Legal
Privacy Policy
Last updated: 9 July 2026·Document version: 2026-07-09-v2
PRIVACY POLICY FOR DERMAROUTINE
Last updated: 9 July 2026
Document version: 2026-07-09-v2
Role: Data Fiduciary under India's DPDP Act / Data Controller under the EU/UK GDPR (except where a third party is an independent controller)
Contact / privacy requests / grievance contact: support@dermaroutine.tech
(We aim to resolve data-related grievances within ninety (90) days of receipt, consistent with India’s DPDP Rules, 2025.)
Website: https://dermaroutine.tech
1. INTRODUCTION
DermaRoutine is an iOS application and website that help you understand visible skin characteristics, build educational skincare routines, scan ingredient lists, check product conflicts, and discover product recommendations. Protecting your personal data is central to how we design and operate the Service.
This Privacy Policy is a standalone notice (separate from our Terms of Service). It explains:
• What personal data we collect and why (itemised by category and purpose).
• How we use, store, and protect that data.
• Who we share data with, including third-party AI (Google Gemini), cloud, authentication, email, and waitlist processors.
• How international data transfers work and what safeguards we use.
• Your rights and choices under laws that may apply to you, including:
- India’s Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”);
- the EU General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the UK GDPR;
- California CCPA/CPRA (including 2026 regulatory updates where applicable); and
- Brazil’s LGPD, where applicable.
By using DermaRoutine, you acknowledge the practices described in this Privacy Policy. If you do not agree, please do not use the Service.
This document is a production-oriented privacy notice based on our current product, infrastructure, and publicly available regulatory frameworks as of the last-updated date. It is not a substitute for formal legal advice.
2. DATA WE COLLECT
2.1 Information You Provide Directly
Account information: Email address; authentication method (Sign in with Apple, Google Sign-In, or email and password); Apple user identifier and/or Google subject identifier if applicable. If you use Sign in with Apple and choose to hide your email, Apple may provide a private relay email address. We store password hashes for email accounts; we do not store plaintext passwords.
Profile information: Skin type, skin goals, top concerns, budget range, country/region, sensitivity and allergy preferences, current routine notes, pregnancy-safe preference, cruelty-free preference, and fragrance-free preference.
Photos: Facial photos you capture with the camera or upload from your photo library for analysis and optional progress tracking.
Ingredient and product text: Product names, brands, and ingredient lists you submit for ingredient analysis or product conflict checking.
Communications: Information you provide when contacting support or responding to surveys.
Website waitlist: Email address and referral or promo codes when you join the waitlist on our website.
2.2 Information Generated Through Use of the Service
Skin analysis results: Skin scores, identified concerns, severity or confidence ratings, generated routine steps, and product recommendations.
Routine and check-in data: Saved routines, daily step check-ins, adherence information, and streak data.
Progress photos and reports: Optional progress photos and AI-generated comparison reports.
Ingredient analysis and conflict results: Verdicts, key actives, warnings, usage guidance, and interaction notes returned by our AI features.
Subscription metadata: Subscription status, plan type, trial status, renewal or expiry dates, and transaction identifiers from Apple. We do not collect or store your payment card information.
2.3 Device and App Information
- Device model and iOS version.
- App version and build number.
- Crash logs and performance diagnostics.
- IP address (used for rate limiting, security, and abuse prevention).
- Device identifiers associated with your account for authentication and analytics.
2.4 Analytics and Product Interaction Data
We collect first-party analytics about how you interact with the App, such as:
- Screen views and feature usage.
- Button taps and navigation paths.
- Scan completion events and analysis outcomes.
- Subscription events (start, restore, cancellation).
- Error events and debug logs.
This data is linked to your account identifier where needed so we can understand user journeys and diagnose issues. By default we store analytics in our own backend systems rather than selling data to advertising networks.
2.5 Affiliate Link Activity
When you tap a merchant or affiliate product link, we may log:
- The product and merchant identifier.
- The timestamp of the click.
- Whether a purchase was attributed to the click (where the merchant or network shares this information).
We do not receive your payment or shipping information from merchants.
