Your privacy matters to us. Health Matters Clinic is a nonprofit serving the Los Angeles community. We collect only the data we need to coordinate services, run events, support volunteers, and connect people to resources. We do not sell your personal information. This policy explains what we collect, how we use it, and the rights you have under California law.
Health Matters Clinic ("HMC," "we," "us," or "our") is a 501(c)(3) nonprofit organization located in Los Angeles, California. We advance health equity by providing free community events, wellness tools, volunteer coordination, and resource navigation services to individuals throughout Los Angeles County and surrounding areas.
This Privacy Policy applies to personal information collected by HMC through our digital platforms, websites, forms, and communications. It does not apply to the personal health information of patients receiving in-person or telehealth clinical services, which is governed by separate HIPAA-compliant notices provided at the point of care.
This Privacy Policy applies to the following HMC digital platforms:
We are transparent about exactly what data each platform collects. The following describes what we collect from each service.
We use personal information for the following purposes:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Event coordination and RSVP management | Name, email, phone number | Consent (RSVP submission) |
| SMS event notifications and reminders | Phone number, event details | Consent (opt-in at RSVP) |
| Volunteer program management and scheduling | Name, email, phone, address, availability, skills | Consent (volunteer application) |
| Volunteer HIPAA training and compliance tracking | Training completion data, timestamps | Legal compliance obligation |
| Partner organization coordination and referral tracking | Org info, contact info, referral records | Contractual necessity |
| Platform security and fraud prevention | IP address, login activity, reCAPTCHA data | Legitimate interest |
| Website and platform analytics | Anonymized usage data via Google Analytics | Legitimate interest |
| Responding to inquiries and support requests | Contact form data, email address | Consent (inquiry submission) |
| Organizational communications and newsletters | Email address (opted-in subscribers only) | Consent (explicit opt-in) |
| Legal compliance and record-keeping | As required by applicable law | Legal obligation |
We do not use your data for automated profiling or algorithmic decision-making that produces legal or similarly significant effects on you.
HMC sends SMS text messages through Twilio for the following purposes:
You opt in to SMS in one of two ways. On an HMC registration or RSVP form you enter your mobile number and tick a consent box that is unchecked by default. That box states the types of messages you will receive, that message frequency varies, that message and data rates may apply, and that you can reply STOP to unsubscribe or HELP for help. Alternatively you can text our published number, (323) 990-4325, where the same disclosures are displayed at healthmatters.clinic/sms. We do not send SMS to anyone who has not taken one of those two actions. Consent to receive text messages is never a condition of attending an event, receiving services, or getting help from HMC.
You may opt out of SMS communications at any time by:
After opting out, you will receive a single confirmation text confirming your opt-out. No further messages will be sent. If you opt back in later, the process starts fresh.
Message frequency varies by event and activity. Message and data rates may apply based on your mobile carrier plan. HMC does not charge for SMS messages on our end. For help, reply HELP to any HMC text message or email contact@healthmatters.clinic.
SMS messages are delivered via Twilio Inc. Twilio processes phone numbers and message content as a service provider on behalf of HMC. Twilio does not use your phone number for its own marketing. HMC maintains a deduplication system to prevent repeated identical messages.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third parties.
The mobile number you give us, and the consent you give with it, are used only to send you the messages you asked to receive. That information is not sold, rented, traded, or shared with third parties or affiliates for marketing or promotional purposes. Twilio transmits the messages on our behalf as a service provider and does not use the information for its own marketing.
Neither tool asks who you are. Neither creates an account. Neither stores the answers you give to individual questions: what you type or tap in CalmKit, and every individual item you answer in Check Yourself, stays in your browser and is discarded when you close or reset the session.
Both tools do send HMC a short, de-identified record after a session so we can tell whether the tools are helping and report totals to the funders who pay for them. Those records carry no name, email or phone number, and HMC never sees your individual answers. They are described in full in 6.1 and 6.2 below.
We recognize that wellness and mental health reflection is deeply personal, so we built both tools to be useful to you without building a profile of you.
When you finish a CalmKit session and rate how you feel, CalmKit sends us that rating (a number from 1 to 5), the type of session, how long it lasted, the distance walked if you used Guided Walk, and your language. It also sends a random identifier your browser generated for itself, which our server immediately converts into an irreversible hash so repeat sessions from one device can be counted once without that device being identifiable. This record is kept for 24 months and then deleted. Guided Walk asks your permission before using your location. If you allow it, your coordinates pass through our server to Google's weather and air quality services so the walk can describe the conditions around you, and HMC does not store them in any database. Meditation audio and guided coaching text are generated by Google Gemini and Google text-to-speech, requested through an HMC server so our API keys are not exposed in your browser.
