Privacy Policy
Your privacy matters to us
PRIVACY POLICY
Aspen Aesthetics, LLC, dba Fifty 410 Health
Effective Date: September 2026 | Last Updated: September 8, 2026
Aspen Aesthetics, LLC, dba Fifty 410 Health (“Fifty 410,” “Company,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect information about you when you visit www.fifty410.com, access our patient portal, communicate with us, or otherwise use our telehealth platform and related services (collectively, the “Services”).
This Privacy Policy is incorporated into and made part of our Terms of Service. Please also review our Telehealth Informed Consent and the Practice's HIPAA Notice of Privacy Practices. Other treating Providers and dispensing pharmacies may issue their own notices during the patient-care process. Washington residents, individuals whose consumer health data is collected in Washington, and Nevada and Connecticut residents should also review our Consumer Health Data Privacy Notice.
BY ACCESSING OR USING THE SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTAND THIS PRIVACY POLICY. IF YOU DO NOT AGREE, PLEASE DO NOT USE THE SERVICES.
1. HOW THIS POLICY WORKS WITH HIPAA
Not all information we handle is governed by the same law. Understanding the difference matters, because your rights differ depending on which category your information falls into.
1.1 Protected Health Information (PHI)
Under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”), Protected Health Information (“PHI”) generally means individually identifiable information about health, healthcare, or payment for healthcare that is held or transmitted by a HIPAA covered entity or its business associate, subject to applicable exclusions. This can include information about past, present, or future care, including an intake or a request for care before a treatment relationship has been established.
Fifty 410 Health is not a medical practice, provider, or pharmacy. Licensed healthcare Providers and pharmacies accessible through the Services are independent entities. When Fifty 410 handles PHI on behalf of a HIPAA covered Provider or pharmacy, that handling is governed by applicable contracts and HIPAA requirements, including a Business Associate Agreement where required.
Our handling of PHI is subject to HIPAA and the applicable Provider's or pharmacy's notice. Read the Practice's HIPAA Notice of Privacy Practices for information about its clinical records and your rights. Where this Privacy Policy conflicts with the applicable notice regarding PHI, that notice controls. This Privacy Policy does not authorize a use or disclosure of PHI that HIPAA does not permit.
1.2 Information Not Covered by HIPAA
Whether information is PHI depends on who collects or handles it, the capacity in which they act, and its connection to healthcare or payment. It does not depend solely on whether you have already become a patient or where you submit the information.
Information handled outside a covered entity or business associate relationship may fall outside HIPAA. For example, general website interactions, marketing preferences, public community activity, or non-clinical support requests may fall into this category, depending on the circumstances. This Privacy Policy applies to such information, which may still be protected by state consumer privacy, consumer health data, and other applicable laws.
2. INFORMATION WE COLLECT
2.1 Information You Provide to Us
- Account and identity information: name, date of birth, email address, mailing and shipping address, telephone number, username and password, and government-issued identification or selfie images submitted for identity verification.
- Health and clinical information: medical history, current and past medications, allergies, height, weight, BMI, medical conditions and diagnoses, family history, symptoms, adverse events and side effects, photographs you submit, laboratory results, treatment preferences, and your responses to intake, refill, and check-in questionnaires.
- Payment information: billing address, payment card or bank account details, FSA/HSA card information, and financing application information. Full payment card numbers are collected and processed directly by our PCI-DSS compliant payment processors; we do not store full card numbers on our systems.
- Communications: the content of emails, SMS messages, secure portal messages, chat sessions, customer support tickets, and recorded or transcribed telephone calls, where permitted by law and with any required notice or consent.
- User content: reviews, testimonials, survey responses, before-and-after photographs you elect to share, and posts or comments in the Fifty 410 community.
- Referral information: if you refer another person, the name and contact information you provide about them.
2.2 Information Collected Automatically
- Device and connection data: IP address, device identifiers, browser type and version, operating system, language settings, and approximate location derived from IP address.
