Last modified: May 7, 2026
Boon Movement Inc. (“Boon”, “we”, “our”, and “us”) recognizes the importance of protecting the privacy and the rights of individuals in relation to their personal information.
While Boon’s affiliate, the Do Well Therapy Group Inc. (“Do Well”), operates clinics (each, a “Clinic”) that offer physiotherapy and massage therapy services to provide personalized, hands-on treatment to address pain, mobility limitations, and injuries, this Privacy Policy solely describes our privacy practices as it relates to Boon’s mobile application and web platform, accessible via www.boonmovement.com (collectively, the “App”), which is independent from the Clinics. For more information on how the Clinics or our affiliated entity, Do Well, and their website handle your personal information please go to: https://www.dowelltherapy.ca/privacy-policy.
This App-focused privacy policy describes:
For further clarity, this policy applies to the following individual users of our Services:
We will only collect, use or disclose your personal information in accordance with this policy unless otherwise required or permitted by applicable law. This policy applies only to information we collect, use or disclose when you communicate with us via email, text or on the phone regarding our Services or when you sign up for or use our Services. This policy does not apply to any personal information, including personal health information, that is collected by physiotherapists in their capacity as health information custodians; please review the privacy policies of your physiotherapist (or the organization they may be affiliated with) to understand how they may process personal information they collect from or about you. Remember that even though your Practitioner may use the Boon App to provide you with services and access to your information, Boon is not responsible for how the Practitioner handles your information; Boon is simply a service provider to your Practitioner.
From the perspective of a customer: Boon gives you access to your personalized exercise program from your Practitioner on your mobile or computer device. It allows you to share your program with other practitioners for better continuity and collaboration.
From the perspective of a Practitioner: Boon provides a platform for creating exercise programs for your clients using personalized content and video library.
Interaction of the customer and Practitioner via the Boon App: The Practitioner will create a program of exercises for the client. These programs can consist of exercises from personalized exercise videos of the client, the Boon Movement Library, or custom exercise videos created by the Practitioner for the client. The client will have the ability to play these videos as a reference for their exercise program and share this program with other health care professionals.
Personal information means any information about an identifiable individual, including information that can be used to identify you. This includes your name, email address, telephone number and payment information. Personal information does not include any contact information that is solely used to communicate with you in relation to your employment, business or profession, such as your name, position name or title, work address, work telephone number, or work e-mail address.
Personal information also does not include information that has been anonymized or aggregated in such a way that there is no serious possibility it can be used to identify an individual, whether on its own or in combination with other information.
If you download, install, sign-up for, access, or use our App or Services, we may collect the following types of information directly from you or when you use our Services, as outlined below.
Personal information. We generally collect your personal information to provide you our services, to communicate with you, and to manage our business. The type of personal information collected via the Services will depend on whether you are a customer (i.e., end-user) or Practitioner. For more information on why we collect your personal information go to the section How we use your information below.
Account information (collected when you create or update your account on the Boon App):
Location data (collected to provide you with personalized recommendations for care providers near you; you can use the App without letting us collect your precise location, but you will have to type your location into your phone instead of allowing us to detect it for you):
Demographic data (collected to enable certain features in the App):
User content (collected when you or your Practitioner upload information about your care needs, or when you provide feedback for your care providers):
Practitioner roster information:
Patient User Authentication Data:
Social media. If you login to our Services using a third-party sign-in service, such as Google, Facebook Connect or Twitter, we will receive personal information from those services, such as your name and email address in order to pre-populate our online forms.
We also include social media “Like” and “Share” buttons on our websites. These features may collect your IP address and the page you are visiting on our website. They may also set a cookie to enable the feature to function properly. Your interactions with these features are governed by the privacy policies of the third parties who provide them.
Google or Apple Calendar. If you choose to connect your Google or Apple Calendar with our Services, we will collect your calendar information from Google or Apple for the purposes of displaying “external events” on your schedule within the Services and to send push notifications.
We only collect Google Calendar or Apple Calendar metadata, which includes a list of your calendars, the start time, end time and duration of calendar events, and a unique event identifier from Google/Apple. We do not collect event titles, descriptions, attendees or other personal information. If you disconnect your Google Calendar or Apple Calendar from the Services, we will delete the Google/Apple credentials, metadata, and all associated “external events” from our Services.
Account information (collected when you create or update your account on the Boon App):
Patient data. Practitioners use our App to collect personal information from their patients to create patient records and to create personalized care plans (“Patient Data”). This information is sometimes referred to as “personal health information”, “protected health information”, “data concerning health” or “sensitive data” depending on the location of the Practitioners and the privacy laws applicable to them.
Non-personal information. This is information that does not directly or indirectly reveal your identity or directly relate to an identified individual, such as demographic information, or statistical or aggregated information. Statistical or aggregated data does not directly identify a specific person, but we may derive non-personal statistical or aggregated data from personal information. For example, we may aggregate personal information to calculate the percentage of users accessing a specific App feature.
Technical information: your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, or information about your internet connection, the equipment you use to access our Website or App, and usage details.
Interaction data. This is non-personal details collected to provide information about your App interactions, including details and information about how you use our App and Services such as events and venues you viewed or searched for, length of visits to certain pages, page interaction information (such as scrolling and clicks), and methods used to browse away from the page.
We use different methods to collect your information, including through:
Information you provide to us. This information may include:
Information provided by Practitioners that is linked to your account. This may include recommendations for exercises to undertake.
