Privacy Policy

Effective Date: January 22, 2020

We respect the privacy of visitors to our websites. This Privacy Policy is intended to inform you of our policies and practices regarding the collection, use and disclosure of any personal information you submit to Rigel Pharmaceuticals, Inc. (“Rigel”) through our websites located at,, and any other websites controlled by Rigel that post or link to this Privacy Policy (collectively, “Site”). “Personal Information” is information about you that is personally identifiable like your name, address, email address, or phone number, and other information that is not otherwise publicly available. This Privacy Policy does not apply to websites we may host that post different policies.

A Note to Users Outside of the United States
Rigel complies with the EU-U.S. and the Swiss-U.S. Privacy Shield Frameworks, as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union or Switzerland to the United States. Rigel intends that all transfers of personal data comply with all applicable international laws and regulations, including the 2016/679 General Data Protection Regulation (“GDPR”). Rigel has certified to the Department of Commerce that it adheres to the Privacy Shield Principles. If there is any conflict between the terms in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification, please visit

Rigel intends that all transfers of personal data comply with all applicable international laws and regulations, including the GDPR.

When transferring personal data out of the European Economic Area (EEA), adequate safeguards will be used, such as including standard contractual clauses issued by the European Commission in contracts with third parties. Specifically, for example, for transfers of personal data from Switzerland and the EU to the US, Rigel follows and complies with the EU-US Privacy Shield and the Swiss-U.S. Privacy Shield Principles published by the U.S. Department of Commerce. Rigel certifies that it adheres to the Privacy Principles of notice, choice, onward transfer, security, data integrity, access and enforcement. To learn more about the Privacy Shield please visit Transfers of personal data outside of the European Union, other than to the U.S. shall be made in accordance with the data protection principals prescribed by the international law and regulations applicable in the relevant countries. In cases of onward transfer to third parties of Personal Data received pursuant to the EU-U.S. Privacy Shield and the Swiss-U.S. Privacy Shield, Rigel is potentially liable. Rigel shall remain liable under the Principles if its agent processes such personal information in a manner inconsistent with the Principles, unless Rigel proves that it is not responsible for the event giving rise to the damage.

The Federal Trade Commission has jurisdiction over Rigel’s compliance with the Privacy Shield.

In compliance with the US-EU and Swiss-US Privacy Shield Principles, Rigel commits to resolve complaints about our collection or use of your personal information. European Union or Swiss individuals with inquiries or complaints regarding our Private Shield policy should first contact Rigel at: Rigel has selected a third party to serve as its independent recourse mechanism (IRM) for dispute resolution arising from certain transfers or processing of Personal Information (non-HR data) under Privacy Shield. Rigel has further committed to refer unresolved Privacy Shield complaints under the EU-US and Swiss-US Privacy Shield Principles to Judicial Arbitration and Mediation Services, Inc. (JAMS), an alternative dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please contact or visit JAMS at: for more information or to file a complaint. The services of JAMS are provided at no cost to you. Under certain conditions, more fully described on the Privacy Shield website, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.

Your Personal Information may be collected, used, disclosed and otherwise processed for the purposes identified in this Privacy Policy. In addition, your Personal Information may be maintained and processed by Rigel and our third-party service providers and Affiliates (as defined below) in the country in which it was collected and in other countries, including the United States, where laws regarding the processing of Personal Information may be less protective than the laws in your country. Personal Information processed in another jurisdiction may be accessible by the courts, law enforcement and national security authorities of such jurisdiction. We will obtain consent from all customers, employees, healthcare professionals, medical research subjects, clinical investigators, customers, business partners, contractors, subcontractors, consultants and investors, where required, for processing, use and/or distribution of any personal and/or special categories of personal data prior to the processing, use or distribution of such data.

User Consent (where permitted by law)
By submitting Personal Information through our Site, you agree to the terms of this Privacy Policy.

Collection of Personal Information
For subscribers to our investor information mailing list, we collect your e-mail address and any Personal Information you enter into the form.

For visitors who sign up to receive information about a specific product, (i) if you are a health care provider, we collect your first and last name, postal address, e-mail address, and you may also elect to provide your specialty type, practice type, and other medical profession information or (ii) if you are a patient or care partner, we collect your e-mail address and information related to your medical condition, and you may also elect to provide your year of diagnosis and whether you are currently receiving treatment for the medical condition.

