# Privacy Policy

Effective August 31, 2026

This policy explains how iPothecary, LLC collects, uses, discloses, and protects information through its public website, business inquiries, and services for healthcare practices.

## Scope

This policy applies to ipothecary.com, forms and business communications initiated through the website, and personal information iPothecary processes while providing product-lifecycle and practice-operations services.

It does not replace a healthcare practice's Notice of Privacy Practices, govern a third-party site reached through a link, or change a customer agreement or business associate agreement. Those documents control where they apply.

## Information we collect

### Information you provide

The contact form asks for your name, work email, role, reason for contacting us, and, if you choose, your organization, number of practice locations, and message. We also receive information you provide during later business conversations.

### Website and security information

Our hosting and security providers may process standard request and diagnostic data. This can include IP address, browser and device information, requested pages, referring URL, timestamps, approximate location derived from an IP address, and signals used to detect abuse or automated submissions.

### Information handled for customers

Healthcare practices may direct iPothecary to process product, vendor, inventory, transaction, staff, and patient-related information in the service. The practice controls this information. iPothecary processes it to provide and secure the service, subject to the governing customer agreement and applicable law.

**Do not submit patient information through the public contact form.** It is intended for business inquiries, not care or support requests involving a patient.

## How we use information

We use information to:

- Respond to demo, partnership, investor, privacy, safety, and general inquiries.
- Provide, support, secure, and improve iPothecary services.
- Authenticate users, maintain records, and investigate errors or misuse.
- Meet contractual, legal, accounting, and safety obligations.
- Protect patients, practices, iPothecary, and others from harm or fraud.

At the effective date above, this public website does not use advertising pixels or third-party behavioral analytics. We do not use public-site inquiry information for targeted advertising.

## How we disclose information

Information may be disclosed to service providers that operate and protect our website and communications, professional advisers, authorities or other parties when required by law or needed to protect safety and rights, a successor organization in a business transaction, and recipients you direct or authorize.

Public website providers include:

- Cloudflare for hosting, network security, and Turnstile bot protection.
- Resend for delivery of contact-form inquiries to iPothecary.

Cloudflare Turnstile evaluates browser and security signals to distinguish legitimate visitors from automated traffic. iPothecary sends the resulting token and network information needed to verify it. The text entered in the contact fields is sent to iPothecary's contact endpoint, not to Turnstile as form content.

**We will not sell patient information.** We also do not sell personal information submitted through this public website.

## Healthcare and patient information

When iPothecary handles protected health information for a healthcare practice, it may act as that practice's business associate. In that role, iPothecary uses and discloses protected health information only as permitted by the applicable agreement, business associate agreement, customer instructions, and law.

If you are a patient seeking access, correction, restriction, or another right relating to information held by your healthcare provider, contact that practice directly. The practice can evaluate and respond under its Notice of Privacy Practices. iPothecary supports its customers in meeting their obligations where required.

iPothecary does not provide medical advice and does not determine which products a clinician should recommend.

## Retention and security

We retain information only as long as reasonably necessary for the purposes described here. This includes providing services, maintaining business and safety records, resolving disputes, enforcing agreements, and meeting legal obligations. Retention can vary by information type and governing agreement.

We use administrative, technical, and organizational safeguards appropriate to the nature of the information. No internet transmission or storage system is perfectly secure, so we cannot promise absolute security.

## Your choices and rights

Depending on where you live and the context, you may have the right to request access, correction, deletion, or a copy of personal information, or to object to or restrict certain processing. We may need to verify your identity and may retain information when the law permits or requires it.

To make a request about public-site or business-contact information, use the privacy option on our contact form. For patient records, contact the healthcare practice that collected or controls the information.

## Children

This public website is intended for healthcare and business professionals, not children under 13. We do not knowingly collect personal information from children through this site.

## Changes

We may update this policy as our services or legal obligations change. We will post the revised policy and update the effective date. Material changes may be communicated through additional notice where appropriate.

## Contact

[Contact iPothecary about privacy](https://ipothecary.com/contact?reason=privacy). Do not include patient information in the public form.
