RAYA HEALTH PRIVACY POLICY

Last Updated: January 2025

Introduction

Raya Health, Inc. ("Raya Health," "we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you use our AI-powered maternal healthcare platform, mobile applications, website, and related services (collectively, the "Platform").

Raya Health provides services that connect patients with doulas through partnerships with health plans and insurance providers. By accessing or using our Platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

HIPAA Notice and Protected Health Information

Raya Health operates as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"). When we receive Protected Health Information ("PHI") from or on behalf of health plans and covered entities, we comply with HIPAA Privacy and Security Rules.

Your HIPAA Rights

As a patient, you have certain rights regarding your PHI:
  • Right to access and obtain a copy of your health records
  • Right to request amendments to your health information
  • Right to an accounting of disclosures of your PHI
  • Right to request restrictions on certain uses and disclosures
  • Right to receive confidential communications

Information We Collect

Information You Provide

  • Account Information: Name, email address, phone number, date of birth, mailing address, and account credentials
  • Health Information: Medical history, pregnancy status, due date, health conditions, medications, healthcare provider information, and other health-related data you share with us or your doula
  • Insurance Information: Health plan name, member ID, group number, and eligibility information
  • Communication Preferences: Your preferences for receiving notifications via email, SMS/text message, or other channels
  • Feedback and Correspondence: Information you provide when contacting us, completing surveys, or providing feedback

Information from Health Plans and Partners

We receive information from health plans and insurance providers, including member eligibility data, coverage information, and referral details necessary to provide and coordinate doula services.

Information Collected Automatically

  • Device Information: Device type, operating system, browser type, and unique device identifiers
  • Usage Data: Pages viewed, features used, session duration, and interaction patterns
  • Location Information: General geographic location based on IP address to match you with local doulas
  • Cookies and Tracking Technologies: We use cookies, web beacons, and similar technologies as described in our Cookie Policy

How We Use Your Information

We use the information we collect for the following purposes:
  • Service Delivery: To match you with appropriate doulas, coordinate care, facilitate appointments, and provide our maternal healthcare services
  • AI-Powered Matching: Our platform uses artificial intelligence to analyze your preferences, needs, and location to recommend suitable doulas
  • Communications: To send appointment reminders, health tips, service updates, and respond to your inquiries via email and text message
  • Insurance Coordination: To verify eligibility, process claims, and coordinate benefits with your health plan
  • Platform Improvement: To analyze usage patterns, improve our services, and develop new features
  • Compliance: To comply with legal obligations, enforce our terms, and protect rights and safety
  • Quality Assurance: To monitor service quality and support doula training and improvement

Email and Text Message Notifications

Types of Communications

We may send you the following types of communications
  • Transactional Messages: Appointment confirmations, reminders, cancellations, and scheduling updates
  • Service Messages: Care coordination updates, doula introductions, and visit summaries
  • Health Information: Pregnancy tips, wellness resources, and educational content
  • Account Notifications: Security alerts, policy updates, and account-related information
  • Promotional Messages: Information about additional services, surveys, and feedback requests (with your consent)

Text Message (SMS) Terms

By providing your mobile phone number and opting in to receive text messages, you consent to receive SMS messages from Raya Health. Message frequency varies. Message and data rates may apply. You can opt out at any time by replying STOP to any message or by updating your communication preferences in your account settings. Reply HELP for assistance.

Managing Your Preferences

You can manage your communication preferences at any time through your account settings, by clicking "unsubscribe" in any email, by replying STOP to text messages, or by contacting us at privacy@rayahealth.com. Please note that even if you opt out of promotional communications, we may still send you transactional messages related to your care and account.

How We Share Your Information

We may share your information with the following parties:
  • Doulas and Healthcare Providers: To coordinate and deliver care services
  • Health Plans and Insurance Partners: To verify eligibility, process claims, and coordinate benefits
  • Service Providers: Third-party vendors who assist with platform operations, including cloud hosting, communication services, and analytics (all bound by confidentiality obligations)
  • Legal Requirements: When required by law, court order, or to protect our rights and safety
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
We do not sell your personal information to third parties for marketing purposes.

Data Security

We implement administrative, technical, and physical safeguards designed to protect your information, including encryption of data in transit and at rest, access controls and authentication measures, regular security assessments and monitoring, employee training on privacy and security practices, and secure data centers with appropriate certifications. While we strive to protect your information, no method of transmission or storage is completely secure. We cannot guarantee absolute security.

Data Retention

We retain your information for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. Health records are retained in accordance with applicable state and federal requirements. When information is no longer needed, we securely delete or anonymize it.

Your Rights and Choices

Depending on your location, you may have the following rights:
  • Access and obtain a copy of your personal information
  • Correct inaccurate or incomplete information
  • Request deletion of your information (subject to legal retention requirements)
  • Object to or restrict certain processing activities
  • Data portability
  • Withdraw consent where processing is based on consent
To exercise these rights, contact us at privacy@rayahealth.com. We will respond to your request within the timeframe required by applicable law.

California Privacy Rights

California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know what personal information we collect and how it is used, the right to delete personal information, the right to opt out of the sale or sharing of personal information, and the right to non-discrimination for exercising privacy rights. To exercise these rights, contact us at privacy@rayahealth.com or call (415) 295-2759.

Children's Privacy

Our Platform is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If we learn that we have collected information from a child under 13, we will promptly delete it. If you believe we have collected information from a child under 13, please contact us immediately.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our Platform, updating the "Last Updated" date, and sending you an email or other notification as required by law. Your continued use of the Platform after changes become effective constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:
Raya Health, Inc.
Email: privacy@rayahealth.com
Phone: (415) 295-2759
Address: 1395 22nd Street, Suite 424, San Francisco, CA 94107
For HIPAA-related inquiries, please contact our Privacy Officer at hipaa@rayahealth.com.