Information collected through automated technologies or interactions. As you navigate through and use our App, we may automatically collect through cookies, web beacons, and other tracking technologies the following types of data: usage details, traffic data, logs, location data and information about your phone and internet connection, including your IP address, operating system, and browser type. Please see Automatic data collection technologies below for more information.
Third parties. For example, from our business partners or clinics who have your consent to share your personal information with us.
We use information that we collect about you or that you provide to us, including any personal information, in the following ways.
Creating, updating and verifying your account on the App. This includes setting up and managing your account, verifying compliance with our legal obligations, protecting the integrity of the account, and for fraud detection purposes. Data used: first and last name; login information, including username, password and Multi-Factor Authentication data; demographic information; location information.
Enabling certain services and features. This includes sharing your information with clinics, physiotherapists and massage therapists for the purpose of providing the Services, including to schedule and manage appointments and billings. Data used: demographic information; interaction data; account information; payment information.
Enabling Practitioners to share Patient Data. This allows Boon to permit approved Practitioners to share videos or other after-care information with you. Data used: Patient User Authentication Data.
Communication and customer support. We may use the information collected from you to answer inquiries, provide information or advice about existing and new services, effectively respond to your customer service requests, and assess and improve our App, services, marketing, or customer relationships and experiences. We may also use your information to process and respond to any complaint made by you. Data used: account information; interaction data; location information; usage history.
Marketing and advertising. We collect certain information to send communications requested by you, and for administrative, marketing and advertising (including direct marketing, such as SMS text messages, emails, and newsletters), planning, product or service development, quality control, and research purposes. Data used: account information; interaction data.
Legal proceedings and requirements. We use data to carry out our obligations and enforce our rights arising from any agreements that we may have with you, including for billing and collection or to comply with our legal obligations. We also use your information to satisfy requirements under and/or for purposes of compliance with applicable laws, regulations, operating licenses, agreements or insurance policies; or pursuant to legal process or governmental request, including from law enforcement. Data used: account information; demographic information; interaction data; location data.
Creating, updating and verifying your account on the App. This includes setting up and managing your account, verifying compliance with our legal obligations, protecting the integrity of the account, and for fraud detection purposes. Data used: first and last name; login information, including username, password and Multi-Factor Authentication data; demographic information; location information.
Enabling certain services and features. This includes sharing your information with customers for the purpose of providing the Services, including to schedule and manage appointments and billings. Data used: demographic information; interaction data; account information; payment information.
Communication and customer support. We may use the information collected from you to answer inquiries, provide information or advice about existing and new services, effectively respond to your customer service requests, and assess and improve our App, services, marketing, or customer relationships and experiences. We may also use your information to process and respond to any complaint made by you. Data used: account information; interaction data; location information; usage history.
Marketing and advertising. We collect certain information to send communications requested by you, and for administrative, marketing and advertising (including direct marketing, such as SMS text messages, emails, and newsletters), planning, product or service development, quality control, and research purposes. Data used: account information; interaction data.
Legal proceedings and requirements. We use data to carry out our obligations and enforce our rights arising from any agreements that we may have with you, including for billing and collection or to comply with our legal obligations. We also use your information to satisfy requirements under and/or for purposes of compliance with applicable laws, regulations, operating licenses, agreements or insurance policies; or pursuant to legal process or governmental request, including from law enforcement. Data used: account information; demographic information; interaction data; location data.
Practitioners retain sole control over Patient Data and may be referred to as a “health information custodian”, a “covered entity” or a “controller” depending on their location and the privacy laws applicable to them. Practitioners determine:
Our role. We are a service provider to the Practitioner and may be referred to as an “agent”, “business associate” or “processor” of the Practitioners. Practitioners are responsible for complying with laws and regulations governing the collection, use and disclosure of Patient Data, and for determining the legal basis for such processing. For further clarity, Boon has no control over Patient Data, and Boon will only access Patient Data under the following circumstances: on the written instructions of the Practitioner or where needed in order to prevent or address technical problems; your written requests for support; or if required by law or court order. Please note that for privacy and cybersecurity reasons, Boon may need to verify the identity of the person requesting access prior to granting such requests.
If you have concerns about the Patient Data collected in the App as part of our Services, please contact your Practitioner directly.
A Practitioner may be able to upload or share videos, audios or other clinical notes via the Boon App. Please note that while the Practitioner may be able to share information and files with you, they will not have access to any information on or associated with your account.
We may disclose your personal information to:
We may also disclose your personal information:
We only collect information by lawful means. As part of using our Services or interacting with us, we may collect and process some details about you. When we do so, we will collect, use or share your personal information with your consent for the purposes identified or as otherwise permitted or required by law. In compliance with our privacy obligations, we may obtain your permission based on implied consent (including through this privacy policy) or through other means (such as express consent). However, in some situations, the law allows us to collect, use or disclose personal information without your consent.
You can withdraw your consent to the collection, use or disclosure of your information at any time. However, in some cases withdrawing consent will mean that we can no longer provide you with certain services or perform certain tasks where the information is required to do so.
You may withdraw your consent to the collection, use or disclosure of your or your child’s personal information at any time by contacting the Privacy Officer (see Contact information below) and, subject to any legal constraints, we will comply with your request.
We may send you direct marketing communications and information about our services that we consider may be of interest to you. These communications may be sent in various forms, including mail, SMS, fax, and email, in accordance with applicable marketing laws, such as Canada’s Anti-Spam Legislation (CASL). If you indicate a preference for a method of communication, we will endeavour to use that method whenever practical to do so. In addition, at any time you may opt-out of receiving marketing communications from us by contacting us (see Contact information below) or by using the unsubscribe mechanisms provided in our marketing communications.
