Privacy Policy

Last updated: April 2, 2025

Who We Are

Virta Health Corp., Virta Medical P.C., Virta Medical, P.A., and Virta Medical Kansas, P.A. ("Virta", “we”, “our” or “us”) operate this website and mobile app (the "Service").

This Policy (this “Policy”) describes the information that we collect through our websites (the “Site”), mobile application (the “App”), and the Services (together with the Site and the App, the “Service”), how we use it, and what choices you have about it.

1. Information We Collect

How we collect information

The type of information collected depends on how you interact with Virta, the services you use, and the choices you make.  Information about you is collected from different sources and in various ways when you use our service, including information you provide directly, information collected automatically and information from third-party sources.

  • User-provided Information. When you sign up for or use Virta you share certain such as name, username or alias and contact details such as email address, postal address, and phone number.  In some cases, we may request you share age, gender, marital status and similar demographic details.
  • Payment information: If you make a purchase or other financial transaction, we collect credit card numbers and other payment details.
  • Contents and files: Virta collects the photos, documents or other files you may upload to Virta.  If you send us emails, we collect and retain those communications.
  • Sensitive Personal Information:
    • Account access information: We collect information such as a username or account number in combination with a password, security or access code, or other credential that allows access to an account.
    • Contents of communication: We collect the contents of messages you send in chats in our app.
  • Cookie data: Virta and its partners also use cookies, web beacons, mobile analytics and advertising device IDs, similar technologies.
    • What are cookies and similar technologies?
    • Cookies are small text files placed by a website and stored by your browser on your device. A cookie can later be read when your browser connects to a web server in the same domain that placed the cookie. The text in a cookie contains a string of numbers and letters that may uniquely identify your device and can contain other information as well. This allows the web server to recognize your browser over time, each time it connects to that web server.
    • Web beacons are electronic images (also called single-pixel or clear GIFs) that are contained within a website or email. When your browser opens a webpage or email that contains a web beacon, it automatically connects to the web server that hosts the image (typically operated by a third party). This allows that web server to log information about your device and to set and read its own cookies. In the same way, third-party content on our websites (such as embedded videos, plug-ins, or ads) results in your browser connecting to the third-party web server that hosts that content. We also include web beacons in our email messages or newsletters to tell us if you open and act on them.
    • Mobile analytics and advertising IDs are generated by operating systems for mobile devices (iOS and Android) and can be accessed and used by apps in much the same way that websites access and use cookies. Our apps contain software that enables us and our third-party analytics and advertising partners to access these mobile IDs.
  • How do we and our partners use cookies and similar technologies?
    • We, and our analytics and advertising partners, use these technologies in our websites, apps, and online services to collect personal information (such as the pages you visit, the links you click on, and similar usage information, identifiers, and device information) when you use our services, including personal information about your online activities over time and across different websites or online services. This data is used to store your preferences and settings, enable you to sign-in, analyze how our websites and apps perform, track your interaction with the site or app, develop inferences, deliver and tailor interest-based advertising, combat fraud, and fulfill other legitimate purposes. We and/or our partners also share the data we collect or infer with third parties for these purposes.
  • Information collected from third-party services: Virta also obtains the types of information described above from third parties.  These third-party sources include, for example:
    • Third-party partners: Third-party applications and services, including social networks you choose to interact with to connect to our services. What we have access to is dependent on the privacy policies or settings for those accounts.
    • Information our advertisers share with us: We also get information about you and your activity from our advertising partners and other third parties we work with. For example, online advertisers or third parties share information with us to measure, report on, or improve the performance of ads for Virta.
    • Co-branding/marketing partners: Partners with which we offer co-branded services or engage in joint marketing activities.
    • Service providers: Third parties that collect or provide data in connection with work they do on our behalf. For example, companies that determine your device’s location based on its IP address.
  • When you are asked to provide your information, you may decline or use browser or device controls to prevent certain types of data collection. In some cases, if you choose not to provide information that is necessary, some services or features may not be available or fully functional.

2. How we use the information we collect

We use information we collect on the Service in a variety of ways in providing the Service and operating our business, including the following:

  • Service Delivery: To provide, maintain, and improve our services, including personalizing your experience.
  • Customer Support: To provide customer support and respond to your questions.
  • Business operation: To operate our business, such as billing, accounting, improving our internal operations, securing our systems, detecting fraudulent or illegal activity, and meeting our legal obligations.
  • Communication: To send administrative messages, service updates, and promotional offers (you can opt out of promotional messages).
  • Research and Development: To analyze usage trends, improve our services, and develop new features.

