Wellness Refined – Privacy Policy
Effective Date: July 16, 2026
Last Updated: July 16, 2026
1. Introduction
Wellness Refined, a DBA of The Injection Specialist, respects your privacy and is committed to handling personal information responsibly.
This Privacy Policy explains how we may collect, use, process, disclose, retain, and protect information when you:
- Visit wellnessrefined.clinic
- Submit a general inquiry
- Contact us by telephone, email, text message, or social media
- Interact with our advertisements
- Request information about services, financing, memberships, or gift cards
- Use links to third-party platforms, including our online booking system
- Otherwise interact with Wellness Refined online
This Privacy Policy applies primarily to information collected through our public website and general business communications.
Information created, received, maintained, or transmitted as part of patient care may be governed by HIPAA and our separate HIPAA Notice of Privacy Practices. If this Privacy Policy conflicts with the HIPAA Notice regarding protected health information, the HIPAA Notice and applicable health-privacy law will control.
By using this website, you acknowledge the practices described in this Privacy Policy.
2. Definitions
For purposes of this Privacy Policy:
“Personal information” or “personal data” means information that identifies, relates to, describes, is linked to, or can reasonably be linked to an identified or identifiable individual. Personal information generally does not include properly de-identified information or information lawfully made publicly available.
“Sensitive personal information” or “sensitive data” means personal information that receives additional protection under applicable law. Depending on the law and context, this may include information concerning physical or mental health, medical conditions, diagnoses, biometric information used for identification, precise geolocation, information concerning a child, or other legally protected information.
“Protected health information” or “PHI” means individually identifiable health information held or transmitted by a HIPAA-covered entity or its business associate in electronic, paper, oral, or another form, as defined under HIPAA.
“Processing” means collecting, accessing, using, storing, analyzing, disclosing, transmitting, modifying, deleting, or otherwise handling personal information.
“Service provider” means a third party that processes information on our behalf to help operate our website, maintain security, communicate with visitors and patients, provide services, process payments, support marketing, or perform other authorized business functions.
“Targeted advertising” generally refers to displaying advertisements selected based on personal information obtained or inferred from a person’s activities across nonaffiliated websites, applications, or services, as defined by applicable law.
3. Information We May Collect
We may collect information directly from you, automatically through website technology, or from third-party platforms and service providers.
Information You Provide
We may collect information when you:
- Submit a website contact form
- Ask a general question
- Request help choosing a service
- Ask about memberships, financing, or gift cards
- Contact us by telephone, email, or text
- Communicate through social media
- Interact with a promotion or advertisement
- Schedule through a linked third-party booking platform
- Complete patient registration, intake, or consent documents through an approved system
Information you provide may include:
- First and last name
- Email address
- Telephone number
- Mailing address
- Preferred contact method
- Whether you are an existing patient
- Services in which you are interested
- General inquiry details
- Appointment preferences
- Financing or membership inquiries
- Communications and correspondence
- Marketing preferences and consent
- Information you voluntarily include in a message
Please do not submit detailed medical information through general website forms, unsecured email, social media, or advertising-platform messaging.
4. Health Information and PHI
Wellness Refined provides wellness, hormone, metabolic, regenerative, aesthetic, skin, and related healthcare services.
Certain information collected during patient care may qualify as PHI under HIPAA. PHI may include information concerning:
- Health history
- Symptoms
- Diagnoses
- Treatments
- Medications
- Laboratory results
- Treatment photographs
- Appointment history
- Billing or payment information
- Other individually identifiable information created or received as part of healthcare
Our use and disclosure of PHI are addressed in our HIPAA Notice of Privacy Practices.
The HIPAA Privacy Rule protects individually identifiable health information held or transmitted by covered entities and their business associates.
Patient-specific medical information should be submitted only through Jane or another secure communication method approved by Wellness Refined.
5. Sensitive Personal Information
Wellness Refined may collect or process sensitive personal information, including health-related information that you voluntarily provide, only:
- For the purposes described in this Privacy Policy
- As reasonably necessary to provide requested services
- As permitted or required by law
- With consent where consent is legally required
- Subject to additional safeguards where appropriate
We do not intend to:
- Sell sensitive personal information
- Use sensitive health information for unrelated targeted advertising
- Make unrelated inferences about a person using sensitive personal information
- Upload PHI to advertising platforms
- Use patient records for unrelated marketing purposes without appropriate authorization
Colorado law requires consent before a covered controller processes certain sensitive data.