For visitors who subscribe to our mailing list to be notified when our products are available for purchase, we collect your e-mail address.

For visitors who email us directly via an e-mail hyperlink, we collect your e-mail address and any Personal Information that may be included with the e-mail.

For health care providers who request access to any of our prescription access programs, such as our Expanded Access Program or Patient Assistance Program, we collect your username, first and last name, e-mail address, and for certain programs may also collect password as well as your clinical investigator’s name, address, e-mail address, and phone number. We also collect patient identifiable information that you provide through submission of enrollment forms for our prescription access programs. We may also collect Anonymous Data about the patient for which you are interested in obtaining our product. “Anonymous Data” means data, either individual or in the aggregate, that does not permit the identification of individual persons and that is not associated with or linked to Personal Information.

For all visitors: As you navigate our Site, certain passive information will also be collected, including but not limited to:

  • The date, time, and duration of your visit to the Site and the Site’s pages and links you click on while navigating within our Site;
  • Information about your interactions with any content appearing on our Site, such as the type of content accessed via our Site;
  • Information about your interactions with our email messages, such as the links you click on and whether you open or forward a message, the date and time of these interactions and the device you use to read emails;
  • The site you visited before and after visiting our Site;
  • Your Internet Protocol (IP) address (a numerical address assigned to your computer or device by your Internet service provider so that other computers or devices connected to the Internet can communicate with your computer or device online) that can sometimes be used to derive your general geographic area;
  • Search terms you enter on our Site or on a referral site;
  • Information about your device such as your device type and model, screen size, browser type, language and other settings, memory capacity, operating system, Wi-Fi information, and time zone;
  • If you are using a mobile device to access the Site, unique identifiers such as non-global mobile device identification numbers, radio type (e.g. LTE, 3G, etc.), and carrier code; and
  • Information collected through cookies, pixel tags and other tracking technologies (see additional descriptions of these terms below).

For employment applicants: Our job application links to a third-party website hosted by ADP, LLC (“ADP”). Any Personal Information you provide to ADP through the job application will be collected and processed by ADP in accordance with ADP’s Privacy Policy available at We will receive Personal Information that you provide on your job application from ADP in order to assess your qualification for the position to which you are applying. We are an equal opportunity employer and make employment decisions solely on the basis of merit and business needs. Accordingly, with respect to hiring or any other employment decisions, we do not unlawfully discriminate against any person on any basis protected under federal, state, or local laws, including, but not limited to, race, ethnic or national origin, sex, gender, actual or perceived sexual orientation, physical or mental condition, disability, arrest record, conviction record, political beliefs, or membership in a trade union or political party. To the extent that you voluntarily provide us with Personal Information outside of the requirements of the job application, you acknowledge that we will not use such information in making employment decisions. Nevertheless, you expressly authorize us to handle such details in accordance with this policy. If you provide information of a prior supervisor, reference, or other third party, it is your responsibility to obtain such third party’s consent to provide this information to us. You are responsible for the information that you provide or make available and you must ensure that it is legal, honest, truthful, accurate, and not misleading in any way. You must ensure that any information provided does not contain any material that is obscene, defamatory, or infringing on any rights of any third party, or otherwise legally actionable by such third party.

Regarding clinical trial investigators and other parties, Rigel will provide specific Privacy Notices as required upon the first collection of personal data or no later than 30 days from the collection of such data. Clinical trial participants will be provided with relevant privacy information in the Informed Consent Form and clinical trial enrollment process.

We may also log information using small data files stored on your hard drive when you visit our Site (“Cookies”). We may use both session Cookies (which expire once you close your web browser) and persistent Cookies (which stay on your computer until you delete them) to provide you with a more personal and interactive experience on our Site. This type of information is collected to make the Site more useful to you and to tailor the experience with us to meet your special interests and needs.

Flash Cookies
When we post videos, third parties may use local shared objects, known as “Flash Cookies,” to store your preferences for volume control or to personalize certain video features. Flash Cookies are different from browser Cookies because of the amount and type of data and how the data is stored. Cookie management tools provided by your browser will not remove Flash Cookies. To learn how to manage privacy and storage settings for Flash Cookies, go to:

Do Not Track
We do not currently respond to “do not track” signals from web browsers.