3. Sharing your information

We may disclose your information to third parties in the following circumstances when you are enrolled as a patient in the Virta program:

  • Service Providers: We work with third-party providers (e.g., payment processors, analytics tools) who assist in delivering our services.
  • Health Plans & Coaches: If enrolled in our health programs, we share your progress with healthcare providers or coaches supporting your care.
  • Legal and Safety Reasons: We may share information to comply with legal requirements, enforce our terms, or protect the safety and rights of others.
  • Business Partners: De-identified data may be shared for research or business purposes.
  • Corporate Transactions: In the event of a merger, acquisition, or asset sale, your information may be transferred to the involved parties.

The above excludes text messaging originator opt-in data and consent; this information will not be shared with any third parties.

4. Your Choices

You have the following rights:

  • Access and Update: You can access and update your personal information by logging into your account or contacting us.
  • Opt-Out: You can ask us to stop using your information for certain purposes, including when we use your information to send you marketing emails or SMS messages. If you opt-out of receiving marketing messages from us, we may still send you updates about your account, such as when you request reminders from us to log in.
  • Request Deletion: You may request that we delete your personal information. (Please note that there may be legal reasons for us to keep your data, such as if we receive a law enforcement request asking us to preserve data.). To request account deletion, please contact us at privacy@virtahealth.com with the subject heading “personal information request” using the email address tied to your Virta account.
  • Cookies & Tracking Settings: Adjust your browser or device settings to control cookie and tracking preferences. Note that disabling cookies may limit some features of the Service.

5. Third-Party Tracking and Online Advertising

Interest-Based Advertising

We engage in interest-based advertising, which uses third-party advertising companies to show you ads tailored to your browsing history. These third parties may collect information about your visits to our website using cookies or similar tracking technologies. This data includes your device type, browsing activities, and other details like the time and date of your visits. The collected information helps ensure the ads you see are relevant to your interests, while also supporting reporting, analytics, and market research.

Social Media Widgets and Advertising

Our website may feature social media tools, like Facebook’s "Like" button or similar widgets from Instagram, Twitter, LinkedIn, and others. These tools allow social media companies to identify you, collect details about your visit, and track your activities using cookies or similar methods. When we display targeted ads on platforms like Facebook or Twitter, these ads are managed according to the privacy policies of those companies.

Cross-Device Linking

We and our third-party partners may link the devices you use to provide consistent advertising across devices. For instance, content viewed on one device could influence ads shown on another. This linking uses data like email addresses or user IDs, alongside tracking technologies and statistical modeling tools. The collected information supports personalized advertising, analytics, and campaign performance tracking.

Your Choices

  • Cookies: Most browsers let you manage cookies by notifying you before a cookie is set, disabling existing cookies, or automatically rejecting new ones. Keep in mind that blocking cookies might limit your experience on our site. Deleting cookies will not remove Local Storage Objects (like HTML5 data).
  • Interest-Based Advertising: To opt out of interest-based ads, visit Network Advertising Initiative’s opt-out page or Digital Advertising Alliance’s website.
  • Cross-Device Linking: Opting out of interest-based ads on one device does not apply to all your devices. You’ll need to repeat the process on each browser and device.
  • Mobile Advertising: Limit interest-based ads on mobile devices by enabling “limit ad tracking” (iOS) or “opt out of interest-based ads” (Android). You can also use the AppChoices app for further options.
  • Browser Settings: Some opt-outs require cookies to work. If you change your browser settings, delete cookies, or switch devices, you may need to opt out again.

Google Analytics and Advertising

We use Google Analytics to understand how users interact with our website and to tailor ads to your preferences. This tool links your activities across devices using unique identifiers like user IDs or hashed email addresses. Additionally, we may use Google’s advanced features like Remarketing, Display Network Impression Reporting, and Demographics Reporting to enhance our advertising. For more information on how Google uses this data, visit Google’s Partner Privacy Policy. You can opt out of Google Analytics via the Google Analytics Browser Add-On or manage your ad preferences at Google Ads Preferences Manager.

Exclusions

This policy does not include text messaging opt-in data or consent information, which will not be shared with third parties.

