Privacy Statement
Healthy Web Inc., together with its parent Natural Partners, Inc. and their affiliates (referred to as “Fullscript”, “we”, “us” or “our”), are committed to protecting your (referred to as “you” or “your”) privacy and providing you with a positive experience on our websites and mobile applications, and when using our Services. Any terms not defined in this Privacy Statement shall have the same meanings ascribed to them in our Terms of Service.
This Privacy Statement applies to our websites, mobile applications, Services, or any other applications or features that link to or reference this Privacy Statement, including when you engage with us on social media; interact with our advertising or marketing materials; as well as offline interactions (such as when you call us, visit our offices, attend Fullscript events, or interact with our representatives at other events). This Privacy Statement describes how we handle your personal information and the choices available to you regarding the collection, use, access, and how to update and correct your personal information. Our privacy practices are subject to the applicable laws of the places in which we operate so you may see additional region-specific terms that only apply to individuals located in those geographic regions, or as required by applicable laws. For certain products, services, and features, there may be additional notices about our practices and this Privacy Statement supplements any other privacy policies provided or communicated to you. For individuals residing in the United States, please refer to our US State Privacy Notice and our Consumer Health Data Privacy Notice for additional information about the processing of your personal information, and your rights under applicable US state data privacy law. Please read those additional privacy disclosures to understand how they apply to you.
By using our Services, you acknowledge the terms of this Privacy Statement. If you do not understand the terms of this Privacy Statement, please do not use our Services. If you are using our Services on behalf of a person or entity other than yourself, you represent that you are authorized to act on such person or entity’s behalf and that such person or entity acknowledges the practices and policies outlined in this Privacy Statement. If you have questions about this Privacy Statement, please contact us before using, or continuing to use, our Platform or Services.
This Privacy Statement does not apply to the practices of companies unaffiliated with us or to parties that we do not employ or manage, including Practitioners. We may also provide links to third-party websites and services. The practices described in this Privacy Statement do not apply to information gathered through these third-party websites and services. We have no control over, and are not responsible for, the actions and privacy policies of third-parties and other websites and services. If you have any questions about the privacy practices of these third-parties, we encourage you to review their privacy policies or notices.
Collection of Personal Information
We collect two basic types of information from you when you provide it to us or when you use or interact with our Services or through our advertising and media across the Internet: personal information and non-personal information.
“Personal information” is any information relates to you or which are opinions about you personally and either identifies or may be used to identify you personally, or is otherwise considered personal information or personal data under applicable law. This includes, for example, name, date of birth, sex and/or gender, address, email address, phone number, login information (account number, password), sensitive personal information including health information and medical history, photos, government issued identification information, online orders, professional and employment information, promotions preferences, social media account information, financial account information, or payment card number. We may collect data, including personal information, about you as you use our Services and interact with us.
We collect personal information for a variety of reasons, such as:
- Creating dispensaries and accounts.
- Processing orders, including payment transactions.
- Enabling communications between users.
- Sending announcement, educational, and promotional communications.
- Enabling the use of certain features of our Services.
- Personalizing your experience.
- Providing customer service.
- Performing necessary operations to maintain our Services, including to troubleshoot software bugs and operational problems.
- For individuals who apply for a career opportunity with Fullscript, we collect contact information, data submitted on a résumé or in a job application, and other information to administer the hiring process.
We may automatically collect information from you when you interact with our Services, including details of your visits, traffic data, site features and pages viewed, search queries, IP address, software and hardware attributes, unique device identifiers, browser type, mobile network information, general geolocation information, site crashes, and other system activity and logs. This information is used to better understand and improve the usability, performance, and effectiveness of the website and to help tailor content or offers for you. Please read the “Cookies and Other Web Technologies” section below for more information.
We may collect personal information from our subsidiaries and affiliates you interact with as permitted by applicable law.
