Policies

Privacy Policy
Cookies Policy
Privacy Notice

Privacy Policy

Last updated: June 17, 2026

Who We Are

Highbar Physical Therapy is the data controller responsible for the personal data described in this Privacy Policy.

Email: hello@highbarhealth.com
Address: 4 Richmond Square Suite 400
Providence, RI 02906

What Data We Collect

We collect the following types of personal data when you use our website and services to register and pay for continuing education courses, apply for jobs, and request appointments through our online appointment request system:

Cookie consent preferences (your choices about cookies and similar technologies, recorded through our consent management system).

Device and connection information (such as IP address, browser type, device type, and similar technical information needed to load and protect the website).

Course registration and account information (such as your name, email address, login credentials, and information you provide when registering for continuing education courses).

Payment and billing information (such as billing details and payment-related information needed to process your purchase; payment card details are handled by payment processors).

Appointment request information (such as your contact details and the information you submit through the online appointment request system).

Job application information (such as your contact details and the information you submit as part of an application, including resume/CV and related materials you choose to provide).

Marketing email information (such as your email address and your marketing communication preferences, where you choose to receive marketing emails).

Usage data via analytics (information about how you interact with the website, collected through analytics technologies that require your consent).

Social media data (information associated with social media features on our website, such as interactions with embedded content or social media tools, where those features are used).

Sources of data:
We collect data directly from you when you create an account, register for courses, submit payment, apply for a job, request an appointment, or contact us.
We collect some data automatically when you access the website (such as device and connection information).
We collect data from cookies and similar technologies; non-essential cookies are used only after you make your choices in our cookie consent tool.

If you do not provide certain information, we may not be able to create your account, process your course registration and payment, process your job application, or handle your appointment request. Marketing emails, analytics, and advertising-related data are optional and depend on your choices.

How We Use Your Data

We use your personal data for the purposes below, and we rely on the following legal bases depending on the purpose:

To provide our services, including creating and managing your account, registering you for continuing education courses, and connecting you to our online appointment request system (contract).

To process purchases and payments for continuing education courses and to manage related transaction administration (contract).

To receive, review, and communicate with you about job applications you submit through our website (contract).

To send marketing emails where you choose to receive them (consent). You can unsubscribe at any time using the link in the email or by contacting us.

To collect analytics data about website usage using cookies or similar technologies (consent).

To display personalized advertising and measure advertising performance using advertising technologies (consent).

To protect our website and users, including monitoring for security threats, abuse, and fraud, and maintaining the reliability of our services (legitimate interest).

To produce aggregated statistics that help us understand overall website performance without using cookies or other technologies that require consent (legitimate interest).

Who We Share Your Data With

We share personal data with the following recipients to operate and protect our website and to provide our services. These recipients process personal data under their own privacy policies and, where applicable, under contractual terms with us.

WordPress / WooCommerce: We use WordPress and WooCommerce to operate our website and course registration functionality. This may involve processing account, order, and technical information needed to provide the site and related services.

WooCommerce / Jetpack: We use Jetpack features associated with our WordPress/WooCommerce setup to support site functionality, performance, and security. This may involve processing device and connection information and other technical data needed to operate and protect the site.

Stripe: We use Stripe to handle payments for continuing education courses. Stripe processes payment and billing information to complete transactions and help prevent fraud.

Klaviyo: We use Klaviyo to send service-related messages and, where you have consented, marketing emails. This involves processing contact details and marketing preference information and may include tracking of email interactions using pseudonymous identifiers where enabled and permitted by your choices.

Mixpanel: If you consent, we use Mixpanel to understand how visitors use our website and to improve it. This involves processing usage data and online identifiers (including pseudonymous identifiers) collected through cookies or similar technologies.

Google Analytics: If you consent, we use Google Analytics to understand how visitors use our website and to improve it. This involves processing usage data and online identifiers (including pseudonymous identifiers) collected through cookies or similar technologies.

Hotjar: If you consent, we use Hotjar to understand how visitors use our website (for example, through usage analytics and feedback tools). This may involve processing usage data and online identifiers (including pseudonymous identifiers) collected through cookies or similar technologies.

Crazy Egg: If you consent, we use Crazy Egg to understand how visitors use our website (for example, through heatmaps and related analytics). This may involve processing usage data and online identifiers (including pseudonymous identifiers) collected through cookies or similar technologies.

Google Ads / Google: If you consent, we may use Google technologies (including Google Ads) for advertising and measurement. These technologies may process online identifiers (including pseudonymous identifiers) and usage data to support personalized advertising and measure advertising performance.

