Privacy Policy

Last Updated: May 2026

This Privacy Policy governs MedRevolve's collection and use of data on medrevolve.com. For our HIPAA-specific healthcare data practices, see our Notice of Privacy Practices (HIPAA NPP).

1. Who We Are

MedRevolve LLC ("MedRevolve," "we," "us") operates medrevolve.com — a B2B telehealth platform and consumer telehealth marketplace. Registered address: Charlotte, North Carolina, United States. Contact: privacy@medrevolve.com | (704) 426-3311.

2. Information We Collect

Information You Provide:

  • Account registration: name, email, password
  • Health intake forms: medical history, symptoms, health goals
  • Appointment booking: contact details, reason for visit
  • Contact forms: name, email, phone, message
  • Business/merchant onboarding: business name, EIN, domain, payment details

Automatically Collected:

  • IP address, browser type, operating system, device identifiers
  • Pages visited, time on site, referring URL, click paths
  • Cookies and tracking pixels (see our Cookie Policy)
  • Google Analytics (GA4) and Meta Pixel data (with consent)

3. How We Use Your Information

  • Providing, operating, and improving our telehealth platform and services
  • Matching patients with licensed healthcare providers
  • Processing payments securely via Stripe (PCI-DSS Level 1 certified)
  • Sending appointment confirmations, reminders, and healthcare communications
  • SMS communications (appointment reminders) with your explicit prior written consent per TCPA
  • Syncing lead and business data to HubSpot CRM for sales and support workflows (de-identified; no PHI)
  • Analytics and platform optimization using anonymized/aggregated data
  • Compliance with HIPAA, DEA, state telehealth laws, and other regulatory requirements
  • Marketing and advertising with your consent (you may opt out at any time)

4. Third-Party Service Providers

We share data with trusted service providers to operate our platform. All providers who handle PHI have signed HIPAA Business Associate Agreements (BAAs). Current third-party processors include:

ProviderPurposeBAA
Stripe, Inc.Payment processing (PCI-DSS L1)Yes
Google LLCCalendar, Meet, Workspace, AnalyticsYes (Workspace/Meet)
Twilio Inc.SMS notificationsYes
HubSpot, Inc.CRM — sales & business data only (no PHI)N/A
Meta PlatformsAdvertising analytics (with consent)N/A
Cookiebot (Usercentrics)Cookie consent managementN/A
QualiphyeConsent & identity verificationYes
Partner PharmaciesPrescription fulfillmentYes (Covered Entity)

5. SMS / Text Message Consent (TCPA)

We send SMS messages only with your prior express written consent, obtained at the time of account creation or appointment booking. Message types: appointment reminders, confirmation codes, care updates. Frequency varies. Message & data rates may apply. To opt out, reply STOP to any SMS. For help, reply HELP or contact support@medrevolve.com. We do not share your phone number with third parties for their marketing purposes.

6. Data Retention

  • Medical records / PHI: 7 years from date of service (or age 21 for minors, whichever is longer)
  • Payment records: 7 years
  • Marketing / analytics data: 26 months (per Google Analytics default)
  • Account data (non-medical): 3 years after last activity
  • After retention period: secure deletion using NIST 800-88 methods

7. Your Rights

All Users:

  • Access, correct, or delete your account information at any time via Account Settings
  • Opt out of marketing emails via unsubscribe link in any email
  • Opt out of SMS via reply STOP

California Residents (CCPA/CPRA):

  • Right to know what personal information is collected and how it's used
  • Right to delete personal information (with certain exceptions)
  • Right to opt out of sale/sharing of personal information (we do not sell PI)
  • Right to non-discrimination for exercising privacy rights

HIPAA Rights:

See our Notice of Privacy Practices for full HIPAA rights.

8. Children's Privacy

Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected data from a minor, contact us immediately at privacy@medrevolve.com.

9. Security

We implement industry-standard security including AES-256 encryption at rest, TLS 1.2+ in transit, role-based access controls, MFA, and regular security assessments. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.

10. Changes to This Policy

We may update this policy periodically. Material changes will be communicated via email to registered users and/or a prominent notice on the website. The "Last Updated" date at the top reflects the most recent revision.

11. Contact Us

Privacy Officer: privacy@medrevolve.com
Phone: (704) 426-3311
Address: Charlotte, North Carolina, United States