Privacy Policy

Effective Date: June 1, 2026 · Last Updated: September 3, 2026 · Version 1.1

Your privacy matters to us. Health Matters Clinic is a nonprofit serving the Los Angeles community. We collect only the data we need to coordinate services, run events, support volunteers, and connect people to resources. We do not sell your personal information. This policy explains what we collect, how we use it, and the rights you have under California law.

01. Who We Are

Health Matters Clinic ("HMC," "we," "us," or "our") is a 501(c)(3) nonprofit organization located in Los Angeles, California. We advance health equity by providing free community events, wellness tools, volunteer coordination, and resource navigation services to individuals throughout Los Angeles County and surrounding areas.

This Privacy Policy applies to personal information collected by HMC through our digital platforms, websites, forms, and communications. It does not apply to the personal health information of patients receiving in-person or telehealth clinical services, which is governed by separate HIPAA-compliant notices provided at the point of care.

02. Platforms This Policy Covers

This Privacy Policy applies to the following HMC digital platforms:

03. Data Collected Per Platform

We are transparent about exactly what data each platform collects. The following describes what we collect from each service.

Main Website (healthmatters.clinic)

Event Finder (eventfinder.healthmatters.clinic)

Volunteer Portal (volunteer.healthmatters.clinic)

Partner Portal (partner.healthmatters.clinic)

CalmKit (calmkit.healthmatters.clinic)

Resource Directory (healthmatters.clinic/resources)

Gumroad Digital Companion

04. How We Use Your Data

We use personal information for the following purposes:

PurposeData UsedLegal Basis
Event coordination and RSVP managementName, email, phone numberConsent (RSVP submission)
SMS event notifications and remindersPhone number, event detailsConsent (opt-in at RSVP)
Volunteer program management and schedulingName, email, phone, address, availability, skillsConsent (volunteer application)
Volunteer HIPAA training and compliance trackingTraining completion data, timestampsLegal compliance obligation
Partner organization coordination and referral trackingOrg info, contact info, referral recordsContractual necessity
Platform security and fraud preventionIP address, login activity, reCAPTCHA dataLegitimate interest
Website and platform analyticsAnonymized usage data via Google AnalyticsLegitimate interest
Responding to inquiries and support requestsContact form data, email addressConsent (inquiry submission)
Organizational communications and newslettersEmail address (opted-in subscribers only)Consent (explicit opt-in)
Legal compliance and record-keepingAs required by applicable lawLegal obligation

We do not use your data for automated profiling or algorithmic decision-making that produces legal or similarly significant effects on you.

05. SMS and Text Message Consent

5.1 SMS Program Description

HMC sends SMS text messages through Twilio for the following purposes:

5.2 How to Consent

You opt in to SMS in one of two ways. On an HMC registration or RSVP form you enter your mobile number and tick a consent box that is unchecked by default. That box states the types of messages you will receive, that message frequency varies, that message and data rates may apply, and that you can reply STOP to unsubscribe or HELP for help. Alternatively you can text our published number, (323) 990-4325, where the same disclosures are displayed at healthmatters.clinic/sms. We do not send SMS to anyone who has not taken one of those two actions. Consent to receive text messages is never a condition of attending an event, receiving services, or getting help from HMC.

5.3 How to Opt Out

You may opt out of SMS communications at any time by:

After opting out, you will receive a single confirmation text confirming your opt-out. No further messages will be sent. If you opt back in later, the process starts fresh.

5.4 Message Frequency and Costs

Message frequency varies by event and activity. Message and data rates may apply based on your mobile carrier plan. HMC does not charge for SMS messages on our end. For help, reply HELP to any HMC text message or email contact@healthmatters.clinic.

5.5 Twilio as SMS Provider

SMS messages are delivered via Twilio Inc. Twilio processes phone numbers and message content as a service provider on behalf of HMC. Twilio does not use your phone number for its own marketing. HMC maintains a deduplication system to prevent repeated identical messages.

5.6 Mobile Information and Third Parties

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third parties.

The mobile number you give us, and the consent you give with it, are used only to send you the messages you asked to receive. That information is not sold, rented, traded, or shared with third parties or affiliates for marketing or promotional purposes. Twilio transmits the messages on our behalf as a service provider and does not use the information for its own marketing.