Facebook (Meta): If you consent, we may use Meta technologies (such as the Meta Pixel) and social media features that may allow Meta to receive information when you interact with embedded content or social tools on our website. This may involve online identifiers (including pseudonymous identifiers) and usage data for advertising measurement and cross-context behavioral advertising.

Microsoft: If you consent, we may use Microsoft technologies for advertising and measurement. These technologies may process online identifiers (including pseudonymous identifiers) and usage data to support personalized advertising and measure advertising performance.

Neustar: If you consent, we may use Neustar services in connection with advertising and measurement. This may involve processing online identifiers (including pseudonymous identifiers) and related usage data to support advertising measurement and related functions.

YouTube / Google: If you view pages where YouTube videos are embedded, YouTube (a Google service) may receive device and connection information and information about your interaction with the embedded content. Depending on configuration and your choices, YouTube may also use cookies or similar technologies and process online identifiers (including pseudonymous identifiers) for playback, security, and measurement purposes.

CookieYes: We may use CookieYes in connection with cookie management and compliance features. Where used, it may process information about your cookie choices and related technical data needed to present and store those choices.

We use our own consent management system (Trustwards) to record and manage your cookie preferences. This data is processed internally and not shared with third parties.

International Data Transfers

Some of our service providers are located outside the EU/EEA, specifically in the United States. When personal data is transferred internationally, we use appropriate safeguards required by applicable data protection laws.

Google (including Google Analytics, Google Ads, and YouTube): Google LLC participates in the EU-U.S. Data Privacy Framework (DPF).

Facebook (Meta): Meta Platforms, Inc. participates in the EU-U.S. Data Privacy Framework (DPF).

Microsoft: Microsoft Corporation participates in the EU-U.S. Data Privacy Framework (DPF).

Stripe: Stripe, Inc. participates in the EU-U.S. Data Privacy Framework (DPF).

Neustar: Neustar, Inc. participates in the EU-U.S. Data Privacy Framework (DPF).

Mixpanel: Mixpanel, Inc. is located in the United States. Where Mixpanel processes personal data transferred from the EU/EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and, where applicable, additional measures based on the transfer and risk assessment.

Hotjar: Hotjar Ltd. is located outside the EU/EEA. Where Hotjar processes personal data transferred from the EU/EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and, where applicable, additional measures based on the transfer and risk assessment.

Crazy Egg: Crazy Egg, Inc. is located in the United States. Where Crazy Egg processes personal data transferred from the EU/EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and, where applicable, additional measures based on the transfer and risk assessment.

CookieYes: CookieYes may process data outside the EU/EEA depending on configuration and hosting. Where personal data is transferred internationally in connection with CookieYes, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and, where applicable, additional measures based on the transfer and risk assessment.

For other providers that may process data outside the EU/EEA (for example, email and website service providers), we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and, where applicable, additional measures based on the transfer and risk assessment.

Our consent management system (Trustwards) is based in Spain (EU), so consent data is not transferred internationally.

How Long We Keep Your Data

We keep personal data for the periods listed below. Each retention period is independent and applies only to the data type described on that line.

Account data: until the account is deleted

Cookie consent records: 10 years (to demonstrate compliance and address potential claims within legal limitation periods)

Security logs and technical records: 12 months

Tax and accounting records: 10 years (legal requirement)

Analytics data: until consent is withdrawn or according to the analytics tool retention settings

Advertising/marketing tracking data: until consent is withdrawn

Marketing email data: until consent is withdrawn or user unsubscribes

Social media integration data: until consent is withdrawn

Your Rights

Depending on where you live and which laws apply, you may have the following rights regarding your personal data:

Access: request access to the personal data we hold about you.

Correction: request that we correct inaccurate or incomplete personal data.

Deletion: request that we delete your personal data in certain circumstances.

Restriction: request that we limit how we use your personal data in certain circumstances.

Data portability: request a copy of certain personal data in a portable format and, where applicable, ask that it be transferred to another provider.

Objection: object to certain processing, including processing based on legitimate interests, and object to certain direct marketing.

Withdraw consent: where we rely on consent, you can withdraw it at any time (this will not affect processing that occurred before you withdrew consent).

Automated decision-making: the right not to be subject to automated decision-making or profiling that produces legal effects or similarly significantly affects you.

Additional rights for California consumers include the right to opt-out of the sale or sharing of personal information and the right to limit the use and disclosure of sensitive personal information (where applicable).

How to exercise your rights: Please contact us at hello@highbarhealth.com. We may need to verify your identity before completing your request.

Response timing: We respond within one month for GDPR and LGPD requests, within 45 days for CCPA/CPRA requests (with the possibility of an additional 45 days where permitted and with notice), and within 30 days for PIPEDA requests, as applicable.

Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.

Children's Privacy

Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

Data Security

We implement appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. No method of transmission over the Internet or method of electronic storage is 100% secure, so we cannot guarantee absolute security.

Data Breach Notification

We maintain procedures to detect, report, and investigate security incidents. If a personal data breach occurs that poses a high risk to your rights and freedoms, we will notify you without undue delay and provide information about the nature of the breach, the likely consequences, and the measures taken or proposed to address it. If you suspect a security issue, please contact us at hello@highbarhealth.com.

How to Lodge a Complaint

We encourage you to contact us first so we can try to resolve your concern. You also have the right to lodge a complaint with the relevant authority depending on your location.

For EU/EEA/UK/Switzerland users: you may contact the competent authority in your jurisdiction.

For California consumers: you may contact the California Privacy Protection Agency (CPPA) at https://cppa.ca.gov/ and/or the California Attorney General.

For Brazilian data subjects: you may contact the ANPD (Autoridade Nacional de Proteção de Dados) at https://www.gov.br/anpd/.

For Canadian data subjects: you may contact the Office of the Privacy Commissioner of Canada (OPC) at https://www.priv.gc.ca/.

Updates to This Policy

We review and update this Privacy Policy periodically. The “Last updated” date at the top of this policy shows when it was last changed. If we make significant changes, we will provide notice by posting an update on our website and/or by email where appropriate. Changes take effect from the date indicated at the top of this policy. Where processing is based on consent, we will request new consent when required.

Contact Us

Email: hello@highbarhealth.com

Address: 4 Richmond Square Suite 400
Providence, RI 02906

Data Controller: Highbar Physical Therapy

California Privacy Rights (CCPA/CPRA)

This section applies to California consumers and describes our Notice at Collection and your rights under the CCPA/CPRA.

Categories of personal information collected in the last 12 months:
Identifiers (such as name, email address, IP address, and online identifiers).
Internet or other electronic network activity information (such as interactions with our website, where collected through analytics and advertising technologies based on your choices).
Commercial information (such as records of course purchases and payment-related transaction details).
Professional or employment-related information (such as information you submit in a job application).
Inferences (such as inferences used to support personalized advertising, where you consent to advertising technologies).

Business and commercial purposes for collecting personal information:
To provide and operate our services, including course registration, payment processing, job application handling, and appointment requests.
To communicate with you, including sending service messages and, where you consent, marketing emails.
To secure and protect our website and users.
To understand and improve website performance and user experience (where you consent to analytics).
To support personalized advertising and measure advertising performance (where you consent).

Sale of personal information: We do not sell personal information.

Sharing for cross-context behavioral advertising: We share personal information for cross-context behavioral advertising.

Categories of personal information shared for cross-context behavioral advertising: We share identifiers and internet or other electronic network activity information for this purpose.

Your CCPA/CPRA rights include:
Right to know what personal information is collected, used, shared, or sold.
Right to delete personal information, subject to exceptions.
Right to correct inaccurate personal information.
Right to opt-out of the sale or sharing of personal information (“Do Not Sell or Share My Personal Information”). You can submit an opt-out request by contacting us at hello@highbarhealth.com and by using our cookie and advertising preference controls where available. We also honor Global Privacy Control (GPC) signals as valid opt-out requests for sharing for cross-context behavioral advertising.
Right to limit the use and disclosure of sensitive personal information. We do not use sensitive personal information for purposes that require offering a “Limit the Use of My Sensitive Personal Information” link; if this changes, we will update this policy and provide the required choices.
Right to non-discrimination for exercising your rights.

How to submit requests: Email us at hello@highbarhealth.com.

Verification: We will take reasonable steps to verify your identity based on the nature of the request and the sensitivity of the information involved. This may include verifying access to the email address associated with your account or requesting additional information needed to confirm your identity. If you use an authorized agent, we may request proof of authorization and may still need to verify your identity directly.

Response timing: We respond within 45 days, and we may extend by an additional 45 days when permitted, with notice.

Brazilian Data Protection (LGPD)

This section applies to Brazilian data subjects.

Legal bases: We process personal data under LGPD legal bases that include consent (for example, marketing emails, analytics, personalized advertising, and social media integrations based on your choices), contract (to provide our services such as course registration and payment processing, job application handling, and appointment requests), and legitimate interest (to protect our website and users and to maintain service security and reliability).

Your LGPD rights include: confirmation of processing and access; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary or excessive data; portability; deletion of personal data processed with consent; information about sharing; and withdrawal of consent.