3. HOW WE USE YOUR DATA
We use your personal data only for the following purposes:
- To create, secure, and authenticate your account (including Sign in with Apple, Google Sign-In, and email/password).
- To analyze your facial photo and generate educational skincare insights.
- To build and display your personalized skincare routine and track adherence.
- To analyze ingredient lists and check product conflicts you request.
- To recommend products matched to your skin profile, budget, country, and preferences.
- To process and verify subscriptions through Apple’s App Store.
- To send optional notifications and reminders (only if you opt in).
- To send transactional emails (for example password reset and waitlist confirmation).
- To operate the website waitlist and referral features.
- To communicate with you about your account, support requests, or legal matters.
- To improve app performance, stability, security, and recommendation quality.
- To detect and prevent fraud, abuse, and unauthorized access.
- To comply with legal obligations and respond to lawful requests.
We do not use your facial photos or skin information for targeted advertising. We do not sell your personal information.
4. LEGAL BASIS FOR PROCESSING
4.1 India DPDP Act and DPDP Rules, 2025 — Notice and Consent
If you are in India (or otherwise protected as a Data Principal under the DPDP Act), the following applies:
Who we are: We act as a Data Fiduciary for personal data we determine the purpose and means of processing.
Notice (aligned with DPDP Rules notice standards): Before or at the time we request consent, we provide this Privacy Policy and in-app notices that, in plain language, describe:
- the personal data categories we process (see Section 2);
- the specified purposes and the goods/services those purposes enable (skin analysis, routines, ingredient tools, recommendations, account, security, support);
- how you may withdraw consent, exercise rights, raise a grievance with us, and complain to the Data Protection Board of India.
Consent: Where we rely on consent, it must be free, specific, informed, unconditional, and given through clear affirmative action (for example, accepting photo-analysis consent in the App). Consent for one purpose is not used as blanket consent for unrelated purposes.
Withdrawal: You may withdraw consent at any time in Profile → Privacy Controls, with the same ease with which it was given. Withdrawal does not affect the lawfulness of processing before withdrawal. Withdrawing photo-analysis consent stops new AI analysis of your photos; withdrawing storage consent may require deletion of stored profile and scan data.
Contact for rights and grievances: support@dermaroutine.tech. We aim to complete grievance redressal within ninety (90) days. You may also approach the Data Protection Board of India where available under applicable law.
4.2 Consent (App Features and Third-Party AI)
We rely on your explicit consent for:
- Photo analysis and progress photo analysis.
- Storage of profile, scan, and related data as described in the App.
- Marketing communications and optional notifications.
- Sharing facial photos, ingredient text, and related context with our third-party AI provider (Google Gemini) before any such transmission occurs (consistent with Apple App Store privacy expectations for third-party AI sharing).
- Other processing where consent is the appropriate lawful basis under applicable law.
You provide this consent through the App’s onboarding and Privacy Controls. You may withdraw consent at any time through Profile → Privacy Controls or by deleting your account. If you decline third-party AI sharing, AI-powered analysis features will not run.
4.3 Contractual Necessity
We process certain data, such as account and profile information, to perform our contract with you and provide the Service.
4.4 Legitimate Interests
We process data for security, fraud prevention, service improvement, first-party analytics, and legal compliance where these interests are not overridden by your rights.
4.5 Legal Obligation
We may process data to comply with applicable laws, regulations, court orders, or lawful requests from public authorities.
4.6 EU/UK GDPR Lawful Bases and Special Category Data
If the EU GDPR (Regulation (EU) 2016/679) or UK GDPR applies:
- We process personal data under Article 6 on the bases of consent, contract, legitimate interests, and legal obligation as described above.
- Facial photographs used for skin analysis and certain self-reported skin or health-adjacent information may be treated as special-category data under Article 9. Where Article 9 applies, we rely primarily on your explicit consent (Article 9(2)(a)) for analysis and related processing.
- You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
5. AI PROCESSING AND THIRD-PARTY SHARING
5.1 AI Analysis Provider (Google Gemini) — Third-Party AI Disclosure
Who receives data: Google (Google Gemini / Gemini API infrastructure).
Why: To generate educational skin analysis, routines, ingredient analysis, conflict checks, and related recommendations you request.
