Effective Date: August 7, 2020
- The Information We Collect and the Sources of Such Information
- Purposes for How We Use Your Information
- Online Analytics and Advertising
- How We Share and Disclose Your Information
- Your Marketing Choices
- Third Party Services and Notice About Health Information
- How We Protect Your Information
- Privacy Information for California Residents
- Privacy Information for Nevada Residents
- Retention of Your Information
- Contacting Us
THE INFORMATION WE COLLECT AND THE SOURCES OF SUCH INFORMATION
We obtain information about you through the means discussed below when you use the Services. Please note that we need certain types of information so that we can provide the Services to you. If you do not provide us with such information, or ask us to delete it, you may no longer be able to access or use part or all of our Services.
- Information You Provide To Us
We collect a variety of information that you provide directly to us. For example, we collect information from you through:
- Account and product registration and administration of your account
- Processing your orders and requests for treatment
- Questions, communications, or feedback you submit to us via forms or email
- Your participation in research and surveys
- Requests for customer support and technical assistance, including through online chat functionalities
- Uploads or posts to the Services
- Employment applications you submit
The specific types of information we collect will depend upon the Services you use, how you use them, and the information you choose to provide. The types of data we collect directly from you includes:
- Name, address, telephone number, date of birth, and email address
- Information about your medical conditions, treatment options, physician referrals, prescriptions, and lab results or other related health information, such as your physical and emotional characteristics
- Log-in credentials, if you create an account
- Billing information, such as shipping address, credit or debit card number, verification number, expiration date, and identity verification information, collected by our payment processors on our behalf
- Information about purchases or other transactions with us
- Information about your customer service and maintenance interactions with us
- Demographic information such as your gender and age
- User-generated content you post in public online forums on our Services
- Any other information you choose to directly provide to us in connection with your use of the
2. Information We Collect Through Automated Means
We collect certain information about your use of the Services and the devices you use to access the Services, asdescribed in this Section. As discussed further below, we and our service providers (which are third party companies that work on our behalf), may use a variety of technologies, including cookies and similar tools, to assist in collecting thisinformation.
Our Websites. When you use our Websites, we collect and analyze information such as your IP address, browser types, browser language, operating system, the state or country from which you
accessed the Services, software and hardware attributes (including device IDs) referring and exit pages and URLs,platform type, the number of clicks, files you download, domain names, landing pages, pages viewed and the order of those pages, the amount of time spent on particular pages, the terms you use in searches on our sites, the date and time you used the Services, error logs, and other similar information.
Location Information. When you use the Services, we and our service providers may automatically collect general location information (e.g., IP address, city/state and or postal code associated with an IP address) from your computer or mobile device. This information allows us to enable access to content that varies based on a user’s general location(e.g., to provide you with accurate sales tax information and to deliver content customized to your location).
We will ask your permission before collecting your precise GPS location information. In such instances, we will use your precise geo-location information to provide customized services, content, promotional offers and other information that may be of interest to you. If you no longer wish for us and our service providers to collect and use GPSlocation information, you may disable the location features on your device. Please see your device manufacturersettings.
- A web server log is a file where website activity is
- An SDK is a set of tools and/or code that we embed in our Apps and software to allow third parties to collect information about how users interact with the Services.
- A cookie is a small text file that is placed on your computer or mobile device when you visit a site, that enables us to: (i) recognize your computer/device; (ii) store your preferences and settings; (iii) understand the parts of the Services you have visited and used; (iv), enhance your user experience by delivering and measuring the effectiveness of content and advertising tailored to your interests; (v) perform searches and analytics; and
- (vi) assist with security and administrative functions.
- Tracking pixels (sometimes referred to as web beacons or clear GIFs) are tiny electronic tags with a unique identifier embedded in websites, online ads and/or email that are designed to: (1) collect usage information like ad impressions or clicks and email open rates; (2) measure popularity of the Services and associated advertising; and (3) access user
As we adopt additional technologies, we may also gather information through other methods. Please note that you can change your settings to notify you when a cookie is being set or updated, or to block cookies altogether. Please consult the “Help” section of your browser for more information (e.g., Internet Explorer; Google Chrome; Mozilla Firefox; or Apple Safari). Please note that by blocking, disabling, or managing any or all cookies, you may not have access to certain features or offerings of the Services.
