Privacy Policy
Last updated: August 6, 2026
1. Introduction
Affinity Direct, a division of Affinity Whole Health LLC ("Affinity Direct," "we," "us," or "our"), is committed to protecting the privacy of our patients and website visitors. This Privacy Policy describes how we collect, use, disclose, and protect your information when you visit our website or use our telehealth services.
By using our services, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
Personal Information
When you use our services, we may collect:
- Name, date of birth, and contact information (email, phone, address)
- Payment information (processed securely via third-party payment processors; we do not store card numbers)
- State of residence and shipping address
- Patient portal sign-in and verification information, such as login credentials, one-time codes, or similar access data
Protected Health Information (PHI)
As a healthcare provider, we collect health information necessary to provide medical services, including:
- Medical history, current medications, and allergies
- Symptoms, health questionnaire responses, and treatment goals
- Prescription and treatment records
- Communications with your assigned provider
All PHI is handled in accordance with the Health Insurance Portability and Accountability Act (HIPAA). Please see our HIPAA Notice of Privacy Practices for details.
Identity Verification Information
To confirm your identity and that you are at least 18 years old, we collect a photo of your government-issued identification (such as a driver's license) and the information it contains — including your name, date of birth, address, and the document's identification number and expiration date. This verification is performed in-house using our own systems; we do not send your identification document to a third-party identity-verification vendor.
Device, Usage & Online Activity Data
We and our analytics and advertising partners automatically collect certain information when you visit our website, including your IP address, device and browser type, the pages you view, the links you click, and referring URLs. Some of this information is collected through cookies and similar technologies, including identifiers set by third-party analytics and advertising services. We use this data to operate and secure the site, understand how it is used, and measure and improve our marketing. See "Cookies and Tracking" below for details and your choices.
3. How We Use Your Information
We use collected information to:
- Provide, operate, and maintain our telehealth services
- Process your intake form and facilitate provider review
- Fulfill and ship your prescriptions
- Communicate with you about your orders and care
- Send transactional and administrative messages (appointment updates, prescription status)
- Send promotional messages about our products and services, which you can opt out of at any time (see "Your Rights" below); marketing text messages are sent only in accordance with the optional choice you make when providing your mobile number
- Measure, analyze, and improve the performance of our website and advertising
- Comply with applicable laws, regulations, and professional standards
- Detect and prevent fraud and abuse
4. How We Share Your Information
We do not sell your personal information for money. We share information only as described below:
- Healthcare providers — Licensed clinicians — including, for certain treatments and states, independent licensed third-party clinicians and medical groups in our partner provider network — who review your case and issue prescriptions.
- Pharmacies and fulfillment partners — The pharmacies and fulfillment partners that prepare, dispense, and ship your treatment.
- Clinical and operational service providers — Electronic health record systems, payment processors, email and text-message providers, shipping carriers, and hosting and infrastructure providers that process data on our behalf under contractual confidentiality and security obligations. Where these providers handle Protected Health Information, we require them to safeguard it and use it only for authorized purposes, under a Business Associate Agreement where HIPAA requires one.
- Analytics and advertising partners — We use third-party analytics and advertising services, including social media and search advertising platforms, to understand site usage and to measure and improve our advertising. To do this, these partners may receive standard activity information such as the pages you visit, general device and browser information, your IP address, and — when you place an order — obscured (cryptographically hashed) contact identifiers used to measure whether our advertising led to a purchase. We do not share your health questionnaire answers, medical history, diagnosis, the specific medication or treatment you request or receive, or your identity-verification information with these analytics or advertising partners.
- Legal authorities — When required by law, court order, or to protect the rights and safety of our patients or the public.
Under some U.S. state privacy laws, our use of analytics and advertising services may be considered "sharing" or a "sale" of personal information for cross-context behavioral advertising. We do not exchange your personal information for money, and you can opt out of this activity — see "Your Privacy Choices" below.
