i2i Privacy Policy
Last Updated: August 19, 2026
-
Our Role Under HIPAA
-
The Personal Data We Collect and How We Use It
-
Why We Collect Your Personal Data
-
Other Permitted Disclosures
-
De-Identified and Aggregated Data
-
How We Share Your Personal Data
-
Cookies, Tracking Tools, and Analytics
-
Data Security
-
Data Retention
-
Children’s Privacy
-
Your California Privacy Rights
-
Other U.S. State Privacy Rights
-
How to Exercise Your Privacy Rights
-
Changes to This Privacy Policy
-
Contact Us
Our Role Under HIPAA
a. Understanding PHI. Certain health and personal information that i2i collects on behalf of the Service Providers on our platform is considered “Protected Health Information” or “PHI” and is governed by the Health Insurance Portability and Accountability Act (“HIPAA”). This typically occurs when i2i is acting as a “Business Associate” for a “Covered Entity” (your healthcare provider) under HIPAA.
b. What This Policy Does Not Cover. This Privacy Policy does not apply to PHI. The use and disclosure of your PHI is governed by HIPAA and by your Service Provider’s own Notice of Privacy Practices. We encourage you to review their notice to understand how your PHI is protected.
c. What This Policy Covers. This Privacy Policy applies strictly to non-PHI Personal Data collected by i2i in its capacity as a direct-to-consumer technology platform prior to the initiation or submission of an appointment request. This includes data collected when you browse directory listings, create an i2i Account, utilize provider matching tools, or input pre-booking care preferences. Immediately upon your submission, initiation, or transmission of an appointment request, booking form, or practice intake document through the Services, all such transmitted and stored data automatically converts to Protected Health Information (PHI) maintained on behalf of your designated Service Provider. At that moment, the handling of such data is governed exclusively by Section 2.a of this policy, your Service Provider’s Notice of Privacy Practices, and i2i’s Business Associate Agreement (BAA).
The Personal Data We Collect and How We Use It
The following sections detail the categories of Personal Data that we may have collected about you over the past twelve (12) months. For each category, we explain the sources from which we collect the data, our business purposes for collecting it, and the categories of third parties with whom we may share it.
“Personal Data” means any information that identifies, relates to, or could reasonably be linked with you or your household. This policy applies to all users of our platform, including patients and providers.
a. Information We Collect from All Users When you interact with the i2i Platform, we may collect the following categories of Personal Data from you or from third parties:
- Online Identifiers. This includes information like your IP address, device ID, and the type of device and browser you are using. We use this information strictly to provide, customize, secure, and improve our Services. We may share this data with our internal service providers and analytics partners.
- Web Analytics. This includes information about how you interact with our website, such as which pages you visit and the referring webpage from which you accessed our Services. We use this information to provide, customize, and improve our Services. We may share this data with our internal service providers and analytics partners.
- Geolocation Data. This includes your approximate location based on your IP address, or a more specific location like a zip code if you provide it. We use this information to provide, customize, and improve our Services. We may share this data with our internal service providers and analytics partners.
- User Demographic Data. This includes information you voluntarily provide to us, such as your gender and date of birth. We use this information to provide and customize our Services and to communicate with you. We may share this data with our internal service providers and the Service Providers you choose to interact with.
- Other Information You Provide. This includes any other identifying information you choose to share in your direct communications with us, such as in emails to our support team. We use this information to provide our Services and to correspond with you. We may share this data with our internal service providers and any other parties you authorize.
b. Pre-Booking Personal Data Collected from Registered Users If you create an Account, we collect the following additional categories of Personal Data from you or from third parties you authorize prior to provider booking. Some of this information is classified as “Sensitive Personal Information” (SPI) under applicable state privacy laws. To the extent this data is collected prior to initiating or submitting an appointment request, it constitutes non-PHI consumer Personal Data used solely to operate our directory, account features, and matching engine:
- Personal Identifiers. Name, email address, and phone number used to manage your account and communicate with you. Prior to booking submission, we may share this data with our internal service providers, the Service Providers you choose, your insurance provider, and other parties you authorize.
- Commercial Information. Payment card details and billing address processed to facilitate transaction services. We share this information strictly with our payment processing partner (Stripe) and internal service providers.
