Coast to Coast Privacy Policy

Effective: October 25, 2023

Because we’re committed to safeguarding Coast to Coast client and participant confidentiality, the following privacy principles apply:

  • Coast to Coast participant data is processed within the USA.
  • HES does not perform any automated decision making or profiling relating to the personal data processed in Coast to Coast.
  • In cases when Coast to Coast may need personal information to customize content or to inform you about new features or services, you will be explicitly asked for that information.
  • Personally identifiable information from you (including name, email, photo, or organization) will only be used:
    • To provide, update, maintain and protect Coast to Coast.
    • As required by applicable law, legal process or regulation.
    • To communicate with you by responding to your requests, comments and questions.
    • To investigate and help prevent security issues and abuse.
  • HES will retain participant data in accordance with client’s instructions, for 2 years after the Coast to Coast campaign ends or for a period of time needed for HES to pursue legitimate business interests, conduct audits, comply with (and demonstrate compliance with) legal obligations, resolve disputes, and enforce our agreements.
  • Note that when you opt in to social features in Coast to Coast you agree to share your name and logging information with other program participants.
  • Individuals across the globe, including the European Economic Area, have certain statutory rights in relation to their personal data. Subject to any exemptions provided by law, you may have the right to request access to Information, as well as to seek to update, delete or correct this Information. You can usually do this using the settings and tools provided in your Coast to Coast account. If you cannot use the settings and tools, please contact HES with any questions or concerns.

Disclosures

We may disclose personal information:

  • To any person performing audit, legal, operational, or other services for us. Whenever feasible, we will use information that does not identify the individual for these activities. Information disclosed to vendors or contractors for operational purposes may not be re-disclosed to others by such a vendor or contractor.
  • When required to do so by a subpoena, court order, or search warrant.
  • As we deem appropriate to protect the safety of an individual, for an investigation related to public safety, or to report an activity that appears to be in violation of law.
  • To protect the security and reliability of this site and to take precautions against liability.

Email addresses may be used for internal communications.

Security

Coast to Coast employs strict security measures to safeguard personal information such as:

  • HES services support the latest recommended secure cipher suites and protocols to encrypt all traffic in transit. Participant Data is encrypted at rest.
  • Participant Data is stored redundantly in our hosting provider’s data centers to ensure availability. We have well-tested backup and restoration procedures, which allow recovery from a major disaster. Participant Data and our source code are automatically backed up nightly.
  • In addition to sophisticated system monitoring and logging, we have implemented two-factor authentication for all server access across our production environment. Firewalls are configured according to industry best practices and unnecessary ports are blocked by configuration with AWS Security Groups.
  • We contract with respected external security firms who perform regular audits of HES services to verify that our security practices are sound and to monitor HES services for new vulnerabilities discovered by the security research community.

Third Parties

To support delivery of our Services HES may engage and use data processors with access to certain Participant Data (each, a “Subprocessor”). This section provides important information about the identity, location and role of each Subprocessor.

HES currently uses third party Subprocessors to provide infrastructure services, and to help us provide customer support and email notifications. Prior to engaging any third party Subprocessor, HES performs diligence to evaluate their privacy, security and confidentiality practices, and executes an agreement implementing its applicable obligations. We do not sell or otherwise disclose personal information collected by our site to third parties.

HES challenges allow a connection to third party platforms for accessing step data. No data entered in a challenge is sent to a third party. HES securely stores this data, is committed to safeguarding participant confidentiality per our privacy policy, and only accesses the data during the challenge. You can control the use of third party platforms for step data under your Settings.

Health Connect

Participants have the option to sync step data with Google’s Health Connect to journal or report their physical activity. No data entered in a challenge is sent to a third party. The use of information received from Health Connect will adhere to the Health Connect Permissions Policy, including the limited use requirements. You can stop Coast to Coast from accessing step data on your wearable or device by changing the settings on your mobile device.

Infrastructure Subprocessors

HES may use the following Subprocessors to host Participant Data or provide other infrastructure that helps with delivery of our Services:
  • Amazon Web Services, Inc. (United States) ­– Cloud Service Provider

Other Subprocessors

HES may use the following Subprocessors to perform other Service functions:
  • Zendesk, Inc. (United States) — Cloud-based Customer Support Services
  • Google LLC (United States) — Analytics.

Cookies

Cookies are small text files sent by us to your computer or mobile device, which enables Coast to Coast features and functionality. They are unique to your account or your browser. Session-based cookies last only while your browser is open and are automatically deleted when you close your browser. Persistent cookies last until you or your browser delete them or until they expire.

Some cookies are associated with your account and personal information in order to remember that you are logged in. Other cookies are not tied to your account but are unique and allow us to carry out analytics.

You can control the use of cookies at the individual browser level. If you elect not to activate the cookie or to later disable cookies, you may still visit Coast to Coast, but your ability to use some features or areas of Coast to Coast may be limited. You may also enable or disable third party cookies using the Cookie Consent configuration.