Privacy Policy
Last updated February 21, 2025.
Thank you for choosing to be part of our community at Rlin, LLC (“Rlin, LLC”, “Rlin”, “Brightway Health”, “Brightway”, “we”, “us”, or “our”). We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about this privacy notice, or our practices with regards to your personal information, please contact us at privacy@moveshealth.com.
When you use our website, mobile application, web application (together, the “Platform), or use any of our services (the "Services", which include the Platform), we appreciate that you are trusting us with your personal information. We take your privacy very seriously. In this privacy notice, we seek to explain to you in the clearest way possible what information we collect, how we use it and what rights you have in relation to it. We hope you take some time to read through it carefully, as it is important. If there are any terms in this privacy notice that you do not agree with, please discontinue use of our Services immediately.
This privacy notice applies to all information collected through our Services, as well as any related services, sales, marketing or events. Please read this privacy notice carefully as it will help you understand what we do with the information that we collect.
Table of Contents
1. What information do we collect?
Personal information you disclose to us
We collect personal information that your medical provider provides to us when they create an account for you, or that you voluntarily provide to us when you update your account, express an interest in obtaining information about us or our products and Services, when you use the Platform, or otherwise when you contact us.
The personal information that we collect depends on the context of your interactions with us and the Platform, the choices you make and the products and features you use. The personal information we collect may include the following:
Personal Information. We collect names; phone numbers; email addresses; dates of birth; contact preferences; contact or authentication data; profile pictures; passwords; and other similar information.
Social Media Login Data. We may provide you with the option to register with us using your existing social media account details, like your Google or other social media account. If you choose to register in this way, we will collect the information described in the section called "How do we handle your social logins" below.
All personal information that you provide to us must be true, complete and accurate, and you must notify us of any changes to such personal information.
Information automatically collected
We automatically collect certain information when you visit, use or navigate the Platform. Unless you log in, this information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about when you use our Platform and other technical information. This information is primarily needed to maintain the security and operation of our Platform, and for our internal analytics and reporting purposes.
Like many businesses, we also collect information through cookies and similar technologies. The information we collect includes:
Log and Usage Data. Log and usage data is service-related, diagnostic usage and performance information our servers automatically collect when you access or use our Platform and which we record in log files. Depending on how you interact with us, this log data may include your IP address, device information, browser type and settings and information about your activity in the Platform (such as the date/time stamps associated with your usage, pages and files viewed, searches and other actions you take such as which features you use), device event information (such as system activity, error reports (sometimes called 'crash dumps') and hardware settings).
Device Data. We collect device data such as information about your computer, phone, tablet or other device you use to access the Platform. Depending on the device used, this device data may include information such as your IP address (or proxy server), device application identification numbers, location, browser type, hardware model Internet service provider and/or mobile carrier, operating system configuration information.
Location Data. We collect information data such as information about your device's location, which can be either precise or imprecise. How much information we collect depends on the type of settings of the device you use to access the Platform. For example, we may use GPS and other technologies to collect geolocation data that tells us your current location (based on your IP address). You can opt out of allowing us to collect this information either by refusing access to the information or by disabling your Locations settings on your device. Note however, if you choose to opt out, you may not be able to use certain aspects of the Services.
Information collected through our Platform
If you use our Platform, we also collect the following information:
Mobile Device Access. We may request access or permission to certain features from your mobile device, including your mobile device's reminders, camera, microphone and other features. If you wish to change our access or permissions, you may do so in the Platform or your device's settings.
Push Notifications. We may request to send you push notifications regarding your account or certain features of the Platform. If you wish to opt-out from receiving these types of communications, you may turn them off in the Platform or in your device's settings.
This information is primarily needed to maintain the security and operation of our Platform, for troubleshooting and for our internal analytics and reporting purposes.
