Privacy Policy
Last updated: June 2026
Draft for legal review
This document is templated, best-effort copy provided for launch and has not yet undergone formal legal review. Sections still requiring attorney sign-off are marked [LEGAL REVIEW NEEDED] below.
This Privacy Policy explains how Whitestone Health (“Whitestone Health,” “we,” “us,” or “our”) collects, uses, and protects information when you visit mywhitestone.com(the “Site”). Whitestone Health is a healthcare alliance of independent provider practices serving Central New Jersey. This policy applies to the Site only.
[LEGAL REVIEW NEEDED] Confirm the correct legal entity name, structure, and registered address for Whitestone Health, and whether this single policy may speak for the alliance and its independent member practices or whether each practice needs its own policy.
Information we collect
We collect the following categories of information:
- Information you provide. When you submit a contact or inquiry form, you may give us your name, email address, phone number, the discipline you are interested in, and the contents of your message.
- Automatically collected information. Like most websites, we may collect limited technical data such as your browser type, device type, and pages viewed, through cookies and similar technologies. See our Cookie Policy.
[LEGAL REVIEW NEEDED] Confirm the actual analytics and tracking tools deployed at launch and the exact data each collects. Per HHS guidance, no advertising or third-party tracking pixels may run on pages addressing health conditions or care. The analytics implementation (E1) must be reconciled with this disclosure before launch.
Protected Health Information (PHI) and the contact form
The Site is a marketing and information resource. Please do not include sensitive medical details in a contact form unless necessary. Where a message may contain health information, we route it through a secure intake channel covered by a Business Associate Agreement (BAA). We do not transmit such information through plain email or share it with analytics services. Treatment-related health information is governed by our Notice of Privacy Practices.
How we use your information
- To respond to your inquiries and route them to the appropriate practice.
- To operate, maintain, and improve the Site.
- To comply with legal obligations.
How we share information
We share the information you submit with the independent member practice or provider relevant to your inquiry so they can respond. We may use service providers (for example, secure form-intake and hosting vendors) who process information on our behalf under appropriate agreements. We do not sell your personal information.
[LEGAL REVIEW NEEDED] Confirm the list of third-party processors (hosting, secure intake, analytics, email) and that a BAA or equivalent data-processing agreement is in place with each one that may touch personal or health information.
Your choices and rights
You may contact us to ask about the information we hold about you. You can control cookies through your browser settings as described in our Cookie Policy.
[LEGAL REVIEW NEEDED] Determine which privacy laws apply (for example, applicable New Jersey state law and any federal requirements) and add the specific consumer rights, request procedures, and response timelines those laws mandate. Confirm whether a dedicated rights-request mechanism is required.
Data retention and security
We retain information for as long as needed to fulfill the purposes described here or as required by law, and we use reasonable administrative, technical, and physical safeguards to protect it. No method of transmission over the Internet is completely secure.
[LEGAL REVIEW NEEDED] Confirm concrete retention periods and the security-safeguards language against the alliance’s actual practices and any applicable breach-notification obligations.
Children’s privacy
The Site is not directed to children under 13, and we do not knowingly collect personal information from them through the Site.
[LEGAL REVIEW NEEDED] The alliance includes ABA services for children. Confirm whether intake involving minors triggers additional consent or disclosure requirements that should be reflected here or in the Notice of Privacy Practices.
Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date above reflects the most recent revision.
Contact us
Questions about this policy? Please contact us.
[LEGAL REVIEW NEEDED] Add the official privacy-contact point (mailing address, dedicated privacy email, and the designated Privacy Officer if required).