Privacy Policy
Effective Date: April 11, 2026 · V-GRIP Technologies LLC
1. Introduction
V-GRIP Technologies LLC (“V-GRIP,” “we,” “our,” or “us”) is committed to protecting your privacy and handling your data responsibly. This Privacy Policy describes how we collect, use, store, disclose, and safeguard information when you use the V-GRIP hardware devices, the V-GRIP mobile and web applications, the clinical dashboard, and the vgriptech.com website (collectively, the “Services”).
By creating an account or using any part of our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with these practices, please do not use our Services.
Our platform collects health and fitness data and facilitates communication between healthcare providers and patients. Certain uses of the platform by licensed healthcare providers may involve Protected Health Information (“PHI”) as defined under the Health Insurance Portability and Accountability Act (“HIPAA”). Please see Section 4 for details on how we handle PHI.
2. Information We Collect
2.1 Account Information
When you create or update an account, we collect:
- Name, email address, and phone number
- Role designation (clinician, trainer, coach, patient, or athlete)
- Professional credentials (license number, specialty, clinic or organization name) for clinical and professional users
- Profile photo (optional)
- Password (stored hashed and salted using bcrypt; never in plaintext)
2.2 Health and Fitness Data
Through your use of V-GRIP hardware and software, we collect data that may be classified as protected health information under HIPAA when processed on behalf of a covered entity. This includes:
- Exercise performance data (velocity, range of motion, repetitions, sets, tempo)
- Rehabilitation program compliance and adherence records
- Pain logs (level, location, descriptive notes)
- Injury history and clinical notes entered by healthcare providers
- Clinical condition and diagnosis information associated with rehabilitation programs
- Body metrics (height, weight, date of birth, gender) when provided
- Exercise history and longitudinal performance trends
2.3 Device Sensor Data
V-GRIP hardware contains inertial measurement unit (IMU) sensors, including accelerometers and gyroscopes. When you use the device, we collect:
- Raw and processed accelerometer data
- Raw and processed gyroscope data
- Calculated velocity, orientation, and motion metrics
- Device serial number, firmware version, battery level, and signal strength
- Bluetooth pairing and connectivity metadata
2.4 Communications Data
The platform enables messaging between clinicians, trainers, coaches, and their patients or athletes. We collect and store:
- Messages exchanged between users through the in-app messaging system
- Shared data reports and exercise summaries
- Notification preferences and delivery records
- Communication timestamps and read receipts
2.5 Payment and Transaction Information
When you purchase hardware or subscribe to a paid plan, we collect:
- Billing name and address
- Payment method details (processed securely through our third-party payment processor; we do not store full credit card numbers)
- Transaction history, subscription tier, and billing cycle information
2.6 Usage and Technical Data
When you access our Site or App, we may automatically collect:
- IP address and approximate geolocation
- Device type, operating system, and browser information
- App version, feature usage patterns, and session duration
- Crash reports and performance diagnostics
- Cookies and similar tracking technologies (see Section 8)
3. How We Use Your Information
We use the information we collect for the following purposes:
- Service delivery: Provide real-time exercise feedback, rehabilitation tracking, compliance monitoring, and data visualization
- Clinical workflows: Enable clinicians, trainers, and coaches to create programs, review adherence, share data reports, and communicate with patients and athletes
- Device operation: Pair, calibrate, and deliver firmware updates to V-GRIP hardware
- Notifications: Send compliance alerts, pain spike warnings, session reminders, and periodic summaries based on your preferences
- Product improvement: Analyze aggregated, de-identified usage data to improve our algorithms, features, and user experience
- Billing: Process subscription payments and hardware purchases and manage account status
- Customer support: Respond to inquiries, troubleshoot issues, and provide technical assistance
- Safety and security: Detect, prevent, and address fraud, unauthorized access, and technical issues
- Legal compliance: Meet regulatory, legal, and audit obligations
- Communications: Send service-related notifications and, with your consent, promotional materials
4. HIPAA and Protected Health Information
When V-GRIP is used by a covered entity (e.g., a licensed physical therapist, occupational therapist, physician, or other healthcare provider), the health data processed through our platform may constitute Protected Health Information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA). In such cases:
- V-GRIP Technologies LLC acts as a Business Associate and will execute a Business Associate Agreement (BAA) with covered entity clients prior to processing PHI
- PHI is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Access to PHI is governed by role-based access controls and all access is logged for audit purposes
- We will use and disclose PHI only as permitted by the BAA, HIPAA, and applicable law
- We do not sell, rent, or trade PHI to third parties for marketing or any other unauthorized purposes
- We maintain administrative, physical, and technical safeguards as required by the HIPAA Security Rule
- We will report any unauthorized use or disclosure of PHI (a breach) to the covered entity in accordance with HIPAA Breach Notification requirements
- Our employees and subcontractors who may access PHI are trained on HIPAA compliance and bound by confidentiality obligations
If you are an individual user (not using the platform through a healthcare provider), your health and fitness data is governed by this Privacy Policy and not by HIPAA. However, we apply the same rigorous data security standards to all user data regardless of HIPAA applicability.