- Pre-Booking & Scheduling Intent Data. Preferred appointment dates, times, search criteria, and selected provider preferences entered prior to final booking transmission. We use this strictly to provide core search and scheduling setup services. Prior to booking, we may share this data with internal service providers and chosen Service Providers. Under no circumstances is this data shared with Health Information Exchanges (HIEs), third-party advertising networks, or for cross-context behavioral marketing.
- Health and Insurance Information. Preliminary health preferences, medical history, reasons for seeking care, and insurance plan details provided to refine provider matches or pre-populate onboarding forms. Prior to booking submission, we may share this data strictly with internal service providers, your chosen Service Providers, and your insurance provider.
- Sensitive Demographic Data. Voluntary identity preferences, such as race, ethnicity, or sexual orientation, used solely to refine provider matches. We may share this data with internal service providers and your chosen Service Providers.
- Other Information You Provide. Social media credentials, customer support communications, or other identifying information you voluntarily submit. We use this to operate our Services and correspond with you, sharing with internal service providers and authorized parties.
Data Lifecycle Transition Boundary: Immediately upon your affirmative submission or transmission of an appointment request, booking form, or practice intake instrument, all associated Booking Data, Health and Insurance Information, and Identifiers transition to Protected Health Information (PHI) governed exclusively by HIPAA, the Business Associate Agreement (BAA), and your Service Provider’s Notice of Privacy Practices, rendering third-party consumer analytics sharing inoperable for that data.
Why We Collect Your Personal Data
We collect your Personal Data for the following primary business purposes:
- Providing, Customizing, and Improving Our Services. This includes, but is not limited to: creating and managing your account; providing you with the products and services you request; billing our provider clients; offering customer support; improving our platform through testing, research, and product development; personalizing your experience; and ensuring the security of our platform through fraud protection and debugging.
- Marketing the Services. This may include marketing our Services to you or showing you advertisements.
- Corresponding with You. This includes responding to your correspondence, contacting you when necessary, and sending you information about the Services, such as appointment reminders.
Other Permitted Disclosures
We may also disclose your Personal Data to government or law enforcement officials or other parties to: fulfill our legal obligations under applicable law or court order; prevent or investigate security incidents or potentially illegal activities; protect the rights and safety of you, i2i, or another party; enforce our agreements; respond to claims that any content violates third-party rights; and resolve disputes.
De-Identified and Aggregated Data
We may create aggregated or de-identified data from the Personal Data we collect by removing any information that makes the data personally identifiable. We may use and share this de-identified data for any lawful business purpose, including to analyze, build, and improve our Services. We may also use technologies such as screen recording tools to analyze how users navigate our website or AI tools to enhance certain features.
AI and Machine Learning. Where permitted by applicable law and our agreements with your healthcare providers, we may de-identify the personal and health-related information you submit during the clinical onboarding or booking process. Once this data is fully de-identified in accordance with HIPAA standards so that it can no longer be reasonably linked to you, it is no longer considered Personal Data or Protected Health Information. We retain sole ownership of this de-identified data and may use it for any lawful business purpose, including the training, development, and enhancement of our artificial intelligence and machine learning models, such as our provider matching algorithms.
How We Share Your Personal Data
In certain circumstances, we may share your Personal Data with the following categories of service providers and other third parties for our business purposes:
a. Service Providers. We may share your Personal Data with our third-party service providers who help us operate and improve the i2i Platform. These providers are contractually obligated to protect your data and are prohibited from using it for any other purpose. These service providers include, but are not limited to:
- Payment Processors, such as Stripe, who collect and process your payment card information.
- Security and Fraud Prevention Consultants, who help us detect security incidents, protect against malicious or fraudulent activity, and prosecute those responsible.
- Hosting, Technology, and Communications Providers, as well as fulfillment providers, data storage providers, analytics providers, insurance verification providers, staff augmentation personnel, virtual care providers, and other operational vendors. We may share your Personal Data with these providers for a variety of business purposes, including performing core operational services, maintaining and servicing your account, providing customer service, debugging, short-term transient use, processing transactions, internal research, and maintaining the quality and safety of our Services.
b. Disclosures to Other Third Parties. We may also share your Personal Data with the following categories of third parties:
- The Service Providers You Select. When you book an appointment, we will share your Personal Data with your chosen Service Provider to facilitate your care. We may also share your information with another provider if you authorize your initial provider to make a referral on your behalf, or to perform analyses on potential health issues or treatments. In the event of an emergency, we may share your information with a Service Provider.