What is sent: Facial photos (for scan/progress features); optional free-text context about concerns, goals, and preferences; product names, brands, and ingredient lists you submit; and a temporary or pseudonymous identifier that does not directly reveal your email or name where feasible.
When: Only after you give explicit in-app permission for photo analysis / related AI processing. If you refuse or later withdraw consent, we do not send new content for those AI features.
What the provider does:
- Generates analysis, guidance, or structured results.
- Returns results to our backend for display in the App.
Safeguards and training (aligned with current Gemini API / processor practices for paid API use):
- We require contractual and technical safeguards with processors that handle personal data on our behalf (including data-processing terms where required by law, such as Google’s processor terms for paid Gemini API services).
- For paid Gemini API use, Google’s published terms state that Google does not use your prompts (including images and files) or responses to improve Google products, and processes them as a processor under applicable Google data-processing terms. Google may still log prompts/responses for a limited period solely for abuse/safety monitoring (public documentation commonly describes a limited abuse-monitoring window for API traffic). We do not control Google’s internal security logging beyond contractual and product settings available to us.
- We do not use your facial photos, skin information, ingredient submissions, or AI-generated results to train, develop, fine-tune, evaluate, or improve third-party or our own AI/ML models unless you separately and explicitly opt in.
- Zero-data-retention (ZDR) or equivalent enterprise options, if enabled for our project, further limit provider-side retention; availability depends on Google product eligibility and configuration.
5.2 Cloud Infrastructure (Cloudflare)
We use Cloudflare for hosting, serverless computing (Workers), database storage (D1), object storage (R2), key-value caching (KV), and related infrastructure. Your data is stored and processed on Cloudflare’s infrastructure under applicable processor terms and safeguards.
5.3 Apple Inc.
We share limited data with Apple for:
- App Store payments and subscription verification.
- Sign in with Apple authentication.
- Transaction processing and refunds.
5.4 Google Sign-In
If you choose Google Sign-In, Google authenticates you and provides us with limited account identifiers (such as a Google subject identifier and email, subject to your Google account settings). Google processes authentication data under its own terms and privacy policy.
5.5 Email Delivery (Resend)
We use Resend to send transactional emails, such as password-reset messages and waitlist confirmation emails. Resend processes the recipient email address and message content as a processor on our behalf.
5.6 Website Waitlist Storage (Supabase)
Waitlist submissions on our website may be stored using Supabase. Supabase processes waitlist email and referral-related fields as a processor for that purpose.
5.7 Analytics and Crash Reporting
We primarily use first-party analytics stored in our backend. We may use third-party crash or diagnostics services in the future. Those providers would receive pseudonymous or aggregated data where possible. We do not share your facial photos or raw health-adjacent profile content with advertising analytics providers.
5.8 Affiliate Merchant Partners
When you tap a merchant or affiliate link, you are redirected to the merchant’s website or app. The merchant may collect data according to its own privacy policy. We may share click attribution data with affiliate networks where necessary to track commissions.
5.9 Law Enforcement and Legal Requests
We may disclose personal data if required to do so by law or if we believe in good faith that such disclosure is necessary to:
- Comply with a legal obligation or court order.
- Protect our rights, property, or safety, or that of our users or the public.
- Detect, prevent, or address fraud, security, or technical issues.
5.10 Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your data may be transferred as part of that transaction. We will notify you of any such change in control where required.
6. INTERNATIONAL DATA TRANSFERS
Your data may be processed on servers and infrastructure located in various jurisdictions, including:
- Cloudflare’s global network.
- Google’s AI and authentication infrastructure (which may include processing outside India and the EEA).
- Apple’s systems for authentication and payments.
- Resend and Supabase infrastructure used for email and waitlist features.
This means personal data may be transferred to, stored in, or accessed from countries other than your country of residence, including countries that may not provide the same level of data protection as your home jurisdiction.
6.1 Safeguards We Use (EU/UK and other restricted transfers)
Where the GDPR or UK GDPR requires a transfer tool for restricted international transfers, we rely on one or more of the following current mechanisms—not repealed legacy SCC decisions:
- EU Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (modern SCCs under the GDPR). These replace older Commission SCC sets adopted under Directive 95/46/EC.