Information collected from other sources
In order to enhance our ability to provide relevant marketing, offers and services to you and update our records, we may obtain information about you from other sources, such as public databases, joint marketing partners, affiliate programs, data providers, social media platforms, as well as from other third parties. This information includes mailing addresses, job titles, email addresses, phone numbers, intent data (or user behavior data), Internet Protocol (IP) addresses, social media profiles, social media URLs and custom profiles, for purposes of targeted advertising and event promotion. If you interact with us on a social media platform using your social media account (e.g. Facebook or Twitter), we receive personal information about you such as your name, email address, and gender. Any personal information that we collect from your social media account depends on your social media account's privacy settings.
2. How do we use your information?
We use personal information collected via our Platform for a variety of business purposes described below. We process your personal information for these purposes for our business interests, to enter into or perform a contract with you, with your consent, and/or for compliance with our legal obligations. We indicate the specific processing grounds we rely on next to each purpose listed below.
We use the information we collect or receive:
To facilitate account creation and login process. If you choose to link your account with us to a third-party account (such as your Google or Facebook account), we use the information you allowed us to collect from those third parties to facilitate account creation and login process for the performance of the contract. See the section below headed "How do we handle your social logins" for further information.
To post testimonials. We post testimonials that may contain personal information. Prior to posting a testimonial, we will obtain your consent to use your name and the consent of the testimonial. If you wish to update, or delete your testimonial, please contact us at privacy@moveshealth.com and be sure to include your name, testimonial location, and contact information.
Request feedback. We may use your information to request feedback and to contact you about your use of our Platform.
To enable user-to-user communications. We may use your information in order to enable user-to-user communications with each user's consent.
To manage user accounts. We may use your information for the purposes of managing our account and keeping it in working order.
To send administrative information to you. We may use your personal information to send you product, service and new feature information and/or information about changes to our terms, conditions, and policies.
To protect our Services. We may use your information as part of our efforts to keep our Platform safe and secure (for example, for fraud monitoring and prevention).
To enforce our terms, conditions and policies for business purposes, to comply with legal and regulatory requirements or in connection with our contract.
To respond to legal requests and prevent harm. If we receive a subpoena or other legal request, we may need to inspect the data we hold to determine how to respond.
To deliver and facilitate delivery of services. We may use your information to provide you with a requested service.
To respond to your inquiries or offer support. We may use your information to respond to your inquiries and solve any potential issues you might have with the use of our Services.
To send you marketing and promotional communications. We and/or our third-party marketing partners may use the personal information you send to us for our marketing purposes, if this is in accordance with your marketing preferences. For example, when expressing an interest in obtaining information about us or our Platform, subscribing to marketing or otherwise contacting us, we will collect personal information from you. You can opt-out of our marketing emails at any time (see the "What are your privacy rights?" below).
Deliver targeted advertising to you. We may use your information to develop and display personalized content and advertising (and work with third parties who do so) tailored to your interests and/or location and to measure its effectiveness.
For other business purposes. We may use your information for other business purposes, such as data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns or to evaluate and improve our Platform, products, marketing and your experience. We may use and store this information in aggregated and anonymized form so that it is not associated with individual end users and does not include personal information. We will never use identifiable personal information without your consent, and only where allowable under HIPAA.
3. Will your information be shared with anyone?
We may disclose your information in the following circumstances:
Disclosures to Service Providers and Rlin, LLC Partners
Rlin, LLC, and third party vendors acting on our behalf, may disclose your information to Rlin Partners, third party service providers, or vendors acting on our behalf, for the purpose of providing the Services and related services to you or other users, including, without limitation, determining eligibility, registering you to use the Services, logging you into the Services, providing you with information you have requested through the Services or related services, connecting you with resources and other benefits, filing of medical claims, managing your account, and for Rlin Partners’ administration of benefits. Third party service providers or vendors acting on our behalf are authorized to use your information to provide services to Rlin, LLC or as required by law, and they are also permitted to aggregate or de-identify your Information, including Personal Data, such that it does not personally identify you.
Rlin, LLC does not disclose Personal Data to third parties for their direct marketing purposes.
