1. TL;DR
- We collect information only when needed to deliver care, run the site, or comply with the law.
- We never sell or rent your personal information to third-party marketers.
- You can access, correct, delete, or unsubscribe at any time.
- This site uses Google Analytics (with IP anonymization) and Google Search Console for traffic analysis only.
- In-clinic medical records are governed by HIPAA — see our HIPAA Notice of Privacy Practices.
2. Information We Collect
2.1 Information You Submit
- Booking form: name, phone, email, preferred clinic, preferred time, reason for visit.
- Contact form: name, phone, email, inquiry topic, message body, marketing opt-in flag.
- Insurance verification: name, phone, email, date of birth, insurance company, member ID, group number, optional notes.
- Newsletter sign-up: email address.
- Fresha online booking (off-site redirect): handled by Fresha under their privacy policy.
2.2 Information Collected Automatically
- Browser, device, OS, screen size, referrer URL, timestamp.
- Approximate geographic location (IP-based, city-level only; GA4 IP anonymization is enabled).
- Pages viewed and time on page (for site-architecture improvements).
- Local browser storage preferences (e.g.
lastClinic, used to remember which NYC clinic you last viewed — never sent to our servers).
2.3 Information We Do Not Collect via This Website
- Credit-card numbers (online payments are handled by Fresha directly).
- Social Security Numbers.
- Medical records you have not voluntarily submitted.
3. How We Use This Information
- Respond to inquiries, schedule first visits, verify insurance benefits.
- Send appointment reminders, follow-ups, and benefit-verification results (where a care relationship exists).
- Send health-education or event emails only if you opt in; one-click unsubscribe in every footer.
- Analyze site traffic and conversion paths to improve information architecture and accessibility.
- Comply with NY-state and federal obligations (HIPAA, ADA, consumer-protection laws).
4. How We Do Not Use It
- We never sell or rent your personal data.
- We do not run behavioral ads based on your health data.
- We do not share your medical information with employers or unrelated insurers without your written authorization (except where required by law).
5. When We Disclose to Third Parties
| Third party | Purpose | What we share |
|---|---|---|
| Fresha (booking platform) | Online appointments + payments | Name, email, phone, chosen service (collected by Fresha after you click through) |
| Google Analytics 4 | Anonymized site analytics | Device info + non-PII visit behavior |
| Google Search Console | SEO performance | Domain verification token only — no visitor data |
| Vercel (hosting) | Site hosting and edge network | HTTP request logs (IP, User-Agent, timestamp) |
| Supabase (database) | Form storage | Form fields you submit |
| Insurance carriers | Benefit verification | Only the carrier you specify, only after you submit the verification form |
| Law enforcement | Lawful subpoena or court order | As legally required |
6. Data Retention
- Bookings / messages / insurance verifications: kept 7 years, matching NY-state medical-record retention.
- Email subscribers: kept until you unsubscribe; removed from active marketing list within 90 days of unsubscribe.
- Web logs (Vercel): rotated after 30–90 days.
- GA4 data: aggregated after 14 months by default.
7. Data Security
- HTTPS (TLS 1.3) site-wide.
- Database (Supabase) uses Row-Level Security; only the server-side service-role can write.
- Admin console secured via HMAC-signed cookies and a strong password.
- Suspicious access attempts are logged.
That said, no system is 100% secure. Please report suspicious activity or vulnerabilities to service@healthkeygroup.com immediately.
8. Your Rights
Whether you live in NY, another US state, California (CCPA/CPRA), the EU (GDPR), or elsewhere, you have these rights:
- Right to know: ask us what data we hold about you.
- Right to correct: ask us to fix inaccurate information.
- Right to delete: ask us to delete your data (subject to medical-record retention obligations).
- Right to opt out: unsubscribe from marketing at any time.
- Right to complain: file a complaint with the NY State Attorney General or your local data-protection authority.
To exercise any of these rights, email service@healthkeygroup.com with subject "Privacy Request". We respond within 30 days.
9. Cookies & Local Storage
This site uses:
- Essential: admin-console session (
admin_session, HttpOnly + Secure). - Analytics: Google Analytics 4 cookies (
_ga,_ga_*) with IP anonymization. - Preferences:
lastClinicin localStorage — remembers the clinic you last viewed so the "Call" button picks the right number; never sent to our servers.
You can block or delete these via your browser. Blocking GA4 cookies does not affect site functionality.
10. Children
This site is not directed to children under 13. If we learn we collected such data, we delete it immediately. Minors must be accompanied by a guardian who signs the consent form.
11. International Transfers
The site is hosted on Vercel (USA) and the database on Supabase (us-east-1, Virginia, USA). If you access from outside the US, your data is transferred to and processed in the US under this policy and US law.
12. Changes to This Policy
Updates are posted on this page with a new "Last updated" date. Material changes (sharing or rights) trigger an email or banner notice.
13. Contact
HealthKey Group · Nikki Zhang, LAc
Manhattan (Chinatown): 139 Centre St #202, New York, NY 10013 · 212-343-9398
Email: service@healthkeygroup.com
Accessibility / privacy issues: service@healthkeygroup.com
This document is informational and not specific legal advice. For questions about your data, contact us at the email above.