- UK International Data Transfer Agreement (IDTA) and/or the UK Addendum to the EU SCCs, as appropriate for UK GDPR restricted transfers.
- Adequacy decisions of the European Commission or UK government where they apply to a destination.
- EU–U.S. Data Privacy Framework (DPF) (and UK Extension where applicable) only where a U.S. recipient is actively certified under the Framework and the transfer is covered by that certification. Major providers such as Google and Cloudflare publicly participate in the DPF; certification status can change, so we do not rely on DPF alone as our only safeguard.
- Processor / data-processing terms (for example Article 28 GDPR-style processor terms) with vendors that process personal data on our instructions.
- Technical and organizational measures, including encryption in transit (TLS), access controls, least-privilege design, and minimization of identifiers sent to AI providers.
6.2 Transfer impact assessments (Schrems II / modern SCCs)
Where required by the 2021 SCCs and EU case law (including the CJEU’s *Schrems II* judgment), parties to SCCs are expected to assess the circumstances of the transfer, relevant laws in the destination country, and any supplementary measures. We take a risk-based approach to documenting transfers of personal data (including facial photos and profile context sent for AI analysis) and to applying appropriate safeguards. You may request a high-level summary of our transfer approach at support@dermaroutine.tech.
6.3 India DPDP cross-border transfers (blacklist / restriction model)
Under the DPDP Act and DPDP Rules, personal data processed by a Data Fiduciary may generally be transferred outside India, subject to any restrictions the Central Government notifies regarding particular countries, territories, or making personal data available to a foreign State or its agencies. This is commonly described as a permissive / negative-list model (transfer allowed unless restricted), not an EU-style pre-approval adequacy list for every destination. We will comply with any such notified restrictions and with other Indian laws that may impose sector-specific localization rules.
6.4 Requests for transfer details
You may contact support@dermaroutine.tech to request additional information about international transfers and the safeguards that apply to your situation.
7. DATA RETENTION
We retain your personal data for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
Data type — Retention period
Facial scan photos — Retained while your account is active and photo-analysis consent is enabled. Deleted upon account deletion or explicit photo-deletion request.
Progress photos — Retained while your account is active and until you delete them or delete your account.
Profile, scan results, ingredient/conflict results — Retained while your account is active.
Routine and check-in data — Retained while your account is active.
Consent logs — Retained for the life of your account plus sixty (60) days to demonstrate compliance.
Analytics and diagnostics — Retained for up to twenty-four (24) months, after which it is aggregated or deleted.
Subscription metadata — Retained as long as required by tax, accounting, and App Store policies.
Waitlist email data — Retained until the waitlist program ends, you request deletion, or we no longer need it for that purpose.
Deleted account data — Permanently erased within ninety (90) days of deletion, except where legal obligations require longer retention.
We may retain certain data in backups for a limited period after deletion. Such data will be isolated and removed in accordance with our backup retention schedule.
8. YOUR RIGHTS AND CHOICES
Depending on applicable law, you may have the following rights:
8.1 Access
You can request a copy of the personal data we hold about you. The App provides an “Export My Data” feature in Profile settings where available.
8.2 Correction
You can update your profile information at any time within the App.
8.3 Deletion
You can delete your account and associated data at any time from Profile → Delete Account. Deletion initiates permanent erasure of your profile, scans, progress photos, reports, routines, and check-ins, subject to legal retention requirements.
8.4 Data Portability
You can export your data in a structured, commonly used format using the in-app export feature where available.
8.5 Withdraw Consent
You can withdraw consent for photo analysis, data storage, and marketing communications through Profile → Privacy Controls. Withdrawing photo-analysis consent will prevent new scans. Withdrawing data-storage consent may require deletion of stored profile and scan data.
8.6 Object to Processing / Restrict Processing
Where applicable law provides these rights (including under the GDPR/UK GDPR), you may object to processing based on legitimate interests or request restriction of processing by contacting us.
8.7 Lodge a Complaint
If you believe we have violated your data protection rights, you may lodge a complaint with the relevant supervisory authority or contact us at support@dermaroutine.tech.
