Privacy Policy
Sapphire Health Services
Effective Date:Jul 21st, 2026
Last Updated: Jul 21st, 2026
1. Introduction
Sapphire Health Services, LLC, together with its parent, affiliates, subsidiaries, and managed communities operating in Oregon, Washington, and Idaho (collectively, “Sapphire,” “we,” “us,” or “our”), respects your privacy and is committed to protecting the personal information of website visitors, prospective residents, current residents and their families, employees, applicants, vendors, and the general public.
This Privacy Statement explains what personal information we collect through https://sapphirehealthservices.com and any associated digital properties (the “Site”), how we use and share it, and the choices and rights you have. It is incorporated into our Terms and Conditions of Use.
IMPORTANT — TWO DISTINCT PRIVACY FRAMEWORKS:
(A) Protected Health Information (“PHI”) created or received by a Sapphire community in connection with care is governed by HIPAA and each community’s separate Notice of Privacy Practices (“NPP”), available at the community’s front desk and/or admissions office. This Privacy Statement does not govern PHI.
(B) Information collected through the Site — such as browsing data, contact-form submissions, job applications, and chat conversations — is governed by this Privacy Statement. This Site is not a HIPAA-compliant patient portal. Do not submit PHI through the Site.
2. Scope
This Privacy Statement applies to information we collect:
- On the Site;
- Through email, text, telephone, or chat communications initiated from the Site;
- From Sapphire’s social-media pages, advertising partners, and analytics providers that link back to the Site;
- From third parties such as referral sources, lead-generation partners, applicant-tracking systems, and business partners that supply us with information relating to your interest in our services or careers.
It does not apply to: (i) PHI subject to HIPAA; (ii) information collected offline at a Sapphire community; (iii) third-party websites linked from the Site, which have their own privacy policies; or (iv) employees and contractors during the course of employment (a separate workforce notice applies).
3. Categories of Information We Collect
3.1 Information You Provide Directly
- Identifiers: name, postal address, email address, telephone number, relationship to a prospective or current resident.
- Inquiry Content: information you include in contact forms, tour requests, brochure requests, chat conversations, and feedback submissions.
- Employment Information: resume, work history, education, references, certifications, voluntary EEO data, and other information submitted via our careers portal or applicant-tracking system.
- Vendor/Business Information: business contact details and credentials submitted by vendors and partners.
3.2 Information Collected Automatically
When you visit the Site, we and our service providers automatically collect:
- Device & Network Data: IP address, browser type and version, operating system, device identifiers, time-zone setting, language preference, screen resolution.
- Usage Data: pages viewed, links clicked, referring/exit URLs, search terms used to reach the Site, dwell time, scroll depth, mouse movements, taps, and similar interactions captured via cookies, pixels, SDKs, server logs, heatmaps, and session-replay technology.
- Location Data: approximate geographic location derived from IP address.
- Chat Transcripts: the content of conversations you have with our website chatbot or human chat agent.
- Advertising Identifiers: information from advertising and conversion pixels (which may include Meta/Facebook, Google, TikTok, LinkedIn, Microsoft, and similar platforms) used to measure campaign performance and serve relevant ads.
3.3 Information From Third Parties
- Analytics and advertising vendors (e.g., Google Analytics, Google Ads, Meta);
- Lead aggregators and senior-living referral networks (where you have consented at their point of collection);
- Background-screening providers (for job applicants, with separate consent);
- Publicly available sources and social-media platforms.
3.4 Sensitive Information; Children
We do not intentionally collect through the Site: government-issued identifiers (other than as required by a job application), financial-account credentials, precise geolocation, biometric data, genetic data, immigration status, sexual orientation, union membership, or PHI. If you submit such information through the Site, you do so voluntarily and at your own risk. We will treat such information with reasonable safeguards and, where applicable, the heightened protections required by law.
The Site is not directed to children under thirteen (13), and we do not knowingly collect personal information from such children. If you believe a child has provided information, please contact us so we can delete it.
4. Cookies, Pixels, Session Replay, Chatbots, and Other Tracking Technologies
4.1 What We Use
We and our service providers use the following categories of Tracking Technologies:
| Category | Examples | Purpose |
|---|---|---|
| Strictly Necessary | Session cookies, security tokens | Site operation, security, load balancing |
| Functional / Preference | Language and accessibility cookies | Remember your preferences |
| Analytics | Google Analytics, server logs, heatmaps, session-replay (e.g., Hotjar or comparable) | Understand Site performance and user experience |
| Advertising / Targeting | Google Ads, Meta Pixel, TikTok Pixel, LinkedIn Insight, Microsoft UET (or equivalents) | Measure ad performance; serve relevant ads; retargeting |
| Chatbots & Engagement | Website chat widget (vendor-hosted) | Answer questions and route inquiries |
4.2 Express Consent — CIPA, MHMDA & State Wiretap Law Notice
By clicking “Accept All,” “I Agree,” “Continue,” or any equivalent option on our consent banner — or by continuing to use the Site after notice of these technologies — you knowingly and voluntarily consent, on a two-party-consent basis, to: (i) the contemporaneous recording, capture, transmission, storage, and analysis of your interactions with the Site, including mouse movements, clicks, scrolls, keystrokes in non-sensitive fields, page views, IP address, device identifiers, and chat conversations; (ii) the use of pixels, beacons, SDKs, and similar technologies that may share data with third-party analytics and advertising partners; and (iii) the use of session-replay technology that records your visit for quality, security, and product-improvement purposes.
