Legal
Version 2 · Effective: February 17, 2026
Function Bone Health — A Project of BioX Unlimited LLC
Effective Date: February 13, 2026 Last Updated: February 13, 2026
BioX Unlimited LLC, doing business as Function Bone Health and operating Strength Lab Plus wellness studios ("Company," "we," "us," or "our"), is committed to protecting your privacy and the security of your personal information. This Privacy Policy explains how we collect, use, disclose, store, and protect information when you visit our website at functionbonehealth.com ("Website"), use our services, create an account, make purchases, or otherwise interact with us.
This Privacy Policy applies to all information collected through our Website, services, mobile applications, email communications, booking systems, and any other channels through which you interact with us.
Important: Function Bone Health is a wellness education and screening center. We are not a healthcare provider. However, because we collect health-related screening data, we voluntarily adopt practices aligned with health data protection standards, including HIPAA-aligned safeguards, to protect your information.
We use your information for the following purposes:
SMS/Text Messaging: If you have opted in to receive text messages, your mobile phone number is used solely to deliver the SMS/MMS messages described in our Terms of Service (Section 21). We do not sell, rent, lease, or share your phone number or SMS opt-in consent data with third parties or affiliates for their own marketing purposes. Your phone number is shared only with our messaging service provider (GoHighLevel/LeadConnector via Twilio) solely for message delivery on our behalf. For full SMS terms, see our Terms of Service and SMS/Text Messaging Consent Policy.
You may opt out of marketing communications at any time by clicking the unsubscribe link in any marketing email, replying STOP to any text message, or contacting us at support@functionbonehealth.com.
We do not sell, rent, lease, or trade your personal information to third parties for their marketing purposes. This applies to all categories of personal information we collect.
We share information with trusted third-party service providers who assist us in operating our business, solely for the purposes described in this Privacy Policy:
| Service Provider | Purpose | Data Shared |
|---|---|---|
| Stripe, Inc. | Payment processing | Payment information, billing details |
| HighLevel Inc. (GoHighLevel) | Booking, CRM, communications | Contact information, booking details, communication records |
| Google LLC (Google Analytics 4) | Website analytics | Anonymized usage data, device information |
| Google LLC (Google Tag Manager) | Tag management | Anonymized interaction data |
All service providers are contractually bound to protect your information and may only use it for the specific purposes for which it was shared.
We may disclose your information when required to do so by law, regulation, legal process, or governmental request, including:
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our Website of any change in ownership or uses of your personal information.
We may share your information with third parties when you have given us explicit consent to do so.
We implement commercially reasonable administrative, technical, and physical safeguards designed to protect your personal information, including:
No method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security. You are responsible for maintaining the security of your account credentials.
We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, including:
| Data Category | Retention Period |
|---|---|
| Account information | Duration of active account + 3 years after closure |
| Screening and assessment data | 7 years from date of service (aligned with health record standards) |
| Payment and transaction records | 7 years (financial record-keeping requirements) |
| Communication records | 3 years from last communication |
| Website usage data | 26 months (Google Analytics default) |
| Marketing preferences | Until you withdraw consent or close your account |
| Supplement purchase history | 7 years from date of purchase |
After the applicable retention period, data will be securely deleted or de-identified. You may request earlier deletion of your data, subject to our legal and regulatory obligations.
Regardless of your location, you have the right to:
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Categories of Personal Information Collected (per CCPA):
Virginia residents have rights to access, correct, delete, obtain a copy of, and opt out of targeted advertising and profiling under the Virginia Consumer Data Protection Act.
Colorado residents have similar rights under the Colorado Privacy Act, including the right to opt out of targeted advertising, sale of personal data, and certain profiling activities.
Connecticut residents have rights to access, correct, delete, and obtain a copy of personal data, and to opt out of sale, targeted advertising, and profiling under the Connecticut Data Privacy Act.
If you are located in the EEA or UK, you have additional rights under the General Data Protection Regulation:
To exercise any of your privacy rights, contact us:
We will respond to verified requests within:
We may need to verify your identity before processing your request. We will not charge a fee for processing your request unless it is manifestly unfounded or excessive.
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will promptly delete that information. If you believe we have collected information from a child under 16, please contact us immediately at support@functionbonehealth.com.
Our Website may contain links to third-party websites and services. This Privacy Policy does not apply to any third-party websites or services. We are not responsible for the privacy practices or content of third-party websites. We encourage you to review the privacy policies of any third-party websites you visit.
If you access our services from outside the United States, your information may be transferred to, stored in, and processed in the United States. By using our services, you consent to such transfer. We take steps to ensure that your information receives an adequate level of protection in the jurisdictions in which we process it.
Some web browsers may transmit "Do Not Track" (DNT) signals. Because there is no uniform standard for interpreting DNT signals, our Website does not currently respond to DNT signals. However, you may manage your cookie preferences as described in our Cookie Policy.
We may update this Privacy Policy from time to time. Material changes will be communicated by posting the revised policy on our Website with an updated "Last Updated" date and, where required by law, by providing direct notice to you. Your continued use of our services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
BioX Unlimited LLC d/b/a Function Bone Health Privacy Officer: Nataliya Koval 3341 N Tamiami Trail Naples, FL 34103
Phone: (239) 544-4114 Email: support@functionbonehealth.com Website: functionbonehealth.com
For HIPAA-related inquiries, please refer to our HIPAA Notice at functionbonehealth.com/legal/hipaa-notice.
© 2026 BioX Unlimited LLC d/b/a Function Bone Health. All rights reserved.