06. Health-Adjacent Data: CalmKit and Check Yourself

Your Individual Answers Never Leave Your Browser

Neither tool asks who you are. Neither creates an account. Neither stores the answers you give to individual questions: what you type or tap in CalmKit, and every individual item you answer in Check Yourself, stays in your browser and is discarded when you close or reset the session.

Both tools do send HMC a short, de-identified record after a session so we can tell whether the tools are helping and report totals to the funders who pay for them. Those records carry no name, email or phone number, and HMC never sees your individual answers. They are described in full in 6.1 and 6.2 below.

We recognize that wellness and mental health reflection is deeply personal, so we built both tools to be useful to you without building a profile of you.

6.1 What CalmKit Sends to HMC

When you finish a CalmKit session and rate how you feel, CalmKit sends us that rating (a number from 1 to 5), the type of session, how long it lasted, the distance walked if you used Guided Walk, and your language. It also sends a random identifier your browser generated for itself, which our server immediately converts into an irreversible hash so repeat sessions from one device can be counted once without that device being identifiable. This record is kept for 24 months and then deleted. Guided Walk asks your permission before using your location. If you allow it, your coordinates pass through our server to Google's weather and air quality services so the walk can describe the conditions around you, and HMC does not store them in any database. Meditation audio and guided coaching text are generated by Google Gemini and Google text-to-speech, requested through an HMC server so our API keys are not exposed in your browser.

6.2 What Check Yourself Sends to HMC, and HIPAA

Check Yourself uses two validated screening questionnaires, the PHQ-9 and the GAD-7. Your answers to the individual questions, and the numeric scores they produce, are never sent to HMC and are never stored anywhere. Only the severity band each questionnaire produces, such as "mild" or "moderate", leaves your browser. When your results appear, Check Yourself automatically sends us an anonymous record containing those two severity bands, whether the questionnaire indicated thoughts of self-harm, your language, and the same kind of irreversible per-device hash described above. That record contains no name, email or phone number, and is deleted after 30 days. If you choose to ask HMC to reach out to you, and only then, you give us a name and a way to contact you. Those details are stored separately from your screening record, linked only by a random session code, kept for 30 days, and emailed to HMC clinical staff so someone can follow up with you. You can use Check Yourself fully without taking this step. If the questionnaire indicates thoughts of self-harm, the results screen surfaces the 988 Suicide and Crisis Lifeline; Check Yourself is a screening tool, not a diagnosis, and it is not monitored in real time, so in an emergency call 988 or 911. HMC's digital wellness tools are not operated as a HIPAA-covered entity in the context of those tools, and using CalmKit or Check Yourself does not by itself create a provider-patient relationship. If you request follow-up, that request is handled by HMC clinical staff, and any care that follows is governed by the separate HIPAA Notice of Privacy Practices you receive at the point of care.

07. Third-Party Service Providers

HMC uses the following third-party services to operate our platforms. Each provider acts as a service provider or data processor and is contractually prohibited from using your data for their own purposes beyond service delivery.

ProviderPurposeData SharedPrivacy Policy
Google AnalyticsWebsite usage analytics and traffic measurementAnonymized browsing data, IP address (anonymized), device typepolicies.google.com/privacy
Google Firebase & FirestoreBackend database, authentication, and cloud infrastructureVolunteer profile data, RSVP data, partner data, authentication tokensfirebase.google.com/support/privacy
Google Cloud PlatformCloud hosting and compute (Cloud Run, us-central1)Application data processed through our hosted servicescloud.google.com/privacy
TwilioSMS delivery for event and volunteer notificationsPhone numbers and message content for opted-in userstwilio.com/legal/privacy
WebflowWebsite hosting and content management for main siteWeb traffic data, CMS content, form submissions on Webflow-hosted pageswebflow.com/legal/privacy
Google reCAPTCHABot prevention and form spam protectionBrowser and behavioral data to assess whether a submission is humanpolicies.google.com/privacy
Google OAuthAccount authentication for Volunteer PortalGoogle account email address and identifier (no password stored by HMC)policies.google.com/privacy
GumroadDigital product distribution and payment processingEmail address, payment data (handled by Gumroad; not shared with HMC)gumroad.com/privacy
CloudflareDNS management and DDoS protectionIP addresses, network traffic metadatacloudflare.com/privacypolicy
Google Apps ScriptEvent RSVP processing and email notificationsRSVP form data (name, email, phone) processed via Google Workspacepolicies.google.com/privacy

We do not authorize these service providers to use, sell, retain, or disclose your personal information for any purpose other than performing services for HMC. We evaluate our service providers for privacy compliance and require contractual data processing protections where applicable.

