Effective: July 1, 2026
Privacy Policy
Introduction
Halftime Health, LLC ("Halftime Health," "we," "our," or "us") is committed to protecting your privacy and handling your health information with the care it deserves. This Privacy Policy explains how we collect, use, disclose, and protect information about you in connection with our Services — including our member platform, mobile application, and all related products and services.
HIPAA Notice: Halftime Health operates as a HIPAA Business Associate of OLA Digital Health's contracted physician network (and its affiliated professional entities), which are the HIPAA Covered Entities for the clinical encounter. We handle protected health information (PHI) in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations, including the Privacy Rule, Security Rule, and Breach Notification Rule. For information about your rights with respect to PHI held by OLA Digital Health's physician entities, please also review OLA Digital Health's Notice of Privacy Practices.
By using our Services, you agree to the collection and use of information as described in this Privacy Policy. This Policy is incorporated into our Terms of Service.
1. Information We Collect
We collect information you provide directly, information generated through your use of our Services, and information from third parties.
1.1 Information You Provide
Account Information: Name, email address, phone number, date of birth, biological sex, state of residence, and password (or authentication credentials).
Health Intake Information: Medical history, current medications, allergies, prior peptide or hormone therapy history, reproductive status, substance use history, height, weight, sleep patterns, energy levels, exercise habits, stress levels, health goals, and other health-related information you provide through our intake form.
Biometric and Lab Information: Blood biomarker results from your Halftime Baseline lab panel and any subsequent panels, organized by category (hormonal, metabolic, inflammation, thyroid, longevity, nutritional, and other markers). This constitutes PHI and is handled in accordance with Section 4.
Personalized Protocol Plan Information: Your biomarker analysis results, Personalized Protocol Plan, physician review notes, prescription information (where applicable), and protocol history.
Payment Information: Credit/debit card numbers, billing address, and other payment details. Payment card data is processed by our third-party payment processor and is not stored by Halftime Health in an unencrypted form.
Communications: Emails, support requests, and other communications you send to us or our care team.
Feedback and Submissions: Surveys, reviews, feedback, or other submissions you provide.
1.2 Information Generated Through Your Use of Services
Usage Data: Pages viewed, features used, time spent, clickstream data, and how you interact with our platform.
Device and Technical Information: IP address, browser type and version, operating system, device identifiers, and similar technical information.
Location Information: Approximate geographic location derived from your IP address (for service eligibility verification and state-specific disclosures). We do not collect precise GPS location without your explicit consent.
Log Data: Server logs recording your interactions with our Services.
1.3 Information from Third Parties
Lab Results: Your blood biomarker test results, generated from a blood sample you self-collect using a Tasso at-home collection kit and return by prepaid mail for processing, and transmitted to us by our lab partner, Tasso. This is PHI.
Identity Verification: Information from identity verification service providers used to verify your identity in connection with your account, where applicable.
Physician Network: Clinical notes, consultation records, and prescription information from OLA Digital Health's contracted physician network, to the extent necessary to facilitate your Services. This is PHI.
Pharmacy Partner: Order status and fulfillment confirmation from our compounding pharmacy partner (Wellsync/BoomRx). We do not receive detailed prescription records from the pharmacy beyond what is necessary to confirm fulfillment.
Referral and Attribution Data: Information about how you learned of our Services, including referral codes and marketing attribution data.
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 Service Delivery
- Creating and managing your Account
- Processing your lab panel order and arranging delivery of your Tasso at-home collection kit
- Generating your biomarker analysis as a clinical decision support tool for physician review
- Showing you which protocols may be relevant to the goals you tell us, and recording the ones you ask to be considered for
- Sharing your health intake information and Lab Results with OLA Digital Health's contracted physician network so a licensed physician can review your case and issue any applicable prescriptions
- Routing approved prescriptions to our pharmacy partners for fulfillment
- Tracking and communicating order and shipment status
- Providing customer and clinical support
2.2 Clinical Decision Support
- Analyzing your biomarker results against reference ranges to produce your biomarker analysis
- Identifying biomarker patterns relevant to our approved peptide and hormone protocol formulary
- Flagging values requiring physician attention or outside the scope of our Services
- Supporting your Ordering Physician's independent clinical review
2.3 Account and Subscription Management
- Processing payments and managing your subscription
- Sending transactional communications (receipts, subscription updates, account alerts)
- Verifying your identity and eligibility
- Maintaining records required by applicable law (including HIPAA)
2.4 Communications
- Sending lab result notifications ("Your results are ready")
- Sending protocol status updates ("Your prescription has been approved")
- Sending appointment reminders and care team messages
- Responding to your support inquiries
- Sending educational content about health, longevity, and peptide therapy (with your consent where required)
- Sending marketing communications about new products, protocols, or promotions (with your consent where required; you may opt out at any time)
2.5 Platform Improvement and Analytics
- Analyzing how members use our Services to improve the platform
- Developing new features and protocols
- Conducting research and analytics on aggregated, de-identified data
- Testing and quality assurance
2.6 Legal and Compliance
- Complying with applicable laws, regulations, and legal process (including HIPAA, state health data laws, and FDA regulations)
- Responding to lawful government requests and law enforcement inquiries
- Enforcing our Terms of Service and other agreements
- Detecting, preventing, and investigating fraud, security incidents, and other prohibited activity
- Protecting the rights, safety, and interests of Halftime Health, our members, our physician partners, and the public
2.7 Aggregated and De-Identified Data
We may use your information to create aggregated, anonymized, or de-identified datasets that cannot reasonably be used to identify you. We may use and share such de-identified data for research, analytics, product development, and other purposes without restriction.