When you “like” or “follow” us on Facebook, Instagram, Twitter, or other social media sites, we may collect some information from you including your name, email address, and any comments or content you post relevant to us. We also collect your information if you sign up for one of our promotions or submit information to us through social media sites.
3. Information We Receive From Other Sources
We work closely with third parties (including, for example, third party intermediaries, such as the physicians, medical professionals, and pharmacies with whom we partner to provide you with the Services and their health care services, sub-contractors in technical, advertising networks, analytics providers, and search information providers). Such third parties will sometimes provide us with additional information about you.
PURPOSES FOR HOW WE USE YOUR INFORMATION
In connection with providing you with the Services, we may use your information for our business purposes to:
- Carry out, improve, and manage the Services and, as applicable, facilitate the provision of health care services to you by physicians or other health care providers and ensure that the physicians or health care providers have the services and support necessary for health care operations.
- Engage in internal research to understand the effectiveness of our Services, improve our Services, and better understand our user base. If we publish or provide the results of this research to others, such research will be presented in a de-identified and aggregate form such that individual users cannot be
- Communicate with you about the Services, your use of the Services, or your inquiries related to the Services and send you communications on behalf of physicians or other health care providers utilizing the Services to meet your
- Communicate with you by email, postal mail, or phone about surveys, promotions, special events or our products and Services and those of our subsidiaries, affiliates, and parent companies and any of their related businesses and those of our third-party
- Provide you with technical support and customer
- Verify your identity and administer your account, including processing your payments and fulfilling your
- Ensure that content from our Services is presented in the most effective manner for you and for your computer or device, allow you to participate in interactive features of our Services (when you choose to do so), and as part of our efforts to keep our Services safe and
- Measure or understand the effectiveness of advertising and content we serve to you and others, and to deliver and customize relevant advertising and content to
- Help us better understand your interests and needs, such as by engaging in analysis and research regarding use of the
- Comply in good faith with any procedures, laws, and regulations which apply to us where it is necessary for our legitimate interests or the legitimate interests of
- Establish, exercise, or defend our legal rights where it is necessary for our legitimate interests or the legitimate interests of
Aggregate/De-Identified Data. We may aggregate and/or de-identify any information collected through the Services so that such information can no longer be linked to you or your device (“Aggregate/De-Identified Information”). We may use Aggregate/De-Identified Information for any purpose, including for research and marketing purposes, and may also share such data with any third parties, including advertisers, promotional partners, and sponsors.
ONLINE ANALYTICS AND ADVERTISING
- Online Analytics
We may use third-party web analytics services (such as those of Google Analytics (including Google Signals, Google User-ID, and other Google Analytics features) and MixPanel) on our Services to collect and analyze usage information through cookies and similar tools; engage in auditing, research, or reporting; assist with fraud prevention; try to locate the same unique users across multiple browsers or devices to better tailor services and features; and provide certain features to you. If you have a Google account with personalized advertising enabled, through Google Signals, Google will also be able to gather for us analytics and engagement information from across the various devices you use toaccess the Services. To prevent Google from using your information for analytics (including cross-device tracking for personalization purposes), you may install the Google Analytics Opt-out Browser Add-on. And to opt out of Google Signals, please open your “Settings” app, locate and tap “Google,” select “Ads,” and turn ON “Opt out of Ads Personalization.” You may also be able to disable cross-device tracking through your Android or Apple device-basedsettings.
If you receive email from us, we may use certain analytics tools, such as clear GIFs to capture data such as when youopen our message or click on any links or banners our email contains. This data allows us to gauge the effectiveness of our communications and marketing campaigns.
2. Online Advertising
We sometimes provide our customer information (such as email addresses) to service providers, who may “match” this information in de-identified form to cookies (or mobile ad identifiers) and
other proprietary IDs, in order to provide you with more relevant ads when you visit other websites and mobileapplications.
Please note that if you exercise the opt out choices above, you will still see advertising when you use the Services, but it will not be tailored to you based on your online behavior over time.
3. Mobile Advertising
When using mobile applications from us or others, you may also receive tailored in-application advertisements. We may use third-party service providers to deliver advertisements on mobile applications or for mobile application analytics. Each operating system, iOS for Apple phones, Android for Android devices, and Windows for Microsoft devices provides its own instructions on how to prevent the delivery of tailored in-application advertisements. We do not control how the applicable platform operator allows you to control receiving personalized in-application advertisements; thus, you should contact the platform provider for further details on opting out of tailored in-application advertisements. You may review the support materials and/or the device settings for the respective operating systems to opt-out of tailored in-app advertisements.
