Last revised August 1, 2025.
Table of Contents
- Introduction
- Where this Privacy Policy applies
- Information we collect about you and how we collect it
- How we use your information
- Disclosure of your information
- Choices about how we use and disclose your information
- Requests regarding your information
- Information for international users
- Information security and retention
- No medical advice or care
- Not intended for children
- Changes to this Privacy Policy
- Ethical conduct
- Contact us
1. Introduction.
We respect your privacy, and we are committed to protecting it. This Privacy Policy describes how Rise Healthcare Tech, Inc., doing business as both “Ostro” and “RxDefine”, and our affiliates (collectively, “Ostro”, “we” and “us”) collects, uses, and protects information about you in connection with your use of (a) the ostrohealth.com, kinara.co, and rxdefine.com websites and any related or associated websites and domains, (b) via e-mail, text message, phone call, chat, and other electronic communications between you and us (along with all related services and functionality that we provide, and (c) any other interactions you have with us online and offline (collectively, “Services”). You acknowledge and agree that references in this Privacy Policy and elsewhere across the Services to RxDefine, Ostro, Ostro Health or similar terms refer, in each case, to us.
Please read this Privacy Policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, your choice is not to use our Services. By accessing or using our Services, you agree to this Privacy Policy, as well as to our Terms of Use.
This Privacy Policy applies to our processing of your information as a data controller under applicable law. This Privacy Policy does not apply to our processing activities on behalf of customers. In such cases, we act as a processor or service provider on behalf of those customers, and our processing is governed by an applicable agreement with those customers. If you are an end-user of one of our customers and have questions about how your information is processed through the customers’ use of our services, please contact the customer who has provided your information to us for more information. You can also review our Processor Privacy Policy.
2. Where this Privacy Policy applies.
This Privacy Policy applies to information, including information about you, that we collect as part of our Services, including via e-mail, text, chat, phone, or other forms of communication between you and us.
Where we process information on our own behalf, Rise Healthcare Tech, Inc. is the data controller, and our contact information can be found in the section titled “How to contact us” at the end of this Privacy Policy.
This Privacy Policy also does not apply to information collected by any third party website, application, or service that is not part of the Services, including those that may be linked to or accessible from the Services.
3. Information we collect about you and how we collect it.
We collect different types of information about you, including information that may identify you either directly or when combined with other information, information that is about you but does not identify you, and information that we combine with information about our other users.
Examples of the types of information we collect from and about users of our Services:
- Information that is about you as a person, such as, where relevant to the Services, name, address (e.g., home, office, billing), date of birth, gender, contact information (e.g., e-mail, phone), professional information (e.g., if you are a Clinician, including license information and NPI number), insurance information, medical or health history, prescription drug history and status, and other health information or other information supplied by you;
- Commercial information, such as the types of Services you use or purchase or may be interested in using or purchasing;
- Information you voluntarily provide to us, such as in communications with our personnel or in response to surveys; and
- Information that is about your usage of the Services, including:
- Technical information, such as IP address data, traffic data, logs, referring/exit pages, date and time of your visit to or use of our Services, error information, clickstream data, session recordings, location data, and other communication and interaction data and the resources and equipment (e.g., device, browser and other software information, operating system, Internet connection) that you access and use on or through our Services; and
- Interaction information, such as information you provide when communicating to us (e.g., including to request a service or report a problem), information about the resources, Content (as such term is defined in our Terms of Use), materials, information, and other aspects of the Services that you request or access, information about how you access and use the Services (e.g., search and chat queries and other information and documentation about how you navigate and use the Services, such as session recordings), and records and copies of your correspondence and other interactions with the Services.
We collect this information:
- Directly from you when you provide it to us, such as through e-mail, phone calls, text messages, website forms, and our webchat function on our Services, including via the use of third party applications, services, and products that we integrate into our Services;
- Automatically as you navigate through or use our Services; and
- From third parties, for example, our customers, service providers, and business partners.
