Privacy Policy

Bespoke Eye Care
Effective Date: August 9, 2026
Last Updated: August 9, 2026

Bespoke Eye Care respects your privacy and is committed to protecting the personal information you provide to us. This Privacy Policy explains how Bespoke Eye Care, including its owners, employees, agents, and affiliated professional entities where applicable, collects, uses, discloses, and protects information when you visit or interact with our website, communicate with us electronically, or use online services made available through our website.

This Privacy Policy applies primarily to information collected through our website and related online services. It is separate from our Notice of Privacy Practices, which describes how we may use and disclose protected health information subject to the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, commonly referred to as HIPAA.

If information we collect is protected health information subject to HIPAA, our use and disclosure of that information will be governed by HIPAA and our Notice of Privacy Practices to the extent applicable.

1. Information We May Collect

We may collect information that you provide directly to us as well as certain information automatically generated when you interact with our website.

Information You Provide

Depending on how you use our website, you may provide information such as:

• Your name
• Telephone number
• Email address
• Mailing address
• Date of birth
• Appointment preferences
• Information submitted when requesting or scheduling an appointment
• Information submitted through contact or inquiry forms
• Insurance information
• Information concerning the reason for your visit or requested services
• Communications you send to us
• Information you provide when communicating with us by telephone, email, text message, or other electronic means
• Any other information you voluntarily provide

Please do not submit sensitive medical information through a general website contact form or ordinary email unless the website specifically identifies the method as appropriate for that purpose.

Information Collected Automatically

When you access our website, certain information may be collected automatically by our website, hosting provider, security services, analytics services, or other technology providers.

This information may include:

• Internet Protocol address
• Browser type
• Device type
• Operating system
• Referring website or source
• Pages viewed
• Date and time of visits
• Approximate geographic location derived from an IP address
• Website interactions
• Links selected
• Session information
• Cookie identifiers and similar technical information
• Information used to detect fraud, abuse, or security threats

The specific information collected depends on the technologies operating on our website.

2. How We Use Information

We may use information collected through our website to:

• Respond to questions and inquiries
• Schedule, confirm, modify, or manage appointments
• Communicate with patients and prospective patients
• Provide requested information about our services
• Operate and maintain our website
• Improve our website, services, and patient experience
• Understand how visitors use our website
• Maintain website functionality and security
• Detect, investigate, and prevent fraud, misuse, security incidents, and technical problems
• Comply with applicable laws, regulations, court orders, and legal obligations
• Establish, exercise, or defend legal rights
• Perform administrative and business operations
• Communicate information concerning the practice
• Carry out other purposes disclosed to you when information is collected or with your consent

Where information constitutes PHI under HIPAA, we will use and disclose that information in accordance with applicable HIPAA requirements and our Notice of Privacy Practices.

3. Appointment Scheduling and Patient Portals

Our website may provide the ability to request or schedule appointments or may direct you to a third party scheduling platform, electronic health record system, patient portal, payment service, or other healthcare technology service.

Information entered into a third party platform may be collected and processed by that service provider according to its own terms, privacy practices, contractual obligations, and applicable law.

Where a third party handles protected health information on our behalf and qualifies as our business associate under HIPAA, we require appropriate contractual protections as required by applicable law.

You should review the privacy information presented by third party services when using them.

4. Cookies and Similar Technologies

Our website may use cookies and similar technologies.

Cookies are small files or pieces of information placed on or associated with your device when you visit a website. They can be used for purposes such as:

• Maintaining website functionality
• Remembering user preferences
• Improving website performance
• Understanding website traffic
• Measuring how visitors interact with our website
• Maintaining website security
• Preventing fraudulent or abusive activity

Some cookies may be necessary for the website to function properly.

Depending on your browser and the technologies used on our website, you may be able to block, delete, or limit cookies through your browser settings. Disabling certain cookies may affect website functionality.

5. Analytics and Tracking Technologies

We may use analytics or similar technologies to understand website traffic, performance, and visitor interactions.

