Last Revised: January 13, 2020
I. Personal Information that Lively Collects
A. Information from the User
When you create an account to log in to our network (“Account”), you may be prompted to provide some or all of the following information in connection with our provision of the Services:
- Physical Address
- Mailing Address
- Social Security Number
- Employer Identification Number (EIN)
- Date of Birth
- Email Address
- Phone Number
- Health plan information
- Beneficiary Information
- Dependent information
- Receipts for medical expenses, which may contain PHI
- Existing Health Savings Account information (for rollover purposes)
- HSA-related investment account information
- Personal bank account information
- If you use our Services on your mobile device, including through our Application, we may collect your phone number and the unique device ID number.
- If you tell us where you are (e.g., by allowing your mobile device to send us your location), we may store and use that information to provide you with location-based information and advertising. If you want to deactivate this feature, you can deactivate GPS on your mobile device.
- Our Site may let you store preferences like how your content is displayed, your location, safe search settings, and favorite widgets. We may associate these choices with your ID, browser or the mobile device, and you can edit these preferences at any time.
- When connecting to our Services via a service provider that uniquely identifies your mobile device, we may receive this identification and use it to offer extended services and/or functionality.
- Certain Services, such as two-factor authentication, may require our collection of your phone number. We may associate that phone number to your mobile device identification information.
- We retain information on your behalf, such as files and messages that you store using your Account.
- If you provide us with feedback or contact us via email, we will collect your name and email address, as well as any other content included in the email, in order to send you a reply.
- If you post messages on the message boards of our Site, the information contained in your posting will be stored on our servers and other users will be able to see it.
- If you participate in one of our surveys, we may collect additional profile information.
- We also collect other types of Personal Information that you provide to us voluntarily, such as your operating system and version and other requested information if you contact us via email regarding support for the Services.
- We may also collect Personal Information at other points on our Site where it states that Personal Information is being collected.
B. Information Collected Automatically
- Information Collected by Our Servers. To make our Site and Services more useful to you, our servers (which may be hosted by a third party service provider) collect information from you, including your browser type, operating system, Internet Protocol (“IP”) address (a number that is automatically assigned to your computer when you use the Internet, which may vary from session to session), domain name, and/or a date/time stamp for your visit.
- Pixel Tags. In addition, we use “Pixel Tags” (also referred to as clear gifs, Web beacons, or Web bugs). Pixel Tags are tiny graphic images with a unique identifier, similar in function to Cookies, that are used to track online movements of Web users. In contrast to Cookies, which are stored on a user’s computer hard drive, Pixel Tags are embedded invisibly in Web pages. Pixel Tags also allow us to send email messages in a format users can read, and they tell us whether emails have been opened to ensure that we are sending only messages that are of interest to our users. We may use this information to reduce or eliminate messages sent to a user. We do not tie the information gathered by Pixel Tags to our users’ Personal Information.
- How We Respond to Do Not Track Signals. We do not currently respond to “do not track” signals or other mechanisms that might enable Users to opt out of tracking on our Site.
- Mobile Services. We may also collect non-Personal Information from your mobile device. This information is generally used to help us deliver the most relevant information to you. Examples of information that may be collected and used include your geographic location, how you use the Site and Services, and information about the type of device you use. This information is sent to us as aggregated information and is not traceable to any individual and cannot be used to identify an individual.
- Browsing-Session Tracking. We may track your browsing activities on our Site and Application in other ways, including by recording, the actions you take, the time you spend, and the features that you utilize. This information may be used to create Anonymous Data to help us better understand customer preferences and needs. Except to the extent we utilize third party services to assist in the collection of this data, we do not share this information with any other party.
C. Information Collected from Third Party Companies
We may receive Personal Information and/or Anonymous Data about you from companies that help us verify your identity, comply with legal obligations, and provide our Services. We may also receive Personal Information and/or Anonymous Data about you from co-branded or private-labeled websites or companies that offer their products and/or services on our Site. Additionally, we may receive certain publicly available information about you from companies we partner with to provide us market research. These third party companies may supply us with Personal Information. We may add this information to the information we have already collected from you via our Site in order to improve the Services we provide.
