O P E N D O C
Privacy Policy
Effective: March 2026 | Version 2.0
Sherlock Health, Inc., doing business as OpenDoc (“we,” “us,” “our”), operates a healthcare transaction platform that enables patients to find providers, see guaranteed cash prices, and pay for defined healthcare services. This Privacy Policy describes how we collect, use, share, and protect your personal information when you use the OpenDoc platform, website, and mobile application (collectively, the “Platform”).
This Privacy Policy applies to all users of OpenDoc, including patients, prospective patients, and visitors to our website. Provider data practices are governed by the OpenDoc Provider Agreement.
Our core commitment: OpenDoc does not sell your personal data. OpenDoc does not use your data for advertising. OpenDoc does not store your medical records.
1. Information We Collect
1.1 Information You Provide
- Account Information. When you create an account: your legal name, date of birth, email address, phone number, and mailing address.
- Payment Information. When you add a payment method: your credit card, debit card, HSA/FSA card, or bank account details. Payment information is collected and stored by our payment processor (currently Stripe, Inc.), not by OpenDoc directly. We receive only a tokenized reference and the last four digits of your card number.
- Transaction Information. When you activate a Health Key: the HSO (service) selected, the provider selected, the price (MPR), the date and time of service, Health Key state changes, Proof of Service status, and payment and refund records.
- Dependent Information. If you manage Health Keys for dependents: their name, date of birth, and transaction information as described above.
- Communications. When you contact us: the content of your messages, dispute filings, and support requests.
1.2 Information Collected Automatically
- Device and Browser Information. Device type, operating system, browser type, screen resolution, and unique device identifiers.
- Usage Information. Pages viewed, features used, search queries entered, time spent on the Platform, and interaction patterns.
- Location Information. Approximate location based on IP address. We use this to show you providers near your area. We do not collect precise GPS location unless you explicitly enable location services, and you can disable this at any time.
- Log Data. IP address, access times, referring URLs, and error logs.
1.3 Information We Do NOT Collect
OpenDoc does not collect:
- Medical records, clinical notes, test results, diagnoses, or prescriptions
- Insurance plan details, member IDs, group numbers, or claims data
- Social Security numbers
- Biometric data (unless you enable biometric authentication for app login, in which case biometric data is processed locally on your device and never transmitted to OpenDoc)
- Health information beyond the transaction data described in Section 1.1
OpenDoc is not a Business Associate under HIPAA. We do not create, receive, maintain, or transmit Protected Health Information on behalf of any healthcare provider.
2. How We Use Your Information
We use your personal information for the following purposes:
- Platform Operations. To create and manage your account, verify your identity, process Health Key transactions, facilitate payments and refunds, and provide customer support.
- Transaction Facilitation. To match you with providers, display prices, activate Health Keys, process escrow and settlement, generate receipts, and maintain your transaction history.
- Receipt Generation. To generate itemized receipts for your completed transactions, including information needed for HSA/FSA expense substantiation (service description, date, provider name and NPI, amount paid).
- Communications. To send you transaction confirmations, Health Key status updates, dispute notifications, account security alerts, and responses to your inquiries.
- Platform Improvement. To analyze usage patterns, diagnose technical issues, improve features, and develop new services. We use only aggregated and anonymized data for this purpose.
- Safety and Security. To detect and prevent fraud, enforce our Terms of Service, protect the security of the Platform, and comply with legal obligations.
- Legal Compliance. To comply with applicable laws, regulations, legal processes, and governmental requests.
We do not use your personal information for advertising, profiling for marketing purposes, or sale to third parties.
Our legal bases for processing your information are: performance of our contract with you (the Terms of Service), our legitimate business interests in operating and improving the Platform, your consent where specifically obtained, and compliance with legal obligations.
3. How We Share Your Information
We share your personal information only in the following circumstances:
3.1 With Your Provider
When you activate a Health Key, we share your name, date of birth, the HSO selected, and the Health Key credential with the provider you selected. This is necessary to facilitate the transaction you authorized. We share only the information needed for the specific transaction. We do not share your payment card details, your transaction history from other providers, or your account information beyond what is displayed on the Health Key.
3.2 With Our Payment Processor
We share your payment information with our payment processor (currently Stripe, Inc.) to process payments, escrow funds, issue refunds, and manage chargebacks. Stripe's handling of your payment information is governed by Stripe's own privacy policy and PCI DSS compliance standards.
3.3 With Service Providers
We may share information with third-party service providers who perform services on our behalf, such as cloud hosting, email delivery, analytics, and customer support tools. These providers are contractually required to use your information only for the purposes of providing services to OpenDoc and must maintain appropriate security standards.
3.4 For Legal Purposes
We may disclose your information if required by law, in response to a valid subpoena, court order, or government request, or as necessary to enforce our Terms of Service, protect OpenDoc's rights, or prevent fraud. Where legally permitted, we will make reasonable efforts to notify you before or promptly after disclosing your information in response to legal process.
3.5 In a Business Transfer
If OpenDoc is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such transfer and any changes to this Privacy Policy.
3.6 With Your Consent
We may share your information in other circumstances with your explicit consent.