6. Third-Party Services

The Service may contain features or links to Web sites and services provided by third parties, and the Service may allow you to display, use or make available content, data, information, applications or materials from third parties. Any information you provide on third-party sites or services is provided directly to the operators of such services and is subject to those operators’ policies, if any, governing privacy and security, even if accessed through the Service. We are not responsible for the content or privacy and security practices and policies of third-party sites or services to which links or access are provided through the Service. We encourage you to learn about third parties’ privacy and security policies before providing them with information.

7. Use By Minors

The Service is generally intended for use by individuals who are at least eighteen (18) years of age.  If you are under 18 years of age, do not use or access the Service at any time or in any manner. If we learn that a person under 18 years of age has used or accessed the Service or any personally identifiable information has been collected on the Service from persons under 18 years of age, then we will take the appropriate steps to delete this information. If you are a parent or guardian and discover that your child under 18 years of age has obtained an account on or otherwise accessed the Service, please contact us at privacy@virtahealth.com with a subject line of “Removal of Minor Information” to request that we delete the minor’s personally identifiable information from our systems.

8. Data Security

We use certain physical, technical, and administrative measures to protect the integrity and security of personal information that we collect and maintain. We cannot, however, ensure or warrant the security of any information you transmit to us or store on the Service, and you do so at your own risk. We also cannot guarantee that such information may not be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, or administrative measures.

9. Jurisdictional Issues

The Service is intended to be used within certain jurisdictions within the United States and is not intended to subject us to the laws or jurisdiction of any state, country or territory other than that of the United States. Any information you provide to us through use of our Websites may be stored and processed, transferred between and accessed from the United States and other countries that may not guarantee the same level of protection of personal data as the one in which you reside. However, we will handle your Personal Information in accordance with this Privacy Policy regardless of where your Personal Information is stored/accessed.

10. Changes and Updates to this Policy

Please revisit this page periodically to stay aware of any changes to this Policy, which we may update from time to time. If we modify this Policy, we will make it available through the Service and indicate the date of the latest revision. Your continued use of the Service after the revised Policy has become effective indicates that you have read, understood and agreed to the current version of this Policy.

11. Our Contact Information

Please contact us with any questions or comments about this Policy, your personal information, our use and disclosure practices, or your consent choices by email at privacy@virtahealth.com.

Jamie Anderson, Privacy Officer, Virta Health Corp.
440 Barranca Ave #5386, Covina, CA 91723

California Consumer Privacy Act

This notice describes how personal information about you may be used and disclosed and how you can get access to this information. Please review it carefully.

Your Rights.

When it comes to your personal information, you have certain rights. This section explains your rights and some of our responsibilities to help you.

You have a right to know 

  • about the categories of personal information collected from you and how the information will be used;
  • about your personal information that was sold or disclosed for a business purpose

You have a right to request

  • us to delete your personal information.

You have a right to opt-out

  • of the sale of your personal information.

You have a right to access

  • your data and have it be portable.

You have a right to exercise these rights

  • Free from discrimination for exercising them.

Our Uses and Disclosures

We typically collect the following categories of personal information:

  • “Aggregate consumer information” which means information that relates to a group or category of consumers, from which individual consumer identities have been removed, that is not linked or reasonably linkable to any consumer or household, including via a device. “Aggregate consumer information” does not mean one or more individual consumer records that have been de-identified.
  • Geolocation data.
  • “Health insurance information” which means a consumer’s insurance policy number or subscriber identification number, any unique identifier used by a health insurer to identify the consumer, or any information in the consumer’s application and claims history, including any appeals records, if the information is linked or reasonably linkable to a consumer or household, including via a device, by a business or service provider.
  • Personal information” which means identifiers such as a real name, alias, postal address, unique personal identifier, online identifier Internet Protocol address, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers.
  • Internet or other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding a consumer’s interaction with an Internet Web site, application, or advertisement.
  • Professional or employment-related information

Our Responsibilities

We use the personal information that we collect for the following business or commercial purpose(s):

  • Performing Services: including maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing advertising or marketing services, providing analytic services, or providing similar services on behalf of the business or service provider.
  • Undertaking internal research for technological development and demonstration.
  • Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity.

About us

Virta is the first clinically-proven approach to safely and sustainably reverse type 2 diabetes and obesity and is on a mission to reverse it in 1 billion people. Learn how we are rethinking this epidemic.