08. Data Sharing and Disclosure

8.1 We Do Not Sell Your Data

Health Matters Clinic does not sell, rent, trade, or lease your personal information to any third party for monetary or other valuable consideration. This applies to all categories of personal information we collect.

8.2 When We Share Data

We may share your information only in the following circumstances:

8.3 Aggregated and De-identified Data

HMC may use and share aggregated, de-identified data that cannot reasonably be used to identify you (for example, "150 community members attended HMC events in May") for reporting, grant applications, public health research, and organizational communications. This data is not personal information.

8.4 No Cross-Platform Data Combination for Marketing

HMC does not combine data from different platforms to create marketing profiles or behavioral advertising segments. Data collected on the Event Finder is used for event coordination. Data collected on the Volunteer Portal is used for volunteer management. These datasets are kept functionally separate.

09. Data Retention

We retain personal information only as long as necessary to fulfill the purpose for which it was collected, to comply with legal obligations, and to resolve any disputes.

Data TypeRetention PeriodReason
Event RSVP data (name, email, phone)24 months from event dateFollow-up outreach and event history
Volunteer application and profile dataDuration of active volunteer status + 3 yearsProgram records, training compliance, reference
Volunteer HIPAA training records6 years from completionHIPAA compliance requirement
Partner organization dataDuration of partnership + 5 yearsLegal compliance, referral records
CalmKit and Check Yourself dataIndividual answers not retained; de-identified session records 24 months; Check Yourself screening records and follow-up requests 30 daysBy design: anonymous tool
Website analytics data (Google Analytics)26 months (Google default)Trend analysis and platform improvement
Contact form submissions24 monthsInquiry follow-up and records
SMS opt-out recordsIndefinitelyCompliance with opt-out requests
Gumroad purchase recordsPer Gumroad's policy (HMC has limited visibility)Transaction history

Upon expiration of retention periods, we delete or de-identify personal information in a manner consistent with applicable law and our security practices.

10. Security

HMC implements reasonable and appropriate technical and organizational security measures to protect personal information from unauthorized access, disclosure, alteration, or destruction. Our security practices include:

Despite these measures, no system is perfectly secure. We cannot guarantee that data transmitted over the internet or stored on our systems will never be accessed by unauthorized parties. If you believe a security incident has occurred involving your data, please contact us immediately at privacy@healthmatters.clinic.

In the event of a data breach affecting California residents, HMC will provide notification as required by California Civil Code Section 1798.82 and any other applicable notification requirements.

11. Children's Privacy

HMC's digital platforms are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected information from a child under 13 without verifiable parental consent, we will delete that information promptly.

Volunteers must be at least 16 years old. Volunteers between the ages of 16 and 17 must have verifiable parental or guardian consent on file with HMC before participating in any volunteer activities.

If you are a parent or guardian and believe that your minor child has provided personal information to HMC without your consent, please contact us at privacy@healthmatters.clinic and we will promptly investigate and, where appropriate, delete the information.

This policy is consistent with the federal Children's Online Privacy Protection Act (COPPA) and California law.

12. California Privacy Rights (CCPA)

Your California Privacy Rights

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you specific rights regarding your personal information. Health Matters Clinic is committed to honoring these rights.

12.1 Right to Know

You have the right to request that HMC disclose:

12.2 Right to Delete

You have the right to request that HMC delete personal information we have collected from you, subject to certain exceptions. We may retain information where necessary to:

If an exception applies, we will inform you and explain the basis for retaining the data.

12.3 Right to Correct

Under the CPRA, you have the right to request correction of inaccurate personal information we hold about you. You can update most profile information directly in your Volunteer Portal account. For corrections to data held elsewhere, contact privacy@healthmatters.clinic.

12.4 Right to Opt Out of Sale or Sharing

HMC does not sell personal information and does not share personal information for cross-context behavioral advertising. Because we do not engage in these activities, there is currently nothing to opt out of under these specific CCPA provisions. However, if this practice ever changes, we will provide a clear "Do Not Sell or Share My Personal Information" link on our website and provide 30 days' notice before implementation.

12.5 Right to Limit Use of Sensitive Personal Information

To the extent HMC collects sensitive personal information as defined under the CPRA (such as health-related data in a clinical context), you have the right to limit its use to what is necessary to provide services you requested. For volunteers, HIPAA training records constitute sensitive data retained for legal compliance purposes.