3.7 What We Never Share
We never share your information with:
- Advertisers or advertising networks
- Data brokers
- Insurance companies (OpenDoc does not interact with insurers)
- Any party for the purpose of marketing products or services to you
4. Aggregated and Anonymized Data
Information that has been aggregated and anonymized so that it cannot reasonably identify any individual is not personal information under this Privacy Policy. OpenDoc may use aggregated and anonymized data for any lawful purpose, including market analysis, pricing intelligence, Platform improvement, statistical reporting, and product development. This data may include aggregate transaction volumes, average prices by service type and geography, and completion rate statistics. No individual user can be identified from this data.
5. Sale of Personal Information
OpenDoc does not sell your personal information. We have never sold personal information. We will not sell your personal information.
For purposes of the California Consumer Privacy Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Texas Data Privacy and Security Act (TDPSA), the Oregon Consumer Privacy Act, and the Montana Consumer Data Privacy Act: OpenDoc does not currently “sell” or “share” (as those terms are defined under applicable state law) your personal information for monetary or other valuable consideration. If this ever changes, we will update this Privacy Policy and provide an opt-out mechanism before any sale or sharing begins.
6. Cookies and Tracking Technologies
6.1 What We Use
OpenDoc uses the following categories of cookies and similar technologies:
- Essential Cookies. Required for the Platform to function. These handle authentication, session management, security, and payment processing. You cannot opt out of essential cookies while using the Platform.
- Analytics Cookies. Help us understand how the Platform is used so we can improve it. These collect aggregated, anonymized usage data. You may opt out of analytics cookies through your browser settings or through the cookie preferences panel at opendoc.com/cookies.
6.2 What We Do Not Use
OpenDoc does not use:
- Advertising or targeting cookies
- Third-party tracking pixels for advertising purposes
- Cross-site tracking technologies
- Fingerprinting or other persistent identification techniques beyond standard cookies
6.3 Do Not Track
OpenDoc honors Do Not Track (DNT) browser signals. When we detect a DNT signal, we disable analytics cookies for that session.
7. Data Retention
7.1 Active Accounts
We retain your personal information for as long as your account is active and as needed to provide you services, process transactions, and maintain your Health Key transaction history.
7.2 After Account Closure
After you close your account, we retain your transaction history for seven (7) years following your last transaction. This retention period is consistent with IRS record-keeping requirements for healthcare expenses (relevant if you used HSA/FSA funds) and applicable state record-keeping laws. After the retention period, your data is permanently deleted.
7.3 Specific Retention Periods
- Account information (name, date of birth): Retained for the duration of the transaction record retention period (7 years from last transaction), because this information is necessary to identify completed transactions for IRS and legal purposes. Other account information (email, phone, address, login credentials) is deleted within 90 days of account closure.
- Transaction records: 7 years from the date of the last transaction.
- Payment tokens: Deleted within 90 days of account closure. Underlying payment data is retained by Stripe pursuant to Stripe's retention policies and PCI DSS requirements.
- Communications and support records: 3 years from the date of the communication.
- Device and usage data: 13 months from collection.
- Dispute records: 7 years from resolution, consistent with legal requirements.
7.4 Legal Holds
We may retain information beyond the periods described above if required by law, regulation, legal hold, or pending litigation.
8. Data Security
We implement technical and organizational security measures designed to protect your personal information, including:
- Encryption of data in transit (TLS 1.2+) and at rest
- Payment information processed through PCI DSS-compliant infrastructure (Stripe)
- Access controls limiting employee access to personal information on a need-to-know basis
- Regular security assessments and monitoring
- Incident response procedures for potential data breaches
No method of electronic transmission or storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security.
8.1 Data Breach Notification
In the event of a data breach that compromises your personal information, we will notify you as required by applicable state law, and in any event within sixty (60) days of confirming the breach. Notification will be sent to the email address associated with your account and, where required by law, to applicable state regulators.
9. Your Rights
9.1 Rights Available to All Users
Regardless of where you live, you have the following rights:
- Access: You can view your account information, transaction history, and receipts through the Platform at any time.
- Correction: You can update your account information through the Platform. If you believe any transaction record is inaccurate, contact us at [email protected].
- Deletion: You can request deletion of your account and personal information by contacting us at [email protected]. Deletion is subject to the retention periods described in Section 7 and any legal obligations.
- Data Export: You can request a copy of your personal information in a portable, machine-readable format by contacting us at [email protected].
9.2 Additional Rights for California Residents (CCPA/CPRA)
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
- Right to Know. You may request that we disclose the categories and specific pieces of personal information we have collected about you, the sources of collection, the business purposes for collection, and the categories of third parties with whom we share your information.
- Right to Delete. You may request deletion of your personal information, subject to certain exceptions (such as completing a transaction you requested, complying with legal obligations, or maintaining records required by law).
- Right to Correct. You may request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing. OpenDoc does not currently sell or share your personal information as defined by the CCPA/CPRA. No opt-out is necessary at this time.
- Right to Limit Use of Sensitive Personal Information. OpenDoc uses sensitive personal information (such as your payment information) only as necessary to provide the Platform services you request. No additional limitation is needed.
