Privacy Policy

Last Revised on January 11, 2023

Welcome to the Privacy Policy (“Privacy Policy”) for Pendulum Therapeutics, Inc. (“Pendulum,” “we” or “us”). This Privacy Policy describes how we collect, use and disclose information about you related to your use of and access to the Pendulum sites, content, applications, services, tools and features, provided by us, including without limitation, the websites: www.pendulum.co and www.pendulumlife.com (each individually referred to herein as the “Site,” or collectively as the “Sites”), any of their subdomains, or any related sites, applications, widgets or online services offered by us (collectively, the “Services”). This Privacy Policy discloses our information collection and dissemination practices in connection with the Services. Please read this Privacy Policy carefully. For purposes of this Privacy Policy, “you” and “your” means you as the user of the Services.

 

What this privacy policy covers: 

This Privacy Policy covers how Pendulum treats information that we collect and receive through the Services, including PI (i.e., information about you that is personally identifiable, such as your name, address, e-mail address, phone number, payment card information, and any other information that you submit, including answers to surveys or questionnaires, testimonials or other information regarding your experiences with Pendulum’s products or services).

 

Information We May Collect About You Includes:

  • Registration details you provide when you create an account, such as your name, email address, telephone number, birthdate, username and password. 
  • PI you provide related to your health condition, including, but not limited to: diabetes related symptoms; triggers you associate with your diabetic conditions; medications you take; information related to your consultations with nutritionists or other healthcare providers; and other medical or health issues.
  • Transaction information, such as your billing address and your payment card information, product details, and the date of purchase and return. 
  • Information you provide when you access or use the Services and each time you interact with the Services or otherwise with us, for example, when you update information in your account, communicate with us by telephone or email, and order or download updates. We also store information about the products you purchase through the Services, such as the product specifications, date of purchase, and details relating to any support issue.
  • Information you provide to the Services, including using our review, comment, testimonials, post or similar functionality. As noted below, if you provide such information to the Services, we will identify you by your initials when posting such information to any public or semi-public part of the Services, including the Sites.
  • Usage, viewing and technical Information, including your IP address or device identifier when you use the Services. If you access your account from a mobile device, that mobile device may also provide us with details of your location. Most mobile devices allow you to disable this functionality.

 

How We Collect Your Information:

  • We collect information you provide to us when you: register with us; input information into the Services; create user generated content; request products, services or information from us; respond to customer surveys; or otherwise interact with us or the Services.
  • Each time you access the Services, Pendulum collects some information to improve the overall quality of your online experience. For example, Pendulum collects aggregate queries for internal reporting and also counts, tracks, and aggregates our users’ activity into Pendulum’s analysis of general traffic-flow on the Services.
  • We collect information through unique identifiers (such as IP address or your mobile device advertising identifier). An Internet Protocol (“IP”) address is a number that automatically identifies the computer/device you have used to access the Internet. The IP address enables our server to send you the web pages that you want to visit, and it may disclose the server owned by your Internet Service Provider.
  • Cookies and Web Beacons. 
    • Cookies are pieces of information that a website transfers to a user’s computer for purposes of storing information about a user’s preferences. Cookies in and of themselves do not personally identify users, although they do identify a user’s computer. Many websites use cookies as a standard practice to provide useful features when a user visits the website and most web browsers are set up to accept cookies. Pendulum uses cookies to improve your online experience when visiting the Site. You can set your browser to refuse cookies, but some portions of the Site may not work properly if you refuse cookies. Some of the Site’s web pages may use web beacons in conjunction with cookies to compile aggregate statistics about website usage. 
    • A web beacon is an electronic image (also referred to as an “action tag,” “singlepixel,” or “clear GIF”) that is commonly used to track the traffic patterns of users from one web page to another in order to maximize web traffic flow and to otherwise analyze the effectiveness of websites. Some web beacons may be unusable if you elect to reject their associated cookies
  • We may also use services hosted by third parties, such as Google Analytics, to better understand who is using the Services, how people are using the Services and how to improve the effectiveness of the Services and its content, and to help those parties serve more targeted advertising to you across the Internet or help us serve more targeted advertising to you. These third parties may use cookies, pixel tags, or other technologies to collect and store information such as time of visit, pages visited, time spent on each page of the Service, device identifiers, type of operating system used and other website(s) you may have visited. They might combine information they collect from your interaction with the Services with PI they collect from other sources. We do not have access to, nor control over, third parties’ use of cookies or other tracking technologies.