Healthcare websites require particular care when implementing tracking technologies. We evaluate technologies used on our website with consideration for the privacy and security of information collected through the website.

We do not authorize third party tracking technology providers to use protected health information for their own advertising or marketing purposes in violation of applicable law.

HHS has specifically advised HIPAA regulated entities that disclosures of PHI to tracking technology vendors must comply with the HIPAA Privacy Rule and that simply describing a disclosure in a website privacy policy does not independently authorize a disclosure prohibited by HIPAA.

6. How We May Share Information

We may disclose information collected through our website to third parties when reasonably necessary to operate our practice and website.

These parties may include:

• Website hosting providers
• Website developers and administrators
• Information technology and cybersecurity providers
• Electronic health record providers
• Patient communication platforms
• Appointment scheduling providers
• Payment processors
• Analytics providers
• Cloud service providers
• Professional advisers, including attorneys, accountants, consultants, and insurers
• Government authorities or regulators when required by law
• Other service providers that perform functions on our behalf

We may also disclose information:

• When required or permitted by applicable law
• In response to a valid subpoena, court order, warrant, or other lawful process
• To protect the rights, property, safety, or security of Bespoke Eye Care, our patients, website users, or others
• To investigate suspected fraud, security incidents, or unlawful activity
• In connection with a merger, acquisition, reorganization, financing, sale, or transfer involving all or part of the practice or its assets, subject to applicable legal requirements
• With your authorization, direction, or consent

Where HIPAA applies to a disclosure of PHI, the disclosure will be handled in accordance with applicable HIPAA requirements.

7. Sale of Personal Information

Bespoke Eye Care does not sell patient medical information.

We do not sell protected health information for advertising purposes.

We also do not authorize the disclosure of PHI to third parties for targeted advertising in violation of HIPAA or other applicable law.

8. Communications by Email

If you communicate with us through email, please understand that ordinary email may not always provide the same security protections as a secure patient portal or other secured communication system.

Do not use ordinary email for emergencies.

If you choose to communicate with us by email, information transmitted electronically may be subject to risks inherent in electronic communications.

When appropriate, we may direct you to a more secure communication method.

9. Telephone and Text Message Communications

If you provide us with a telephone number, we may use that number to communicate with you regarding inquiries, appointments, scheduling, office matters, and other communications permitted by law.

Text messages may include appointment confirmations, reminders, responses to inquiries, scheduling communications, or other practice related information.

Standard message and data rates imposed by your mobile carrier may apply.

The frequency of messages may vary.

You may request that we stop sending nonessential text messages by replying STOP where that functionality is available or by contacting our office.

Consent to receive text messages is not a condition of receiving healthcare services from Bespoke Eye Care.

Text messaging may not always be a secure means of communicating sensitive medical information. Please avoid sending highly sensitive medical information through ordinary SMS unless specifically instructed otherwise.

10. Data Security

We use reasonable administrative, technical, and physical safeguards designed to protect information under our control from unauthorized access, use, alteration, disclosure, or destruction.

When electronic protected health information is involved, additional requirements under the HIPAA Security Rule may apply.

However, no website, electronic transmission, network, or data storage system can be guaranteed to be completely secure. Accordingly, we cannot guarantee the absolute security of information transmitted electronically.

HHS emphasizes the importance of protecting the privacy and security of electronic health information when healthcare organizations use information technology.

11. Third Party Websites and Services

Our website may contain links to websites or services operated by third parties.

For example, our website may link to:

• Patient portals
• Appointment scheduling systems
• Payment platforms
• Maps or navigation services
• Insurance resources
• Social media services
• Professional organizations
• Other external websites

A link from our website does not necessarily mean that we control or endorse the privacy practices of that third party.

When you leave our website and interact with a third party service, that service's privacy policy and terms may govern the information it collects.

We encourage you to review the privacy practices of third party websites and services before providing personal information.