We may offer features and/or functionality that require you to enter other Personal Information. In these cases, we will use the information, including sharing the information with third parties as may be necessary, to provide the features and/or functionality described.
D. Information Collected from Employers, Payroll Companies, or Health Plans
If your Account was established by your employer or your health plan, they may have requested that we set up a communication channel whereby you can log into Lively’s portal (known as single sign on) or access your Account information through their site without entering your user name and password again. Your employer or health plan may have also contracted with another vendor that provides additional services, such as personal health care costs management or online benefits enrollment, that allows you to log into Lively’s portal or access your Account through that vendor’s website, also without entering your Lively username and password. When you use those websites to sign into Lively’s portal or access your Account, you are authorizing Lively’s system to pass on certain information, such as your account balances, to those systems.
E. Information Collected from Banks and Financial Institutions
We collect information from banks and/or financial institutions in several different cases.
If you had previously established an account through another provider with a bank or financial institution, we may receive information pertaining to your account, deposit and withdrawal history, and financial transactions.
In the establishment and ongoing maintenance of your Account with Lively, we will receive information from our banking and financial institution partners related to your Account in order to provide the Services.
You may receive separate terms and conditions from our partner financial institutions, which will also describe their processing of your personal information connected with the use of your Account.
If you establish an investment account through the Services, we will transmit and receive information between Lively and the investment institution to provide you with the Service.
F. Location Information
When you use our Site and Services, we may collect and process location information. If you do not want this information collected by us, you can disable location services on your phone.
II. Processing of Personal Information
We need certain Personal Information in order to provide you with access to the Site and/or the Services. We will only process your Personal Information in accordance with applicable data protection and privacy laws. If you registered with us, you will have been asked to check a tick box indicating your agreement to provide this data in order to access our Services and view our content. This consent provides us with the legal basis we require under applicable law to process your Personal Information. You maintain the right to withdraw such consent at any time. If you do not agree to our use of your Personal Information in line with this policy, please do not use our Site or Services.
A. Use of Your Personal Information
We use and retain your Personal Information in order to provide products and services and may, from time to time, provide such information to nonaffiliated third party service providers to perform services for or functions on behalf of us, to effect, administer, or enforce transactions authorized by you, including:
- To detect, analyze, and prevent security incidents.
- To audit our Site’s performance.
- To identify, debug, and repair any errors that impair existing intended functionality.
In order to deliver the Services to you, we will also use your information:
- To verify your identity, open and administer your Accounts, and provide other financial services under the USA PATRIOT Act;
- To link accounts you provide us to facilitate the movement of funds for savings, investment accounts, and payments, as directed by you;
- To communicate with you about your Account(s) and the Services;
- To make payments to medical service providers;
- To provide you with any health insurance information, if applicable;
- To help us protect you and us from financial loss;
- To prepare account statements; and
- To prepare annual tax reporting information, if applicable.
In addition, we will collect and store the following:
- Names and other identifying information of the dependents that are covered by your Account;
- Names and other identifying information of people authorized by you to use your Account;
- Names and other identifying information of people authorized by you to access your Account; and
- Transactions with us such as your Account balance, fees, payments, withdrawals, deposits/contributions, and the identity of persons to whom you make payments, including health care providers.
B. User Testimonials and Feedback
We often receive testimonials and comments from users who have had positive experiences with our Services. We occasionally publish such content. If we publish this content, we may identify our users by their first and last name and may also indicate their home city with the user’s consent. We may share your feedback with your first name and last initial only. If you make any comments on a blog or forum associated with our Site, you should be aware that any Personal Information you submit there can be read, collected, or used by other users of these forums, and could be used to send you unsolicited messages. We are not responsible for the personally identifiable information you choose to submit in these blogs and forums.
C. Anonymous Data
We may create Anonymous Data records from Personal Information by excluding information (such as your name) that makes the data personally identifiable to you. We use this Anonymous Data to analyze request and usage patterns so that we may enhance the content of our Services and improve Site navigation. We reserve the right to use Anonymous Data and aggregated and other de-identified information for any purpose and disclose Anonymous Data to third parties in our sole discretion.
