Your privacy matters to us. Health Matters Clinic is a nonprofit serving the Los Angeles community. We collect only the data we need to coordinate services, run events, support volunteers, and connect people to resources. We do not sell your personal information. This policy explains what we collect, how we use it, and the rights you have under California law.
Health Matters Clinic ("HMC," "we," "us," or "our") is a 501(c)(3) nonprofit organization located in Los Angeles, California. We advance health equity by providing free community events, wellness tools, volunteer coordination, and resource navigation services to individuals throughout Los Angeles County and surrounding areas.
This Privacy Policy applies to personal information collected by HMC through our digital platforms, websites, forms, and communications. It does not apply to the personal health information of patients receiving in-person or telehealth clinical services, which is governed by separate HIPAA-compliant notices provided at the point of care.
This Privacy Policy applies to the following HMC digital platforms:
We are transparent about exactly what data each platform collects. The following describes what we collect from each service.
We use personal information for the following purposes:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Event coordination and RSVP management | Name, email, phone number | Consent (RSVP submission) |
| SMS event notifications and reminders | Phone number, event details | Consent (opt-in at RSVP) |
| Volunteer program management and scheduling | Name, email, phone, address, availability, skills | Consent (volunteer application) |
| Volunteer HIPAA training and compliance tracking | Training completion data, timestamps | Legal compliance obligation |
| Partner organization coordination and referral tracking | Org info, contact info, referral records | Contractual necessity |
| Platform security and fraud prevention | IP address, login activity, reCAPTCHA data | Legitimate interest |
| Website and platform analytics | Anonymized usage data via Google Analytics | Legitimate interest |
| Responding to inquiries and support requests | Contact form data, email address | Consent (inquiry submission) |
| Organizational communications and newsletters | Email address (opted-in subscribers only) | Consent (explicit opt-in) |
| Legal compliance and record-keeping | As required by applicable law | Legal obligation |
We do not use your data for automated profiling or algorithmic decision-making that produces legal or similarly significant effects on you.
HMC sends SMS text messages through Twilio for the following purposes:
You consent to SMS by providing your mobile phone number and submitting an RSVP or registration form on any HMC platform. Consent is required before we send any SMS messages. Your consent is not a condition of accessing any free HMC service or resource.
You may opt out of SMS communications at any time by:
After opting out, you will receive a single confirmation text confirming your opt-out. No further messages will be sent. If you opt back in later, the process starts fresh.
Message frequency varies by event and activity. Message and data rates may apply based on your mobile carrier plan. HMC does not charge for SMS messages on our end. For help, reply HELP to any HMC text message or email contact@healthmatters.clinic.
SMS messages are delivered via Twilio Inc. Twilio processes phone numbers and message content as a service provider on behalf of HMC. Twilio does not use your phone number for its own marketing. HMC maintains a deduplication system to prevent repeated identical messages.
CalmKit self-screening responses, mood check-ins, coaching prompts, and any wellness inputs are processed entirely within your browser session. These responses are never transmitted to HMC's servers, never stored in any database, and never shared with any person or third party.
When you close your browser tab or reset the session, all inputs are permanently discarded. There is no account, no history, and no record of your CalmKit session in any HMC system.
CalmKit is designed this way intentionally. We recognize that wellness and mental health reflection is deeply personal. We built CalmKit to give you a private space without creating any data trail.
The only data collected by HMC during a CalmKit session is anonymous technical data necessary for platform operation, including session duration, general device type, and error logs. This data cannot be linked back to any individual and is used only for debugging and performance monitoring.
HMC's digital wellness tools, including CalmKit, are not operated as a HIPAA-covered entity in the context of those tools. CalmKit does not create a provider-patient relationship and does not collect protected health information (PHI) as defined under HIPAA. If you receive in-person or telehealth clinical care from HMC directly, your PHI is handled under a separate HIPAA Notice of Privacy Practices provided to you at the time of care.
