This policy explains what SureTides Health, Inc. ("SureTides," "we," "us") collects when you visit our site, apply for a wholesale account, or use the provider portal — and how we use, share, and protect it. We collect business and professional information to verify providers and fulfill orders. We do not sell personal information.
This policy covers information collected through the SureTides public website, the wholesale application form, and the provider portal. It does not cover the practices of third parties we link to, or information you handle as a healthcare provider about your own patients.
We do not ask for or want patient-identifiable health information. Please do not include patient names, records, or protected health information in application forms, emails, or support messages.
We use information to:
Where a legal basis is required, we rely on: performance of a contract (administering your account and orders), legitimate interests (verification, fraud prevention, service improvement), legal obligation (tax, recordkeeping, product safety), and consent where we ask for it, such as for optional marketing email.
We share information only as needed to run the business:
| Recipient | Purpose |
|---|---|
| Payment processor | Authorizing and settling payments; storing payment credentials on our behalf |
| Fulfillment & carriers | Cold-chain packing, shipping, and delivery tracking |
| Verification services | Confirming license status, NPI, and business identity |
| Technology vendors | Hosting, email delivery, analytics, and customer support tooling |
| Professional advisors | Legal, accounting, and audit support |
| Authorities | When required by law, subpoena, or to address safety and recall obligations |
| Successors | In connection with a merger, financing, acquisition, or sale of assets |
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Card and bank details are collected and stored by our PCI-compliant payment processor. SureTides receives only limited information — such as card brand, last four digits, expiration, and authorization result — which is what appears in your saved payment methods. We never see or store full card numbers.
We use a small number of cookies and similar technologies to keep you signed in, remember preferences, and understand how the site is used. Essential cookies are required for the portal to function. Analytics cookies help us see which pages providers actually find useful.
You can block or delete cookies in your browser settings; blocking essential cookies will break portal sign-in. Where required, we honor Global Privacy Control signals.
We keep information only as long as needed for the purpose it was collected, then delete or de-identify it.
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption in transit, access controls, credential separation, and vendor review. No system is perfectly secure; if a breach affects you we will notify you as required by law.
You are responsible for protecting your portal credentials and for telling us promptly if you suspect unauthorized access.
Depending on where you are, you may have the right to:
To make a request, email jordan@suretides.com. We will verify your identity and respond within the timeframe the applicable law requires. Note that order, invoice, and product-safety records generally cannot be deleted while retention obligations apply.
Residents of states with comprehensive privacy laws — including California, Colorado, Connecticut, Texas, and Virginia — have the rights described above. Californians may also request the categories of information collected, the purposes for collecting it, and the categories of recipients; those categories are listed in sections 02 and 05. We do not sell personal information or share it for targeted advertising, so there is no opt-out to exercise for those activities. You may designate an authorized agent to submit a request on your behalf.
SureTides supplies products to practices; we are not a healthcare provider, health plan, or clearinghouse, and we are not a HIPAA covered entity or business associate in our wholesale relationship with you. Information you submit to us is business and professional information about your practice, not patient health information — please keep it that way.
We operate in the United States and process information there. If you access the site from outside the U.S., you understand that your information will be transferred to and processed in the U.S., where privacy laws may differ from those in your jurisdiction.
The site and portal are intended for licensed professionals and are not directed to anyone under 18. We do not knowingly collect information from children. If you believe a minor has provided information, contact us and we will delete it.
We may update this policy as our practices or the law change. Material changes will be posted here with a revised date and, for active accounts, communicated by email.
Email us and we will route your request to the right person. Please include the practice name on your account.
jordan@suretides.com