In addition to collecting data directly from you, we also use the following technologies in connection with certain of our Services:
- Cookies, Local Storage, Session Storage. We, our advertising, marketing, and analytics partners, and customers may use cookies, local storage, session storage, web beacons, and other data collection and analytics technologies to receive and store certain types of information when you interact with our Services. A cookie is a small file or piece of data sent from a website and stored on the hard drive of your computer or mobile device. Local storage and session storage technologies are an alternative to cookies that store and save data locally only. On your device, you may be able to customize how your device interacts with these technologies, for instance by refusing to accept some or all cookies, by activating the appropriate setting in your browser and/or device settings. However, modifying these settings (for example, by refusing cookies) may cause certain parts of our Services to be unavailable to you or to not work as intended.
- Analytics Providers. We may use marketing and analytics service providers, including Google Analytics, a web analytics service provided by Google, Inc. (“Google”) to collect certain information relating to your use of our Services. Google Analytics also utilizes cookies for this purpose. You can find out more about how Google uses data directly from Google, for instance on Google’s website. We may also use Google Analytics Advertising Features or other advertising networks to provide you with interest-based advertising based on your online activity.
- Pixels and Tags. We may use pixels, tags, and similar technologies (i) to help identify what users do after they see or click on an element of our Services and/or an advertisement or other content prior to reaching our Services; (ii) identify users who interact with our Services from different devices; (iii) connect users’ activities across platforms and devices, including enabling online to offline activity connections; and (iv) better understand the effectiveness of our Services and our customers’ and partners’ user initiatives, and improve the content (including advertisements) provided to targeted audiences of interest to us, our customers, and our business partners. Examples of these technologies include Facebook’s pixel and Instagram’s web analytics and advertising service, both provided by Meta Platforms, Inc. (“Meta”); please note, however, that this is not an exhaustive or comprehensive list. Data provided to Meta and other advertising, marketing, and analytics partners in connection with your use of the Services is saved and processed by those third parties, and may be used for their own and others’ purposes in accordance with those companies’ policies and applicable laws. For more information, including how to adjust your privacy preferences or exercise your privacy rights with those companies, please visit their website directly.
For more information generally about online targeted advertising activities and to understand your right to opt out from these practices, please visit: https://youradchoices.com/choices-faq. Additional information on how to opt out of targeted advertising practices of NAI or DAA affiliated advertisers is available here: NAI Opt Out or DAA Opt Out. To further prevent targeted advertising based on browser behavior, you can disable digital tracking tools on your browser. - AI Tools. We may use software, platforms, and applications that utilize data analysis, learning, reasoning, problem solving, perception, prediction, planning or other cognitive functions in an attempt to augment or replicate human intelligence (we refer to these, collectively, as “AI Tools”). Examples of techniques employed by AI Tools include machine learning, deep learning, computer vision, natural language processing, robotics, virtual agents, chatbots, and other emerging technologies that aim to simulate human intelligence. AI Tools may be owned and provided by us and/or by third parties. Our customers may use certain AI Tools that we provide them, such as to enable certain functionality and features of our Services; in such cases, we process your information on their behalf to enable their services subject to our Processor Privacy Policy.
4. How we use your information.
We may use information that we collect about you or that you provide to us to:
- provide you with services, including the Services, associated Content, and our other products and services;
- provide you with other information, products, or services that you request from us or that we believe may be of interest to you;
- administer surveys, sweepstakes, promotions, and contests;
- develop, support, maintain, secure, audit, review, and improve our Services, Content, and other products and services that we may develop from time to time, including to develop, build, improve, and train AI Tools constituting or used as part of the Services (such as usage data from your use of AI Tools on our Services, which is used for product improvement purposes);
- fulfill any other purpose for which you provide such information or otherwise consent to, including as we may describe to you when you provide the information;
- for recruiting and human resources purposes, in particular with respect to applicants and candidates who interact with us through our website or other Services (please note: applicant information is subject to our Applicant Privacy Notice, available here);
- carry out our obligations and enforce our rights arising from any contracts entered into between you and us;
- notify you about changes to our Services or any products or services we offer or provide though them;
- allow us and our advertising and marketing partners to deliver more relevant content to you on our Services and through third-party services and events;
- allow us and our advertising, marketing, and analytics partners to analyze data and information about the provision, use, activity, and performance of our Services, Content, and any other related products and services, including those that we may develop or provide in the future, as well as of their users, including you;
- create aggregated or de-identified information and provide access, disclose, and otherwise use them and related analytics products and services as described above, in whole or in part, including to our customers and other partners as part of the services we offer to them;
- exercise our rights and discharge our obligations under the law, which may including disclosing your information as described in this Privacy Policy;
- enforce our Terms of Use (and other applicable agreements) and comply with laws, regulations, and other legal process and procedures;
- protect the safety, health, rights, property, or security of Ostro, our users, employees and workforce members, third parties, members of the public, and/or the Services, including to maintain and secure our Services and prevent and detect potential fraud;
- communicate with you about any of the above, including to provide you with notices relevant to your use of or changes in the Services and to respond to your requests of us;
Our use of your information, including as described above, is subject to this Privacy Policy and the laws applicable to your privacy and personal information (as such term is defined under applicable law) in connection with your use of our Services (“Privacy Laws”). We will update this Privacy Policy and notify you as required under applicable law.