Additional Disclosures with Your Consent. With your consent outside of this Privacy Policy, we or an Rlin Partner may share your information with third parties or allow them to collect information from the Services in some ways not specifically described in this Privacy Policy. For example, sharing information to streamline your log-in or registration to allow you to use services provided by a third party, such as a healthcare provider.
Security and Compliance with Law. Your information and the contents of your communications through the Services may be disclosed to third parties as required by law, such as to comply with a subpoena or similar legal process, or when we reasonably believe disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, report improper or unlawful activity, or respond to a government request.
Sale, Merger or Similar Business Transaction. We may share your Information in connection with any proposed or actual merger, reorganization, a sale of some or all our assets, a financing or acquisition of all or a portion of our business by another company, or to a receiver, trustee or successor in interest in bankruptcy, in which case such company may continue to process your Information as set forth in this Privacy Policy (except where prohibited by law) or otherwise with your consent.
Non-Personal and Aggregate Services Use Information. Rlin, LLC may compile and share your Information in aggregated form (i.e., in a manner that would not personally identify you) or in de-identified form so that it cannot reasonably be used to identify an individual (“De-Identified Information”). We may disclose such De-Identified Information publicly and to third parties, for example, in public reports about exercise and activity, or to Rlin Partners under agreement with us. Rlin, LLC may also disclose De-Identified Information for general research purposes and in research collaborations with third parties, such as universities, hospitals or other laboratories to determine the prevalence of particular conditions among Users or to determine whether a User might be suitable for research or clinical trials. Rlin, LLC may also use De-Identified Information for commercial collaborations with private companies for purposes such as product design or enhancement of Services.
Uses and Disclosures Permitted by Law, Including for Health Care Operations, Public Health, and Research. To the extent not prohibited by law or precluded by Rlin’s agreements with the applicable Rlin Partner and any third party vendors acting on Rlin’s behalf, may use and disclose your Personal Data: (a) as required or permitted by law, including, where applicable, HIPAA, which may include disclosures to the applicable Rlin Partner; (b) for Research purposes; (c) for purposes of Health Care Operations of the applicable Rlin Partner; and (d) for Public Health, as each is defined and in accordance with HIPAA.
4. The technologies we use for automatic data collection
We and our partners use various technologies to collect and store information when you visit one of our services, such as information about your browser or device. The technologies that we may use for automatic data collection may include:
1. Cookies. A cookie is a small file placed on the hard drive of your computer. You may refuse to accept browser cookies by activating the appropriate setting on your browser. However, if you select this setting you may be unable to access certain parts of our services. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our Services.
2. Web Beacons. Pages of our Services or our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags and single-pixel gifs) that permit us, for example, to count Users who have visited those pages or opened an e-mail and for other related website statistics (for example, recording the popularity of certain website content and verifying system and server integrity).
3. Website Logging Tools. Clickstream data is information collected via website logging tools by our computers when you request web pages from the Services. Clickstream data may include information such as the page served, the time spent viewing the page, source of the request, type of browser making the request, the preceding page viewed and similar information. Clickstream data permits us to analyze how visitors arrive at the Services, what type of content is popular, what type of visitors in the aggregate are interested in particular kinds of content on the Services.
4. Mobile Device Identifiers and SDKs. A mobile SDK is the mobile app version of a web beacon (see “Web Beacons” above). The SDK is a bit of computer code that app developers can include in their apps to enable ads to be shown, data to be collected, and related services or analytics to be performed.
5. Additional Technologies: Network Advertisers and other Advertising. Third party companies that manage and deliver advertisements to websites and applications are commonly referred to as “network advertisers.” A permitted network advertiser may use cookies, web beacons or similar technologies to collect information about your interaction with the Services or to tailor certain advertisements and content delivered within the Services or on other websites within such network advertiser’s ad network. These companies may also use non-cookie technologies to recognize your computer or device and/or to collect and record information about your web activity including your activities on or off of the Services. Rlin, LLC does not control these third party technologies and their use is governed by the privacy policies of the third parties using such technologies.