3. How We Share Your Information
We share your information only as described in this Policy or with your consent.
3.1 OLA Digital Health (Physician Network)
We share your health intake information, Lab Results, and related clinical data with OLA Digital Health's contracted physician network so that a licensed physician can review your case, determine what protocol (if any) is clinically appropriate for you, and issue any applicable prescriptions. OLA Digital Health's physician entities are HIPAA Covered Entities; we share PHI with them pursuant to our Business Associate Agreement. The Ordering Physician's records are maintained by OLA Digital Health, not by Halftime Health.
3.2 Laboratory Partners
We share necessary identification and requisition information with Tasso (our at-home blood collection and laboratory partner) to facilitate the delivery of your at-home collection kit, the processing of the blood sample you self-collect and return by prepaid mail, and the transmission of your Lab Results. Your Lab Results are transmitted from Tasso to Halftime Health pursuant to applicable agreements.
3.3 Pharmacy Partners
We share your prescription information (as provided by the Ordering Physician) with our licensed compounding pharmacy partner — Wellsync/BoomRx — for the purpose of fulfilling your physician-prescribed protocol. Prescription data shared with the pharmacy is the minimum necessary to fulfill the order.
3.4 Identity Verification
We share limited identification data with third-party identity verification providers, where applicable, for the purpose of verifying your identity.
3.5 Technology and Infrastructure Partners
We share data with technology service providers under Business Associate Agreements (where PHI is involved) for the purpose of operating our platform:
- AWS (Amazon Web Services): Cloud infrastructure, encrypted storage (S3, KMS), email delivery (SES). BAA in place.
- Neon: Managed Postgres database hosting. BAA in place.
- AWS Cognito: Authentication and identity management. BAA in place where PHI is involved.
- NetValve / Corepay: Payment processing. PHI-isolated.
- Sentry: Application monitoring and error tracking. BAA in place. PHI excluded from error logs.
3.6 Marketing Technology (Non-PHI Only)
We use the following marketing and analytics tools. No PHI or individually identifiable health information is transmitted to any of these services:
- Klaviyo: Marketing email and lifecycle messaging. Non-PHI only (membership status, engagement signals, non-health attributes).
- Google Analytics / Plausible: Website analytics. Non-PHI only.
- Meta Pixel / Google Ads: Advertising measurement. Non-PHI only. We do not share health information with advertising platforms.
We maintain technical controls and audit mechanisms to prevent PHI from being transmitted to non-BAA marketing platforms.
3.7 Legal Disclosures
We may disclose your information — including PHI, where legally required — to:
- Comply with applicable laws, regulations, subpoenas, court orders, or other legal process
- Respond to lawful requests from government authorities, regulators, or law enforcement
- Protect the safety, rights, or property of Halftime Health, our users, our physician and pharmacy partners, or the public
- Investigate or prevent fraud, security incidents, or illegal activity
- Comply with mandatory public health reporting obligations under applicable federal or state law
3.8 Business Transfers
In connection with a merger, acquisition, asset sale, or other business transaction, your information (including PHI, subject to applicable legal requirements) may be transferred to a successor entity, subject to the same privacy protections described in this Policy.
3.9 With Your Consent
We may share your information with other parties when you direct us to do so or otherwise provide your consent.
4. Protected Health Information (PHI) and HIPAA
4.1 HIPAA Applicability
Halftime Health handles PHI as a HIPAA Business Associate. The Covered Entity for your clinical encounter is OLA Digital Health's contracted physician network (the Ordering Physician's professional entity). As a Business Associate, we implement the administrative, technical, and physical safeguards required by HIPAA's Security Rule.
