Privacy Policy

Review our privacy policy to understand how we collect and use personal data
Last updated December 6, 2023

This Privacy Policy describes how Zaghi Medical Inc, a California Professional Corporation doing business as Shapely, collects and uses Personal Data, defined below, about the use of our www.getshapely.com website and any companion websites linked thereto and associated mobile applications made available (“Website”), and through email, text, and other electronic communications between you and Shapely and its service providers (“Other Interactions”). By accessing or using our Website and Services in any manner, you acknowledge that you accept the practices and policies outlined below, and you consent to our collection, use and sharing of your Information as described in this Privacy Policy. This Privacy Policy ("Policy") will tell you how Shapely collects, stores, uses, share and processes the personal data and information we collect about you (“User” or “You”) through the Website and Services.

Zaghi Medical, Inc. d/b/a Shapely ("Shapely," "we," "us" or "our") is committed to respecting your privacy and protect your Personal Data and Information through compliance with this Policy.

This Policy does not cover the practices of third parties and/or companies that Shapely doesn’t own or control or people we don’t manage. This Policy also does not cover Protected Health Information (as defined by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and HIPAA Privacy Rule) collected by the physicians, dieticians and other practitioners (“Service Providers”) with whom Shapely contracts to facilitate services offered through the Shapely platform. Shapely currently contracts with these Service Providers, however, the Service Providers we contract with may change from time to time. This Policy describes how Shapely and its Service Providers may use and disclose your Protected Health Information. If you do not agree to those terms, which are available here, you should not access or use the Website and Services.

Quick Links: 

  • Read our Cookie Policy
  • To opt-out of the collection of your information or to learn more about your privacy rights, click here
  • Your use of the Website and Services is subject at all times to our Terms of Use, which incorporates this Privacy Policy. Any terms we use in this Policy without defining them have the definitions assigned in the Terms of Use.

What Information Do We Collect?

Through your access and use of our Website you may choose to submit or provide us the following information or such information may be collected from the use of cookies on our website (collectively “Information”):

  • Personal and Contact Information – we collect information by which you may be personally identified, such as your name, email and postal address, telephone number, driver’s license or other government issued identification card number, date of birth, health insurance information, credit or debit card (for payment purposes only), images, photos or videos of your, your medical history, your race or ethnicity, and other health information when you provide it to us to contact you or during your enrollment in our offered programs (“Personal Data”).
  • Cookies and the like: We may collect non-personally identifiable Information such as your IP address, pages visited, time spent on the website, type of browser and device, language and date of access, traffic data and logs, error information, clickstream data and other communication data and the resources that you use on the Website for the purpose of identification and better navigation of the Website. 
  • Career Submissions – we collect your resume/CV and contact details, if you are interested in being part of the Shapely team.
  • Investor, Media, Update Subscription or General Inquiries – we collect your name, email address, mailing address, telephone number and other contact details.

Categories of Sources of Personal Data

We may collect Personal Data about you from the following categories of sources:

1. You

When you provide information directly to us by:

  • creating an account or use our interactive tools and Services.
  • linking your activity tracker, Apple Health, Google Fit, continuous glucose monitoring, smart scale, or wireless-enabled wearable technology device (such as a Fitbit or Apple watch) to the Services to track metrics such as weights, glucose levels, or sleep minutes per day.
  • providing information in free-form text boxes through the Website and Services or through responses to surveys or questionnaires.
  • Sending us an email or other electronic messages.
  • Calling us or leaving a voicemail

When you use the Website and Services and information is collected automatically:

  • through Cookies (as defined in the “Tracking Tools, Advertising and Opt-Out” section below).
  • if you use a location-enabled browser, we may receive information about your location.
  • if you download and install certain applications and software we make available, we may receive and collect information transmitted from your computing device to provide you with Services, such as information about when you are logged on and available to receive updates or alert notices.

2. Third Parties

  Vendors

  • We may use analytics providers to analyze how you interact and engage with the Website and Services.
  • We may use third parties to help us provide you with customer support.
  • We may use vendors to obtain information to generate leads and create user profiles.

