Privacy Policy
This Privacy Policy and Notice of Privacy Practices explains how Minnesota Tint Exemption, operated in partnership with MyEyeRx, handles your information and protects your health data under HIPAA.
Last updated: June 2, 2026
Minnesota Tint Exemption("we," "us," or "our") provides an online service that helps Minnesota drivers apply for a window tint medical exemption. Medical review is performed by licensed physicians in partnership with MyEyeRx. We take the privacy and security of your information seriously, especially your health information. This policy applies to minnesotatintexemption.com and our online application.
Information We Collect
- Identifying information: name, email address, phone number, and the state in which you drive.
- Health information (PHI): the medical condition(s) you report, symptom duration and frequency, medications, prior care history, and any medical documentation you choose to upload.
- Payment information: your card details are entered into a secure, PCI-compliant field hosted by our payment processor (Clover) and tokenized. We never receive or store your full card number.
- Technical information: limited data such as IP address and device/browser details, used for security and to operate the website.
How We Use Your Information
- To process your application and facilitate licensed-physician review of your documentation.
- To issue your exemption certificate if your documentation supports approval.
- To process payment for the consultation.
- To communicate with you about your application, including requesting additional documentation.
- To comply with legal, regulatory, and recordkeeping obligations.
We apply the HIPAA "minimum necessary" standard — we access and use only the information needed for these purposes.
How We Share Your Information
We do not sell your personal or health information. We share information only as needed to provide the service:
- Licensed physicians who review your documentation to determine whether a medical exemption is supported.
- Service providers under written agreements, including our records platform (GoHighLevel, covered by a Business Associate Agreement) and our payment processor (Clover, which handles only payment data — never your medical condition).
- When required by law, such as a valid legal request or to protect safety.
HIPAA Notice of Privacy Practices
Because we facilitate medical consultations, your health information is protected under the federal Health Insurance Portability and Accountability Act (HIPAA). We maintain administrative, technical, and physical safeguards and have Business Associate Agreements in place with vendors that handle protected health information (PHI).
Your HIPAA Rights
- Access: request a copy of the health information we hold about you.
- Amendment: request a correction to your health information.
- Accounting of disclosures: request a list of certain disclosures we have made.
- Restriction: request limits on how we use or share your information.
- Confidential communications: ask us to contact you a specific way.
- Complaint: file a complaint with us or with the U.S. Department of Health and Human Services without fear of retaliation.
We use and disclose PHI only for treatment, payment, and healthcare operations, or with your written authorization. We do not use your PHI for marketing without your authorization.
Communications Consent
When you submit an application, you agree to receive communications from us by email, phone, and text message about your application and order. Message and data rates may apply. You can opt out of non-essential messages at any time by replying STOP to a text or contacting us at tory@myeyerx.net. We may still send you essential messages about your active application.
How We Protect Your Information
- Encryption in transit (TLS/HTTPS) across the entire site and application.
- Encryption of stored health information within our HIPAA-compliant records platform.
- Tokenized, PCI-compliant payment handling — card data never touches our servers.
- Role-based access limited to personnel and physicians who need it.
Data Retention
We retain records, including health information and related documentation, for at least the period required by applicable medical-records and HIPAA regulations (generally six years), and longer where required by law.
Cookies & Analytics
We use only essential cookies and limited, privacy-respecting analytics to operate and improve the site. We do not place your health information in cookies, URLs, or browser storage.
Children's Privacy
Our service is intended for licensed drivers and is not directed to children under 18. We do not knowingly collect information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date above reflects the most recent revision.
Contact Us
For privacy questions or to exercise your rights, contact us at tory@myeyerx.net.
Minnesota Tint Exemption is operated in partnership with a licensed medical provider and follows HIPAA-compliant practices for handling your health information. Questions about this document? Contact us using the details in the section above.