HMC uses the following third-party services to operate our platforms. Each provider acts as a service provider or data processor and is contractually prohibited from using your data for their own purposes beyond service delivery.
| Provider | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Google Analytics | Website usage analytics and traffic measurement | Anonymized browsing data, IP address (anonymized), device type | policies.google.com/privacy |
| Google Firebase & Firestore | Backend database, authentication, and cloud infrastructure | Volunteer profile data, RSVP data, partner data, authentication tokens | firebase.google.com/support/privacy |
| Google Cloud Platform | Cloud hosting and compute (Cloud Run, us-central1) | Application data processed through our hosted services | cloud.google.com/privacy |
| Twilio | SMS delivery for event and volunteer notifications | Phone numbers and message content for opted-in users | twilio.com/legal/privacy |
| Webflow | Website hosting and content management for main site | Web traffic data, CMS content, form submissions on Webflow-hosted pages | webflow.com/legal/privacy |
| Google reCAPTCHA | Bot prevention and form spam protection | Browser and behavioral data to assess whether a submission is human | policies.google.com/privacy |
| Google OAuth | Account authentication for Volunteer Portal | Google account email address and identifier (no password stored by HMC) | policies.google.com/privacy |
| Gumroad | Digital product distribution and payment processing | Email address, payment data (handled by Gumroad; not shared with HMC) | gumroad.com/privacy |
| Cloudflare | DNS management and DDoS protection | IP addresses, network traffic metadata | cloudflare.com/privacypolicy |
| Google Apps Script | Event RSVP processing and email notifications | RSVP form data (name, email, phone) processed via Google Workspace | policies.google.com/privacy |
We do not authorize these service providers to use, sell, retain, or disclose your personal information for any purpose other than performing services for HMC. We evaluate our service providers for privacy compliance and require contractual data processing protections where applicable.
Health Matters Clinic does not sell, rent, trade, or lease your personal information to any third party for monetary or other valuable consideration. This applies to all categories of personal information we collect.
We may share your information only in the following circumstances:
HMC may use and share aggregated, de-identified data that cannot reasonably be used to identify you (for example, "150 community members attended HMC events in May") for reporting, grant applications, public health research, and organizational communications. This data is not personal information.
HMC does not combine data from different platforms to create marketing profiles or behavioral advertising segments. Data collected on the Event Finder is used for event coordination. Data collected on the Volunteer Portal is used for volunteer management. These datasets are kept functionally separate.
We retain personal information only as long as necessary to fulfill the purpose for which it was collected, to comply with legal obligations, and to resolve any disputes.
| Data Type | Retention Period | Reason |
|---|---|---|
| Event RSVP data (name, email, phone) | 24 months from event date | Follow-up outreach and event history |
| Volunteer application and profile data | Duration of active volunteer status + 3 years | Program records, training compliance, reference |
| Volunteer HIPAA training records | 6 years from completion | HIPAA compliance requirement |
| Partner organization data | Duration of partnership + 5 years | Legal compliance, referral records |
| CalmKit session data | Not retained (session-only) | By design: anonymous tool |
| Website analytics data (Google Analytics) | 26 months (Google default) | Trend analysis and platform improvement |
| Contact form submissions | 24 months | Inquiry follow-up and records |
| SMS opt-out records | Indefinitely | Compliance with opt-out requests |
| Gumroad purchase records | Per Gumroad's policy (HMC has limited visibility) | Transaction history |
Upon expiration of retention periods, we delete or de-identify personal information in a manner consistent with applicable law and our security practices.
HMC implements reasonable and appropriate technical and organizational security measures to protect personal information from unauthorized access, disclosure, alteration, or destruction. Our security practices include:
Despite these measures, no system is perfectly secure. We cannot guarantee that data transmitted over the internet or stored on our systems will never be accessed by unauthorized parties. If you believe a security incident has occurred involving your data, please contact us immediately at privacy@healthmatters.clinic.
In the event of a data breach affecting California residents, HMC will provide notification as required by California Civil Code Section 1798.82 and any other applicable notification requirements.
HMC's digital platforms are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected information from a child under 13 without verifiable parental consent, we will delete that information promptly.
Volunteers must be at least 16 years old. Volunteers between the ages of 16 and 17 must have verifiable parental or guardian consent on file with HMC before participating in any volunteer activities.
If you are a parent or guardian and believe that your minor child has provided personal information to HMC without your consent, please contact us at privacy@healthmatters.clinic and we will promptly investigate and, where appropriate, delete the information.
This policy is consistent with the federal Children's Online Privacy Protection Act (COPPA) and California law.
