Essos Privacy Policy
Last updated: November 18th, 2025.
This Privacy Policy describes how Essos Technologies Incorporated ("Essos," "we", "us" or "our") processes personal information that we collect through our digital and online properties or services that link to this Privacy Policy (including as applicable, our website located at https://www.essos.com/, web application, member platform, electronic communications, and social media pages) as well as our marketing activities, and other activities described in this Privacy Policy (collectively, the "Service").
DUE TO LAWS THAT APPLY TO SENSITIVE PERSONAL INFORMATION SUCH AS HEALTH INFORMATION, OUR SERVICES ARE NOT AVAILABLE TO RESIDENTS OF WASHINGTON, NEVADA, OR CONNECTICUT. BY ACCESSING OR USING OUR SERVICES, YOU REPRESENT AND WARRANT THAT YOU ARE NOT A RESIDENT OF ANY OF THESE STATES. IF WE BECOME AWARE THAT YOU ARE A RESIDENT OF WASHINGTON, NEVADA, OR CONNECTICUT, WE MAY DISCONTINUE YOUR ACCESS TO THE SERVICES AND DELETE YOUR PERSONAL DATA IN ACCORDANCE WITH APPLICABLE LAW.
ADDITIONALLY, DUE TO LAWS THAT APPLY TO BIOMETRIC DATA, FACIAL RECOGNITION AND RELATED BIOMETRIC FEATURES ARE NOT AVAILABLE TO USERS LOCATED IN OR RESIDENTS OF ILLINOIS, TEXAS, WASHINGTON OR COLORADO. USERS IN THESE STATES MAY NOT USE ANY FEATURE THAT COLLECTS, ANALYZES, OR STORES FACIAL OR BIOMETRIC DATA. WE MAY USE TECHNICAL MEASURES (SUCH AS GEOLOCATION RESTRICTIONS) TO ENFORCE THIS LIMITATION.
This Privacy Policy does not apply to our employees or independent contractors or job candidates.
This Privacy Policy does not apply to representatives of businesses with which we have a business relationship.
Index
Other sites and services
Children and teens
Changes to this Privacy Policy
How to contact us
Personal information we collect
Information you provide to us. Personal information you may provide to us through the Service includes:
Contact data, such as your first and last name, alias, signature, salutation, email address, billing and mailing addresses, and phone number.
Demographic data, such as your city, state, country of residence, postal code, and gender.
Profile data, such as account name, the username and password that you may set to establish an online account on the Service, procedures of interest, date of birth, preferences, and any other information that you add to your account profile.
Health data, such as your height and weight, medical history, pregnancy history, current medications and supplements, surgical history, information related to scarring, bleeding, and transfusions, allergies, and personal habits (e.g., whether you use tobacco products or drink alcohol).
Procedure logistics data, such as flight (e.g., source and destination IATA codes, frequent flyer numbers, flight and airplane numbers, and layover information) and hotel booking information (e.g., hotel name, address, and duration of your stay) in connection with any procedures that you book with healthcare providers ("Providers").
Transactional data, such as information relating to or needed to book your procedures on or through the Service, including date and type of procedure and Provider information. This includes procedure history.
Payment data needed to complete transactions, including payment card information or bank account number. We use a third-party vendor to directly collect and process your payment card information, as described further below.
Communications data based on our exchanges with you and your exchanges with Providers, including when you contact us through the Service, communicate with us via email, phone, social media, or otherwise, and when you communicate with a Provider through our Service.
Marketing data, such as your preferences for receiving our marketing communications and details about your engagement with them.
User-generated content data, such as any communications you send to other users through the Service as well as your comments, reviews, questions, messages, photos, and other content or information that you generate, transmit, or otherwise make available on the Service, including associated metadata. Metadata includes information on how, when, where and by whom a piece of content was collected and how that content has been formatted or edited. Metadata also includes information that users can add or can have added to their content, such as keywords, geographical or location information, and other similar data.
Call/audio data, such as your virtual consultations with our Providers. Note that while we assist in scheduling your virtual consultations, we do not have access to such consultations. We collect call and audio data through our third-party vendor, Sendbird. Please refer to Sendbird's privacy policy to learn more about how they collect and process personal data: https://sendbird.com/privacy-notice.
Sensitive Personal Information, including biometric data, your precise location, and contents of a communication to which we were not a party.
Other data not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection.
Data about others. We request that users provide information about their emergency contact, and we may collect contact details (including name and phone number) for these individuals so we can reach out in case of an emergency. Please do not refer someone to us or share their contact details unless you have their permission to do so.
Third-party sources. We may combine personal information we receive from you with personal information falling within one of the categories identified above that we obtain from other sources, such as:
Public sources, such as credit bureaus, government agencies, public records, social media platforms, and other publicly available sources.
Service providers that provide services on our behalf or help us operate the Service or our business.
Data analytics providers.
Ad networks.