If you wish to customize or restrict how we use or disclose your information, please see the section of this Privacy Policy entitled “Choices about how we use and disclose your information” and “Requests regarding your information” for more information on how to do so.
5. Disclosure of your information.
We may disclose your information in any of the following circumstances:
- to our affiliates, contractors, service providers, and other third parties in connection with our business. The services provided by these organizations include:
- IT and infrastructure support services;
- information and cybersecurity services;
- payment processing services;
- data analytics services;
- information, product marketing, or content hosting and fulfillment services;
- patient safety, including adverse event or adverse reaction reporting services, including on behalf of our customers;
- internal infrastructure and support services, including communications, product development, user support, and quality assurance;
- recruiting and human resources support services; and
- to our advertising, marketing, and analytics partners, which help us customize the Services and provide you with advertising that we think will be of interest to you;
- to provide marketing related to products or services that we believe you may find of interest;
- to a buyer or other successor in interest of our business in the event of an actual or contemplated merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which user information is among the assets subject to such transaction or otherwise part of the due diligence of such a transaction;
- to fulfill the purpose for which you provide it;
- for any other purpose disclosed by us when you provide the information; and
- with your consent.
We may also disclose your information:
- to comply with any court order, law, or legal process, including to respond to any government or regulatory request;
- to you or your designated agent to allow you to exercise your individual choices under applicable laws with respect to your data;
- to third parties to market their products or services to you;
- to enforce or apply our Terms of Use and other agreements; and
if we believe disclosure is necessary or appropriate to protect the security, health, rights, property, or safety of us, our customers, our users, any member of the public, or others. This includes exchanging information with government agencies and authorities, other companies and organizations for the purposes of fraud protection, information security, credit risk reduction, health and safety, and other lawful purposes.
6. Choices about how we use and disclose your information.
We do not control the collection and use of your information collected by third parties, including our customers and other third parties with which you interact separately from our Services. These third parties may use the information they collect from or about you for their own purposes, which may be different from those described in this Privacy Policy. Please familiarize yourself with the privacy policies and other terms provided by these third parties about their own products and services.
In addition, we strive to provide you with choices regarding the information that you provide to us, such as:
- Tracking technologies. On your device, you may be able to choose to be alerted and/or to refuse to accept some or all cookies or other tracking technologies by activating the appropriate setting in your browser and/or device settings. However, refusing these technologies, including cookies, may cause certain parts of our Services to be unavailable to you or to not work as intended.
Some web browsers permit you to broadcast a signal to websites and online services indicating a preference that they “do not track” your online activities. At this time, while you can disable cookies and/or other tracking technologies as described above, we do not honor or recognize when your browser sends “do not track” signals. We do not modify what information we collect or how we use that information based on whether such a signal is broadcast or received by us. - Text message (SMS) and voice communications. In connection with the Services you may have the opportunity to provide your phone number. By providing your phone number, you are agreeing to be contacted by or on behalf of Ostro at the number you have provided, including calls and text messages, to receive informational or transactional messages and communications relating to the Services. You may also have the option to separately consent to the use of your phone number for additional services and communications, including to receive marketing and/or promotional communications from us or our partners, including as described in this Privacy Policy. Voice and text messages may be sent using automated or nonautomated technology. If you are experiencing issues with any text messaging program or service that is part of the Services please reply with the keyword HELP for further assistance. To stop receiving text messages text a reply to us with the word STOP. We may confirm your opt out by text message. If you subscribe to multiple types of text messages from us, we may unsubscribe you from the service that most recently sent you a message or respond to your STOP message by texting you a request to identify services you wish to stop. Please note that by withdrawing your consent some Services may no longer be available to you.
