Privacy Policy
Effective July 24, 2026 · v2026-07-24
Your privacy is a baseline, not a feature. This Policy describes what we collect, how we use it, who we share it with, and the rights and choices you have.
1. Overview and scope
This Privacy Policy explains how Oxiline RX Corp. (“Oxiline,” “we,” “us”) collects, uses, discloses, and protects information when you visit our websites, use our patient portal, or participate in the Oxiline RX telehealth program (together, the “Services”). It applies to information we handle as a business. Your clinical care is delivered by US-licensed clinicians through our clinical partner, MD Integrations, which acts as the platform of record for your protected health information (“PHI”); PHI is governed by our HIPAA Notice of Privacy Practices and applicable law, and to the extent this Policy conflicts with the HIPAA Notice as to PHI, the HIPAA Notice controls.
The Services are intended for individuals in the United States who are 18 years of age or older. By using the Services, you agree to this Policy.
2. Information we collect
We collect the following categories of information:
- Account & contact information you provide, such as your name, email address, shipping address, and phone number.
- Eligibility pre-screen answers you enter on our site (for example, your state and general goal). Sensitive health inputs used to estimate eligibility (such as height, weight, and contraindication questions) are processed on your device to guide the flow and are not transmitted to us as identified health records.
- Health & medical information you provide during the clinical intake and in messages with your care team, which is collected and stored by MD Integrations in a HIPAA-compliant environment — not on Oxiline’s servers.
- Payment information, which is collected, processed, and stored by our payment processor (Stripe). We receive limited transaction details (such as the last four digits of your card, charge status, and billing history) but never full card numbers.
- Order & fulfillment information, such as your membership status, shipment status, and tracking details.
- Usage & device data collected automatically, such as pages viewed, approximate location derived from IP address, browser and device type, and interactions with the Services. Health-related fields and pages are redacted from analytics before processing (see Section 3).
- Communications you send to us, such as support emails.
We do not knowingly collect information from anyone under 18 (see Section 11), and we do not collect precise geolocation or biometric identifiers.
4. How we use information
We use the information described above to:
- provide, operate, secure, and improve the Services and your patient portal;
- connect you with a US-licensed clinician for evaluation and treatment, and coordinate fulfillment with licensed pharmacies;
- process membership and medication payments and prevent fraud;
- communicate with you about your care, orders, account, and — only with your consent or as permitted by law — promotions;
- enforce our Terms of Service; and
- comply with legal, regulatory, and recordkeeping obligations.
6. Protected health information (PHI)
Your clinical records, messages with your care team, and prescription details are created and maintained by MD Integrations and your treating clinicians in a HIPAA-compliant environment, under appropriate business associate arrangements. Oxiline is designed so that PHI is not stored on our own servers. When Oxiline handles limited information on behalf of the clinical program (for example, order status needed to run your membership), it does so under those arrangements. Our handling of PHI is described further in our HIPAA Notice of Privacy Practices.
7. How we protect information
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information we handle, including encryption in transit, access controls, and segregation of clinical data with our clinical partner. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; if we learn of a breach affecting your information, we will notify you and regulators as required by law.
8. Data retention
We retain personal information for as long as needed to provide the Services, run your membership, and meet legal, regulatory, tax, and recordkeeping requirements, after which we delete or de-identify it. Medical records are retained by our clinical partner and your treating clinicians in accordance with applicable medical-records retention laws, which typically require retention for a number of years after your last treatment.
9. Your privacy rights and choices
Depending on where you live, state privacy laws (including in California, Colorado, Connecticut, Texas, Virginia, and other states) may give you the right to:
- know and access the personal information we hold about you, and receive a portable copy;
- correct inaccurate personal information;
- delete personal information, subject to legal exceptions (for example, records we must keep by law);
- opt out of the sale of personal information, sharing for targeted advertising, and certain profiling — noting that we do not sell personal information or share it for targeted advertising; and
- not be discriminated against for exercising any of these rights.
To exercise these rights, email support@oxilinerx.com with the subject line “Privacy Request.” We will verify your identity (for example, by confirming control of the email associated with your account) before acting on a request, and we will respond within the time required by applicable law. You may use an authorized agent where permitted; we may require proof of authorization. If we deny a request, you may appeal by replying to our decision, and — depending on your state — you may also contact your state attorney general. We honor opt-out preference signals such as Global Privacy Control where required by law.
Requests involving your medical records are handled by our clinical partner as the record holder under HIPAA; we will route such requests or you may make them directly as described in the HIPAA Notice. You may opt out of marketing communications at any time via the unsubscribe link in any marketing email or by replying STOP to any marketing text; transactional care and account messages will continue.
10. Consumer health data
Some states (including Washington, under the My Health My Data Act, and Nevada) provide specific rights over “consumer health data” collected by businesses that are not otherwise covered by HIPAA. To the extent we collect any consumer health data covered by those laws, we collect and use it only as described in this Policy and with any consent those laws require, we do not sell it, and residents of those states may exercise the rights those laws provide — including access, deletion, and withdrawal of consent — by contacting support@oxilinerx.com.
11. Children’s privacy
The Services are for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us personal information, contact us at support@oxilinerx.com and we will delete it.
12. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will update the effective date and version above and notify you as required by law (for example, by email or a notice in the patient portal) before the changes take effect. Changes are not retroactive.
13. Contact us
Questions, concerns, or requests about this Policy or your information? Contact Oxiline RX Corp. at support@oxilinerx.com.