Privacy Policy

Effective January 1, 2020

The Vitality Group, LLC (“Vitality”; “We”; “Us”; “Our”) owns and operates the websites VitalityGroup.com; and PowerofVitality.com (“POV”) (“Websites”); and the mobile applications Vitality Today and Vitality One (“Applications”), which may be referred to collectively as the “Program(s).” Vitality’s Programs are made available to individuals through either your employer; your spouse’s employer; or another provider (“Program Provider”). This Privacy Policy applies to Personal Information (defined below) collected by Vitality whether online or offline.

This Privacy Policy will address the following:

From who or where does Vitality collect Personal Information about me?
What type of information does Vitality collect about me?
How does Vitality use Personal Information it collects about me?
How is Vitality protecting my Personal Information?
Who can access my Personal Information at Vitality?
Outside of Vitality, with whom would Vitality share my Personal Information?
Do Vitality’s Websites or Applications contain links to third-party websites or apps?
Does Vitality sell my Personal Information?
What are cookies and does Vitality use them?
How will I know if this Privacy Notice changes?
Will Vitality communicate directly with me?
I am a California resident; how can I exercise my rights under California law?
Does Vitality comply with the EU-US Privacy Shield Framework?
How can I contact Vitality with any privacy concerns or inquiries I have?

From who or where does Vitality collect Personal Information about me?

  • From your Program Provider: As part of your eligibility for the Program, your Program Provider will provide Vitality the information necessary to verify your identity when you register for the Program and to manage your account on an ongoing basis. If you do not want Vitality to receive this information, please contact your Program Provider and ask them to stop sending Vitality any information about you. Please note that this will make you ineligible to participate in the Program.
  • Directly from You, including from your devices: Throughout your engagement with the Program information linked to you and your interactions with the Program, for example your physical activity, reward earning events and redemption, and form submission, will be collected or created by Vitality. You can also choose to allow certain devices and mobile applications to sync data to a Vitality Applications you use. You can modify these permissions at any time through the settings menu of the applicable application.
  • From authorized third-parties on behalf of you or your Program Provider: When you or your Program Provider has authorized it, Vitality may receive information about your participation with third-party service providers.

Additionally, if you engage with Vitality on a social media platform Vitality may respond or contact you through the applicable social media platform.

What type of information does Vitality collect about me?

For the purposes of this Privacy Policy, Vitality’s definition of Personal information is information that can be used to identify a particular individual. Note that certain information may not be Personal Information until it is combined with other identifying information, for as long as this information is combined Vitality will treat it as Personal Information. The following is a list of the types information that Vitality may collect through its Program(s), please note that the types of information collected about you will depend on the particular Program you are using and the activities in which you participate.

  • ­Name
  • ­Gender
  • Address
  • Contact details
  • Date of birth
  • Joining date
  • Reporting classifications (e.g. at which branch you are employed)
  • A unique ID (e.g. your employee ID or SSN)
  • Dependents / Spouse / Partner (if applicable)
  • Eligibility start and end date data (if relevant)
  • Cookies
  • Log data including IP address
  • Answers to questionnaires about your health and wellbeing
  • Program engagement information
  • Survey responses; commentary; or feedback you give on POV or Vitality Applications; or otherwise provide to Vitality
  • Reward partner engagement if authorized
  • Devices information such as the type of device; operating system; data that you have synched, which may include health and fitness related information and location data if you have consented to this data synching
  • Details of rewards you’ve earned and your reward redemptions
  • Financial information such as transactions and payment details
  • Health information including biometrics and medical conditions
  • Additional information provided by you through online form submission or by otherwise contacting Vitality

How does Vitality use Personal Information it collects about me?