We may collect information about you from both publicly available and other third-party sources to enhance and improve the accuracy of our information about you. We may combine the information we collect from you with information we get from and about you from other online and offline sources. This helps us improve its overall accuracy and completeness and also helps us better tailor our interactions with you. We may use the combined information in accordance with this Privacy Statement.
If you choose to provide Fullscript with a third party’s personal information (such as name, email address, or phone number), you represent that you have that third party’s permission to do so. Examples include forwarding reference or promotional material to a friend or sending job referrals. Third parties may unsubscribe from any continued communication by following the link provided in the initial message or contacting us directly.
Non-personal information includes information that does not personally identify you or information that has been anonymized (collectively, “non-personal information”). When we link non-personal information with personal information, we treat the linked information as personal information.
Use of Personal Information
We primarily use personal information to provide, maintain, and improve our Services, but we may also use personal information for any or all of following purposes: fulfill your requests for Products and Services, process your transactions, maintain your account and subscriptions, customize our Platform and Services, conduct core business functions(such as training, research, and analysis), contact you (including email, text, direct mail, push notifications), communicate with your or on your behalf, send promotional and other communications related to our business, investigate and respond to your inquiries, protect your security and the security of our Services, combat fraud, enforce our rights or applicable Terms of Service and take appropriate actions for violations, fulfill our legal or contractual obligations, comply with applicable law or legal directives, and any other purpose with your consent.
Access to and Accuracy of Personal Information
We need your help in keeping your personal information accurate and up to date. We provide you with several options to access and correct your personal information:
- You can view or edit your personal information and preferences online by logging into your Fullscript account.
- You can contact us directly by phone, email, and chat.
- You can update your mobile device settings.
We honor requests to access, update, or correct your personal information and will do so in accordance with applicable laws. We will respond to your request in a timely manner in accordance with applicable laws. If we are unable to honor your request, we will provide you with an explanation.
Sharing of Personal Information
We do not sell personal information.
We only share personal information in limited circumstances. For example, we may share Personal Information with third party service providers, suppliers, vendors, contractors, professional advisors, and business partners, which may include IT service providers, financial institutions and payment providers, customer relationship management vendors, social media platforms, marketing and advertising networks, cloud-based solution providers, lawyers, accountants, auditors, and other professional advisors. We primarily share personal information with these third parties to help us with the uses described above, including for the purposes of operating our business, delivering, improving, providing, and customizing our Services, fulfilling orders, analyzing data, sending promotional and other communications related to our business, and for other legitimate purposes permitted by applicable law or otherwise with your consent.
We may also share personal information in the following ways:
- With your Practitioner for the purpose of fulfilling your transactions and your use of their dispensary.
- With Fullscript affiliated entities for business purposes including, but not limited to, customer support, technical and business operations, and data processing and storage.
- With service providers we use to support our business including, but not limited to, cloud storage, shipping of orders, payment processing and fraud detection, product suppliers, assisting with sales-related efforts or post-sales support, analyzing data, and providing customer support.
- With other companies who place cookies, tags, and web beacons on our Services. These companies help operate our Services and provide you with additional products and services.
- With third-party advertising networks to serve advertisements on our behalf.
- In connection with, or during negotiations of, any merger, sale of company assets, consolidation or restructuring, financing, or acquisition of all or a portion of our business by or to another company.
- In response to a request for information by a competent authority, if we believe disclosure is in accordance with or is otherwise required by any applicable law, regulation, or legal process.
- With law enforcement officials, government authorities, or other third parties as necessary to comply with legal process or meet national security requirements, protect the rights, property, or safety of Fullscript, its service providers, you, or others, or as otherwise required by applicable law.
- To otherwise fulfill the purpose for which you provide it. For example, if you give us an email address to use the referral features of our Services, we will transmit the contents of that email and your personal information to the recipients.
- If we otherwise notify you and you consent to the sharing of personal information.
We may also share aggregated, anonymized and/or de-identified information that cannot reasonably be used to identify you.