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you specific rights regarding your personal information. Health Matters Clinic is committed to honoring these rights.
You have the right to request that HMC disclose:
You have the right to request that HMC delete personal information we have collected from you, subject to certain exceptions. We may retain information where necessary to:
If an exception applies, we will inform you and explain the basis for retaining the data.
Under the CPRA, you have the right to request correction of inaccurate personal information we hold about you. You can update most profile information directly in your Volunteer Portal account. For corrections to data held elsewhere, contact privacy@healthmatters.clinic.
HMC does not sell personal information and does not share personal information for cross-context behavioral advertising. Because we do not engage in these activities, there is currently nothing to opt out of under these specific CCPA provisions. However, if this practice ever changes, we will provide a clear "Do Not Sell or Share My Personal Information" link on our website and provide 30 days' notice before implementation.
To the extent HMC collects sensitive personal information as defined under the CPRA (such as health-related data in a clinical context), you have the right to limit its use to what is necessary to provide services you requested. For volunteers, HIPAA training records constitute sensitive data retained for legal compliance purposes.
HMC will not discriminate against you for exercising your CCPA rights. We will not deny you services, charge different prices, provide a different level or quality of service, or suggest that you will receive inferior treatment because you exercised your privacy rights. Since all of HMC's core community services are free, there is no pricing mechanism that could be used in a discriminatory manner.
To exercise any of the rights described above, you may:
We will acknowledge receipt of your request within 10 business days and respond substantively within 45 calendar days. If we need more time (up to an additional 45 days), we will notify you in writing with the reason for the extension.
We will verify your identity before processing your request using reasonable verification measures, such as matching information you provide with our records. We will not require you to create an account or disclose information beyond what is necessary for verification.
You may designate an authorized agent to submit a CCPA request on your behalf. The authorized agent must provide written permission signed by you, and we may still verify your identity directly. We will not require direct verification from you if your authorized agent provides a valid power of attorney executed pursuant to California Probate Code Sections 4121-4130.
In the past 12 months, HMC has collected the following categories of personal information as defined by the CCPA:
HMC has not collected sensitive personal information as defined under CPRA (such as precise geolocation, financial account numbers, racial or ethnic origin, biometric data, or health data in a clinical context) through its digital platforms in the past 12 months, except for HIPAA training records of volunteers maintained for legal compliance.
California residents may request information about personal data we disclosed to third parties for their direct marketing purposes during the preceding calendar year. HMC does not disclose personal information to third parties for their direct marketing purposes. If this practice ever changes, California residents will have the right to request a list of such disclosures at no charge once per year.
HMC complies with CalOPPA. This Privacy Policy is posted prominently on our website, discloses what information we collect and how it is used, and describes how you can access and correct your information.
To the extent HMC's activities involve medical information as defined under California Health and Safety Code Section 56.05, HMC is committed to complying with the CMIA. HMC does not share medical information about identified individuals without authorization except as permitted by law.
HMC's privacy practices are designed to be transparent and non-deceptive. We do not engage in any unfair, deceptive, or misleading practices regarding our collection or use of personal information. California residents who believe HMC has engaged in deceptive privacy practices may have rights under the CLRA and are encouraged to contact us first to resolve concerns.
Some browsers include a "Do Not Track" (DNT) feature that sends a signal to websites requesting that your browsing activity not be tracked. Currently, there is no industry standard for how websites should respond to DNT signals. HMC's platforms do not currently respond to DNT signals in a manner that would change data collection behavior. We use Google Analytics with IP anonymization enabled to minimize the identifiability of analytics data.
California law requires that we disclose our response to DNT signals. We have made that disclosure here. We will update this section if our practices change or if an industry standard emerges.
HMC may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or organizational operations. When we make material changes, we will:
Your continued use of HMC's platforms after the effective date of a revised Privacy Policy constitutes your acceptance of the updated practices. If the changes are material and you do not agree, you should stop using the affected platforms and contact us to request deletion of your data.
For any privacy questions, to exercise your CCPA rights, or to report a privacy concern:
Email: privacy@healthmatters.clinic
Phone: (323) 990-4325
Health Matters Clinic
Los Angeles, California
Website: healthmatters.clinic