We do not provide your personal information to other organizations for the purposes of direct marketing.
We may also use these technologies to collect information about your online activities over time and across third-party websites or other online services (behavioural tracking). To learn more or to opt-out of tailored advertising, please visit the Digital Advertising Alliance of Canada Opt-Out Tool for information on how you can opt out of behavioural tracking on this website and how we respond to web browser signals and other mechanisms that enable consumers to exercise choice about behavioural tracking.
The information we collect automatically is statistical information and may include personal information, and we may maintain it or associate it with personal information we collect in other ways, that you provide to us, or receive from third parties. It helps us to improve our website and to deliver a better and more personalized service, including by enabling us to:
The technologies we use for this automatic data collection may include:
Cookies (or browser cookies). A cookie is a small file placed on the hard drive of your smartphone. You may refuse to accept browser cookies by activating the appropriate setting on your smartphone. However, if you select this setting, you may be unable to access certain parts of our App. Unless you have adjusted your settings so that it will refuse cookies, our system will issue cookies when you open our App. These include the following:
Some content or applications on the App, including advertisements, are served by third parties, including advertisers, ad networks and servers, content providers, and application providers. These third parties may use cookies alone or in conjunction with web beacons or other tracking technologies to collect information about you when you use our App. We also use third party analytics services, such as Google Analytics, on our App to help us analyze how users interact with and use our Services, compile reports regarding activity on our Services, and provide other services. The information that third parties collect may be associated with your personal information or they may collect information, including personal information, about your online activities over time and across different websites and other online services, plus technical data such as your IP address, browser type and version, time of visit, whether you are a return visitor, or any referring website. They may use this information to provide you with interest-based (behavioural) advertising or other targeted content. Third party analytics services use cookies and other tracking technologies to collect information about your use of our services, plus technical data such as your IP address, browser type and version, time of visit, whether you are a return visitor, or any referring website. The information generated by these analytics services will be transmitted to and stored by them and will be subject to their privacy policies.
You can opt-out of several third-party ad servers’ and networks’ cookies simultaneously by using an opt-out tool created by the Digital Advertising Alliance of Canada. You can also access these websites to learn more about online behavioural advertising and how to stop websites from placing cookies on your device. Opting out of a network does not mean you will no longer receive online advertising. It does mean that the network from which you opted out will no longer deliver ads tailored to your web preferences and usage patterns. To opt out of Google Analytics tracking, visit https://tools.google.com/dlpage/gaoptout. Information collected through cookies is used anonymously for analytical purposes.
We do not control these third parties’ tracking technologies or how they are used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly. For more information about how you can opt out of receiving targeted advertising from many providers, see Choices about how we use and disclose your information.
Boon owns the statistical usage data derived from your use of the App or Services, including any partner applications and services integrated for use with the App, such as: IP addresses, web browser type, operating system information, information about the parts of the App that you access and use, the date and time of your access and use of the Services and in-application time, actions within the App, crashes and other system activity on the App, certain content that you download from the App, configurations, log data, feature access, and the performance results for the App (“Usage Data”). The Usage Data is not personal health information. You agree that the Usage Data will be owned by Boon without providing additional compensation to you, the Practitioner, or any other person and without any liability whatsoever. Boon may utilize the Usage Data to optimize and improve the App, retain customers, or otherwise operate or market Boon’s business.
We may transfer personal information that we collect or that you provide as described in this policy to contractors and service providers we use to support our business (such as analytics and search engine providers that assist us with App improvement and optimization) and who are contractually obligated to keep personal information confidential, use it only for the purposes for which we disclose it to them, and to process the personal information with the same standards set out in this policy.
The security of your personal information is very important to us. We may hold your information in either electronic or hard copy form. We take reasonable steps to ensure your personal information is protected from misuse and loss and from unauthorized access, modification, or disclosure. We store all information you provide to us behind firewalls on our secure servers. Any payment transactions and information including your account information and demographic data, video recordings of clients, programs created for clients, records of program changes, and exercises created for clients, will be encrypted at rest and in transit between the client and server using SSL technology. Our email providers use opportunistic encryption when sending emails, if your email provider supports this. This type of encryption ensures that the emails are encrypted in transit between our email provider and your email provider.
When you use the App offline, certain information — including programs, exercises, and associated media that your Practitioner has shared with you — may be cached on your device so that it remains available without an internet connection. This on-device cache is encrypted using industry-standard encryption (AES-GCM via Apple CryptoKit on iOS) and is erased when you sign out of the App or delete your account.
The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our App, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.
Unfortunately, no data transmission over the Internet can be guaranteed to be totally secure. Accordingly, any personal information or other information which you transmit to us online is transmitted at your own risk. We endeavour to take all reasonable steps to protect the personal information you may transmit to us or from our online services. Once we do receive your transmission, we will also make our best efforts to ensure its security on our systems.
Except as otherwise permitted or required by applicable law or regulation, we will only retain your personal information for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. Under some circumstances we may anonymize your personal information so that it can no longer be associated with you. We reserve the right to use such anonymous and de-identified data for any legitimate business purpose without further notice to you or your consent.
Our App may include links to third-party websites, plug-ins, services, social networks, or applications (collectively, “Third-Party Services”). Clicking on those links or enabling those connections may allow the third party to collect or share data about you. If you follow a link to a Third-Party Service, please note that these third parties have their own privacy policies, and we do not accept any responsibility or liability for these policies. We do not control these Third-Party Services, and we encourage you to read the privacy policy of every Third-Party Service prior to use.
