Supplemental Privacy Notice for State Specific Privacy Laws

Effective: March 26, 2024

This supplemental notice is provided for individuals residing in states that have enacted comprehensive state privacy laws. It explains your rights regarding your personal data and how we handle your personal data. Certain terms in this supplemental notice are defined by applicable state law and their meanings may differ from the meanings applied elsewhere on our website.

Sources of Personal Data

We collect personal data from the following categories of sources:

  • Directly from you when you provide information
  • Our affiliates and business partners
  • Data verification services & data brokers
  • Marketing vendors and advertising networks
  • Social media
  • Healthcare providers

Personal Data We May Collect

We collect or process the following categories of personal data:

  • Identifiers, such as real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, signature, physical characteristic or description, telephone number, insurance policy numbers, employment status, or employment history
  • Characteristics of protected classifications, such as race, sex, disability, national origin, marital status
  • Commercial information, including records of personal property, products or services purchased, obtained, or considered or other purchasing histories or tendencies
  • Biometric information
  • Internet or other electronic network activity, including, but not limited to, browsing history, search history, and information regarding interactions with the site
  • Geolocation data
  • Audio, electronic, visual, thermal, olfactory, or similar information
  • Professional or employment-related information
  • Education information
  • Inferences drawn from any of the information identified above to create a profile about you that reflects your preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligences, abilities, and aptitudes

We collect or process the following categories of sensitive personal data:

  • Social security number
  • Driver’s license number
  • Passport number
  • State identification card
  • Medical information
  • Health insurance information
  • Financial information such as, bank account information, credit or debit card number, account log-in, account numbers, required security or access code, password, or credential(s) allowing access to the account
  • Precise geolocation
  • Racial or ethnic origin, religious or philosophical beliefs, or union membership
  • Genetic data
  • Biometric information, such as audio, electronic, visual, thermal, olfactory, or similar information
  • Personal information collected and analyzed concerning your sex life or sexual orientation
  • Personal information collected and analyzed concerning your health

Processing, Disclosure, and Retention of Personal Data

The categories of data collected and listed above will be processed, disclosed, sold, shared, and retained as described below:

Processing Purpose

Business Purposes:

  • To perform the business services you have requested and/or to provide reasonably expected goods
  • To develop new products and services
  • To provide personalized and non-personalized offers and services based on your interactions with our site/product or affiliated vendors utilizing your browsing history, search history, and interactions with our site products, or services
  • To detect security incidents that compromise the availability, integrity, authenticity, and confidentiality of stored or transmitted personal information
  • To prevent malicious, deceptive, fraudulent, or illegal actions and to prosecute those responsible for those actions
  • To protect our rights, property, and safety or the rights, property, and safety of others
  • To perform services, such as maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying information, processing payments, providing financing, providing analytic services, or providing storage
  • To verify, analyze, maintain, or enhance the quality or safety of our products and services
  • To offer or provide employee benefits and services
  • To comply with legal obligations

Commercial Purposes:

  • For targeted advertising. We utilize cookies, pixels, and other advertising technology to provide users personalized ads.
  • For profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer

Categories of Third Parties to which we Disclose that Personal Data

  • Our vendors and service providers
  • Healthcare providers
  • Advertising networks, who may use your browsing history, search history, and information regarding your interaction with the site
  • Our affiliates and business partners
  • Law enforcement, when required by law

Categories of Third Parties to which we “Sold” or “Shared” that Personal Data

  • Our vendors and service providers
  • Healthcare providers
  • Advertising networks, who may use your browsing history, search history, and information regarding your interaction with the site
  • Our affiliates and business partners
  • Law enforcement, when required by law

We do not knowingly sell or share personal data of residents under the age of 16.

Retention

  • We retain your data in accordance with applicable contracts, Terms of Service, regulatory/legal obligations, or as otherwise allowed.

There are times when personal data is disclosed externally with other companies, organizations, or individuals when we have a good faith belief that access, use, preservation, or disclosure of that data is reasonably necessary to:

  • Meet applicable laws, regulations, legal processes, or enforceable governmental requests
  • Enforce applicable Terms of Service, including investigation of potential violations
  • Detect, prevent, or otherwise address fraud, security, or technical issues
  • Protect against harm to the rights, property or safety of our users, McKesson, or the public as required or permitted by law
  • Engage in a merger, acquisition, reorganization, or sale of all or a portion of the business’s assets

We sell or share deidentified information. Deidentified information is data that is no longer considered individually identifiable and has been deidentified in compliance with either the HIPAA expert determination method or the HIPAA safe harbor method as described in Sections 164.514(b)(1) and (2) of the Code of Federal Regulations.

Your Rights

The following states provide privacy rights to their residents. If you or your authorized representative would like to exercise one of your rights, please use the applicable link below or call 1-833-925-0545. Should you exercise one of your rights, we may require certain identifying data from you or your authorized representative to verify your request. We will honor your request if it complies with applicable state privacy laws. Questions and concerns can be emailed to privacy@covermymeds.com.

