Search requires functional cookies. Manage cookie preferences to enable.
Notice at Collection. At or before the time of collection of personal information, residents of certain U.S. states may have a right to receive notice of our information practices, including the categories of personal information to be collected, the purposes for which such personal information is collected or used, whether such personal information is sold or shared and how to opt-out of such selling and sharing, and how long such information is retained. You can find those details in this Privacy Policy by clicking on the above links.
This Privacy Policy describes how Joint Restoration Foundation, Inc., and its subsidiaries, affiliates, and related entities (collectively, “JRF Ortho”, “Company”, “we”, or “us”) collect and process personal information about individuals (including, but not limited to, health care professionals, job applicants, agents, consultants, contractors, vendors, service providers, business associates and other users) through the JRF Ortho website located at https://jrfortho.org/ (the “Website”) and any other products, programs, or services we offer online or offline (together with the Website, collectively, the “Services”).
This Privacy Policy is intended to address the rights and disclosure obligations applicable to individuals under U.S. state privacy laws that may apply to JRF Ortho’s data practices, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act (the “CCPA”), and other comparable state privacy laws that may apply from time to time (collectively, “Privacy Laws”).
We collect and use information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household (“personal information”). Personal information does not include:
The chart below identifies which categories of personal information we collected from you within the last 12 months and the source of this personal information.
| Category | Examples | Collected | Source of this Personal Information |
|---|---|---|---|
| A. Identifiers. | A real name, postal address, Internet Protocol address, email address. | YES | You, Service Providers |
| B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)) (“California Customer Records”). | A name, signature, address, telephone number, education, employment, employment history. Some personal information included in this category may overlap with other categories. | YES | You, Service Providers |
| C. Protected classification characteristics under applicable state or federal law (“Protected Classes”). | Age (40 years or older), race, color, ancestry, national origin, citizenship, physical or mental disability, sex, military and veteran status. | YES | You |
| D. Commercial information. | Records of personal property, products, or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. | YES | You, Service Providers |
| E. Biometric information. | Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data. | NO | N/A |
| F. Internet or other similar network activity. | Activity on our websites, mobile apps, or other digital systems, such as internet browsing history, search history, system usage, electronic communications with us, postings on our social media sites. | YES | You |
| G. Geolocation data. | Physical location or movements, such as the time and physical location related to use of our internet website, application, or device. | YES | You |
| H. Sensory data. | Audio, electronic, visual, thermal, olfactory, or similar information. | NO | N/A |
| I. Professional or employment-related information. | Current or past job history. | YES | You |
| J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)) (“FERPA Information”). | Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records. | NO | N/A |
| K. Inferences drawn from other personal information. | Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. | NO | N/A |
| L. Sensitive personal information. | Further identified in the chart below. | NO | N/A |
Sensitive personal information is a subtype of personal information consisting of the specific information categories listed in the chart below. Importantly, applicable Privacy Laws only treat this information as sensitive personal information when it is collected or used to infer characteristics about you.
The chart below identifies which sensitive personal information categories, if any, we have collected from consumers to infer characteristics about them in the last 12 months.
| Sensitive Personal Information Category | Collected to Infer Characteristics? | Retention Period |
|---|---|---|
| L.1. Government identifiers, such as your Social Security number (SSN), driver’s license, state identification card, or passport number. | NO | N/A |
| L.2. Complete account access credentials, such as usernames, account logins, account numbers, or card numbers combined with required access/security code or password. | NO | N/A |
| L.3. Precise geolocation, such as physical store visits or physical locations when visiting websites or using mobile apps. | NO | N/A |
| L.4. Racial or ethnic origin. | NO | N/A |
| L.5. Citizenship or immigration status. | NO | N/A |
| L.6. Religious or philosophical beliefs. | NO | N/A |
| L.7. Union membership. | NO | N/A |
| L.8. Mail, email, or text messages not directed to the Company. | NO | N/A |
| L.9. Genetic data. | NO | N/A |
| L.10. Neural Data, such as information generated by measuring a consumer’s central or peripheral nervous system’s activity that is not inferred from nonneural information. | NO | N/A |
| L.11. Unique identifying biometric information. | NO | N/A |
| L.12. Health information. | NO | N/A |
| L.13. Sex life or sexual orientation information. | NO | N/A |
We obtain the categories of personal information listed above from the following categories of sources:
This section provides more detail about Category F in the above table.
We collect information about how you use our Services by setting and accessing cookies on your computer. A cookie is a small piece of information sent by our Services that is saved on your storage drive by your computer’s browser. The cookie holds information our Services may need to personalize or enhance your experience and to gather statistical data, such as which pages are visited, the Internet provider’s domain name and the addresses of the sites visited immediately before coming to and immediately after leaving our Services. The information in the cookie lets us trace “clickstream” activity (i.e., the paths taken by visitors to our Services as they move from page to page) to enable us to better serve visitors by revealing which portions of our Services are the most popular. We may link the anonymous visitor ID from your cookie to a user ID in our database to help us analyze web traffic and statistics. From time to time, other companies may help us with data research and analysis, but they will be prohibited from using that data for any other purpose.