We strive to provide you with choices regarding the personal information you provide to us. We have created mechanisms to provide you with the following control over your information:
Tracking Technologies and Advertising. You can set your App settings to refuse all or some browser cookies, or to alert you when cookies are being sent. If you disable or refuse cookies, please note that some parts of our App may not be accessible or may not function properly. For more information about tracking technologies, see Automatic data collection technologies above.
Location Data. You can choose whether to allow the App to collect and use real-time information about your device's location through the device's privacy settings. If you block the use of location, some parts of the App may be inaccessible or not function properly.
Promotional Offers from the Company. If you have opted in to receive certain emails or texts from us but no longer wish for us to use your contact information to promote our own or third parties' products or services, you can opt-out by clicking the unsubscribe link normally located at the bottom of the email or by contacting us using the information outlined below. If we have sent you a promotional email or text, you may unsubscribe by clicking the unsubscribe link we have included in the email, or by following instructions in the SMS communications we send you. You can also always opt-out by logging into the App and adjusting your user preferences in your account profile by checking or unchecking the relevant boxes.
Third-Party Advertising. If you do not want us to share your personal information with unaffiliated or non-agent third parties for promotional purposes, you can opt-out by checking the relevant box located on the form where we collect your data. You can also opt-out by contacting us (see Contact information below).
Targeted Advertising. If you do not want us to use information that we collect or that you provide to us to deliver advertisements according to our advertisers’ target-audience preferences, you can opt out by contacting us (see Contact information below).
We do not control third parties’ collection or use of your information to serve interest-based advertising. However, these third parties may provide you with ways to choose not to have your information collected or used in this way. You can opt out of several third-party ad servers’ and networks’ cookies simultaneously by using an opt-out tool created by the Digital Advertising Alliance of Canada. You can also access these websites to learn more about online behavioural advertising and how to stop websites from placing cookies on your device. Opting out of a network does not mean you will no longer receive online advertising. It does mean that the network from which you opted out will no longer deliver ads tailored to your web preferences and usage patterns.
You may request access to any personal information we hold about you at any time by contacting us (see Contact information below). Where we hold information that you are entitled to access, we will try to provide you with suitable means of accessing it (for example, by emailing it to you).
If you believe that personal information we hold about you is incorrect, incomplete, or inaccurate, then you may request us to amend it. We will consider whether the information requires amendment. If we do not agree that there are grounds for amendment, then we will add a note to the personal information stating that you disagree with it, together with your requested amendment. If we correct your personal information, we will, so far as is reasonably practicable, inform every other person to whom we have disclosed that information of the correction.
We may request specific information from you to help us confirm your identity and your right to access, and to provide you with the personal information that we hold about you or to give effect to other data subject rights you may be entitled to. In certain situations, we may not be able to fulfil your request. If that is the case, we'll explain the reasons for our decision when responding to your request. For example, in some cases the information you request access to may contain details about other individuals, or there may be legal, security, or commercial proprietary reasons why information is withheld.
You may delete your Boon account at any time from within the App: Settings → Account → Delete Account. On confirmation:
If you are unable to access your account, you may request deletion by contacting our Privacy Officer (see Contact information below). We may need to verify your identity before processing such requests.
Records held by your Practitioner. Your Practitioner is the health information custodian (or equivalent under applicable law) for clinical records they create about you. They may retain copies of those records separately from your Boon account, to meet their own legal record-keeping obligations. Boon does not control those copies. To request deletion of records held by your Practitioner, contact your Practitioner directly. See also Practitioner's ability to upload or share your Patient Data to a Boon account associated with you above.
Retention while your account is active. As described in Data retention above, we retain information only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements.
The Services that Boon offers are not directed to individuals under the age of thirteen (13) and we do not knowingly collect personal information from individuals under 13. Where individuals under 13 seek to access our Services, we require express parental and legal guardian consent and will verify the authenticity of such consent prior to processing. We also require that parents and legal guardians monitor their children's usage of the App and to help enforce our Privacy Policy by instructing their children never to provide personal information through the Services without their permission. If you have reason to believe that a child under the age of 13 has provided personal information to us through the Services without your express prior consent, please contact us using the Contact information below and we will endeavour to delete that information from our systems and databases.
We welcome your questions, comments, complaints and requests regarding this privacy policy and our privacy practices. Please contact our Privacy Officer by emailing privacy@boonmovement.com.
We have procedures in place to receive and respond to complaints or inquiries about our handling of personal information, our compliance with this policy, and with applicable privacy laws. To discuss our compliance with this policy please contact our Privacy Officer using the contact information listed above. Please note that we may need to confirm your identity or request additional details in order to process your request.
We may change this privacy policy from time to time. Any updated versions of this privacy policy will be posted on Boon's App and will be effective from the date of posting. You are responsible for checking if any amendments have been made to this privacy policy. Your continued use of our App or our Services following a change to this privacy policy will constitute your consent to the collection, use, and disclosure of your personal information as described in the amended privacy policy.
Last modified: May 7, 2026
This summary provides key points from our Privacy Policy, but you can find out more details about any of these topics by clicking the link following each key point.
What information do we collect? If you download, install, sign-up for, access, or use our App, web platform or Services, we may collect certain personal information, non-personal information, technical information, and interaction data directly from you or when you use our Services. Learn more about information we collect about you.
How do we collect your personal information? We use different methods to collect your information, including through the information you provide to us, information provided by Practitioners that is linked to your account, information collected through automated technologies or interactions, or third parties. Learn more about how we collect your personal information.
