Privacy Policy

Effective Date: June 1, 2026 · Last Updated: June 1, 2026 · Version 1.0

Your privacy matters to us. Health Matters Clinic is a nonprofit serving the Los Angeles community. We collect only the data we need to coordinate services, run events, support volunteers, and connect people to resources. We do not sell your personal information. This policy explains what we collect, how we use it, and the rights you have under California law.

01. Who We Are

Health Matters Clinic ("HMC," "we," "us," or "our") is a 501(c)(3) nonprofit organization located in Los Angeles, California. We advance health equity by providing free community events, wellness tools, volunteer coordination, and resource navigation services to individuals throughout Los Angeles County and surrounding areas.

This Privacy Policy applies to personal information collected by HMC through our digital platforms, websites, forms, and communications. It does not apply to the personal health information of patients receiving in-person or telehealth clinical services, which is governed by separate HIPAA-compliant notices provided at the point of care.

02. Platforms This Policy Covers

This Privacy Policy applies to the following HMC digital platforms:

03. Data Collected Per Platform

We are transparent about exactly what data each platform collects. The following describes what we collect from each service.

Main Website (healthmatters.clinic)

Event Finder (eventfinder.healthmatters.clinic)

Volunteer Portal (volunteer.healthmatters.clinic)

Partner Portal (partner.healthmatters.clinic)

CalmKit (calmkit.healthmatters.clinic)

Resource Directory (healthmatters.clinic/resources)

Gumroad Digital Companion

04. How We Use Your Data

We use personal information for the following purposes:

PurposeData UsedLegal Basis
Event coordination and RSVP managementName, email, phone numberConsent (RSVP submission)
SMS event notifications and remindersPhone number, event detailsConsent (opt-in at RSVP)
Volunteer program management and schedulingName, email, phone, address, availability, skillsConsent (volunteer application)
Volunteer HIPAA training and compliance trackingTraining completion data, timestampsLegal compliance obligation
Partner organization coordination and referral trackingOrg info, contact info, referral recordsContractual necessity
Platform security and fraud preventionIP address, login activity, reCAPTCHA dataLegitimate interest
Website and platform analyticsAnonymized usage data via Google AnalyticsLegitimate interest
Responding to inquiries and support requestsContact form data, email addressConsent (inquiry submission)
Organizational communications and newslettersEmail address (opted-in subscribers only)Consent (explicit opt-in)
Legal compliance and record-keepingAs required by applicable lawLegal obligation

We do not use your data for automated profiling or algorithmic decision-making that produces legal or similarly significant effects on you.

05. SMS and Text Message Consent

5.1 SMS Program Description

HMC sends SMS text messages through Twilio for the following purposes:

5.2 How to Consent

You consent to SMS by providing your mobile phone number and submitting an RSVP or registration form on any HMC platform. Consent is required before we send any SMS messages. Your consent is not a condition of accessing any free HMC service or resource.

5.3 How to Opt Out

You may opt out of SMS communications at any time by:

After opting out, you will receive a single confirmation text confirming your opt-out. No further messages will be sent. If you opt back in later, the process starts fresh.

5.4 Message Frequency and Costs

Message frequency varies by event and activity. Message and data rates may apply based on your mobile carrier plan. HMC does not charge for SMS messages on our end. For help, reply HELP to any HMC text message or email contact@healthmatters.clinic.

5.5 Twilio as SMS Provider

SMS messages are delivered via Twilio Inc. Twilio processes phone numbers and message content as a service provider on behalf of HMC. Twilio does not use your phone number for its own marketing. HMC maintains a deduplication system to prevent repeated identical messages.

06. Health-Adjacent Data: CalmKit Self-Screening

CalmKit Is Intentionally Anonymous

CalmKit self-screening responses, mood check-ins, coaching prompts, and any wellness inputs are processed entirely within your browser session. These responses are never transmitted to HMC's servers, never stored in any database, and never shared with any person or third party.

When you close your browser tab or reset the session, all inputs are permanently discarded. There is no account, no history, and no record of your CalmKit session in any HMC system.

CalmKit is designed this way intentionally. We recognize that wellness and mental health reflection is deeply personal. We built CalmKit to give you a private space without creating any data trail.

6.1 What Is Collected in CalmKit

The only data collected by HMC during a CalmKit session is anonymous technical data necessary for platform operation, including session duration, general device type, and error logs. This data cannot be linked back to any individual and is used only for debugging and performance monitoring.

6.2 Not a HIPAA Covered Entity for Digital Tools

HMC's digital wellness tools, including CalmKit, are not operated as a HIPAA-covered entity in the context of those tools. CalmKit does not create a provider-patient relationship and does not collect protected health information (PHI) as defined under HIPAA. If you receive in-person or telehealth clinical care from HMC directly, your PHI is handled under a separate HIPAA Notice of Privacy Practices provided to you at the time of care.

07. Third-Party Service Providers

HMC uses the following third-party services to operate our platforms. Each provider acts as a service provider or data processor and is contractually prohibited from using your data for their own purposes beyond service delivery.

