Data Controller and Contact Information

OnlinePharmacyMD.com: Your Comprehensive Guide to Medications and Supplements ("OnlinePharmacyMD.com", "we", "us", or "our") is the data controller for personal data processed in connection with this website.

Owner: Harrison Thurston

Postal Address: 1703 Orrington Ave, Evanston, IL 60201, United States

Email: [email protected]

This Notice applies to the processing of personal data when you access or use our website and related services.

Scope and Relationship to United States Law

We operate from the United States and process personal data in alignment with the European Union General Data Protection Regulation (GDPR) where it applies to individuals in the European Economic Area and the United Kingdom, while ensuring consistency with applicable United States federal and state privacy laws (including, as applicable, the California Consumer Privacy Act as amended by the CPRA and similar state laws). This Notice is intended to be read together with any other disclosures we provide at the point of data collection.

Categories of Personal Data We Process

  • Identification and Contact Data: name, email address, postal address, and any information you include in inquiries.
  • Technical and Usage Data: IP address, unique device identifiers, browser type, operating system, referring URLs, pages viewed, time and date of visits, and clickstream data.
  • Cookies and Similar Technologies Data: cookie identifiers, preferences, and consent signals.
  • Communications Data: content of messages you send to us and metadata associated with such communications.
  • Preference and Feedback Data: survey responses, content preferences, and settings.
  • Health-Related Data (Special Category): only if you voluntarily provide it in free-text fields (e.g., conditions or medications of interest). We do not require such information to use the site.

Sources of Personal Data

  • Direct Collection: information you provide directly through forms, inquiries, or email.
  • Automated Collection: information collected via cookies, pixels, and similar technologies when you interact with our website.
  • Third Parties: service providers (e.g., analytics providers), and publicly available sources, where permitted by law.

Purposes of Processing and Legal Bases

Purposes

  • Provide and maintain the website, including troubleshooting, analytics, and performance monitoring.
  • Respond to inquiries, provide user support, and manage communications.
  • Improve content relevance, develop new features, and enhance user experience.
  • Conduct analytics, metrics, and audience measurement.
  • Comply with legal obligations and enforce our terms.
  • Protect our operations, users, and the public against fraud, misuse, or security threats.
  • With consent, deliver newsletters or similar communications.

GDPR Legal Bases

  • Consent: for non-essential cookies, newsletters, and processing of special category data you voluntarily provide.
  • Legitimate Interests: to operate, secure, and improve the website; to perform analytics and measure engagement; to prevent fraud and ensure network security. We balance these interests against your rights and freedoms.
  • Contract: to take steps at your request prior to entering into a contract or to perform a contract (e.g., responding to requests you initiate).
  • Legal Obligation: to comply with applicable laws, regulatory requirements, and lawful requests.
  • Vital Interests/Public Interest: only where necessary to protect life or for substantial public interest, as applicable.

Cookies and Similar Technologies

We use cookies and similar technologies to enable core site functionality, measure site performance, understand audience engagement, and, where applicable, support limited advertising or cross-context analytics. Non-essential cookies are used based on your consent. You may manage cookie preferences through your browser settings and, where available on our site, via cookie preference tools. Disabling certain cookies may affect site functionality.

Special Category and Health-Related Information

We do not require health-related information to access our site. If you voluntarily provide health-related details, we process such data only with your explicit consent and for the limited purpose of responding to your inquiry or providing requested information. We apply enhanced safeguards, including access restrictions and data minimization. We are not a covered entity or business associate under HIPAA, and our processing is governed by privacy laws described in this Notice.

Disclosure of Personal Data

  • Service Providers: hosting, security, analytics, customer support, and email service vendors, bound by contractual confidentiality and data protection obligations.
  • Analytics and Measurement Partners: to understand site performance and improve content; where required, we obtain your consent.
  • Legal and Safety: to comply with law, regulatory requests, or protect rights, property, users, or the public.
  • Business Transfers: in connection with a merger, acquisition, restructuring, or asset transfer, subject to appropriate safeguards.
  • Aggregated/De-identified Data: we may share aggregated or de-identified insights that do not identify individuals.