  • To administer and manage your account
    • Creating and maintaining your profile
    • Generating goals, activities and/or targets
    • Recommending activities and engagements
    • Applying rewards earned
    • Making Program features available to you
    • Fulfilling purchase orders you make through the Program
    • Tracking your progress through the Program
  • To resolve any complaints or inquiries you may have
    • ­Registering complaints and inquiries
    • ­ Managing and resolving complaints and inquiries
  • For management of any debts owed to Vitality, if applicable
    • ­­Tracking and administration of payment installments (if any)
    • ­­Recovery of unpaid debts or reimbursement of damages under a contract
  • To prevent, detect and investigate fraud or security incidents
    • ­Investigating suspicions of fraud
    • ­Prosecuting fraud
    • ­Investigating security incidents
  • For company and management information purposes and internal analysis of products and services
    • ­Accounting and financial records, analysis and reporting
    • ­Audit requirements
    • ­System security and effective operation
    • ­Program quality assessments; improvements; and developments
    • ­
  • For training purposes to improve your customer experience
    • ­­Assessing customer experiences
    • ­­Developing and improving our customer experience
  • To fulfill legal obligations
    • ­­Reporting necessary information to your Program Provider for benefit administration
    • ­­Complying with any applicable law, regulation, subpoena or legal process, or responding to any governmental requests and cooperate with law enforcement, if we believe such action is required or permitted by law
    • ­Enforce our Terms and Conditions
  • Creating De-Identified or Aggregated Data Sets
    • ­­De-identified data sets are data sets that contain member-level information, but without any identifiers that can be used to link the information back to a particular individual
    • ­­Aggregated data sets are data sets that contain only aggregated information which cannot be decompiled to identify any individual whose data may be included
    • ­De-identified and Aggregated Data Sets are not Personal Information, and subject to any applicable laws or other restrictions, Vitality may use and disclose De-identified and Aggregated data sets for any purpose

Vitality may also seek to use your Personal Information in a way not described above, such as in using a testimonial you have written on our website or marketing materials. Before using your Personal Information in this way, Vitality will first seek your voluntary and explicit consent.

How is Vitality protecting my Personal Information?

Personal Information that you share on the website is kept strictly confidential and fully secure. Your encrypted (encoded) Personal Information is protected using "Secure Socket Layers (SSL)" as it passes between your browser and this website. We follow generally accepted industry standards to protect the Personal Information submitted to us, both during transmission and once we receive it.

No method of transmission over the Internet, or method of electronic storage, is 100% secure, however. Therefore, while we strive to use commercially acceptable means to protect your Personal Information, we cannot guarantee its absolute security.

Who can access my Personal Information at Vitality?

Your Personal Information is accessible by Vitality employees, including employees of Vitality affiliates, only on a need to know basis for the provision of services and support. Only such authorized persons are permitted to access your Personal Information. All authorized persons must abide by security, privacy, and confidentiality agreements, rules and laws.

Outside of Vitality, with whom would Vitality share my Personal Information?

Your Program Provider: Vitality may share with your plan sponsor offering Vitality the minimum necessary information for them to administer your incentives. Vitality will share information only to the extent needed for administration of your incentives, such as calculation of health plan premium discounts, health club dues subsidies, applicable taxation, reward redemption, or other arrangements for which such information is relevant

Your Program Provider’s authorized Third-Party Wellness Service Providers: Your Program Provider may make additional incentives available to you that are provided by Third-Party Wellness Service Providers. In order to administer this benefit, your Program Provider may authorize Vitality to share your information to the extent necessary for the third-party service provider to make its offering available to you.

Service Providers of Vitality: There are instances in which Vitality may disclose your Personal Information to our agents, third-party partners, affiliates and subsidiaries to enable them to perform functions on our behalf. These service providers are only permitted to share, store and/or use Personal Information for contracted business purposes.

Additionally, We may share your Personal Information when we believe that such action is necessary to:

  • Fulfill an enforceable government request
  • Conform with the requirements of the law or legal process
  • Protect or defend Our legal rights or property, Our Websites or Applications, or other users; or
  • Protect your health and safety or the health and safety of this website's users or the general public

With your express authorization and consent, We may share your Personal Information for a specific purpose not provided above. Agreeing to these terms and conditions is not your express authorization. When appropriate, while you are logged into the POV or a Vitality Application, you will be presented with a specific electronic authorization form on which you may or may not provide your consent. You may revoke such authorization at any time by navigating to your My Accounts page within the Power of Vitality website.