- Email communications. By providing your e-mail address, you acknowledge that you will be contacted by or on behalf of Ostro at the address you have provided to receive informational, transactional, product or service related, or marketing communications relating to the Services. If you do not wish to have your e-mail address used by us to communicate with you, with respect to marketing or promotional communications, if any, you can opt-out at any time by clicking the unsubscribe link at the bottom of any e-mail or by contacting us at privacy@ostrohealth.com.
- User account settings. For some Services, you may have created a user account (“User Account”) to allow you to access information, communicate with us, and otherwise access and use certain features of the Services that are available only to registered users. If you have created a User Account, you may also adjust certain communication and privacy preferences and settings directly via your User Account.
Please note that the above choices may not apply to or affect our activities as a processor or service provider to our customers. Please refer to the relevant customer’s privacy policy – which is typically accessible from the website, application or other channel from which you accessed our Services – for the choices that the customer may provide to you.
If you have questions about your choices regarding your information, please contact us at privacy@ostrohealth.com or by using the additional information included in the “Contact us” section at the end of this Privacy Policy.
7. Requests regarding your information.
Please note that we are not obligated to respond to requests regarding information that we handle as a processor or service provider to our customers. The relevant customer is responsible for responding to such requests. If you submit a request regarding information for which we are a processor or service provider, we may forward your request to the applicable customer so that they may review and, if appropriate, accommodate your request.
For requests regarding your information for which we are a controller, if a privacy law is in force in your jurisdiction of residence and we are subject to such law with regard to your information, you may be able to request:
- Access to information we have about you or a copy of such information.
- Information about the categories of information we have about you, our purposes for collecting and disclosing this information, and categories of third parties to which we disclose this information.
- Correction of certain information we have about you
- Deletion of certain information we have about you.
- That we opt you out of certain uses and disclosures of your information.
You may email us at privacy@ostrohealth.com to make these requests. Please note your request and the information regarding which you are making the request. If you have created a User Account, you may also be able to make and/or carry out such requests directly via your User Account.
These requests are subject to certain limitations and exceptions. For example, we may not be able to accommodate your request, including because:
- you reside in a jurisdiction where we are not obligated, or are unable, to fulfill your request;
- we have deidentified or anonymized the relevant information;
- we believe that fulfilling your request would violate Privacy Laws or another legal requirement or cause information to be incorrect; and/or
- your request falls within a specific exception under Privacy Laws.
If we decline to fulfill your request, certain Privacy Laws may allow you to appeal this decision. If legally required, we will provide instructions for how to appeal when we notify you that we have declined to fulfill your request.
Finally, we may ask you for additional information in order to better understand and validate your request, including information as reasonably necessary and permitted by Privacy Laws to verify your identity and your right to access and take action with respect to the requested information. If the Privacy Laws applicable to you allow you to authorize an agent to submit requests on your behalf, the agent must provide legally sufficient proof (e.g., power of attorney) that they are authorized to submit the request on your behalf. Before responding to a request by an authorized agent, we may validate the agent’s identity and may also validate your identity directly with you.
Please note that we reserve the right not to respond to requests related to your information if we are not legally required to respond.
8. Information for international users
Ostro is headquartered in the United States, and we may transfer, store, and/or process your information to or with other entities within the Ostro family of companies or other third parties such as trusted service providers and partners in locations around the world for the purposes described in this Privacy Policy. Wherever your information is transferred, stored, or processed by us, we take appropriate steps to protect your information in accordance with this Privacy Policy and applicable laws. These measures may include implementing Standard Contractual Clauses to govern the transfer of your information, or other means recognized by applicable laws. By providing us with your information, you acknowledge any such transfer, storage, or processing.