You may choose to connect your Fullscript account to accounts on another service, and that service may send us information about your account on that service. We use that information to provide you features like EHR integrations. By connecting accounts, you are enabling us and the other service provider to exchange information about you and data in your account in order to provide the requested services. If you would like to revoke your consent to share information, please visit the other service provider to revoke your permission.
Security of Personal Information
We endeavor to protect the personal information you entrust to us. We have reasonable and appropriate technical, physical, and administrative security measures in place to protect the confidentiality of personal information and protect against accidental or unlawful destruction or accidental loss, alteration, unauthorized disclosure or access. These measures are designed to provide a level of security appropriate to the risk represented by the processing and the nature of the data. In the event we share personal information with service providers, we require such service providers to have appropriate security measures and we restrict the ways in which they may use or disclose personal information.
Transmitting personal information is at your own risk (for example, the internet and mobile networks cannot be guaranteed to be secure). While we attempt to protect and safeguard your personal information in our possession, no system or network is perfect and can be guaranteed to be 100% secure and we cannot promise that information about you will remain secure in all circumstances. The safety and security of your personal information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Services, you are responsible for keeping this password confidential. You are solely responsible for all uses of your password, even if such uses were not authorized by you. If you suspect an unauthorized use or security breach of your personal information, please contact us immediately.
Transfer, Processing, and Storage of Personal Information
We may transfer personal information between Fullscript offices in Canada and the US, or to third parties as described above, which may be located in various countries around the world. While other countries or territories may not have the same standards of data protection as those in your home country, we will continue to protect personal information that we transfer in line with this Privacy Statement requiring that our business partners or service providers adhere to this Privacy Statement and the applicable privacy regulations in your home country.
Retention of Personal Information
We typically retain personal information for the period necessary to fulfill the purposes for which it was collected and any other permissible, related purpose, unless a longer retention period is required or permitted by law. In many situations, we must retain some or all of your personal information to comply with our legal obligations; resolve disputes; enforce our agreements; protect against fraudulent, deceptive, or illegal activity; or for other legitimate business purposes, such as for auditing, accounting, or tax purposes.
Patient/Client Data Storage for Practitioners
If you are a Patient Account, you acknowledge that your use of our Services is solely through your Practitioner and that Fullscript will share personal information with your Practitioner for the purposes of facilitating the provision of Services to you on behalf of your Practitioner. Your use of the Services is also subject to your Practitioner’s privacy policies; please contact your Practitioner if you have any questions about their policies or terms.
If you are a Practitioner, you acknowledge that, with respect to other users’ personal information that you obtain or transmit through your use of your Fullscript account or through a Fullscript communication or transaction, you will only use such information as strictly necessary for transactions or activity under your Fullscript account. Practitioners remain solely responsible for compliance with the applicable law related to their collection and handling of personal information and other user information, including health information.
Use of Cookies and Other Web Technologies
Like many websites, Fullscript uses automatic data collection tools, such as cookies, SDKs, embedded web links, and web beacons, to collect traffic and usage patterns, and to help us personalize the Services. These tools collect certain standard information that your browser sends to us. Examples include your browser type and the address of the website from which you arrived at our website. We automatically receive and record information on our server logs from your browser, including IP addresses, cookie information, browsing history, and the Fullscript website pages requested. We utilize this information for analytical purposes which allow us to improve our Services and your experience.
The above technologies may also collect information about:
- Your IP address. This is a number automatically assigned to your computer or device whenever you connect to the Internet. Among other things, the IP address allows web servers to locate and identify your device for the purpose of facilitating online communications between you and other parties you engage with on the Internet. Information generated from your IP address also permits us to determine your general location.
- Clickstream behavior. This includes, for example, the pages you view and the links you click. These tools help make your visit to our Services easier, more efficient, and more valuable by providing you with a customized experience and recognizing you when you return.
