MONARCH — CONSUMER HEALTH DATA PRIVACY POLICY
v1.0 · Effective September 8, 2026
Effective date: September 8, 2026
Last updated: September 2026
This policy explains how Monarch Transformation Center LLC ("Monarch," "we," "I") collects, uses, shares, and protects consumer health data. Monarch is a California limited liability company, and Sean Connick delivers the coaching personally.
This policy applies to consumer health data protected by Washington, Nevada, or Connecticut law. Monarch voluntarily gives the rights described here to every person whose consumer health data it holds. Our general Privacy Policy at /privacy covers other personal information. Where the two policies differ about consumer health data, this policy controls.
1. What consumer health data means here
Consumer health data is personal information that identifies or can be used to identify your physical or mental health condition or status, bodily functions, symptoms, measurements, or your effort to obtain services that assess, measure, improve, or teach you about health.
In Monarch's systems, ordinary identity or transaction data can become consumer health data when it identifies you as a person seeking or receiving this program. For that reason, this policy can cover your name, contact details, mailing address, application, intake, coaching, and payment records even when a field does not look medical by itself.
2. What we collect and why
- Identity and contact information — name, email, phone, mailing address, date of birth, city and state, time zone, and preferred contact method. We use it to communicate, schedule, confirm adulthood, apply state-specific rules, administer the engagement, and send program materials.
- Application information — training history, goals, desired body-composition change, sleep, schedule, lifestyle information, and what you tell us about your obstacle and timing. We use it for a human review of program fit and to prepare for a Strategy Session.
- Intake information — medical conditions, medications relevant to training or nutrition, surgeries, injuries, diet history, eating and training practices, equipment, schedule, stress, alcohol, and caffeine. We use it to design and deliver safer, appropriate coaching.
- Program and progress information — height, weight, measurements, body-fat percentage, scan results, progress photographs, check-ins, compliance, nutrition adherence, sleep, energy, notes, and images of Operator's Log entries. We use it to coach you, run the weekly Plan-of-Action cycle, and, where your signed agreement includes it, verify the Reclaim Sovereignty Guarantee.
- Call recordings — only where you separately consent to recording. We use recordings to deliver and document coaching. Declining recording does not change your eligibility for coaching.
- Monarch's coaching notes and inferences — observations, plans, annotations, and conclusions created from the information above. We use them to deliver and improve your coaching.
- Technical information — IP address and security-event information processed by the bot-protection and secure form-delivery services that protect our forms. We use it to secure the site, prevent abuse, and deliver submissions.
- Payment and transaction records — payment status, amount, date, method category, invoices, and subscription history. We use them to take and reconcile payment, administer the engagement, prevent fraud, respond to disputes, and keep records a specifically identified law requires. Monarch does not store full card numbers.
Categories of personal data sold to third parties: none.
Categories of third parties to which we sell personal data: none.
3. Where we get it
We obtain information from you and your device when you submit a form, communicate with us, attend a call, or participate in coaching. We also create coaching notes and inferences during the engagement. We do not buy consumer health data from data brokers, advertising networks, or public records.
4. How we process it
Your state answer can automatically route an application to proceed, waitlist, or decline. That routing uses state, not health information.
Application answers may produce an internal score and review flags, but they do not automatically approve or reject a person based on health or lifestyle answers. Every application that passes the separate state screen is routed to human review. The score and flags are advisory inputs for Sean; Sean makes the fit decision.
We do not use consumer health data to make automated decisions about credit, insurance, employment, housing, education, or health care.
