Skip to content

Legal

Cookie Policy

Version 1.0Effective 1 September 2026

Version1.0
PublishedSeptember 1, 2026
EffectiveSeptember 1, 2026
ProviderGetClinic, Inc., a Delaware corporation
Applies WithPatient Privacy Policy

1. Who We Are

GetClinic, Inc., 74 E Glenwood Ave, Unit #5895, Smyrna, Delaware 19977, United States, operates the GetClinic technology marketplace. Privacy questions may be sent to [email protected].

2. What Cookies and Similar Technologies Are

Cookies are small files or identifiers stored on or accessed from a browser or device. Similar technologies can include local storage, mobile SDK identifiers, tags, pixels and comparable tools. They can support security, remember settings, measure how a service works or, where lawfully enabled, support advertising.

3. Categories We May Use

CategoryPurposeTypical StatusExamples
Strictly Necessary / SecurityOperate core features, authenticate sessions, prevent fraud/abuse, maintain security, route traffic and remember privacy choices.Generally active where necessary to provide or secure the service.Session, load-balancing, security, consent-choice and authentication identifiers.
Preferences / FunctionalRemember user-selected language, display, region or other non-essential preferences.Subject to applicable consent/choice rules.Language and interface preferences.
Analytics / PerformanceUnderstand aggregate use, reliability, errors and product performance.Enabled only where permitted by applicable law and consent/choice state.Audience measurement, error/performance analytics.
Advertising / MeasurementMeasure or support advertising on public/non-medical surfaces where GetClinic lawfully uses such technology.Disabled unless lawfully enabled and any required consent/opt-out state permits it.Campaign attribution or advertising measurement.

4. Health Data and Private Medical Areas

GetClinic does not use Patient Health Data to create targeted-advertising audiences or sell Health Data. GetClinic's current privacy commitment is not to place third-party advertising pixels or cross-context behavioral-advertising trackers in authenticated medical areas, private Patient-Clinic messaging, medical-document upload areas or other private health-data surfaces.

Necessary security, fraud-prevention, service-delivery and first-party operational technologies may still operate in those areas where required to provide or protect the service.

Where applicable law requires prior consent for a non-essential category, GetClinic will keep that category disabled until the required consent is obtained. Where law provides an opt-out rather than prior-consent model, GetClinic will provide the applicable choice mechanism.

You can change available choices through GetClinic's Cookie Settings / consent interface. Withdrawing consent does not make earlier processing unlawful where it was lawful before withdrawal, but GetClinic will stop future use of the withdrawn optional category as required by law.

The current Cookie Settings / consent interface should identify the specific cookies and similar technologies active for the user's device or service surface, including provider, purpose, category and duration where applicable. That operational inventory is the source of truth for the technologies currently deployed; this Policy describes the governing categories and rules.

GetClinic must not silently deploy a new optional analytics or advertising technology outside the category and consent status shown to the user.

Technologies in scope. The list below identifies the technologies GetClinic uses on Patient-facing surfaces and the category each falls into. Exact identifier names, durations and any newly added technology are maintained in the Cookie Settings inventory, which remains the operational source of truth.

Strictly necessary and security. GetClinic session and authentication identifiers, including those set through GetClinic's identity provider, to sign you in and keep the session secure; a synthetic-monitoring identifier (gc_synthetic) used to exclude automated monitoring traffic from measurement; Cloudflare Turnstile, to protect forms against automated abuse; and Stripe, for payment integrity and fraud prevention when you make a payment. These operate without consent only where necessary to provide or secure the service.

Preferences and functional. GetClinic preference identifiers for display currency (gc_currency), language (gc_locale) and region (gc_region), retained for up to twelve months; a comparison-list identifier (gc_compare); and an anonymous landing-page attribution identifier (gc_lp_anon). Where applicable law requires consent for a non-essential preference technology, that technology stays disabled until consent is obtained.