8.8 India DPDP Act Rights
If you are in India, you have the right to:
- Access and obtain a summary of your personal data and processing.
- Request correction and erasure of your personal data.
- Nominate another individual to exercise your rights in case of your death or incapacity.
- Raise a grievance with us (we aim to resolve within 90 days) and, where applicable, complain to the Data Protection Board of India.
- Withdraw consent as easily as it was given.
8.9 EU/UK Rights Summary
If you are in the EU, EEA, or UK, you may also have rights to access, rectification, erasure, restriction, portability, objection, and withdrawal of consent, and the right to lodge a complaint with your local supervisory authority. We act as the data controller for personal data collected through the App and website (except where a third party acts as an independent controller, such as Apple or Google for their own authentication or payment systems).
8.10 How to Exercise Rights
Contact support@dermaroutine.tech. We will make reasonable efforts to respond within applicable legal timeframes (including the DPDP Rules grievance window noted above and GDPR timelines where they apply).
9. SECURITY
We implement industry-standard technical and organizational measures to protect your data, including:
- Encryption in transit using HTTPS/TLS.
- Encrypted or access-controlled storage for photos and personal data.
- Secure authentication tokens stored in the device Keychain.
- Access controls and audit logging on backend systems.
- Rate limiting and abuse detection.
- Regular security reviews and vulnerability management.
No online service is completely secure. If you believe your account has been compromised, contact us immediately at support@dermaroutine.tech.
10. PERSONAL DATA BREACH NOTIFICATION
If we become aware of a personal data breach, we will take appropriate steps to contain, investigate, and remediate the incident. Where required by law:
- India (DPDP Rules): we will intimate affected Data Principals and the Data Protection Board of India in the manner prescribed, including a detailed intimation to the Board within seventy-two (72) hours of becoming aware of the breach (or such longer period as the Board may allow). Separate Indian cybersecurity rules (for example CERT-In directions) may impose shorter timelines for certain security incidents.
- EU/UK GDPR: we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms; we will also notify affected individuals without undue delay when required.
- Other jurisdictions: we will comply with applicable breach-notification laws.
Contact support@dermaroutine.tech if you have reason to believe your data may have been compromised through the Service.
11. CHILDREN’S PRIVACY
DermaRoutine is not intended for users under the age of 13. We do not knowingly collect personal data from children under 13 without verifiable parental consent.
If we learn that a child under 13 has provided personal data without parental consent, we will delete that information promptly. If you believe we may have collected data from a child under 13, please contact us at support@dermaroutine.tech.
12. COOKIES AND SIMILAR TECHNOLOGIES
The mobile App does not use traditional browser cookies. We may use local storage, Keychain, and device identifiers for authentication, preferences, and analytics.
Our website may use essential cookies or similar technologies required to operate the site and waitlist forms (for example session or security-related storage). We do not currently use non-essential advertising cookies on the website. If we introduce non-essential analytics or marketing cookies later, we will update this policy and, where required, provide additional notice or consent tools.
13. AUTOMATED DECISION-MAKING AND PROFILING
The Service uses automated systems, including AI models, to analyze your photo, profile information, and ingredient or product inputs and generate recommendations. These outputs are educational and informational only. You are not solely subject to a decision that produces legal or similarly significant effects based solely on automated processing.
You may contest or disregard any AI-generated recommendation and should consult a qualified professional for personalized medical or dermatological advice.
14. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. We will notify you of material changes through the App or by email. The “Last updated” date and document version at the top of this page reflect the most recent revision.
When we publish a new document version, the App may require you to re-acknowledge the Privacy Policy and Terms of Service before continuing.
Your continued use of the Service after the updated Privacy Policy takes effect constitutes your acceptance of the changes, to the extent permitted by law.
15. CALIFORNIA CONSUMER PRIVACY ACT (CCPA/CPRA) NOTICE
If you are a California resident and the CCPA/CPRA applies to us, the following additional disclosures apply (including concepts reflected in California’s 2026 privacy regulation updates where relevant):
Categories of personal information collected: Identifiers; commercial information; internet or other electronic network activity information; biometric-adjacent information (facial photos used for analysis—not used by us as a general facial-recognition identity system); sensory data (photos); inferences drawn from the above; and, where we have actual knowledge a consumer is under 16, personal information of that consumer may itself be treated as sensitive personal information under updated California rules.