  Employers

  • If your employer makes the Website and Services available to you as a benefit of employment, we may receive certain information from them about you to enable your account and/or facilitate provision of or payment for the Services.

  Affiliates

  • We may receive information about your participation in the Website and Services from our affiliates, such as professional health care providers, dietitians, or nutritionists (including the Practice and Providers).

  Advertising Partners

  • We receive information about you from some of our vendors who assist us with marketing or promotional services related to how you interact with our websites, applications, products, Services, advertisements or communications.

  Social Networks

  • If you provide your social network account credentials to us or otherwise sign in to the Website and Services through a third-party site or service, some content and/or information in those accounts may be transmitted into your account with us.

How Do We Use Your Information?

We use your Information to contact you when you give us your consent to do so.

We also use your Information for the following purposes:

  • To provide our branded Website and the tools used as part of our Other Interactions governed by this Policy to you (together, the "Shapely Sites");
  • Providing, Customizing and Improving the Services
  • Creating and managing your account or other user profiles.
  • Processing orders or other transactions; billing.
  • Providing you with the products, services or information you request.
  • Meeting or fulfilling the reason you provided the information to us.
  • Providing support and assistance for the Website and Services.
  • Improving the Website and Services, including testing, research, internal analytics and product development.
  • Personalizing the Website and Services, website content and communications based on your preferences.
  • Carrying out other business purposes stated when collecting your Personal Data or as otherwise set forth in applicable data privacy laws, such as the California Consumer Privacy Act (the “CCPA”).
  • Sending emails and other communications according to your preferences or that display content that we think will interest you.
  • To monitor, improve and administer the Shapely Sites and the Website and Services provided on the Shapely Sites, including testing, research, internal analytics and product development;
  • Informing You of significant changes to this Policy;
  • Marketing the Website and Services;
  • Marketing and selling the Website and Services.
  • Showing you advertisements, including interest-based or online behavioral advertising.
  • Corresponding with you including, responding to correspondence that we receive from you, contacting you when necessary or requested, and sending you information about Services;
  • Processing your application for employment;
  • To detect and prevent fraud and to comply with and enforce our legal requirements, including but not limited to protecting the rights, property or safety of you, Shapely, or another party; ensuring compliance with our Terms of Use; resolving disputes; and enforcing agreement with you; and
  • Carrying out other business purposes stated when collecting Your Information or as otherwise set forth in applicable data privacy laws, such as the California Consumer Privacy Act (“CCPA”).

Who Do We Share Your Information With?

We do not share, sell or otherwise disclose your Information other than to those outlined in this Privacy Policy. Moreover, we do not share your information with any third parties for marketing purposes. However, we may disclose aggregated information about our users and information that does not identify any individual (i.e.: deidentified data) without restriction. We do disclose your Information to a certain third parties, including:

  • Our affiliates, which are bound to the terms of this Policy;
  • Any alliance partners with whom we partner with to offer certain products and Services we may have and who are identified on the Shapely Websites. We share your personal data as needed for them to comply with their legal obligations with respect to those services and to understand how to effectively market and improve those Services. Our alliance partners are bound by a duty of confidentiality to Shapely.
  • Our Service Providers, which are contractually obligated to provide services on our behalf in a manner consistent with this Policy. Our Service Providers include:
  • vendors and suppliers that provide us with hosting, technology, services, and/or content related to better operation and maintenance of the Shapely Websites;
  • our attorneys and auditors;
  • security and fraud prevention consultants;
  • support and customer services vendors;
  • payment processors. Our payment processing partner Stripe Inc (“Stripe”) collects your voluntarily-provided payment card information necessary to process your payment. Please see Stripe’s terms of service and privacy policy for information on its use and storage of your Personal Data;
  • vendors that provide analytics and research services.
  • Advertising partners who help us market our services and provide you with other offers that may be of interest to you.
  • Analytic partners who provide analytics on web traffic or usage of the Website and Services.
  • Third parties you authorize, access or authenticate including social media services.
  • To another third party as part of a merger, acquisition or other sale or transfer of Shapely and/or any of its affiliates to such other party.
  • To third parties in order to comply with our legal obligations or enforce our rights; and
  • To other third parties in other circumstances where you provide your consent.

