Privacy Policy
Effective Date: August 20, 2026
1. Introduction and Scope
This Privacy Policy (the "Policy") sets forth the policies and practices of CTrue LLC, a New York limited liability company doing business as CTrue Vision (the "Company," "We," "Us," or "Our"), with respect to the collection, use, transmission, disclosure, retention, and safeguarding of information in connection with the website accessible at thectrue.com (the "Website").
This Policy governs information collected through the Website only. It does not govern information collected in person at Our offices, by telephone, or through any channel other than the Website.
The Company is a covered entity under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, each as amended (collectively, "HIPAA"). Where information collected through the Website constitutes Protected Health Information ("PHI"), such information is additionally and primarily governed by Our Notice of Privacy Practices (the "Notice"). In the event of any conflict between this Policy and the Notice with respect to PHI, the Notice shall control.
By accessing or using the Website, You acknowledge that You have read and understood this Policy. If You do not agree with this Policy, You must not submit information through the Website.
2. Interpretation and Definitions
Interpretation
Words of which the initial letter is capitalized have the meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Policy:
Appointment Request Form means the form made available on the Website at the "Schedule" page for the purpose of requesting an appointment at the Practice.
Business Associate has the meaning given to that term under HIPAA, being a person or entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity and that is bound by a business associate agreement.
Company (referred to as either "the Company," "We," "Us," or "Our") refers to CTrue LLC, doing business as CTrue Vision, 433 Park Ave, Brooklyn, NY 11205, United States.
Contact Form means the general-inquiry form made available on the Website's home page under the heading "Contact Us."
Notice means the Company's Notice of Privacy Practices, available at thectrue.com/notice-of-privacy-practices.
Personal Data means any information that relates to an identified or identifiable natural person.
PHI means Protected Health Information as defined under HIPAA, being individually identifiable health information transmitted or maintained in any form or medium, including demographic information collected from an individual in connection with the provision of health care.
Practice means the optometry practice operated by the Company at its offices located in Williamsburg (433 Park Ave, Brooklyn, NY 11205), Borough Park (1581 48th St, Brooklyn, NY 11219), and Monroe (1 Preshburg Blvd, Kiryas Joel, NY 10950).
Service Provider means any natural or legal person that processes information on behalf of the Company pursuant to the Company's instructions.
Website refers to the CTrue Vision website, accessible from thectrue.com.
You means the individual accessing or using the Website, or, where an individual submits information on behalf of a minor for whom that individual is a parent or legal guardian, that individual acting in such capacity.
3. Information We Collect
The Company collects only the information enumerated in this Section 3. The Company does not collect any category of information through the Website other than as expressly set forth below.
3.1 Information You Provide Through the Appointment Request Form
When You submit the Appointment Request Form, the Company collects the following, and only the following, information:
First name and last name;
Date of birth;
Telephone number;
Email address;
The Practice office location You select (Williamsburg, Borough Park, or Monroe);
The doctor You request, if You elect to provide one;
The appointment date and time You request, if You elect to provide them;
The visit type You select (one of: New; Follow Up; Emergency; Pediatric; or Geriatric); and
A record of Your affirmative acknowledgment of this Policy, the Terms and Conditions, and the Notice, together with the version of those documents in effect at the time of submission.
Information submitted through the Appointment Request Form identifies You and relates to Your seeking of health care from the Practice. Such information constitutes PHI and is governed by the Notice in addition to this Policy.
3.2 Information You Provide Through the Contact Form
When You submit the Contact Form, the Company collects the following, and only the following, information:
Full name;
Email address;
Telephone number; and
The contents of the message You compose.
The Contact Form is designated for general inquiries and business correspondence only. It is not intended for, and You are instructed not to include in it, any health information, including symptoms, diagnoses, medications, treatment history, or any other PHI. The Contact Form is processed through a Service Provider that is not a Business Associate, as described in Section 5.2. For any communication concerning Your health or care, contact the Practice by telephone or submit the Appointment Request Form.