You may manage how we use cookies on your browser by clicking the “Manage Cookie Preferences” link in the bottom left hand corner of our Website or by visiting https://jrfortho.org/info/manage-cookies (collectively, the “Cookie Preference Tools”). Clicking either of the Cookie Preference Tools takes you to a page where you can manage your cookie preferences. The four categories of cookies utilized and their purpose are as follows:
By selecting the appropriate radio button next to each cookie type, you can choose which cookies to allow, except for the Strictly Necessary Cookies that are necessary for the operation of the Services. In addition to using our Cookie Preference Tools, you can also manage and disable cookies through your browser settings. You can learn more about cookies at the following link: All About Cookies | Online Privacy and Digital Security. Note that certain features of the Services may not be available if you delete or reject cookies.
In addition to the cookie categories described above, our Website uses the following third-party tracking technologies. Each is configured to operate only after you have indicated your preferences through our “Manage Cookie Preferences” tool, except where strictly necessary for the operation of the Website:
Information collected through these technologies may be transferred to and processed by the technology providers in accordance with their respective privacy policies. You may disable non-essential tracking at any time using our “Manage Cookie Preferences” tool.
Some web browsers offer a “Do Not Track” feature that lets you tell websites you visit that you do not want to have your online activity tracked. Our Website does not currently respond to Do Not Track signals, as no uniform industry standard for recognizing and implementing such signals has been adopted. If a uniform standard is adopted, we will re-evaluate our practices and update this Policy accordingly.
We may obtain information about you from a third-party website or application where we post content or invite your feedback or participation.
We obtain information about you that you provide through our chat feature, which is hosted and operated on our behalf by Crisp IM SAS, a French company located at 2 boulevard de Launay, 44100 Nantes, France (“Crisp” or the “Chat Provider”). When you initiate a chat, Crisp receives, processes, and stores your messages on its servers in the European Union, in real time, on our behalf.
Before any conversation begins, an automated message will appear in the chat window stating that the conversation is recorded and processed by Crisp on our behalf. By continuing the conversation after that notice, you consent to that recording and processing. If you do not wish to consent, please do not use the chat feature — you may instead contact us by phone at 877-255-6727 or by email at privacy@jrfortho.org.
JRF Ortho and Crisp may monitor and record information (including personal information should you provide it) you share through the chat feature, and collect information about your interaction with it and your device (e.g., IP address, online identifiers), for quality assurance, analytics, and the other purposes described in this Privacy Policy.
Because Crisp is established in France, information you submit through the chat feature is transferred to and processed in the European Union. We rely on Crisp’s GDPR-compliant infrastructure and our Data Processing Agreement with Crisp as the basis for this transfer. Crisp’s own privacy practices are described at https://crisp.chat/en/privacy/.
We may use and disclose the personal information we collect to advance the Company’s business and commercial purposes, specifically to:
We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice. If required by law, we will also seek your consent before using your personal information for a new or unrelated purpose. We may collect, process, and disclose aggregated or deidentified information for any purpose, without restriction. When we collect, process, or disclose aggregated or deidentified information, we will maintain and use it in deidentified form and will not attempt to reidentify the information, except to determine whether our deidentification processes satisfy any applicable legal requirements.
We may disclose the personal information we collect to third parties for the business purposes described in the Personal Information Collection, Use, and Disclosure Purposes section and in the table below, such as to engage third parties to support our business functions.
We only make these business purpose disclosures under written contracts that describe the purposes, require the recipient to keep the personal information confidential, prohibit using the disclosed information for any purpose except performing the contract, and meet the other contract requirements under applicable Privacy Laws for engaging service providers or contractors.
The chart below identifies the categories of entities to whom we have disclosed your personal information for a business purpose over the preceding 12 months, along with the personal information categories disclosed and the disclosure’s business purposes.
| Category of Business Purpose Disclosure Recipients | Personal Information Categories Disclosed | Sensitive Personal Information Categories Disclosed | Business Purpose Disclosures |
|---|---|---|---|
| Service Providers (including Sales Representatives) | A. Identifiers. B. California Customer Records. D. Commercial information. |
None | To deliver our services |
| Order Fulfillment and Shipping Providers | A. Identifiers. B. California Customer Records. D. Commercial information. |
None | To deliver products you purchased from us |
| Payment Processor | A. Identifiers. B. California Customer Records. D. Commercial information. |
None | To process payments for products you purchased from us |
| Enterprise Resource Planning System | A. Identifiers. B. California Customer Records. D. Commercial information. |
None | To deliver our services |
| Chat Provider | A. Identifiers. B. California Customer Records. D. Commercial information. F. Internet or other similar network activity. G. Geolocation data. |
None | To provide customer service and support |
a. Categories of Third Parties: We do not sell your personal information in exchange for monetary compensation. We may allow the sharing of your personal information via automated technologies on our Website in exchange for non-monetary consideration such as:
b. Categories of Data: During the 12-month period prior to the last updated date of this Privacy Policy, we may have shared personal information from the following categories:
c. User Age: We do not sell the personal information of minors under 18 years of age without affirmative authorization if we have actual knowledge of the individual’s age. The parent or the child who has opted into personal information sales or sharing may opt out of future sales at any time. If a parent, guardian or child has provided affirmative authorization, they may opt out of future processing at any time by contacting us at privacy@jrfortho.org.