4.2 What Constitutes PHI
In connection with our Services, the following categories of information constitute PHI:
- Your Lab Results (blood biomarker values)
- Your health intake responses (medical history, medications, conditions)
- Your Personalized Protocol Plan and the clinical notes and analysis underlying it
- Your prescription information (protocol name, dosage, prescribing physician, pharmacy)
- Any communications between you and our clinical support team that include health information
- Any other individually identifiable health information created, received, or maintained in connection with your care
4.3 Minimum Necessary Standard
We apply the HIPAA Minimum Necessary standard to all PHI access and disclosures. Staff and systems access only the PHI needed to perform their specific function. We do not share your full clinical record with any party that does not need it to perform services on your behalf.
4.4 HIPAA Notice of Privacy Practices
This Privacy Policy serves, in part, as Halftime Health's Notice of Privacy Practices. For information about the rights you have with respect to PHI held by OLA Digital Health's physician entities as Covered Entities, please request OLA Digital Health's Notice of Privacy Practices.
Your rights with respect to PHI held by Halftime Health include:
- Access: You have the right to request access to PHI we maintain about you.
- Correction: You have the right to request correction of inaccurate PHI.
- Restriction: You have the right to request restrictions on how we use or disclose your PHI, though we are not always required to agree.
- Accounting of Disclosures: You have the right to request an accounting of certain disclosures of your PHI.
- Revocation of Authorization: Where we use PHI based on your Authorization, you have the right to revoke that Authorization at any time (see Authorization for Use of Medical Information).
To exercise these rights, contact us at privacy@halftime.health.
4.5 PHI Data Architecture
Halftime Health's PHI handling architecture:
- PHI is stored in our encrypted Postgres database (Neon, AES-256 encryption at rest) in our
clinicalschema - Sensitive fields (including biomarker values and physician notes) receive additional field-level encryption using AWS KMS
- PHI is never transmitted to non-BAA destinations (including marketing platforms, advertising networks, or analytics services not covered by a BAA)
- Every access to PHI is recorded in our audit log with the actor, action, resource, purpose code, timestamp, and IP hash
- PHI access requires authentication, and clinical routes require re-verification within 30-minute windows
4.6 PHI Retention
We retain PHI for the minimum period required by applicable law. HIPAA generally requires a minimum of 6 years for certain records. Consent records are retained for 7 years. You may request deletion of non-PHI personal information (see Section 7.2), but we may be required to retain PHI beyond the period of your account activity.
5. Data Retention
| Category | Retention Period |
|---|---|
| Account information (non-PHI) | Duration of account + 3 years |
| Health intake responses (PHI) | 6 years (HIPAA minimum) |
| Lab Results (PHI) | 6 years (HIPAA minimum) |
| Personalized Protocol Plans (PHI) | 6 years (HIPAA minimum) |
| Prescription records (PHI) | 6 years (HIPAA minimum) |
| Consent records | 7 years |
| Audit logs | 6 years (HIPAA Security Rule) |
| Payment information | As required by payment processor and applicable law |
| Marketing contact information (non-PHI) | Until opt-out + 3 years |
6. Security
We implement administrative, technical, and physical safeguards designed to protect your information from unauthorized access, use, or disclosure. Our security measures include:
- Encryption at rest: All data in our Postgres database uses AES-256 encryption. PHI fields receive additional field-level encryption via AWS KMS.
- Encryption in transit: All data transmitted between your browser/app and our servers uses TLS 1.2 or higher.
- Access controls: Role-based access controls; staff access PHI only as needed for their function. PHI access requires multi-factor authentication.
- Audit logging: All PHI access is logged with actor, action, resource, purpose, timestamp, and IP hash. Logs are append-only and retained for 6 years.
- Vendor management: All vendors accessing PHI are required to execute a Business Associate Agreement and demonstrate appropriate security controls.
- Incident response: We maintain a written incident response plan and breach notification procedures consistent with HIPAA's Breach Notification Rule.
- Annual risk assessment: We conduct annual security risk assessments in accordance with HIPAA Security Rule requirements.
No security system is perfect. Despite our efforts, we cannot guarantee that unauthorized parties will never be able to overcome our safeguards. If we become aware of a security breach affecting your PHI, we will notify you as required by HIPAA's Breach Notification Rule and applicable state law.
7. Your Rights and Choices
7.1 Access and Update Your Information
You may access and update most of your account information by logging into your account at halftime.health. For corrections to PHI, contact privacy@halftime.health.
7.2 Deletion Requests
You may request deletion of your non-PHI personal information by contacting privacy@halftime.health. We will honor deletion requests to the extent permitted by applicable law. Note that we may be required to retain PHI beyond your requested deletion date under HIPAA and other applicable law, and we may retain de-identified data.
