This page explains what happens to your information on www.tervehealth.com, and what changes when you become a member. It describes the site as it is actually built today — not as we hope to build it, and not as it was before checkout opened.
The short version. This website runs Google Analytics, and a Meta pixel on three pages — the homepage, checkout and the welcome page after checkout — so we can tell which of our ads work. The pixel is not on any biomarker or guide page, it is never told which biomarker or guide page you came from, it does not read the checkout form, and it is switched off for browsers that send the Global Privacy Control signal. Meta's own script also sends each of those events a second time, to a relay Meta configured; our servers send Meta nothing. If you buy a membership, you give us the details a physician needs to order laboratory testing, and Stripe takes the payment. Nothing about your health — a result, a physician's review, your plan, a medication, a diagnosis — is ever sent to Google, to Meta, or to any other advertising company. If you want out, one email removes you.
Who "we" are
Terve Health is the consumer brand of Heartlab Medical PC, a licensed medical practice. The practice provides the clinical service, is the party you contract with when you join, and is who your payment goes to. Where this page says "we", it means that practice. Membership is currently available in California, Nevada, Montana, Nebraska, New York and Michigan.
What we collect
| What | When, and why | How long |
|---|---|---|
| Your email address | If you type it into a form on this site, or at checkout. We record which form it came from. | Until you ask us to delete it. |
| Checkout details | Only if you start checkout: your legal name, date of birth, biological sex, mobile number and mailing address. A physician needs these to decide whether to order laboratory testing and to put the right name on the requisition. Your card details go straight to Stripe — we never see or store a card number. | Held by the medical practice as part of your record, under the retention rules that apply to medical records. |
| Which consents you accepted | The document version, the date and time, and the IP address it came from — so there is a record of what you agreed to. | Kept with your record. |
| Your IP address | Recorded automatically in our web server's access log alongside the page requested, and stored with a form submission to investigate abuse. | Access logs: 90 days, then deleted automatically. The copy stored with a submission is deleted when that record is. |
| How you found us | Which version of our panel page you were shown, and the campaign tags on the link you arrived through (utm_source, utm_campaign, utm_content). Sent to our own server once with your order and stored with your membership record, so we can tell which advertisement brought you. Marketing measurement only, kept apart from anything clinical. | In your browser until you clear site data; with your record if you buy. |
| Analytics events | Which steps of the purchase you reached — a page view, reaching checkout, reaching the payment step, an error code we generate. Never what you typed, never a health answer. | For the retention period set on our Google Analytics property. |
If you never start checkout, the first, fourth, fifth and sixth rows are the whole of it: this site does not ask a visitor for a health answer, a symptom or a result anywhere, because there is nowhere on it to enter one.
Cookies and browser storage
An earlier version of this page said this site set no cookies. That stopped being true when analytics went live. Here is the actual list.
| Name | What it does | How long |
|---|---|---|
| _ga, _ga_* | Cookies set by Google Analytics. Distinguish one browser from another so a visit is not counted twice. | Up to 2 years (Google's default). |
| _fbp | Cookie set by the Meta pixel on the homepage, checkout and welcome pages only. Distinguishes one browser from another for Meta's ad measurement. | 90 days. |
| _fbc | Cookie set by the Meta pixel when you arrive from a Meta ad. Holds the click identifier Meta put on the link, so the ad can be credited. Set on the same three pages only. | 90 days. |
| terve.panel | Local storage, first-party. Which version of our panel page you were shown and the campaign tags from the link you followed, so the page stays the same if you come back. No name, no email, nothing clinical, and deliberately not the click identifier advertising platforms add to links. | Until you clear your browser's site data. |
| terve.checkout.email, terve_conv_* | Session storage, first-party. Carries your email from the form to the checkout page so you are not asked twice, and stops one completed checkout being counted twice. | Until the tab closes. |
| terve.welcome | Session storage, first-party. Keeps the outcome of your checkout — the payment reference Stripe returns, and whether it was a purchase, a held place or an existing membership — for the welcome page, so that outcome can be taken off the page address before any measurement script runs and the page still shows the right thing if you reload it. | Until the tab closes. |
| Stripe | Set by Stripe on the checkout page, for fraud prevention on its payment form. | See Stripe's own policy. |
Clearing your browser's site data removes all of them. Blocking them does not change what you can do on this site; you will simply be invisible to our measurement, which we would rather you knew than didn't.