We share certain data with social media networks and search engine platforms to allow us to target existing or prospective customers with highly relevant advertising campaigns. For a description of how social media networks handle your information, please refer to their respective privacy policies and terms of use, which may permit you to modify your privacy settings.
5. How do we handle your social logins?
Our Platform may offer you the ability to register and login using your third-party social media account details (like your Google login). Where you choose to do this, we will receive certain profile information about you from your social media provider. The profile information we receive may vary depending on the social media provider concerned, but will often include your name, email address, profile picture as well as other information you choose to make public on such social media platforms.
We will use the information we receive only for the purposes that are described in this privacy notice or that are otherwise made clear to you on the relevant Platform. Please note that we do not control, and are not responsible for, other uses of your personal information by your third-party social media provider. We recommend that you review their privacy notice to understand how they collect, use and share your personal information, and how you can set your privacy preferences on their sites and apps.
6. How long do we keep your information?
We may retain your Personal Data for a period of time consistent with the original purpose for collection. For example, we keep your Personal Data for no longer than reasonably necessary for your use of our programs and Services and for a reasonable period afterward. We may retain your Personal Data even after your business relationship with us ends, if reasonably necessary to comply with our legal obligations (including law enforcement requests), comply with HIPAA, meet regulatory requirements, resolve disputes, maintain security, prevent fraud and abuse, enforce our Terms and Conditions, in copies made for backup and business continuity purposes, or to fulfill your request to “unsubscribe” from further messages from us. We will retain De-Identified information after your account has been closed. Our servers are located in the United States of America.
7. Children
Our Services are not designed to be used by or intended to attract children under the age of 13. Individuals who we actually know are under the age of 13 will not be permitted to use our Services and we will not collect their personal information. We do not share the personal information of consumers we know to be less than 16 years of age, unless we receive affirmative authorization (the “Right to Opt In”) from the minor who is between 13 and 16 years of age. If you are a parent or guardian and you are aware that your child who is under the age of 13 has provided us with identifiable personal data, please contact us. If we become aware that we have inadvertently collected data from children under the age of 13 without verification of parental consent, we will remove that information in a timely manner from Our servers to the extent permissible by law.
8. Your rights with respect to personal data
You may have certain rights relating to your Personal Data, subject to local data protection law. We aim to provide you with choices about how we use your Personal Data.
Subject to applicable law, you may request to access, update, correct, or delete the information we maintain about you by contacting us at privacy@moveshealth.com. To help protect your privacy and maintain security, we will take steps to verify your identity before granting you access to the information.
The European Union’s General Data Protection Regulation (GDPR) and other countries’ privacy laws provide certain rights for data subjects. Data Subject rights under GDPR include the following:
Right to be informed
Right of access
Right to rectification
Right to erasure
Right to restrict processing
Right of data portability
Right to object
Rights related to automated decision making including profiling
This Privacy Policy is intended to provide you with information about what personal data Rlin, LLC collects about you and how it is used.
If you wish to confirm that Rlin, LLC is processing your personal data, or to have access to the personal data Rlin, LLC may have about you, please contact us.
You may also request information about: the purpose of the processing; the categories of personal data concerned; who else outside Rlin, LLC might have received the data from Rlin, LLC; what the source of the information was (if you didn’t provide it directly to Rlin, LLC); and how long it will be stored. You have a right to correct (rectify) the record of your personal data maintained by Rlin, LLC if it is inaccurate. You may request that Rlin, LLC erase that data or cease processing it, subject to certain exceptions. You may also request that Rlin, LLC cease using your data for direct marketing purposes. In many countries, you have a right to lodge a complaint with the appropriate data protection authority if you have concerns about how Rlin, LLC processes your personal data. When technically feasible, Rlin, LLC will—at your request—provide your personal data to you.
Reasonable access to your personal data will be provided at no cost. If access cannot be provided within a reasonable time frame, Rlin, LLC will provide you with a date when the information will be provided. If for some reason access is denied, Rlin, LLC will provide an explanation as to why access has been denied.
