Effective August 1st, 2017
This policy applies to information we collect:
• On the website. • In email, text, and other electronic messages between you and the Site. • Through mobile and desktop applications you download from the Site, which provide dedicated non-browser-based interaction between you and the Site. • When you interact with our advertising and application on third party websites and services, if those applications or advertising include links to this Policy and/or Site.
Please read this Policy carefully to understand our policies and practices regarding your information and how we will treat it. BY ACCESSING OR BROWSING THE SITE, REGISTERING, OR USING THE SERVICES AVAILABLE AT THE SITE, YOU CONSENT TO THE COLLECTION AND USE OF YOUR INFORMATION AS DESCRIBED IN THIS POLICY, AS MODIFIED FROM TIME TO TIME BY US.
1. INFORMATION WE COLLECT ABOUT YOU AND HOW WE COLLECT IT.
In connection with accessing our Services, we may collect information which can be used to identify you (“Personal Information”), such as your name, credit card information, shipping/billing address, email address, phone, user name and password, service or order information, and history (including amounts ordered, spending habits, location-based information including, but not limited to, delivery of orders placed through the Website), and other information that permits us to contact you. We may also collect information that is about you, but individually does not identify you, or information about your internet connection, equipment you use to access our Site, and Site usage details. This information is collecting through the following methods:
• Directly from you when you provide it to us during registration on our site. • Automatically as you navigate through the site. Information collected automatically may include usage details, IP addresses, and information collected through cookies and other tracking technologies. • From third parties.
You also may provide information to be published or displayed (hereinafter, “posted”) on public areas of the Website, or transmitted to other users of the Website or third parties (collectively, “User Contributions”). Your User Contributions are posted on and transmitted to others at your own risk. We cannot control the actions of other users of the Website with whom you may choose to share your User Contributions. Therefore, we cannot and do not guarantee that your User Contributions will not be viewed by unauthorized persons.
2. HOW WE USE YOUR PERSONAL INFORMATION.
We use information that we collect about you or that you provide to us, including any Personal Information:
• To present our Site and its contents to you. • To personalize your experience (your information helps us to better respond to your individual needs). • To provide you with information, products, or services that you request from us • To improve our Site (we continually strive to improve our Site offerings based on the information and feedback we receive from you). • To improve customer service (your information helps us to more effectively respond to your customer service requests and support needs). • To process billing transactions and carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including billing and collection. • To provide you with notices about your account including updates on order processing, delivery and expiration of your account. • To send periodic emails. The email address provided for order processing may be used to send information and updates pertaining to occasional company news, updates, related product or service information. Note, that we include unsubscribe instructions at the bottom of each email. • To track and retain details of transactions and communications between users, such as emails, feedback, ratings, sale and purchase of products or services, and any other forms of communications. • To notify you about changes to our website or any products or services we offer or provide through it. • For any other purpose with your consent.
We may also use information that the Company receives from you or about your visit to the Site to contact you via e-mail or other means to occasionally send you information on products, services, special deals, and promotions about our own goods or services that may be of interest to you. Out of respect for your privacy, we provide you a way to unsubscribe from each of these communications. If you no longer wish to receive this information, you may opt-out by contacting us email@example.com.
We may use the information we have collected from you to enable us to display advertisements to our advertisers’ target audiences. We do not disclose your Personal Information for these purposes without your consent, however, if you interact with the advertisement, the advertiser may assume that you meet its target criteria.
3. HOW WE COMPLY WITH HIPPA AND PROTECT YOUR PHI.
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
Under a federal law called the Health Insurance Portability and Accountability Act (“HIPAA”), some of your Personal Information, such as demographic, health and/or health-related information that we collect as part of providing the Services, may be considered “protected health information” or “PHI.” Specifically, when we receive identifiable information about you, such as identifiable health information, including without limitation, information about your past, present, or future physical or mental health condition, the name and license number of your recommending physician, contact information of that physician, the method to verify the recommendations authenticity, the expiration date of the recommendation, and the details of orders placed through the website is considered PHI. Further, a healthcare provider’s medical data is considered PHI and includes information provided by doctors or other healthcare specialists, professionals, or providers (collectively, “Healthcare Providers”) you have visited, the reasons for your visit, the dates of your visit, your medical history, and other medical and health information you choose to share with us.
