Privacy Policy
Before using our sites, please read this privacy policy carefully.
The Privacy Policy was last updated on January 22, 2025.
Wylo is a Brand of Simpill Health Group Inc.
Welcome to Simpill Health Group Inc. dba Wylo (“Wylo”, “we”, “us”, “our”), a virtual health service. Outside of Quebec, Wylo provides virtual assessments, health coaching, and prescription facilitation services for weight loss medications. Wylo offers both Consultation Services (which means eligibility assessments for medications) and Prescription Facilitation Services through our website, www.wylo.com (the “Website”), and through our proprietary platform (the “Platform”), together with the Consultation Services (the “Services”).
Our Services provide patients with convenient access to virtual healthcare and medication facilitation through our Platform. We fill prescriptions from our central fill locations in either Ontario, Manitoba, or British Columbia, as applicable. We are committed to protecting your personal information and complying with applicable data protection and privacy laws. This Privacy Policy outlines how we handle and protect your personal information.
Simpill complies with Canadian Federal and Provincial privacy laws and regulations, including the Personal Information Protection and Electronic Documents Act (PIPEDA), the Personal Health Information Act (PHIA MB) and the Personal Information Protection Act (PIPA BC).
This Privacy Policy describes the types of personal information we collect, how we use it, and how we protect your personal information when providing you with the Service or when you access our Website, www.wylo.com (the “Website”). Simpill reserves the right to change, add, remove, or modify sections of this Privacy Policy or the Website at any time. Changes will be effective immediately on the date that appears on the revised policy. Any notices regarding any changes to this Privacy Policy will be indicated on our Website. If any changes to this Privacy Policy are significant, we will provide you with more prominent notice (including email notifications).
What information do we collect?
We collect personal information such as name, age, gender, phone number, email address, shipping address, provincial health card details (or an image of card), credit card details (or an image of card), insurance details (or an image of card), prescription information, and any other necessary information required to deliver medication through either the Platform or the Secure Platform. We also collect optional medical and health-related information to serve you better and share with the pharmacist and healthcare team that you may provide at your sole discretion.
Further, we collect non-personally identifiable information, including but not limited to medication adherence statistics and location data when you use our Platform or the Secure Platform.
Access and disclosure:
We only allow access and disclosure of personal information as permitted by applicable laws and regulations.
Other types of information we collect:
We may also collect additional information such as such as IP address, device identifiers, online identifiers, unique identifiers, access dates and times, crash logs, device event information, cookie data, or other similar identifiers, geo-location data if enabled on your device, usage information, inferences drawn from compiled data and customer profiles, payment transaction information, and cookies when you use the Services or the Secure Platform. We use cookies to track your interests and recognize you as a returning visitor. Please note that disabling cookies may affect certain features of our Website. We may also record your IP address, which contains no personally identifiable information.
How we use your personal information:
We use your personal information to provide and improve Services or the Secure Platform, process transactions, communicate with users, provide customer support, personalize user content or features, inform product development, and for analytics and research purposes. We also use your personal information to comply with legal or regulatory obligations, ensure the security of a service, or prevent fraud.
In compliance with the Personal Health Information Protection Act (PHIPA), we may aggregate and anonymize Personal Health Information (PHI) and other information stored on our system. Aggregated and anonymized PHI may be used by us, or our strategic partners to improve our services, conduct research, or provide insights into healthcare trends. This data will not identify any individual and will be handled in accordance with all applicable laws and regulations.
How we share personal information:
We may disclose personally identifiable information to various third parties under the following circumstances: to parties who we engage on your behalf to provide you the Services or the Secure Platform, including but not limited to credit card processing, messaging and push notifications, insurance plan, and delivery services. If you book an appointment on the Platform, you authorize Wylo to share the necessary personal health information to book the appointment with our virtual care partners. Users can sign up and log in to the Platform or the Secure Platform by linking third-party social accounts (Gmail, Facebook and Apple), and we may use certain personal information provided to us from linked services to create your personal Wylo account (name, email, date of birth etc.). In addition, for the provision of the Services or the Secure Platform, Wylo may use aggregated, non-personally identifiable demographic information for the purposes of providing insight into the trends about the general use of our services and demographics of Canadian healthcare consumers. Wylo may share this information with its strategic partners, who are required to maintain the confidentiality, security, and integrity of the information they receive. We will ensure that these parties are bound by confidentiality obligations and are prohibited from using or disclosing your personal information for any purpose other than as needed to perform their services on our behalf or to comply with legal requirements.