We do not sell personal information for money. Some disclosures for analytics or cross-context behavioral advertising may constitute “sharing” under certain US state privacy laws; you may opt out as described below.

International Data Transfers

We process data primarily in the United States. Where GDPR applies and personal data is transferred from the EEA/UK to the United States or other jurisdictions lacking an adequacy decision, we implement appropriate safeguards, such as Standard Contractual Clauses and supplementary measures, and assess risks associated with such transfers. You may contact us for more information about transfer safeguards.

Retention of Personal Data

We retain personal data only for as long as necessary to fulfill the purposes described in this Notice, including to meet legal, accounting, or reporting requirements, resolve disputes, and enforce agreements. Retention periods vary by data category and purpose, and we apply criteria such as the nature of the data, sensitivity, potential risk from unauthorized use, and applicable legal requirements.

Security Measures

We maintain organizational, technical, and administrative measures designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. While no system can be guaranteed 100% secure, we regularly review and enhance our safeguards, limit access on a need-to-know basis, and require service providers to implement appropriate security controls.

Your Rights Under the GDPR

Subject to conditions and exceptions under the GDPR, you may have the following rights:

  • Access: obtain confirmation of processing and a copy of your personal data.
  • Rectification: correct inaccurate or incomplete personal data.
  • Erasure: request deletion of personal data where grounds apply.
  • Restriction: limit processing in certain circumstances.
  • Portability: receive personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Objection: object to processing based on legitimate interests or for direct marketing.
  • Withdraw Consent: withdraw consent at any time without affecting the lawfulness of prior processing.
  • Complaint: lodge a complaint with a competent supervisory authority.

To exercise rights, contact us using the details in the Contact section below.

California and Other US State Privacy Rights

If you are a resident of California or another state with a comprehensive privacy law (e.g., Colorado, Connecticut, Virginia, Utah), you may have the following rights, subject to legal exceptions:

  • Right to Know/Access: request information about categories and specific pieces of personal information we collected, used, disclosed, and, if applicable, shared.
  • Right to Delete: request deletion of personal information.
  • Right to Correct: request correction of inaccurate personal information.
  • Right to Opt Out of Sale/Sharing/Targeted Advertising: opt out of certain disclosures that constitute a “sale,” “sharing,” or “targeted advertising.”
  • Right to Limit Use of Sensitive Personal Information: where applicable, limit use to permitted purposes.
  • Non-Discrimination: we will not discriminate against you for exercising your rights.

You may exercise these rights by contacting us. We will verify your request and, where permitted, accept authorized agent submissions. We endeavor to honor browser-based opt-out signals, such as recognized global privacy controls, to the extent required by law.

Children’s Data

Our services are not directed to children under 16, and we do not knowingly collect personal data from children under 13. If you believe a child has provided personal data, please contact us so we can take appropriate steps.

Automated Decision-Making and Profiling

We do not engage in automated decision-making that produces legal or similarly significant effects on individuals. We may use limited profiling for analytics to understand site usage; such processing is conducted under a lawful basis and with appropriate safeguards.

Exercising Your Rights and Verification

To submit a request, contact us using the email or postal address below. We may request information sufficient to verify your identity and authority, including email verification or additional data reasonably related to your request. We will respond within the timeframes required by applicable law.

Records of Processing and Accountability

We maintain records of processing activities where required, apply data protection by design and by default, and conduct risk assessments, including transfer impact assessments and, when applicable, data protection impact assessments.

Changes to This Notice

We may update this Notice from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. Material changes will be indicated by an updated effective date. Your continued use of our services after an update constitutes acknowledgment of the revised Notice.

Contact

Data Controller: OnlinePharmacyMD.com

Owner: Harrison Thurston

Postal Address: 1703 Orrington Ave, Evanston, IL 60201, United States

Email: [email protected]

Effective Date: 2025-08-22