Please do not submit the following through a general website form:
- Diagnoses
- Medication lists
- Laboratory results
- Medical photographs
- Insurance information
- Social Security numbers
- Payment-card information
- Emergency symptoms
- Detailed treatment histories
6. Information Collected Automatically
When you visit our website, we or our service providers may automatically collect certain technical and usage information, including:
- Internet Protocol address
- Browser type
- Device type
- Operating system
- Language preferences
- Referring website or campaign
- Pages viewed
- Links or buttons selected
- Date and time of access
- General geographic area inferred from an IP address
- Website performance and error information
- Cookie identifiers
- Advertising or analytics identifiers
- Interaction and conversion data
We may collect this information through cookies, pixels, tags, local storage, server logs, analytics tools, and similar technologies.
We do not intend to use automatic tracking technologies to collect the contents of patient communications, medical records, or information entered into secure patient systems for advertising purposes.
7. Cookies and Similar Technologies
Cookies are small files or identifiers stored on a browser or device. We may use cookies and similar technologies for:
Essential Functions
These technologies may support:
- Website navigation
- Security
- Spam prevention
- Form operation
- Consent preferences
- Session management
- Load balancing
- Fraud detection
Analytics
Analytics technologies may help us understand:
- How visitors reach the website
- Which pages are viewed
- How visitors navigate the site
- Whether pages function properly
- How website performance may be improved
Advertising and Conversion Measurement
Subject to applicable law and consent requirements, advertising technologies may help us:
- Measure campaign performance
- Understand whether an advertisement led to a website visit
- Measure general conversion events
- Limit repetitive advertising
- Present relevant advertisements
- Improve advertising campaigns
Visitors may manage cookies through browser settings, our cookie-preference tool, or recognized privacy signals where available.
Disabling certain cookies may affect website operation.
8. Advertising Platforms
Wellness Refined may advertise through platforms including:
- TikTok
- Other approved advertising or social platforms
These platforms may use cookies, pixels, tags, or similar technologies to measure website visits and campaign performance, subject to applicable law and user consent.
We do not intend to send advertising platforms:
- Form messages
- Diagnoses
- Symptoms
- Medical histories
- Laboratory results
- Appointment details
- Jane account information
- Patient records
- PHI
- Identifiable treatment photographs without appropriate authorization
- Service-interest information that reveals or implies a sensitive medical condition
General advertising events may include actions such as:
- Page viewed
- Button selected
- General inquiry submitted
- External booking link selected
Healthcare organizations should carefully evaluate online tracking technologies because data transmitted through healthcare websites may create obligations under HIPAA and other privacy laws.
9. How We May Use Information
We may use personal information to:
- Operate and maintain the website
- Respond to inquiries
- Provide requested information
- Route questions to an appropriate team member
- Help visitors understand available services
- Support appointment scheduling through approved systems
- Communicate about memberships, financing, gift cards, or services
- Provide appointment-related or administrative communications
- Deliver services requested by patients
- Maintain patient and business records
- Process payments or support financing inquiries
- Improve website usability and performance
- Measure general advertising effectiveness
- Prevent spam, fraud, misuse, and security threats
- Enforce website terms and policies
- Protect our rights and the safety of others
- Comply with legal, regulatory, professional, and recordkeeping obligations
- Establish, exercise, or defend legal claims
- Obtain consent for additional uses when required
We seek to collect and retain only information reasonably necessary for legitimate and authorized purposes.
The Federal Trade Commission recommends that businesses identify the personal information they maintain, retain only what they need, protect it, dispose of it appropriately, and plan for security incidents.
10. Communications
If you provide your telephone number or email address, we may contact you regarding:
- Your inquiry
- Scheduling assistance
- Administrative matters
- Membership or financing questions
- Services you requested information about
- Appointment reminders
- Follow-up instructions
- Account or payment matters
- Changes to our services or policies
- Marketing communications, when you have provided the required consent
Email may not be fully secure. Avoid sending sensitive medical information through general email.
Text Messages
If you consent to receive text messages:
- Message frequency may vary
- Message and data rates may apply
- Consent to marketing texts is not a condition of receiving treatment
- You may opt out of marketing texts by replying STOP
- You may request assistance by replying HELP or contacting us
Transactional or appointment-related communications may be treated differently from optional marketing messages under applicable law.
Marketing Opt-Out
You may unsubscribe from marketing email by using the unsubscribe link included in the message or contacting us.
Opting out of marketing does not prevent necessary administrative, transactional, appointment-related, or legally required communications.
11. How We May Disclose Information
We may disclose personal information to service providers and other parties when reasonably necessary for the purposes described in this policy.
Categories of recipients may include:
- Website hosting providers
- WordPress developers and support providers
- Website security and spam-prevention providers
- Email and communication providers
- Scheduling and patient-management platforms
- Payment processors
- Financing providers
- Analytics providers
- Advertising platforms
- Customer-relationship or form-management providers
- Cloud-storage providers
- Accountants, attorneys, auditors, and compliance professionals
- Technology support providers
- Government agencies or legal authorities when required
- Successors involved in a merger, acquisition, reorganization, financing, sale, or transfer of business assets
Service providers are expected to use information only for authorized purposes and to apply appropriate safeguards.