- Usage data: pages viewed, links clicked, referring and exit pages, search terms entered on our site, and time spent.
- Local website storage: limited preference and technical data described in Section 5.
2.3 Information We Receive from Third Parties
- Providers, pharmacies, and laboratories: prescription status, dispensing and fill records, shipment tracking, and lab results.
- Payment processors and financing partners: transaction status, chargeback and dispute records, and fraud signals. We do not receive your full financial account credentials.
- Shipping and logistics providers: delivery status, delivery exceptions, and address validation results.
- Identity verification and fraud prevention vendors: verification results and risk scores.
- Publicly and commercially available sources: where used to validate contact information or prevent fraud.
3. SENSITIVE INFORMATION AND CONSUMER HEALTH DATA
Some of the information we collect is treated as sensitive personal information or consumer health data under state law. This includes health conditions, treatments and medications, biometric or identity-verification data, precise geolocation (if ever collected), account credentials, and government identifiers.
We process sensitive personal information and consumer health data only:
- to provide the Services you request;
- for purposes permitted without consent under applicable law, such as security, fraud prevention, and legal compliance; or
- with your consent, where consent is required.
WE DO NOT SELL YOUR HEALTH INFORMATION, AND WE DO NOT SHARE YOUR HEALTH INFORMATION WITH THIRD PARTIES FOR THEIR OWN CROSS-CONTEXT BEHAVIORAL ADVERTISING PURPOSES.
Washington residents, individuals whose consumer health data is collected in Washington, and Nevada and Connecticut residents should also review our Consumer Health Data Privacy Notice, which provides additional disclosures required by those states’ laws.
4. HOW WE USE INFORMATION
We use the information described above to:
- Provide the Services — create and maintain your account, route your intake to a licensed Provider, transmit prescriptions to dispensing pharmacies, coordinate laboratory testing, arrange shipment, and support refills and follow-up care.
- Process payments — bill you, process refunds and credits where applicable, administer financing and FSA/HSA transactions, and respond to chargebacks and payment disputes.
- Communicate with you — send appointment reminders, refill notices, shipping and delivery notifications, safety and recall information, account and billing notices, and responses to your inquiries.
- Support safety and quality — monitor and report adverse events, respond to pharmacovigilance obligations, conduct clinical documentation and chart review, and improve clinical protocols.
- Improve and develop the Services — troubleshoot, evaluate aggregate service performance, and develop new features and offerings.
- Market our Services — send promotional emails and text messages and personalized offers, subject to your choices in Section 6 and applicable law.
- Protect the Services — verify identity, detect and prevent fraud, abuse, diversion of prescription medications, and unauthorized access.
- Comply with law — meet obligations under federal and state healthcare, pharmacy, tax, and consumer protection laws, and respond to lawful requests from regulators, law enforcement, and courts.
We do not use automated processing to make decisions that produce legal or similarly significant effects about you without human involvement. All clinical decisions, including whether to prescribe, are made by a licensed Provider exercising independent medical judgment.
5. WEBSITE STORAGE AND TRACKING TECHNOLOGIES
Our website may use browser storage or similar first-party technology that is necessary to operate the site, remember a language or accessibility preference, maintain security, or preserve information you enter during a session.
Our commitments regarding tracking technology:
- We do not deploy third-party analytics or advertising pixels on the website.
- We do not transmit health information, intake responses, or prescription information to advertising platforms.
- We do not use geofencing to identify, track, or send messages to consumers based on proximity to any healthcare facility, pharmacy, or provider location.
You can remove or block first-party browser storage through your browser settings, although doing so may reset preferences or affect website functionality. Because we do not sell personal information, share it for cross-context behavioral advertising, or use targeted-advertising technology, there is no sale, sharing, or targeted-advertising activity to opt out of on this website.
6. TEXT MESSAGES, EMAIL, AND TELEPHONE COMMUNICATIONS
6.1 SMS Text Messaging
We use SMS text messaging to support your care and your account. Full program terms are set out in the SMS Text Messaging section of our Terms of Service.
Consent is collected separately for each message category. We do not treat consent to one category as consent to another, and we do not use blanket or shared opt-ins.
- Verification codes — one-time passcodes for login, account creation, and password reset. You request the code by entering your number and choosing to receive it.
- Transactional and care-related — order confirmations, shipping and delivery notices, refill reminders, appointment reminders, and safety notices. Consent is given by a separate checkbox at intake or in account settings.
- Marketing and promotional — offers, product announcements, and program news. Consent is given by a separate, unchecked opt-in checkbox.
Message frequency varies. Message and data rates may apply for any messages sent to you from us and to us from you. Carriers are not liable for delayed or undelivered messages. If you have questions about your text plan or data plan, contact your wireless provider.
- Reply STOP to any message to cancel messages in that category.
- Reply HELP for help, or contact us at [email protected]. This support contact does not require a login to reach.
- Opting out of marketing text messages does not stop verification, transactional, or clinical messages necessary to deliver your care. To stop those, you may need to change your account settings or contact us.
- We maintain records of your consent and of any opt-out request.
How your mobile information is handled:
- No mobile numbers will be shared with third parties or affiliates for marketing or promotional purposes.
- Text messaging originator opt-in data and consent will not be shared with any third parties. This exclusion applies to every other disclosure described in this Privacy Policy — no category of sharing described in Section 7 includes SMS opt-in data or consent.
- Your mobile number is disclosed only to the messaging service providers that transmit the messages on our behalf, and those providers are contractually prohibited from using it for any other purpose.
6.2 Message Delivery Providers
Message categories may be delivered through service providers acting on our instructions. They may use mobile information only to provide the messaging services we request and may not use it for their own marketing or promotional purposes.
6.3 Email
You may unsubscribe from marketing emails using the link in any marketing message or by contacting us. Transactional, clinical, safety, and account communications will continue.
6.4 Telephone
We may call you regarding your account, orders, or care. Calls may be monitored or recorded for quality assurance, training, and documentation purposes where permitted by law and with any legally required notice or consent.
7. HOW WE DISCLOSE INFORMATION
WE DO NOT SELL YOUR PERSONAL INFORMATION FOR MONEY, AND WE DO NOT SHARE IT FOR CROSS-CONTEXT BEHAVIORAL ADVERTISING, AS THOSE TERMS ARE DEFINED UNDER STATE LAW.
We disclose information in the following circumstances:
- Licensed Providers — intake responses, health history, communications, and treatment records, so they can evaluate you and make clinical decisions.
- Compounding and retail pharmacies — prescription, identity, shipping, and payment-status information, to dispense and ship your medication.
- Laboratory partners — identity and order information, to perform ordered testing and return results.
- Service providers and business associates — only what is necessary for their function, including hosting, intake and portal platform, secure messaging, customer support tooling, and IT security, under written contracts restricting further use.
- Payment processors and financing partners — billing and transaction information, to process payments, refunds, and disputes.
- Shipping and logistics providers — name, address, and package information, to deliver your order.
- Identity verification and fraud vendors — identity and device signals, to verify you and prevent fraud and diversion.
- Regulators, law enforcement, and courts — as legally required, to comply with subpoenas, court orders, investigations, mandatory reporting, and other legal obligations.
- Acquirers in a corporate transaction — information relevant to a merger, acquisition, financing, reorganization, or sale of assets, subject to this Policy and applicable law.
- Others you authorize — where you give written authorization or direct us to share.
We may also disclose information where necessary to protect the rights, property, or safety of you, our patients, our workforce, or the public, including reporting suspected adverse events, abuse, or imminent harm.
De-identified and aggregated data. We may create and use de-identified or aggregated information for research, analytics, quality improvement, and business purposes. We maintain such information in de-identified form and will not attempt to re-identify it, except as permitted by law to test de-identification methods.
8. YOUR PRIVACY RIGHTS
8.1 Rights Under State Consumer Privacy Laws
Depending on your state of residence, you may have the right to:
- Know and access the personal information we have collected about you, the categories of sources, the purposes for processing, and the categories of third parties to whom we disclose it;
- Obtain a copy of your personal information in a portable format;
- Correct inaccurate personal information;
- Delete personal information we hold about you;
- Opt out of the sale of personal information, sharing or processing for targeted advertising, and profiling that produces legal or similarly significant effects;
- Limit the use and disclosure of sensitive personal information;
- Withdraw consent previously given for the processing of consumer health data;
- Appeal a denial of a request; and
- Be free from discrimination for exercising any of these rights.
8.2 Important Limits on Deletion
Medical records cannot always be deleted. Federal and state law require Providers and pharmacies to retain clinical, prescribing, and dispensing records for minimum periods regardless of a deletion request. Requests to delete records maintained under HIPAA are handled under HIPAA, not under state consumer privacy law, and HIPAA does not provide a general right to have your medical record deleted. We will honor deletion requests to the extent the law allows and will tell you what we cannot delete and why.
8.3 How to Exercise Your Rights
Submit a request by:
- Email: [email protected]
- Mail: Privacy Officer, Aspen Aesthetics, LLC dba Fifty 410 Health, 1630 W Prosper Trail, Suite 620, Prosper, Texas 75078
We will verify your identity before responding, using information already in our possession. We will respond within 45 days, and may extend once by an additional 45 days where reasonably necessary, with notice to you. There is no charge for up to two requests in a twelve-month period; we may charge a reasonable fee for manifestly unfounded, excessive, or repetitive requests, or decline to act with an explanation.
Authorized agents may submit requests on your behalf with written permission signed by you and proof of the agent’s identity. We may still require you to verify your own identity directly.
Appeals. If we deny your request, you may appeal by writing to [email protected] with the subject line “Privacy Request Appeal.” We will respond within 60 days, or the shorter period your state requires. If your appeal is denied, we will provide instructions for contacting your state Attorney General.
9. STATE-SPECIFIC DISCLOSURES
9.1 California
California residents have the rights described in Section 8 under the California Consumer Privacy Act, as amended (“CCPA”). In addition:
- Categories collected in the past 12 months: identifiers; personal records under Cal. Civ. Code § 1798.80; protected classification characteristics such as age, sex, and medical condition; commercial information; internet and network activity; approximate geolocation; audio and visual information; and inferences. Sensitive personal information collected includes health information, account credentials, and government identifiers.
- Sale and sharing: we have not sold or shared personal information in the preceding 12 months, and we do not knowingly sell or share the personal information of consumers under 16.
- Retention: see Section 10.
- Medical information is additionally protected under the California Confidentiality of Medical Information Act (CMIA), Cal. Civ. Code § 56 et seq.
- Shine the Light: California residents may request information about disclosures to third parties for direct marketing purposes. We do not make such disclosures.
9.2 Texas
Texas residents have the rights described in Section 8 under the Texas Data Privacy and Security Act.
NOTICE: WE MAY COLLECT AND PROCESS YOUR SENSITIVE PERSONAL DATA, INCLUDING HEALTH DATA, CONSISTENT WITH THIS PRIVACY POLICY AND ONLY WITH YOUR CONSENT WHERE REQUIRED.
9.3 Washington, Nevada, and Connecticut
See our Consumer Health Data Privacy Notice, published separately as required by the Washington My Health My Data Act.
9.4 Other States
Residents of other states with comprehensive consumer privacy laws — including Virginia, Colorado, Connecticut, Utah, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island — have the rights described in Section 8 to the extent those laws apply to us and to the information at issue. Most state consumer privacy laws contain exemptions for PHI handled under HIPAA and for information used in connection with the provision of healthcare.
10. DATA RETENTION
We retain information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
- Medical and prescribing records — retained by the applicable Provider or pharmacy as required by that state’s medical and pharmacy record retention laws, commonly a minimum of seven to ten years from the last date of service, and longer where state law requires.
- Billing and transaction records — retained consistent with tax, accounting, and payment-network requirements.
- Account and profile information — retained while the account or service relationship is active and afterward only as needed for fraud prevention, dispute resolution, contractual obligations, and applicable limitation or recordkeeping periods.
- Marketing preferences and opt-out records — retained for as long as needed to honor and document your communication preference.
- Website and security logs — retained on a limited, rolling basis determined by security, troubleshooting, fraud-prevention, and legal requirements.
- Customer support communications — retained for the period needed to resolve the request, document the response, and address related disputes or legal obligations.
When information is no longer needed, we delete, destroy, or de-identify it using methods appropriate to its sensitivity.
11. DATA SECURITY
We use administrative, physical, and technical safeguards designed to protect information against unauthorized access, use, disclosure, alteration, and destruction. The safeguards applied depend on the sensitivity of the information, the systems involved, and applicable contractual and legal requirements.
NO METHOD OF TRANSMISSION OR STORAGE IS COMPLETELY SECURE. WE CANNOT GUARANTEE ABSOLUTE SECURITY.
You are responsible for safeguarding your account credentials and for using a secure device and network. Notify us immediately at [email protected] if you suspect unauthorized access to your account.
Breach notification. If a breach of unsecured PHI or personal information occurs, we will provide notice to affected individuals, and to regulators and the media where required, in accordance with the HIPAA Breach Notification Rule, the FTC Health Breach Notification Rule where applicable, and applicable state breach notification laws.
12. CHILDREN’S PRIVACY
The Services are intended solely for individuals eighteen (18) years of age or older. We do not knowingly collect personal information from children under 18. If we learn that we have collected information from a person under 18, we will delete it promptly and terminate any associated account. If you believe a minor has provided us information, contact us at [email protected].
13. THIRD-PARTY WEBSITES, PLATFORMS, AND SOCIAL MEDIA
The Services contain links to third-party websites and integrations, including our patient intake and portal platform, payment and financing providers, and our social media pages on Instagram, Facebook, LinkedIn, and TikTok. This Privacy Policy does not apply to those third parties. Their collection and use of your information is governed by their own privacy policies, which we encourage you to review. Do not post health information on our public social media pages or in our community forum if you wish to keep it private.
14. USERS OUTSIDE THE UNITED STATES
The Services are intended for use only by residents of the United States who are physically located in the United States. Our systems and service providers are located in the United States. If you access the Services from outside the United States, you consent to the transfer, storage, and processing of your information in the United States, which may have different data protection laws than your jurisdiction.
15. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy at any time. The “Last Updated” date above indicates when it was last revised. We will not make material retroactive changes to how we use previously collected consumer health data without obtaining your consent where required by law. Material changes will be communicated by posting notice on our website, by email, or through the patient portal. Your continued use of the Services after the effective date constitutes acceptance of the revised Privacy Policy.
16. CONTACT US AND COMPLAINTS
Aspen Aesthetics, LLC, dba Fifty 410 Health
Attn: Privacy Officer
1630 W Prosper Trail, Suite 620
Prosper, Texas 75078
Privacy and legal inquiries: [email protected]
General support: [email protected]
Website: www.fifty410.com
Filing a complaint. You may file a privacy complaint with us at any time, and we will not retaliate against you for doing so. You may also file a complaint with:
- U.S. Department of Health and Human Services, Office for Civil Rights — 200 Independence Avenue SW, Washington, D.C. 20201; 1-800-368-1019 (TDD 1-800-537-7697); hhs.gov/ocr/privacy/hipaa/complaints
- Your state Attorney General
- The Federal Trade Commission — ftc.gov
- California residents: Complaint Assistance Unit, Division of Consumer Services, California Department of Consumer Affairs, 1625 North Market Blvd., Suite N 112, Sacramento, CA 95834; (800) 952-5210
- Consumers protected by Washington's My Health My Data Act: Washington State Attorney General, atg.wa.gov/file-complaint