Social media platforms.
Automatic data collection. We, our service providers, and our advertising partners may automatically log information about you, your computer or mobile device, and your interaction over time with the Service, our communications and other online services, such as:
Device data, such as your computer or mobile device's operating system type and version depending on the browser that you use, manufacturer and model, browser type, screen resolution, device type (e.g., phone, tablet), IP address, unique identifiers (including identifiers used for advertising purposes), language settings, mobile device carrier, radio/network information (e.g., Wi-Fi, LTE, 3G), and general location information such as city, state or geographic area.
Location data when you authorize the Service to access your device's location.
Communication interaction data such as your interactions with our email, text, or other communications (e.g., whether you open and/or forward emails) – we may do this through use of pixel tags (which are also known as clear GIFs), which may be embedded invisibly in our emails enabling us to detect if you have opened or forwarded a message.
Online activity data, such as pages or screens you viewed, search history, how long you spent on a page or screen, the website you visited before browsing to the Service, navigation paths between pages or screens, information about your activity on a page or screen, access times and duration of access, and whether you have opened our emails or clicked links within them.
Tracking technologies
Some of the automatic collection described above is facilitated by the following technologies:
Cookies, which are small text files that websites store on user devices and that allow web servers to record users' web browsing activities and remember their submissions, preferences, credentials, and login status as they navigate a site. Cookies used on our sites include both "session cookies" that are deleted when a web browser session ends, "persistent cookies" that remain longer, "first party" cookies that we place and "third party" cookies that our service providers and other third parties place.
Local storage technologies, like HTML5, that provide cookie-equivalent functionality but can store larger amounts of data on your device outside of your browser in connection with specific applications.
Web beacons, also known as pixel tags or clear GIFs, which are used to demonstrate that a webpage or email was accessed or opened, or that certain content was viewed, clicked or forwarded.
How we use your personal information
We may use your personal information for the following purposes or as otherwise described at the time we collect personal information from you:
Service delivery and operations. We may use your personal information to:
provide and operate the Service;
suggest vetted providers and facilitate consultations;
assign and support your dedicated care advisor;
process payments and assist our members with booking flights and hotels;
process your requests, orders and transactions;
enable security features of the Service;
personalize the service, including remembering the devices from which you have previously logged in and remembering your selections and preferences as you navigate the Service;
establish and maintain your user profile on the Service;
communicate with you about the Service, including by sending Service-related announcements, updates, security alerts, user-to-user communications, and support and administrative messages;
communicate with you about events for which you register;
understand your needs and interests, and personalize your experience with the Service and our communications;
provide support for the Service, and respond to your requests, questions and feedback;
collect and share user testimonials; and
fraud prevention and security.
Research and development. We may use your personal information for research and development purposes, including to develop, analyze and improve our products and services. As part of these activities, we may create aggregated, de-identified or other anonymous data from personal information. We may use this anonymous or de-identified data and share it with third parties for any lawful business purposes. We do not attempt to reidentify deidentified information derived from personal information, except for the purpose of testing whether our deidentification processes comply with applicable law.
Marketing and advertising. We and our third-party advertising partners may collect and use your personal information for marketing and advertising purposes:
Direct marketing. We may send you direct marketing communications and may personalize these messages based on your needs and interests. You may opt-out of our marketing communications as described in the Opt-out of marketing section.
Interest-based advertising. We and our third-party advertising partners may use cookies, pixels and other technologies to collect information about your interaction (including the data described in the Automatic Data Collection section above) with the Service, our communications and other third party online services over time, and use that information to serve online ads that they think will interest you. This is called interest-based advertising. We may also share information about our users with these companies to facilitate interest-based advertising to those or similar users on other online properties. You can learn more about your choices for limiting interest-based advertising in the Your choices section.
Compliance and protection. We may use your personal information to:
comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas, court orders, investigations or requests from government authorities;
protect our, your or others' rights, privacy, safety or property (including by making and defending legal claims);
audit our internal processes for compliance with legal and contractual requirements or our internal policies;
enforce the terms and conditions that govern the Service; and
prevent, identify, investigate and deter fraudulent, harmful, unauthorized, unethical or illegal activity, including cyberattacks and identity theft.
With your consent. In some cases, we may specifically ask for your consent to collect, use, or share your personal information for further purposes, if those purposes are not compatible with the initial purpose for which that personal information was collected.
Cookies and similar technologies. In addition to the other uses included in this section, we may use the Cookies and similar technologies described above for the following purposes:
Technical operation. To allow the technical operation of the Service.
Functionality. To enhance the performance and functionality of our services.
Analytics. To help us understand user activity on the Service, including the volume and demographics of users, which pages are most and least visited and how visitors move around the Service, as well as user interactions with our emails. For example, we use Google Analytics for this purpose. You can learn more about Google Analytics and how to prevent the use of Google Analytics relating to your use of our sites here: https://tools.google.com/dlpage/gaoptout.