Where required by HIPAA, vendors handling PHI must enter into appropriate agreements and comply with applicable privacy and security obligations.
12. Third-Party Platforms and Links
Our website may link to or integrate with third-party services, including:
- Jane
- Cherry
- CareCredit
- Google Maps
- TikTok
- Payment providers
- Gift-card providers
- Social media platforms
- External educational resources
Third-party websites and applications operate under their own privacy policies, terms, security practices, and data-retention rules.
Wellness Refined does not control the privacy or security practices of third parties. Review their policies before providing information.
Information submitted directly to Jane or another third-party platform is also governed by that platform’s privacy practices and applicable contractual or legal requirements.
13. Sale, Sharing, and Targeted Advertising
Wellness Refined does not sell PHI.
We do not knowingly sell personal information for monetary payment.
Some state privacy laws define “sale,” “sharing,” or targeted advertising broadly and may treat certain cookie- or advertising-related disclosures as a sale or targeted advertising even when money is not exchanged.
Where applicable, you may have the right to opt out of:
- The sale of personal data
- Processing for targeted advertising
- Certain profiling activities
You may exercise available opt-out rights through:
- Our cookie- or privacy-preference tool
- A recognized universal opt-out signal
- A written request sent to the contact information below
14. Colorado Privacy Rights
Where the Colorado Privacy Act applies, Colorado residents may have the right to:
- Confirm whether we process their personal data
- Access personal data we maintain about them
- Correct inaccurate personal data
- Request deletion of certain personal data
- Obtain certain personal data in a portable format
- Opt out of the sale of personal data
- Opt out of processing for targeted advertising
- Opt out of certain profiling activities
- Withdraw consent for certain sensitive-data processing
- Appeal a decision concerning a privacy request
These rights may be subject to legal exceptions, identity verification, and limitations.
The Colorado Privacy Act gives qualifying Colorado consumers rights involving access, correction, deletion, portability, sales, targeted advertising, and certain profiling.
Submitting a Request
To submit a privacy request, contact:
Email: hello@wellnessrefined.clinic
Phone: 303.565.7735
Please state that your message concerns a privacy request and describe the right you wish to exercise.
We may request information reasonably necessary to:
- Verify your identity
- Confirm your residency
- Locate responsive records
- Confirm the authority of an authorized agent
- Prevent fraudulent requests
We will respond within the period required by applicable law.
Appeals
If we deny a qualifying Colorado privacy request, you may appeal by contacting us using the same contact information and clearly stating that you are submitting a privacy appeal.
We will provide a written response within the time required by applicable law.
15. Global Privacy Control and Universal Opt-Out Signals
Where required by applicable law, Wellness Refined will recognize and process valid Global Privacy Control, or GPC, signals and other universal opt-out mechanisms recognized by the Colorado Department of Law.
A valid signal may be treated as a request to opt out of:
- The sale of personal data
- Processing for targeted advertising
A GPC signal generally applies to the browser or device from which the signal is sent. You may need to enable the preference separately on each browser or device.
Colorado maintains a list of recognized universal opt-out mechanisms and identifies GPC as a recognized mechanism.
You may also submit an opt-out request directly through our privacy-preference tool or by contacting us.
16. Artificial Intelligence and Model Training
Wellness Refined does not permit personal information or PHI submitted through our website, patient systems, contact forms, or clinical workflows to be used to train publicly available or generalized artificial-intelligence models without appropriate authorization, consent, or another lawful basis.
We do not knowingly provide the following for unrelated AI-model training:
- Patient records
- Medical histories
- Diagnoses
- Laboratory results
- Identifiable treatment photographs
- Contact-form messages
- Appointment details
- PHI
- Sensitive personal information
We may use technology platforms containing AI-enabled features for limited administrative, security, analytical, communication, or operational purposes.
When such tools are used, we seek to:
- Limit the information provided
- Avoid submitting PHI unless appropriately authorized and protected
- Review relevant privacy and contractual terms
- Restrict use to authorized purposes
- Apply appropriate access controls and safeguards
Companies that make privacy and confidentiality promises must ensure that data used for AI development or deployment is handled consistently with those promises.
17. Data Retention
We may retain personal information for as long as reasonably necessary to:
- Respond to inquiries
- Provide requested services
- Maintain patient and business records
- Complete transactions
- Support security and fraud prevention
- Comply with professional, legal, regulatory, tax, accounting, or recordkeeping obligations
- Enforce agreements
- Resolve disputes
- Establish, exercise, or defend legal claims
- Fulfill other authorized business purposes
Retention periods may vary based on:
- The type of information
- The purpose for which it was collected
- Whether a patient relationship exists
- Contractual requirements
- Applicable statutes of limitation
- Medical-record retention requirements
- Legal preservation obligations
- Security considerations
We may delete, anonymize, or de-identify information when it is no longer reasonably needed.