ProviderPurposeData SharedPrivacy Policy
Google AnalyticsWebsite usage analytics and traffic measurementAnonymized browsing data, IP address (anonymized), device typepolicies.google.com/privacy
Google Firebase & FirestoreBackend database, authentication, and cloud infrastructureVolunteer profile data, RSVP data, partner data, authentication tokensfirebase.google.com/support/privacy
Google Cloud PlatformCloud hosting and compute (Cloud Run, us-central1)Application data processed through our hosted servicescloud.google.com/privacy
TwilioSMS delivery for event and volunteer notificationsPhone numbers and message content for opted-in userstwilio.com/legal/privacy
WebflowWebsite hosting and content management for main siteWeb traffic data, CMS content, form submissions on Webflow-hosted pageswebflow.com/legal/privacy
Google reCAPTCHABot prevention and form spam protectionBrowser and behavioral data to assess whether a submission is humanpolicies.google.com/privacy
Google OAuthAccount authentication for Volunteer PortalGoogle account email address and identifier (no password stored by HMC)policies.google.com/privacy
GumroadDigital product distribution and payment processingEmail address, payment data (handled by Gumroad; not shared with HMC)gumroad.com/privacy
CloudflareDNS management and DDoS protectionIP addresses, network traffic metadatacloudflare.com/privacypolicy
Google Apps ScriptEvent RSVP processing and email notificationsRSVP form data (name, email, phone) processed via Google Workspacepolicies.google.com/privacy

We do not authorize these service providers to use, sell, retain, or disclose your personal information for any purpose other than performing services for HMC. We evaluate our service providers for privacy compliance and require contractual data processing protections where applicable.

08. Data Sharing and Disclosure

8.1 We Do Not Sell Your Data

Health Matters Clinic does not sell, rent, trade, or lease your personal information to any third party for monetary or other valuable consideration. This applies to all categories of personal information we collect.

8.2 When We Share Data

We may share your information only in the following circumstances:

8.3 Aggregated and De-identified Data

HMC may use and share aggregated, de-identified data that cannot reasonably be used to identify you (for example, "150 community members attended HMC events in May") for reporting, grant applications, public health research, and organizational communications. This data is not personal information.

8.4 No Cross-Platform Data Combination for Marketing

HMC does not combine data from different platforms to create marketing profiles or behavioral advertising segments. Data collected on the Event Finder is used for event coordination. Data collected on the Volunteer Portal is used for volunteer management. These datasets are kept functionally separate.

09. Data Retention

We retain personal information only as long as necessary to fulfill the purpose for which it was collected, to comply with legal obligations, and to resolve any disputes.

Data TypeRetention PeriodReason
Event RSVP data (name, email, phone)24 months from event dateFollow-up outreach and event history
Volunteer application and profile dataDuration of active volunteer status + 3 yearsProgram records, training compliance, reference
Volunteer HIPAA training records6 years from completionHIPAA compliance requirement
Partner organization dataDuration of partnership + 5 yearsLegal compliance, referral records
CalmKit session dataNot retained (session-only)By design: anonymous tool
Website analytics data (Google Analytics)26 months (Google default)Trend analysis and platform improvement
Contact form submissions24 monthsInquiry follow-up and records
SMS opt-out recordsIndefinitelyCompliance with opt-out requests
Gumroad purchase recordsPer Gumroad's policy (HMC has limited visibility)Transaction history

Upon expiration of retention periods, we delete or de-identify personal information in a manner consistent with applicable law and our security practices.

10. Security

HMC implements reasonable and appropriate technical and organizational security measures to protect personal information from unauthorized access, disclosure, alteration, or destruction. Our security practices include:

Despite these measures, no system is perfectly secure. We cannot guarantee that data transmitted over the internet or stored on our systems will never be accessed by unauthorized parties. If you believe a security incident has occurred involving your data, please contact us immediately at privacy@healthmatters.clinic.

In the event of a data breach affecting California residents, HMC will provide notification as required by California Civil Code Section 1798.82 and any other applicable notification requirements.

11. Children's Privacy

HMC's digital platforms are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected information from a child under 13 without verifiable parental consent, we will delete that information promptly.

Volunteers must be at least 16 years old. Volunteers between the ages of 16 and 17 must have verifiable parental or guardian consent on file with HMC before participating in any volunteer activities.

If you are a parent or guardian and believe that your minor child has provided personal information to HMC without your consent, please contact us at privacy@healthmatters.clinic and we will promptly investigate and, where appropriate, delete the information.

This policy is consistent with the federal Children's Online Privacy Protection Act (COPPA) and California law.

12. California Privacy Rights (CCPA)

Your California Privacy Rights

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you specific rights regarding your personal information. Health Matters Clinic is committed to honoring these rights.

12.1 Right to Know

You have the right to request that HMC disclose:

12.2 Right to Delete

You have the right to request that HMC delete personal information we have collected from you, subject to certain exceptions. We may retain information where necessary to:

If an exception applies, we will inform you and explain the basis for retaining the data.

