Legal

Privacy Policy

Last updated August 24, 2026 · Effective August 24, 2026

This policy explains what SureTides Health, Inc. ("SureTides," "we," "us") collects when you visit our site, apply for a wholesale account, or use the provider portal — and how we use, share, and protect it. We collect business and professional information to verify providers and fulfill orders. We do not sell personal information.

01Scope of this policy

This policy covers information collected through the SureTides public website, the wholesale application form, and the provider portal. It does not cover the practices of third parties we link to, or information you handle as a healthcare provider about your own patients.

02Information we collect

Information you give us

  • Applicant and contact details — first and last name, work email, phone number, role
  • Practice information — practice name, business legal name, practice type, state, shipping addresses
  • Credentialing information — medical director NPI, license details, tax identification or EIN
  • Order information — products ordered, quantities, order history, delivery addresses
  • Correspondence — messages you send to your account specialist or support

Information collected automatically

  • Device and browser type, operating system, and general location inferred from IP address
  • Pages viewed, referring pages, and interactions with the site and portal
  • Portal session and authentication activity
What we do not collect

We do not ask for or want patient-identifiable health information. Please do not include patient names, records, or protected health information in application forms, emails, or support messages.

03How we use information

We use information to:

  • Review applications and verify licensure, NPI, and practice legitimacy
  • Create and administer provider accounts and portal credentials
  • Process, fulfill, ship, and invoice orders, and provide COA documentation
  • Provide account support, clinical documentation, and pharmacist consultation
  • Detect and prevent fraud, diversion, unauthorized access, and abuse
  • Comply with legal, tax, recordkeeping, and recall obligations
  • Improve the site, catalog, and portal, and measure whether they work
  • Send account, order, compliance, and — where permitted — relevant product communications

04Legal bases

Where a legal basis is required, we rely on: performance of a contract (administering your account and orders), legitimate interests (verification, fraud prevention, service improvement), legal obligation (tax, recordkeeping, product safety), and consent where we ask for it, such as for optional marketing email.

05How we share information

We share information only as needed to run the business:

RecipientPurpose
Payment processorAuthorizing and settling payments; storing payment credentials on our behalf
Fulfillment & carriersCold-chain packing, shipping, and delivery tracking
Verification servicesConfirming license status, NPI, and business identity
Technology vendorsHosting, email delivery, analytics, and customer support tooling
Professional advisorsLegal, accounting, and audit support
AuthoritiesWhen required by law, subpoena, or to address safety and recall obligations
SuccessorsIn connection with a merger, financing, acquisition, or sale of assets

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

06Payment data

Card and bank details are collected and stored by our PCI-compliant payment processor. SureTides receives only limited information — such as card brand, last four digits, expiration, and authorization result — which is what appears in your saved payment methods. We never see or store full card numbers.

07Cookies & analytics

We use a small number of cookies and similar technologies to keep you signed in, remember preferences, and understand how the site is used. Essential cookies are required for the portal to function. Analytics cookies help us see which pages providers actually find useful.

You can block or delete cookies in your browser settings; blocking essential cookies will break portal sign-in. Where required, we honor Global Privacy Control signals.

08Data retention

We keep information only as long as needed for the purpose it was collected, then delete or de-identify it.

  • Application records — retained for the life of the account, and for declined applications a limited period for fraud prevention and reapplication context
  • Order, invoice, and lot records — retained as long as required by tax, product-safety, and recall obligations
  • Portal access logs — retained on a rolling basis for security investigation
  • Marketing preferences — retained until you opt out, plus a record of the opt-out itself

09Security

We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption in transit, access controls, credential separation, and vendor review. No system is perfectly secure; if a breach affects you we will notify you as required by law.

You are responsible for protecting your portal credentials and for telling us promptly if you suspect unauthorized access.

10Your choices & rights

Depending on where you are, you may have the right to:

  • Access the personal information we hold about you
  • Correct information that is inaccurate or out of date
  • Delete information, subject to our legal retention obligations
  • Obtain a portable copy of information you provided
  • Opt out of marketing email at any time
  • Not be discriminated against for exercising a privacy right

To make a request, email jordan@suretides.com. We will verify your identity and respond within the timeframe the applicable law requires. Note that order, invoice, and product-safety records generally cannot be deleted while retention obligations apply.

11State privacy rights

Residents of states with comprehensive privacy laws — including California, Colorado, Connecticut, Texas, and Virginia — have the rights described above. Californians may also request the categories of information collected, the purposes for collecting it, and the categories of recipients; those categories are listed in sections 02 and 05. We do not sell personal information or share it for targeted advertising, so there is no opt-out to exercise for those activities. You may designate an authorized agent to submit a request on your behalf.

12Not a HIPAA covered entity

SureTides supplies products to practices; we are not a healthcare provider, health plan, or clearinghouse, and we are not a HIPAA covered entity or business associate in our wholesale relationship with you. Information you submit to us is business and professional information about your practice, not patient health information — please keep it that way.

13International transfers

We operate in the United States and process information there. If you access the site from outside the U.S., you understand that your information will be transferred to and processed in the U.S., where privacy laws may differ from those in your jurisdiction.

14Children

The site and portal are intended for licensed professionals and are not directed to anyone under 18. We do not knowingly collect information from children. If you believe a minor has provided information, contact us and we will delete it.

15Changes to this policy

We may update this policy as our practices or the law change. Material changes will be posted here with a revised date and, for active accounts, communicated by email.

Privacy requests and questions

Email us and we will route your request to the right person. Please include the practice name on your account.

jordan@suretides.com