Check Yourself uses two validated screening questionnaires, the PHQ-9 and the GAD-7. Your answers to the individual questions, and the numeric scores they produce, are never sent to HMC and are never stored anywhere. Only the severity band each questionnaire produces, such as "mild" or "moderate", leaves your browser. When your results appear, Check Yourself automatically sends us an anonymous record containing those two severity bands, whether the questionnaire indicated thoughts of self-harm, your language, and the same kind of irreversible per-device hash described above. That record contains no name, email or phone number, and is deleted after 30 days. If you choose to ask HMC to reach out to you, and only then, you give us a name and a way to contact you. Those details are stored separately from your screening record, linked only by a random session code, kept for 30 days, and emailed to HMC clinical staff so someone can follow up with you. You can use Check Yourself fully without taking this step. If the questionnaire indicates thoughts of self-harm, the results screen surfaces the 988 Suicide and Crisis Lifeline; Check Yourself is a screening tool, not a diagnosis, and it is not monitored in real time, so in an emergency call 988 or 911. HMC's digital wellness tools are not operated as a HIPAA-covered entity in the context of those tools, and using CalmKit or Check Yourself does not by itself create a provider-patient relationship. If you request follow-up, that request is handled by HMC clinical staff, and any care that follows is governed by the separate HIPAA Notice of Privacy Practices you receive at the point of care.
HMC uses the following third-party services to operate our platforms. Each provider acts as a service provider or data processor and is contractually prohibited from using your data for their own purposes beyond service delivery.
| Provider | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Google Analytics | Website usage analytics and traffic measurement | Anonymized browsing data, IP address (anonymized), device type | policies.google.com/privacy |
| Google Firebase & Firestore | Backend database, authentication, and cloud infrastructure | Volunteer profile data, RSVP data, partner data, authentication tokens | firebase.google.com/support/privacy |
| Google Cloud Platform | Cloud hosting and compute (Cloud Run, us-central1) | Application data processed through our hosted services | cloud.google.com/privacy |
| Twilio | SMS delivery for event and volunteer notifications | Phone numbers and message content for opted-in users | twilio.com/legal/privacy |
| Webflow | Website hosting and content management for main site | Web traffic data, CMS content, form submissions on Webflow-hosted pages | webflow.com/legal/privacy |
| Google reCAPTCHA | Bot prevention and form spam protection | Browser and behavioral data to assess whether a submission is human | policies.google.com/privacy |
| Google OAuth | Account authentication for Volunteer Portal | Google account email address and identifier (no password stored by HMC) | policies.google.com/privacy |
| Gumroad | Digital product distribution and payment processing | Email address, payment data (handled by Gumroad; not shared with HMC) | gumroad.com/privacy |
| Cloudflare | DNS management and DDoS protection | IP addresses, network traffic metadata | cloudflare.com/privacypolicy |
| Google Apps Script | Event RSVP processing and email notifications | RSVP form data (name, email, phone) processed via Google Workspace | policies.google.com/privacy |
We do not authorize these service providers to use, sell, retain, or disclose your personal information for any purpose other than performing services for HMC. We evaluate our service providers for privacy compliance and require contractual data processing protections where applicable.
Health Matters Clinic does not sell, rent, trade, or lease your personal information to any third party for monetary or other valuable consideration. This applies to all categories of personal information we collect.
We may share your information only in the following circumstances:
HMC may use and share aggregated, de-identified data that cannot reasonably be used to identify you (for example, "150 community members attended HMC events in May") for reporting, grant applications, public health research, and organizational communications. This data is not personal information.
HMC does not combine data from different platforms to create marketing profiles or behavioral advertising segments. Data collected on the Event Finder is used for event coordination. Data collected on the Volunteer Portal is used for volunteer management. These datasets are kept functionally separate.
We retain personal information only as long as necessary to fulfill the purpose for which it was collected, to comply with legal obligations, and to resolve any disputes.
| Data Type | Retention Period | Reason |
|---|---|---|
| Event RSVP data (name, email, phone) | 24 months from event date | Follow-up outreach and event history |
| Volunteer application and profile data | Duration of active volunteer status + 3 years | Program records, training compliance, reference |
| Volunteer HIPAA training records | 6 years from completion | HIPAA compliance requirement |
| Partner organization data | Duration of partnership + 5 years | Legal compliance, referral records |
| CalmKit and Check Yourself data | Individual answers not retained; de-identified session records 24 months; Check Yourself screening records and follow-up requests 30 days | By design: anonymous tool |
| Website analytics data (Google Analytics) | 26 months (Google default) | Trend analysis and platform improvement |
| Contact form submissions | 24 months | Inquiry follow-up and records |
| SMS opt-out records | Indefinitely | Compliance with opt-out requests |
| Gumroad purchase records | Per Gumroad's policy (HMC has limited visibility) | Transaction history |
Upon expiration of retention periods, we delete or de-identify personal information in a manner consistent with applicable law and our security practices.
HMC implements reasonable and appropriate technical and organizational security measures to protect personal information from unauthorized access, disclosure, alteration, or destruction. Our security practices include:
Despite these measures, no system is perfectly secure. We cannot guarantee that data transmitted over the internet or stored on our systems will never be accessed by unauthorized parties. If you believe a security incident has occurred involving your data, please contact us immediately at privacy@healthmatters.clinic.
In the event of a data breach affecting California residents, HMC will provide notification as required by California Civil Code Section 1798.82 and any other applicable notification requirements.
HMC's digital platforms are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected information from a child under 13 without verifiable parental consent, we will delete that information promptly.
Volunteers must be at least 16 years old. Volunteers between the ages of 16 and 17 must have verifiable parental or guardian consent on file with HMC before participating in any volunteer activities.
If you are a parent or guardian and believe that your minor child has provided personal information to HMC without your consent, please contact us at privacy@healthmatters.clinic and we will promptly investigate and, where appropriate, delete the information.
This policy is consistent with the federal Children's Online Privacy Protection Act (COPPA) and California law.
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you specific rights regarding your personal information. Health Matters Clinic is committed to honoring these rights.
You have the right to request that HMC disclose:
You have the right to request that HMC delete personal information we have collected from you, subject to certain exceptions. We may retain information where necessary to:
If an exception applies, we will inform you and explain the basis for retaining the data.
Under the CPRA, you have the right to request correction of inaccurate personal information we hold about you. You can update most profile information directly in your Volunteer Portal account. For corrections to data held elsewhere, contact privacy@healthmatters.clinic.
HMC does not sell personal information and does not share personal information for cross-context behavioral advertising. Because we do not engage in these activities, there is currently nothing to opt out of under these specific CCPA provisions. However, if this practice ever changes, we will provide a clear "Do Not Sell or Share My Personal Information" link on our website and provide 30 days' notice before implementation.
To the extent HMC collects sensitive personal information as defined under the CPRA (such as health-related data in a clinical context), you have the right to limit its use to what is necessary to provide services you requested. For volunteers, HIPAA training records constitute sensitive data retained for legal compliance purposes.
HMC will not discriminate against you for exercising your CCPA rights. We will not deny you services, charge different prices, provide a different level or quality of service, or suggest that you will receive inferior treatment because you exercised your privacy rights. Since all of HMC's core community services are free, there is no pricing mechanism that could be used in a discriminatory manner.
To exercise any of the rights described above, you may:
We will acknowledge receipt of your request within 10 business days and respond substantively within 45 calendar days. If we need more time (up to an additional 45 days), we will notify you in writing with the reason for the extension.
We will verify your identity before processing your request using reasonable verification measures, such as matching information you provide with our records. We will not require you to create an account or disclose information beyond what is necessary for verification.
You may designate an authorized agent to submit a CCPA request on your behalf. The authorized agent must provide written permission signed by you, and we may still verify your identity directly. We will not require direct verification from you if your authorized agent provides a valid power of attorney executed pursuant to California Probate Code Sections 4121-4130.
In the past 12 months, HMC has collected the following categories of personal information as defined by the CCPA:
In the past 12 months HMC has collected two categories of sensitive personal information as defined under CPRA. Health information: the de-identified session and screening records described in Section 6, the follow-up contact details you choose to provide through Check Yourself, and volunteer HIPAA training records retained for legal compliance. Precise geolocation: only where you grant CalmKit's Guided Walk permission, and only to retrieve local weather and air quality, as described in Section 6.1. HMC has not collected financial account numbers, racial or ethnic origin, religious or philosophical beliefs, union membership, genetic data, biometric data used to identify you, or the contents of your mail, email or text messages. HMC does not use sensitive personal information to infer characteristics about you, and does not sell or share it.
California residents may request information about personal data we disclosed to third parties for their direct marketing purposes during the preceding calendar year. HMC does not disclose personal information to third parties for their direct marketing purposes. If this practice ever changes, California residents will have the right to request a list of such disclosures at no charge once per year.
HMC complies with CalOPPA. This Privacy Policy is posted prominently on our website, discloses what information we collect and how it is used, and describes how you can access and correct your information.
To the extent HMC's activities involve medical information as defined under California Health and Safety Code Section 56.05, HMC is committed to complying with the CMIA. HMC does not share medical information about identified individuals without authorization except as permitted by law.
HMC's privacy practices are designed to be transparent and non-deceptive. We do not engage in any unfair, deceptive, or misleading practices regarding our collection or use of personal information. California residents who believe HMC has engaged in deceptive privacy practices may have rights under the CLRA and are encouraged to contact us first to resolve concerns.
Some browsers include a "Do Not Track" (DNT) feature that sends a signal to websites requesting that your browsing activity not be tracked. Currently, there is no industry standard for how websites should respond to DNT signals. HMC's platforms do not currently respond to DNT signals in a manner that would change data collection behavior. We use Google Analytics with IP anonymization enabled to minimize the identifiability of analytics data.
California law requires that we disclose our response to DNT signals. We have made that disclosure here. We will update this section if our practices change or if an industry standard emerges.
HMC may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or organizational operations. When we make material changes, we will:
Your continued use of HMC's platforms after the effective date of a revised Privacy Policy constitutes your acceptance of the updated practices. If the changes are material and you do not agree, you should stop using the affected platforms and contact us to request deletion of your data.
For any privacy questions, to exercise your CCPA rights, or to report a privacy concern:
Email: privacy@healthmatters.clinic
Phone: (323) 990-4325
Health Matters Clinic
Los Angeles, California
Website: healthmatters.clinic