To exercise your rights, contact us at hello@highbarhealth.com. You also have the right to petition the ANPD (Autoridade Nacional de Proteção de Dados).

Data Protection Officer contact: hello@highbarhealth.com.

Canadian Privacy Rights (PIPEDA)

This section applies to Canadian data subjects.

Accountability: We are responsible for personal information under our control and we use appropriate safeguards and practices to protect it.

Meaningful consent: We seek meaningful consent for the collection, use, and disclosure of personal information, including through clear notices and choices. For non-essential cookies and similar technologies used for analytics and advertising, we provide choices through our cookie consent tool.

Access and accuracy: You have the right to request access to your personal information and to challenge the accuracy and completeness of the information, and have it amended as appropriate.

Withdrawing consent: You can withdraw consent, subject to legal or contractual restrictions, by contacting us at hello@highbarhealth.com, using unsubscribe links in marketing emails, and adjusting cookie preferences through our consent tool.

Complaints: You may contact us to raise concerns, and you also have the right to complain to the Office of the Privacy Commissioner of Canada (OPC) at https://www.priv.gc.ca/.

Cookies Policy

Last updated: June 17, 2026

What Are Cookies

Cookies are small text files stored on your device when you visit a website. They help websites function properly, remember your preferences, and improve your experience. Some cookies are essential for the website to work and are exempt from consent requirements, while others require your consent before they are used. We also use embedded content (iframes) from third-party services, which is described in a separate section below.

Types of Cookies We Use

Strictly Necessary Cookies
These cookies are required for core website functionality and security, including protecting the site from automated abuse and ensuring the service you request is delivered reliably.
Legal basis: Exempt from consent - strictly necessary for the service requested

Cookie NameProviderDomainDurationSource
__stripe_midStripejs.stripe.comSessionfiltered-https://js.stripe.com/v3/
__stripe_sidStripejs.stripe.comSessionfiltered-https://js.stripe.com/v3/
trustwardsCookieTrustwardswww.highbarhealth.comSessionhttps://cdn.trustwards.io/storage/v1/object/public/cdn-script/bc181d38-d987-4c9c-b7ca-4643fb61ec5b.js
woocommerce_cart_hashWooCommercewww.highbarhealth.comSessionFirst-party
woocommerce_items_in_cartWooCommercewww.highbarhealth.comSessionFirst-party
cookieyes-consentCookieYeswww.highbarhealth.comSessionFirst-party

Functional Cookies
These cookies enable optional features and help the website remember choices you make (such as settings that improve your experience).
Legal basis: Requires user consent - blocked by default

Cookie NameProviderDomainDurationSource
_hjSessionUser_6561776Hotjarwww.highbarhealth.comSessionFirst-party
tk_aiWooCommerce / Jetpackwww.highbarhealth.comSessionFirst-party
usw_userway_activation_notice_dismissedUnknownwww.highbarhealth.comSessionFirst-party

Analytics Cookies
These cookies help us understand how visitors use our website (for example, which pages are visited and how users navigate), so we can improve performance and user experience. They may process information such as device details and online identifiers (including pseudonymous identifiers).
Legal basis: Requires user consent - blocked by default

Cookie NameProviderDomainDurationSource
_clckMicrosoftwww.clarity.msSessionhttps://www.clarity.ms/tag/s8qobcdixj
_clskMicrosoftwww.clarity.msSessionhttps://www.clarity.ms/tag/s8qobcdixj
CLIDMicrosoftwww.clarity.msSessionhttps://www.clarity.ms/tag/s8qobcdixj
_ce.sCrazy Eggwww.highbarhealth.comSessionFirst-party
mp_6da9ec762c35d2149e04198aaa735e72_mixpanelMixpanelwww.highbarhealth.comSessionFirst-party
_gaGoogle Analyticswww.highbarhealth.comSessionfiltered-https://www.googletagmanager.com/gtag/js
tk_qsWordPresswww.highbarhealth.comSessionFirst-party
sbjs_migrationsWooCommercewww.highbarhealth.comSessionFirst-party
sbjs_current_addWooCommercewww.highbarhealth.comSessionFirst-party
sbjs_first_addWooCommercewww.highbarhealth.comSessionFirst-party
sbjs_currentWooCommercewww.highbarhealth.comSessionFirst-party
sbjs_firstWooCommercewww.highbarhealth.comSessionFirst-party
sbjs_udataWooCommercewww.highbarhealth.comSessionFirst-party
sbjs_sessionWooCommercewww.highbarhealth.comSessionFirst-party
_ga_17TVTE4Y0BGoogle Analyticswww.highbarhealth.comSessionfiltered-https://www.googletagmanager.com/gtag/js
_ga_38BKYCGNNWGoogle Analyticswww.highbarhealth.comSessionfiltered-https://www.googletagmanager.com/gtag/js