For questions or complaints concerning the processing of your personal data, you can email us at privacy@moveshealth.com. Alternatively, if you are located in the European Union, you can also have recourse to the European Data Protection Supervisor or with your nation’s data protection authority.
Transferring personal data to the U.S.
Rlin, LLC has its headquarters in the United States. Information we collect about you will be processed in the United States. By using Rlin, LLC’s services, you acknowledge that your personal information will be processed in the United States. The United States has not sought nor received a finding of “adequacy” from the European Union under Article 45 of the GDPR. Pursuant to Article 46 of the GDPR, Rlin, LLC is providing for appropriate safeguards by entering binding, standard data protection clauses, enforceable by data subjects in the EEA and the UK. These clauses have been enhanced based on the guidance of the European Data Protection Board and will be updated when the new draft model clauses are approved.
Depending on the circumstance, Rlin, LLC also collects and transfers to the U.S. personal data with consent; to perform a contract with you; or to fulfill a compelling legitimate interest of Rlin, LLC in a manner that does not outweigh your rights and freedoms. Rlin, LLC endeavors to apply suitable safeguards to protect the privacy and security of your personal data and to use it only consistent with your relationship with Rlin, LLC and the practices described in this Privacy Statement. Rlin, LLC also enters into data processing agreements and model clauses with its vendors whenever feasible and appropriate. Since it was founded, Rlin, LLC has received zero government requests for information.
For more information or if you have any questions, please contact us at privacy@moveshealth.com.
9. Our opt-in / opt-out policy
By providing an email address on the Services, you agree that we may contact you in the event of a change in this Privacy Policy, to provide you with any Service-related notices, or to provide you with information about our events, invitations, or related educational information.
For purposes of this Privacy Policy, “opt-in” is generally defined as any affirmative action by a User to submit or receive information, as the case may be.
We currently provide the following opt-out opportunities:
At any time, you can follow a link provided in offers, newsletters or other email messages (except for e-commerce confirmation or service notice emails) received from us or an Rlin Partner to unsubscribe from communications.
At any time, you can contact us through privacy@moveshealth.com or the address or telephone number provided below to unsubscribe from communications and services and opt-out of our right per your consent under the terms of this Privacy Policy to share your Personal Data.
Notwithstanding anything else in this Privacy Policy, please note that we always reserve the right to contact you in the event of a change in this Privacy Policy, or to provide you with any Service-related notices.
10. Third party links
Our Services may contain links that enable you to visit or use other third party websites, resources or programs. However, we do not have control over the other websites, resources, or programs that you choose to visit, so this Privacy Policy does not apply to information collected or that you provide while visiting such other websites, resources, or programs. You should refer to the privacy policies, if any, applicable to the other websites, resources, or programs.
11. How we protect personal data
Rlin, LLC maintains administrative, technical and physical safeguards designed to protect users’ information against accidental, unlawful or unauthorized destruction, loss, alteration, access, disclosure or use. These safeguards vary based on the sensitivity of the information that we collect, process and store and the current state of technology. No method of transmission over the Internet, or method of electronic storage, is 100% secure, however. Therefore, we cannot guarantee its absolute security. We also maintain procedures to help ensure that such data is reliable for its intended use and is accurate, complete and current.
12. Direct marketing and “Do Not Track” signals
Rlin, LLC does not respond to Do Not Track (DNT) signals. However, some third party sites do keep track of your browsing activities when they serve you content, which enables them to tailor what they present to you. If you are visiting such sites, your browser may include controls to block and delete cookies, web beacons and similar technologies, to allow you to opt out of data collection through those technologies.
13. Changes to the terms of this policy
We may update this privacy notice from time to time. The updated version will be indicated by an updated “Revised” date and the updated version will be effective as soon as it is accessible. If we make material changes to this privacy notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this privacy notice frequently to be informed of how we are protecting your information.
14. How you can contact us about this policy
If you have questions or comments about this notice, you may email us at privacy@moveshealth.com.