Privacy Policy & Trust Center
Transparency is key to your health. Read how we secure your medical data with bank-grade encryption and strict compliance protocols.
Table of Contents
1. Introduction & Scope
GetMeds ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our prescription services. By accessing or using our Service, you verify that you have read, understood, and agree to be bound by these terms.
2. Collection of Personal Information
We collect personally identifiable information (PII) that you voluntarily provide to us when registering or placing an order. This includes specific data points required for logistics:
Identity Data
Full Name, Government ID (for age verification), and Date of Birth.
Logistics Data
Shipping Address, Billing Address, Email, and Phone Number.
3. Protected Health Information (PHI)
To facilitate pharmacy services, we collect Protected Health Information (PHI). This data is afforded extra protection under healthcare laws and includes:
- Prescription copies and medication history.
- Physician names and contact details.
- Medical intake forms detailing allergies and health conditions.
4. Automated Data Collection
When you access our servers, we automatically record data sent by your browser. This "Log Data" may include your computer's IP address, browser version, pages visited, and timestamps. We use this technical data to prevent fraud, detect bot activity, and optimize website load speeds.
5. How We Use Your Information
We use your data for specific business purposes:
- Fulfillment: To process transactions and ship prescription orders.
- Clinical Safety: Pharmacists review your data to check for drug interactions.
- Communication: Sending order confirmations, refill reminders, and safety alerts.
- Security: Verifying identity to prevent fraudulent prescription requests.
6. Payment Data Security
We take payment security seriously. We do not store full credit card numbers on our servers. All transactions are processed through Level 1 PCI-DSS compliant providers (Stripe/PayPal). We only retain a secure "token" to reference the transaction for refunds or recurring subscriptions.
7. Cookies & Tracking
We use cookies to enhance user experience. You can instruct your browser to refuse all cookies, though some site features (like the Shopping Cart) may stop working.
8. Sharing with Third Parties
We may share information with trusted third parties solely for operational needs:
- Logistics: USPS, DHL, and FedEx require your name and address to deliver packages.
- Clinical Partners: Licensed physicians and pharmacists who review your medical intake forms.
- Legal Compliance: We may disclose data if compelled by a subpoena, court order, or FDA audit.
9. HIPAA Compliance
Although we operate internationally, we voluntarily adhere to the strict standards of the Health Insurance Portability and Accountability Act (HIPAA). We utilize HIPAA-compliant servers, end-to-end encryption, and business associate agreements (BAAs) with all vendors handling patient data.
10. International Data Transfers
GetMeds operates globally. Your information may be transferred to secure processing centers in India, Canada, or the UK for fulfillment. By using our service, you consent to this transfer. We ensure all international centers adhere to GDPR or equivalent privacy standards.
11. Security Protocols
We implement military-grade security measures:
- SSL Encryption: All data in transit is encrypted via TLS 1.3.
- At-Rest Encryption: Sensitive databases are encrypted using AES-256 standards.
- Access Control: Strict role-based access restricts data visibility to essential employees only.
12. Data Retention Policy
We retain Personal Data only as long as necessary. Prescription records are maintained for a minimum of 5 years (or longer if required by state law) to comply with pharmacy regulations and potential audits.
13. Your Rights & Choices
You have the right to:
14. Children's Privacy
Our Service does not address anyone under the age of 18 ("Children"). We do not knowingly collect PII from children. Parents who believe their child has provided us with data should contact us immediately for deletion.
15. Contact & Updates
We may update this policy periodically. For questions regarding privacy, please contact our Data Protection Officer.