What Information This Website Collects
We keep website data collection deliberately small. Most visitors read two or three articles and leave, and nothing about that visit identifies them personally. Information becomes identifiable only when you type it into a form, send an email, or call the number on the page.
Information You Give Us Directly
The appointment request form asks for your name, phone number, email address, the body area that hurts, your preferred visit times, and how you heard about the practice. The contact form and any email you send carry whatever you choose to write in them. When you call the front desk, we note the reason for the call so the right person can return it.
We ask you not to type diagnoses, imaging reports, medication lists, insurance identifiers or Social Security numbers into a web form. A line such as "right knee, six weeks, worse on stairs" is plenty for scheduling. The clinical detail belongs in the exam room or the patient portal, where it is protected properly.
Information Collected Automatically
Our web server and analytics keep standard technical records: IP address (truncated before storage where our analytics supports it), browser and operating system, device type and screen width, the page requested, the page that referred you, and the date and time. These records let us find broken links, block abusive traffic, and see which patient education articles people actually finish.
Cookies and Similar Technologies
Essential cookies remember your cookie choice and keep forms working across a page reload. Preference cookies remember display settings such as text size. Analytics cookies count visits in aggregate and are set only after you accept them.
We do not place advertising or social-network pixels on condition and service pages. A page about a herniated disc should not follow you around the internet afterward.
Why We Collect It, and the Legal Basis for Doing So
Every piece of data here has a job. When the job ends, the data goes.
- Answering appointment requests, questions and callback requests — we cannot return a call without a number.
- Confirming, rescheduling and reminding you about visits once you are a patient of the practice.
- Keeping the site available and safe: rate limiting, spam filtering, error logs and backups.
- Improving the education library by seeing which articles are read, searched for, or abandoned halfway.
- Meeting the legal, accounting and record-keeping obligations that apply to a medical practice in Ohio.
The Legal Bases We Rely On
For visitors in the United States, we handle website data on the basis of the service you asked for, your consent for analytics cookies and marketing email, and our legitimate interest in keeping the site secure and functioning. State consumer privacy laws give residents of several states specific rights on top of that, described further down this page.
For visitors in the European Economic Area or the United Kingdom, the equivalent GDPR bases are Article 6(1)(b) for handling an appointment request you initiated, Article 6(1)(a) consent for analytics and email updates, Article 6(1)(f) legitimate interests for security logging, and Article 6(1)(c) where a law obliges us to keep a record.
Health information is a special category under those European rules and sensitive data under several US state laws. That is one more reason the web form asks for scheduling detail only.
A Web Form Is Not a Secure Medical Channel
Email and website forms travel across the open internet. We encrypt them in transit, but we cannot control what happens at your end — a shared computer, a work account your employer can read, or an unsecured network all carry risk we cannot remove.
Nothing sent through goldplaypot.com creates a doctor-patient relationship, and nobody watches the inbox around the clock. A form submitted at 9 p.m. on Friday is usually read on Monday morning. If your question cannot wait that long, call the clinic. If it cannot wait at all, use the guidance in the box below.
Website Data and Medical Records Are Two Different Things
This policy covers the public website. It does not cover your chart.
Once you are seen at the practice, the notes, imaging, test results and billing records created about your care are protected health information held by a HIPAA covered entity. Those records are governed by the federal HIPAA Privacy Rule and by the practice's Notice of Privacy Practices, which you receive at your first visit and can ask for at the front desk. The rights described there — to inspect and receive a copy of your record, to request an amendment, to ask for an accounting of disclosures, to request restrictions on certain disclosures — are in several respects broader than the website rights described below.
If an appointment request becomes a scheduled visit, the details you submitted are moved into the practice's clinical systems and are protected as part of your record from that point on. Requests about medical records should go to the medical records office rather than through the website privacy contact, because we have to verify identity to a higher standard before releasing them.
Cookies, Analytics and How to Switch Them Off
Our analytics are configured to collect as little as possible: no advertising features, no cross-device identity graph, no data sales. You can turn measurement off at any time and every page keeps working exactly as before.
- Cookie banner: reopen it from the footer link and withdraw analytics consent. Your choice is stored for twelve months.
- Browser settings: every major browser can block or clear cookies for a single site, including this one.
- Global Privacy Control: if your browser or extension sends a GPC signal, we treat it as an opt-out of analytics and of any sharing for advertising.
- Google Analytics opt-out: the browser add-on published by Google blocks measurement across every site that uses it.
- Do Not Track: DNT headers were never standardized, so we act on your cookie choice and on GPC instead.
How Long We Keep Data, and How We Protect It
Keeping data longer than it is useful is a liability, not an asset. These are the working retention periods for website data.
- Appointment and contact form submissions: 24 months. If the request becomes a visit, the relevant clinical detail moves into your medical record and follows medical record retention rules instead.
- Email correspondence with the front desk: 24 months.
- Web server and security logs: 90 days.
- Analytics records: 14 months, held in aggregate.
- Email updates list: until you unsubscribe, plus 12 months so that we can prove the unsubscribe was honored.
- Medical records: retained under Ohio and federal requirements, with longer periods for records of patients treated as minors. The records office can confirm the current schedule.
