Privacy Policy
Last updated: April 20, 2025
On This Page
- Part A — The people behind this website
- Who this website is written for
- Part B — What reaches us, and what never leaves your device
- Technical details our hosting receives
- What stays on your own device
- Why you are not seeing a cookie banner
- Part C — What we do with what we receive
- The consent record we keep as proof
- Who else can see your information
- A separate promise about mobile information
- Do Not Sell or Share My Personal Information
- Privacy rights outside California
- How long we hold on to things
- Turning the messages off
- How your submission is protected
- Nothing here is for children
- When this notice changes
- Reaching our privacy desk
Part A — The people behind this website
NJ Foot & Ankle Care is the public name used for the educational website published at nufeetfootcare.com. The operator responsible for that website, and the entity accountable for the personal information described in this notice, is Diabetic Foot & Ankle Centers of NJ LLC, 667 Eagle Rock Ave, West Orange, NJ 07052, USA. Where this notice says "we" or "our", it means that operator.
Questions about anything written below go to [email protected]. That address is monitored for privacy matters specifically, including requests to see, correct, or delete what we hold.
Who this website is written for
This is a static educational website intended for adults in the United States who are 18 years of age or older. It has no shopping cart, no payment processing, no patient portal, and no accounts to register for. Nothing on this website asks you to create a password, and no page should ever present you with a login. If one appears to, it did not come from us.
Part B — What reaches us, and what never leaves your device
Almost everything that reaches us does so because you typed it into one of two forms and pressed a button. Nothing is collected silently for advertising or profiling.
The foot health updates form on our subscribe page collects your first name, last name, email address, and date of birth. It collects a mobile number only when you have separately asked for text messages; leave that permission unchecked and the phone field stays empty and optional. Date of birth is collected because this is health education intended for adults, and it is the field we use to confirm you are 18 or older.
The contact form collects the name you give, an email address to reply to, and whatever you choose to write in the message box. We ask you not to describe your symptoms, medical history, or treatment in that box. It is an ordinary web form, not a clinical channel, and the message travels the same way any website form submission does.
Technical details our hosting receives
Serving a web page and accepting a form submission are not silent acts. In the ordinary course of delivering this website, the hosting platform and the endpoint that receives our form submissions observe the technical details every web request carries: the originating IP address, the browser and operating system identified in the user-agent string, the page that referred you, which file was requested, and the date and time. This is the same connection data any web server necessarily sees in order to send a page back to you.
We do not run any script that looks up your IP address, geolocates you, fingerprints your browser, or attaches an advertising identifier to you. Server-level records of this kind exist for delivery, security, and troubleshooting; they are not assembled into a profile of you and they are not used to decide what content you see.
What stays on your own device
Two features on this website remember things, and both of them remember on your device rather than on ours.
- The Plan Your Visit checklist saves which items you have ticked off and any questions you add to your own list. That content is written to your browser's local storage. It is never transmitted to us, we have no way to read it, and clearing your browser's site data erases it.
- The newsletter invitation and subscription state are remembered for the length of your browsing session so that a dismissed invitation stays dismissed and a completed subscription is not asked for again. That is a single yes-or-no marker in session storage, holding no name, no email, and no identifier. It disappears when you close the tab.
The Symptom Explorer stores nothing at all. What you click and what you type into its search box exist only in the page's memory while it is open, and are gone the moment you navigate away. No search term is logged, sent, or associated with you.
Why you are not seeing a cookie banner
This website loads no analytics package, no advertising pixel, no tag manager, no session recorder, no social media widget, and no third-party font or script. There is consequently nothing to consent to, so we do not display a consent banner. Presenting one would suggest tracking that does not exist here, and we would rather tell you plainly than manufacture a dialog.
If that ever changes, the change will not be quiet. Any tracker would have to wait for your affirmative permission before loading, a genuine way to decline and keep browsing would sit beside the way to accept, your choice would be re-openable and changeable, and a Global Privacy Control signal sent by your browser would be honored automatically as an opt-out without requiring you to click anything. This notice would be revised before any of that went live.
Part C — What we do with what we receive
Your submission is used for the purpose you submitted it for, and for the narrow operational purposes that make that possible:
- sending the educational podiatry and diabetic foot care emails you asked to receive;
- sending educational text messages, but only if you separately gave written permission for them;
- reading and replying to a message you sent through the contact form;
- keeping our own record that a permission was given, in the form described in the next section;
- honoring an unsubscribe, a STOP, or a deletion request, and keeping the suppression record that makes it stick;
- keeping the website working and defending it against abuse, fraud, and security incidents;
- meeting a legal obligation that applies to us.
Your information is not used to build an advertising audience, is not enriched with data bought from anyone, and is not run through automated decision-making that produces legal or similarly significant effects.
The consent record we keep as proof
When you tick a permission box, we store more than a checkmark. We store the exact wording that was on screen at the moment you agreed, a version stamp identifying that wording, which boxes were and were not ticked, the address of the page you were on, and the timestamp of the submission. This exists so that a permission can be demonstrated later, exactly as it was worded when you gave it. It is evidence of your choice, and it is not used to market to you.
Who else can see your information
We do not trade, rent, or sell personal information, and there is no category of recipient beyond the two described here.
Service providers acting on our instructions. Running a website and sending email requires vendors: a hosting platform, the automation endpoint that receives form submissions, an email delivery service, and — where you have opted in to texts — the messaging platform and the mobile carriers that actually move the message to your handset. Each receives only what its function requires, is bound by contract to use it only to perform that function for us, and may not repurpose it for its own marketing.
Legal and safety disclosures. We may disclose information when a subpoena, court order, or other legally valid demand requires it; where disclosure is necessary to establish, exercise, or defend a legal claim; to investigate suspected fraud, abuse, or a security incident; to protect the rights, property, or physical safety of any person; or to a successor entity as part of a merger, acquisition, financing, or sale of assets, in which case this notice governs until the successor provides a replacement.
These two categories are exhaustive. There is no third bucket in which your details are passed to marketing partners, data brokers, list co-operatives, or advertising networks.
A separate promise about mobile information
This clause stands on its own and is deliberately narrower than the section above it.
Mobile information, opt-in data, and consent will not be shared with third parties or affiliates for their marketing or promotional purposes, and will not be sold. Text messaging originator opt-in data and consent will not be shared with any third parties, excluding aggregators and providers of the text message service. Those excluded parties are the technical pipeline required to deliver a message you asked for; they cannot use your number for their own purposes.
Do Not Sell or Share My Personal Information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. That is a statement of fact about how this website is built, not a preference you need to set. There is no opt-out toggle here because there is no sale or cross-context sharing to opt out of.
If your browser or an extension transmits a Global Privacy Control signal, we treat it as a valid opt-out request. Because no sale or cross-context sharing occurs, honoring it requires no change in our behavior, and we will not ask you to log in or identify yourself for the signal to count.
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the right to know what personal information we have collected about you and where it came from, the right to receive a portable copy of it, the right to correct information that is inaccurate, the right to delete it, the right to opt out of sale or sharing, the right to limit the use of sensitive personal information, and the right not to be discriminated or retaliated against for exercising any of them. We do not use or disclose sensitive personal information for purposes beyond those a consumer would reasonably expect, and we do not offer financial incentives in exchange for personal information.
Making a request. Email [email protected] and state which right you are exercising. Verification. Before we act on a request to know, correct, or delete, we confirm that the request really comes from you by matching the details in your message against what we already hold — typically the email address or mobile number in our records. We ask for the minimum needed to be confident, and anything provided solely to verify you is used for nothing else and then discarded. Authorized agents. An agent may submit a request on your behalf with written permission signed by you; we may still contact you directly to confirm that you authorized it. Timing and appeals. We acknowledge requests within ten business days and respond substantively within forty-five calendar days, extending once by another forty-five where reasonably necessary and telling you why. If we decline a request in whole or in part, we will explain the basis, and you may appeal by replying to our decision with the word "appeal" in your message; an appeal receives a fresh review and a written outcome. Where your state provides one, you also retain the right to complain to your state attorney general.
Privacy rights outside California
Residents of other states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana, among a growing list — have comparable rights to access, correct, delete, and obtain a portable copy of their personal information, to opt out of targeted advertising, sale, and certain profiling, and to appeal a refusal. Rather than sort visitors by state, we extend the same handling to everyone who writes to us. Use the same address and the same process described above.
How long we hold on to things
Contact form messages are kept while the conversation is open and for a reasonable period afterward for reference, then deleted. Subscriber details are kept for as long as you remain subscribed. When you unsubscribe, your details come off the active sending list promptly.
Two records outlive the subscription itself, deliberately. Evidence of an SMS opt-in and of an opt-out — the wording shown, the version stamp, the timestamp, and the number involved — is retained for at least four years, because messaging law requires an operator to be able to prove that a permission was given and when it ended. Suppression records, meaning the list of addresses and numbers that must not be contacted again, are retained for at least ten years or longer where the law requires it. A suppression record is what guarantees that a STOP or an unsubscribe is permanent; deleting it would risk contacting you again by mistake, so it survives even a deletion request, and it is used for nothing except to keep you off the list.
Turning the messages off
Every educational email carries an unsubscribe link in its footer, and using it takes effect without any further step from you. You can also write to [email protected] and ask to be removed.
For text messages, reply STOP to any message from the program and the messages end; reply HELP to any message for assistance. If your handset or plan makes replying difficult, email [email protected] and we will remove the number ourselves. Ending texts does not end your emails, and ending emails does not end your texts — the two permissions are separate, and so are the two ways of withdrawing them. Full program terms are in our SMS Terms.
How your submission is protected
Form submissions travel over an encrypted connection, access to what we receive is restricted to the people who need it in order to answer you or send what you asked for, and we keep the collection surface deliberately small — the less that is gathered, the less there is to expose. That said, no method of transmitting information over the internet or storing it electronically is completely secure, and we cannot promise absolute security. If a breach affecting your personal information occurs, we will notify you and the relevant authorities as required by applicable law.
Nothing here is for children
This website is directed to adults. The subscription form asks for a date of birth and refuses any submission from someone under 18; the contact form has no such check, so please do not write to us through it if you are under 18. We do not knowingly collect personal information from anyone under 18. A parent or guardian who believes a child has submitted information should write to [email protected], and we will delete the record and remove the address or number from every list.
When this notice changes
We revise this notice when the website's data practices actually change. The revised version is posted here with a new "Last updated" date at the top of the page, and the change takes effect when posted. If a revision would materially alter how we use information you have already given us, we will seek your consent before applying it to that information rather than relying on a silent update.
Reaching our privacy desk
Privacy questions, rights requests, and appeals:
Diabetic Foot & Ankle Centers of NJ LLC
Operator of NJ Foot & Ankle Care
667 Eagle Rock Ave, West Orange, NJ 07052, USA
Privacy: [email protected]
General support: [email protected]