Pixel Tags
We and our service providers may also use “Pixel Tags” (sometimes referred to as clear gifs, web beacons, or web bugs). Pixel Tags are tiny graphic images with a unique identifier, similar in function to Cookies, that are used to track online movements of web users. In contrast to Cookies, which are stored on a user’s computer hard drive, Pixel Tags are embedded invisibly in web pages. Pixel Tags also allow us to send e-mail messages in a format that users can read, and they tell us whether e-mails have been opened to help us ensure that we are sending messages that are of interest to our users. We may use this information to, among other things, reduce the frequency of or eliminate messages sent to a user.

Analytics Services
We use technology provided by third-party analytics services (“Analytics Services”) to help analyze how users use our Site. The information generated by Cookies or other technologies that monitor your use of our Site (“Analytics Information”) is collected by such Analytics Services (e.g., Google Analytics, Bing Webmaster Tools, etc.) so that they can compile reports on user activity. The Analytics Services may also transfer the Analytics Information to third parties where required to do so by law, or where such third parties process Analytics Information on their behalf. Each Analytics Service’s ability to use and share Analytics Information is restricted by such Analytics Service’s terms of use and privacy policy. By using our Site, you consent to the processing of data about you by Analytics Services in the manner and for the purposes set out above. For a list of our Analytics Services, please contact us at

Use of Personal Information
In general, Personal Information you submit to us is used to respond to requests that you make, aid us in serving you better, or improve our Site, products, and services. Depending on your intended use of this Site, we may use your Personal Information for a variety of purposes, including:

  • To facilitate the creation of and secure your account on our network;
  • To send you a welcome e-mail to verify ownership of the e-mail address provided when your account was created;
  • To identify you as a user in our system;
  • To provide improved administration of our Site;
  • To provide you with content that may be of interest to you;
  • To provide the services you request;
  • To respond to your e-mail inquiries and other requests, including providing you with notification regarding the availability our products for purchase;
  • To measure and analyze audience traffic and improve the quality of your experience with our Site, products, and services;
  • To determine your patient’s eligibility in participating in our prescription access programs, as applicable;
  • To send investor information, new product availability information, administrative e-mail notifications (e.g. security or support and maintenance advisories);
  • To understand how you use our Site;
  • To detect and prevent fraud and other potentially prohibited or illegal activities and comply with applicable law, our Privacy Policy, and the terms of any applicable agreements; and
  • For any other purposes disclosed to you at the time of collection or pursuant to your consent.

If you are an employment applicant, we may use your Personal Information to process and respond to your job application, including to assess your skills, interests, and qualifications for job opportunities, conduct reference checks, verify the information provided, and for compliance with corporate governance and legal and regulatory requirements. However, we will only use your Personal Information to make employment decisions to the extent permitted under federal, state, or local equal employment opportunity laws. Personal Information that you submit may also be added to our candidate database for future consideration when job vacancies arise. If you are hired, we may also use the information collected during the application process for other business purposes relating to your employment.

We may create Anonymous Data records from Personal Information by excluding information (such as your name) that makes the data personally identifiable to you. We reserve the right to use Anonymous Data for any purpose and disclose Anonymous Data to any third parties in our sole discretion.

Retention of Personal Information
The purposes, methods, storage limitation and retention period of personal data are consistent with the information contained above, and/or in the relevant Privacy Notice. We retain personal data and maintain the accuracy, integrity, confidentiality and relevance of personal data based on the processing purpose. Adequate security mechanisms designed to protect personal data are used to prevent personal data from being stolen, misused, or abused and prevent personal data breaches.

Sharing of Personal Information
We may share Personal Information in any manner for which you provide consent. We may share your Personal Information with third-party service providers that we employ to provide services on our behalf, such as to: provide you with services that you request; conduct quality assurance testing; facilitate creation of accounts; or provide technical support.

Although we currently do not have a parent company, any active subsidiaries, joint ventures, or other companies under a common control (collectively, “Affiliates”), we may in the future. We may share some or all of your Personal Information with these Affiliates, in which case we will require our Affiliates to honor this Privacy Policy.

