This Privacy Policy (“Privacy Policy”) describes how and why Triangulate Labs, Inc. (“Triangulate,” “we,” “us” or “our”) collect, use, share, and store, (“process”) your information when you use our services (“Services”), such as when you:

  • Visit our website at https://www.skinmap.com or https://triangulatelabs.com, or any other website that links to this privacy policy
  • Download and use our mobile application (Skinmap™) or any other application of ours that links to this privacy policy
  • Engage with us in other related ways, including any sales, marketing, or events

Please carefully review this Privacy Policy and our Terms of Service available at https://www.skinmap.com/terms (the “Terms of Service”). Unless otherwise defined in this Privacy Policy, terms used in this Privacy Policy have the same meanings as terms defined in our Terms of Service.

BY USING THE SERVICES, YOU AGREE TO ALLOW US TO COLLECT AND PROCESS INFORMATION AS DESCRIBED IN THIS PRIVACY POLICY. YOU CAN CHOOSE NOT TO PROVIDE CERTAIN INFORMATION. IF YOU CHOOSE NOT TO PROVIDE SUCH INFORMATION, HOWEVER, YOU MIGHT NOT BE ABLE TO USE OR TAKE ADVANTAGE OF MANY OF OUR SERVICES.

Personal Information; Protected Health Information.

“Personal Information” is information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with you or your household. In this Privacy Policy, we do not include Protected Health Information (defined below) in the definition of “Personal Information” because Protected Health Information has different treatment under HIPAA and other applicable laws.

“Protected Health Information” is personally identifiable health information that is protected by the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”).

What information do we collect?

We collect personal and protected information when you provide it to us. Examples of information we collect are:

Registration Information. When you create an Account, we will collect personal information, which may include your name, address, telephone number, email address, username, password, contact preferences, and healthcare provider affiliation. We collect this information to identify you, provide you access to certain Services, and communicate with you.

User Content. Some of our Services may allow you to create, post or upload content, such as data, text, photographs, graphics, messages, or other materials that you create or provide to us (“User Content”), which may include information about yourself.

Device and Internet Information. When using the Services, we and our third-party service providers may use cookies and similar technologies to collect your browsing history, search history, and the IP address, geolocation, and identification number of the device that you use to access the Services. We collect this information to enable and personalize your online experience and to ensure security of our systems. If you reject cookies, you may still use our website, but your ability to use some features or areas of our website may be limited. 

Customer Service. When you correspond with us about the Services, we collect information to: track and respond to your inquiry; investigate any breach of the Terms of Service, this Privacy Policy or applicable laws or regulations; and analyze and improve our Services.

Protected Health Information. We collect your Protected Health Information that either you or your healthcare provider(s) submit, transmit or upload through the Services.

How do we process your information?

In addition to the purposes for which we collect your Personal Information and Protected Health Information listed above, we may use your Personal Information and/or Protected Health Information for the following purposes:

  • To provide you with the Services, create and maintain your Account, communicate with you, and provide other features and functionality to you.
  • To personalize the Services, including to remember your preferences, provide personalized content and information, and track your use of the Services. 
  • To market to you, including to send you marketing messages and other Services-related communications, or to ask you to participate in surveys about your use or experience with the Services. (Personal information only; not Protected Health Information)
  • To improve and further develop the Services, including to perform quality control activities, help us build new products, and improve the existing Services.
  • To provide customer support, including to answer your questions, resolve disputes, and/or investigate and troubleshoot problems or complaints.
  • To enforce our rights and for other legal purposes, including to provide you with legally required notices, to enforce our Terms of Service, or to alert you to changes in our policies or agreements that may affect your use of the Services.

Aggregate Information. We may also use information collected from you or the Services in a non-personally identifiable or aggregate form to help us improve the Services, make sales, marketing, and business decisions. This information is not Personal Information or Protected Health Information because it does not identify you or any particular individual or disclose your or any particular individual’s data.

We may use third-party service providers to perform some of these functions. Those service providers are restricted from sharing your Personal Information or Protected Health Information for any other purpose.

When and with whom do we share your information?

Under no circumstance will we share your Personal Information or Protected Health Information for any commercial or marketing purpose unrelated to the Services without your prior permission. We will not rent or sell our customer lists that include your Personal Information without your prior permission. We may share your Personal Information or Protected Health Information for the reasons we tell you when we collect it or in the following ways:

With Your Consent. We may share Personal Information and Protected Health Information when we have your consent.

At Your Direction. We may share your Personal Information and Protected Health Information with third parties when you direct us to. For example, if you request that we share your Personal Information and/or Protected Health Information with a designated healthcare provider, we will share your information with that healthcare provider.