- Your Insurance Provider. To determine your eligibility and cost-sharing obligations, we will share your Personal Data with your designated insurance company.
- Analytics and Advertising Partners. We may share your Personal Data with our analytics and advertising partners to help us understand how users interact with our Services and to measure the effectiveness, quality, and compliance of our marketing campaigns. Notwithstanding the foregoing, under no circumstances will i2i share, sell, or disclose your Health and Insurance Information, Booking Appointment Data, or any data indicating your specific clinical search intent with third-party Advertising Partners or social media platforms for cross-context behavioral advertising purposes.
- Health Information Exchanges (HIEs). To improve the safety and efficiency of your care, we may share your information with HIEs and similar organizations that help your Service Providers access your health information more securely.
- Third-Party Login Services. If you choose to create an account or log in using a third-party service like Google or Apple, we will share certain Personal Data with that service as directed by you.
- Publicly Posted Information. Any information you choose to post in a public forum on our platform, such as in a review, is not private. You understand that any information you post publicly may be seen, collected, and used by third parties in ways we cannot control or predict.
c. Legal Obligations and Business Transfers. We may also share your Personal Data in the following circumstances:
- For Legal Reasons. We may disclose your Personal Data to third parties if we believe in good faith that such disclosure is necessary to comply with a legal obligation, such as a court order or subpoena.
- In the Event of a Business Transfer. Your Personal Data is a business asset. If i2i is involved in a merger, acquisition, or sale of assets, your Personal Data may be sold or transferred as part of that transaction. We will make reasonable efforts to notify you before your information becomes subject to a different privacy policy.
Cookies, Tracking Tools, and Analytics
This section provides additional information about how we collect your Personal Data using automated technologies.
a. Our Use of Cookies. Like most online services, we use cookies and similar technologies, such as pixel tags, web beacons, and JavaScript (collectively, “Cookies”), to help our servers recognize your web browser, secure your session, and analyze how you use our Services. Cookies are small text files placed on your device when you visit our websites. We use the following types of Cookies:
- Essential Cookies. These Cookies are required to provide you with core platform functionality, security, and authentication. For example, we use Essential Cookies to allow you to log in to your secure account. If you disable these Cookies, certain parts of our platform may become unavailable to you.
- Functional Cookies. These Cookies remember your preferences and settings (such as language or display options) to enhance your user experience.
- Performance and Analytical Cookies. These Cookies help us understand how visitors interact with our website by collecting information about page views, navigation paths, and platform usage. We use first-party analytics tools (including Google Analytics) strictly for our own internal business purposes to monitor system performance, fix bugs, and improve our Services.
b. Analytics and No Targeted Advertising. We configure our analytics tools (including Google Analytics) strictly in a “Service Provider” capacity. We have disabled cross-device advertising features, data-sharing for advertising purposes, and Google Signals. Under no circumstances do we deploy Advertising or Retargeting Cookies, Meta Pixels, or similar third-party tracking technologies to share your online activity, search intent, or personal data with advertising networks for cross-context behavioral advertising.
c. Managing Your Cookie Preferences. You can manage or block non-essential Cookies through your internet browser’s settings or your mobile device options. Please note that if you block essential Cookies, certain core features of our Services may become unavailable. We also honor legally recognized opt-out preference signals, such as the Global Privacy Control (GPC), broadcast by supported web browsers.
Data Security
We are committed to protecting the security of your Personal Data. We use appropriate physical, technical, organizational, and administrative security measures to protect the data submitted to us, both during transmission and in storage. For example, we use SSL technology to encrypt Personal Data. We may store and process your information on servers in the United States and abroad.
You also play a crucial role in protecting your data. We encourage you to use a strong and unique password, limit access to your computer and browser, and sign off after you have finished using the Services.
Although we make good faith efforts to store your Personal Data in a secure operating environment, no method of transmission or storage is completely secure. We cannot and do not guarantee the absolute security of any information you share with us. Except as expressly required by law, we are not responsible for the theft, destruction, or inadvertent disclosure of your Personal Data.