Marketing Cookies
These cookies are used to measure the effectiveness of advertising and to help deliver more relevant ads. They may involve tracking across websites and processing online identifiers (including pseudonymous identifiers).
Legal basis: Requires user consent - blocked by default

Cookie NameProviderDomainDurationSource
tk_orWordPresswww.highbarhealth.comSessionFirst-party
tk_lrWordPresswww.highbarhealth.comSessionFirst-party
_fbcFacebookwww.highbarhealth.comSessionFirst-party
_gcl_gsGoogle Adswww.highbarhealth.comSessionFirst-party
ConversionGoogle Adsgoogleads.g.doubleclick.netSessionfiltered-https://googleads.g.doubleclick.net/pagead/viewthroughconversion/784018154/
_gcl_awGoogle Adsgoogleads.g.doubleclick.netSessionfiltered-https://googleads.g.doubleclick.net/pagead/viewthroughconversion/784018154/
_gcl_auGooglegoogleads.g.doubleclick.netSessionfiltered-https://googleads.g.doubleclick.net/pagead/viewthroughconversion/784018154/
_gcl_dcGooglegoogleads.g.doubleclick.netSessionfiltered-https://googleads.g.doubleclick.net/pagead/viewthroughconversion/784018154/
_fbpFacebookwww.highbarhealth.comSessionfiltered-https://connect.facebook.net/signals/config/1463993788673755
ab-advanced-idNeustarwww.highbarhealth.comSessionFirst-party
__kla_idKlaviyowww.highbarhealth.comSessionFirst-party

Other Cookies
These cookies do not clearly fall into the categories above based on the information available from our scan. Where they are not strictly necessary, they require your consent and are blocked by default until you choose to enable them.
Legal basis: Requires user consent - blocked by default (unless strictly necessary for the service requested)

Cookie NameProviderDomainDurationSource
btab_6178Unknownwww.highbarhealth.comSessionFirst-party
btab_8980Unknownwww.highbarhealth.comSessionFirst-party
btab_6124Unknownwww.highbarhealth.comSessionFirst-party
btab_6133Unknownwww.highbarhealth.comSessionFirst-party
btab_6136Unknownwww.highbarhealth.comSessionFirst-party
wc_visitorUnknownwww.highbarhealth.comSessionFirst-party
btab_6320Unknownwww.highbarhealth.comSessionFirst-party
btab_6323Unknownwww.highbarhealth.comSessionFirst-party
btab_7189Unknownwww.highbarhealth.comSessionFirst-party
wt_consentUnknownwww.highbarhealth.comSessionFirst-party
btab_6319Unknownwww.highbarhealth.comSessionFirst-party
Liine-session-14b4d60e08684bca86f7f1d677414d15Unknownwww.highbarhealth.comSessionFirst-party
Liine-user-14b4d60e08684bca86f7f1d677414d15Unknownwww.highbarhealth.comSessionFirst-party
googleadsvisitorUnknownwww.highbarhealth.comSessionFirst-party
btab_6451Unknownwww.highbarhealth.comSessionFirst-party
btab_6452Unknownwww.highbarhealth.comSessionFirst-party
btab_6845Unknownwww.highbarhealth.comSessionFirst-party
btab_6846Unknownwww.highbarhealth.comSessionFirst-party
__adroll_fpcUnknownwww.highbarhealth.comSessionFirst-party
__ar_v4Unknownwww.highbarhealth.comSessionFirst-party
btab_8979Unknownwww.highbarhealth.comSessionFirst-party
__ssidUnknownwww.highbarhealth.comSessionFirst-party
_vbUnknownwww.highbarhealth.comSessionFirst-party

Our website embeds content from third-party services using iframes. Iframes allow us to display external content (such as videos, maps, social media widgets, or payment forms) directly on our pages. When you interact with this embedded content, the third-party provider may set cookies or collect data according to their own privacy policies. These embedded elements are subject to the same consent requirements as cookies.