Depending on your state of residence, applicable Privacy Laws may provide you with some or all of the following data subject rights:
You can submit a request to exercise one or more of your data subject rights stated above using the following methods:
After we receive your request, we will determine if the request is a verifiable request before acting on the request. You must provide enough information for us to verify that it is the proper person making the request; if we cannot complete the verification, the request will not be processed. We have 45 days in which to take action on your request. If we run into issues in honoring your request, we will notify you within those 45 days. The original 45-day period may be extended by an additional 45 days if reasonably necessary. We will inform you, without delay, of the reasons, if we decide not to take action on your request. We will also inform you if you have rights to appeal our decision.
If you use an authorized agent to submit a request and the authorized agent does not provide a proper power of attorney, we may require you to either (1) verify your identity directly with us, or (2) directly confirm with us that you provided the authorized agent permission to submit the request.
If your browser supports an opt-out preference signal, specifically the Global Privacy Control (“GPC”) signal, you may opt out of the sharing or sale of your personal information by enabling that signal in your browser or browser extension. When we detect a GPC signal from your browser, we will treat it as a valid request to opt you out of the sale and sharing of your personal information for the device and browser from which the signal originates, and we will not require any additional action from you to give effect to that request.
Because the GPC signal is browser-based and tied to the cookies on your device, if you subsequently delete cookies, change your browser settings, or use a different browser, you will need to turn the opt-out signal on again. If you have an account with us and would like an opt-out applied across browsers and devices, please submit a request via the methods described in How to Exercise Your Rights above.
More information about Global Privacy Control, including supported browsers and extensions, is available at https://globalprivacycontrol.org.
Some features within our Services may require us to sell or share your personal information. If you have previously opted out and later want to opt back in so that you can access such a feature, we will notify you that the feature requires the sale or sharing of your personal information and provide instructions for providing your consent to opt back in.
We apply commercially reasonable and appropriate administrative, technical, and physical safeguards to protect the confidentiality, integrity, and availability of your personal information. Such safeguards protect against unauthorized access, alteration, disclosure, unlawful processing and accidental loss, destruction, or damage of your personal information. Although these safeguards reduce the risk of adverse effects to the confidentiality, integrity, and availability of your personal information, they cannot ensure or guarantee against the possibility of a security incident.
Your personal information is retained for as long as reasonably necessary and proportionate to achieve:
We do not knowingly collect or allow the collection of personal information with our Services from individuals under the age of 18, nor do we knowingly sell or share for targeted or cross-context behavioral advertising personal information of individuals under the age of 18. If we have actual knowledge that we have collected personal information from someone under the age of 18 we will delete that personal information. If you believe that we have collected information from a child under the age of 18, please contact us at privacy@jrfortho.org.
Our Services may contain links to third party websites, services, or resources that are not covered under this Privacy Policy and our Terms and Conditions. Upon visiting or using those third-party websites, services, or resources, we recommend that you review their privacy policy, terms and conditions, and terms of use before providing your personal information.
If JRF Ortho is acquired by or merged with a third-party entity, we reserve the right to transfer or assign the personal information you provided to us as part of such merger, acquisition, sale, or other change of control to the new entity. In the event of bankruptcy, insolvency, reorganization, receivership, or assignment for the benefit of creditors, or the application of laws or equitable principles affecting creditors’ rights generally, we may not be able to control how your personal information is processed. If such a situation arises, we would request that all applicable privacy laws and protection standards at least as stringent as ours be applied to your personal information originally in our possession. In the event of a transfer of corporate assets, the information regarding the transfer will be posted on our Services.
You have choices available when it comes to information about you:
If you are a California resident, you may request information regarding our disclosure, if any, of your personal information to third parties for those third parties’ own direct marketing purposes during the preceding calendar year. We do not currently disclose personal information to third parties for their own direct marketing purposes.
We use features or technologies provided by our third-party service providers that leverage artificial intelligence or machine learning (collectively, “AI”) in connection with our Services to facilitate a more seamless customer service chatbot experience. While we strive for accuracy and relevance, AI-generated content may not always be entirely accurate or up-to-date, and may not reflect personalized advice. Please verify key information with reliable sources and consider consulting with a professional for specific guidance. We do not guarantee the accuracy or completeness of AI-generated content, and users rely on it at their own risk.
We reserve the right to update this Privacy Policy to accurately disclose changes as necessitated by applicable laws and other events. If those changes are material in nature, we will notify you by a notice placed on our public facing Website or by electronic mail.
If you have a question about this Privacy Policy, or you would like to contact us about any of your rights mentioned herein, please contact us at privacy@jrfortho.org. You may reach us by mail to JRF Ortho, Attention: Legal, 7245 S. Havana Street, Suite #300, Centennial, Colorado 80112 USA.
Last Modified: July 29, 2026