The measurement we run, precisely
We advertise on Google and on Meta, and we need to know which advertisement produced a member. Here is exactly how that is done, because "we use analytics" is not a description of anything.
- Google Analytics 4, with the page address cut down first.
Most of this site's URLs name a biomarker or a test, and a URL like that
is a health-revealing thing to hand anyone. So before any measurement is
sent,
/biomarkers/apob/is collapsed to/biomarkers/:slug/— Google is told a biomarker page was read, never which one. Google Signals and advertising personalization are switched off on the property, and IP anonymization is on. The campaign parameters on the link you arrived through, including the click identifier Google adds to its own ad links, stay on the page address Google Analytics receives; that is how a visit is matched to a Google campaign. - Campaign attribution, kept first-party. The version of our panel page you were shown and the campaign tags on your link are kept in your browser and, if you buy, recorded with your order so we can tell which advertisement brought you. We do not keep the click identifier Meta adds to links. This is a marketing label. It is not part of your medical record and it has no effect on your care.
- The Meta pixel, on three pages. On the homepage, the checkout page and the welcome page after checkout, Meta's pixel reports that a page was viewed, that checkout was started, that the payment step was reached, that a waiting-room place was held, and, when a purchase completes on this site, the membership price. It is configured not to watch buttons or form fields, so nothing you type at checkout reaches Meta; it is given no name, email or phone number; and it is not loaded on any biomarker or guide page. A browser that sends the Global Privacy Control signal gets no pixel at all. One thing Meta does that we did not configure: its pixel script also sends a copy of each of these events to a relay that Meta's own configuration points to (Meta calls this its "Meta-enabled Conversions API" and turns it on for every dataset by default). That copy carries the same event and, unlike the direct one, the full address of the page — including any campaign tags and Meta's own click identifier on it — the address of the page you came from (never a biomarker or guide page, as above), the two Meta cookies listed above and, as any web request does, your IP address and browser type. Because of it, the welcome page takes the outcome of your checkout off its own address before the pixel runs: whether you already held a membership, or live outside the states we serve, is no longer in any address Meta receives. The payment reference Stripe returns is still passed to Meta as the event's identifier, on both copies — that is how Meta tells they are one event — and the events themselves still say that a purchase completed or a place was held, as they always did.
- Funnel events, never content events. The complete list of what we send to Google Analytics: a page view; a signup on the email form, when that form is shown; reaching the checkout page; reaching the payment step, with whether it was a purchase or a held place; completing a purchase or a held place; and an error code we generate ourselves when something goes wrong in the form. No event carries an email address, a name, a phone number, a date of birth, a state, or anything a clinician would recognise as clinical.
What we do not do
- One advertising pixel, three pages, nothing else. The Meta pixel described above is the only advertising tag on this site. There is no Google Ads conversion tag, no tag manager, and no pixel of any kind on the biomarker and guide pages.
- Nothing from our servers. Our backend sends nothing to Google or Meta — no Conversions API integration of our own, no Measurement Protocol, no audience upload, no offline conversion file. The only server-side path is the one described above, started by Meta's own pixel script in your browser, carrying the same events the pixel already sends — with the page address and the previous page's address in full, where the direct beacon carries only our domain.
- No clinical information reaches an advertising platform. Not a laboratory result. Not whether a result was abnormal or critical. Not your physician's review, or whether it has been written. Not your plan, your medications, your history, a diagnosis, or a referral. This is not a setting we switched off — no code exists in this website, in the member portal, or on our servers that could send it.
- No tags on the member portal. The signed-in area at my.tervehealth.com, where your results and your physician's review live, carries no analytics and no advertising technology at all.
- No session recorders, heatmaps or chat widgets. Nothing records your screen or your keystrokes.
- Nothing about what you read goes to an advertiser. The page addresses on this site name specific biomarkers. Those pages carry no Meta pixel, the analytics hit from them names the section rather than the biomarker, and our servers send nothing to an advertising platform afterwards.
- We do not sell your personal information, and here is the one thing that may count as sharing. We have never sold it, we do not upload email addresses to advertising platforms, and we do not build custom or lookalike audiences from our list. The Meta pixel described above does send Meta the page views and checkout steps it measures, which California's privacy law may treat as "sharing" for cross-context behavioral advertising. You can opt out of that: if your browser sends the Global Privacy Control signal the pixel does not load at all, and an email to the address below works too.