How do we use your information? We use your information, including personal information, in various ways, including but not limited to: creating, updating and verifying your account on the App; enabling certain services and features; enabling Practitioners to share Patient Data; and communication and customer support. Learn more about these and the other ways that we use your information.
How do we share your information? We may disclose your personal information to provide, improve, and administer our Services, for security and fraud prevention, and to comply with law. We may also share your information for other purposes with your consent. Learn more about how we share your information.
How do we keep your information safe? We take reasonable steps to ensure your personal information is protected from misuse and loss and from unauthorized access, modification, or disclosure. Learn more about security of your information.
For more information, review the Privacy Policy in full.
Boon Movement Inc. (“Boon”, “we”, “our”, and “us”) recognizes the importance of protecting the privacy and the rights of individuals in relation to their personal information.
While Boon’s affiliate, the Do Well Therapy Group Inc. (“Do Well”), operates clinics (each, a “Clinic”) that offer physiotherapy and massage therapy services to provide personalized, hands-on treatment to address pain, mobility limitations, and injuries, this Privacy Policy solely describes our privacy practices as it relates to Boon’s mobile application and web platform, accessible via www.boonmovement.com (collectively, the “App”), which is independent from the Clinics. For more information on how the Clinics or our affiliated entity, Do Well, and their website handle your personal information please go to: https://www.dowelltherapy.ca/privacy-policy.
This App-focused privacy policy describes:
For further clarity, this policy applies to the following individual users of our Services:
We will only collect, use or disclose your personal information in accordance with this policy unless otherwise required or permitted by applicable law. This policy applies only to information we collect, use or disclose when you communicate with us via email, text or on the phone regarding our Services or when you sign up for or use our Services. This policy does not apply to any personal information, including personal health information, that is collected by physiotherapists in their capacity as health information custodians; please review the privacy policies of your physiotherapist (or the organization they may be affiliated with) to understand how they may process personal information they collect from or about you. Remember that even though your Practitioner may use the Boon App to provide you with services and access to your information, Boon is not responsible for how the Practitioner handles your information; Boon is simply a service provider to your Practitioner.
From the perspective of a customer: Boon gives you access to your personalized exercise program from your Practitioner on your mobile or computer device. It allows you to share your program with other practitioners for better continuity and collaboration.
From the perspective of a Practitioner: Boon provides a platform for creating exercise programs for your clients using personalized content and video library.
Interaction of the customer and Practitioner via the Boon App: The Practitioner will create a program of exercises for the client. These programs can consist of exercises from personalized exercise videos of the client, the Boon Movement Library, or custom exercise videos created by the Practitioner for the client. The client will have the ability to play these videos as a reference for their exercise program and share this program with other health care professionals.
Personal information means any information about an identifiable individual, including information that can be used to identify you. This includes your name, email address, telephone number and payment information. Personal information does not include any contact information that is solely used to communicate with you in relation to your employment, business or profession, such as your name, position name or title, work address, work telephone number, or work e-mail address.
Personal information also does not include information that has been anonymized or aggregated in such a way that there is no serious possibility it can be used to identify an individual, whether on its own or in combination with other information.
If you download, install, sign-up for, access, or use our App or Services, we may collect the following types of information directly from you or when you use our Services, as outlined below.
Personal information. We generally collect your personal information to provide you our services, to communicate with you, and to manage our business. The type of personal information collected via the Services will depend on whether you are a customer (i.e., end-user) or Practitioner. For more information on why we collect your personal information go to the section How we use your information below.
Account information (collected when you create or update your account on the Boon App):
Location data (collected to provide you with personalized recommendations for care providers near you; you can use the App without letting us collect your precise location, but you will have to type your location into your phone instead of allowing us to detect it for you):
Demographic data (collected to enable certain features in the App):
User content (collected when you or your Practitioner upload information about your care needs, or when you provide feedback for your care providers):
Practitioner roster information:
Patient User Authentication Data:
Social media. If you login to our Services using a third-party sign-in service, such as Google, Facebook Connect or Twitter, we will receive personal information from those services, such as your name and email address in order to pre-populate our online forms.
We also include social media “Like” and “Share” buttons on our websites. These features may collect your IP address and the page you are visiting on our website. They may also set a cookie to enable the feature to function properly. Your interactions with these features are governed by the privacy policies of the third parties who provide them.
Google or Apple Calendar. If you choose to connect your Google or Apple Calendar with our Services, we will collect your calendar information from Google or Apple for the purposes of displaying “external events” on your schedule within the Services and to send push notifications.
We only collect Google Calendar or Apple Calendar metadata, which includes a list of your calendars, the start time, end time and duration of calendar events, and a unique event identifier from Google/Apple. We do not collect event titles, descriptions, attendees or other personal information. If you disconnect your Google Calendar or Apple Calendar from the Services, we will delete the Google/Apple credentials, metadata, and all associated “external events” from our Services.
Account information (collected when you create or update your account on the Boon App):
Patient data. Practitioners use our App to collect personal information from their patients to create patient records and to create personalized care plans (“Patient Data”). This information is sometimes referred to as “personal health information”, “protected health information”, “data concerning health” or “sensitive data” depending on the location of the Practitioners and the privacy laws applicable to them.
Non-personal information. This is information that does not directly or indirectly reveal your identity or directly relate to an identified individual, such as demographic information, or statistical or aggregated information. Statistical or aggregated data does not directly identify a specific person, but we may derive non-personal statistical or aggregated data from personal information. For example, we may aggregate personal information to calculate the percentage of users accessing a specific App feature.