 

How Personal Information Provided By You May Be Used:

We use the information that we collect from you to provide you with the Services, support and enhance your access to and use of the Services, to monitor which features of the Services are of most interest and to allow us to determine which features we need to focus on improving. If you choose to provide us with PI, you consent to the transfer and storage of that PI on our servers located in the United States, and to the use of that personal information in accordance with the terms of this Privacy Policy.

 

The Ways in Which We May use your Information Include The Following: 

  • To provide you with the Services and other products and services you request. 
  • To administer your Pendulum account, respond to your inquiries and send you administrative communications. 
  • To communicate with you about your account or transactions with us and send you details or updates about features of the Services or changes to our policies. 
  • To create anonymized and aggregated data sets that may be used for a variety of functions, including research, internal analysis, analytics, and other functions. 
  • To personalize content and experiences and advertising. 
  • To detect, investigate and prevent activities that may violate our policies or be illegal.
  • To optimize or improve the content, products, services, and features of the Services.
  • To evaluate customer response to our products and services, personalize and improve the Services and user experiences, to increase the functionality and user friendliness of the Services, to deliver content or features that match user profiles or interests. 
  • To monitor and analyze the Services usage and trends and otherwise measure the effectiveness of the services.
  • To send you offers and promotions for our other products and services

 

In some cases, Pendulum may use PI submitted by you, such as your answers to questions or surveys about our products or services, your demographic or geographic information, to demonstrate the value of its products and/or services in marketing and/or advertising materials or media. In such cases, Pendulum shall not identify you as the source of such information without your express consent, and absent such consent, shall ensure that any such presented information is anonymized so that the information will not be attributable to you when and as presented.

 

We may participate in behavioral-based advertising and AB testing. This means that a third party may place a cookie on your browser, or use a web beacon, to collect information about your use of our Services so that they can provide advertising about products and services tailored to your interest. That advertising may appear either on our Services or on other websites. If you would like to opt-out from having the behavioral-based advertising companies with whom we have a relationship use your information for advertising purposes, you can do so by visiting the Network Advertising Initiative or Digital Advertising Alliance. Unless you give us permission to do so, Pendulum will not share your PI other than as specified in this Privacy Policy.

 

Disclosures to Third Parties:

We may share your PI outside Pendulum in the following circumstances which you consent to:

  • Pendulum may share your PI with other companies that work with, or on behalf of, Pendulum to provide the Services, including for Services development and maintenance, and operations. We require all third parties to process your data in accordance with this Privacy Policy and as permitted by applicable data protection laws.
  • We do not sell any of your PI to third parties in the traditional sense of the word “sale.” We may, however, share certain information about you with contracted third parties in order to provide better services and advertising to you, and provide you with the option to opt-out of sharing this information, by contacting us via the “How to Contact Us” section below.
  • We may share PI about you with trusted third parties in order to improve your customer experience. These third parties may contact you about products, services or promotions we believe you may be interested in, or to otherwise improve your customer experience with this Site. We provide you with the option to opt-out of sharing this information with such third parties, by contacting us via the “How to Contact Us” section below.
  • We may share PI about you, such as your name, address, e-mail address, telephone number, as well as a record of any transactions you conduct on our Site or offline with us with our third-party advertising partners and service providers, in order to deliver to you banner advertisements and other advertising tailored to your interests when you visit certain websites. Our advertising partners will make the data we provide to them anonymous. To learn more about the use of this information or to make choices about receiving personalized advertising provided by third parties, please visit the Network Advertising Initiative here.
  • We may disclose your PI when you request our referral services to forward or share certain content with a friend, such as an email or text message inviting a friend to use the Services or sharing certain content from the Services with a friend.
  • We may disclose your PI to respond to subpoenas, court orders, legal process or governmental regulations, or to establish or exercise our legal rights or defend against legal claims. We may also disclose your PI if we believe it is necessary to share PI in order to investigate, prevent or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, or as otherwise required by law or regulation.
  • We may share your PI in connection with the sale of a business (including merger, acquisition, or sale of all or a material portion of its assets, change in corporate control, or insolvency or bankruptcy proceedings).

 

In addition, we may share non-PI and aggregated data sets with third parties, alone or in combination with anonymous data of other users.

 

Posting Reviews or Other Comments to the Services:

If you submit a review or provide other comments to the Services, and we display such comments on a public or semi-public part of the Services, we will identify you by your first name and last name initials.