You do not have to take our word for it. View the source of any page on this site and count the script tags. On the biomarker and guide pages you will find our own code, structured data for search engines and Google's analytics script, nothing else. The homepage, checkout and welcome pages add Meta's pixel script, and checkout adds Stripe's. That check takes about a minute and we would rather you ran it. It shows you the scripts; what Meta's script does once loaded, including the relay copy described above, is visible in your browser's network tools rather than in our source.
Who else is involved
Being honest about tags means being honest about everything else, so here is everyone with a hand in this.
- Amazon Web Services hosts this website and our application, stores our access logs and our database, and delivers the email we send you. Address suggestions in the checkout form are answered by Amazon Location Service through our own servers, so what you type goes to no one else.
- Stripe processes payments. Card details are entered into Stripe's own payment form and never touch our servers. Stripe receives your email address, your name and the amount, and uses cookies on the checkout page for fraud prevention.
- Meta receives the pixel events described above from the homepage, checkout and welcome pages: a page view, checkout started, the payment step reached, a waiting-room place held, a completed purchase and its price. Each arrives twice — once from your browser directly and once through the relay Meta configured — and Meta says it deduplicates the pair. No form contents, no name, no email, no state, nothing clinical.
- Google receives the analytics described above, and serves the three typefaces this site uses from fonts.googleapis.com and fonts.gstatic.com — which means Google receives your IP address and the address of the page requesting a font. Serving the fonts from our own domain instead is still on our list.
- Telnyx delivers our text messages, if you asked for them.
- Laboratories and the clinical record. A CLIA-certified laboratory performs your testing and returns results to the ordering physician; your medical record lives in the practice's electronic health record system. These are part of your care, not part of this website, and they are governed by the documents linked below rather than by this page.
Health information, and a precise word about HIPAA
Reading this website does not create a medical relationship and does not produce health information. An email address typed into a marketing form is not protected health information.
What you provide at checkout, and everything created afterwards — the laboratory order, your results, your physician's review, your plan — is protected health information held by Heartlab Medical PC under HIPAA and, in California, the Confidentiality of Medical Information Act. What may be shared, with whom, and how to revoke it are set out in the Authorization for Use & Disclosure of Medical Information, which is a separate document you sign separately. The Telehealth Informed Consent and the Request for Laboratory Testing & Results govern the care itself.
The practice's Notice of Privacy Practices is a separate document and is still owed. We would rather say that plainly here than imply a document exists that you cannot read.
How to leave
To stop the emails: every marketing email we send carries a one-click unsubscribe link at the bottom, and the standard unsubscribe header that your mail app's own "Unsubscribe" button uses. Either one takes effect immediately. The link is generated uniquely for each message and arrives inside it, so there is no generic unsubscribe address for us to print here. To stop texts, reply STOP.
One honest note about what unsubscribing does: it does not delete your address, because it cannot. The only reliable way to guarantee we never email you again is to remember not to. Your address is kept on a suppression list and is never sent to.
To be deleted entirely: email support@tervehealth.com and say so. You do not need to give a reason, you do not need to be a California resident, and we will not try to talk you out of it. If you are a member, records that a medical practice is legally required to retain are kept for as long as the law requires and no longer; we will tell you what that covers rather than pretending everything is erasable.
The same address handles requests to see what we hold about you, to correct it, or to opt out of any sale or sharing — which, as set out above, we do not do. California residents have these rights under the CCPA, as amended by the CPRA, and we will not discriminate against you for exercising them. We extend the same rights to everyone else, because operating two standards would be more work than operating one.
Children
This website and the Terve Health membership are for adults. Checkout refuses anyone under 18. We do not direct this site to children, and we do not knowingly collect information from anyone under 18. If you believe a child has given us information, email us and we will delete it.
Changes to this policy
When what we collect or what we run changes, this page changes in the same release, and the date at the top changes with it. If a change ever materially affects information we already hold about you, we will email the people it affects rather than quietly editing the page.
Contact
Privacy questions, requests, and complaints all go to the same place, and a person reads it: support@tervehealth.com.
Heartlab Medical PC (doing business as Terve Health) · 6245 Wilshire Boulevard, Los Angeles, CA 90048
Related: Terms of Use · About Terve Health