Authorities and others. We may disclose your personal information to law enforcement, government authorities, and private parties, as we believe in good faith to be necessary or appropriate for the compliance and protection purposes described above.

Business transferees. We may disclose your personal information to acquirers and other relevant participants in business transactions (or negotiations for such transactions) involving a corporate divestiture, merger, consolidation, acquisition, reorganization, sale or other disposition of all or any portion of the business or assets of, or equity interests in, our business (including, in connection with a bankruptcy or similar proceedings).

With your instruction or permission. We may disclose personal information to a relevant third party, where you give us permission to do so in the course of your relationship with us from time to time.

4. Your Privacy Rights and Choices

Opt-out of marketing communications. You may opt-out of marketing-related emails and other communications by following the opt-out or unsubscribe instructions in the communications you receive from us or by contacting us as provided in the “Contact Us” section below. You may continue to receive Services-related and other non-marketing emails.

Personal information requests. Depending on your location and the nature of your interactions with our Services, you may request the following in relation to personal information:

  • Information about how we have collected and used your personal information. We have made this information available to you without having to request it by including it in this Privacy Policy.

  • Access to a copy of the personal information that we have collected about you. Where applicable, we will provide the information in a portable, machine-readable, readily usable format.

  • Correction of personal information that is inaccurate or out of date.

  • Deletion of personal information that we no longer need to provide our Services or for other lawful purposes.

  • Opt out of the sharing of your personal information or use of your personal information for interest-based advertising.

To make a request, please email us or write to us as provided in the “Contact Us” section below. We may ask for specific information from you to help us confirm your identity. Depending on where you reside, you may be entitled to empower an authorized agent to submit requests on your behalf. We will require authorized agents to confirm their identity and authority, in accordance with applicable laws. You are entitled to exercise the rights described above free from discrimination.

Account deactivation and deletion. If you have an account on our Services, you may deactivate and delete your account by contacting us as described in the “Contact Us” section below. Note that deactivating your account may not cause us to fully delete all of your personal information. To request that we do so, please submit a data deletion request as described in the “Personal information requests” section.

Limits on your choices. In some instances, your choices may be limited, such as where fulfilling your request would impair the rights of others, our ability to provide a service you have requested, or our ability to comply with our legal obligations and enforce our legal rights. If you are not satisfied with how we address your request, you may submit a complaint by contacting us as provided in the “Contact Us” section below.

How to control cookies. You can limit online tracking by:

  • Blocking cookies in your browser. Most browsers let you remove or reject cookies, including cookies used for interest-based advertising. To do this, follow the instructions in your browser settings. Many browsers accept cookies by default until you change your settings. For more information about cookies, including how to see what cookies have been set on your device and how to manage and delete them, visit www.allaboutcookies.org.

    Use the following links to learn more about how to control cookies and online tracking through your browser:

  • Blocking advertising ID use in your mobile settings. Your mobile device settings can provide functionality to limit use of the advertising ID associated with your mobile device for interest-based advertising purposes.

  • Using privacy plug-ins or browsers. You can block our websites from setting cookies used for interest-based ads by using a browser with privacy features, like Brave, or installing browser plugins like Privacy Badger, Ghostery, or uBlock Origin, and configuring them to block third party cookies/trackers.

  • Google Analytics. We use Google Analytics to help us better understand how people engage with our Services by collecting information and creating reports about how users use our Services. For more information on Google Analytics, click here. For more information about Google’s privacy practices, click here. You can opt out of Google Analytics by downloading and installing the browser plug-in available at: tools.google.com/dlpage/gaoptout.

  • Advertising industry opt out tools. You can also use these opt out options to limit use of your information for interest-based advertising by participating companies:

  • Platform opt-outs. Some advertising partners offer opt-out features that let you opt out of use of your information for interest-based advertising, including:

Note that because these opt out mechanisms are specific to the device or browser on which they are exercised, you will need to opt out on every browser and device that you use.

Do Not Track. Some Internet browsers can be configured to send “Do Not Track” signals to the online services that you visit. We currently do not respond to “Do Not Track” or similar signals. To find out more about “Do Not Track,” please visit www.allaboutdnt.com.

5. Other Sites and Services

Our Services may contain links to websites and other online services operated by third parties. In addition, our content may be integrated into web pages or other online services that are not associated with us. These links and integrations are not an endorsement of, or representation that we are affiliated with, any third party. We do not control websites or online services operated by third parties, and we are not responsible for their actions. This Privacy Policy does not apply to such third-party sites or services.

6. Job Applicants

If you apply for a job through the “Careers” portion of our Websites, we collect the information that you provide to us in connection with your job application. This includes but is not limited to business and personal contact information, professional credentials and skills, educational and work history, and other information of the type that may be included in a resumé. This may also include diversity information that you voluntarily provide. We use this information to facilitate our recruitment activities and process employment applications, such as by evaluating a job candidate for an employment activity, to monitor recruitment statistics, and to respond to surveys. We may also use this information as necessary (i) to comply with relevant laws or to respond to subpoenas or warrants served on us, (ii) to protect and defend our or others’ rights or property, (iii) in connection with a legal investigation and (iv) to investigate or assist in preventing any violation or potential violation of the law.

7. Security

We use reasonable organizational, technical and administrative measures designed to protect against unauthorized access, misuse, loss, disclosure, alteration and destruction of personal information we maintain. However, no method of transmission over the Internet, and no means of electronic or physical storage, is absolutely secure. As such, we cannot guarantee the security of your personal information and any such transmission of personal information is at your own risk.