Data Retention
We retain your Personal Data for as long as is necessary to provide our Services and to fulfill our legitimate business and commercial purposes. When determining how long to keep your data, we consider its sensitivity, why we collected it, and our legal obligations.
In some cases, we may retain Personal Data for a longer period, such as to comply with the law, resolve disputes, or collect fees owed. We may retain de-identified or aggregated data indefinitely. For example:
- We retain your account information for as long as you have an active account with us.
- We retain technical data, such as your IP address, for as long as is necessary to ensure the security and efficiency of our systems.
- We retain any PHI in accordance with our legal obligations under HIPAA and our agreements with our Service Providers.
Children’s Privacy
Our Services are not intended for use by individuals under the age of eighteen (18). Individuals under the age of eighteen (18) are not permitted to create an Account or directly use the Services. We do not knowingly collect Personal Data directly from children under 18.
If you are a parent or legal guardian, you may create an account and use the Services on behalf of a minor child. By doing so, you represent and warrant that you are the parent or legal guardian of such child and that you consent to our collection and use of their information as described in this Privacy Policy.
If we learn that we have inadvertently collected Personal Data directly from a child under the age of 13 without verified parental consent, we will only use that information to respond directly to that child (or their parent or legal guardian) to inform them that they cannot use the Services, and we will subsequently delete that information. If you believe we have collected information from a child under 18, please contact us at legal@i2iconnect.com.
If you use the Services on behalf of another person, regardless of age, you agree that i2i may send you communications in connection with the Services, and you agree to forward all such communications to the person on whose behalf you are acting.
Your California Privacy Rights
The California Consumer Privacy Act (“CCPA”) provides California residents with specific rights regarding their Personal Data. This section describes your rights under the CCPA and explains how to exercise them. Please note that these rights are subject to certain conditions and exceptions, which may permit or require us to deny your request.
Because of the minimal Personal Data we collect and retain about users who do not create an account, certain rights may not be available to you.
If you are the patient of a provider who uses our i2iConnect platform, we may be processing your data as a “service provider” on behalf of that provider. In such cases, you should direct any requests to exercise your privacy rights to your provider in the first instance.
a. Your Rights Under the CCPA.
- The Right to Know (Access). You have the right to request a report detailing the Personal Data we have collected about you, including: the categories of Personal Data; the categories of sources from which it was collected; our business purpose for collecting it; the categories of third parties with whom we have shared it; and the specific pieces of Personal Data we have collected about you. If we have disclosed your Personal Data for a business purpose, we will identify the categories of Personal Data shared with each category of third-party recipient. If we have “sold” your Personal Data, as that term is defined under the CCPA, we will identify the categories of Personal Data purchased by each category of third-party recipient.
- The Right to Delete. You have the right to request that we delete the Personal Data we have collected from you. This right is subject to certain exceptions; for example, we may need to retain your data to provide you with the Services you have requested.
- The Right to Correct. You have the right to request that we correct any inaccurate Personal Data we have collected about you. This right is also subject to certain exceptions; for example, we may deny a request if we determine, based on the totality of the circumstances, that the data is more likely than not accurate.
b. The Right to Limit Use of Sensitive Personal Information. Some of the Personal Data we collect, such as your health information, may be considered “sensitive” under the California Consumer Privacy Act (CCPA). You have the right to request that we limit our use and disclosure of this Sensitive Personal Information. This “Right to Limit” allows you to direct us to only use your Sensitive Personal Information for purposes that are necessary to perform the services you have requested.
c. No Data “Selling” or “Sharing” for Advertising. We do not sell your Personal Data for monetary consideration, nor do we “share” your Personal Data with third parties for cross-context behavioral advertising or targeted marketing purposes under the California Consumer Privacy Act (CCPA) or other U.S. state privacy laws. We configure all our website analytics tools to act strictly as Service Providers. Because we do not sell or share Personal Data for targeted advertising, we do not require a “Do Not Sell or Share My Personal Information” opt-out link. Over the past 12 months, we have not sold or shared any Personal Data of consumers, including minors under the age of 16.
d. Our Commitment to Non-Discrimination. We will not discriminate against you for exercising any of your rights under the CCPA. We will not deny you our Services, charge you different prices, or provide you with a lower quality of service if you choose to exercise your privacy rights.
e. Financial Incentives. From time to time, we may offer a financial incentive for your participation in our user research. The personal data you submit in connection with this research will only be used to improve our product and will never be sold to third parties. The financial incentive we offer is based on our good faith determination of the estimated value of your data.