You acknowledge that Sapphire is a party to all such communications, that you have been provided notice prior to such collection, and that you have no reasonable expectation of privacy in the data collected. This consent is required under the California Invasion of Privacy Act (Cal. Penal Code §§ 630–638), the federal Wiretap Act (18 U.S.C. § 2511), the Washington Privacy Act (RCW 9.73), the Washington My Health My Data Act (RCW 19.373), the Oregon Consumer Privacy Act (ORS 646A.570 et seq.), and comparable state and federal laws.
4.3 Sensitive Field Masking
Where session-replay technology is deployed, we configure it to mask sensitive form fields by default (including any field that could capture name + health condition combinations, financial information, or government IDs) so the underlying keystrokes are not captured or transmitted.
4.4 Your Choices
- Consent Banner: Use our cookie/preference center to accept, reject, or customize categories of Tracking Technologies.
- Global Privacy Control (“GPC”): We honor browser-level opt-out signals such as GPC as a request to opt out of “sales” and “sharing” of personal information for targeted advertising under applicable state laws.
- Do Not Track: Because there is no industry consensus on Do Not Track signals, we do not respond to DNT headers other than via GPC as described above.
- Browser Settings: You can configure your browser to block or delete cookies, but parts of the Site may not function properly.
- Advertising Opt-Outs: Visit the Digital Advertising Alliance (optout.aboutads.info), the Network Advertising Initiative (optout.networkadvertising.org), and the European Interactive Digital Advertising Alliance (youronlinechoices.eu).
5. How We Use Personal Information
We use personal information for the following purposes:
- Service Delivery: respond to inquiries, schedule tours, provide brochures, route prospective residents to the appropriate community.
- Recruiting & HR: evaluate job applications, schedule interviews, conduct lawful pre-employment screening.
- Marketing: send newsletters, event invitations, community updates, and targeted advertisements, where permitted.
- Analytics & Improvement: measure traffic patterns, improve content and user experience, develop new services.
- Security & Fraud Prevention: detect, investigate, and prevent fraudulent, abusive, or illegal activity; protect the rights and safety of Sapphire, residents, staff, and visitors.
- Legal & Compliance: comply with HIPAA, state and federal long-term-care regulations, public-health reporting, subpoenas, court orders, and other legal obligations; protect against, investigate, and respond to elder abuse, neglect, or financial exploitation as required by Oregon, Washington, and Idaho law.
- Quality Assurance: monitor and improve customer service, including reviewing chat transcripts and session replays.
We do not sell personal information in exchange for monetary consideration. We do share certain information with advertising and analytics partners in ways that may be considered a “sale” or “sharing” under some state laws, and you may opt out as described in Section 7.
6. How We Share Personal Information
We share personal information with:
- Service Providers bound by contractual confidentiality and data-protection obligations (e.g., website hosting, email/SMS delivery, analytics, chat vendors, applicant-tracking systems, CRM, advertising platforms).
- Affiliates and Managed Communities within the Sapphire family of companies, for the purposes described in this Statement.
- Professional Advisors (legal, accounting, insurance, compliance).
- Government Authorities, Regulators, and Law Enforcement when required by law, subpoena, court order, or to protect the safety of residents and staff (including mandatory reporting of suspected elder abuse, neglect, or financial exploitation under ORS 124.050 et seq. (Oregon), RCW 74.34 (Washington), and Idaho Code § 39-5301 et seq.).
- Successors in connection with a merger, acquisition, financing, reorganization, sale of assets, or bankruptcy.
- With Your Consent for any other purpose disclosed at the time of collection.
We do not disclose PHI through the Site. PHI sharing is governed by each community’s HIPAA Notice of Privacy Practices.
7. Your Privacy Rights
7.1 Rights Available to Residents of Oregon, Washington, and Idaho (and All U.S. Residents)
Depending on your state of residence and applicable law, you may have the right to:
- Know / Access the categories and specific pieces of personal information we collect, use, and disclose.
- Correct inaccurate personal information.
- Delete personal information we hold about you, subject to legal exceptions.
- Portability — receive a copy of your information in a portable, machine-readable format.
- Opt Out of (i) targeted advertising, (ii) the “sale” or “sharing” of personal information, and (iii) certain profiling.
- Limit the use of sensitive personal information.