3.3 Information Collected Automatically
The Website does not set or read cookies. The Website does not deploy analytics services, advertising identifiers, pixel tags, web beacons, session-replay technologies, cross-site tracking technologies, or third-party scripts of any kind. Fonts and media served on the Website are hosted by the Company and do not cause Your browser to transmit requests to third-party font or media services.
The infrastructure on which the Website is hosted generates standard server records incidental to the operation of any website, which may include Your Internet Protocol (IP) address, browser type and version, the pages requested, and the date and time of each request. The Company's application code does not write the contents of Your form submissions to such records.
3.4 Information We Do Not Collect
The Website does not provide for the creation of user accounts and collects no credentials. The Company does not collect through the Website any payment or financial information, insurance information, Social Security numbers, precise geolocation data, or biometric information, and does not acquire information about You from data brokers or other third-party sources.
4. Use of Your Information
The Company uses information collected through the Website exclusively for the following purposes:
To process appointment requests: to receive, review, and respond to Your Appointment Request Form submission, including contacting You by telephone or email to confirm, schedule, reschedule, or discuss the requested appointment;
To respond to inquiries: to receive, review, and respond to messages submitted through the Contact Form;
To maintain security and integrity: to protect the Website and the Company's systems against fraudulent, abusive, or unlawful activity; and
To comply with law: to satisfy applicable legal, regulatory, and professional obligations.
The Company does not use information collected through the Website for advertising or marketing purposes. The Company does not sell, rent, lease, or trade Your Personal Data or Your PHI to or with any person. The Company does not use Your information for automated decision-making or profiling.
5. Transmission and Disclosure of Your Information
5.1 How Your Information Is Transmitted
Information You submit through the Website is transmitted to the Company's web application using transport-layer encryption (HTTPS/TLS). The Website maintains no database, and Your submissions are not stored by the web application. Each submission is formatted into an email message and delivered, through the Service Providers identified in Section 5.2, to the Practice's email system, where it is received and retained as described in Section 7.
5.2 Service Providers
The Company engages the following Service Providers, each of which receives only the information necessary to perform the function described:
UniOne (unione.io), a transactional email delivery service, transmits Appointment Request Form submissions from the Website to the Practice's email system. UniOne receives the full contents of each Appointment Request Form submission, which constitute PHI, and processes such information as a Business Associate of the Company pursuant to a business associate agreement.
Resend, Inc. (resend.com), a transactional email delivery service, transmits Contact Form submissions from the Website to the Practice's email system. Resend receives the full contents of each Contact Form submission. Resend utilizes Amazon Web Services as a downstream email-delivery subprocessor. The Contact Form is a designated non-PHI channel, and Resend is not engaged as a Business Associate; this is the reason for the instruction in Section 3.2 that no health information be submitted through the Contact Form.
Microsoft Corporation (Microsoft 365 / Outlook) provides the Practice's email system, in which Website submissions are received and retained. Microsoft processes such information, including PHI contained in Appointment Request Form submissions, as a Business Associate of the Company pursuant to a business associate agreement.
Website hosting provider. The Website is served by a third-party cloud infrastructure provider, which processes network traffic to and from the Website, including form submissions in transit, and maintains the standard server records described in Section 3.3.
5.3 Other Disclosures
Except as set forth in Section 5.2, the Company does not disclose information collected through the Website to any third party, other than in the following circumstances:
Legal obligation: where disclosure is required by law, subpoena, court order, or other valid legal process, or in response to a lawful request by a public authority;
Protection of rights and safety: where disclosure is necessary to protect the rights, property, or safety of the Company, its patients, or the public, to the extent permitted by law;
Business transfer: in connection with a merger, acquisition, or sale of all or substantially all of the Company's assets, in which case any successor shall remain bound by obligations no less protective than those set forth in this Policy, and any PHI shall remain subject to HIPAA and the Notice; and
With Your authorization: where You have provided prior written authorization for a disclosure not otherwise described in this Policy, which authorization You may revoke as provided therein.
Disclosures of PHI, in all circumstances, are made only as permitted or required by HIPAA and as described in the Notice.
