Oxiline RX // Legal

Privacy Policy

Effective July 24, 2026 · v2026-07-24

Your privacy is a baseline, not a feature. This Policy describes what we collect, how we use it, who we share it with, and the rights and choices you have.

1. Overview and scope

This Privacy Policy explains how Oxiline RX Corp. (“Oxiline,” “we,” “us”) collects, uses, discloses, and protects information when you visit our websites, use our patient portal, or participate in the Oxiline RX telehealth program (together, the “Services”). It applies to information we handle as a business. Your clinical care is delivered by US-licensed clinicians through our clinical partner, MD Integrations, which acts as the platform of record for your protected health information (“PHI”); PHI is governed by our HIPAA Notice of Privacy Practices and applicable law, and to the extent this Policy conflicts with the HIPAA Notice as to PHI, the HIPAA Notice controls.

The Services are intended for individuals in the United States who are 18 years of age or older. By using the Services, you agree to this Policy.

2. Information we collect

We collect the following categories of information:

  • Account & contact information you provide, such as your name, email address, shipping address, and phone number.
  • Eligibility pre-screen answers you enter on our site (for example, your state and general goal). Sensitive health inputs used to estimate eligibility (such as height, weight, and contraindication questions) are processed on your device to guide the flow and are not transmitted to us as identified health records.
  • Health & medical information you provide during the clinical intake and in messages with your care team, which is collected and stored by MD Integrations in a HIPAA-compliant environment — not on Oxiline’s servers.
  • Payment information, which is collected, processed, and stored by our payment processor (Stripe). We receive limited transaction details (such as the last four digits of your card, charge status, and billing history) but never full card numbers.
  • Order & fulfillment information, such as your membership status, shipment status, and tracking details.
  • Usage & device data collected automatically, such as pages viewed, approximate location derived from IP address, browser and device type, and interactions with the Services. Health-related fields and pages are redacted from analytics before processing (see Section 3).
  • Communications you send to us, such as support emails.

We do not knowingly collect information from anyone under 18 (see Section 11), and we do not collect precise geolocation or biometric identifiers.

3. Cookies and analytics

We use cookies and similar technologies that are necessary to operate the Services (for example, to keep you signed in and to secure your session), and first-party analytics to understand how the Services are used and to improve them. Our analytics are designed with health privacy in mind: pages and fields that could reveal health information are redacted before analytics processing, and we do not use analytics events to build health profiles of identified individuals.

We do not sell your personal information, and we do not disclose health information for third-party advertising or cross-context behavioral advertising. You can control cookies through your browser settings; disabling necessary cookies may prevent parts of the Services (such as sign-in) from working.

4. How we use information

We use the information described above to:

  • provide, operate, secure, and improve the Services and your patient portal;
  • connect you with a US-licensed clinician for evaluation and treatment, and coordinate fulfillment with licensed pharmacies;
  • process membership and medication payments and prevent fraud;
  • communicate with you about your care, orders, account, and — only with your consent or as permitted by law — promotions;
  • enforce our Terms of Service; and
  • comply with legal, regulatory, and recordkeeping obligations.

5. How we share information

We share information only as described below:

  • Clinical partners and pharmacies — MD Integrations, the clinicians who treat you, and the licensed pharmacies that fill and ship your prescriptions, as needed to evaluate you and fulfill your treatment.
  • Service providers that support our operations — for example, payment processing (Stripe), email delivery, hosting, analytics, and shipping — under contracts that limit their use of your information to providing services to us.
  • Legal & safety — where required by law, subpoena, or other legal process, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of you, us, or others.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy and applicable law (including legal limits on the transfer of health information).

We do not sell your personal information or your health information, and we do not share it for cross-context behavioral advertising. We have not sold or shared personal information in this manner in the preceding 12 months.

6. Protected health information (PHI)

Your clinical records, messages with your care team, and prescription details are created and maintained by MD Integrations and your treating clinicians in a HIPAA-compliant environment, under appropriate business associate arrangements. Oxiline is designed so that PHI is not stored on our own servers. When Oxiline handles limited information on behalf of the clinical program (for example, order status needed to run your membership), it does so under those arrangements. Our handling of PHI is described further in our HIPAA Notice of Privacy Practices.

7. How we protect information

We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information we handle, including encryption in transit, access controls, and segregation of clinical data with our clinical partner. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; if we learn of a breach affecting your information, we will notify you and regulators as required by law.

8. Data retention

We retain personal information for as long as needed to provide the Services, run your membership, and meet legal, regulatory, tax, and recordkeeping requirements, after which we delete or de-identify it. Medical records are retained by our clinical partner and your treating clinicians in accordance with applicable medical-records retention laws, which typically require retention for a number of years after your last treatment.

9. Your privacy rights and choices

Depending on where you live, state privacy laws (including in California, Colorado, Connecticut, Texas, Virginia, and other states) may give you the right to:

  • know and access the personal information we hold about you, and receive a portable copy;
  • correct inaccurate personal information;
  • delete personal information, subject to legal exceptions (for example, records we must keep by law);
  • opt out of the sale of personal information, sharing for targeted advertising, and certain profiling — noting that we do not sell personal information or share it for targeted advertising; and
  • not be discriminated against for exercising any of these rights.

To exercise these rights, email support@oxilinerx.com with the subject line “Privacy Request.” We will verify your identity (for example, by confirming control of the email associated with your account) before acting on a request, and we will respond within the time required by applicable law. You may use an authorized agent where permitted; we may require proof of authorization. If we deny a request, you may appeal by replying to our decision, and — depending on your state — you may also contact your state attorney general. We honor opt-out preference signals such as Global Privacy Control where required by law.

Requests involving your medical records are handled by our clinical partner as the record holder under HIPAA; we will route such requests or you may make them directly as described in the HIPAA Notice. You may opt out of marketing communications at any time via the unsubscribe link in any marketing email or by replying STOP to any marketing text; transactional care and account messages will continue.

10. Consumer health data

Some states (including Washington, under the My Health My Data Act, and Nevada) provide specific rights over “consumer health data” collected by businesses that are not otherwise covered by HIPAA. To the extent we collect any consumer health data covered by those laws, we collect and use it only as described in this Policy and with any consent those laws require, we do not sell it, and residents of those states may exercise the rights those laws provide — including access, deletion, and withdrawal of consent — by contacting support@oxilinerx.com.

11. Children’s privacy

The Services are for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us personal information, contact us at support@oxilinerx.com and we will delete it.

12. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will update the effective date and version above and notify you as required by law (for example, by email or a notice in the patient portal) before the changes take effect. Changes are not retroactive.

13. Contact us

Questions, concerns, or requests about this Policy or your information? Contact Oxiline RX Corp. at support@oxilinerx.com.