HIPAA provides specific protections for the privacy and security of PHI and restricts how PHI is used and disclosed. We may only use and disclose your PHI in the ways permitted by you and your Healthcare Providers and such permission may be revoked at any time.
The following describes the circumstances in which we may use or disclose your PHI:
• Treatment, Payment and Healthcare Operations. We are permitted to use and disclose your PHI for purposes of treatment, payment and healthcare operations. For example: • Treatment. We may disclose your PHI to another physician or healthcare provider for purposes of a visit or in connection with the provision of follow-up treatment. • Payment. We may use and disclose your PHI to our delivery agents to collect payment upon delivery. In the event that medicinal cannabis becomes a medication covered by your health insurer or health plan, we may one day use and disclose your PHI in connection with the processing and payment of claims and other charges. • Healthcare Operations. We may use and disclose your PHI in connection with our healthcare operations, such as providing customer services, storing your purchase and delivery history, and conducting quality review assessments. We may engage third parties to provide various services for us. If any such third party must have access to your PHI in order to perform its services, we will require the third party enter into an agreement that binds the third party to the use and disclosure restrictions outlined in this Policy. • Authorization. We are permitted to use and disclose your PHI upon your written authorization, to the extent such use or disclosure is consistent with your authorization. You may revoke any such authorization at any time. • As Required by Law. We may use and disclose your PHI to the extent required by law. • Verification. We may use your medical cannabis identification number entered on our Site or provided in our dispensary locations, and stored on our servers, to perform patient pre-verification checks, identification check, quantity and other eligibility-related verification, or collection, recordation, and/or transmission of information for recordkeeping and/or entry into the medical marijuana electronic verification system; • Dispatch. If you elect to use our delivery service, our licensed dispensary agents will, upon delivery, require and verify your medicinal cannabis identification number for all cannabis products ordered via the Site. • Research and Marketing. We may under certain circumstances, use or disclose PHI that is necessary for research or marketing purposes. Such disclosure will deidentify you from your PHI.
You have the following rights regarding the PHI maintained by us:
• Confidential Communication. You have the right to receive confidential communications of your PHI. You may request that we communicate with you through alternate means or at an alternate location, and we will accommodate your reasonable requests. You must submit your request in writing. • Restrictions. You have the right to request restrictions on certain uses and disclosures of PHI for treatment, payment, or healthcare operations. You also have the right to request that we restrict its disclosures of PHI to only certain individuals involved in your care or the payment of your care. You must submit your request in writing. We are not required to comply with your request. • Inspection and Copies. You have the right to obtain a paper copy of this Policy from us at any time upon request. We may charge a fee for the costs of copying, mailing, or other supplies associated with your request. To obtain a paper copy of this notice, please contact the Company by calling (480) 219-1400. We may deny your request to inspect and/or copy your PHI in certain limited circumstances. If that occurs, we will inform you of the reason for the denial, and you may request a review of the denial. • Amendment. If you feel that medical information we have about you is incorrect or incomplete, you may ask us to amend the information. You must provide a reason that supports your request. We may deny your request if: (i) it is not in writing or does not include a reason to support your request; (ii) information is not part of the medical information stored by us; (iii) the information was not created by us; (iv) information is not part of the information you are permitted to inspect and copy; or (v) the information is complete and accurate. • Breach Notification. You have the right to be notified in the event that the Company (or one of our business associate) discovers a breach of unsecured PHI. • Accounting of Disclosures. You have a right to receive an accounting of all disclosures we have made of your PHI. However, that right does not include disclosures made for treatment, payment or healthcare operations, disclosures made to you about your treatment, disclosures made pursuant to an authorization, and certain other disclosures. You must submit your request in writing and you must specify the time period involved (which must be for a period of time less than six years from the date of the disclosure). Your first accounting will be free of charge. However, we may charge you for the costs involved in fulfilling any additional request made within a period of 12 months. • Complaints. If you believe your privacy rights have been violated, you may file a complaint with the us by email to firstname.lastname@example.org or with the Secretary of the Department of Health and Human Services.
4. HOW WE USE AUTOMATIC DATA COLLECTION TECHNOLOGIES TO COLLECT YOUR INFORMATION AND YOUR CHOICES ABOUT ITS USE.
We strive to provide you with choices regarding the Personal Information you provide to us. As you navigate through and interact with our Site, we may use automatic data collection technologies to collect information about your equipment, browsing actions, and patterns, including:
• Details of your visit to our Site, including traffic data, location data, and other communication data and the resources that you access and use on the Site. • Information about your computer and internet connection, including your IP address, operating system, and browser type.
We collect information from or about the computers and devices that you use to access the Site, as determined and allowed by the personal settings you have for the computer and device. We collect the Internet Protocol (IP) address, domain name, browser type, operating system, device settings, location, web log files, and other code tracking devices from any device you use to access our Site and any pages at our Site.
You can turn-off or adjust your browser settings on your computers and devices that will alert you when cookies are being sent. You may elect to unsubscribe from Company offers and advertising by unsubscribing from the link at the bottom of all email correspondence or send us an email at email@example.com.
5. HOW WE DISCLOSE YOUR INFORMATION.
We do not sell, trade, or otherwise transfer to outside parties your Personal Information; however, we may disclose de-identified, aggregate information about our users, and information that does not identify any individual, without restriction for marketing, advertising, or other uses.
All leads generated by our customers and data stored for our customers are held and protected in strict confidence. We do not contact customer leads, nor do we sell to or share customers’ lead information with any other party.
6. HOW WE PROTECT YOUR INFORMATION.
We have implemented measures designed to secure your Personal Information from accidental loss and from unauthorized access, use, alteration, and disclosure. We follow generally accepted industry standards to protect Personal Information, including your email address, submitted to us, both during transmission and once we receive it. However, no method of transmission over the Internet, or method of electronic storage is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your Personal Information, we cannot guarantee its absolute security.
The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Site, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your Personal Information, we cannot guarantee the security of your Personal Information transmitted to our Site. Any transmission of Personal Information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Site.
7. HOW YOU CAN ACCESS AND CORRECT YOUR INFORMATION.
You can review, access, update, change, and correct information that identifies you by logging into the Site and visiting your account profile page. You may also send us an email at firstname.lastname@example.org to request access to, correct, or delete any Personal Information that you have provided to us. We cannot delete your Personal Information except by also deleting your user account. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect.
8. NOTICE TO RESIDENTS OF COUNTRIES OUTSIDE THE UNITED STATES OF AMERICA
The Company is headquartered in the United States of America. Personal Information may be accessed by us or transferred to us in the United States or to our affiliates, business partners, or service providers elsewhere in the world. By providing us with Personal Information, you consent to this transfer. We will protect the privacy and security of Personal Information according to this Policy, regardless of where it is processed or stored.
9. COLLECTION AND USE OF CHILDREN’S INFORMATION.
We do not knowingly collect information from minors. Our Site is intended for and directed towards adults. Our Services are not directed to minors and we do not knowingly collect Personal Information from minors.
10. CHANGES IN THIS PRIVACY STATEMENT
From time to time we may change or update our Privacy Statements. We reserve the right to make changes, updates, or modify this Policy at any time, without notices to you. If we decide to change our Policy, we will post a new policy on our Site and change the date at the top of the Policy. Any change, update or modification will be effective immediately upon posting on our Site and will apply to any Personal Information provided to us on and after that date. Therefore, we encourage you to check the date of our Policy whenever you visit the Site for any updates or changes.
If we make a material change to our Policy that affects how we collect or use your Personal Information, we will notify you via the email provided by you when creating your account.