Privacy Policy

PERFORMANCE YOUTH MEDICINE

WEBSITE PRIVACY POLICY

Effective Date: January 16, 2026  |  Last Updated: January 16, 2026

INTRODUCTION

The Practice’s Notice of Privacy Practices applies only to individuals who have established a formal patient relationship with the Practice.

This Privacy Policy describes how Performance Youth Medicine, LLC ("Practice," "we," "us," or "our") collects, uses, and protects information that you provide when you visit our website at performanceyouthmedicine.com (the "Website"). The terms "you" or "your" refer to users of our Website.

By using the Website, you consent to the data practices described in this Privacy Policy. If you do not agree to these terms, please do not access or use the Website.

IMPORTANT: This Privacy Policy applies only to information collected through our Website BEFORE you become a patient. If you enroll as a patient, your Protected Health Information (PHI) is governed by separate HIPAA regulations and our HIPAA Notice of Privacy Practices, which you will receive at enrollment.

INFORMATION WE COLLECT

1.1 Personal Information You Provide

When you use our Website, we may collect the following personal information that you voluntarily provide:

•       Name (first and last)

•       Email address

•       Mobile phone number

•       Athlete's age (optional)

•       Information about your concerns or questions (optional)

•       Any other information you choose to provide through contact forms

1.2 Information Automatically Collected

When you visit our Website, we automatically collect certain technical information, including:

•       IP address

•       Browser type and version

•       Device type (computer, mobile, tablet)

•       Operating system

•       Pages you visit on our Website

•       Date and time of your visit

•       Referring website addresses

•       General location information (city/state level based on IP address)

1.3 Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience on our Website. For more information, see Section 8 below.

HOW WE USE YOUR INFORMATION

We use the information we collect for the following purposes:

2.1 To Communicate With You

       Schedule and confirm discovery call appointments

       Respond to your inquiries and requests

       Send you information about our programs and services

       Provide customer support

2.2 To Improve Our Services

       Analyze how visitors use our Website

       Improve Website functionality and user experience

       Develop new programs and services

       Conduct internal research and quality improvement

2.3 Marketing Communications (With Your Consent)

       Send periodic emails about our programs, services, and health information

       Send text messages about appointments and program information (only if you opt in)

       Share educational content and wellness tips

2.4 Legal and Business Purposes

       Comply with legal obligations

       Protect our rights and property

       Prevent fraud or abuse

       Maintain accurate records

       Respond to legal requests or court orders

TEXT MESSAGE COMMUNICATIONS (TCPA COMPLIANCE)

3.1 Consent Required

If you provide your mobile phone number and check the consent box on our contact form, you are agreeing to receive text messages from Performance Youth Medicine. Text messages may include:

       Appointment reminders and confirmations

       Discovery call scheduling and follow-up

       Program information and updates

       Occasional marketing messages about our services

       Health and wellness tips

3.2 Message Frequency

Message frequency varies. You may receive up to 4 text messages per month. During active appointment scheduling, you may receive additional messages.

3.3 How to Opt Out

Consenting to text messages is completely optional and is NOT required to use our services or enroll in our programs.

You can opt out of text messages at any time by:

       Replying STOP to any text message from us

       Emailing [email protected] with "Unsubscribe from Texts" in the subject line

       Calling our office at 720-531-4233

We will confirm your opt-out and stop sending texts within 24 hours.

3.4 Message and Data Rates

Message and data rates may apply based on your mobile carrier's plan. Performance Youth Medicine is not responsible for any charges from your mobile carrier.

3.5 No Sharing of Mobile Numbers

We will never sell, rent, or share your mobile phone number with third parties for their marketing purposes without your explicit consent.

EMAIL COMMUNICATIONS (CAN-SPAM COMPLIANCE)

4.1 Email Consent

If you provide your email address and check the consent box on our contact form, you agree to receive email communications from Performance Youth Medicine.

4.2 Unsubscribe from Emails

You can unsubscribe from marketing emails at any time by:

       Clicking the "Unsubscribe" link at the bottom of any marketing email

       Emailing [email protected] with "Unsubscribe" in the subject line

       Contacting our office directly

We will process your unsubscribe request within 10 business days.

Note: Even if you unsubscribe from marketing emails, we may still send you important administrative emails about appointments, program enrollment, or changes to our policies.