Do Vitality’s Websites or Applications contain links to third-party websites or apps?

Vitality’s Power of Vitality portal and its mobile applications, Vitality Today and Vitality One, may contain links to other websites that are not owned or controlled by Us. We provide these links to other websites or mobile applications for your convenience in participating in If you choose to submit Personal Information while visiting these websites or using these mobile applications, please be aware your rights will be governed by the third parties’ privacy policies. We strongly encourage you to carefully read the privacy notice of any website or mobile application you visit or use.

Does Vitality sell my Personal Information?

No. Vitality will never sell, rent, or lease your Personal Information.

What are cookies and does Vitality use them?

A cookie is a file containing an identifier that is automatically sent by Us to your browser or mobile device is stored by the browser or mobile device. The identifier is then sent back to the server each time the browser or device requests a page from the server. This information might be about you, your preferences or your device and is mostly used to make the Website or Application work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized experience.

Cookies may be either "persistent" cookies or "session" cookies: a persistent cookie will be stored by a web browser and will remain valid until its set expiry date, unless deleted by the user before the expiry date; a session cookie, on the other hand, will expire at the end of the user session, when the web browser is closed.

Cookies do not typically contain any information that personally identifies a user, but personal information that we store about you may be linked to the information stored in and obtained from cookies.

Vitality uses different categories of cookies for certain purposes:

  • trictly Necessary: These cookies are necessary for the Website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.
  • Performance: These cookies allow Us to count visits and traffic sources so We can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how users move around the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies We will not know when you have visited Our Website, and will not be able to monitor its performance.
  • Functional: These cookies enable the Website to provide enhanced functionality and personalization. If you do not allow these cookies then some or all of these services may not function properly.
  • Cookies used by our third-party service providers: We use Google Analytics to analyze the use of Our Websites. The information gathered relating to Our Website is used to create reports about the use of Our Websites. Additionally, We use MaxMind to assist in determining from where Our Program is being accessed.

You can find more information about cookies at www.allaboutcookies.org, including how to disable certain cookies. If you use different computers or devices to access the Websites you will need to ensure that each browser is adjusted to suit your cookie preferences. If you restrict Our Websites and Applications from setting cookies, you may worsen your overall user experience and/or lose the ability to access the Programs and may also stop you from saving customized settings.

How will I know if this Privacy Notice changes?

Vitality reserves the right to update this privacy notice from time to time. If we decide to change this website's privacy policy, we will post those changes to this Privacy Notice, the home page, and other places that we deem appropriate so that you are aware of what information is being collected, how the information is being used, and under what circumstances, if any, the information may be disclosed.

Will Vitality communicate directly with me?

As a Vitality member, We will aim to provide you with a fully invested experience and dedication to your wellness journey. Depending on your particular Program, We will deliver marketing, status updates, or other informational emails to you via the email address you provide on your My Account page. If you choose, you may opt-out of receiving these emails at any time by adjusting the settings on your account on the POV or the Application you use. . If you use a Vitality Application, push notifications and triggered communication may be sent to you through the App. These notifications can be turned off at any time by adjusting the application’s settings on your device.

Of course, certain communications are necessary and cannot be turned off. Such communications include; transactional emails, such as order confirmations, emails relating to payment processing activities, and reward redemptions; communications from our Customer Care team in response to contacts initiated by you; or other important updates like security and fraud notices or change in services.

If you send questions or comments to an email address listed within a Program or via a contact form provided within a Program, We will share your correspondence with a Vitality associate most capable of addressing your questions and concerns. We will retain your communications until we have done our very best to provide you with a complete and satisfactory response. Ultimately, We will either discard your communication or, in some cases, archive it. We will not keep your email address for secondary purposes. All information and correspondence you share with us will be handled in the strictest confidence.