Analytics Embedded Content
These embedded elements support analytics and tag management delivered through third-party infrastructure.
Legal basis: Requires user consent - blocked by default

Iframe NameProviderDomainDurationSource
UnknownUnknownwww.googletagmanager.comSessionfiltered-https://www.googletagmanager.com/ns.html

Marketing Embedded Content
These embedded elements support marketing content delivery and may enable tracking depending on your consent choices.
Legal basis: Requires user consent - blocked by default

Iframe NameProviderDomainDurationSource
YouTubeYouTubewww.youtube.comSessionfiltered-https://www.youtube.com/embed/drEIo9q5_yU
YouTubeYouTubewww.youtube.comSessionfiltered-https://www.youtube.com/embed/LXi2qwMTnVY

Other Embedded Content
These embedded elements do not clearly fall into the categories above based on the information available from our scan. Where they are not strictly necessary, they require your consent and are blocked by default until you choose to enable them.
Legal basis: Requires user consent - blocked by default (unless strictly necessary for the service requested)

Iframe NameProviderDomainDurationSource
UnknownUnknownjs.stripe.comSessionfiltered-https://js.stripe.com/v3/elements-inner-payment-method-messaging-a3ef800a96dba2c8811f298be89b4bb3.html
UnknownUnknownjs.stripe.comSessionfiltered-https://js.stripe.com/v3/controller-with-preconnect-1d952dc8c304f3deccbcba133a6569ac.html
UnknownUnknownjs.stripe.comSessionfiltered-https://js.stripe.com/v3/m-outer-3437aaddcdf6922d623e172c2d6f9278.html
UnknownUnknownjs.stripe.comSessionfiltered-https://js.stripe.com/v3/elements-inner-payment-method-messaging-adc63c154d011416bbae437b17951ea3.html
UnknownUnknownjs.stripe.comSessionfiltered-https://js.stripe.com/v3/controller-with-preconnect-7bdf318928f16256742488a8de6aca37.html
UnknownUnknownjs.stripe.comSessionfiltered-https://js.stripe.com/v3/elements-inner-payment-method-messaging-ae92b0c564c575344146a4541365ae75.html
UnknownUnknownjs.stripe.comSessionfiltered-https://js.stripe.com/v3/controller-with-preconnect-065f5947f793cda48418c1454505c69d.html
UnknownUnknownscheduling.go.promptemr.comSessionfiltered-https://scheduling.go.promptemr.com/onlineScheduling
UnknownUnknowntranslate.google.comSessionfiltered-https://translate.google.com/websitetranslationui
UnknownUnknownapi.leadconnectorhq.comSessionhttps://api.leadconnectorhq.com/widget/form/vu5VFz4IJ1eNLJQzpV9C
UnknownUnknowncdn.userway.orgSessionfiltered-https://cdn.userway.org/widget/2026-05-12-14-26-48/en-US/index.html

Third-Party Services and Data Recipients

Google (Google Analytics / Google Tag Manager / Google Ads / Google Translate / YouTube)
We use Google services to support analytics, tag management, advertising measurement, and website translation functionality. These services may process device and network information and online identifiers (including pseudonymous identifiers) and may set or read cookies and similar technologies depending on your consent choices. Processing is carried out according to Google’s privacy information: https://policies.google.com/privacy

Microsoft (Clarity)
We use Microsoft Clarity to help us understand how users interact with our website (for example, navigation patterns and usability). Clarity may process device information and online identifiers (including pseudonymous identifiers) and may set or read cookies and similar technologies depending on your consent choices. Processing is carried out according to Microsoft’s privacy statement: https://privacy.microsoft.com/privacystatement

Mixpanel
We use Mixpanel to support analytics and product/website usage measurement. Mixpanel may process device and network information and online identifiers (including pseudonymous identifiers) and may set or read cookies and similar technologies depending on your consent choices. Processing is carried out according to Mixpanel’s privacy information (as made available by the provider).

Hotjar
We use Hotjar to support optional website functionality and user experience features. Hotjar may process device and network information and online identifiers (including pseudonymous identifiers) and may set or read cookies and similar technologies depending on your consent choices. Processing is carried out according to Hotjar’s privacy information (as made available by the provider).

Crazy Egg
We use Crazy Egg to help us understand how visitors use our website (for example, which pages are visited and how users navigate) so we can improve performance and user experience. Crazy Egg may process device and network information and online identifiers (including pseudonymous identifiers) and may set or read cookies and similar technologies depending on your consent choices. Processing is carried out according to Crazy Egg’s privacy information (as made available by the provider).

