HealthEquity Skip to content

Team member privacy notice

HealthEquity, Inc. and its subsidiaries, including WageWorks, Inc. and Fort Effect Corp. (DBA Luum), prioritize your privacy. This notice explains who we are, how and why we handle your personal information as your employer, and your rights regarding that information. It also outlines how to contact us with complaints. This notice applies to all current and former employees ("team members").

The Company processes personal information as per this Notice, unless required by law. We follow state privacy laws in the United States and are responsible for your data.

We collect relevant and limited personal information related to employment. The Company neither sells nor shares team member information for behavioral advertising.

This Notice excludes aggregated, anonymous, or de-identified data. Aggregated data removes individual identities. Anonymous data makes individuals unidentifiable. De-identified data cannot reasonably identify any individual.

Failing to provide requested personal information may affect our ability to serve you fully as an employer (such as payment or benefits) or comply with legal obligations (such as worker health and safety).

  1. Personal Information We Collect About You. The Company may collect and use personal information that can identify, relate to, describe, or be reasonably associated with team members. Sensitive Personal Information may be collected and processed if required or permitted under applicable law, necessary for the establishment, exercise, or defense of legal claims, or if the team member has provided explicit consent.

  2. If you provide personal information about others, inform them of the purpose and share this Notice. We will assume their consent for collection and processing unless notified otherwise in writing.

  3. How Your Personal Information is Collected. We collect most of this Personal Information directly from you—in person, by telephone, text, email, website, and apps. However, we may also collect information:

    • From publicly accessible sources (e.g., LinkedIn).
    • Directly from a third party (e.g., background screening providers).
    • From a third party with your consent (e.g., your bank).
    • From cookies on our website; and
    • Via our IT systems, including:
      • Automated monitoring of our websites and other technical systems, such as our computer networks and connections, CCTV and access control systems, communications systems, email and instant messaging systems. Please refer to the People Handbook (including any applicable state supplement) and Acceptable Use Policy for additional information.
      • Through Data Loss Prevention tools 
  4. How and Why, We Use Your Personal Information. We only use your Personal Information if we have a proper reason for doing so, including (and as set forth below):

    • To comply with our legal and regulatory obligations;
    • To protect our legal rights;
    • For our legitimate interests or those of a third party;
    • In an emergency where health or security is at stake; or
    • Where you have given consent.

    A legitimate interest is when we have a business or commercial reason to use your information, so long as this is not overridden by your own rights and interests.

    To innovate and continuously improve, we employ AI tools, including Microsoft Copilot, to aid in a variety of tasks such as:

    • Streamlining administrative workflows and improving process efficiencies.
    • Facilitating informed decision-making.

    The Company's Responsible AI Policy governs our use of AI tools and requires all team members to use AI Systems responsibility and with written approval before inputting Personal Data, Company Confidential Information, and Customer Data. Company may take necessary steps to both enforce this Policy and to protect Company intellectual property (IP) in connection with AI Systems use.

    To the extent we use AI to process your personal information, we do so in accordance with relevant privacy laws and regulations. We refrain from using AI to make significant decisions impacting your employment without human oversight.

    The table below explains what we use your personal information for and our reasons for doing so:

    We have appropriate measures in place to protect your personal information and will never sell or share it with other organizations for marketing or cross context behavioral advertising purposes or any other behavioral marketing.

  5. Who We Share Your Personal Information With. We routinely share personal information with:

    • Our affiliates and subsidiaries;

    • Service providers we use to help deliver our products and services to you, such as benefit providers, information technology providers for shipping and receiving Company devices, cloud providers, data hosting and storage services, background check providers, warehouses and delivery companies;

    • Government authorities as required by law, such as tax and social security authorities;

    • With our clients when necessary to inform them who their point of contact is, or who may otherwise be working on their accounts.

    We only allow our service providers to access or use your personal information if they meet our data privacy and protection requirements. We impose contractual obligations on service providers to ensure they can only use your personal information to provide services to us and to you. We may also share personal information with external auditors, e.g., in relation to accreditation and audit activities.

    We may disclose and exchange information with law enforcement agencies and regulatory bodies to comply with our legal and regulatory obligations.

  6. Where Your Personal Information is Held. Information may be held at our offices, in Company systems and databases, third party agencies, service providers, representatives and agents as described above (see above: “Who We Share Your Personal Information with”).

  7. How Long Your Personal Information Will Be Kept. We will keep your personal information while you are employed with us. Thereafter, we will keep your personal information for as long as is necessary:

    • To respond to any questions, complaints or claims made by you or on your behalf; or,

    • To comply with record retention laws and requirements, and our policies.

    We will not retain your personal information for longer than necessary for the purposes set out in this notice. Different retention periods apply for different types of personal information. Further details on this are available in our Records Retention Policy.

    When it is no longer necessary to retain your personal information, we will delete or anonymize it.

  8. Your Rights Under State Privacy Laws. Where permitted or required by State Privacy Laws (such as the California Privacy Rights Act (CPRA)) you may be entitled to exercise any of the following privacy rights with respect to your personal information:

  9. Keeping Your Personal Information Secure. We have appropriate security measures in place to prevent personal information from being accidentally lost or used or accessed in an unauthorized way. We limit access to your personal information to those who have a genuine business need to access it. Those processing your information will do so only in an authorized manner and are subject to a duty of confidentiality. We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.

  10. Changes to This Privacy Notice. This privacy notice was published on 2/1/2022 and last updated on 4/24/2025.

    We may change this privacy notice from time to time - when we do, we will inform you via posting to the Company's intranet and systems or record.

  11. How to Contact the Privacy Office. Please contact the Privacy Office by email – privacy@healthequity.com if you have any questions about this privacy notice or the information the Company holds about you.

  12. Do You Need Extra Help? If you would like this notice in another format (for example: audio, large print, braille) please contact us (see “How to contact us” above).

COBRA/Direct Bill Employer login

Please refer to your Client Welcome email for the URL of your specific COBRA/Direct Bill Employer login page.