12.6 Right to Non-Discrimination

HMC will not discriminate against you for exercising your CCPA rights. We will not deny you services, charge different prices, provide a different level or quality of service, or suggest that you will receive inferior treatment because you exercised your privacy rights. Since all of HMC's core community services are free, there is no pricing mechanism that could be used in a discriminatory manner.

12.7 How to Submit a CCPA Request

To exercise any of the rights described above, you may:

We will acknowledge receipt of your request within 10 business days and respond substantively within 45 calendar days. If we need more time (up to an additional 45 days), we will notify you in writing with the reason for the extension.

We will verify your identity before processing your request using reasonable verification measures, such as matching information you provide with our records. We will not require you to create an account or disclose information beyond what is necessary for verification.

12.8 Authorized Agents

You may designate an authorized agent to submit a CCPA request on your behalf. The authorized agent must provide written permission signed by you, and we may still verify your identity directly. We will not require direct verification from you if your authorized agent provides a valid power of attorney executed pursuant to California Probate Code Sections 4121-4130.

12.9 Categories of Personal Information Collected (CCPA Disclosure)

In the past 12 months, HMC has collected the following categories of personal information as defined by the CCPA:

In the past 12 months HMC has collected two categories of sensitive personal information as defined under CPRA. Health information: the de-identified session and screening records described in Section 6, the follow-up contact details you choose to provide through Check Yourself, and volunteer HIPAA training records retained for legal compliance. Precise geolocation: only where you grant CalmKit's Guided Walk permission, and only to retrieve local weather and air quality, as described in Section 6.1. HMC has not collected financial account numbers, racial or ethnic origin, religious or philosophical beliefs, union membership, genetic data, biometric data used to identify you, or the contents of your mail, email or text messages. HMC does not use sensitive personal information to infer characteristics about you, and does not sell or share it.

13. Other California Privacy Laws

13.1 California Shine the Light Law (Civil Code 1798.83)

California residents may request information about personal data we disclosed to third parties for their direct marketing purposes during the preceding calendar year. HMC does not disclose personal information to third parties for their direct marketing purposes. If this practice ever changes, California residents will have the right to request a list of such disclosures at no charge once per year.

13.2 California Online Privacy Protection Act (CalOPPA)

HMC complies with CalOPPA. This Privacy Policy is posted prominently on our website, discloses what information we collect and how it is used, and describes how you can access and correct your information.

13.3 California Confidentiality of Medical Information Act (CMIA)

To the extent HMC's activities involve medical information as defined under California Health and Safety Code Section 56.05, HMC is committed to complying with the CMIA. HMC does not share medical information about identified individuals without authorization except as permitted by law.

13.4 California Consumer Legal Remedies Act (CLRA)

HMC's privacy practices are designed to be transparent and non-deceptive. We do not engage in any unfair, deceptive, or misleading practices regarding our collection or use of personal information. California residents who believe HMC has engaged in deceptive privacy practices may have rights under the CLRA and are encouraged to contact us first to resolve concerns.

14. Do Not Track

Some browsers include a "Do Not Track" (DNT) feature that sends a signal to websites requesting that your browsing activity not be tracked. Currently, there is no industry standard for how websites should respond to DNT signals. HMC's platforms do not currently respond to DNT signals in a manner that would change data collection behavior. We use Google Analytics with IP anonymization enabled to minimize the identifiability of analytics data.

California law requires that we disclose our response to DNT signals. We have made that disclosure here. We will update this section if our practices change or if an industry standard emerges.

15. Changes to This Policy

HMC may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or organizational operations. When we make material changes, we will:

Your continued use of HMC's platforms after the effective date of a revised Privacy Policy constitutes your acceptance of the updated practices. If the changes are material and you do not agree, you should stop using the affected platforms and contact us to request deletion of your data.

16. Contact Our Privacy Team

Privacy Inquiries and CCPA Requests

For any privacy questions, to exercise your CCPA rights, or to report a privacy concern:

Email: privacy@healthmatters.clinic

Phone: (323) 990-4325

Health Matters Clinic
Los Angeles, California
Website: healthmatters.clinic

For general inquiries: contact@healthmatters.clinic
For volunteer matters: volunteer@healthmatters.clinic
For partnership inquiries: partner@healthmatters.clinic

Wellness events, workshops, and training. Find your next one on the HMC Event Finder. Find Events