We may agree that email has become a standard communication tool used by many different parties. Unfortunately, by design standard Internet email is not secure. For that reason, please do not use unsecured email to communicate information to us that you may consider to be confidential.

I am a California resident; how can I exercise my rights under California law?

Under California Civil Code Section 1798.83 California residents have the right to request from companies conducting business in California a list of all third parties to which the company has disclosed certain personally identifiable information as defined under California law during the preceding year for third party direct marketing purposes. You are limited to one request per calendar year. Note that Vitality does not disclose any Personal Information to third-parties for their direct marketing purposes.

Under the California Consumer Privacy Act (“CCPA”), if you are a California Consumer, or an authorized representative of a California Consumer, as defined by the CCPA, you have the following rights regarding your Personal Information collected during the 12 months before your request:

  • The right to request disclosure of the categories and specific pieces of Personal Information collected about you.
  • The right to request deletion any Personal Information collected about you.
  • The right to request disclosure of the categories of sources from which your Personal Information is collected.
  • The right to request disclosure of the business or commercial purpose for collecting or selling your Personal Information. Note that We do not sell Personal Information We collect about you; however third-party cookies are used as described above. If you do not wish to permit such cookies, please visit http://optout.aboutads.info/
  • The right to request the categories of third parties with whom the business shares your Personal Information.
  • The right to request a copy of the specific Personal Information collected about you.
  • The right not to be discriminated against because you have exercised any of these rights.

In order to exercise rights enumerated above, please contact Vitality in one of the ways following depending on which Vitality Program you use.

If you use the Power of Vitality Website or the Vitality Today Application, please contact Vitality through our Contact Us page.

If you use the Vitality One Application, please submit a request through the Application as provided.

If you are not a current Vitality member or one of the above options does not work for you, please contact Vitality through the following link: https://www.vitalitygroup.com/contact-us/.

Alternatively, you may submit your request by calling Us at 877.224.7117.

Vitality will attempt to verify your request by using information related to your account, but in some cases additional information may be required. Subject to certain exceptions that may apply, if We are able to verify your request, We will accommodate your request in accordance with the CCPA.

Does Vitality comply with the EU-US Privacy Shield Framework?

Yes. Vitality complies with the EU-US Privacy Shield Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of Personal Information from European Union member countries. The Vitality Group, LLC, including and on behalf of its affiliate Vitality Group International, Inc., have certified adherence to the Privacy Shield Principles of Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity and Purpose Limitation, Access, and Recourse, Enforcement and Liability. If there is any conflict between the policies in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification page, please visit https://www.privacyshield.gov/.

Vitality acknowledges the Federal Trade Commission’s authority over our compliance with the Privacy Shield. In compliance with the EU-US Privacy Shield Principles, The Vitality Group commits to resolve complaints about your privacy and our collection or use of your Personal Information. European Union individuals with inquiries or complaints regarding this privacy policy should first contact The Vitality Group at:

The Vitality Group, LLC
Attn: Data Privacy Officer
200 W. Monroe St., Suite 1900
Chicago, IL 60606
US_Privacy@vitalitygroup.com
+1.877.224.7117

The Vitality Group has elected the EU Data Protection Authorities (DPAs) as its independent recourse mechanism available to ensure users that Vitality is consistently in compliance with the Privacy Shield Privacy Principals. Users may contact the appropriate DPA by visiting http://ec.europa.eu/justice/data-protection/bodies/index_en.htm.

Under limited circumstances, an arbitration option is available to an individual to determine, for residual claims, whether The Vitality Group has violated its obligations under the Principles as to that individual, and whether any such violation remains fully or partially unremedied.

Does Vitality comply with the EU-US Privacy Shield Framework?

Individuals with inquiries or complaints regarding the privacy of their Personal Information at Vitality or this privacy policy should first contact The Vitality Group at:

The Vitality Group, LLC
Attn: Data Privacy Officer
200 W. Monroe St., Suite 1900
Chicago, IL 60606
US_Privacy@vitalitygroup.com
+1.877.224.7117