Data sharing in the context of corporate transactions, we may share certain personal information in the context of actual or prospective corporate transactions – for more information, see How we share your personal information, below.
Further uses, in some cases, we may use your personal information for further uses, in which case we will ask for your consent to use your personal information for those further purposes if they are not compatible with the initial purpose for which information was collected.
Your choices
In this section, we describe the choices available to you.
Access or update your information. If you have registered for an account with us through the Service, you may review and update certain account information by logging into the account and navigating to your account profile and settings.
Opt-out of communications. You may opt-out of marketing-related emails by following the opt-out or unsubscribe instructions at the bottom of the email, or by contacting us. It may take time for your opt-out to be effective. Please note that if you choose to opt-out of marketing-related emails, you may continue to receive service-related and other non-marketing emails. You may opt-out of text messages by texting "STOP" in response to a text that you receive or by other reasonable means.
Mobile location data. You can disable our access to your device's precise geolocation in your mobile device settings.
Cookies. Most browsers let you remove or reject cookies. To do this, follow the instructions in your browser settings. Many browsers accept cookies by default until you change your settings. Please note that if you set your browser to disable cookies, the Service may not work properly. For more information about cookies, including how to see what cookies have been set on your browser and how to manage and delete them, visit http://www.allaboutcookies.org.
Blocking images/clear gifs: Most browsers and devices allow you to configure your device to prevent images from loading, so the business hosting the image will not detect that you have viewed a page. To do this, follow the instructions in your particular browser or device settings.
Do Not Track. Some Internet browsers may be configured to send "Do Not Track" signals to the online services that you visit. We currently do not respond to "Do Not Track" signals. To find out more about "Do Not Track," please visit http://www.allaboutdnt.com.
Advertising choices
You may be able to limit use of your information for interest-based advertising through the following settings/options/tools:
Browser settings. Changing your internet web browser settings to block third-party cookies.
Privacy browsers/plug-ins. Using privacy browsers and/or ad-blocking browser plug-ins that let you block tracking technologies.
Platform settings. Google and Facebook offer opt-out features that let you opt-out of use of your information for interest-based advertising. You may be able to exercise that option at the following websites:
Google: https://adssettings.google.com/
Facebook: https://www.facebook.com/about/ads
Ad industry tools. Opting out of interest-based ads from companies that participate in the following industry opt-out programs:
Network Advertising Initiative: http://www.networkadvertising.org/managing/opt_out.asp
Digital Advertising Alliance: https://optout.aboutads.info
AppChoices mobile app, available at https://www.youradchoices.com/appchoices, which will allow you to opt-out of interest-based ads in mobile apps served by participating members of the Digital Advertising Alliance.
Mobile settings. Using your mobile device settings to limit use of the advertising ID associated with your mobile device for interest-based advertising purposes.
You will need to apply these advertising-related opt-out settings on each device and browser from which you wish to limit the use of your information for interest-based advertising purposes. We cannot offer any assurances as to whether the companies we work with participate in the opt-out programs described above.
Declining to provide information. We need to collect personal information to provide certain services. If you do not provide the information we identify as required or mandatory, we may not be able to provide those services.
Other sites and services
The Service may contain links to websites, mobile applications, and other online services operated by third parties. In addition, our content may be integrated into web pages or other online services that are not associated with us. These links and integrations are not an endorsement of, or representation that we are affiliated with, any third party. We do not control websites, mobile applications or online services operated by third parties, and we are not responsible for their actions. We encourage you to read the privacy policies of the other websites, mobile applications and online services you use.
Security
We employ technical, organizational and physical safeguards that are designed to protect the personal information we collect. However, security risk is inherent in all Internet and information technologies, and we cannot guarantee the security of your personal information.
International data transfer
We are headquartered in the United States and may use service providers that operate in other countries. Your personal information may be transferred to the United States or other locations where privacy laws may not be as protective as those in your state, province, or country.
Children and Teens
The Service is not intended for use by anyone under 18 years of age. If you are a parent or guardian of a minor from whom you believe we have collected personal information in a manner prohibited by law, or if information was provided on your behalf when you were under 18, please contact us. If we learn that we have collected personal information through the Service from a child without the consent of the child's parent or guardian as required by law, we will comply with applicable legal requirements to delete the information.
Changes to this Privacy Policy
The "LAST UPDATED" legend at the top of this Privacy Policy indicates when this Privacy Policy was last revised. We reserve the right to modify this Privacy Policy at any time. We will notify you by updating the "Last Updated" date. Depending on the kind of change we make, we may also notify you directly or ask for your consent to the change. Any modifications to this Privacy Policy will be effective upon our posting the modified version or as otherwise indicated at the time of posting.
How to contact us
Email: legal@essos.com
Mail: Essos Technologies Incorporated 401 Broadway, Suite 1610 New York, NY 10013