For External Processing. We may engage contractors, service providers, and third-party technicians (collectively, the “Subcontractors”) to assist us with some of the data processing, storage and use described in this Privacy Policy, including to help answer your questions. Our Subcontractors may include marketing, operations, and technology vendors. These Subcontractors may also assist with monitoring our servers (including third-party servers used by Triangulate) for technical problems. These Subcontractors (as well as Triangulate’s employees) may be given access to certain Personal Information about you or your Account if necessary to provide those services. In no event will these Subcontractors be allowed to use this data for purposes not permitted under this Privacy Policy or the Terms of Service.

As Part of Business Transitions. If Triangulate participates in the sale or transfer of Triangulate business and/or all or part of its assets, your Personal Information and Protected Health Information may be among the items sold or transferred. We will require that any purchaser treat your data in accordance with this Privacy Policy.

For Legal Reasons. We will share Personal Information and/or Personal Health Information with third parties if we have a good faith belief that access, use, preservation or disclosure of the information is required by Triangulate to (i) comply with any applicable law, regulation, legal process or enforceable government request; (ii) enforce Triangulate’s policies (including the Terms of Service) or contracts, including in connection with the investigation of potential violations; (iii) detect, prevent or otherwise address fraud, security or technical issues; (iv) lawfully protect the rights, property or safety of Triangulate, our customers and users of the Services or the public.

Aggregate Information. We may share non-personal information (for example, aggregated or anonymized customer data) publicly and with our partners. We will take steps to ensure that this non-personal information does not identify you, and we require any of our partners who have access to that non-personal information to do the same.

How do we protect your information?

We take measures that exceed industry-standard methods and procedures to keep your Personal Information and Protected Health Information safe and secure when it is transmitted over networks and stored within our databases. Despite our safeguards and efforts to secure your information, no electronic transmission can be guaranteed to be 100% secure, so we cannot guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal or modify your information.

How do we process your information?

The Services are intended for use only in the United States of America. All information collected by the Services will be processed in and subject to the laws of the United States. If you are not located in the United States, such laws may not provide the same level of protection for your Personal Information and Protected Health Information as those in your home country. By using the Services and providing us your Personal Information and Protected Health Information, you consent to the transfer of your Personal Information and Protected Health Information to, and processing of your Personal Information and Protected Health Information in, the United States.

How can you access, edit or delete your personal information?

Triangulate stores your Personal Information and Protected Health Information (including personal information provided when creating an Account) on Triangulate’s and/or Triangulate-designated third-party servers until you choose to edit or delete such information. In addition, except as otherwise prohibited by law, Triangulate may store your Personal Information and Protected Health Information in order to resolve disputes, establish legal defenses, conduct audits, pursue legitimate business purposes, enforce our agreements and comply with applicable laws as provided in this Privacy Policy.

You can access, edit or update your Personal Information from these servers through the controls in your Account.

If you no longer wish to participate in our Services, or no longer wish to have your Personal Information and Protected Health Information be processed, you may delete your Personal Information and Protected Health Information by emailing privacy@skinmap.com. Once you submit your request, we will send an email to the email address linked to your Account requesting that you confirm your deletion request. Once you confirm your request, this process cannot be cancelled, undone, withdrawn, or reversed. Once you confirm your request, your Personal Information and Protected Health Information will be schedule for deletion according to our Data Retention policy.

How long do we keep your information? (Data Retention Policy)

We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy policy, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). No purpose in this policy will require us keeping your personal information for longer than one hundred twenty (120) months past the termination of your account.

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.

Third-Party Websites and Services.

When using the Services you may come across links or references to third-party websites and services that we do not operate or control. If you provide your Personal Information or Protected Health Information to that third party through its websites or services, you will be subject to that third party’s privacy practices and policies and terms of use. This Privacy Policy solely applies to Personal Information and Protected Health Information collected by Triangulate. Except as specifically indicated, Triangulate does not review or endorse those third parties, and is not responsible for the privacy practices of these third-party organizations. 

Do we collect information from minors?

We do not knowingly solicit data from or market to children under 18 years of age. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent’s use of the Services. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us at privacy@skinmap.com.

Do California residents have specific privacy rights?

California Civil Code Section 1798.83, also known as the “Shine The Light” law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us using the contact information provided below.

If you are under 18 years of age, reside in California, and have a registered account with Services, you have the right to request removal of unwanted data that you publicly post on the Services. To request removal of such data, please contact us using the contact information provided below and include the email address associated with your account and a statement that you reside in California. We will make sure the data is not publicly displayed on the Services, but please be aware that the data may not be completely or comprehensively removed from all our systems (e.g., backups, etc.).

CCPA Privacy Policy

The California Code of Regulations defines a “resident” as:

(1) every individual who is in the State of California for other than a temporary or transitory purpose and

(2) every individual who is domiciled in the State of California who is outside the State of California for a temporary or transitory purpose

All other individuals are defined as “non-residents.”

If this definition of “resident” applies to you, we must adhere to certain rights and obligations regarding your personal information.

What categories of personal information do we collect?

