Home Privacy Policy
— Privacy policy

Plain-English privacy policy.

What we collect, why we collect it, who we share it with, and how to make us stop. Written by a human, not by a legal-template generator. The full legal version is linked at the end.

EffectiveApr 22, 2026 Last revisedApr 22, 2026 JurisdictionUS · CCPA · GDPR-aligned

The short version

We collect what we need to ship you product, run your account, and improve the site. We don't sell your data. We don't share it with advertisers for retargeting. We don't use it to train third-party AI. If you ever want it deleted, email support and we'll do it within 30 days.

— TL;DR

Order data, account data, basic site analytics, and customer-support history. That's it. No advertising trackers. No data brokers.

1. What we collect

Account & order data

Name, email, shipping address, billing address, phone (if provided), order history, subscription status, and any notes our support team has added to your account during interactions.

Payment data

Card details are tokenized by Stripe and never touch our servers. We see only the last 4 digits, expiration, and brand.

Site analytics

Page views, referrer, device type, approximate location (city level, from IP), and which buttons you click. We use Plausible — a privacy-first analytics tool that does not use cookies and does not track individuals across sessions.

Customer support history

The full text of any chat, email, or text exchange you have with our support team. Retained for 5 years for quality and dispute resolution.

What we do not collect

  • Health information beyond what you tell us in support;
  • Cross-site browsing behavior;
  • Social-media-linked profile data;
  • Biometric or device-level identifiers.

2. How we use it

  • To ship your order — we share your address with FedEx/UPS;
  • To run your account — login, subscription, refill scheduling;
  • To answer your questions — pull up your order history when you contact support;
  • To improve the site — aggregate, anonymous analytics on which pages convert and which don't;
  • To comply with the law — respond to subpoenas, tax obligations, etc.

That's the full list. We don't use it for advertising. We don't use it to "personalize" anything beyond your order history. We don't enrich it with third-party data.

3. Who we share it with

Recipient What we share Why
Stripe Tokenized payment Process the transaction
FedEx / UPS Shipping address, name, phone Deliver the package
Klaviyo Email, name, order history Send order confirmations and (opt-in) marketing
Postmark Email, name Transactional email delivery
Sentry Anonymized error data Site reliability monitoring
Helpscout Email, support history Customer support tooling

All of these are GDPR-compliant data processors with DPAs on file. We do not share with advertising networks, data brokers, AI training providers, or any party for any purpose other than the one listed.

4. Your rights

Regardless of where you live, you can:

  • Access — request a copy of all data we hold on you, in machine-readable form;
  • Correct — fix anything that's wrong;
  • Delete — have everything we hold on you erased, except records we're legally required to keep (tax records, etc.);
  • Port — export your data to another service;
  • Object — opt out of any processing you disagree with.

Email support with the request. We respond within 30 days, usually within 5.

5. Cookies & similar

We use only first-party essential cookies — login session, cart contents, and a small set of preference flags. We do not set third-party advertising cookies. Full breakdown is on the cookies page.

6. Children

Element MD is not intended for users under 21. We do not knowingly collect data from anyone under 21. If you believe we have, email support and we'll delete the account.

7. Changes to this policy

If we change this policy materially, we'll email every active customer at least 30 days before the change takes effect. The current and all prior versions are diffed and dated in our public archive — email support for the redline.

8. Contact our DPO

Our Data Protection Officer is Jordan Asher, JD, MPH (also on our advisor board — see the charter for his disclosures). Reach him at support or by post at the headquarters address on the contact page.

Want a copy of your data?

Email support and we'll send a machine-readable export within 30 days. Usually within 5.