D. Financial Institution Data
III. How Lively Shares Your Personal Information
A. Third Parties Designated by You
When you use the Services, the Personal Information you provide will be shared with third parties that you or your employer designate to receive such information. Depending on the type of access you or your employer grant to such third parties, they may also be permitted to edit the information you have provided to us and to designate others to access and edit such information. You may change your settings at any time as to who has access to your information by contacting us at email@example.com.
We will share your Personal Information with your employer solely for the purpose of providing the Services.
C. Third Party Service Providers
We may share your Personal Information with third party service providers, including reputable reference sources or reporting agencies, to: provide you with the Services that we offer you through our Site; to conduct quality assurance testing; to facilitate creation of accounts; to provide technical support; for risk management and to maximize the accuracy of your information; and/or to provide other services to Lively. These third party service providers are required not to use your Personal Information other than to provide the services requested by Lively.
E. Corporate Restructuring
F. Disclosure to Third Party Companies
We may enter into agreements with companies that provide our Services by way of a co-branded or private-labeled website or companies that offer their products and/or services on our website (“Third Party Companies”). A Third Party Company may want access to Personal Information that we collect from its customers. As a result, we may disclose your Personal Information to a Third Party Company partners involved in the provision of our Services; however, we will not disclose your Personal Information to any unaffiliated Third Party Company for the unaffiliated Third Party Company’s own direct marketing purposes. The privacy policies of these Third Party Companies may apply to the use and disclosure of your Personal Information that we collect and disclose to such Third Party Companies. Because we do not control the privacy practices of Third Party Companies, you should read and understand their privacy policies.
G. Other Disclosures
H. Third Party Websites
I. No Sales
Lively does not engage in the sale of personal information. We have not engaged in the sale of personal information in the past 12 months and do not anticipate doing so moving forward.
IV. Exercising Your Rights
Consistent with our belief that you are in control of how your personal information is used and shared, Lively supports a full array of data subject rights. To exercise any of these rights, you may contact Lively through any of the following means:
Postal mail: Lively, Inc.
588 Sutter Street, #214
San Francisco, CA 94102
A. Right of Access
You can access your account through the Site and view and update your personal information. Users may make changes to their Personal Information through their Accounts. For Personal Information that cannot be changed via your Account, you may contact us at firstname.lastname@example.org to request the change. We will use commercially reasonable efforts to honor your requests. If you have questions about what Personal Information Lively holds about you, you can contact us at email@example.com or through any of the other methods described above.
B. Right to Deletion
You may request deletion of your personal information. We may retain an archived copy of your records as required by law, to continue to provide you with the Services, or for other legitimate business purposes. If you completely delete all of your Personal Information, then your Account may become deactivated.
C. Right to Non-Discrimination
Lively will never discriminate against you for exercising any of the above-described rights.
D. Other Choices Regarding Information
In addition to the above rights, you have the following choices regarding the use of information on our Service:
- Cookies. If you decide at any time that you no longer wish to accept Cookies from our Service for any of the purposes described above, then you can instruct your browser, by changing its settings, to stop accepting Cookies or to prompt you before accepting a Cookie from the websites you visit. Consult your browser’s technical information. If you do not accept Cookies, however, you may not be able to use all portions of the Service or all functionality of the Service. If you have any questions about how to disable or modify Cookies, please let us know at the contact information provided above.
V. About the Services
A. No Users Under Age 13
The Services are not intended for children. We do not intentionally gather Personal Information from visitors who are under the age of 13. If a child under 13 submits Personal Information to Lively and we learn that the Personal Information is the information of a child under 13, we will attempt to delete the information as soon as possible. If you believe that we might have any Personal Information from a child under 13, please contact us at firstname.lastname@example.org.
B. Users Outside the United States
C. Security of Personal Information and Bank Information
We have developed policies and procedures to keep your Personal Information confidential and secure. We restrict access to those employees and other persons who must use that information to provide services on our behalf. We maintain physical, electronic, and procedural safeguards, in compliance with applicable laws, regulations, and industry standards, to protect the confidentiality of the Personal Information we obtain. We require our service providers to maintain the same level of confidentiality and security that we do. We continually update and improve our security standards and procedures to help protect against anyone gaining unauthorized access to your Personal Information and to prevent fraud.