We may share some or all of your Personal Information in connection with or during negotiation of any contemplated or actual merger, financing, acquisition or dissolution transaction or proceeding involving sale, transfer, divestiture, or disclosure of all or a portion of our business or assets. In the event of an insolvency, bankruptcy, or receivership, Personal Information may also be transferred as a business asset.

If another company acquires our company, business, or assets, that company will possess the Personal Data collected by us.

Regardless of any choices you make regarding your Personal Information (as described below), we may disclose Personal Information if we believe in good faith that such disclosure is necessary (a) in connection with any legal investigation or proceeding; (b) to comply with relevant laws or to respond to subpoenas or warrants served on Rigel; (c) to protect or defend the rights or property of Rigel, its Affiliates, their agents, customers, or others; and/or (d) to investigate or assist in preventing any violation or potential violation of the law, this Privacy Policy, or the terms of any applicable agreements.

Rigel reserves the right to share individuals’ personal information as required by law or duly authorized information request of governmental authorities.

Regarding Children
Our Site is not designed for children under the age of 13. We will not deliberately gather Personal Information about visitors in this age group, and do not collect any information on this Site with respect to age. If we discover that a child under 13 has submitted Personal Information to us, we will attempt to delete the information as soon as possible. If you believe that we might have any Personal Information from a child under 13, please contact us at

Links to Other Sites
Our provision of a link to any other website or location is for your convenience and does not signify our endorsement of such other website or location or its contents. We have no control over, do not review, and cannot be responsible for, these third-party websites or their content. Please be aware that the terms of our Privacy Policy do not apply to these third-party websites. We encourage you to review the policies of these third-party websites.

Your Choices Regarding Information
In every email we send, we provide instructions regarding how to opt-out of receiving future mailings. You may also contact us at the address provided on any email you receive to request removal from our mailing list. Despite your indicated e-mail preferences, we may continue to send you account or service-related communications, including notices of any updates to our Privacy Policy and the terms of any applicable agreements. You can typically remove and reject cookies from our Site with your browser settings. Many browsers are set to accept cookies until you change your settings. If you remove or reject our cookies, it could affect how our Site works for you.

You may opt-out of tracking by Google Analytics by visiting You may request to access or correct any other Personal Information collected by Rigel by contacting

Individuals may have the right to limit the use and disclosure of their personal information as required by the Privacy Shield’s Principles, such as whether your personal information is disclosed to a third party or used for purposes materially different from the purpose for which the personal information was originally collected or subsequently authorized by you. If you wish to limit the use and disclosure of personal information in accordance with the Privacy Shield Principles, please contact us at

Access to Your Data
When acting as a data controller, Rigel provides you with a mechanism to enable you to access your personal data and allows you to update, rectify, erase, or transmit your personal data, if appropriate or required by law.

Data Portability
You have the right to receive, upon request, a copy of the data you provided to Rigel in a structured format and to transmit those data to another controller, for free. Rigel´s Data Protection Officer is responsible to ensure that such requests are processed within one month, are not excessive and do not affect the rights to personal data of other individuals.

Right to be Forgotten
Upon request, you have the right to obtain from Rigel the erasure of your personal data, if applicable. When Rigel is acting as a controller, Rigel will take necessary actions to inform the third-parties who use or process that data to comply with the request.

Data Security
We use industry-standard methods to secure the communication of Personal Information from your computer to our servers. In addition, we use industry-standard methods of securing our databases of Personal Information, including the use of firewalls. Except as provided elsewhere in this Privacy Policy, we limit access to Personal Information databases to those persons in our organization who have a business need for such access. However, you should know that no company, including Rigel, can fully eliminate security risks associated with Personal Information.

Contact Us
Should you have any questions or concerns regarding this Privacy Policy, please contact us:

Rigel Pharmaceuticals, Inc.
1180 Veterans Boulevard
South San Francisco, CA 94080

Privacy Policy Updates
This Privacy Policy is subject to occasional revision, and any changes will be posted on this Site. If you object to any such changes, you must cease using our Site. Continued use of our Site following notice of any such changes shall indicate your acknowledgement of such changes and agreement to be bound by the terms and conditions of such changes.