REFLECT HEALTH PRIVACY NOTICE

Last Updated: January 30, 2026

Reflect Health (“Reflect Health,” “we,” “us,” or “our”) is committed to protecting the privacy of individuals who visit our Website, use our Portal, interact with our mobile application, or otherwise engage with our services. This Privacy Notice describes the types of information we collect, how we use that information, the circumstances in which we may share it, and the choices you have regarding your personal data. We encourage you to review this Notice carefully in order to fully understand our privacy practices. If you have any questions or concerns about the content of this Notice, you may contact us at help@reflecthealth.com.

This Notice applies to information collected through the public website located at https://www.reflecthealth.com/ (“Website”), any secure online portal accessible through the Website (“Portal”), and our mobile applications, including Reflect Health, ATA and ACMG (“App”). By accessing or using any of these Services, you acknowledge that you have read, understood, and agreed to the terms contained in this Privacy Notice. If you do not agree with any part of this Notice, you should discontinue use of the Services immediately.


1. Scope of This Privacy Notice

Reflect Health operates both public-facing and secure digital environments. The public portions of our Website generally may be accessed without providing any personal information; however, if you choose to contact us, request information, or interact with certain features, we may collect limited information needed to fulfill your request. In contrast, the Portal and App may require you to provide identifying information in order to authenticate your account, access benefit materials, or utilize the services offered within those environments. This Notice governs all such information, regardless of the specific platform on which it is collected.


2. Information We Collect

A. Information You Voluntarily Provide

We collect personal information that you choose to provide to us directly. This may occur when you create an account, use the Portal or App, submit a form through the Website, or reach out to us with questions or requests. Depending on the nature of your interaction, this information may include your name, email address, phone number, mailing address, health plan member identification numbers, or any other information you submit voluntarily. We ask that you ensure this information is accurate, complete, and kept current.

B. Information Collected Through Email Communications

If you send us a message via email, we will use your email address solely for the purpose of addressing your inquiry or providing assistance related to your request. In connection with email communications sent to us through the Website, we may utilize a temporary browser cookie. This cookie does not store personal information about you or your preferences. Furthermore, your email address is automatically removed from this cookie within seven (7) days, and we do not use this information for any other purpose.

C. Comments and Use of the Gravatar Service

If the Website offers the ability to leave public comments, we may collect the information displayed in the comment submission form, as well as your IP address and browser user agent string. This helps us detect spam and protect the integrity of the Website. In addition, an anonymized hash created from your email address may be transmitted to the Gravatar service to determine whether you are using that service. The Gravatar service’s privacy policy is available at: https://automattic.com/privacy/. If your comment is approved for posting, your profile image, as provided through Gravatar, may be visible to the public in connection with your comment.

D. Log Data and Technical Information

When you access the Website, Portal, or App, our systems automatically record certain technical information sent by your browser or device. This may include your IP address, browser type and version, device information, referring website, the pages you visit, the time and date of your visit, the duration of your time on each page, and other similar technical data. This information helps us maintain the security of our Services and improve user experience.


3. How We Use Your Information

Reflect Health uses personal information to support the operation and improvement of our Services. This includes managing and maintaining user accounts, communicating important administrative updates, responding to inquiries, and providing the services and functionality you request. We also use information to maintain the security and integrity of our systems, to monitor for fraud or unauthorized access, and to comply with applicable legal and regulatory obligations. In some cases, we may process information to further our legitimate business interests; in others, we do so based on your consent or to fulfill our legal responsibilities.


4. When and Why We Share Information

We may share personal information only when necessary and only under specific circumstances. For example, we may share information with thirdparty service providers who perform operational or technical functions on our behalf, such as hosting, data storage, analytics, customer support, or email delivery. These service providers are required to use the information only for the purposes for which it was provided and to maintain its confidentiality.

We may also share information with affiliated organizations under our common ownership or control, provided that such affiliates agree to abide by the terms of this Notice. In certain situations, we may be legally required to disclose information in response to valid requests from law enforcement, courts, or regulatory bodies. Additionally, we may share information if we believe it is necessary to prevent harm, to investigate suspected misconduct, or to protect the rights and safety of our users and the public.

Reflect Health does not sell, rent, or trade personal information for third-party marketing or promotional purposes.


5. Use of Cookies and Similar Technologies

Cookies and related technologies may be used on the Website to support functionality, recognize returning users, personalize the browsing experience, and enhance security. Cookies cannot be used to deliver viruses or run programs on your device. You may choose to decline cookies through your browser settings; however, doing so may limit your ability to fully experience the interactive features of the Services. As described earlier, the temporary emailrelated cookie used in limited circumstances does not contain personal information and is removed within seven (7) days.


6. Retention of Personal Information

Reflect Health retains personal information only for as long as needed to fulfill the purposes for which it was collected, unless longer retention is required or permitted by applicable law. In general, personal information associated with a user account may be retained for up to one (1) year following the termination of that account. When information is no longer needed, we will delete it or render it anonymous. If immediate deletion is not reasonably possible—for example, because the information is stored in secure backup archives—we will isolate the information and protect it from further processing until deletion is feasible.


7. How We Protect Your Information

We have implemented a combination of technical and organizational measures designed to protect personal information from unauthorized access, use, or disclosure. When personal information is transmitted across websites, it is secured using encryption protocols, such as Secure File Transfer Protocol. Despite these measures, no method of electronic transmission or storage can be guaranteed to be completely secure. For that reason, we urge users to access our Services within a safe and secure environment.


8. Links to ThirdParty Websites

Our Website may contain links that direct users to thirdparty websites or online services. These external websites may require you to provide login credentials, personal identification numbers, or other information in order to access benefit information or related materials. Reflect Health does not control and is not responsible for the privacy practices, content, or security measures of external websites. We strongly encourage you to review the privacy statements of any linked sites, as their policies may differ from ours.


9. Children’s Privacy

Reflect Health does not knowingly collect personal information from children under the age of thirteen (13). If you are under the age of thirteen, you must obtain permission from a parent or guardian before accessing or using our Services. If we become aware that personal information has been collected from a child under thirteen without appropriate consent, we will take steps to delete that information promptly.


10. Your Privacy Rights

You have the right to request the deletion of personal information we maintain about you. Upon receiving a verifiable request, we will delete your personal information from our records and direct any service providers to do the same, unless retaining the information is necessary for us to complete a transaction, detect or prevent fraud, debug or repair system functionality, comply with legal obligations, conduct certain types of research, exercise legal rights, or use the information internally in a lawful manner consistent with your original interaction. To review, update, or request deletion of your information, you may contact us using the information provided at the end of this Notice.


11. DoNotTrack Signals

Some browsers offer a “DoNotTrack” (“DNT”) feature intended to signal your preference not to be tracked across websites. Because uniform standards for recognizing and responding to DNT signals have not been established, Reflect Health does not currently respond to DNT signals. We will update this Notice if such standards are developed and adopted.


12. Updates to This Privacy Notice

We may update this Privacy Notice from time to time in order to reflect changes to our practices, technologies, or legal obligations. Any updated version will be indicated by an updated “Last Updated” date. If we make significant changes to this Notice, we may choose to notify you by posting a prominent notice on the Website or by sending you a direct communication. Your continued use of the Services following the posting of changes constitutes your acknowledgment and acceptance of the revised Notice.


13. Contact Us

If you have any questions, comments, or concerns regarding this Privacy Notice, or if you would like to exercise your privacy rights, you may contact us at:

Email: help@reflecthealth.com
Mailing Address:
Reflect Health
4900 Parkway Dr #160
Mason, OH 45040