Security Measures
Pages and forms are served over TLS. The site is hosted in access-controlled US data centers. Administrative accounts require multi-factor authentication, permissions follow a least-privilege model, and vendors that can touch patient information sign a HIPAA business associate agreement before they are given access. Staff complete privacy and security training, software is patched on a schedule, and backups are encrypted and tested.
No website or email system is perfectly secure, and any policy that claims otherwise is overselling. What we can promise is a short list of people with access, prompt patching, and honest notification if something goes wrong.
If Something Goes Wrong
If a breach affects personal information held through this website, we investigate, contain it, and notify affected individuals and the relevant regulators within the deadlines set by Ohio law and, where protected health information is involved, by the federal HIPAA Breach Notification Rule.
Who Sees Your Information
A small number of service providers help run the site and the practice. Each one is contractually limited to doing the work we hired them for.
- The hosting and content delivery provider that stores the site and its server logs.
- The form delivery and email service that carries a submission to the front desk inbox.
- Our privacy-configured analytics provider, which receives page-level measurement rather than identified profiles.
- The practice's scheduling and electronic health record vendors, which sign business associate agreements before handling any patient information.
- Professional advisers — attorneys, auditors, insurers — where they genuinely need the information and are bound to keep it confidential.
- A court, regulator or law enforcement agency, when valid legal process requires it and we cannot lawfully narrow the request.
- A successor organization, if the practice is ever merged with or acquired by another group, under the commitments in this policy.
Your Rights, Children, and Visitors Outside the United States
Rights You Can Use Today
Whatever state you live in, you may ask us to confirm what website data we hold about you, give you a copy, correct something inaccurate, delete it, or stop sending email updates. You may withdraw consent for analytics at any time. We will not treat you differently — in scheduling, pricing or care — for exercising any of these rights.
To make a request, email care@goldsplaypot.com with "Privacy request" in the subject line, call +1 (555) 014-7788, or write to the Columbus address at the end of this page. We verify identity in proportion to the sensitivity of the request, usually by confirming details you already gave us, and we do not use verification information for anything else.
We respond within 45 days, and tell you if we need a further 45 days for a complicated request. There is no charge for a reasonable request once in a twelve-month period. An authorized agent may act for you with written permission. If we decline a request, we explain why and you may appeal by replying to that decision within 30 days; if the appeal fails you may complain to the Ohio Attorney General, to your own state attorney general, or — in the EEA or UK — to your national supervisory authority.
Children's Privacy
This site is written for adults making decisions about their own care or the care of a child in their household. It is not directed to children under 13, and we do not knowingly collect personal information from them. Appointment requests for a minor patient must be submitted by a parent or legal guardian.
If we learn that a child under 13 submitted personal information through a form here, we delete it. If you believe that has happened, contact us and we will remove it promptly.
Visitors Outside the United States
The clinic is in Columbus, Ohio, and the website is hosted in the United States, so any information you send is processed here under US law, which offers different protections from those in your home country. Submitting a form from outside the US means you accept that transfer. Where our processors offer them, we rely on standard contractual clauses and equivalent safeguards for transfers from the EEA and UK.
You are welcome to read the education library from anywhere. Clinical care, including telehealth, can only be provided where our clinicians hold a license.
Changes to This Policy, and How to Reach Us
We review this policy at least once a year, and again whenever we change a form, an analytics tool, or a vendor that handles your information. The date at the top of this page is the one that counts. Material changes are announced with a site banner for 30 days before they take effect, and continued use of the site after that date means the updated policy applies to your website data.
Questions, corrections and complaints about privacy all go to the same place:
- GoldPlayPot Orthopedic Care, 2140 Meridian Health Parkway, Suite 300, Columbus, OH 43215, United States
- Phone +1 (555) 014-7788 · Urgent +1 (555) 014-7799
- Email care@goldsplaypot.com — mark the subject line "Privacy request"
- Mon-Fri 8:00-18:00, Sat 9:00-14:00, Sun urgent fracture care only
Frequently asked questions
Does submitting the appointment form make me a patient?
No. It puts a request in the scheduling queue. A doctor-patient relationship begins only when a clinician at the practice evaluates you and accepts you for care, so nothing you send through the website should be treated as medical advice or as a confirmed visit.
Is my medical record covered by this privacy policy?
No. Charts, imaging, test results and billing records are protected health information under HIPAA and are governed by the practice's Notice of Privacy Practices. Requests to see, copy or amend a record go to the medical records office, which verifies identity before releasing anything.
I typed detailed medical history into the contact form. What now?
Tell us and we will move it into your chart or delete it, whichever you prefer. It is a common thing to do and nothing bad happens because of it — we simply prefer clinical detail to travel through the portal or the exam room rather than an email inbox.
Can I read the site without accepting cookies?
Yes. Essential cookies keep forms working and remember your choice; everything else is optional. Decline analytics and every article, service page and condition page behaves exactly the same.
How do I ask what data you hold about me?
Email care@goldsplaypot.com with "Privacy request" in the subject line or call the front desk. We confirm your identity, then return the form submissions and email correspondence tied to you. Analytics is aggregated, so there is usually nothing personally identifiable to return from it.