Through your participation in our research, we may collect various categories of Personal Data, including, but not limited to: identifiers, characteristics of protected classifications, commercial information, internet activity, geolocation data, professional or employment-related information, and any other information you provide in free-form fields.
Participation in any financial incentive program is entirely optional. If you choose to participate, you agree that we are not required to comply with your right to know or delete the specific Personal Data collected in exchange for the financial incentive. You may withdraw from any financial incentive program at any time by following the instructions provided in the offer.
f. California’s “Shine the Light” Law. Under California Civil Code Sections 1798.83-1798.84, California residents are entitled to request information regarding our disclosure of Personal Data to third parties for their direct marketing purposes. To submit such a request, please contact us at legal@i2iconnect.com.
Other U.S. State Privacy Rights
If you are a resident of a U.S. state with a comprehensive consumer privacy law (such as Virginia, Colorado, Connecticut, Utah, or others), you may have specific rights regarding your Personal Data. These rights generally align with those provided to California residents and are subject to similar conditions and exceptions under applicable law.
If you are the patient of a provider who uses our i2iConnect platform, we may be processing your data as a “processor” (or similar term) on behalf of that provider. In such cases, you should direct any requests to exercise your privacy rights to your provider in the first instance.
Because of the minimal Personal Data we collect and retain about users who do not create an account, certain rights may not be available to you.
If you have any questions about your state-specific privacy rights, please contact us at legal@i2iconnect.com and indicate “State Rights” in the subject line.
a. Your Rights in Other U.S. States.
In addition to the rights provided to California residents, other state privacy laws may provide their residents with the following rights:
- Right of Access. The right to confirm whether we are processing your Personal Data and to access that data.
- Right to Correction. The right to correct inaccuracies in your Personal Data.
- Right to Portability. The right to obtain a copy of your Personal Data in a portable and, to the extent technically feasible, readily usable format.
- Right of Deletion. The right to delete your Personal Data.
b. Your Right to Opt-Out of Certain Data Uses. Certain state privacy laws provide residents with the right to opt out of the sale of their Personal Data, targeted advertising, or profiling that produces significant legal effects. Because we do not sell your Personal Data, do not share it for targeted cross-context behavioral advertising, and do not engage in automated profiling that produces significant legal effects, these opt-out mechanisms are not applicable to our current data practices.
c. Appealing Our Decisions. If we deny your request to exercise a privacy right, you may have the right to appeal our decision. To do so, please email us at legal@i2iconnect.com with the subject line “Privacy Request Appeal.” Your appeal must include sufficient information for us to identify your original request and a description of the basis for your appeal.
We will respond to your appeal within 45 days of receipt. If your appeal is denied, you may have the right to contact your state’s Attorney General or other applicable regulator.
How to Exercise Your Privacy Rights
a. Submitting a Request.To exercise any of the privacy rights described in this policy, you must submit a verifiable request to us that:
- Provides sufficient information to allow us to reasonably verify you are the person about whom we collected Personal Data.
- Describes your request with enough detail to allow us to properly understand, evaluate, and respond to it.
We will only use Personal Data provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request. We will respond to your request within the timeframe required by applicable law. Generally, we will not charge a fee for processing a verifiable request unless it is excessive, repetitive, or manifestly unfounded. If a fee is necessary, we will notify you and explain our decision before proceeding.
b. Where to Exercise Your Rights. You can submit a verifiable consumer request to access, correct, or delete your Personal Data through the following methods:
- For Account Holders & Webapp Users: If you have an i2i account, you can submit requests to access, delete, or correct your Personal Data directly through your account settings.
- For All Users (including Visitors): You may submit a request by emailing legal@i2iconnect.com with the subject line “Data Privacy Request.”
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make a material change to the policy, we will provide you with notice by posting an announcement on our website or by sending you an email. Please note that the use of any information we collect is governed by the Privacy Policy that was in effect at the time the information was collected.
Contact Us
If you have any questions or comments about this Privacy Policy, our data practices, or your privacy rights, please do not hesitate to contact us at legal@i2iconnect.com