1. WHY THIS POLICY EXISTS
The Washington My Health My Data Act (chapter 19.373 RCW) requires a separate consumer health data privacy policy. This is that policy. It is a companion to our general Privacy Policy and does not replace it.
This policy describes how Toothsome, Inc. ("Toothsome," "we," "us," or "our") collects, uses, shares, and protects consumer health data as that term is defined in RCW 19.373.010(8): personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status.
If you are a Washington resident, or if your consumer health data is collected in Washington, this policy applies to you.
2. WHAT THIS POLICY DOES AND DOES NOT COVER
Most of the health information Toothsome handles is Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"). We receive it as a business associate of your employer's health plan or of a dental provider, and we handle it under a Business Associate Agreement.
RCW 19.373.100(1)(a)(i) excludes PHI from the definition of consumer health data. That exclusion applies to the data, not to the company: information that is PHI is governed by HIPAA and by Section 5 of our Privacy Policy, and information that is not PHI is governed by this policy even though we hold both.
This policy therefore covers health-related information we hold that is not PHI — for example, information collected from a visitor to our public website before any plan relationship exists, or information a person gives us outside the business-associate relationship.
We do not treat HIPAA as a reason to disclose less here. Where we are unsure whether a particular item is PHI or consumer health data, we describe it in this policy.
A note on the definition of "consumer." RCW 19.373.010(7) defines a consumer as a natural person acting in an individual or household context and states that the term "does not include an individual acting in an employment context." Employees who receive dental benefits through an employer that uses our Platform may fall outside that definition for some or all of their interactions with us. We have not written this policy to depend on that question. We describe our practices for everyone, and we honor the rights in Section 7 for any Washington resident who asks, without requiring them to establish which capacity they were acting in.
3. CATEGORIES OF CONSUMER HEALTH DATA WE COLLECT, AND WHY
Required by RCW 19.373.020(1)(a)(i).
| Category | Why we collect it | How we use it |
|---|---|---|
| Dental treatment information — procedure descriptions, dental procedure codes, dates of service, and treating practice, taken from receipts and invoices you submit | To determine whether an expense qualifies for reimbursement under your employer's plan rules | Matched mechanically against the plan's eligibility rules and against the medical-expense definition in Section 213(d) of the Internal Revenue Code; retained as the substantiation record for the reimbursement |
| Amounts paid for dental care — what you paid, to whom, and when | To reimburse the correct amount and to track the balance remaining in your benefit | Applied against your available benefit; reported to your employer only as a reimbursement amount, without clinical detail |
| Benefit eligibility and enrollment status — whether you are enrolled in an employer dental benefit program and what remains available to you | To confirm you are eligible before a reimbursement | Checked at the time of a request; shared with a participating practice only as an eligibility status, as described in Section 5 |
| Information indicating you sought dental care — including the identity of a dental practice you looked up, contacted, or visited through the Platform | To operate the practice directory | Used to show you practices; not used to build advertising profiles |
| Communications you send us about your care — messages, questions, and appeal or dispute correspondence that mention your dental condition or treatment | To answer you and to support your employer's plan administrator in an appeal | Read by the people handling your request; retained with the request record |
We do not collect biometric data, genetic data, precise location information, reproductive or sexual health information, gender-affirming care information, or information about your mental health, and we do not infer health status from non-health information using algorithms or machine learning.
4. CATEGORIES OF SOURCES
Required by RCW 19.373.020(1)(a)(ii).
- From you directly — receipts, invoices, and documents you upload; information you enter into the Platform; messages you send us.
- From your employer — enrollment, eligibility, and benefit-amount information about the program your employer sponsors.
- From dental practices participating in Toothsome Direct — invoices, treatment descriptions, and procedure codes submitted in connection with your care.
- From our payment partner — confirmation that a payment or reimbursement settled, and the amount and date.
We do not buy consumer health data, and we do not obtain it from data brokers, advertising networks, or public sources.
5. CATEGORIES OF CONSUMER HEALTH DATA WE SHARE
Required by RCW 19.373.020(1)(a)(iii).
- Reimbursement amounts and dates — shared with your employer for payroll and plan administration. We do not share clinical details, procedure codes, or treatment descriptions with your employer.
- Eligibility status and your Toothsome identifier — shared with a participating dental practice so it can confirm your benefit before treating you.
- Treatment and payment information — shared with our service providers listed in Section 6, only as needed to host, secure, or operate the Platform.
- Substantiation records — shared with your employer's plan administrator when a reimbursement request requires a determination the plan administrator must make, or when you appeal one.
We share the minimum necessary in each case.
6. THIRD PARTIES AND AFFILIATES WITH WHOM WE SHARE
Required by RCW 19.373.020(1)(a)(iv), which requires categories of third parties and specific affiliates.
Specific affiliates: Toothsome, Inc. has no affiliates, and therefore shares consumer health data with no affiliate. If that changes, we will name the affiliate in this policy before sharing anything with it.
