Privacy Policy
Last updated: April 7, 2026
1. Overview
2. Information We Collect
Personal Information: Name, email, phone number, date of birth, address, payment information.
Health Information (PHI): Medical history, current medications, allergies, health conditions, treatment records, prescription information, lab results, physician notes.
Usage Data: IP address, browser type, pages visited, session duration (collected automatically).
3. How We Use Your Information
- To provide telehealth consultations and peptide therapy services
- To process prescriptions through licensed pharmacies
- To manage your subscription and billing
- To communicate about your treatment and orders
- To comply with legal and regulatory requirements
- To improve our services (using de-identified data only)
4. HIPAA Compliance
We implement administrative, technical, and physical safeguards to protect your PHI, including:
- End-to-end encryption for data in transit and at rest
- Role-based access controls limiting PHI access to authorized personnel
- Regular security audits and vulnerability assessments
- Business Associate Agreements (BAAs) with all third-party service providers handling PHI
- Employee training on HIPAA requirements
5. Information Sharing
We do not sell your personal information. We may share your information with:
- Healthcare Providers: Licensed physicians who provide consultations
- Pharmacies: Licensed compounding pharmacies that fulfill prescriptions
- Payment Processors: Stripe for secure payment processing
- Technology Providers: Supabase (database), Vercel (hosting) — under BAAs
- Legal Requirements: When required by law, court order, or government regulation
6. Your Rights Under HIPAA
You have the right to:
- Access your PHI and request copies of your medical records
- Request corrections to your PHI
- Request restrictions on certain uses of your PHI
- Request confidential communications
- Receive an accounting of disclosures of your PHI
- File a complaint if you believe your privacy rights have been violated
7. Data Retention
8. Data Security
We use industry-standard security measures including:
- 256-bit AES encryption for data at rest
- TLS 1.3 encryption for data in transit
- Multi-factor authentication for administrative access
- Regular penetration testing
- SOC 2 Type II compliant infrastructure (Supabase, Vercel)
9. Cookies and Tracking
10. Children's Privacy
11. California Privacy Rights (CCPA)
12. Changes to This Policy
13. Contact Us
For privacy inquiries, HIPAA requests, or complaints:
VAULT Men's Health / Read Ranch LLC
Email: support@vaultmenshealth.com
HIPAA Privacy Officer: privacy@vaultmenshealth.com