Technical information: your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, or information about your internet connection, the equipment you use to access our Website or App, and usage details.
Interaction data. This is non-personal details collected to provide information about your App interactions, including details and information about how you use our App and Services such as events and venues you viewed or searched for, length of visits to certain pages, page interaction information (such as scrolling and clicks), and methods used to browse away from the page.
We use different methods to collect your information, including through:
Information you provide to us. This information may include:
Information provided by Practitioners that is linked to your account. This may include recommendations for exercises to undertake.
Information collected through automated technologies or interactions. As you navigate through and use our App, we may automatically collect through cookies, web beacons, and other tracking technologies the following types of data: usage details, traffic data, logs, location data and information about your phone and internet connection, including your IP address, operating system, and browser type. Please see Automatic data collection technologies below for more information.
Third parties. For example, from our business partners or clinics who have your consent to share your personal information with us.
We use information that we collect about you or that you provide to us, including any personal information, in the following ways.
Creating, updating and verifying your account on the App. This includes setting up and managing your account, verifying compliance with our legal obligations, protecting the integrity of the account, and for fraud detection purposes. Data used: first and last name; login information, including username, password and Multi-Factor Authentication data; demographic information; location information.
Enabling certain services and features. This includes sharing your information with clinics, physiotherapists and massage therapists for the purpose of providing the Services, including to schedule and manage appointments and billings. Data used: demographic information; interaction data; account information; payment information.
Enabling Practitioners to share Patient Data. This allows Boon to permit approved Practitioners to share videos or other after-care information with you. Data used: Patient User Authentication Data.
Communication and customer support. We may use the information collected from you to answer inquiries, provide information or advice about existing and new services, effectively respond to your customer service requests, and assess and improve our App, services, marketing, or customer relationships and experiences. We may also use your information to process and respond to any complaint made by you. Data used: account information; interaction data; location information; usage history.
Marketing and advertising. We collect certain information to send communications requested by you, and for administrative, marketing and advertising (including direct marketing, such as SMS text messages, emails, and newsletters), planning, product or service development, quality control, and research purposes. Data used: account information; interaction data.
Legal proceedings and requirements. We use data to carry out our obligations and enforce our rights arising from any agreements that we may have with you, including for billing and collection or to comply with our legal obligations. We also use your information to satisfy requirements under and/or for purposes of compliance with applicable laws, regulations, operating licenses, agreements or insurance policies; or pursuant to legal process or governmental request, including from law enforcement. Data used: account information; demographic information; interaction data; location data.
Creating, updating and verifying your account on the App. This includes setting up and managing your account, verifying compliance with our legal obligations, protecting the integrity of the account, and for fraud detection purposes. Data used: first and last name; login information, including username, password and Multi-Factor Authentication data; demographic information; location information.
Enabling certain services and features. This includes sharing your information with customers for the purpose of providing the Services, including to schedule and manage appointments and billings. Data used: demographic information; interaction data; account information; payment information.
Communication and customer support. We may use the information collected from you to answer inquiries, provide information or advice about existing and new services, effectively respond to your customer service requests, and assess and improve our App, services, marketing, or customer relationships and experiences. We may also use your information to process and respond to any complaint made by you. Data used: account information; interaction data; location information; usage history.
Marketing and advertising. We collect certain information to send communications requested by you, and for administrative, marketing and advertising (including direct marketing, such as SMS text messages, emails, and newsletters), planning, product or service development, quality control, and research purposes. Data used: account information; interaction data.
Legal proceedings and requirements. We use data to carry out our obligations and enforce our rights arising from any agreements that we may have with you, including for billing and collection or to comply with our legal obligations. We also use your information to satisfy requirements under and/or for purposes of compliance with applicable laws, regulations, operating licenses, agreements or insurance policies; or pursuant to legal process or governmental request, including from law enforcement. Data used: account information; demographic information; interaction data; location data.
Practitioners retain sole control over Patient Data and may be referred to as a “health information custodian”, a “covered entity” or a “controller” depending on their location and the privacy laws applicable to them. Practitioners determine:
Our role. We are a service provider to the Practitioner and may be referred to as an “agent”, “business associate” or “processor” of the Practitioners. Practitioners are responsible for complying with laws and regulations governing the collection, use and disclosure of Patient Data, and for determining the legal basis for such processing. For further clarity, Boon has no control over Patient Data, and Boon will only access Patient Data under the following circumstances: on the written instructions of the Practitioner or where needed in order to prevent or address technical problems; your written requests for support; or if required by law or court order. Please note that for privacy and cybersecurity reasons, Boon may need to verify the identity of the person requesting access prior to granting such requests.
If you have concerns about the Patient Data collected in the App as part of our Services, please contact your Practitioner directly.
A Practitioner may be able to upload or share videos, audios or other clinical notes via the Boon App. Please note that while the Practitioner may be able to share information and files with you, they will not have access to any information on or associated with your account.
We may disclose your personal information to:
We may also disclose your personal information:
We only collect information by lawful means. As part of using our Services or interacting with us, we may collect and process some details about you. When we do so, we will collect, use or share your personal information with your consent for the purposes identified or as otherwise permitted or required by law. In compliance with our privacy obligations, we may obtain your permission based on implied consent (including through this privacy policy) or through other means (such as express consent). However, in some situations, the law allows us to collect, use or disclose personal information without your consent.
You can withdraw your consent to the collection, use or disclosure of your information at any time. However, in some cases withdrawing consent will mean that we can no longer provide you with certain services or perform certain tasks where the information is required to do so.