Categories of third parties:
| Third party | Category | What it receives |
|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure and storage | All Platform data, at rest and in transit. Under a Business Associate Agreement. |
| Google LLC (Google Workspace) | Business email and document storage | Business communications that may reference a request. Under a Business Associate Agreement. |
| Moov Financial, Inc. | Invoicing employers for Toothsome's administration fee | Employer billing and payment information only. Moov does not receive member information, procedure codes, treatment descriptions, or any clinical information. |
| Twilio Inc. (SendGrid) | Email delivery | Email addresses and message content. Our emails are written to contain no health information. |
| Employers sponsoring a benefit program | Plan sponsor and plan administrator | Reimbursement amounts and dates; substantiation records where a plan-administrator determination or appeal requires them. No clinical detail. |
| Participating dental practices | Health care providers | Eligibility status and your Toothsome identifier. |
Each service provider that processes consumer health data on our behalf does so only under a binding written contract that limits it to our instructions, as RCW 19.373.060 requires.
We may also disclose consumer health data when required by law, subpoena, court order, or government request, and in connection with a merger, acquisition, or sale of assets. We will notify you of any change in ownership or control of your information.
7. YOUR RIGHTS
Required by RCW 19.373.020(1)(a)(v); rights granted by RCW 19.373.040.
If you are a Washington consumer, you have the right to:
Confirm and access. Ask whether we collect, share, or sell your consumer health data, and get a copy of it. Your response will include a list of all third parties and affiliates with whom we have shared your consumer health data, and an active email address or other online contact for each one.
Withdraw consent. Where we collect or share your consumer health data based on your consent, withdraw that consent. You can withdraw consent to collection and consent to sharing separately. Withdrawing consent does not undo what was lawfully done before you withdrew it.
Delete. Ask us to delete your consumer health data. When you do, we will delete it from all of our records, including archived and backup systems, and we will notify every affiliate, processor, contractor, and third party with which we have shared it, each of which must honor the deletion. Deletion from archived or backup systems may take longer than deletion from live systems, and will be completed within six months in any event.
How to exercise these rights. Email privacy@toothsome.io, or write to us at the address in Section 12. We will not charge you and we will not require you to create an account.
If we refuse. If we decline your request, we will tell you why, and you may appeal by replying to our decision or by emailing privacy@toothsome.io with the word "appeal." We will give you a written decision on the appeal within forty-five (45) days, with our reasons. If we deny the appeal, we will give you a link you can use to submit a complaint to the Washington State Attorney General.
We will not discriminate against you, deny you goods or services, or charge you a different price because you exercised any of these rights.
8. CONSENT
RCW 19.373.030.
We collect consumer health data either with your consent for a specified purpose, or because it is necessary to provide a product or service you have requested from us. Submitting a receipt for reimbursement is an example of the second: we cannot process the request without the information on the receipt.
We share consumer health data only to the extent necessary to provide the service you have requested, as described in Section 5. For example, we send your approved reimbursement amount to your employer so it can pay you through payroll. If we ever want to collect or share consumer health data for any other purpose, we will first ask for your consent. Consent to share is always asked separately from consent to collect, and neither is ever obtained through acceptance of general terms of use.
Before we ask for consent, we will tell you the categories of consumer health data involved, the purpose including the specific ways it will be used, the categories of entities it will be shared with, and how to withdraw your consent.
We will not collect, use, or share any category of consumer health data, or use it for any purpose, that is not disclosed in this policy without first disclosing it here and obtaining your consent.
9. WE DO NOT SELL CONSUMER HEALTH DATA
We do not sell consumer health data, and we have no plans to. Selling it would require a signed valid authorization from you under RCW 19.373.070 — a separate document from consent, with its own required contents and a one-year expiration. We have never sought one and we do not intend to.
10. WE DO NOT USE GEOFENCING
We do not implement a geofence around any facility that provides in-person health care services. We do not use location technology to identify or track anyone seeking health care services, to collect consumer health data, or to send anyone notifications, messages, or advertisements related to their health data or their health care. RCW 19.373.080 prohibits all three, and we do none of them.
11. HOW WE PROTECT CONSUMER HEALTH DATA
RCW 19.373.050.
We maintain administrative, technical, and physical safeguards appropriate to the volume and nature of the data: encryption in transit using TLS and at rest using AES-256; access restricted to the members of our workforce who need it to do their jobs; monitoring for unauthorized access; and regular privacy and security training.
Access to consumer health data inside Toothsome is limited to what each person needs to perform their role.
If consumer health data is involved in a data breach, the notification obligations described in Section 11 of our Privacy Policy apply.
12. CONTACT US
Toothsome, Inc. 3550 N Lakeline Blvd, Unit 170, PMB 1022 Leander, TX 78641
Email: privacy@toothsome.io
To exercise any right in Section 7, or to ask a question about this policy, email privacy@toothsome.io.
13. CHANGES TO THIS POLICY
If we make a material change — including collecting a new category of consumer health data, using it for a new purpose, or sharing it with a new category of third party — we will update this policy and disclose the change before the new collection, use, or sharing begins, and we will obtain your consent where RCW 19.373.020(1)(c) and (1)(d) require it.
Document Version: 1.0 · Last Updated: September 24, 2026