Privacy Policy
Scratch · onescratch.com Effective Date: July 1, 2026 | Last Updated: July 1, 2026 | Version: 1.0
1. Introduction and Scope
This Privacy Policy explains how Onescratch Inc. (“Scratch,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use the website at onescratch.com and related services (the “Platform”). It also describes your privacy rights and how to exercise them.
2. Information We Collect
2.1 Information you provide
- Account and identity: name, email address (used for magic-link sign-in), organization, and role or title.
- Professional and verification information: NPI, specialty, credentials, and institution type, where you choose to register as a reviewer or verified user.
- Content and communications: reviews, comments, saved comparisons, inquiries you submit (including through “Talk to us” or manufacturer-contact forms), and messages to support.
2.2 Information collected automatically
- Device and usage data: IP address, browser and device type, pages viewed, searches run, comparisons performed, referring URLs, timestamps, and similar analytics data, collected through cookies and similar technologies. See our Cookie Policy.
2.3 Information from third parties
- Verification and reference sources (for example, the NPI registry and public databases such as CMS Open Payments, used to identify financial relationships for disclosure), analytics and advertising partners, and our service providers.
3. How We Use Information
- provide, operate, secure, and improve the Platform and its comparison features;
- authenticate you and protect accounts;
- verify credentials and apply disclosure labels (for example, financial-relationship disclosures on reviews);
- respond to your inquiries and route manufacturer-contact requests to the relevant manufacturer;
- personalize content and measure engagement;
- marketing and advertising: to deliver, measure, and improve advertising and promotional content on and off the Platform, subject to your choices (see Section 6);
- detect, prevent, and address fraud, abuse, and security issues; and
- comply with legal obligations and enforce our Terms.
4. Legal Bases (where the EU/UK GDPR applies)
Where the EU or UK GDPR applies, we rely on: performance of a contract; our legitimate interests (operating and securing the Platform, analytics, and direct marketing to professionals); your consent (for example, for certain cookies and marketing); and compliance with legal obligations. You may withdraw consent at any time without affecting prior processing.
5. How We Disclose Information
- Service providers (processors): hosting, database, authentication, email, analytics, and security vendors that process data on our behalf under contract — for example, our cloud hosting and database providers and our web-analytics provider.
- Manufacturers: if you submit an inquiry or contact request, we share the information you provide so the manufacturer can respond. Its use of your information is governed by its own privacy policy.
- Advertising and analytics partners: we may share certain identifiers and usage data for analytics and advertising as described in Section 6 and the Cookie Policy.
- Legal and safety: to comply with law, respond to lawful requests, enforce our Terms, or protect rights, property, and safety.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets.
- We do not knowingly sell the personal information of individuals under 16 years of age.
6. Advertising, Analytics, and Your Choices
- We and our partners use cookies, pixels, SDKs, and similar technologies to understand usage and to deliver and measure advertising, which may include cross-context behavioral (interest-based) advertising.
- Depending on configuration, sharing data with advertising partners may be a “sale” or “sharing” under California law or “targeted advertising” under other U.S. state privacy laws. You can opt out using the methods in Section 10 and our “Do Not Sell or Share My Personal Information” control, and we honor Global Privacy Control (GPC) signals where required.
- You can also manage cookies through our consent tool and your browser settings. See the Cookie Policy.
7. Cookies and Similar Technologies
We use cookies and similar technologies as described in our Cookie Policy, which forms part of this Privacy Policy.
8. Data Retention
We retain personal information for as long as needed for the purposes described in this Policy, to comply with legal obligations, resolve disputes, and enforce our agreements, after which we delete or de-identify it. Retention periods depend on the type of data and the context in which it was collected.
9. Data Security
We use reasonable administrative, technical, and organizational measures designed to protect personal information, such as encryption in transit, access controls, and reputable cloud infrastructure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your Privacy Rights
10.1 California (CCPA/CPRA)
California residents have the right to know and access the personal information we collect, to delete it, to correct it, to opt out of its “sale” or “sharing,” to limit the use of sensitive personal information, and to be free from discrimination for exercising these rights. The categories of personal information we collect and disclose are described in Sections 2 and 5. California’s “Shine the Light” law also lets residents request information about disclosures for third parties’ direct-marketing purposes.
10.2 Other U.S. state privacy laws
Residents of states with comprehensive privacy laws (for example, Virginia, Colorado, Connecticut, Utah, and Texas, among others) may have rights to access, correct, delete, and obtain a portable copy of their data, to opt out of targeted advertising, “sale,” and certain profiling, and to appeal a denied request. We extend the core rights to access, correct, and delete your information, and to opt out of targeted advertising, to all U.S. residents regardless of state.
10.3 EEA/UK (where applicable)
If the GDPR or UK GDPR applies, you may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority.
10.4 How to exercise your rights
Contact us at help@onescratch.com to exercise any of these rights. We will verify your request as required and respond within the timeframes set by applicable law. You may use an authorized agent where permitted.
11. “Do Not Sell or Share” and Global Privacy Control
We do not sell your personal information, and we do not share it for cross-context behavioral (interest-based) advertising. We honor Global Privacy Control (GPC) browser signals as a valid opt-out where required by law. If our practices change, we will provide a clear “Do Not Sell or Share My Personal Information” mechanism before doing so.
12. Children’s Privacy
The Platform is intended for professionals and is not directed to children under 18 (and not to children under 13 or 16 for purposes of relevant laws). We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.
13. Health Information and HIPAA
14. International Data Transfers
We are based in the United States and process data there. If you access the Platform from outside the United States, you understand that your information may be transferred to and processed in the United States. Where required, we use appropriate safeguards (such as Standard Contractual Clauses).
15. Third-Party Links
The Platform links to third-party websites (including manufacturer sites and Instructions for Use) that have their own privacy practices. We are not responsible for those practices, and this Policy does not apply to them.
16. Changes to This Policy
We may update this Policy from time to time. We will revise the “Last Updated” date and provide additional notice for material changes where required.
17. Contact Us
Onescratch Inc., 707 Sunset Avenue, Venice, CA 90291. Privacy questions and requests: help@onescratch.com. Scratch is based in the United States and directs the Platform to U.S. users; we have not appointed an EU/UK representative or Data Protection Officer.