7.3 Marketing Opt-Out
You may opt out of marketing email communications by clicking "Unsubscribe" in any marketing email. You may not opt out of transactional and clinical communications (such as lab result notifications and prescription status updates) without closing your account.
7.4 Data Portability
You may request a copy of your personal information in a machine-readable format by contacting privacy@halftime.health. For Lab Results specifically, you may also request a copy directly from our lab partner, Tasso, under applicable law.
7.5 Do Not Sell / Do Not Share
Halftime Health does not sell your personal information or PHI to third parties. We do not share your PHI with advertising networks. If you are a California resident, see Section 9 for additional rights.
7.6 State Privacy Rights
See Section 9 for state-specific privacy rights.
8. Children's Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you believe we have collected information from a child, contact us immediately at privacy@halftime.health and we will promptly delete it.
9. State-Specific Privacy Rights
9.1 Texas
Texas residents may have rights under the Texas Data Privacy and Security Act (TDPSA), including rights to access, correct, delete, and obtain a copy of your personal data, and to opt out of certain processing. To exercise these rights, contact privacy@halftime.health. We will respond within the timeframes required by applicable law.
9.2 Washington
Washington State residents have rights under the Washington My Health MY Data Act (MHMDA), RCW Chapter 19.373, with respect to consumer health data that Halftime Health collects outside of its HIPAA Business Associate functions. Note: protected health information (PHI) that Halftime Health handles as a HIPAA Business Associate of OLA Digital Health is governed by HIPAA and is exempt from MHMDA under RCW 19.373.010(6)(a).
For Washington residents, Halftime Health publishes a separate Washington Consumer Health Data Privacy Policy that describes in full: the categories of consumer health data collected, purposes of use, third parties who receive such data, and how to exercise your rights under the MHMDA. This policy is available at halftime.health/washington-health-data-privacy.
Your MHMDA rights include: the right to confirm and access consumer health data we hold about you, the right to withdraw consent, the right to request deletion of non-HIPAA consumer health data, and the right to non-discrimination for exercising these rights. To exercise these rights, contact privacy@halftime.health.
9.3 Nevada
Nevada residents may have rights under Nevada SB 370 (Nevada Consumer Health Data Privacy Law, NRS Chapter 603C) with respect to consumer health data. Nevada's law imposes affirmative consent requirements before collection and sharing of consumer health data and provides rights similar to Washington's MHMDA. To exercise your Nevada health data privacy rights, contact privacy@halftime.health. We will respond within 45 days of a verified request.
9.4 Other State Laws
Residents of other states with applicable consumer privacy laws (including but not limited to Virginia, Colorado, Connecticut, Utah, Montana, and other states) may have additional rights under applicable law. Virginia and Colorado residents have the right to opt-in consent before processing of sensitive personal data, including health information. To exercise state privacy rights, contact privacy@halftime.health. We will respond within the timeframes required by applicable law in your state.
9.5 CCPA / California
At this time, our Services are not available to California residents. If we expand to California in the future, we will update this section with CCPA/CPRA disclosures.
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website and platform for the following purposes:
- Strictly Necessary Cookies: Required for the platform to function (authentication, session management, security). Cannot be disabled.
- Analytics Cookies: Help us understand how you use our Services (e.g., Plausible Analytics). We prefer privacy-preserving analytics tools.
- Marketing Cookies: Used on our marketing website to measure campaign performance. We do not use marketing cookies within the authenticated member platform.
You may manage cookie preferences through your browser settings or through our cookie preference center. Note that disabling certain cookies may affect platform functionality.
We do not share cookie-derived data with advertising networks in connection with your health information.
Global Privacy Control (GPC): For Texas residents, we honor Global Privacy Control (GPC) browser signals as an opt-out of the sale of personal data and targeted advertising, as required by the Texas Data Privacy and Security Act (TDPSA) effective January 1, 2025.
11. Third-Party Links
Our platform may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party services you visit.
12. Updates to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-platform notification. The "Last Updated" date at the top of this Policy indicates when it was most recently revised. Continued use of our Services after a change becomes effective constitutes acceptance of the updated Policy.
13. Contact Us
For questions, concerns, or requests regarding this Privacy Policy or your privacy rights, contact us:
Privacy Officer
Halftime Health, LLC
600 W 6th St, Suite 400
Fort Worth, TX 76102
Email: privacy@halftime.health
General: legal@halftime.health
Website: halftime.health
For HIPAA-specific complaints, you may also contact:
U.S. Department of Health & Human Services, Office for Civil Rights
Website: hhs.gov/hipaa
Phone: 1-800-368-1019
You will not be retaliated against for filing a complaint with the Office for Civil Rights.
This Privacy Policy is governed by applicable federal law and the laws of the State of Texas.