Plain-English summary
We collect the information you give us when you place an order, subscribe, or contact us — plus standard analytics about how you use the site. We use it to send your products, run our business, and improve our service. We don't sell your data. You can ask us to delete it anytime.
The rest of this page is the detailed version. If you'd rather skip the legalese, the summary above is the gist.
What we collect
Information you give us
- Name, email, shipping & billing address, phone (when ordering or subscribing)
- Payment information — processed by our payment processor; we never store your card number
- Account credentials (email + hashed password)
- Messages, support tickets, and product reviews you submit
- Information you submit in partnership, wholesale, or contact forms
Information we collect automatically
- Device, browser, and operating system info
- IP address (truncated for analytics)
- Pages visited, time on site, referring URL
- Cookie and similar tracker data (see Cookies)
How we use it
- To fulfill your orders, deliver subscriptions, and provide customer support
- To send order confirmations, shipping updates, and account notifications
- To send marketing emails — only if you've opted in. You can unsubscribe anytime via any email's footer.
- To run our business: accounting, fraud prevention, legal compliance
- To analyze site performance and improve our products and experience
- To personalize what you see (e.g. product recommendations based on past orders)
Who we share with
We share data only with the providers and partners necessary to run our business. Specifically:
- Payment processors — to charge your card and prevent fraud
- Fulfillment & shipping providers — to pick, pack, and ship your order
- Email service providers — to send transactional and (opted-in) marketing email
- Analytics providers — anonymized or aggregated data to understand site usage
- Customer support tools — to manage your tickets and conversation history
- Legal authorities — when required by law, subpoena, or to protect rights and safety
We do not sell your personal information. We never have, and we have no intention of doing so.
Cookies & tracking
We use cookies and similar technologies for three purposes:
- Essential — keep you signed in, remember items in your cart, process checkout. The site can't work without these.
- Analytics — understand how visitors use the site so we can improve it. Aggregated, not personally identifying.
- Marketing — show you relevant ads on other sites if you've visited ours. Only set with your consent.
You can disable non-essential cookies through our cookie banner (first visit) or your browser settings at any time. Doing so may affect site functionality.
How long we keep data
- Order records — 7 years (tax & accounting requirement)
- Account data — until you delete your account, plus 30 days backup retention
- Marketing email data — until you unsubscribe
- Support conversations — 3 years from last interaction
- Analytics — 26 months, then aggregated and anonymized
Your rights
Regardless of where you live, you have the right to:
- Access — request a copy of the personal data we hold about you
- Correct — fix anything that's inaccurate
- Delete — ask us to delete your data (subject to legal retention requirements)
- Port — get your data in a portable format
- Object — opt out of certain processing (e.g. marketing)
- Restrict — limit how we use your data in certain circumstances
To exercise any of these rights, email [email protected]. We'll respond within 30 days.
California residents (CCPA/CPRA)
You have the right to know what we collect, request deletion, and opt out of any "sale" or "sharing" of personal information. We do neither, but you can confirm by submitting a request to the email above.
European residents (GDPR)
You may also lodge a complaint with your local data protection authority if you believe we've mishandled your data.
How we keep it safe
We encrypt data in transit (TLS 1.3) and at rest. Access to personal data is limited to employees and processors with a need to know, audited regularly. Payment information never touches our servers — it's tokenized and handled by our PCI-compliant payment processor.
No system is unbreachable. If we ever discover a breach involving your personal data, we'll notify you within 72 hours as required by law.
Children's privacy
Our products are intended for adults. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with information, please email [email protected] and we will delete it.
Changes to this policy
We may update this policy occasionally — new features, new regulations, clearer language. The "Last updated" date at the top reflects the most recent change. For material changes, we'll notify you by email or a prominent site banner.
Contact us
Questions, requests, or complaints about your privacy?
Email: [email protected]
Mail: Alpha Health, Inc., Attn: Privacy, 2200 Mission Bay Blvd, San Francisco, CA 94158