 

Your Controls and Choices:

We provide you the ability to exercise certain controls and choices regarding our collection, use and sharing of your PI. Your controls and choices may include:

  • You may correct, update and delete your registration account. 
  • You may change your choices for newsletters and alerts. 
  • You may choose whether to receive from us offers and promotions for our products and services. 
  • You may request access to the PI we hold about you and that we amend or delete it.

You may exercise your controls and choices, or request access to your PI, by modifying your profile or by contacting us at hello@pendulumlife.com or following instructions provided in communications sent to you. Please be aware that, if you do not allow us to collect PI from you, we may not be able to deliver certain products and services to you, and some of our services may not be able to take account of your interests and preferences. If you have questions regarding the specific PI about you that we process or retain, please contact us at hello@pendulumlife.com.

 

Referrals and Links:

The Site may contain links to third-party websites that may offer information of interest. We do not control such other online platforms and are not responsible for their content, their privacy policies, or their use of your PI. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators except as disclosed on the Services. This Privacy Policy does not apply to those websites, and Pendulum recommends reviewing those websites’ privacy policies individually. We expressly disclaim any and all liability for the actions of third parties, including but without limitation to actions relating to the use and/or disclosure of PI by third parties.

 

Security:

Please note that PI you send to us electronically may not be secure when it is transmitted to us. We recommend that you do not use unsecure channels to communicate sensitive or confidential PI to us. From time to time, we review our security procedures to consider appropriate new technology and methods. Our products and services are not governed by HIPAA but in the interest of our customers’ privacy we have implemented robust security safeguards as described herein. Please be aware though that, despite our best efforts, no security measures are perfect or impenetrable. We will retain your PI for the length of time needed to fulfill the purposes outlined in this Privacy Policy unless a longer retention period is required, or for the establishment, exercise or defense of legal claims, or for legitimate businesses purposes, or as provided by law.

 

To provide secure credit card processing when ordering from us, orders placed through our Services are processed through Shopify Inc (“Shopify”), which operates under its own privacy policy. If you choose to make purchases from us online using a credit card, the credit card PI is sent to Pendulum using SSL (Secure Socket Layer) encryption, an industry-standard method for protecting data as it travels over the Internet, or a similar encryption technology that may become accepted as an industry standard, or better encryption method, in the future. To learn more about our credit card processing vendor, Shopify, and its respective privacy and other policies which apply when you make a payment through their services, please review the terms of Shopify’s privacy policies.

 

CCPA: 

Under the California Consumer Privacy Act of 2018, as amended (“CCPA”), California residents are afforded certain rights about the personal information (as such term is defined under the CCPA) we have collected about them, which we have described in more detail below. In the chart below, we have described the categories of personal information that we have collected and shared over the past twelve (12) months, the purposes for such collection and the types of entities with whom we have shared such information.



Categories of Personal Information

Sources of Information

Use of Information

Sharing of Information

Identifiers, including your name, postal address, e-mail address, and telephone number. These data types also include “personal information,” as the term is defined by Cal. Civ. Code 1798. 

We collect this information directly from you.

We use this information to: provide, maintain, and improve our Services; deliver products to you; respond to customer inquiries; and personalize your online experience. 

We share this information with service providers who help us provide, maintain, and improve our Services; deliver products to you; and personalize your online experience. 

Commercial information.

We collect this information directly from you.

We use this information to process your transactions and deliver our products to you.

We share this information with service providers who help us to process your transactions. 

Internet or other electronic network activity information, such as IP addresses and cookies. 

We collect this information automatically from your computer or device.

We use this information to provide, maintain, and improve our Services and to personalize your online experience.

We share this information with service providers who collect this information on our behalf to help us provide, maintain, and improve our Services and to personalize your online experience.

Geolocation data.

We collect this information from your device when you give us permission to do so.

We use this information to provide features of our Service and to improve and customize our Services

We work with service providers who collect this information on our behalf to help us provide, maintain, and improve our Services and to personalize your online experience.

Inferences drawn from any of the information identified above, such as your preferences, interests, and other information used to personalize your experience. 

This information is derived from the categories above. 

We collect this information to personalize and improve the Services and to perform other business purposes.

We work with service providers who collect this information on our behalf to help us provide, maintain, and improve our Services and to personalize your online experience.