 

Please note that we may need to disclose your Personal Data and Information if we are required to do so by law, to exercise and protect the legal rights of Shapely or its personnel and representatives, and to investigate, prevent or respond to suspected illicit activities, including fraud and threats of harm to individuals.

Tracking Tools, Advertising and Opt-Out

The Website and Services use cookies and similar technologies such as pixel tags, web beacons, clear GIFs and JavaScript (collectively, “Cookies”) to enable our servers to recognize your web browser, tell us how and when you visit and use our Website and Services, analyze trends, learn about our user base and operate and improve our Website and Services. Cookies are small pieces of data – usually text files – placed on your computer, tablet, phone or similar device when you use that device to access our Website and Services. We may also supplement the information we collect from you with information received from third parties, including third parties that have placed their own Cookies on your device(s). Because of our use of Cookies, the Website and Services do not support “Do Not Track” requests sent from a browser at this time.

We use the following types of Cookies:

  • Essential Cookies. Essential Cookies are required for providing you with features or services that you have requested. For example, certain Cookies enable you to log into secure areas of our Website and Services. Disabling these Cookies may make certain features and services unavailable.
  • Functional Cookies. Functional Cookies are used to record your choices and settings regarding our Website and Services, maintain your preferences over time and recognize you when you return to our Website and Services. These Cookies help us to personalize our content for you and remember your preferences (for example, your choice of language or region).
  • Performance/Analytical Cookies. Performance/Analytical Cookies allow us to understand how visitors use our Website and Services. They do this by collecting information about the number of visitors to the Website and Services, what pages visitors view on our Website and Services and how long visitors are viewing pages on the Website and Services. Performance/Analytical Cookies also help us measure the performance of our advertising campaigns in order to help us improve our campaigns and the Website and Services’ content for those who engage with our advertising. For example, Google LLC (“Google”) uses cookies in connection with its Google Analytics services. Google’s ability to use and share information collected by Google Analytics about your visits to the Website and Services is subject to the Google Analytics Terms of Use and the Google Privacy Policy. You have the option to opt-out of Google’s use of Cookies by visiting the Google advertising opt-out page at www.google.com/privacy_ads.html or the Google Analytics Opt-out Browser Add-on at https://tools.google.com/dlpage/gaoptout/.
  • Retargeting/Advertising Cookies. Retargeting/Advertising Cookies collect data about your online activity and identify your interests so that we can provide advertising that we believe is relevant to you. For more information about this, please see the section below titled “Information about Interest-Based Advertisements.”

You can decide whether or not to accept Cookies through your internet browser’s settings. Most browsers have an option for turning off the Cookie feature, which will prevent your browser from accepting new Cookies, as well as (depending on the sophistication of your browser software) allow you to decide on acceptance of each new Cookie in a variety of ways. You can also delete all Cookies that are already on your device. If you do this, however, you may have to manually adjust some preferences every time you visit our website and some of the Website and Services and functionalities may not work.

To explore what Cookie settings are available to you, look in the “preferences” or “options” section of your browser’s menu. To find out more information about Cookies, including information about how to manage and delete Cookies, please visit https://www.allaboutcookies.org/.

Information about Interest-Based Advertisements:

We may serve advertisements, and also allow third-party ad networks, including third-party ad servers, ad agencies, ad technology vendors and research firms, to serve advertisements through the Website and Services. These advertisements may be targeted to users who fit certain general profile categories or display certain preferences or behaviors (“Interest-Based Ads”). Information for Interest-Based Ads (including Personal Data) may be provided to us by you, or derived from the usage patterns of particular users on the Website and Services and/or services of third parties. Such information may be gathered through tracking users’ activities across time and unaffiliated properties, including when you leave the Website and Services. To accomplish this, we or our service providers may deliver Cookies, including a file (known as a “web beacon”) from an ad network to you through the Website and Services. Web beacons allow ad networks to provide anonymized, aggregated auditing, research and reporting for us and for advertisers. Web beacons also enable ad networks to serve targeted advertisements to you when you visit other websites. Web beacons allow ad networks to view, edit or set their own Cookies on your browser, just as if you had requested a web page from their site.

Social Media

Shapely may provide the option for individuals to participate in polling, messaging, and posting activities, including through social media channels. Shapely is not responsible for the information collection, use, disclosure, or security policies or practices of other organizations, such as Facebook, Apple, Google, Microsoft, RIM, or any other social media platform provider, operating system provider, wireless service provider, or device manufacturer, including with respect to any personal data you disclose to other organizations through or in connection with our social media pages. Additionally, Shapely may monitor social media channels for mentions of our brand, competitors, and products, which gives Shapely an opportunity to track, analyze, and respond to conversations about us on social media.

Third Party Sites

The Shapely Website and Services may feature links to third-party websites ("Third-Party Site(s)"). These Third-Party Sites are not owned or controlled by us and we are not responsible for the privacy practices of such Third-Party Sites. We encourage you to be aware when you leave the Shapely Website. If you choose to link to a Third-Party Site, you should read the privacy policy, statement or Policy of that website to understand how that Third-Party Site collects and uses personal data. This Policy does not apply to any information collected by Third-Party Sites.

How Long Do We Retain Your personal data?

We intend to keep your Personal Data and Information accurate and up-to-date and retain it for the period necessary to fulfill the legitimate business purposes or uses outlined in this Policy (i.e.: as long as you have an open account with us or as otherwise necessary to provide you with our Services), unless a longer retention period is required or allowed by applicable data protection law or to otherwise fulfill a legal obligation. In addition, Information about You may be retained for a longer period of time to resolve disputes or collect fees owed to us, or as otherwise advisable, permitted or required by applicable law, rule or regulation. Precisely how long we need to keep your Personal Data and Information depends on the purpose for which we collect it, and therefore there is no standard retention period. Thus, the retention period may vary depending on the circumstances. For other legal reasons, e.g. in the context of legal claims, we may need hold Personal Data and Information beyond the term required to meet the defined purpose for which they were collected in the first place. However, in these cases we will no longer actively process the Personal Data for the originally specified purpose. We also retain Information in an anonymous, deidentified form which would not identify You personally for archival and research purposes. In general, we do not retain the Information collected on the Shapely Sites for longer than five (5) years unless we have a need to retain it.

How Do We Protect Your Personal Data?

Shapely maintains a comprehensive data security program, including commercially reasonable administrative, physical and technological security measures, to protect your Personal Data and Information and to guard against unauthorized access to your Personal Data and Information or against the unauthorized alteration, disclosure, destruction and/or loss of such data. In deciding what level of security is appropriate, Shapely will take into account the nature of the Personal Data and Information in question, and the harm that might result from its unauthorized use, disclosure or loss.

Although we take reasonable precautions to protect the Information and Personal Data we collect on the Shapely Website and Services and store in our databases, no data transmission over the Internet can be guaranteed to be 100% secure.

Children

The Shapely Websites and Services are not directed to children under the age of eighteen (18) and we request that these individuals not provide personal data through the Shapely Websites. The Shapely Websites, its content, and its services are intended for individuals over the age of 18, without exception. The Shapely Websites are not directed to, nor do we knowingly collect information from, children under the age of 18. If we actually know that a user under the age of 18 has volunteered personal data on the Shapely Websites we will delete such information from our records. If you become aware that your child or any child under your care has provided us with personal data, please contact us at the contact information listed below.

What Are Your Rights?

You always have the right to:

  • Confirmation of Access: You may request confirmation of the existence of processing of your Personal Data so that you can access it if you so desire;
  • Correction: You may request the correction of your Information or Personal Data if it is incomplete, inaccurate or outdated;
  • Anonymization, blocking or erasure: You may request (a) the anonymization of your Personal Data ; (b) the blocking of your Personal Data or Information which, it should be noted, will temporarily suspending your ability to process for certain purposes; and (c) the erasure of your Personal Data;
  • Portability: You may ask us to provide your Personal Data in a structured format for your transfer to a third party, provided that such transfer does not violate Shapely’s intellectual property or business secrets, or is characterized as an act of unfair competition against Shapely;
  • Sharing Information: You have the right to know which public and private entities with whom Shapely shares your Personal Data and Information;
  • Information about the possibility of not consenting: You have the right to receive clear and complete information about the possibility and consequences of not providing consent, when it is requested by Shapely. Consent, when necessary, must be free and informed. Therefore, whenever we ask for consent, You will be free to deny it - in such cases, it is possible that some Services cannot be provided or some features are partially or totally inoperative;
  • Withdrawal of consent: If You have consented, You can always choose to withdraw your consent. If you withdraw your consent, we may not be able to provide certain services to you, but we will let you know when we do;
  • Objection: the general data protection laws authorizes the processing of personal data for legitimate reasons even without your consent or a contract with us. In these situations, we will only process your personal data if we have legitimate reasons.

For your safety, whenever a request is made to exercise your rights, Shapely may request some information and/ or additional documents so that we can prove your identity, seeking to prevent fraud. We do this to ensure your safety and privacy.

You can exercise your rights through hello@getshapely.com. You also have the right to lodge a complaint with the data protection authority.

Special Notice Regarding International Personal Data Laws

Shapely is a United States corporation based in Los Angeles, California. Shapely does not transact business outside the United States and its Territories and thus does not gather, store or process Personal Data from ex-US citizens. Shapely uses web servers and stores data in the United States. We may transfer your personal data to our service providers and others located in the United States for the purposes described in this Policy. However, it is acknowledged that this Website may be accessed by individuals residing outside the United States and its Territories and different countries have different privacy laws and requirements, and some provide less or more stringent legal protection for your personal data than others. Please know, however, that no matter where your personal data is collected or processed, if it was collected through an Shapely Website, we will ensure that it is protected by the terms of this Policy and any privacy Policies or click-through agreements that apply to you.

Your California Privacy Rights

If you are a California resident, you have certain additional rights related to information that we collect about you.

Shapely has collected the following categories of personal data from consumers within the last twelve (12) months:

  • Contact Information (name, email and postal address)
  • Online Identifiers (IP address, cookie IDs)
  • Demographic Information (age, race, gender)
  • Internet Activity Information
  • Audio Information (voicemail and other call recordings)
  • Professional or employment related information

Your California Rights

  • Right to Notice. Before or at the time we collect personal data from you, you have the right to receive notice of the personal data to be collected and the purposes for which we use it. This Notice is intended to satisfy this requirement.
  • Right to Know. You have the right to request that we provide you with the following
  • The categories of personal data we have collected about you;
  • The categories of sources from which we have collected personal data about you;
  • The business or commercial purpose for collecting your personal data;
  • The categories of third parties with whom we share personal data;
  • The specific pieces of personal data we have collected about you; and
  • The categories of personal data that we have disclosed about you for a business purpose.
  • Right Not to Be Subject to Discrimination. You have the right to be free from discrimination or retaliation for exercising any of your rights under the California Consumer Protection Act (CCPA), including the rights listed above.

Please note that Shapely may not be required to fulfill your requests in certain circumstances. These include instances where we must retain or restrict access to personal data in order to preserve scientific integrity, as your personal data must be managed in specific ways in order for the information to be reliable and accurate and to meet regulatory obligations of Shapely and its affiliates.

Additionally, Shapely is not required to provide information in response to a request to know for a particular consumer more than twice in any given twelve-month period.

When you submit a request to exercise your right of access, your right to deletion, or your right to know, we are required to verify that you are who you say you are. We may request that you provide additional personal data for the verification process.

To exercise the rights described above, to file a concern or complaint, or to opt-out of particular programs, please contact our Privacy Officer at hello@getshapely.com or by calling (424) 600-8360.

Updates to This Policy and Contacting Us

We may amend this Policy at any time. Any changes to this Policy will be posted on the Shapely Websites. Should these amendments materially relate to any consents You may have given, Shapely will contact you in order to obtain your consent to any change in the use of your personal data.

If you have any questions or concerns about this Policy or our use of your Personal Data and Information, please email us hello@getshapely.com or write us at:

Zaghi Medical, Inc. d/b/a Shapely

5665 W. Wilshire Blvd #1609

Los Angeles, CA 90036

Attention: Privacy Officer