4. Notice Concerning Do Not Track
Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. We are committed to providing you with meaningful choices about the information collected on our website for third party purposes, and that is why we provide the variety of opt-out mechanisms listed above. However, we do not currently recognize orrespond to browser-initiated DNT signals.
HOW WE SHARE AND DISCLOSE YOUR INFORMATION
We may share your information for our business purposes in the following ways:
- Affiliates and Subsidiaries. We may share information we collect within any GRx member or group (i.e., our subsidiaries and affiliates, including our ultimate holding company and its subsidiaries) to deliver products and services to you, ensure a consistent level of service across our products and services, and enhance our products, services, and your customer
- Health Care Providers and Services. We share your information with health care providers: (i) to schedule and fulfill appointments and provide health care services as part of the Services, (ii) to whom you send messages through our Services, and (iii) for other
treatment, payment or health care operations purposes, including pharmacy services, upon your request.
- Service Providers. We provide access to or share your information with select third parties who use the information to perform services on our They provide a variety of services to us, including billing, sales, marketing, advertising, analytics, research, customer service, shipping and fulfillment, data storage, IT and security, fraud prevention, payment processing, and auditing and legal services. These entities may also include health care organizations, pharmacies, and other third parties we use to support our business or in connection with the administration and support of the Services.
- Protection of GRx and Others. By using the Services, you acknowledge and agree that we may access, retain and disclose the information we collect and maintain about you if required to do so by law or in a good faith belief that such access, retention or disclosure is reasonably necessary to: (a) comply with legal process (e.g. a subpoena or courtorder);
- Business Transfers. As we continue to develop our business, we may buy, merge, or partner with other companies. In such transactions, (including in contemplation of such transactions) user information may be among the transferred assets. If a portion or all of our assets are sold or transferred to a third-party, customer information (including your email address) would likely be one of the transferred business assets. If such transfer is subject to additional mandatory restrictions under applicable laws, we will comply with such
- Public Forums. Certain features of our Services make it possible for you to share comments publicly with other users. Any information that you submit through such features is not confidential, and we may use it for any purpose (including in testimonials or other marketing materials). For example, if you submit a product review on one of our sites, we may display your review (along with the name provided, if any) on other GRx websites and on third-party websites. Any information you post openly in these ways will be available to the public at large and potentially accessible through third-party search engines. Accordingly, please take care when using these
- We may also disclose your information in other ways you direct us to and when we have your consent.
- Aggregate/De-Identified Information. We reserve the right to create Aggregate/De- Identified Data from the information we collect through the Services and our sharing of such Aggregate/De-Identified Data is in our
YOUR MARKETING CHOICES
THIRD PARTY SERVICES AND NOTICE ABOUT HEALTH INFORMATION
HOW WE PROTECT YOUR INFORMATION
GRx takes a variety of technical and organizational security measures to protect your information against accidental orunlawful destruction or accidental loss, alteration, unauthorized disclosure or access. However, no method of transmission over the Internet, and no means of electronic or physical storage, is absolutely secure. As such, you acknowledge and accept that we cannot guarantee the security of your information transmitted to, through, or on our Services or via the Internet and that any such transmission is at your own risk.
Where we have given you (or where you have chosen) a password that enables you to access the Services, you areresponsible for keeping this password confidential. We ask you not to share your password with anyone. The information you share in public areas may be viewed by any user of the Services.
How we use and share these categories of personal information. We use and share the categories of personal information we collect from and about you consistent with the various business purposes we discuss throughout this Policy. Please see the “Purposes for How We Use Your Information” and “How We Share and Disclose Your Information” sections of this Policy above for more information.
Please note that the CCPA sets forth certain obligations for businesses that “sell” personal information to third parties. We do not engage in such activity and have not engaged in such activity in the past twelve months.
RETENTION OF YOUR INFORMATION
We keep your information for no longer than necessary for the purposes for which it is processed. The length of time forwhich we retain information depends on the purposes for which we collected and use it and/or as required to comply with applicable laws.
4975 Royal Gulf Circle
Fort Myers, Florida 33966