We have collected the following categories of personal information in the past twelve (12) months:

CategoryExamplesCollected
A. IdentifiersContact details, such as real name, alias, postal address, telephone or mobile contact number, unique personal identifier, online identifier, Internet Protocol address, email address, and account name  YES
B. Personal information categories listed in the California Customer Records statuteName, contact information, education, employment, employment history, and financial information  YES
C. Protected classification characteristics under California or federal lawGender and date of birth  YES
D. Commercial informationTransaction information, purchase history, financial details, and payment information  NO
E. Biometric informationPhotographs and LiDAR body measurements  YES
F. Internet or other similar network activityBrowsing history, search history, online behavior, interest data, and interactions with our and other websites, applications, systems, and advertisements  NO
G. Geolocation dataDevice location  NO
H. Audio, electronic, visual, thermal, olfactory, or similar informationImages and audio, video or call recordings created in connection with our business activities  YES
I. Professional or employment-related informationBusiness contact details in order to provide you our Services at a business level or job title, work history, and professional qualifications if you apply for a job with us  NO
J. Education InformationStudent records and directory information  NO
K. Inferences drawn from other personal informationInferences drawn from any of the collected personal information listed above to create a profile or summary about, for example, an individual’s preferences and characteristics  NO

We may also collect other personal information outside of these categories through instances where you interact with us in person, online, or by phone or mail in the context of:

  • Receiving help through our customer support channels;
  • Participation in customer surveys or contests; and
  • Facilitation in the delivery of our Services and to respond to your inquiries.

How do we use and share your personal information?

More information about our data collection and sharing practices can be found in this privacy policy.

You may contact us by email at ccpa@skinmap.com, or by referring to the contact details at the bottom of this document.

If you are using an authorized agent to exercise your right to opt out we may deny a request if the authorized agent does not submit proof that they have been validly authorized to act on your behalf.

Will your information be shared with anyone else?

We may disclose your personal information with our service providers pursuant to a written contract between us and each service provider. Each service provider is a for-profit entity that processes the information on our behalf.

We may use your personal information for our own business purposes, such as for undertaking internal research for technological development and demonstration. This is not considered to be “selling” of your personal information.

Triangulate Labs, Inc. has not sold any personal information to third parties for a business or commercial purpose in the preceding twelve (12) months. 

The categories of third parties to whom we disclosed personal information for a business or commercial purpose can be found under “When and with whom do we share your information?”

Your rights with respect to your personal data

Right to request deletion of the data — Request to delete

You can ask for the deletion of your personal information. If you ask us to delete your personal information, we will respect your request and delete your personal information, subject to certain exceptions provided by law, such as (but not limited to) the exercise by another consumer of his or her right to free speech, our compliance requirements resulting from a legal obligation, or any processing that may be required to protect against illegal activities.

Right to be informed — Request to know

Depending on the circumstances, you have a right to know:

  • whether we collect and use your personal information;
  • the categories of personal information that we collect;
  • the purposes for which the collected personal information is used;
  • whether we sell your personal information to third parties;
  • the categories of personal information that we sold or disclosed for a business purpose;
  • the categories of third parties to whom the personal information was sold or disclosed for a business purpose; and
  • the business or commercial purpose for collecting or selling personal information.

In accordance with applicable law, we are not obligated to provide or delete consumer information that is de-identified in response to a consumer request or to re-identify individual data to verify a consumer request.

Right to Non-Discrimination for the Exercise of a Consumer’s Privacy Rights

We will not discriminate against you if you exercise your privacy rights.

Verification process

Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. These verification efforts require us to ask you to provide information so that we can match it with information you have previously provided us. For instance, depending on the type of request you submit, we may ask you to provide certain information so that we can match the information you provide with the information we already have on file, or we may contact you through a communication method (e.g., phone or email) that you have previously provided to us. We may also use other verification methods as the circumstances dictate.

We will only use personal information provided in your request to verify your identity or authority to make the request. To the extent possible, we will avoid requesting additional information from you for the purposes of verification. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes. We will delete such additionally provided information as soon as we finish verifying you.

Other privacy rights

  • You may object to the processing of your personal information.
  • You may request correction of your personal data if it is incorrect or no longer relevant, or ask to restrict the processing of the information.
  • You can designate an authorized agent to make a request under the CCPA on your behalf. We may deny a request from an authorized agent that does not submit proof that they have been validly authorized to act on your behalf in accordance with the CCPA.
  • You may request to opt out from future selling of your personal information to third parties. Upon receiving an opt-out request, we will act upon the request as soon as feasibly possible, but no later than fifteen (15) days from the date of the request submission.

To exercise these rights, you can contact us by email at ccpa@skinmap.com, or by referring to the contact details at the bottom of this document. If you have a complaint about how we handle your data, we would like to hear from you.

Policy Changes.

Please note that this Privacy Policy may change from time to time. When we make material changes to this Privacy Policy, we will give you notice by posting an alert through the Services or by sending you an email to the email address we have on file. 

Contact Triangulate.

We welcome your questions and instructions at privacy@skinmap.com