18. Data Security
We use administrative, technical, and physical safeguards designed to protect personal information against:
- Unauthorized access
- Loss
- Misuse
- Alteration
- Destruction
- Improper disclosure
Safeguards may include:
- Access limitations
- Authentication controls
- Encryption where appropriate
- Secure hosting
- Website security monitoring
- Spam protection
- Backups
- Vendor review
- Staff training
- Written privacy and security procedures
- Incident-response planning
The HIPAA Security Rule requires appropriate administrative, physical, and technical safeguards for electronic PHI when it applies.
No internet transmission, email system, website, storage system, or security measure can be guaranteed to be completely secure.
Please avoid submitting sensitive information through unsecured channels.
19. Data Storage and Processing Locations
Information collected through our website or services may be stored or processed in the United States.
Some service providers may process information in other states, countries, or jurisdictions where they or their subcontractors operate.
Privacy and data-protection laws in those locations may differ from those in your jurisdiction.
Where appropriate, we use contractual, administrative, technical, and organizational safeguards designed to protect information and limit processing to authorized purposes.
20. Data Breach and Incident Response
If we discover a security incident involving personal information, we will investigate and respond in accordance with applicable law.
Where legally required, we may notify:
- Affected individuals
- Government agencies
- Regulators
- Law enforcement
- Business partners or service providers
HIPAA-regulated information may also be subject to the HIPAA Breach Notification Rule.
21. Children’s Privacy
Our website and general online services are intended primarily for adults.
We do not knowingly collect personal information online from children under 13 without appropriate authorization.
If you believe a child has submitted personal information through our website without proper authorization, contact us so that we can review and address the matter.
Certain services may be available to minors only with legally appropriate consent and through approved patient-care processes.
22. Social Media
Wellness Refined may maintain profiles on Facebook, Instagram, TikTok, and other social platforms.
Information submitted through social media may be visible to the platform and governed by its policies.
Do not use social media to send:
- Medical records
- Diagnoses
- Treatment photographs
- Medication information
- Emergency concerns
- Urgent clinical questions
- Other confidential health information
Social media messages may not be monitored continuously and should not be relied upon for appointment changes, urgent issues, or clinical care.
23. Testimonials, Reviews, and Photographs
We will seek appropriate permission before using identifiable patient photographs, testimonials, treatment information, or stories for marketing where authorization is required.
Providing marketing authorization is voluntary and is not a condition of receiving treatment.
Reviews posted independently on third-party platforms may be governed by the platform’s terms and privacy practices.
To protect patient privacy, Wellness Refined may be limited in how it can publicly respond to online reviews.
24. Your Choices
Depending on applicable law and the context, you may:
- Opt out of marketing emails
- Opt out of marketing text messages
- Adjust browser cookie settings
- Use our privacy-preference tool
- Enable Global Privacy Control
- Request access, correction, deletion, or portability
- Withdraw consent where processing relies on consent
- Request confidential healthcare communications as described in our HIPAA Notice
- Decline optional marketing authorization
- Contact us with privacy questions
Certain information may still be processed when required for treatment, payment, healthcare operations, security, legal compliance, or another lawful purpose.
25. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect:
- Changes in our services
- Changes in technology
- Changes in vendors
- Changes in advertising practices
- Legal or regulatory developments
- Changes in privacy or security practices
The revised policy will be posted on this page with an updated effective date.
Material changes may be communicated through the website or another appropriate method when required.
Your continued use of the website after an updated policy is posted constitutes acknowledgment of the revised policy, subject to any additional consent required by law.
26. Severability
If any provision of this Privacy Policy is determined to be invalid, unlawful, or unenforceable, that provision will be interpreted or limited to the minimum extent necessary.
The remaining provisions will continue in full force and effect.
27. Contact Us
For questions about this Privacy Policy, requests concerning your personal information, or concerns about our privacy practices, contact:
Wellness Refined
A DBA of The Injection Specialist
304 Inverness Way S, Suite 100
Englewood, CO 80112
Phone: 303.565.7735
Email: hello@wellnessrefined.clinic
Privacy Officer: Practice Administrator
Privacy Contact: hello@wellnessrefined.clinic
Please include “Privacy Request” in the subject line when submitting a privacy-rights request.
Do not send urgent medical concerns, medical records, laboratory results, diagnoses, or other sensitive health information through general email.
For questions involving PHI or your patient-record rights, review our HIPAA Notice of Privacy Practices or contact the practice through an approved secure method.