Meta (Facebook)
We use Meta technologies to measure advertising effectiveness and support marketing activities. Meta may process device and network information and online identifiers (including pseudonymous identifiers) and may set or read cookies and similar technologies depending on your consent choices. Processing is carried out according to Meta’s privacy policy: https://www.facebook.com/privacy/policy/

YouTube
We embed videos delivered via YouTube. When enabled, YouTube may process device and network information and online identifiers (including pseudonymous identifiers) and may set or read cookies and similar technologies depending on your consent choices. Processing is carried out according to Google’s privacy information: https://policies.google.com/privacy

Stripe
We use Stripe to support payment-related functionality. Stripe may process device and network information and online identifiers (including pseudonymous identifiers) for fraud prevention and security and may set cookies that are necessary to provide secure payment services. Processing is carried out according to Stripe’s privacy policy: https://stripe.com/privacy

Klaviyo
We use Klaviyo for marketing communications and related measurement. Klaviyo may process online identifiers (including pseudonymous identifiers) and interaction data depending on your consent choices. Processing is carried out according to Klaviyo’s privacy policy: https://www.klaviyo.com/legal/privacy

WooCommerce / WordPress / Jetpack
Our website uses WooCommerce and WordPress features (and related Jetpack functionality) that may set cookies to support site features and measurement depending on your consent choices. Processing is carried out according to Automattic’s privacy policy: https://automattic.com/privacy/

Neustar
We use Neustar-related functionality for marketing measurement and/or advertising support depending on your consent choices. Neustar may process online identifiers (including pseudonymous identifiers). Processing is carried out according to Neustar’s privacy information (as made available by the provider).

CookieYes
We use CookieYes to support cookie consent functionality. CookieYes may set a consent-related cookie to store your preferences. Processing is carried out according to CookieYes’ privacy policy: https://www.cookieyes.com/privacy-policy/

Userway
We use Userway to provide accessibility-related functionality. Userway may process device and network information and online identifiers (including pseudonymous identifiers) and may set or read cookies and similar technologies depending on your consent choices and configuration. Processing is carried out according to Userway’s privacy information (as made available by the provider).

LeadConnector (LeadConnectorHQ)
We embed a form/widget delivered via LeadConnectorHQ infrastructure. This embedded content may process device and network information and online identifiers (including pseudonymous identifiers) and may set or read cookies and similar technologies depending on your consent choices and configuration. Processing is carried out according to the provider’s privacy information (as made available by the provider).

PromptEMR (Online Scheduling)
We embed an online scheduling interface delivered via PromptEMR infrastructure. This embedded content may process device and network information and online identifiers (including pseudonymous identifiers) and may set or read cookies and similar technologies depending on your consent choices and configuration. Processing is carried out according to the provider’s privacy information (as made available by the provider).

We use our own consent management system (Trustwards) to record your cookie preferences. The 'trustwardsCookie' stores which cookie categories you have accepted or rejected, ensuring your choices persist across visits. This cookie is strictly necessary for compliance with applicable privacy regulations and consent requirements. Your consent data is processed securely and is not shared with third parties unless legally required.

International Data Transfers

Some of our service providers may be located outside the EU/EEA (or may process data from locations outside the EU/EEA), including in the United States. Where required under GDPR and related regimes, we rely on appropriate safeguards for such transfers, which may include the EU-U.S. Data Privacy Framework (DPF) where the provider is certified, and/or Standard Contractual Clauses (SCCs) approved by the European Commission (together with supplementary measures where appropriate).

Based on the services detected in our scan, providers that may involve transfers to the United States include: Google (Google Analytics / Google Tag Manager / Google Ads / Google Translate / YouTube), Microsoft (Clarity), Mixpanel, Hotjar, Crazy Egg, Meta (Facebook), Stripe, Klaviyo, WooCommerce / WordPress / Jetpack (Automattic), Neustar, CookieYes, Userway, LeadConnector (LeadConnectorHQ), and PromptEMR (Online Scheduling).

We recommend reviewing each provider's privacy policy for detailed information about their data protection measures.

Legal Basis for Processing

Strictly Necessary cookies are exempt from the consent requirement because they are strictly necessary for the service you request and cannot be disabled through our cookie settings. All other cookie categories and embedded content require your consent; they are blocked by default and only activated after you provide explicit consent through our cookie settings.

Managing Your Cookie Preferences

You can accept or reject cookie categories at any time, and non-essential cookies remain blocked until you provide consent. You can also withdraw your consent at any time, and we will apply your updated choices going forward. You can manage your cookie preferences through the cookies settings link in our website footer.

How to Control Cookies in Your Browser

In addition to our cookie settings tool, you can control cookies through your browser settings.
Chrome: Settings > Privacy and security > Third-party cookies (or Cookies and other site data) to view, delete, and block cookies and manage first-party and third-party cookie settings.
Firefox: Settings > Privacy & Security > Cookies and Site Data to view, delete, and manage cookie blocking and enhanced tracking protection settings.
Safari (macOS): Safari > Settings (or Preferences) > Privacy to manage website data, block cookies, and control cross-site tracking.
Edge: Settings > Cookies and site permissions > Cookies and site data to view, delete, block cookies, and manage third-party cookie settings.
Blocking cookies can affect website functionality. Strictly necessary cookies are required for the site to operate and deliver the service you request.