IMPORTANT DISTINCTION: WEBSITE DATA VS. HEALTH INFORMATION

5.1 What This Privacy Policy Covers

This Privacy Policy applies ONLY to information collected through our Website, including:

       Contact information (name, email, phone number)

       Information submitted through website forms

       Website browsing and usage data

       Cookie and tracking data

5.2 What This Privacy Policy Does NOT Cover

This Privacy Policy does NOT cover your Protected Health Information (PHI) if you become a patient of Performance Youth Medicine, including:

       Medical records and health history

       Test results and diagnoses

       Treatment plans and clinical notes

       Health-related communications with our providers

       Billing and insurance information

       Any health information collected after you enroll as a patient

5.3 HIPAA Protection for Patient Health Information

If you become a patient, your health information is protected under the Health Insurance Portability and Accountability Act (HIPAA). You will receive a separate HIPAA Notice of Privacy Practices that explains in detail how we use, disclose, and protect your medical information.

For questions about how we handle your health records as a patient, please contact our HIPAA Privacy Officer at [email protected] or request a copy of our HIPAA Notice of Privacy Practices.

SHARING YOUR INFORMATION WITH THIRD PARTIES

6.1 Service Providers We Use

We share your personal information with the following third-party service providers who help us operate our Website and communicate with you:

Customer Relationship Management (CRM) and Communications Platform

       Provider: FunnelProRx

       Purpose: Manage contact information, send emails and text messages, schedule appointments, store form submissions

       Data Shared: Name, email address, phone number, form responses

       Protection: Business Associate Agreement (BAA) in place; HIPAA-compliant platform

Website Hosting

       Provider: GoDaddy

       Purpose: Host and maintain the Website

       Data Shared: All website data and traffic

       Protection: Secure servers, encrypted connections

Analytics

       Provider: FunnelProRx and Google Analytics

       Purpose: Understand how visitors use our Website

       Data Shared: Anonymized browsing data, IP addresses

       Protection: Data anonymization settings enabled

Payment Processing (when applicable)

       Provider: Rectangle Health

       Purpose: Process payments for programs and services

       Data Shared: Payment card information only when you make a purchase

       Protection: PCI-DSS compliant; we never store payment card data on our servers

6.2 Contractual Protections

All third-party service providers are contractually required to:

       Protect your data with appropriate security measures

       Use your data only to provide services to Performance Youth Medicine

       Not sell, rent, or share your data for their own purposes

       Comply with HIPAA requirements if they access any health information

       Notify us of any data breaches

6.3 Automated Decision-Making and Profiling

We do not use automated decision-making or profiling that produces legal or similarly significant effects concerning you.

6.4 When We May Disclose Your Information

We may disclose your personal information in the following circumstances:

       With your explicit consent

       To comply with legal obligations (court orders, subpoenas, legal process)

       To protect our rights, property, or safety, or that of our patients or the public

       To enforce our Terms of Service or other agreements

       In connection with a business transfer (merger, acquisition, sale of assets)

       To prevent fraud, abuse, or illegal activity

6.5 What We Do NOT Do

We do NOT:

       Sell your personal information to third parties

       Rent or lease your contact information

       Use your information for targeted advertising on other websites

       Share your information with third parties for their marketing purposes (without your consent)

YOUR PRIVACY RIGHTS

7.1 Colorado Residents' Privacy Rights

If you are a Colorado resident, you have the following rights under the Colorado Privacy Act (CPA):

Right to Access: Request confirmation of whether we are processing your personal data and access to that data

Right to Correct: Request correction of inaccurate personal data

Right to Delete: Request deletion of your personal data (subject to legal retention requirements)

Right to Data Portability: Receive a copy of your personal data in a portable, readily usable format

Right to Opt-Out: Opt out of:

       Sale of personal data (we do not sell personal data)

       Targeted advertising (we do not use targeted advertising)

       Profiling that produces legal or similarly significant effects

7.2 How to Exercise Your Rights

To exercise any of these rights, please contact us at:

Email: [email protected]

Phone: 720-531-4233

Mail: Performance Youth Medicine, LLC, 9250 E Costilla Ave, Suite 110, Greenwood Village, CO 80112

We will respond to your request within 45 days. If we need additional time, we will notify you of the extension and the reason.

7.3 Appeal Process

If we deny your request, you have the right to appeal by contacting us at [email protected] within 30 days. We will respond to your appeal within 45 days.

7.4 All Users' Rights

Regardless of location, all users have the right to:

       See what personal information we have about you

       Request correction of incorrect information

       Request deletion of your information (subject to legal requirements)

       Opt out of marketing communications

       Withdraw consent for text messages or emails at any time

COOKIES AND TRACKING TECHNOLOGIES

8.1 What Are Cookies

Cookies are small text files stored on your device by your web browser. They help us recognize your device and remember your preferences.