Wylo will not allow third parties to access your personal information without consent except to provide you with the Services or the Secure Platform. Wylo will never sell the personal information of its users. Wylo will not allow access to the personal health information of any of its users to any third party without getting the users’ express consent, except where required by law or regulatory requirements. We will ensure that any third parties to whom we disclose personal information are bound by confidentiality obligations and are prohibited from using or disclosing your personal information for any purpose other than as needed to perform their services on our behalf, to comply with legal requirements or for additional purposes where your express consent is provided.
Consent to use personal information:
By using the Wylo website, pharmacy services, and/or the Secure Platform you consent to the collection and use of your personal information by Wylo in accordance with this Privacy Policy. We only collect the information you voluntarily provide us, except where otherwise permitted or required by law or regulatory requirements.
Your control and rights over personal information and withdrawing consent:
- You have the right to withdraw your consent. Users can withdraw consent to provide personal information and may request the deletion of their data. By withdrawing consent, users will no longer be eligible for services. The pharmacy team will support any medication requirements while the patient is transitioned to a new pharmacy provider. However, we will still have to retain records of services provided to you to comply with regulatory requirements.
- We will seek additional consent from you if we collect, use or disclose personal information about you for purposes not otherwise described in this Privacy Policy.
- You have the right to delete your data and account. To exercise your right to delete your data and account, you can either go into your profile settings on the website and select "Delete Account" or contact us via the chat function on the Platform. Alternatively, you can contact us via phone or email. We may take up to 48 hours to process your request. We may still retain personal information to the extent necessary to comply with legal and regulatory requirements (for example, medical history, tax and audit purposes). We may also retain personal information to the extent necessary to protect against and prosecute malicious, illegal, and fraudulent activity.
- You have the right to request access to your data or make corrections to your data. To request access to your data or to make corrections to your data, please email privacy@wylo.com. A request to modify your data may take up to 30 days to complete
Children’s privacy:
The Services are intended for adults, and we do not knowingly collect personal information from anyone under the age of 18. If we discover that anyone under the age of 18 has provided us with their personal information, we will take all necessary steps to delete this information immediately.
How we protect your privacy:
Your privacy and security are of utmost importance to us, and we take measures to protect your personal information. We follow industry-standard security measures to encrypt your data, both when it is in motion and at rest. Your personal information may be stored on your device and transferred to our servers. While we take all necessary precautions to ensure the safety of your data, it is important to note that no method of transmission or storage is 100% secure. Microsoft Azure Canadian Datacenter, an enterprise-grade cloud computing platform, hosts our servers. You can read more about Microsoft Azure’s security standards here: https://www.microsoft.com/en-us/trustcenter/Security/AzureSecurity.
Wylo will notify you to the extent required by law of any breach that has resulted in the unauthorized access to, collection, use or disclosure of your personal information.
Password use:
Your Wylo account and personal information are protected by a password. Choose a robust and unique password and keep it confidential. Do not share your password with anyone, and if you believe your password has been compromised, reset it immediately.
How we will use your email:
We will contact you via email for notification purposes and to inform you of promotional offers that may interest you. Personal health information (PHI) and financial information will not be communicated via email. We will not share your personal information for marketing or advertising purposes without your consent, this may include consent provided to our healthcare partners. However, we may market or advertise from time to time. You can opt out of receiving marketing and promotional material at any time, and we will take all necessary steps to remove you from the mailing list. We have implemented this set of practices to comply with Canada’s Anti-Spam Legislation (CASL).
How long do we store your data
Wylo will store your data as long as is necessary to provide you with Wylo services or to comply with applicable laws.
How to contact us?
You can contact the Chief Privacy Officer via email privacy@wylo.com or the address below if:
- You have questions that relate to the collection, use and disclosure of your personal information.
- You want to withdraw your consent to the collection, use or disclosure of your personal information.
- You have the need to report any privacy violations including but not limited to: any real or suspected unauthorized access, use, disclosure or loss of your personal information.
- You wish to make a complaint regarding the handling of your personal information or this Privacy Policy in general.
Chief Privacy Officer
Simpill Health Group Inc.
19-3 Brewster Rd.
Brampton ON, L6T 5G9
Get in touch today!
Don't be shy, you can ask us anything! Whether you’re curious about our services, need guidance, or just want to say hello—don’t hesitate to reach out!