Treatment-preference storage. GetClinic may store a treatment-interest preference (gc_treatment_prefs) so you do not have to re-enter it. Because its content can reveal health interest, GetClinic treats it as health-related information under the Patient Privacy Policy and the Consumer Health Data Privacy Policy rather than as an ordinary functional preference.

Analytics and performance. Google Analytics 4, loaded through Google Tag Manager (Google), and Microsoft Clarity (Microsoft), used to understand aggregate usage, navigation and reliability. Google identifiers may persist up to twenty-four months and Microsoft Clarity identifiers up to twelve months. Where applicable law requires prior consent, these technologies are not loaded at all until that consent is obtained; setting a consent signal without withholding the technology is not sufficient.

Error and performance diagnostics. Sentry (Functional Software, Inc.) captures application errors and performance diagnostics so faults can be identified and fixed. It is used for service reliability, not advertising or audience building.

Health surfaces. GetClinic does not load third-party analytics, session-replay or advertising technologies in authenticated medical-document, consultation, private message or other private health-information areas, regardless of consent state. Only necessary security, fraud-prevention and service-delivery technologies operate in those areas.

No health information to analytics or advertising providers. GetClinic does not send treatment or procedure identifiers, clinical questionnaire content, or page addresses that reveal a specific treatment or condition to an analytics or advertising provider. Where a page address would reveal that information, it is generalised or removed before any analytics event is sent.

Advertising. GetClinic does not currently operate third-party advertising or cross-context behavioural advertising technologies on Patient-facing surfaces. If that changes, the technology will be identified in the Cookie Settings inventory and in an updated version of this Policy and will be subject to the consent or opt-out rule that applies.

7. Third-Party Services

Some necessary or optional technologies may be provided by third parties that support hosting, security, analytics, communications, payments or other service functions. A payment service provider may also use its own fraud, authentication or transaction technologies when a payment flow is opened. Those providers may process data under their own legally required notices and terms.

8. Advertising and Cross-Context Tracking

GetClinic does not use Health Data from private medical interactions for targeted advertising. If GetClinic uses advertising or cross-context measurement on public/non-medical surfaces, it will do so only where permitted by applicable law and the user's applicable consent or opt-out state.

Where applicable law requires recognition of a legally valid browser/device opt-out preference signal for sale, sharing or targeted/cross-context advertising, GetClinic will apply that signal to the processing covered by the applicable law and implemented service.

9. Browser and Device Controls

Browsers and devices may allow you to delete or block cookies. Blocking strictly necessary technologies can prevent account login, security controls, payments or other core functionality from working correctly. Browser settings do not always control mobile SDKs or other non-cookie identifiers, so the GetClinic Cookie Settings interface should be used where available.

10. Retention

Cookie and similar-technology retention varies by purpose. Session technologies may expire when a session ends; persistent technologies expire after a defined period or when removed. Specific durations should be shown in the current Cookie Settings / technology inventory where applicable. GetClinic should retain consent/choice records for the period reasonably necessary to demonstrate the applicable user's preference and comply with law.

11. Children and Minors

GetClinic does not use Health Data from minors for targeted advertising. Where a service is used for a Patient who is a minor through an authorized representative, GetClinic applies the applicable privacy and consent rules to cookie/technology use and may disable optional tracking where age or jurisdiction makes consent uncertain.

12. International Users

Cookie and similar-technology rules differ by jurisdiction. GetClinic may present different consent choices, banners, settings or technology availability depending on applicable law, user location and service surface. Nothing in this Policy removes a mandatory privacy or electronic-communications right.

13. Changes to This Policy

GetClinic may update this Policy when technologies, services or legal requirements change. Each version will identify its effective date and version. Where a change requires renewed consent or a new user choice, GetClinic will request it rather than treating continued use or acceptance of contractual terms as consent.

14. Contact

Privacy: [email protected]
Legal: [email protected]
Support: [email protected]
GetClinic, Inc., 74 E Glenwood Ave, Unit #5895, Smyrna, DE 19977, United States.