5. Categories we share, recipients, and purposes
We disclose only the data reasonably necessary for the listed role and purpose. A provider can receive more than one listed category when its service requires it.
| Recipient category | Data categories disclosed | Purpose |
|---|---|---|
| Marketing, website, CRM, and communications provider | Identity/contact data; form answers; conversations; scheduling; security and assent records | Host pages and forms, maintain contact records, deliver submissions and communications, and schedule sessions |
| Network-security and form-delivery provider | IP address, request metadata, security signals, and submitted payload in transit | Prevent abuse and securely route forms |
| Training-delivery provider | Identity/contact, intake, program, progress, photographs, measurements, and coaching communications | Deliver training, messaging, check-ins, and progress tracking |
| Video-conferencing providers | Identity/contact, meeting metadata, and call content or recordings when separately consented to | Conduct and, when authorized, record coaching calls; a conferencing provider may also process limited account, security, support, fraud-prevention, or legal-compliance data for its own stated purposes |
| Business-operations providers | Identity/contact, agreements, correspondence, scheduling, billing, and transaction records | Billing, e-signature, business email, scheduling, records, and storage |
| Payment processor | Identity/contact and payment/transaction information | Authorize, settle, reconcile, and prevent fraud in payments |
| Print-and-mail provider | Name and mailing address | Send a welcome card or approved printed program material |
| Cloud-storage provider | The categories stored in the relevant file | Store and protect Monarch's working records |
We may also disclose information when law requires it or in connection with a sale or reorganization of the business, subject to applicable law and this policy. Monarch has no affiliate that receives consumer health data. We do not disclose consumer health data to advertisers, data brokers, or other clients.
Mobile information and text-message consent are not shared with third parties or affiliates for their marketing. Providers that deliver Monarch's own text messages receive only what is necessary to provide that service.
6. Sale, targeted advertising, tracking, geofencing, and model training
Monarch does not sell consumer health data or other personal data and does not process it for targeted advertising. We do not use geofences around health-care facilities to identify or track people or send health-related messages.
Monarch does not instruct a provider to use your personal information to train a large language model. We do not knowingly submit intake answers, photographs, measurements, or call recordings to a general-purpose model for training. Providers can process limited service, security, support, fraud-prevention, or legal-compliance data under their own terms; this policy does not promise facts about a provider's systems that Monarch cannot verify.
Monarch does not intentionally install advertising or analytics pixels on its public pages. The site uses security and form-delivery technology. You can use the Privacy Choices page at /privacy-choices to record an opt-out request even though Monarch currently engages in neither sale nor targeted advertising.
7. Consent and withdrawal
For a Connecticut consumer, Monarch processes sensitive data only when the processing is reasonably necessary for the disclosed purpose and after obtaining consent. For Washington and Nevada consumers, Monarch collects or shares consumer health data only with the consent those laws require or to the extent necessary to provide a product or service the consumer requested. Consent to share is separate from consent to collect whenever the law requires it.
At the point of collection, the form identifies the categories involved, the purpose, the recipient categories, this policy, and the withdrawal route. Accepting the general Terms is not health-data consent.
You may withdraw consent at any time through /privacy-choices or by emailing [email protected]. We stop the processing covered by the withdrawal as soon as reasonably practicable and, for Connecticut consumer health data, within fifteen days. Withdrawal does not undo processing that lawfully occurred before it and does not itself delete earlier data; you may submit a deletion request at the same time.
8. Your rights
Subject to applicable law, you may ask Monarch to:
- confirm whether we hold your consumer health data and provide access to it, including covered inferences;
- correct inaccurate data;
- provide a portable copy;
- provide a list of recipients to which your consumer health data was shared or sold, with a way to contact them where required;
- delete your consumer health data and notify covered recipients to delete it;
- stop future collection, processing, sharing, or sale covered by a withdrawal or opt-out;
- record an opt-out of sale, targeted advertising, or qualifying profiling;
- honor a request made through an authorized agent after verifying identity and authority; and
- appeal a refusal.
We do not discriminate against you for exercising a privacy right.
9. How to submit and verify a request
Use /privacy-choices or email [email protected]. The request is logged with a tracking identifier and receipt date. We acknowledge it, ask only for information reasonably necessary to verify identity and authority, and send responsive health data through a reasonably secure delivery method rather than ordinary email when the contents require it.
Requests are free. We may charge a reasonable fee or decline only when a request is manifestly unfounded, excessive, or repetitive, and Monarch bears the burden of showing why.