- Right to Non-Discrimination. We will not discriminate against you for exercising any of your privacy rights.
- Authorized Agents. You may designate an authorized agent to submit requests on your behalf. We may require the authorized agent to provide proof of your written authorization and may verify your identity directly.
To exercise these rights, contact us at [email protected] or use the request form at opendoc.com/privacy/request. We verify your identity by matching information you provide in your request against information we already have on file. We may ask you to confirm your name, email address, and details of a recent transaction.
For California residents under 16, we comply with the additional protections required by the CPRA, including not selling or sharing their personal information without affirmative opt-in consent.
9.3 Additional Rights for Virginia, Colorado, Connecticut, Texas, Oregon, and Montana Residents
If you are a resident of Virginia, Colorado, Connecticut, Texas, Oregon, or Montana, you have similar rights under your state's applicable consumer data privacy law:
- Right to access, correct, and delete your personal data
- Right to data portability (receive your data in a portable format)
- Right to opt out of the sale of personal data (not applicable — OpenDoc does not sell data)
- Right to opt out of targeted advertising (not applicable — OpenDoc does not engage in targeted advertising)
- Right to opt out of profiling (not applicable — OpenDoc does not engage in profiling that produces legal or similarly significant effects)
To exercise these rights, contact us at [email protected]. If we deny your request, you may appeal by contacting us at [email protected] with the subject line “Privacy Appeal.” If you are a Colorado, Connecticut, or Oregon resident, you may also contact your state attorney general if you are not satisfied with the outcome of your appeal.
9.4 Additional Rights for Other States
Privacy laws are evolving across the United States. If your state enacts consumer privacy legislation that provides additional rights not listed above, we will comply with applicable requirements. Contact us at [email protected] to exercise any state-specific privacy rights.
9.5 Response Timing
We respond to all verified privacy rights requests within forty-five (45) days. If we need additional time due to the complexity of the request, we will notify you of the extension and the reason, and will respond within a total of ninety (90) days.
10. Children's Privacy
OpenDoc accounts may only be created by individuals 18 years of age or older (or the age of majority in their state). We do not knowingly collect personal information directly from children under 18.
Parents and legal guardians may manage Health Keys for minor dependents through their own account, as described in our Terms of Service. In such cases, the parent or guardian provides and controls the dependent's information.
If we learn that we have collected personal information directly from a child under 13 without verified parental consent as required by the Children's Online Privacy Protection Act (COPPA), we will delete that information promptly. For California residents under 16, we comply with the additional protections required by the CPRA. If you believe we have collected information from a child under 13, contact us at [email protected].
11. Categories of Personal Information (CCPA Disclosure)
The following table describes the categories of personal information we have collected in the preceding 12 months, as required by the CCPA:
| Category | Examples | Purpose | Shared With |
|---|---|---|---|
| Identifiers | Name, DOB, email, phone, address | Account creation, identity verification, transaction facilitation | Provider (name/DOB only), payment processor |
| Financial information | Payment card last 4 digits, payment tokens | Payment processing, refunds, receipts | Payment processor (Stripe) |
| Transaction information | HSO, provider, price, date, Health Key states, receipts | Transaction facilitation, history, receipts, dispute resolution | Provider (their transaction only); OpenDoc (aggregated/anonymized) |
| Device/usage data | IP, device type, browser, pages viewed | Platform operation, security, analytics | Service providers (aggregated) |
| Location data | Approximate location from IP | Provider search and display | Not shared |
| Communications | Support messages, dispute filings | Customer support, dispute resolution | Not shared (except as needed for dispute with provider) |
Categories NOT collected: biometric data, health/medical data, insurance data, Social Security numbers, education records, precise geolocation, audio/visual data, professional/employment data, inferences or profiles for advertising.
12. Third-Party Services and Links
The Platform may contain links to third-party websites or services, such as provider websites. This Privacy Policy applies only to OpenDoc. We are not responsible for the privacy practices of third-party websites or services. We encourage you to review the privacy policies of any third-party services you visit.
Our payment processor (Stripe) operates under its own privacy policy. When you provide payment information through OpenDoc, Stripe's privacy policy and PCI DSS compliance standards govern the handling of your payment card data.
13. International Users
The Platform is intended solely for users in the United States. We do not knowingly collect personal information from individuals outside the United States. If you access the Platform from outside the United States, please be aware that your information will be transferred to and processed in the United States, and US privacy laws may differ from those in your jurisdiction. We do not currently offer services outside the United States.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you at least thirty (30) days before the changes take effect by email or through the Platform. We will also update the “Effective” date at the top of this page. Your continued use of the Platform after the effective date constitutes acceptance of the updated Privacy Policy.
15. Contact Us
If you have questions about this Privacy Policy, want to exercise your privacy rights, or have a concern about how we handle your data:
Email: [email protected]
Mail: Sherlock Health, Inc. d/b/a OpenDoc, Attn: Privacy, [Address]
Privacy rights requests: opendoc.com/privacy/request
Cookie preferences: opendoc.com/cookies
Your data exists to serve your transactions, not the other way around.
— End of Privacy Policy —