Policies

Privacy policy

Last updated June 1, 2026

This policy describes how Connect Wellness collects, uses, and shares personal information when you visit connectwellness.health, create an account, shop online, or sign up for product updates. It reflects the data practices built into our website today.

Policy details

Who we are

Connect Wellness operates connectwellness.health and a compounding pharmacy in Eagle, Idaho. In this policy, “we,” “us,” and “our” mean Connect Wellness.

Mailing address: 44 N Fisher Park Way, Eagle, ID 83616. Email: wellness@connectrx.health. Phone: (208) 593-0133.

What this policy covers

This policy applies to personal information collected through our website and online shop, including account registration, guest checkout, wholesale applications, and email sign-up forms.

Compounded prescription services involve health information that may be protected under HIPAA. Those pharmacy workflows—such as e-prescribe, fax, and phone—are handled under our pharmacy privacy practices, not through the online checkout flow on this site. If you are a pharmacy patient and have questions about protected health information, contact us using the information above.

Information we collect

Account information. When you create an account, we collect your email address and password. Passwords are handled by our authentication provider; we do not store plain-text passwords.

Order and checkout information. When you place a shop order, we collect your email address, shipping name and address, and—if different—billing name and address. You may optionally add an order note. Guest checkout is supported; if you later create an account with the same email, prior guest orders may be linked to your account.

Payment information. Card numbers and security codes are entered in a payment lightbox hosted by our payment processor (Wind River Financial / NMI Collect.js). Those card details are tokenized and sent directly to the processor; they are not stored on our servers. We retain payment-related records such as transaction IDs, authorization codes, amounts, and limited gateway response data needed for receipts, refunds, and support. Full card numbers and CVV values are not kept in our database.

Apple Pay. If you use Apple Pay express checkout, we receive the shipping and contact details you authorize through your wallet. Those addresses are validated for deliverability before your order is placed.

Wholesale applications. Approved wholesale buyers submit a business name, contact name, phone number, and a resale certificate file (PDF, JPG, or PNG). Certificate files are stored in our secure file storage.

Email sign-ups. If you join our product waitlist, request a launch notification, or ask to be notified when a product is back in stock, we collect your email address and record which form you used (and, for product notifications, which product you selected).

Information collected automatically. We set a guest-cart cookie to remember your cart between visits, authentication cookies when you sign in, and use analytics and advertising tools described below. When you check out, we may derive your IP address from request headers for fraud prevention, checkout rate limiting, and—when placing a payment—transmission to our payment processor as part of the transaction record.

Address validation and tax. Before an order ships, your shipping address may be sent to UPS to verify deliverability; we store the validation result with your order. For certain Idaho shipping destinations, your postal code may be sent to Zip-Tax to look up applicable sales tax rates.

How we use information

We use personal information to operate the website, process and fulfill shop orders, manage accounts and order history, review wholesale applications, send transactional emails (such as order confirmations and account messages), deliver product availability notifications you requested, prevent abuse of checkout and related services, comply with tax and legal obligations, and improve our site.

We may email pharmacy staff who have opted in to internal operational alerts (for example, new orders or daily summaries). Those preferences apply to staff accounts only and do not change customer-facing emails such as order confirmations.

How we share information

We share personal information with service providers that help us run the site and fulfill orders, including:

Supabase (database, authentication, and file storage for wholesale certificates); Vercel (website hosting and analytics); ZeptoMail (transactional email delivery); Wind River Financial / NMI (payment processing); UPS (shipping-address validation); and Zip-Tax (optional Idaho sales-tax rate lookups).

Google Ads measurement code on our site may receive page and conversion-related data as described in the analytics section below.

We do not sell your personal information. We may disclose information when required by law, to protect our rights or safety, or in connection with a business transfer subject to this policy.

Cookies and similar technologies

Our site uses cookies and similar technologies for essential functions and measurement:

cw_cart_sid — an httpOnly cookie that identifies your guest shopping cart for up to 30 days.

Authentication cookies — set when you sign in, managed by our authentication provider, so you can stay logged in and access your account.

Third-party cookies — Google Ads may set cookies (for example, for ad measurement) when its scripts load on our pages. Your browser may block some third-party cookies depending on its settings.

You can control cookies through your browser settings. Disabling essential cookies may prevent cart or sign-in features from working correctly.

Analytics and advertising

We use Vercel Analytics to understand site traffic and performance. Vercel’s analytics are designed to be privacy-friendly and do not use third-party cookies for measurement.

We load Google Ads tag (gtag) scripts to measure advertising performance. Those scripts may collect page URLs, device/browser characteristics, and conversion events—including checkout-related events such as address verification steps. Google’s use of data is governed by Google’s policies.

We do not currently use PostHog or other product-analytics platforms on the public site.

Email communications

Transactional emails—such as order confirmations, password resets, and account verification—are sent because they are necessary to provide the service you requested.

Marketing and availability emails—such as waitlist or back-in-stock notifications—are sent only when you submit your email through the relevant sign-up form. To stop those emails, contact us at wellness@connectrx.health with the address you used to sign up.

Data retention

We keep account information while your account is active. Order and payment records are retained as needed to fulfill orders, handle returns and chargebacks, meet tax and accounting requirements, and resolve disputes.

Guest-cart session identifiers expire after 30 days of inactivity unless you complete checkout or sign in (which may merge your cart into an account). Mailing-list sign-ups are kept until you ask us to remove your address or we retire the list.

Security

We use industry-standard measures appropriate to an e-commerce site, including encrypted connections (HTTPS), httpOnly cart cookies in production, payment tokenization so card data does not pass through our servers, and access controls on administrative tools.

No method of transmission or storage is completely secure. If you believe your account or order information has been compromised, contact us promptly.

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information we hold about you, and to opt out of certain processing.

California residents. We do not sell personal information. You may request disclosure of categories of information we collect, request deletion of information we collected through the website, or ask us to correct inaccurate information. Submit requests to wellness@connectrx.health. We will verify your request using information associated with your account or order before responding.

Other U.S. state privacy laws may provide similar rights. Contact us at the email above and we will respond consistent with applicable law.

You can limit some online tracking by adjusting cookie settings in your browser and by using the opt-out tools offered by advertising platforms such as Google.

Children

Our website and shop are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us so we can delete it.

Changes to this policy

We may update this policy when our practices or legal requirements change. The “Last updated” date at the top of this page will reflect the most recent revision. Material changes may also be noted on the website.

Contact us

Questions about this policy or our data practices? Email wellness@connectrx.health, call (208) 593-0133, or write to Connect Wellness, 44 N Fisher Park Way, Eagle, ID 83616.

See also our shipping & delivery policy and return policy. Questions? Contact us.