If you have any concerns or complaints about our data processing activities, we urge you to first try to resolve such issues directly with us. However, if applicable, you may make a complaint to the data protection supervisory authority in the country where you are based, or seek a remedy through local courts if you believe your rights have been violated.
The laws in some jurisdictions also require us to tell you about the legal grounds we rely on to use or disclose your “personal data” (as such term is defined under applicable law) when we act as a data controller. To the extent that those laws apply, our legal grounds are as follows:
- To honor our contractual commitments to you: We process personal data to fulfill customers’ requests in anticipation of entering into a contract with them or in the course of providing services to them. For example, we handle business contact information of prospective customers and customers in furtherance of our contracts with the relevant customer.
- Legitimate interests: In many cases, we handle personal data on the ground that it furthers our legitimate interests in ways that are not overridden by the interests or fundamental rights and freedoms of the affected individuals, such as to fulfill customer service requests, market our services to you, protect our users, personnel and property, and analyze and improve our website.
- Consent: Where required by law, and in some other cases, we handle personal data on the basis of your implied or express consent.
- Legal compliance: We use and disclose personal data in certain ways to comply with our legal obligations.
9. Information security and retention.
We have implemented measures designed to secure your information from accidental loss and from unauthorized access, use, alteration, and disclosure. We use encryption technology, multifactor authorization, and various authentication and identity management tools to safeguard the information sent and received by us.
The safety and security of your information also depends on you. Where you have chosen a password for the use of our Services, you are responsible for keeping this password confidential. We ask you not to share your password with anyone. If you believe that your password may have been compromised please access your User Account and reset it immediately. If you believe that your information may have been compromised or misused, please contact us immediately at privacy@ostrohealth.com.
Unfortunately, the transmission of information via the Internet is not completely secure. Although we do our best to protect your information, we cannot guarantee the security of your information when it is transmitted to, on, or through our Services or otherwise disclosed to us. Any transmission or disclosure of your information is at your own risk.
Generally, we retain your information for as long as it serves the business purpose for which it was collected. If there is a specific retention period required by law or contract, your information will be retained for that length of time.
10. No medical advice or care.
Ostro does not provide medical advice or care. Information communicated to you through our Services is not a substitute for a discussion with a licensed medical practitioner and should never be applied or interpreted as medical advice or any form of personal treatment plan. Please see our Terms of Use for additional details.
11. Not intended for children.
Our Services are intended for general audiences and are not directed at children. If we become aware that we have collected data without legally valid parental consent from children under an age where such consent is required, we will take reasonable steps to delete it as soon as possible. In some instances, certain products or services may be provided through the Services that are intended for use by the caregivers of children; please see our Terms of Use for additional information. If you believe we might have any information from a child for which legally required parental consent was not provided, please contact us immediately at privacy@ostrohealth.com.
12. Changes to this Privacy Policy.
This Privacy Policy may change from time to time. It is our policy to post any changes we make to our Privacy Policy on this page, and to clearly indicate the date on which this Privacy Policy was last updated. Your continued use of our Services after we make changes is deemed to be acceptance of those changes, so please check this Privacy Policy periodically for updates. Where we make material changes that require notice to you under Privacy Laws, we will use commercially reasonable efforts to directly notify you of such change, including by sending you an e-mail if we have an e-mail address for you and/or taking other steps as may be required by such Privacy Law. If you would like to be notified of such changes and would like to provide us with a current e-mail address, please contact us at privacy@ostrohealth.com or, if applicable, access your User Account to update your contact information.
13. Ethical conduct.
We pride ourselves on ethically empowering people like you to navigate their health. If you see or suspect any unethical or illegal activity of any kind in connection with the Services we would appreciate it if you would report it to us immediately so that we may promptly investigate. Please contact us at compliance@ostrohealth.com.
14. Contact us.
If you have any questions, concerns, complaints or suggestions regarding our Privacy Policy or otherwise need to contact us, you may contact us at the contact information below or through any of the various “Contact Us” elements of our Services.
How to Contact Us:
Ostro
382 NE 191st St
# 71935
Miami, Florida 33179-3899
(786) 550-8082
E-mail: privacy@ostrohealth.com