Where we have given you (or where you have chosen) a password that enables you to access the Services, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.

8. Retention of Personal Information

Where required under applicable laws, we retain personal information only for as long as is necessary to fulfil the purposes for which it was collected and processed, in accordance with our retention policies, and in accordance with applicable laws and regulatory obligations or until you withdraw your consent (where applicable).

To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of personal information, the purposes for which we use personal information and whether we can achieve those purposes through other means, and the applicable legal and regulatory requirements.

9. Children’s Privacy

The Services are not intended for use by children under 18 years of age. If we learn that we have collected personal information through the Services from a child under 18 without the consent of the child’s parent or guardian as required by law, we will delete it.

10. Changes to This Privacy Policy

We reserve the right to change this Privacy Policy at any time to reflect changes in the law, our data collection and use practices, the features of our Services, or advances in technology. We will make the revised Privacy Policy accessible through the Services, so you should review it periodically. The date this Privacy Policy was last revised is identified at the top of the document. You are responsible for periodically monitoring and reviewing any updates to the Privacy Policy. If we make a material change to the Privacy Policy, we will provide you with appropriate notice in accordance with legal requirements.

11. Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us by email at privacy@bask.health or write to us at:

Attn: Privacy Officer
Bask Health, Inc.
10 Kenmare Street, Ste 4
New York, NY 10022

12. For California Residents

If you are a California resident, California law requires us to provide you with additional information regarding how we collect, use, and share your “personal information” (as defined in the California Consumer Privacy Act (“CCPA”).

12.1 Categories of personal information we collect and disclose:

Throughout this Policy, we describe the specific pieces of personal information we collect from and about our users. Under the CCPA, we are also required to list the “categories” of personal information we collect and the categories of third parties to which we disclose personal information.

Please note: Some information collected through the Services (e.g., medical information) is subject to health data privacy laws and is not subject to the CCPA.

See below for a summary of the categories of personal information subject to the CCPA and the third parties to which we disclose it.

Category of Personal InformationCategories of Third Parties to Which we Disclose
Identifiers and contact information (e.g., name, address, email address, account names)Service providers; our affiliates; health care providers and services; entities for legal and fraud prevention
Commercial and transactional information (e.g., information about your purchases)Service providers; our affiliates; health care providers and services; entities for legal and fraud prevention
Financial information (e.g., credit card info collected by our payment processors)Payment processors; service providers; our affiliates; entities for legal and fraud prevention
Internet or other network or device activity (e.g., IP address, browsing history, app usage)Service providers; our affiliates; entities for legal and fraud prevention
Geolocation information (e.g., general location and precise location, with your permission)Service providers; our affiliates; entities for legal and fraud prevention
Demographic and statistical data (e.g., your gender, interests based on products and services you use)Service providers; our affiliates; entities for legal and fraud prevention
Physical characteristics (e.g., photos of you)Service providers; our affiliates
User-generated content (e.g., information you choose to post in our online forums)Service providers; our affiliates; entities for legal and fraud prevention
Customer service data (e.g., information you provide through a chat or call with Bask’s Care Team)Service providers; our affiliates; health care providers and services; entities for legal and fraud prevention

12.2 Business Purposes for Using Personal Information

We use the personal information we collect for the following business purposes:

  • Manage, facilitate, and improve the Services
  • Conduct research, marketing, and analytics
  • Communicate with users
  • Provide technical support and customer service
  • Ensure security and prevent fraud
  • Comply with legal obligations and defend against legal claims

For more detailed information, please refer to refer to the “Personal Information We Collect” and “How We Use Personal Information” sections of this Policy.

12.3 Your California Privacy Rights – CCPA Disclosure

Under the CCPA, you may request that we:

  • Inform you about the categories of personal information we collect or disclose, the sources of such information, the business or commercial purposes for collecting it, and the categories of third parties with whom we share it
  • Provide access to and/or a copy of certain personal information we hold about you
  • Delete certain personal information we have about you

You also have the right not to be discriminated against for exercising your rights under the CCPA.

Please note:

  • Some information may be exempt from these requests under California law (e.g., data needed to provide the Services)
  • We will take reasonable steps to verify your identity before responding to a request.

To exercise your rights:

  • Submit your request via our webform
  • Or email us at: california-privacy@bask.health
    Include your full name, email address, and residential address associated with your use of our Services, along with the rights you wish to exercise

12.4 Sale of Personal Information

Bask does not and will not sell information that identifies you (e.g., name, email address, phone number, postal address). However, we work with third parties that provide marketing and advertising services, including interest-based advertising. These third parties may place tracking technologies (e.g., cookies, pixels) on our Website and App and collect online identifiers. Under the CCPA, this may be considered a “sale.”

To opt out of sharing your information for interest-based advertising:

  • Visit the Network Advertising Initiative’s Consumer Opt-Out link
  • Visit the Digital Advertising Alliance’s Consumer Opt-Out link
  • Visit Your Online Choices

Note: These opt-outs are device and browser specific. You must opt out on each device and browser you use.

12.5 Shine the Light Disclosure

California’s “Shine the Light” law allows residents to request information about how we share certain categories of personal information with third parties for their direct marketing purposes. We do not share your personal information with third parties for their own direct marketing purposes.

Enhance patients experience and maximize revenue with our solutions.

Use Bask’s flexible applications blocks to build secure, customizable and compliant online store.