5. Data Sharing and Disclosure
We do not sell your personal information or health data to advertisers, data brokers, or other third parties. We may share your information in the following circumstances:
- Your care team: Clinicians, trainers, or coaches you are connected to on the platform can view your exercise data, compliance records, pain logs, and messages as part of the Services
- Service providers: We engage third-party vendors who perform services on our behalf, such as cloud hosting, payment processing, and analytics. These providers operate under data processing agreements and are contractually obligated to protect your data and use it only for the purposes we specify
- Legal requirements: When required by law, court order, subpoena, or governmental regulation, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others
- Business transfers: In connection with a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will provide prior notice of any such change in ownership or control
- Aggregated and de-identified data: We may share aggregated or de-identified data that cannot reasonably be used to identify you for research, analytics, or product development purposes
- With your consent: We may share your information with third parties when you have given us explicit consent to do so
6. Data Security
We implement administrative, technical, and physical safeguards designed to protect your personal information, including:
- All data in transit is encrypted using TLS 1.2 or higher
- Data at rest is encrypted using AES-256
- Passwords are hashed using bcrypt with per-user salts
- Role-based access control limits data visibility to authorized users
- Regular security audits and vulnerability assessments are conducted
- Device communication uses authenticated Bluetooth Low Energy (BLE) with session tokens
- Incident response procedures are in place for potential data breaches
- Employee training on data protection and privacy practices
No system is 100% secure. While we implement industry-standard protections, we cannot guarantee absolute security. If we become aware of a data breach affecting your information, we will notify you in accordance with applicable law.
7. Data Retention
We retain your account and exercise data for as long as your account is active or as needed to provide you with our Services. We may also retain and use your information as necessary to:
- Comply with legal obligations (e.g., billing records retained for 7 years per applicable tax law)
- Resolve disputes and enforce agreements
- Maintain business records as required by applicable law
- Support legitimate business operations using aggregated, de-identified data
If you request account deletion, we will remove your personal data within 30 days, except where retention is required by law, regulation, or legitimate business purposes. Health data shared with a clinician as part of a clinical record may be subject to separate retention requirements under applicable healthcare regulations. Aggregated, de-identified data may be retained indefinitely for product improvement.
8. Cookies and Tracking Technologies
Our Site and App may use cookies, pixels, and similar technologies to:
- Authenticate your session and maintain your login state
- Remember your preferences and settings
- Analyze site traffic and usage patterns
- Improve site performance and user experience
You may control cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of our Services. We do not use cookies to track you across third-party websites for advertising purposes.
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data, subject to certain legal exceptions
- Portability: Export your exercise and compliance data in a structured, machine-readable format
- Restrict processing: Request that we limit how we process your data in certain circumstances
- Objection: Object to the processing of your personal data for certain purposes
- Withdraw consent: Where processing is based on consent, you may withdraw that consent at any time
- Opt-out of marketing: Unsubscribe from promotional communications at any time by using the unsubscribe link or adjusting your account settings
To exercise any of these rights, contact us at privacy@vgriptech.com. We will respond within 30 days or as required by applicable law.
10. State-Specific Privacy Rights
California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) may provide you with additional rights, including the right to know what personal information we collect, the right to delete your personal information, the right to opt out of the sale or sharing of personal information, and the right to non-discrimination for exercising your privacy rights. We do not sell personal information as defined under the CCPA/CPRA.
Other U.S. States
Residents of Virginia, Colorado, Connecticut, Texas, and other states with comprehensive privacy legislation may have similar rights under their respective laws. To exercise any state-specific privacy rights, please contact us using the information provided in Section 13.
11. Children's Privacy
Our Services are not directed to children under 13. We do not knowingly collect personal information from children under 13. If a parent or guardian becomes aware that their child has provided us with personal data without their consent, please contact us at privacy@vgriptech.com and we will take steps to delete such information promptly.
12. Third-Party Links and Integrations
Our Services may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to those third-party services, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you interact with.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the “Effective Date” at the top of this page and notify you via email or a prominent notice within the application at least 30 days before the changes take effect. Your continued use of the Services after the effective date of a revised Privacy Policy constitutes your acceptance of the revised terms.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:
Legal Notice: This Privacy Policy is intended to provide a comprehensive overview of V-GRIP Technologies LLC's data practices. V-GRIP Technologies LLC recommends that all users, and particularly healthcare providers and organizations, consult with qualified legal counsel to ensure compliance with all applicable federal, state, and local laws, including HIPAA, CCPA/CPRA, and other relevant regulations.