You may withdraw your consent to the collection, use or disclosure of your or your child’s personal information at any time by contacting the Privacy Officer (see Contact information below) and, subject to any legal constraints, we will comply with your request.
We may send you direct marketing communications and information about our services that we consider may be of interest to you. These communications may be sent in various forms, including mail, SMS, fax, and email, in accordance with applicable marketing laws, such as Canada’s Anti-Spam Legislation (CASL). If you indicate a preference for a method of communication, we will endeavour to use that method whenever practical to do so. In addition, at any time you may opt-out of receiving marketing communications from us by contacting us (see Contact information below) or by using the unsubscribe mechanisms provided in our marketing communications.
We do not provide your personal information to other organizations for the purposes of direct marketing.
We may also use these technologies to collect information about your online activities over time and across third-party websites or other online services (behavioural tracking). To learn more or to opt-out of tailored advertising, please visit the Digital Advertising Alliance of Canada Opt-Out Tool for information on how you can opt out of behavioural tracking on this website and how we respond to web browser signals and other mechanisms that enable consumers to exercise choice about behavioural tracking.
The information we collect automatically is statistical information and may include personal information, and we may maintain it or associate it with personal information we collect in other ways, that you provide to us, or receive from third parties. It helps us to improve our website and to deliver a better and more personalized service, including by enabling us to:
The technologies we use for this automatic data collection may include:
Cookies (or browser cookies). A cookie is a small file placed on the hard drive of your smartphone. You may refuse to accept browser cookies by activating the appropriate setting on your smartphone. However, if you select this setting, you may be unable to access certain parts of our App. Unless you have adjusted your settings so that it will refuse cookies, our system will issue cookies when you open our App. These include the following:
Some content or applications on the App, including advertisements, are served by third parties, including advertisers, ad networks and servers, content providers, and application providers. These third parties may use cookies alone or in conjunction with web beacons or other tracking technologies to collect information about you when you use our App. We also use third party analytics services, such as Google Analytics, on our App to help us analyze how users interact with and use our Services, compile reports regarding activity on our Services, and provide other services. The information that third parties collect may be associated with your personal information or they may collect information, including personal information, about your online activities over time and across different websites and other online services, plus technical data such as your IP address, browser type and version, time of visit, whether you are a return visitor, or any referring website. They may use this information to provide you with interest-based (behavioural) advertising or other targeted content. Third party analytics services use cookies and other tracking technologies to collect information about your use of our services, plus technical data such as your IP address, browser type and version, time of visit, whether you are a return visitor, or any referring website. The information generated by these analytics services will be transmitted to and stored by them and will be subject to their privacy policies.
You can opt-out of several third-party ad servers’ and networks’ cookies simultaneously by using an opt-out tool created by the Digital Advertising Alliance of Canada. You can also access these websites to learn more about online behavioural advertising and how to stop websites from placing cookies on your device. Opting out of a network does not mean you will no longer receive online advertising. It does mean that the network from which you opted out will no longer deliver ads tailored to your web preferences and usage patterns. To opt out of Google Analytics tracking, visit https://tools.google.com/dlpage/gaoptout. Information collected through cookies is used anonymously for analytical purposes.
We do not control these third parties’ tracking technologies or how they are used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly. For more information about how you can opt out of receiving targeted advertising from many providers, see Choices about how we use and disclose your information.
Boon owns the statistical usage data derived from your use of the App or Services, including any partner applications and services integrated for use with the App, such as: IP addresses, web browser type, operating system information, information about the parts of the App that you access and use, the date and time of your access and use of the Services and in-application time, actions within the App, crashes and other system activity on the App, certain content that you download from the App, configurations, log data, feature access, and the performance results for the App (“Usage Data”). The Usage Data is not personal health information. You agree that the Usage Data will be owned by Boon without providing additional compensation to you, the Practitioner, or any other person and without any liability whatsoever. Boon may utilize the Usage Data to optimize and improve the App, retain customers, or otherwise operate or market Boon’s business.
We may transfer personal information that we collect or that you provide as described in this policy to contractors and service providers we use to support our business (such as analytics and search engine providers that assist us with App improvement and optimization) and who are contractually obligated to keep personal information confidential, use it only for the purposes for which we disclose it to them, and to process the personal information with the same standards set out in this policy.
The security of your personal information is very important to us. We may hold your information in either electronic or hard copy form. We take reasonable steps to ensure your personal information is protected from misuse and loss and from unauthorized access, modification, or disclosure. We store all information you provide to us behind firewalls on our secure servers. Any payment transactions and information including your account information and demographic data, video recordings of clients, programs created for clients, records of program changes, and exercises created for clients, will be encrypted at rest and in transit between the client and server using SSL technology. Our email providers use opportunistic encryption when sending emails, if your email provider supports this. This type of encryption ensures that the emails are encrypted in transit between our email provider and your email provider.
When you use the App offline, certain information — including programs, exercises, and associated media that your Practitioner has shared with you — may be cached on your device so that it remains available without an internet connection. This on-device cache is encrypted using industry-standard encryption (AES-GCM via Apple CryptoKit on iOS) and is erased when you sign out of the App or delete your account.
The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our App, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.
Unfortunately, no data transmission over the Internet can be guaranteed to be totally secure. Accordingly, any personal information or other information which you transmit to us online is transmitted at your own risk. We endeavour to take all reasonable steps to protect the personal information you may transmit to us or from our online services. Once we do receive your transmission, we will also make our best efforts to ensure its security on our systems.
