Privacy Policy

Effective Date: August 12, 2026
Last Updated: August 12, 2026

Fem Haven Rx (“Fem Haven Rx,” “we,” “us,” or “our”) respects your privacy and is committed to protecting the personal, health, medical, and other information you provide through our website, mobile application, telehealth services, healthcare services, and related products and services. Fem Haven Rx is committed to providing inclusive care for everyone. We do not discriminate based on gender, and our services are open to all individuals, with the option to select the gender identity that best represents you.

Fem Haven Rx currently provides services within the United States.

This Privacy Policy explains what information we collect, how we collect, use, disclose, protect, and retain it, and the rights and choices available to you under applicable federal and state law.

Where HIPAA applies, Protected Health Information (“PHI”) will be handled in accordance with applicable HIPAA Privacy, Security, and Breach Notification requirements. This Privacy Policy does not replace a separate Notice of Privacy Practices provided by a HIPAA-covered healthcare provider.

1. Information We Collect

Depending on how you use our services, we may collect:

Personal and Account Information

  • Name
  • Date of birth or age
  • Email address
  • Telephone number
  • State of residence
  • Mailing, billing, or shipping address
  • Account credentials and authentication information
  • User preferences
  • Identity-verification information
  • Customer-support communications

Health and Medical Information

  • Medical history
  • Medications
  • Allergies
  • Symptoms and health conditions
  • Treatment goals
  • Health and wellness information
  • Laboratory information and results
  • Medical assessments and questionnaires
  • Consultation and provider communications
  • Treatment and prescription information
  • Healthcare service information

Certain health information may constitute PHI when collected, created, received, maintained, or transmitted by or on behalf of a HIPAA-covered entity or business associate.

Telehealth Information

We may collect appointment and provider information, consultation communications, information submitted during appointments, technical information required for telehealth connections, and treatment or follow-up information.

Provider, Pharmacy, and Healthcare Information

We may collect information relating to healthcare providers, pharmacies, prescriptions, laboratories, healthcare organizations, referrals, and treatment services.

Payment Information

We may collect information necessary to process purchases, orders, subscriptions, payments, and transactions. Payment-card information may be processed directly by third-party payment processors. Fem Haven Rx does not intentionally store complete payment-card information when handled by the payment processor.

Device and Technical Information

We may collect device type, operating system, browser type, IP address, application activity, logs, crash and diagnostic information, security information, network information, and authentication/session information.

2. How We Collect Information

We may collect information directly from you when you create or use an account, complete health or medical forms, communicate with providers or support, participate in telehealth, purchase services, or use our website or application.

We may also receive information from healthcare providers, pharmacies, laboratories, payment processors, technology and hosting providers, and other organizations involved in providing requested services.

We use cookies, SDKs, logs, analytics, and similar technologies where necessary for operation, security, performance, troubleshooting, and service improvement.

We collect information in accordance with applicable law and required consent or authorization.

3. How We Use Information

We may use information to:

  • Create and administer accounts
  • Provide healthcare and telehealth services
  • Facilitate provider consultations
  • Determine service or treatment eligibility
  • Review health information for requested services
  • Communicate treatment, prescription, laboratory, order, and follow-up information
  • Coordinate with providers, pharmacies, laboratories, and healthcare organizations
  • Process payments and fulfill orders
  • Verify identity and authenticate accounts
  • Provide customer support
  • Maintain and improve services
  • Maintain security and prevent fraud or unauthorized access
  • Troubleshoot and monitor service performance
  • Comply with legal, regulatory, healthcare, accounting, and recordkeeping requirements
  • Respond to lawful governmental or legal requests
  • Perform other activities permitted by applicable law

Where information constitutes PHI, uses and disclosures will be limited to those permitted or required by HIPAA and applicable law.

4. HIPAA and Protected Health Information

Where HIPAA applies, PHI may be used or disclosed for purposes including:

  • Treatment
  • Payment
  • Healthcare operations
  • Providing requested healthcare services
  • Coordination with providers, pharmacies, and laboratories
  • Healthcare administration
  • Legal and regulatory compliance
  • Fraud and security investigations
  • Other purposes permitted or required by law

Where HIPAA requires authorization for a particular use or disclosure, we will obtain the appropriate authorization unless another legal basis applies.

5. Sharing Information and Business Associates

We may disclose information to organizations necessary to provide or support our services, including:

  • Licensed healthcare providers and organizations
  • Pharmacies and laboratories
  • Fulfillment organizations
  • Payment processors
  • Technology and hosting providers
  • Telehealth providers
  • Communications providers
  • Customer-support providers
  • Security and monitoring providers
  • Other service providers acting on our behalf

Service providers must use information only for authorized purposes and maintain appropriate security and confidentiality protections.

Where HIPAA applies and a service provider qualifies as a business associate, Fem Haven Rx will enter into a Business Associate Agreement (“BAA”) where required.

Applicable vendor agreements may address confidentiality, security, access controls, incident reporting, breach notification, PHI handling, retention, deletion, and subcontractor responsibilities.

6. Health Information, Advertising, and Sale

Fem Haven Rx does not sell PHI or consumer health data.

We do not use PHI for advertising or marketing where authorization is legally required unless the required authorization has been obtained.

We do not use health information for unrelated advertising purposes.

Where applicable law imposes additional restrictions on the sale, sharing, targeted advertising, or other use of consumer health data, we will comply with those requirements.

We will not intentionally provide PHI to analytics, advertising, or similar third parties unless permitted or required by law and appropriate contractual and privacy protections are in place.

7. Security Safeguards

We maintain administrative, technical, and physical safeguards designed to protect personal information and PHI from unauthorized access, acquisition, use, disclosure, alteration, or destruction.

Depending on the information and applicable requirements, safeguards may include:

  • Encryption in transit and at rest
  • Access and authentication controls
  • Role-based and least-privilege access
  • Administrative access restrictions
  • Security monitoring and audit logging
  • Security assessments and vulnerability management
  • Backup and recovery controls
  • Incident-response procedures
  • Employee access controls
  • Vendor security assessments
  • Secure development practices

No electronic storage or transmission system can be guaranteed to be completely secure.

8. Data Retention

We retain information only as reasonably necessary to provide services, maintain accounts, provide healthcare, process transactions, maintain required medical and healthcare records, prevent fraud, maintain security, resolve disputes, and comply with legal, regulatory, accounting, and recordkeeping requirements.

Different information may have different retention periods.

HIPAA does not establish a single universal medical-record retention period; applicable federal and state laws may impose different requirements.

When information is no longer required for a legitimate purpose, it will be securely deleted, destroyed, or de-identified.

9. Account and Data Deletion

You may request deletion of your Fem Haven Rx account and eligible personal information.

Account deletion:
https://femhavenrx.com/delete-account

Where account creation is available through our mobile application, users may initiate account deletion from within the application. Identity verification may be required.

After verification, we will delete or de-identify information that we are not legally or operationally required to retain.

Eligible requests will generally be completed within 30 days after verification unless a different period is required or permitted by law.

Certain information may continue to be retained, including medical records, PHI, prescription and treatment records, transaction records, security and fraud-prevention information, regulatory or accounting records, and other information required or permitted by law.

Retained information remains subject to applicable privacy and security protections.

10. HIPAA Privacy Rights

Where HIPAA applies, individuals may have rights to:

  • Request access to certain PHI
  • Request amendment of certain PHI
  • Request restrictions on certain uses or disclosures
  • Request confidential communications
  • Request an accounting of certain disclosures

HIPAA rights may be subject to legal limitations and exceptions.

You may submit a privacy complaint to Fem Haven Rx or, where applicable, the U.S. Department of Health and Human Services Office for Civil Rights.

Exercising a HIPAA privacy right will not result in retaliation where prohibited by law.

11. United States State Privacy Rights

Additional privacy rights may apply depending on your state of residence, the information involved, our relationship with you, and applicable statutory exemptions.

Depending on applicable law, rights may include:

  • Access to personal information
  • Confirmation of processing
  • Correction of inaccurate information
  • Deletion
  • Data portability
  • Opting out of certain sales or sharing
  • Opting out of targeted or cross-context behavioral advertising
  • Opting out of certain profiling
  • Limiting certain uses of sensitive personal information
  • Appeal rights
  • Authorized-agent requests
  • Non-discrimination for exercising applicable rights
  • Additional consumer-health-data rights

These rights are not necessarily available to every person or every category of information.

Certain information may be exempt, including information subject to HIPAA, medical-record laws, or other federal or state exemptions.

Where a state law provides additional rights that apply to your information, Fem Haven Rx will provide those rights as required by law.

12. Consumer Health Data

Certain states protect consumer health data even when information is not PHI under HIPAA.

Consumer health data may include information relating to health conditions, diagnoses, symptoms, medications, allergies, medical history, healthcare services, treatments, prescriptions, healthcare providers, telehealth services, and health-related interests or inferences.

Fem Haven Rx will handle consumer health data in accordance with applicable federal and state requirements.

Where applicable law requires consent or authorization for collecting, sharing, selling, or otherwise processing consumer health data, we will obtain the required consent or authorization and provide applicable rights and controls.

Where applicable law provides rights to withdraw consent, access, delete, or otherwise control consumer health data, we will provide the applicable mechanism.

13. California Privacy Rights

If you are a California resident and applicable California privacy law applies to you, you may have additional rights, including rights to:

  • Know/access personal information
  • Correct personal information
  • Delete personal information
  • Obtain information about collection and use
  • Obtain information about categories of recipients
  • Opt out of certain sales or sharing
  • Limit certain uses of sensitive personal information
  • Receive non-discriminatory treatment for exercising applicable rights

California law contains exemptions for certain information regulated under federal healthcare laws and other applicable laws. Where an exemption applies, the corresponding right may not apply.

14. State Consumer Health Privacy Laws

Certain states have specific consumer-health-data requirements concerning consent, collection, sharing, sale, deletion, consumer requests, vendor agreements, security, and retention.

Fem Haven Rx will comply with applicable state requirements.

Nothing in this Privacy Policy is intended to limit a privacy right provided by applicable state law.

15. Apple App Privacy

For applications distributed through the Apple App Store, Fem Haven Rx provides applicable Apple privacy disclosures concerning:

  • Data categories collected
  • Purposes of collection
  • Whether data is linked to a user’s identity
  • Whether data is used for tracking
  • Retention and deletion practices
  • Third-party service providers that may process information

Apple App Privacy disclosures are intended to remain consistent with this Privacy Policy and our actual application and supporting-service data practices.

We will update applicable Apple disclosures when material data-practice changes occur.

16. Google Play Data Safety

For applications distributed through Google Play, Fem Haven Rx provides applicable Google Play Data Safety disclosures concerning:

  • Data collected
  • Data shared with third parties
  • Purposes for collection or sharing
  • Whether collection is optional or required
  • Data security practices
  • Encryption practices
  • Account and data deletion
  • Other disclosures required by Google Play

We will update Google Play Data Safety disclosures when material changes occur to our data collection, sharing, processing, security, or deletion practices.

Fem Haven Rx will also complete applicable Google Play health-related declarations for healthcare or health-related functionality.

17. Mobile Account Deletion

Users may initiate account deletion from within the Fem Haven Rx mobile application where account creation is supported.

Users may also submit a deletion request through:

https://femhavenrx.com/delete-account

Identity verification may be required.

After verification, eligible personal information will be deleted or de-identified, subject to legally required or permitted retention.

18. Exercising Privacy Rights

To exercise an applicable privacy right:

Email: support@femhavenrx.com
Phone: +1 913-218-9238

For account deletion:

https://femhavenrx.com/delete-account

We may verify your identity before processing a request to protect against unauthorized access, modification, or deletion.

We will respond within the period required by applicable law and provide an appeal process where required.

Where permitted by state law, you may designate an authorized agent to submit a privacy request on your behalf. We may require documentation confirming the agent’s authority.

19. Children’s Privacy

Fem Haven Rx services are intended for individuals legally permitted to use the applicable healthcare services.

We do not knowingly collect personal information from children in violation of applicable law.

Where services involve minors, we will follow applicable consent, healthcare, privacy, and parental or guardian requirements.

20. Data Processing Within the United States

Fem Haven Rx currently provides services within the United States.

Information may be processed by Fem Haven Rx and its service providers as necessary to provide, secure, maintain, and support our services.

Where applicable law imposes requirements on processing or transfer of personal information, Fem Haven Rx will comply with those requirements.

21. Breach and Security Incident Response

Fem Haven Rx maintains procedures designed to detect, investigate, respond to, and remediate security incidents.

If a security incident involving personal information or PHI requires notification under applicable federal or state law, Fem Haven Rx will provide notification as required.

Where HIPAA applies, applicable HIPAA Breach Notification requirements will be followed.

22. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes to our services, technology, privacy practices, federal or state law, healthcare regulations, or contractual requirements.

When material changes are made, we may provide notice through our website, application, email, or another appropriate method.

The “Last Updated” date identifies when this Privacy Policy was most recently revised.

23. Contact Us

If you have questions about this Privacy Policy, personal information, PHI, privacy rights, or deletion requests, contact:

Fem Haven Rx

Email: support@femhavenrx.com
Phone: +1 913-218-9238
Website: femhavenrx.com

Account and data deletion:
https://femhavenrx.com/delete-account

Important Notice About Compounded Medications: Some programs offered through Fem Haven Rx include compounded medications prepared by a licensed U.S. compounding pharmacy pursuant to a valid prescription from a licensed provider. Compounded medications are not FDA-approved and have not been reviewed by the FDA for safety, effectiveness, or quality. They are not generic versions of any FDA-approved drug. These statements have not been evaluated by the Food and Drug Administration. Programs are not intended to diagnose, treat, cure, or prevent any disease.