Similar Technologies

Local Storage: A browser feature that allows websites to store data persistently on your device. Unlike cookies, this data does not expire automatically and remains until manually cleared. We use Local Storage strictly for essential website functionality, such as remembering your preferences and settings to provide a consistent browsing experience. This usage is strictly necessary for the service you have requested and is therefore exempt from consent requirements under applicable law.

Session Storage: A browser feature that temporarily stores data only for the duration of your browser session. This data is automatically deleted when you close your browser tab or window. We use Session Storage strictly for essential functionality during your visit, such as maintaining your navigation state and form data. This usage is strictly necessary for the service you have requested and is therefore exempt from consent requirements under applicable law.

Cookie Retention Periods

Session cookies: deleted when you close your browser.

Persistent cookies: We currently use session-duration cookies as identified in the tables above.

Your Rights

You have the right to withdraw your consent at any time by changing your cookie preferences through the cookies settings link in our website footer. You also have the right to access information about the cookies we use (provided in this policy), to request deletion of cookie data, and to lodge a complaint with the data protection authority in your country if you believe your rights have been violated. To exercise your rights, contact us at hello@highbarhealth.com.

Updates to This Policy

We review this policy periodically and update it when our cookie practices change. The “Last updated” date at the top indicates when changes were last made. For significant changes, we will notify users through the cookie banner and request new consent where required. Changes take effect from the date indicated at the top of this policy.

Contact Us

Highbar Physical Therapy
Email: hello@highbarhealth.com
Address: 4 Richmond Square Suite 400
Providence, RI 02906

Privacy Notice

Last updated: June 17, 2026

Notice at Collection

This Notice at Collection is for California consumers and explains the categories of personal information Highbar Physical Therapy collects and the business or commercial purposes for which we collect and use it.

Categories of Personal Information We Collect

We collect the following categories of personal information:

Identifiers (such as name, email, address, phone number).
Commercial information (such as purchase history and records of products or services).
Internet or other electronic network activity information (such as browsing history, search history, and interactions).
Geolocation data.
Professional or employment-related information.

How We Use Your Information

We collect and use personal information for the following business or commercial purposes: to process transactions, provide customer support, improve our services, and for marketing purposes.

Sale and Sharing of Personal Information

We do not sell personal information.

We share personal information for cross-context behavioral advertising. The categories of personal information we share for this purpose are: identifiers, internet or other electronic network activity information, and geolocation data. Based on our website scan, this sharing may occur through third-party advertising, analytics, and embedded content technologies and partners such as Facebook, Google (including Google Ads and Google Analytics), Microsoft, Neustar, Mixpanel, Hotjar, Crazy Egg, Klaviyo, and YouTube. We may also disclose personal information to service providers that help us operate our website and process transactions, such as Stripe, WooCommerce (including WooCommerce / Jetpack), WordPress, and CookieYes. Trustwards is our own consent management platform and is not a third party.

You have the right to opt out of the sharing of your personal information for cross-context behavioral advertising at any time. You may submit a request to opt out by contacting us at hello@highbarhealth.com and stating that you want to “Do Not Sell or Share My Personal Information.”

Retention

We retain personal information for as long as necessary to fulfill the purposes described in this notice, to comply with legal obligations, and to resolve disputes.

Your California Privacy Rights

Subject to certain exceptions, California consumers have the following rights under the CCPA/CPRA:

Right to know/access: You can request information about the personal information we collected about you, including the categories of personal information, the purposes for collecting it, and the categories of personal information shared for cross-context behavioral advertising.
Right to delete: You can request that we delete personal information we collected from you.
Right to correct: You can request that we correct inaccurate personal information we maintain about you.
Right to opt out of sale/sharing: You can opt out of the sale or sharing of your personal information. We do not sell personal information, but we do share certain personal information for cross-context behavioral advertising as described above.
Right to limit use of sensitive personal information: You can request that we limit the use and disclosure of sensitive personal information to certain permitted purposes.
Right to non-discrimination: You have the right not to receive discriminatory treatment for exercising your CCPA/CPRA rights.

How to submit a request: Email us at hello@highbarhealth.com. We will respond within 45 days, unless an extension is permitted by law.

Global Privacy Control (GPC): We honor opt-out preference signals sent through the Global Privacy Control where required by the CCPA/CPRA.

Contact Us

Highbar Physical Therapy
hello@highbarhealth.com