10. Response times, deletion, and backups
We respond without undue delay and no later than forty-five days after receiving a request. When law allows and complexity or request volume makes it reasonably necessary, we may extend once by forty-five additional days; we will explain the extension within the first forty-five days. The receipt-based clock is not delayed merely because identity verification is ongoing.
We complete a verified deletion request within thirty days where Nevada law requires that period. We direct covered recipients to delete the data and retain the request, verification, instructions, responses, and completion evidence. Data on an archived or backup system is isolated from ordinary use and deleted at the earliest practicable restoration cycle, no later than six months where Washington law applies.
11. Retention
Monarch keeps consumer health data only while a disclosed purpose remains live, then deletes it under the documented deletion workflow unless a specifically identified law requires a narrower record to be retained.
| Category | Retention rule |
|---|---|
| Health intake, including conditions, medications, surgeries, and injuries | Through active coaching and any active Guarantee continuation, then deleted |
| Progress photographs | Through active coaching and any active Guarantee continuation, then deleted; a separate signed Media Release governs any authorized marketing copy |
| Measurements and scan results | Through active coaching and any active Guarantee continuation; afterward, only the minimum record supported by a documented legal requirement or consent |
| Non-enrolling applicant health information | Thirty days after final decline, withdrawal, or abandonment, unless the applicant asks to remain under consideration and affirmatively consents to a longer stated period |
| Contract, payment, and billing records that also identify a health-service relationship | Only for the period required by a specifically identified accounting, tax, payment, or legal obligation, with unnecessary health detail removed where practicable |
| Rights-request and deletion evidence | Long enough to prove receipt, verification, action, recipient notice, completion, and any lawful denial or appeal |
A verified deletion right controls over Monarch's ordinary retention schedule. If an applicable law permits or requires a narrow exception, Monarch will identify the law and retained category in its response rather than relying on a blanket “business records” exception.
12. Security and access
Monarch limits access to people and systems that need the information for a disclosed purpose. We use account-level controls available for the relevant service, including unique credentials and multi-factor authentication where configured, and review processor scope before a new health-data flow begins. No internet service is perfectly secure. If a breach occurs, Monarch will investigate and give notices required by applicable law.
13. Children and minors
Monarch's site and services are for adults. We do not knowingly collect personal information from anyone under 18. If we learn that a minor submitted information, we stop processing it, identify every processor that received it, direct deletion, verify completion, and preserve only the minimum evidence needed to show the request was completed.
14. Appeals
If we refuse all or part of a request, we give written reasons and appeal instructions. Reply to the decision or email [email protected] with Privacy Appeal in the subject line. We decide the appeal in writing within forty-five days. If denied, we provide the applicable state Attorney General complaint route.
15. Processors and independent uses
Monarch uses providers for the roles, data categories, and purposes listed in Section 5. A provider may process data for Monarch under online service terms, an incorporated data-processing addendum, an account-level acceptance, or a separately signed addendum. Those provider agreements are separate from these Terms and do not change the disclosures or consents in this policy.
Monarch maintains provider-contract status internally and will answer a consumer who asks whether a particular provider is subject to a processing agreement. Obtaining, replacing, or supplementing a provider agreement does not require new Terms or a new policy version unless it changes a disclosed data category, purpose, recipient category, independent use, or consumer right. If it does, Monarch will update the notice and obtain any required consent before the changed processing begins.
16. Changes
If Monarch proposes to collect a new category, use data for a new purpose, or share it with a new recipient category, we update the relevant notice before the change and obtain affirmative consent where law requires it. Material changes affecting data already collected are communicated to the people affected, with a real opportunity to withdraw before the new processing begins. A new public version receives a new effective date; superseded versions remain available.
17. Contact
Monarch Transformation Center LLC
1020 Copeland Creek Drive, Rohnert Park, CA 94928
Email: [email protected]
Telephone: (707) 230-5341
Email is monitored for rights requests, withdrawals, and appeals. The /privacy-choices page is the public request and opt-out route.