 

Your rights and choices:

California residents have the following rights under the CCPA: 

  • (i) the right to be notified about what personal information is collected about you, and our intended use and purpose for collecting your personal information, 
  • (ii) the right to know and access personal information we have collected, used, disclosed, or sold about you over the past twelve (12) months, including the categories of personal information we have collected, used, disclosed, or sold about you, the categories of sources from which the personal information is collected, the business or commercial purpose for which your personal information was collected, used, disclosed, or sold, and the categories of third parties with whom we have shared your personal information, 
  • (iii) the right to request Pendulum to transfer, to the extent feasible, personal information in certain forms and formats, 
  • (iv) the right to request that we delete/erase your personal information under certain circumstances, and 
  • (v) the right not to be subject to discrimination for asserting your rights under the CCPA. 

The personal information we collect from you, the purposes for which it is used, the source of such personal information, and the parties to whom we share your personal information is set forth in this Privacy Policy. 

 

Further, under the California “Shine the Light Law,” California residents have the right to request certain details about how their “personal information” (as defined in Cal. Civil Code § 1798.83) is shared with third parties for direct marketing purposes. To the extent we have shared personal information in this way, California residents may, under certain circumstances, request and obtain certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. 

 

To exercise any of the CCPA’s data privacy rights set forth herein, please contact us in accordance with the “Contact Us” section listed below. If you would prefer, you may designate an authorized agent to submit a CCPA privacy request on your behalf. An authorized agent must be registered with the California Secretary of State to conduct business in California. For information pertaining to your rights with respect to our financial incentive programs, please see below (“Rewards Programs and Financial Incentives”).

 

Privacy Request Verification Process:

If you (or your authorized agent) makes any request related to your personal information under the CCPA, Pendulum will ascertain your identity (and the identity of the authorized agent, to the extent applicable) to the degree of certainty required or permitted under the law before addressing your request. You may make a verifiable consumer request to access your personal information twice per twelve (12) month period. We aim to fulfill all verified requests within 45 days pursuant to the CCPA. If necessary, extensions for an additional 45 days will be accompanied by an explanation for the delay.

 

Pendulum will, to the extent required or permitted by law, require you (or your authorized agent) to verify your request via email or other means and match at least two or three pieces of personal information we have previously collected from you before granting you access to, or erasing, specific pieces or categories of personal information, or otherwise responding to your request. 

 

We may require written documentation that demonstrates a third party is authorized to serve as your agent for the purposes of submitting the requests set forth herein, unless you have provided the authorized agent with power of attorney pursuant to California Probate Code §§ 4121 to 4130. None of the CCPA’s rights are absolute and are subject to legal and regulatory exceptions and exemptions. For more information about the CCPA, please see: https://oag.ca.gov/privacy/ccpa. 

 

Opt-Out Rights / Do Not Sell My Personal Information. California residents have the right to opt out of the sale of their personal information. Pendulum does not sell your personal information to third parties for profit. However, we do use third-party website analytical tools and features and marketing partners, and such relationships may involve the disclosure of your personal information for “valuable consideration” as set forth in the CCPA. To opt-out of the “sale” of your personal information in these circumstances, please click on the “Do Not Sell My Personal Information” link on the footer of the Site. You (or your authorized agent) may also contact us in accordance with the “Contact Us” section listed below. 

 

The Site is not directed at, and should not be used by, minors under the age of sixteen (16), and therefore Pendulum does not knowingly sell the personal information of minors under sixteen (16) years of age without affirmative authorization.

 

CHILDREN’S PRIVACY PROTECTION 

We do not seek or knowingly collect any personal information about children under 18 years of age. If we become aware that we have unknowingly collected personal information from a child under 18 years of age, we will make commercially reasonable efforts to delete such information from our database. If you are the parent or guardian of a child under 18 years of age who has provided us with personal information, you may contact us to request it be deleted.

 

UPDATING THIS PRIVACY POLICY 

We may modify this Privacy Policy from time to time in which case we will update the “Last Revised” date at the top of this Privacy Policy. If we make changes that are material, we will use reasonable efforts to attempt to provide notice to you and, where required by applicable law, we will obtain your consent. Notice may be by email to you at the last email address you provided us, by posting notice of such changes on the Services, or by other means, consistent with applicable law. However, it is your sole responsibility to review the Privacy Policy from time to time to view any such changes. The updated Privacy Policy will be effective as of the time of posting, or such later date as may be specified in the updated Privacy Policy. IF YOU DO NOT ACCEPT THIS PRIVACY POLICY, INCLUDING ANY CHANGES, THEN YOU MUST NOT ACCESS OR USE THE SERVICES.

 

How to Contact Us:

You may contact us regarding the Services or this Privacy Policy at: