Last updated and effective: October 2, 2026.
Taweret LLC, 8 The Green, Suite B, Dover, DE 19901, United States, is responsible for the consumer health data described here. Contact ![]()
This policy supplements our Privacy Policy. It explains protections for consumer health data under Washington’s My Health My Data Act, Nevada’s consumer health data law and Connecticut’s privacy law. The described protections also form our store policy for other US customers.
Health data and its sources
Consumer health data is personal information linked or reasonably linkable to you that identifies or reveals health status or health-related activity. It can include information suggesting that you are seeking a product to address pain, sleep, mobility or another health concern, even without a diagnosis.
We collect health-related product selections and order or return details; symptoms, reactions, limitations and other health information you choose to include in support or safety reports; health-related content submitted in a review; and identifiers that connect these details to you, such as your name, email, order number or device information recorded in necessary security logs.
Sources are you, your activity on our store, people acting on your behalf, and service providers or fulfilment partners supplying information about your order or complaint. We do not purchase health profiles from data brokers or use precise location to identify visits to healthcare facilities.
Collection, use and consent
We use this information to supply the product or service you request, administer an order or return, answer a question, investigate a safety concern and meet applicable legal requirements. We handle it in order-management, support and restricted safety records, with access limited to people who need it for those purposes.
We obtain affirmative consent before collection or sharing when required. Under Washington and Nevada law, processing strictly necessary to provide a product or service you requested can be permitted without separate consent. That exception does not authorize unrelated advertising. Where Connecticut law requires consent to sensitive-data processing, we obtain it before that processing. Consent to sharing is separate from consent to collection where required. We explain the categories, purpose, recipients and withdrawal method when asking.
We do not sell consumer health data, use it for targeted advertising, or send it to advertising platforms. This includes health-revealing page URLs, product identifiers, search queries, purchase events and matched customer lists. Nonessential advertising and analytics tracking is blocked on health-related journeys. We do not allow advertising partners to collect consumer health data through our store for tracking across websites.
Information shared and recipients
We share necessary product and order details and related identifiers with Shopify, order-processing and payment services, suppliers, fulfilment partners and carriers to complete your request. A carrier normally receives delivery details rather than the health content of a support conversation. Customer-support providers handle the relevant correspondence; review providers handle content you choose to publish. A public review can disclose health information to anyone who reads it, so please avoid including private medical details.
Where necessary for a product safety investigation or legally required report, we share relevant product, event and contact details with the responsible manufacturer or distributor, qualified advisers and regulators. We require appropriate confidentiality and processing restrictions for service providers. These transfers remain subject to the consent and legal limitations described above.
We do not share consumer health data with affiliated companies. We do not give advertising companies access to health data for their own purposes. Necessary service providers process only the information permitted for the relevant service.
Retention and deletion
We keep health details in order and return records for up to 24 months after the order or case closes, and health-related support correspondence for up to 24 months after closure, unless you exercise an applicable deletion right earlier. We remove unnecessary health details from tax and accounting records rather than retaining an entire health history with those records.
Where we are legally responsible for maintaining adverse-event records for dietary supplements, we keep the required record for six years after receipt. Required cosmetic adverse-event records are kept for six years after the record is created, or three years where the qualifying small-business rule applies. Other records subject to a specific legal reporting or preservation obligation are restricted to that obligation. These exceptions apply only to the extent permitted by the applicable health privacy law.
For a valid deletion request, we delete covered data and notify the processors and other recipients required by law. For Nevada requests, we delete active records and notify recipients within 30 days after authentication; recipients have their own 30-day deletion duty after notification. Health data in archived or backup systems is deleted within six months after authentication, and sooner when technically available. Backups awaiting deletion are not used for other purposes.
Your rights and requests
You can ask whether we collect, share or sell your consumer health data, obtain access, request correction, withdraw consent, ask us to stop collection or sharing, and request deletion. You can request a list of recipients; for Washington data this includes the third parties and affiliates and an active email address or other online contact method for them. We extend the same recipient-contact assistance to other US customers.
Email
with “Health data request.” An authorized representative may contact us with appropriate authority. We will authenticate requests using reasonably necessary information and arrange an appropriate way to provide sensitive records. You do not need a new account. Requests are normally free, subject only to legally permitted rules for manifestly unfounded, excessive or repetitive requests.
We respond within 45 calendar days of receipt. Where permitted and reasonably necessary, we may extend once by up to 45 days, explaining why within the initial period. Washington counts from receipt without pausing for authentication. Nevada’s statutory response period runs from authentication, but our receipt-based service commitment is shorter; its separate 30-day active-record deletion deadline still applies. Connecticut requests follow the 45-day response rule in our Privacy Policy.
Consent withdrawal is available by email at any time. For Connecticut consent-based sensitive processing, we act as soon as practicable and within 15 days. Withdrawal does not authorize us to continue an activity prohibited by another applicable law. Some requested services may be unavailable if we cannot use information genuinely needed to provide them, but we do not penalize you for exercising a right.
Appeals and complaints
If we decline a request, reply to the decision or email us with “Health data appeal.” We do not impose a fixed filing cutoff. We provide a written appeal decision within 45 calendar days after receipt, including the reasons. This meets Washington and Nevada’s 45-day appeal periods and is shorter than Connecticut’s 60-day period.
If we deny an appeal, we will provide the relevant complaint route. You can contact the Washington Attorney General, Nevada Attorney General or Connecticut Attorney General. Your ability to contact a regulator does not depend on first completing our appeal process.
Changes
We update the date above when this policy changes. We provide prominent notice of material changes and direct notice where required. Before collecting or sharing new categories, adding recipients or using data for a new purpose that requires fresh consent, we make the required disclosures and obtain that consent.