6. Third-Party Channels and Linked Services
The Website contains a link enabling You to initiate a conversation with the Practice through WhatsApp, a messaging service operated by Meta Platforms, Inc. If You elect to use that link, any information You transmit is processed by Meta Platforms, Inc. under its own terms of service and privacy policy, and not under this Policy. WhatsApp is not a secure channel for health information, Meta Platforms, Inc. is not a Business Associate of the Company, and You are instructed not to transmit PHI through WhatsApp.
The Website contains outbound links to third-party services, including links to Google Maps for directions to the Practice's offices. If You follow such a link, the operator of the destination service may process Your IP address and referring page. The Company has no control over, and assumes no responsibility for, the content or privacy practices of any third-party site or service.
7. Retention of Your Information
Website submissions are retained within the Practice's email system described in Section 5.2. Information constituting PHI or forming part of a patient record is retained for the period required by applicable federal law and the laws of the State of New York governing the retention of patient records, and thereafter disposed of in accordance with applicable law. Contact Form submissions that do not form part of a patient record are retained only as long as reasonably necessary to address the inquiry and to satisfy the Company's legal and professional obligations.
8. Security of Your Information
The Company maintains administrative, technical, and physical safeguards reasonably designed to protect the security, confidentiality, and integrity of Personal Data, consistent with the requirements of the New York Stop Hacks and Improve Electronic Data Security Act (the "SHIELD Act"), and, with respect to PHI, the HIPAA Security Rule. Such safeguards include: transport-layer encryption of all Website traffic; the engagement of Business Associates, bound by business associate agreements, for the transmission and storage of PHI; the exclusion of form-submission contents from application logs; and limitation of access to submissions to workforce members who require such access, consistent with the minimum-necessary standard.
No method of transmission over the Internet and no method of electronic storage is completely secure. Accordingly, while the Company employs the safeguards described above, the Company cannot guarantee absolute security. In the event of a breach of unsecured PHI or of private information as defined under New York law, the Company will provide notification as required by HIPAA, the Health Information Technology for Economic and Clinical Health Act (HITECH), and New York General Business Law § 899-aa, respectively.
9. Your Rights and Choices
You may request access to, correction of, or deletion of information You have submitted through the Website by contacting the Privacy Officer using the information in Section 12. The Company will honor such requests to the extent consistent with its legal and professional record-retention obligations; information that forms part of a patient record may not be eligible for deletion during the retention period required by law.
With respect to PHI, You hold the rights enumerated in the Notice, including the rights to inspect and obtain a copy of Your records, to request amendment, to request restrictions on use and disclosure, to request confidential communications, to receive an accounting of disclosures, and to receive notification of a breach. The Notice describes each right and the manner of its exercise. Nothing in this Policy limits any right available to You under HIPAA or under New York Public Health Law § 18.
10. Children's Privacy
The Website is a general-audience website intended for use by adults. An appointment request on behalf of a minor, including a request designating the "Pediatric" visit type, must be submitted by the minor's parent or legal guardian, who in so doing represents that they hold authority to submit the minor's information. The Company does not knowingly collect Personal Data directly from children under the age of 13. If You believe that a child under 13 has submitted Personal Data through the Website without parental involvement, contact the Privacy Officer, and the Company will delete such information to the extent permitted by its legal obligations.
11. Changes to This Policy
The Company may revise this Policy from time to time. Each revision will be posted on this page with a revised Effective Date. Material revisions will be accompanied by a conspicuous notice on the Website. Revisions apply prospectively from their Effective Date. Changes to the Company's privacy practices with respect to PHI are governed by the Notice and the procedures for its amendment described therein.
12. Contact; Privacy Officer
Questions, requests, and complaints concerning this Policy or the Company's privacy practices may be directed to:
Privacy Officer, CTrue LLC, 433 Park Ave, Brooklyn, NY 11205
By email: info@thectrue.com
By phone: (718) 534-7100
You also have the right to file a complaint with the Secretary of the U.S. Department of Health and Human Services, Office for Civil Rights, as described in the Notice. The Company will not retaliate against You for filing a complaint.