- Non-Discrimination — we will not deny services, charge different prices, or provide a different level of service because you exercised a privacy right.
- Appeal a denial of any of the above requests.
7.2 Washington My Health My Data Act (“MHMDA”) — Consumer Health Data
If you are a Washington resident or your data is collected in Washington, you have additional rights with respect to “consumer health data” (any personal information linkable to you that identifies your past, present, or future physical or mental health status, including inferences derived from non-health information):
- Right to Confirm whether we collect, share, or sell your consumer health data, and to access such data;
- Right to Withdraw Consent to the collection and sharing of consumer health data;
- Right to Delete consumer health data;
- Right to a List of third parties with whom we have shared or to whom we have sold your consumer health data, including contact information for those parties.
We obtain opt-in consent before collecting or sharing consumer health data for purposes beyond what is strictly necessary to provide a service you requested, and a separate, valid authorization before any “sale” of consumer health data. We do not engage in geofencing within 2,000 feet of any healthcare facility for the purpose of identifying, tracking, or sending notifications to consumers regarding their consumer health data.
7.3 Oregon Consumer Privacy Act (“OCPA”) — Effective July 1, 2024
Oregon residents have the rights listed in Section 7.1, including the right to obtain a list of specific third parties (not just categories) to whom we have disclosed personal data. Appeals will be addressed within 45 days; if denied, you may contact the Oregon Department of Justice at justice.oregon.gov/consumer.
7.4 California Residents (CCPA/CPRA), If Applicable
To the extent we collect information from California residents, the rights in Section 7.1 apply, including the right to limit the use of “Sensitive Personal Information” and the right to opt out of “sharing” for cross-context behavioral advertising. We honor Global Privacy Control signals as a valid opt-out request. California residents may designate an authorized agent to submit requests, subject to verification.
7.5 How to Exercise Your Rights
Submit a request by:
- Visiting our online privacy request form at https://sapphireattigardrehab.com/contact-us/
- Emailing tigardrehab@sapphirehealthservices.com
- Calling (503) 639-1144
- Mailing the address in Section 13.
We will verify your identity using information reasonably necessary to confirm the request is legitimate. We will respond within the timeframe required by applicable law (generally 45 days, extendable as permitted).
8. Data Retention
We retain personal information only for as long as necessary to fulfill the purpose for which it was collected, including to satisfy legal, accounting, regulatory, or reporting requirements. Specifically:
- Contact-Form Submissions: up to 24 months after last interaction, then deletion or anonymization.
- Chat Transcripts & Session Replays: typically 90 days, longer if needed for security investigation or legal hold.
- Job Applications: retained per federal and state record-retention rules (generally 3–4 years).
- Marketing Lists: until you unsubscribe or request deletion.
- Server Logs: typically 12 months unless required longer for security.
- Legal Holds: longer where required by litigation, regulation, or insurance reserve requirements.
Criteria used to determine retention include legal obligations, statute-of-limitations periods, regulatory recordkeeping (CMS, DHS, DSHS, IDHW), and the operational need to deliver services.
9. Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, alteration, disclosure, or destruction, including TLS/HTTPS encryption in transit, access controls, multi-factor authentication for administrative systems, vendor due-diligence, and workforce training. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security. You are responsible for keeping your access credentials confidential.
In the event of a security incident affecting your personal information, we will notify affected individuals and regulators in accordance with applicable federal and state breach-notification laws, including the HIPAA Breach Notification Rule, ORS 646A.604 (Oregon), RCW 19.255 (Washington), and Idaho Code § 28-51-104 et seq.
10. International Visitors
The Site is operated in the United States. If you access the Site from outside the U.S., your information will be transferred to, processed, and stored in the United States, where data-protection laws may differ from those in your jurisdiction. By using the Site, you consent to such transfer.
11. Third-Party Links & Features
The Site may contain links to or embed content from third parties, including social-media plug-ins, mapping tools, video players, and review platforms. We are not responsible for the privacy practices of these third parties, and their collection of information is governed by their own privacy policies.
12. Changes to This Privacy Statement
We may update this Privacy Statement from time to time. When we do, we will revise the “Last Updated” date and, for material changes, provide additional notice such as a banner on the Site or email notification. Your continued use of the Site after the effective date constitutes acceptance of the revised Statement.
13. How to Contact Us
For privacy questions, requests, or complaints, please contact:
14145 SW 105th Ave | Tigard, Oregon 97224
Phone: (503)-639-1144
Email: tigardrehab@sapphirehealthservices.com
For HIPAA-related concerns (PHI handled at a Sapphire community), please contact that community’s Privacy Officer directly, or the U.S. Department of Health and Human Services, Office for Civil Rights, at hhs.gov/ocr. For Washington MHMDA concerns, you may contact the Washington Attorney General at atg.wa.gov. For Oregon privacy concerns, contact the Oregon Department of Justice at doj.state.or.us.