5. Data Security
We use reasonable administrative, technical, and physical safeguards designed to protect your information, taking into account the nature of the information and the services we provide. These safeguards may include:
- Encryption for data transmitted to and from our platform
- Administrative and technical access controls intended to limit PHI access to authorized workforce members and service providers with a legitimate need to know
- Vendor management and contractual protections for service providers that handle sensitive information on our behalf
- Policies and procedures designed to support confidentiality, integrity, and availability of sensitive data
No method of transmission over the internet or method of electronic storage is 100% secure. While we take reasonable precautions designed to protect your information, we cannot guarantee absolute security.
6. Cookies and Tracking
We use several types of cookies and similar technologies. Essential cookies are required to operate our platform (for example, maintaining your intake session and keeping your account signed in). Analytics and advertising cookies and technologies — including pixels and tags provided by third-party social media and search advertising partners — help us understand how our site is used and measure the performance of our advertising. These technologies may set their own identifiers in your browser and transmit standard activity information (such as the pages you visit, your device and browser, and your IP address) to those partners. As described in "How We Share Your Information," we do not transmit your health questionnaire answers, diagnosis, the specific medication you request, medical history, or identity-verification data to these partners.
Your choices. You can set your browser to refuse or delete cookies (some features may not function properly without them), adjust the ad-personalization settings offered by the advertising platforms, or contact us using the details below. California residents have additional choices described under "Your Privacy Choices."
If you arrive through a referral or partner link, we may set a first-party cookie containing a random identifier so we can credit that referral if you make a purchase within 30 days. This cookie is set and read only by our own site, contains no personal or health information, and is never shared with the referring party or any third party.
7. Your Rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your personal information (subject to legal and medical record retention requirements)
- Opt out of promotional communications at any time — follow the unsubscribe instructions in our marketing emails, reply STOP to any marketing text message, or contact us at the address below (this does not stop transactional messages such as order updates and sign-in codes)
- Request a copy of your medical records (see our HIPAA Notice for the process)
To exercise these rights, contact us at virtual@affinitywholehealth.com.
7a. California Residents (CCPA/CPRA)
California residents have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). California residents may request to: (1) know what personal information we collect and how it is used; (2) delete personal information (subject to HIPAA and other legal retention requirements); (3) correct inaccurate personal information; and (4) opt out of the "sharing" or "sale" of personal information for cross-context behavioral advertising. Submit requests to virtual@affinitywholehealth.com. We do not discriminate against you for exercising these rights, and we will respond to verifiable requests within 45 days. Note: Protected Health Information governed by HIPAA, and medical information governed by California's Confidentiality of Medical Information Act, are exempt from the CCPA.
Your Privacy Choices. We do not sell your personal information for money. We do use third-party analytics and advertising services to measure and improve our advertising, which may be considered "sharing" or a "sale" for cross-context behavioral advertising under California law. To opt out of this activity, you can (1) refuse or delete cookies through your browser settings, (2) adjust the ad-personalization settings offered by the advertising platforms, or (3) email us at virtual@affinitywholehealth.com with the subject "Privacy Choices" and we will process your opt-out request.
7b. Data Retention
We retain medical records and Protected Health Information for a minimum of 7 years from the date of service, or longer as required by the laws of your state of residence. Non-health personal data is retained only as long as necessary for the purposes described in this policy or as required by applicable law. You may request deletion of non-PHI data; however, we are required by law to retain medical records regardless of such requests.
8. Children's Privacy
Our services are intended for adults 18 years of age or older. We do not knowingly collect personal information from individuals under 18. If we become aware that a minor has provided us with personal information, we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page with an updated "Last updated" date and, when required by law, provide additional notice of material changes. Your continued use of our services after changes become effective constitutes acceptance of the updated policy.
10. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
Affinity Direct — Privacy Officer
Email: virtual@affinitywholehealth.com
Affinity Whole Health LLC
Columbus, Ohio