8.2 Types of Cookies We Use

Essential Cookies

       Purpose: Required for basic website functionality (forms, navigation)

       Duration: Session-based (deleted when you close your browser)

       Can be disabled: No, without limiting website functionality

Analytics Cookies

       Purpose: Help us understand how visitors use our Website to improve user experience

       Provider: FunnelProRx

       Duration: Up to 2 years

       Can be disabled: Yes, through browser settings

8.3 Managing Cookies

You can control and manage cookies through your browser settings:

       Chrome: Settings > Privacy and Security > Cookies

       Firefox: Preferences > Privacy & Security > Cookies

       Safari: Preferences > Privacy > Cookies

       Edge: Settings > Privacy > Cookies

Note: Disabling cookies may limit certain website functionality.

8.4 Do Not Track Signals

Our Website does not currently respond to "Do Not Track" signals from web browsers. You can still control cookies through your browser settings as described above.

DATA SECURITY AND RETENTION

9.1 Security Measures

We take the security of your personal information seriously and implement industry-standard security measures, including:

       SSL/TLS encryption for all data transmitted to and from our Website (HTTPS)

       Secure servers with restricted access

       Encrypted storage of sensitive information

       Regular security assessments and updates

       Limited employee access to personal information (only those who need it to perform their jobs)

       Business Associate Agreements with all vendors who may access health-related data

9.2 Data Breach Notification

In the event of a data breach affecting your personal information, we will notify you within 30 days of discovery as required by Colorado law (C.R.S. § 6-1-716). Notification will include:

       The nature of the breach

       Types of information involved

       Steps you can take to protect yourself

       Contact information for questions and support

9.3 Limitations of Internet Security

Despite our security measures, please understand that no data transmission over the Internet or wireless network can be guaranteed to be 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security. You acknowledge that:

       There are inherent security and privacy limitations of the Internet beyond our control

       The security and privacy of information exchanged through our Website cannot be guaranteed

       Any information transmitted may potentially be viewed or tampered with by unauthorized third parties

9.4 Data Retention

We retain your personal information for the following periods:

       Contact form submissions: 3 years from last contact, or until you request deletion

       Email marketing data: Until you unsubscribe, plus 30 days to process removal

       Text message consent: Until you opt out, plus 30 days to process removal

       Website analytics: 26 months (analytics platform default)

       Legal compliance records: As required by law (typically 7 years for medical practices)

If you become a patient, medical records retention is governed by HIPAA and Colorado medical records laws (minimum 7 years after last treatment for adults; until age 25 for minors).

You may request deletion of your data at any time by contacting us at [email protected].

CHILDREN'S PRIVACY (COPPA COMPLIANCE)

Our Website is not designed for or directed to children under the age of 13. We do not knowingly collect personal information from children under 13 without verified parental consent.

Because our programs are designed for youth athletes (typically ages 11-18), we recognize that minors may visit our Website. We require that:

       Parents or legal guardians submit contact forms on behalf of minors

       Parents provide consent before we communicate with minors

       Parents review all program materials and provide informed consent for treatment

Parental Verification

For children ages 11-12, we verify parental consent by requiring parents to submit forms directly and confirm their identity through phone or video consultation before any program enrollment or significant data collection.

If we learn that we have collected personal information from a child under 13 without verified parental consent, we will delete that information as quickly as possible.

If you believe we have collected information from a child under 13, please contact us immediately at [email protected].

CHANGES TO THIS PRIVACY POLICY

11.1 Right to Update

We reserve the right to update or modify this Privacy Policy at any time. When we make changes, we will update the "Last Updated" date at the top of this policy.

11.2 Notification of Material Changes

If we make material changes that significantly affect how we use your personal information, we will notify you by:

       Email to the address you provided (if we have it)

       Prominent notice on our Website homepage

       Updated effective date on this Privacy Policy

11.3 Your Acceptance

Your continued use of our Website after we post changes constitutes your acceptance of the updated Privacy Policy. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

CONTACT INFORMATION

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Performance Youth Medicine, LLC

Email: [email protected]

Phone: 720-531-4233

Mailing Address: 9250 E Costilla Ave, Suite 110, Greenwood Village, CO 80112

HIPAA Privacy Officer: Jeanne Oh, MD (For questions about patient health information)

ACCESSIBILITY

We are committed to ensuring that our Privacy Policy is accessible to all users, including those with disabilities. If you have difficulty accessing this Privacy Policy in its current format, please contact us at [email protected] and we will provide it in an alternative format.

EFFECTIVE DATE AND ACKNOWLEDGMENT

This Privacy Policy is effective as of the date listed at the top of this document.

By using our Website, submitting a contact form, or providing your personal information to us, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

This Privacy Policy is intended to comply with applicable Federal Trade Commission (FTC) requirements regarding truthful, non-deceptive disclosures and the protection of consumer personal information collected through this Website.

END OF PRIVACY POLICY

© 2026 Performance Youth Medicine, LLC. All rights reserved.