12. Social Media

Bespoke Eye Care may maintain profiles on social media platforms.

Information you post publicly or submit directly to a social media platform is subject to the policies and practices of that platform.

Please do not use social media to communicate urgent or sensitive medical information to us.

Interactions with our social media pages do not establish a doctor patient relationship.

13. Children's Privacy

Our website is intended to provide information concerning our healthcare services and is not designed to collect personal information directly from children without appropriate involvement of a parent or legal guardian.

If a parent or legal guardian provides information concerning a minor for purposes such as requesting healthcare services or scheduling an appointment, that information may be handled as permitted by applicable healthcare and privacy laws.

If you believe a child has provided personal information through our website inappropriately, please contact us.

14. Protected Health Information and HIPAA

Certain information you provide to Bespoke Eye Care may constitute protected health information under HIPAA.

When HIPAA applies, our collection, use, disclosure, and protection of PHI is governed by applicable HIPAA requirements and our Notice of Privacy Practices.

Our Notice of Privacy Practices is separate from this Website Privacy Policy and provides additional information regarding:

• How we may use and disclose PHI
• Your rights concerning your PHI
• Our responsibilities regarding PHI
• How to exercise your HIPAA rights
• How to file a privacy complaint

If this Website Privacy Policy and our Notice of Privacy Practices differ with respect to PHI governed by HIPAA, the Notice of Privacy Practices and applicable law will control.

15. Medical Emergencies

Do not use our website, contact forms, email, or text messaging for medical emergencies.

If you believe you are experiencing a medical emergency, call 911 or seek appropriate emergency medical care.

Submission of information through our website does not guarantee that it will be reviewed immediately.

16. No Doctor Patient Relationship Through Website Use

Visiting our website, submitting a general inquiry, sending an email, or reviewing information available on the website does not by itself establish a doctor patient relationship between you and Bespoke Eye Care or any of its healthcare providers.

A doctor patient relationship is established only through appropriate professional interaction and acceptance of the relationship by the practice.

Information provided on our website is intended for general informational purposes and should not be considered individualized medical advice, diagnosis, or treatment.

17. Data Retention

We may retain information collected through our website for as long as reasonably necessary to:

• Fulfill the purpose for which the information was collected
• Provide services
• Maintain appropriate business and administrative records
• Comply with legal and regulatory requirements
• Resolve disputes
• Enforce agreements
• Maintain security
• Establish, exercise, or defend legal claims

Where information becomes part of a patient's designated medical or billing record, different retention requirements may apply.

18. Your Choices

Depending on the nature of your relationship with us and applicable law, you may be able to:

• Request correction of certain information you have submitted
• Change communication preferences
• Opt out of certain nonessential communications
• Manage cookies through your browser
• Contact us with questions about our privacy practices

Rights relating specifically to PHI are described in our Notice of Privacy Practices.

19. Do Not Track and Browser Privacy Signals

Some browsers and devices provide privacy preference mechanisms, including "Do Not Track" signals or other browser based privacy controls.

Because standards and legal requirements concerning these technologies continue to evolve, our website's response may depend on the technology involved and applicable legal requirement

Where applicable law requires us to recognize a particular legally valid privacy preference signal, we will comply with that requirement.

20. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our website, technologies, services, privacy practices, or applicable legal requirements.

When we make changes, we will revise the Last Updated date at the beginning of this Privacy Policy.

We encourage visitors to review this Privacy Policy periodically.

Material changes may be communicated through additional means when required by law.

21. Contact Us

If you have questions regarding this Privacy Policy or our website privacy practices, you may contact:

Bespoke Eye Care
100 Begonia Dr, Ste G
Chester Springs, PA 19425

Phone: (484) 606-3937
Fax: (484) 829-3937
Email: info@BespokeEyeCare.com

For questions specifically concerning protected health information and your rights under HIPAA, please refer to our Notice of Privacy Practices or contact the practice.

Contact Us