Sensitive personal information we may process: health-related information you provide about skin concerns/sensitivities; photographs used for analysis; and account login credentials. We do not intentionally collect neural data.
Business or commercial purposes: Providing the Service; processing subscriptions; analytics; security; fraud prevention; and affiliate attribution.
Categories of third parties: AI analysis providers (Google Gemini); cloud infrastructure providers (Cloudflare); Apple; Google (authentication and AI); email delivery providers (Resend); waitlist storage providers (Supabase); analytics providers; and affiliate merchant partners.
Sale / share: We do not sell personal information. We do not share personal information for cross-context behavioral advertising as those terms are commonly understood under the CPRA. We do not use sensitive personal information to infer characteristics for advertising.
Automated decision-making / profiling: We use automated AI tools to generate educational skin insights and recommendations. These are not used to make legal or similarly significant decisions about you (such as credit, employment, housing, or insurance).
Your California rights: You have the right to know/access (including beyond a trailing 12-month window where required), delete, correct, opt out of sale/sharing, limit the use of sensitive personal information, and non-discrimination for exercising your rights.
Limit the Use of My Sensitive Personal Information: We collect and use sensitive personal information only to provide the Service (skin analysis, routines, ingredient/conflict tools, and recommendations) and to maintain security and fraud prevention—purposes reasonably expected by consumers of a skincare analysis app. To submit a Limit request, contact support@dermaroutine.tech (or use any dedicated Limit control we publish on https://dermaroutine.tech). We will provide confirmation that a Limit request has been processed where required.
Risk assessments: Where California law requires risk assessments for high-risk processing of sensitive personal information or certain automated decision-making technology, we will document and maintain those assessments as applicable to our operations.
To exercise any of your CCPA/CPRA rights, contact us at support@dermaroutine.tech. We will verify requests as permitted by law.
16. EUROPEAN UNION / UK / EEA NOTICE
If you are located in the European Union, European Economic Area, or the United Kingdom, the following applies:
- Controller: DermaRoutine is the data controller for personal data collected through the App and website (subject to independent-controller roles of Apple, Google, or merchants for their own services).
- Lawful bases: Article 6 GDPR/UK GDPR (consent, contract, legitimate interests, legal obligation) and, where special-category data is processed for analysis, Article 9(2)(a) explicit consent.
- Rights: as described in Section 8, including access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to your local supervisory authority (or the ICO in the UK).
- International transfers: Article 46 GDPR appropriate safeguards, primarily the 2021 EU SCCs (Decision (EU) 2021/914) and, for the UK, the IDTA or UK Addendum, plus supplementary measures and transfer assessments as described in Section 6. Where a U.S. recipient is certified under the EU–U.S. Data Privacy Framework, that may also support the transfer; we do not treat DPF as the sole safeguard.
- EU representative (Article 27): We have not appointed a separate EU Article 27 representative at this time; contact support@dermaroutine.tech.
- Automated decision-making: AI outputs are educational; you are not subject to solely automated decisions with legal or similarly significant effects.
17. BRAZIL LGPD NOTICE
If you are in Brazil, Lei Geral de Proteção de Dados (LGPD) may apply. Facial images and health-related information can constitute sensitive personal data (including biometric data under Brazilian law where applicable). We generally rely on your specific consent for processing sensitive data for skin analysis and related features, and we process data to provide the Service you request.
You have rights under the LGPD, including confirmation of processing, access, correction, anonymization, portability, deletion, information about sharing, and withdrawal of consent. Contact support@dermaroutine.tech to exercise these rights. You may also contact Brazil’s Autoridade Nacional de Proteção de Dados (ANPD).
18. CONTACT US
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:
Email: support@dermaroutine.tech
We will make reasonable efforts to respond to your inquiry within a reasonable timeframe and within any period required by applicable law.
BY USING DERMAROUTINE, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO THE PRACTICES DESCRIBED IN THIS PRIVACY POLICY.