12.3 Right to Correct

Under the CPRA, you have the right to request correction of inaccurate personal information we hold about you. You can update most profile information directly in your Volunteer Portal account. For corrections to data held elsewhere, contact privacy@healthmatters.clinic.

12.4 Right to Opt Out of Sale or Sharing

HMC does not sell personal information and does not share personal information for cross-context behavioral advertising. Because we do not engage in these activities, there is currently nothing to opt out of under these specific CCPA provisions. However, if this practice ever changes, we will provide a clear "Do Not Sell or Share My Personal Information" link on our website and provide 30 days' notice before implementation.

12.5 Right to Limit Use of Sensitive Personal Information

To the extent HMC collects sensitive personal information as defined under the CPRA (such as health-related data in a clinical context), you have the right to limit its use to what is necessary to provide services you requested. For volunteers, HIPAA training records constitute sensitive data retained for legal compliance purposes.

12.6 Right to Non-Discrimination

HMC will not discriminate against you for exercising your CCPA rights. We will not deny you services, charge different prices, provide a different level or quality of service, or suggest that you will receive inferior treatment because you exercised your privacy rights. Since all of HMC's core community services are free, there is no pricing mechanism that could be used in a discriminatory manner.

12.7 How to Submit a CCPA Request

To exercise any of the rights described above, you may:

We will acknowledge receipt of your request within 10 business days and respond substantively within 45 calendar days. If we need more time (up to an additional 45 days), we will notify you in writing with the reason for the extension.

We will verify your identity before processing your request using reasonable verification measures, such as matching information you provide with our records. We will not require you to create an account or disclose information beyond what is necessary for verification.

12.8 Authorized Agents

You may designate an authorized agent to submit a CCPA request on your behalf. The authorized agent must provide written permission signed by you, and we may still verify your identity directly. We will not require direct verification from you if your authorized agent provides a valid power of attorney executed pursuant to California Probate Code Sections 4121-4130.

12.9 Categories of Personal Information Collected (CCPA Disclosure)

In the past 12 months, HMC has collected the following categories of personal information as defined by the CCPA:

HMC has not collected sensitive personal information as defined under CPRA (such as precise geolocation, financial account numbers, racial or ethnic origin, biometric data, or health data in a clinical context) through its digital platforms in the past 12 months, except for HIPAA training records of volunteers maintained for legal compliance.

13. Other California Privacy Laws

13.1 California Shine the Light Law (Civil Code 1798.83)

California residents may request information about personal data we disclosed to third parties for their direct marketing purposes during the preceding calendar year. HMC does not disclose personal information to third parties for their direct marketing purposes. If this practice ever changes, California residents will have the right to request a list of such disclosures at no charge once per year.

13.2 California Online Privacy Protection Act (CalOPPA)

HMC complies with CalOPPA. This Privacy Policy is posted prominently on our website, discloses what information we collect and how it is used, and describes how you can access and correct your information.

13.3 California Confidentiality of Medical Information Act (CMIA)

To the extent HMC's activities involve medical information as defined under California Health and Safety Code Section 56.05, HMC is committed to complying with the CMIA. HMC does not share medical information about identified individuals without authorization except as permitted by law.

13.4 California Consumer Legal Remedies Act (CLRA)

HMC's privacy practices are designed to be transparent and non-deceptive. We do not engage in any unfair, deceptive, or misleading practices regarding our collection or use of personal information. California residents who believe HMC has engaged in deceptive privacy practices may have rights under the CLRA and are encouraged to contact us first to resolve concerns.

14. Do Not Track

Some browsers include a "Do Not Track" (DNT) feature that sends a signal to websites requesting that your browsing activity not be tracked. Currently, there is no industry standard for how websites should respond to DNT signals. HMC's platforms do not currently respond to DNT signals in a manner that would change data collection behavior. We use Google Analytics with IP anonymization enabled to minimize the identifiability of analytics data.

California law requires that we disclose our response to DNT signals. We have made that disclosure here. We will update this section if our practices change or if an industry standard emerges.

15. Changes to This Policy

HMC may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or organizational operations. When we make material changes, we will:

Your continued use of HMC's platforms after the effective date of a revised Privacy Policy constitutes your acceptance of the updated practices. If the changes are material and you do not agree, you should stop using the affected platforms and contact us to request deletion of your data.

16. Contact Our Privacy Team

Privacy Inquiries and CCPA Requests

For any privacy questions, to exercise your CCPA rights, or to report a privacy concern:

Email: privacy@healthmatters.clinic

Phone: (323) 990-4325

Health Matters Clinic
Los Angeles, California
Website: healthmatters.clinic

For general inquiries: contact@healthmatters.clinic
For volunteer matters: volunteer@healthmatters.clinic
For partnership inquiries: partner@healthmatters.clinic

Free wellness events near you. Find your next one on the HMC Event Finder. Find Events