Our Services also may include widgets, which are interactive mini-programs that provide specific services from other companies. Information collected by a widget is governed by the privacy policy of the company that created the widget.
Some web browsers may give you the ability to enable a “do not track” feature that sends signals to the websites you visit, indicating that you do not want your online activities tracked. This is different from blocking or deleting cookies, as browsers with a “do not track” feature enabled may still accept cookies. No industry standard currently exists on how companies should respond to “do not track” signals, although one may develop in the future. Fullscript’s Platform functionality is not currently able to recognize and respond to “do not track” signals. To learn more about “do not track” signals, visit https://www.allaboutdnt.com.
We use third-party web analytics services, such as Google Analytics and Mixpanel. The service providers that administer these services use automated technologies to collect data (such as IP addresses, cookies, and other device identifiers) to evaluate use of our Services. To learn more about Google Analytics and how to opt out of their tool entirely, please visit the Google Analytics Opt-out Browser Add-on. Please note that blocking cookies may affect the availability and functionality of our Services and other websites and may also invalidate opt outs that use cookies to recognize devices that have opted out.
We partner with third parties to manage our advertising on other websites. Our third-party partners may use cookies or similar technologies in order to provide you with Fullscript’s advertising based on your browsing activities and interests. This permits us to reach people who have previously visited our website and show them relevant advertisements when they visit other websites across the internet in the Google Display Network and Facebook Ads platform. You may be able to opt-out of customized Google Display Network ads by visiting the Ads Preferences Manager. To learn how to opt out of interest-based advertising, visit www.aboutads.info/choices and http://www.networkadvertising.org/choices/. You can also opt out of these third-party cookies though the banner when you visit our website.
When you opt out of receiving interest-based advertisements, this does not mean you will no longer see advertisements from Fullscript. It means that the online ads that you do see will not be tailored for you based on your particular interests. We may still collect information about you for any purpose permitted under the Policy Statement, including for analytics.
Your Choices and Selecting your Communication Preferences
We give you the choice of receiving a variety of information related to our Services. You can manage your communication preferences through the following methods:
- By updating your communication preferences in your account settings when logged in to your Fullscript account.
- By following the instructions included in each promotional email from us to unsubscribe from that particular mailing.
- By emailing, chatting with or calling our Customer Success team at 1-866-807-3828.
- By stopping push notices through your mobile device settings.
These choices do not apply to service notifications or other required communications that are considered part of certain Services, which you may receive periodically unless you stop using or cancel the Services in accordance with our Terms of Service.
By using our Services, or otherwise providing personal information to us, you acknowledge that we may communicate with you electronically regarding security, privacy, and administrative issues relating to your use.
Children’s Privacy
Our Services are not for children or those under the age of 18. Fullscript does not knowingly collect personal information from children or those under 18 years of age without appropriate parental or guardian consent. Individuals who are children or those under the age of 18 should not attempt to provide us with any personal information. We will cancel the registration of a Fullscript account initiated by a child or an individual under 18 years of age upon becoming aware of such registration. Parents have the right to terminate the registration of a child under age 18. If you think we have received personal information from children or those under the age of 18, please contact us immediately.
How to Contact Us
We value your opinions. Should you have questions or comments directly pertaining to this Privacy Statement, please contact us at:
Email: privacy@fullscript.com
Phone: 1-866-807-3828
Mail:
Fullscript
Attn: Privacy Officer
360 Albert Street, 2nd Floor
Ottawa, Ontario, Canada K1R 7X7
Fullscript
Attn: Privacy Officer
1750 Elm St., Floor 12
Manchester, NH 03104
Changes to Our Privacy Statement
We reserve the right to amend this Privacy Statement from time to time. If we amend this Privacy Statement, we will post the updated Privacy Statement on the website and update the Privacy Statement’s effective date. You acknowledge and understand that you should visit this pages periodically to be aware of and review any such revisions. By continuing to use our Services after such revisions are in effect, you are acknowledging that you have read and understand the revisions.