Except as otherwise permitted or required by applicable law or regulation, we will only retain your personal information for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. Under some circumstances we may anonymize your personal information so that it can no longer be associated with you. We reserve the right to use such anonymous and de-identified data for any legitimate business purpose without further notice to you or your consent.
Our App may include links to third-party websites, plug-ins, services, social networks, or applications (collectively, “Third-Party Services”). Clicking on those links or enabling those connections may allow the third party to collect or share data about you. If you follow a link to a Third-Party Service, please note that these third parties have their own privacy policies, and we do not accept any responsibility or liability for these policies. We do not control these Third-Party Services, and we encourage you to read the privacy policy of every Third-Party Service prior to use.
We strive to provide you with choices regarding the personal information you provide to us. We have created mechanisms to provide you with the following control over your information:
Tracking Technologies and Advertising. You can set your App settings to refuse all or some browser cookies, or to alert you when cookies are being sent. If you disable or refuse cookies, please note that some parts of our App may not be accessible or may not function properly. For more information about tracking technologies, see Automatic data collection technologies above.
Location Data. You can choose whether to allow the App to collect and use real-time information about your device's location through the device's privacy settings. If you block the use of location, some parts of the App may be inaccessible or not function properly.
Promotional Offers from the Company. If you have opted in to receive certain emails or texts from us but no longer wish for us to use your contact information to promote our own or third parties' products or services, you can opt-out by clicking the unsubscribe link normally located at the bottom of the email or by contacting us using the information outlined below. If we have sent you a promotional email or text, you may unsubscribe by clicking the unsubscribe link we have included in the email, or by following instructions in the SMS communications we send you. You can also always opt-out by logging into the App and adjusting your user preferences in your account profile by checking or unchecking the relevant boxes.
Third-Party Advertising. If you do not want us to share your personal information with unaffiliated or non-agent third parties for promotional purposes, you can opt-out by checking the relevant box located on the form where we collect your data. You can also opt-out by contacting us (see Contact information below).
Targeted Advertising. If you do not want us to use information that we collect or that you provide to us to deliver advertisements according to our advertisers’ target-audience preferences, you can opt out by contacting us (see Contact information below).
We do not control third parties’ collection or use of your information to serve interest-based advertising. However, these third parties may provide you with ways to choose not to have your information collected or used in this way. You can opt out of several third-party ad servers’ and networks’ cookies simultaneously by using an opt-out tool created by the Digital Advertising Alliance of Canada. You can also access these websites to learn more about online behavioural advertising and how to stop websites from placing cookies on your device. Opting out of a network does not mean you will no longer receive online advertising. It does mean that the network from which you opted out will no longer deliver ads tailored to your web preferences and usage patterns.
You may request access to any personal information we hold about you at any time by contacting us (see Contact information below). Where we hold information that you are entitled to access, we will try to provide you with suitable means of accessing it (for example, by emailing it to you).
If you believe that personal information we hold about you is incorrect, incomplete, or inaccurate, then you may request us to amend it. We will consider whether the information requires amendment. If we do not agree that there are grounds for amendment, then we will add a note to the personal information stating that you disagree with it, together with your requested amendment. If we correct your personal information, we will, so far as is reasonably practicable, inform every other person to whom we have disclosed that information of the correction.
We may request specific information from you to help us confirm your identity and your right to access, and to provide you with the personal information that we hold about you or to give effect to other data subject rights you may be entitled to. In certain situations, we may not be able to fulfil your request. If that is the case, we'll explain the reasons for our decision when responding to your request. For example, in some cases the information you request access to may contain details about other individuals, or there may be legal, security, or commercial proprietary reasons why information is withheld.
You may delete your Boon account at any time from within the App: Settings → Account → Delete Account. On confirmation:
If you are unable to access your account, you may request deletion by contacting our Privacy Officer (see Contact information below). We may need to verify your identity before processing such requests.
Records held by your Practitioner. Your Practitioner is the health information custodian (or equivalent under applicable law) for clinical records they create about you. They may retain copies of those records separately from your Boon account, to meet their own legal record-keeping obligations. Boon does not control those copies. To request deletion of records held by your Practitioner, contact your Practitioner directly. See also Practitioner's ability to upload or share your Patient Data to a Boon account associated with you above.
Retention while your account is active. As described in Data retention above, we retain information only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements.
The Services that Boon offers are not directed to individuals under the age of thirteen (13) and we do not knowingly collect personal information from individuals under 13. Where individuals under 13 seek to access our Services, we require express parental and legal guardian consent and will verify the authenticity of such consent prior to processing. We also require that parents and legal guardians monitor their children's usage of the App and to help enforce our Privacy Policy by instructing their children never to provide personal information through the Services without their permission. If you have reason to believe that a child under the age of 13 has provided personal information to us through the Services without your express prior consent, please contact us using the Contact information below and we will endeavour to delete that information from our systems and databases.
We welcome your questions, comments, complaints and requests regarding this privacy policy and our privacy practices. Please contact our Privacy Officer by emailing privacy@boonmovement.com.
We have procedures in place to receive and respond to complaints or inquiries about our handling of personal information, our compliance with this policy, and with applicable privacy laws. To discuss our compliance with this policy please contact our Privacy Officer using the contact information listed above. Please note that we may need to confirm your identity or request additional details in order to process your request.
We may change this privacy policy from time to time. Any updated versions of this privacy policy will be posted on Boon's App and will be effective from the date of posting. You are responsible for checking if any amendments have been made to this privacy policy. Your continued use of our App or our Services following a change to this privacy policy will constitute your consent to the collection, use, and disclosure of your personal information as described in the amended privacy policy.