California

The right to know what specific elements of personal data we collect about you, which includes the following. You can exercise your right to know by clicking HERE.

  • The right to know the categories of personal data we have collected.
  • The categories of our sources from which the personal data is collected.
  • The categories of third parties to whom we disclose personal data to.
  • The specific elements of personal data we have collected about you.
  • The categories of personal information we sold or shared.
  • The categories of personal information we disclosed for a business purpose.
  • Our business or commercial purpose for collecting, selling, or sharing your personal data.

The right to delete personal data that we have collected from you, subject to certain exceptions.  You can exercise your right to delete by clicking HERE.

The right to correct inaccurate personal data we maintain about you. You can exercise your right to correct by clicking HERE.

The right to limit the use or disclosure of sensitive personal data. Subject to certain exceptions, you have the right to limit our use or disclose of your sensitive personal data by clicking HERE.

The right to opt-out of the sale or sharing of your personal data with other parties. You can exercise your right to opt-out by clicking this Do Not Sell or Share My Personal Information link. We recognize Global Privacy Control (GPC) signals, and if your web browser utilizes GPC, your opt-out preferences over the use of your cookie data will be honored in compliance with state law.

The right not to receive discriminatory treatment for exercising your privacy rights. This right extends to an employee, applicant, or independent contractor who may not be retaliated against for exercising a right.

Virginia

The right to opt-out of the sale of your personal data: You can exercise your right to opt-out of a sale by clicking HERE.

The right to opt-out of targeted advertising. When personal data is collected and stored for purposes of serving targeted ads, you may direct us to stop using your data for such purposes by clicking HERE.

The right to opt-out of using your data for profiling purposes if the profiling produces legal or similarly significant effects for you. You may opt-out of profiling by clicking HERE.

The right to correct inaccurate personal data we maintain about you. You can exercise your right to correct by clicking HERE.

The right to delete personal data provided by or obtained about you. You may ask that we delete certain personal data we have collected about you. You can exercise your right to delete by clicking HERE.

The right to confirm whether we are processing your personal data and access such data. You can exercise this right by clicking HERE.

The right to obtain a copy of your data in a portable format. You may request to receive your personal data in a readily useable format, to the extent technically feasible.

Colorado

The right to opt-out of the sale of your personal data: You can exercise your right to opt-out by clicking HERE.

The right to opt-out of targeted advertising: When personal data is collected and stored for purposes of serving targeted ads, you may direct us to stop using your data for such purposes by clicking HERE.

The right to opt-out of using your data for profiling purposes if the profiling produces legal or similarly significant effects for you. You may opt-out of profiling by clicking HERE.

The right to correct inaccurate personal data we maintain about you. You can exercise your right to correct by clicking HERE.

The right to delete your personal data. You may request that we delete certain personal data we have collected about you. You can exercise your right to delete by clicking HERE.

The right to confirm whether we are processing your personal data and access such data. You can exercise this right by clicking HERE.

The right to obtain a copy of your data in a portable format. You may request to receive your personal data in a readily useable format, to the extent technically feasible.  

Utah

The right to confirm whether we are processing your personal data and access such data. You can exercise this right by clicking HERE.

The right to delete personal data provided by you. You may ask that we delete certain personal data we have collected about you. You can exercise your right to delete by clicking HERE.

The right to opt-out of the sale of your personal data. You can exercise your right to opt-out by clicking HERE.

The right to opt-out of targeted advertising. When personal data is collected and stored for purposes of serving targeted ads, you may direct us to stop using your data for such purposes by clicking HERE.

The right to obtain a copy of your data in a portable format. You may request to receive your personal data in a readily useable format, to the extent technically feasible.  

Connecticut

The right to confirm whether we are processing your personal data and access such data. You can exercise this right by clicking HERE.

The right to correct inaccurate personal data we maintain about you. You can exercise your right to correct by clicking HERE.

The right to delete personal data provided by you or obtained about you: You may ask that we delete certain personal data we have collected about you. You can exercise your right to delete by clicking HERE.

Right to opt-out of the sale of your personal data. Subject to certain considerations for your voluntary participation in a rewards program, you can exercise your right to opt-out of a sale by clicking HERE.

The right to opt-out of targeted advertising: When personal data is collected and stored for purposes of serving targeted ads, you may direct us to stop using your data for such purposes by clicking HERE.

The right to opt-out of using your data for profiling purposes if the profiling produces legal or similarly significant effects for you. You may opt-out of profiling by clicking HERE.

The right to obtain a copy of your data in a portable format. You may request to receive your personal data in a readily useable format, to the extent technically feasible.  

Nevada

Right to opt-out of sale. You may direct us to stop selling your personal data and can exercise your right to opt-out by clicking HERE.

Contact Information

If required by your state, we will provide you the opportunity to appeal certain decisions made by us related to your rights. For each request you submit, we will inform you of the action we have taken in response to your request. If your state requires it, you will be provided the opportunity to appeal our decision by following the instructions in our response.

If you have questions or concerns about this Privacy Notice, you may contact us at privacy@covermymeds.com.

Chat with support