Our Commitment to Your PrivacyAt DirectOD, safeguarding your privacy is a core part of how we do business. We are committed to handling your personal information with integrity, transparency, and in full compliance with applicable data protection laws, including the California Consumer Privacy Act (CCPA), Colorado Privacy Act (CPA), Virginia Consumer Data Protection Act (VCDPA), and others.
This Privacy Policy explains how we collect, use, store, and share your personal data when you interact with our website, platform, and services. By using the DirectOD platform, you consent to the practices described in this Policy.
If you have any questions or requests, contact us at
admin@directod.com.
Scope of This PolicyThis Privacy Policy applies to:
- Visitors to our website (https://directod.com)
- Independent eye care providers and their staff who use DirectOD
- Patients enrolled in a vision membership plan administered through DirectOD
If you are a patient of a participating provider, this policy explains how we process your data on behalf of your eye care provider. DirectOD acts as a "service provider" or "data processor" under applicable law. For HIPAA-related inquiries or rights, please contact your provider directly.
Information We CollectWe may collect the following categories of personal information:
Category | Examples |
---|
Contact Data | Name, email address, phone number, mailing address |
Patient Enrollment Data | Birthdate, plan selections, eligibility, transaction history |
Payment Data | Card type, last four digits, payment activity (via JP Morgan Chase Bank) |
Account & Usage Data | Login activity, IP address, session timestamps |
Device & Technical Data | Browser type, device type, operating system, geolocation |
Marketing & Analytics Data | Referral sources, ad engagement, cookie identifiers |
Communication Records | Emails, chats, support tickets, survey responses |
We collect this information directly from you, your practice, or automatically through our website and tools such as Google Analytics or other integrated services.
How We Use Your InformationWe use your information for the following business purposes:
- To operate, manage, and maintain your vision membership plan
- To enroll patients and administer recurring renewals
- To communicate with you about your account or services
- To process and confirm payments securely
- To detect and prevent fraud, abuse, or security issues
- To generate performance reports and optimize platform functionality
- To comply with applicable laws and contractual obligations
- To send relevant product updates, practice resources, or marketing (with your consent)
We will never use your information in a manner inconsistent with this Policy or applicable law.
Cookies and Tracking TechnologiesWe use cookies and similar technologies (such as web beacons and pixels) for:
- Essential functionality – keeping your session active and secure
- Analytics – measuring traffic and user behavior across our site
- Advertising – delivering relevant promotions and retargeting users
You may adjust cookie settings via your browser or opt out through our cookie banner. Disabling cookies may affect the usability of certain features on our site.
How We Share Personal InformationDirectOD does not sell personal information for monetary gain. However, we may disclose your data in the following scenarios:
- With service providers such as JP Morgan Chase Bank (for payment processing), Amazon Web Services (hosting), and analytics or email platforms that support our operations
- With your healthcare provider, if you are a patient enrolled in a membership plan
- With marketing and advertising partners, to improve engagement (in compliance with opt-out laws)
- To comply with legal obligations, such as subpoenas, court orders, or regulatory inquiries
- As part of a business transaction, such as a merger, acquisition, or restructuring
- With your consent, when you authorize us to share your information
All vendors are contractually required to maintain strict confidentiality and adhere to applicable privacy standards.
Third-Party Links and IntegrationsOur website or platform may contain links to third-party websites or tools. DirectOD is not responsible for the privacy practices, content, or security of those third-party services. We encourage you to review their privacy policies before providing any personal information.
Data Transfers Outside the United StatesOur platform is designed for users within the United States. If you access the Services from outside the U.S., please be aware that your information may be transferred to and processed in the United States, where privacy laws may be less stringent than those in your jurisdiction.
HIPAA and Medical PrivacyDirectOD is not a covered entity under HIPAA. However, when acting as a service provider to healthcare practices, we may receive limited protected health information (PHI) in connection with membership plan administration. We maintain strict controls and access limitations around such data and comply with all applicable healthcare privacy obligations as required by law or business associate agreements (BAAs).
Data Security and RetentionWe use administrative, technical, and physical safeguards to protect your data, including:
- SSL encryption for all communications
- Secure data storage in monitored data centers
- PCI-DSS compliant payment processing via JP Morgan Chase Bank
- Role-based access restrictions and internal audits
We retain personal information only as long as necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required by law. Once no longer needed, your data is securely deleted or anonymized.
Your Rights Under U.S. Privacy LawsDepending on your state of residence, you may have the following rights:
- Right to Access – request a copy of the personal data we have collected about you
- Right to Delete – request the deletion of your personal information (with some exceptions)
- Right to Correct – request correction of inaccurate personal data
- Right to Opt-Out – opt out of targeted advertising or third-party tracking
- Right to Limit – restrict the use of sensitive personal information
- Right to Portability – request your data in a machine-readable format
To exercise any of these rights, email us at
admin@directod.com with the subject line: “Privacy Rights Request.” We will verify your identity and respond within 45 days as required by law.
Children’s PrivacyDirectOD does not knowingly collect personal data from children under 13. If we become aware that such information has been submitted, we will take prompt steps to delete it. If you believe we may have collected data from a child under 13, please contact us immediately.
Business Continuity and Ownership ChangesIn the event of a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred to a successor entity. Any acquiring party will be bound by the terms of this Privacy Policy or one with equivalent protections.
Changes to This PolicyWe reserve the right to update or modify this Privacy Policy at any time. Changes will be posted on this page with an updated effective date. Your continued use of our Services after changes are posted constitutes your acceptance of those changes.
Contact UsIf you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:
DirectOD LLC
#1010, 2321 Sir Barton Way, Suite 140
Lexington, KY 40509
admin@directod.comhttps://directod.com