Who we are
Waypoint Data Solutions (“Waypoint,” “we,” “us,” or “our”) is committed to protecting the privacy and security of our users’ personal and health-related data. This Privacy Policy outlines how we collect, use, store, and share personal information through our technology platform, including the:
-
- Waypoint Web Application (web portal)
-
- Waypoint Mobile Application (pilot smartphone app for iOS and Android)
-
- IoT-connected wearable devices (e.g., Fitbit Sense 2) and related cloud-based infrastructure (Azure-hosted)
Waypoint’s systems are designed for mental health support and remote patient monitoring (RPM), providing services to patients, healthcare providers, and authorized administrative users.
Scope
This Privacy Policy applies to all users who interact with our digital health services and products, including individuals who:
Participate in a clinical program utilizing Waypoint’s data-driven services
Visit our website or use our web app
Download or use the pilot version of our mobile app
Connect their wearable device (e.g., Fitbit Sense 2) to our platform
Information We Collect
Waypoint collects the following categories of information:
a. Personally Identifiable Information (PII)
-
- Full name, date of birth, and contact details
-
- Usernames, passwords, or authentication tokens
-
- Email address, phone number, or IP address
b. Protected Health Information (PHI)
-
- Biometric readings (e.g., HRV, sleep, respiration rate, skin temperature, SpO2)
-
- Session notes, mood logs, check-in responses, and health assessments
-
- Diagnoses, treatment protocols, and therapy progression data
c. Device & Usage Information
-
- Device identifiers (UUIDs)
-
- Device operating system and browser type
-
- Log files and usage events on web and mobile apps
-
- GPS and location data (if user consents)
d. System Integrations & Metadata
-
- Cloud telemetry logs (Azure IoT Central)
-
- Fitbit OAuth tokens and device sync records
-
- Audit logs from the web app, API requests, and administrative actions
How We Use Your Information
We use your information for the following purposes:
-
- To provide, operate, and improve our mental health support tools
-
- To securely sync biometric data between wearables and cloud dashboards
-
- To generate actionable insights for clinicians and care managers
-
- To enable user and provider account access, role-based permissions, and data visualizations
-
- To comply with HIPAA, GDPR, and other relevant data protection laws
-
- To communicate with users about alerts, updates, and scheduled therapy sessions
Cookies
If you leave a comment on our site, you may opt in to saving your name, email address, and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
Data Sharing & Disclosure
Waypoint does not sell personal data. We may share user information:
In de-identified and aggregated formats for research and analytics
With authorized clinical providers or guardians as part of a care team
With our cloud service provider (Microsoft Azure) under strict HIPAA- and SOC 2-compliant agreements
With third-party platforms (e.g., Fitbit) for device syncing, as authorized by users via OAuth 2.0
With regulatory bodies or auditors, as required by law
Data Storage and Security
All personal data is stored securely within Microsoft Azure’s cloud infrastructure. Key protections include:
-
- End-to-end encryption (AES-256 in transit and at rest)
-
- Access control via role-based permissions (RBAC)
-
- Secure APIs and multi-factor authentication (MFA)
-
- Regular vulnerability scanning, logging, and intrusion detection
We follow NIST and HIPAA technical safeguards and have business associate agreements (BAAs) with all data processors.
Your Rights and Choices
Users may:
-
- Request access to or correction of personal data
-
- Withdraw consent for specific types of data collection (e.g., GPS)
-
- Request deletion or export of their data
-
- Request audit logs of access to their health records
To make a request, contact us at: admin@waypointhealth.us
Children’s Privacy
Waypoint does not knowingly collect personal information from children under the age of 13 without verified parental consent. For minors participating in clinical programs, all data is collected with guardian oversight and controlled access.
Changes to This Policy
We may periodically update this Privacy Policy to reflect changes to our practices or legal requirements. Users will be notified of any material changes via email and/or app notification.
Contact Us
If you have questions or concerns about this policy or how your data is handled: