SuppleStack, Inc. (“SuppCo,” “we”, “us” or “our”) is an online platform that allows people motivated by health and wellness to track and share their supplement regimen and preferred products with a like-minded community to help achieve health goals.
This Consumer Health Data Privacy Policy (“Consumer Health Data Privacy Policy”) applies to the extent that the Washington My Health My Data Act and other applicable U.S. state laws (“Consumer Health Data Laws”) apply to SuppCo in respect of consumer health data (“Consumer Health Data”) as the Consumer Health Data Laws define that or similar terms. This Consumer Health Data Privacy Policy supplements our general Privacy Policy. In the event of a conflict between our Privacy Policy and the Consumer Health Data Privacy Policy, the Consumer Health Data Privacy Policy applies to the extent that it is consistent with the Consumer Health Data Laws.
This Consumer Health Data Privacy Policy describes how SuppCo processes personal information that we collect through our digital or online properties or services that link to this Privacy Policy (including as applicable, our website, mobile application, and social media pages) as well as our marketing activities, and other activities described in this Consumer Health Data Privacy Policy (collectively, the “Service”)).
Consumer Health Data you may provide to us through the Service or otherwise includes:
In addition to Consumer Health Data that you may provide to us directly, we may collect your Consumer Health Data through other means.
We use Consumer Health Data for purposes described in this Consumer Health Data Privacy Policy or as otherwise disclosed to you. For example, we use Consumer Health Data for the following purposes:
Purpose of Use | Categories of Consumer Health Data |
---|---|
Service delivery and operations: providing the Service, enabling security features of the Service, establishing and maintaining your user profile on the Service, communicating with you about the Service, providing support for the Service and responding to your requests/questions/feedback. | Contact data, demographic data, profile data, communications data, marketing data, user-generated content data, payment data, transaction data, device data, online activity data, location data, communications interaction data |
Research and development: to analyze and improve the Service and our business and to develop new products and services. | Contact data, demographic data, profile data, communications data, marketing data, user-generated content data, payment data, transaction data, device data, online activity data, location data, communications interaction data |
Service personalization: understanding your needs and interests, personalizing your experience with the Service and our Service-related communications, remembering your selections and preferences as you navigate webpages | Contact data, demographic data, profile data, communications data, marketing data, user-generated content data, payment data, transaction data, device data, online activity data, location data, communications interaction data |
Service improvement and analytics: analyzing your usage of the Service, improving the Service, improving the rest of our business, helping us understand user activity on the Service, including which pages are most and least visited and how visitors move around the Service, as well as user interactions with our emails, and developing new products and services. | Contact data, demographic data, profile data, communications data, marketing data, user-generated content data, payment data, transaction data, device data, online activity data, location data, communications interaction data |
Direct marketing: communicating with you about new services, upcoming events, and other information | Contact data, demographic data, profile data, communications data, marketing data, user-generated content data, payment data, transaction data, device data, online activity data, location data, communications interaction data |
Compliance and protection: complying with applicable laws, lawful requests, and legal process, such as to respond to subpoenas, investigations or requests from government authorities; protecting our, your or others’ rights, privacy, safety or property; auditing our internal processes for compliance with legal and contractual requirements or our internal policies; enforcing the terms and conditions that govern the Service; preventing, identifying, investigating and deterring fraudulent, harmful, unauthorized, unethical or illegal activity, including cyberattacks and identity theft | Contact data, demographic data, profile data, communications data, marketing data, user-generated content data, payment data, transaction data, device data, online activity data, location data, communications interaction data |
To create aggregated, de-identified and/or anonymized data. We may create aggregated, de-identified and/or anonymized data from your personal information and other individuals whose personal information we collect. We make personal information into de-identified and/or anonymized data by removing information that makes the data identifiable to you. We may use this aggregated, de-identified and/or anonymized data and share it with third parties for our lawful business purposes, including to analyze and improve the Service and promote our business. | Contact data, demographic data, profile data, communications data, marketing data, user-generated content data, payment data, transaction data, device data, online activity data, location data, communications interaction data |
We may “share” (as the Consumer Health Data Laws define that term) Consumer Health Data with your consent or as we determine necessary to provide the Website to you, or as otherwise permitted or required by law. For example, we may share your Consumer Health Data to:
Affiliates. As applicable, our corporate parent, subsidiaries, and affiliates.
Partners. We may sometimes share your Consumer Health Data with partners or enable partners to collect information directly via our Service.
Business and marketing partners. Third parties with whom we co-sponsor events or promotions, with whom we jointly offer products or services, or whose products or services may be of interest to you.
Legal and law enforcement. We will access, share, and preserve Consumer Health Data when we believe that doing so is necessary to comply with applicable law or respond to valid legal process, including from law enforcement or other government agencies. We will also share Consumer Health Data if we believe it is necessary to protect our customers and/or the rights or property of ourselves or others.
You may have certain rights to your Consumer Health Data under applicable Consumer Health Data Laws. Any of the rights discussed below may be subject to certain limitations (for example, a monetary charge).
If you wish to exercise these rights, please email us at privacy@supp.co.
Withdraw consent. To the extent we rely upon your consent for either our collection or sharing of your Consumer Health Data, you have the right to withdraw such consent from any future collection or sharing.
Access and confirm. You have the right to ask us to confirm whether we have collected, shared or sold your Consumer Health Data. Further, you have the right to access (in other words, request a copy of) the Consumer Health Data that we have collected, shared or sold. You also have a right to access a list of all “third parties” (as Consumer Health Data Laws define that term) and affiliates with whom we have shared or sold your Consumer Health Data and receive certain corresponding information.
Correction. You have the right to ask us to correct inaccuracies in your Consumer Health Data.
Deletion. You have the right to ask us to delete your Consumer Health Data.
Appeal. You have the right to appeal our denying a Consumer Health Data Law right you have attempted to exercise. We will provide details on how to appeal our denial in connection with such action.
To exercise your rights above and make a Consumer Health Data rights request, please email us at privacy@supp.co. We may need to verify your identity in order to process your request. To confirm your identity, we may ask you to verify personal information we already have on file for you. If we cannot verify your identity based on the information we have on file, we may request additional information from you (such as government identification), which we will only use to verify your identity, and for security or fraud-prevention purposes.
Declining to provide information. We need to collect personal information to provide certain services. If you do not provide the information we identify as required or mandatory, we may not be able to provide those services.
We reserve the right to modify this Consumer Health Data Privacy Policy at any time. If we make material changes to this Consumer Health Data Privacy Policy, we will notify you by updating the date of this Consumer Health Data Privacy Policy and posting it on the Service or other appropriate means. Any modifications to this Consumer Health Data Privacy Policy will be effective upon our posting the modified version (or as otherwise indicated at the time of posting). In all cases, your use of the Service after the effective date of any modified Consumer Health Data Privacy Policy indicates your acknowledging that the modified Consumer Health Data Privacy Policy applies to your interactions with the Service and our business.
These statements have not been evaluated by the Food and Drug Administration. Any products and informational content displayed on this page are not intended to diagnose, treat, cure, or prevent any disease.