LEGAL
Privacy Policy
Last updated: August 24, 2026
This policy explains what personal information MedVita Wellness collects when you use medvitawellness.com, why we collect it, who else handles it, and what you can ask us to do with it. It is written to describe what our systems actually do rather than to cover every possibility.
MedVita Wellness LLC is the company responsible for your personal information — the data controller, in the language of privacy law. We sell and ship only within the United States.
If anything here is unclear, email Orders@MedvitaWellness.com and we will answer.
1. WHAT WE COLLECT
We do collect personal information. Specifically:
- Account details. Your name, email address and phone number. Your password is never stored — we keep only a bcrypt hash of it, which cannot be reversed into the password you chose.
- Shipping details. Recipient name, phone number, street address, city, state, postal code and country, taken at checkout and stored against the order.
- Order history. What you ordered, the sizes and quantities, the amount charged, any discount or referral code applied, and the order’s status and shipping dates.
- Payment information. Handled entirely by our payment processor. Card numbers are sent from your browser straight to Stripe and never reach our servers — see section 4.
- Chat messages. Whatever you type into the chat widget. These are sent to a third-party AI provider to generate a reply — see section 5.
- Support and complaints. If you use the contact form, the name, email address and message you submit.
- Email sign-ups and waitlists. Your email address if you join the newsletter or ask to be told when a product is back in stock.
- Reviews. Your rating and words. Only your first name is ever published alongside a review.
- Affiliate applications. If you apply to the affiliate programme: your name, email, country, audience size, the social handles or website you choose to give us, and what you write in the motivation field.
- Analytics and device data. Pages viewed, approximate location, browser and device type, and referring links, collected through Google Analytics — see section 7.
- Your IP address, in hashed form only. When you register we store a one-way HMAC-SHA256 hash of your IP address, truncated, and used solely to spot self-referral abuse. We do not keep the IP address itself. Our hosting provider and analytics provider do see your real IP as part of serving the site.
2. WHY WE COLLECT IT
- To fulfil your order. Name, address and phone go to whoever ships it. A phone number is required because a courier holding a parcel resolves it with a phone call.
- To run your account. Email and password hash let you sign in and see your order history, loyalty points and referral link.
- To take payment. Passed to our processor to authorise and settle the charge.
- To support you. Order confirmations, shipping updates, password resets, refund notices, and answers to anything you ask us.
- To send marketing, only if you asked for it. Marketing email requires you to tick an unticked box at registration. Transactional email about an order you placed is sent regardless, because it is part of the order.
- To prevent fraud and abuse. The hashed IP and prior-purchase checks stop someone referring themselves for a reward.
- To run the loyalty and affiliate programmes. Points, referral attribution and affiliate commission all require linking activity to an account.
- To understand and improve the site. Aggregate analytics about which pages people use.
3. WHO ELSE HANDLES YOUR DATA
We do not sell your personal information, and we do not share it with anyone for their own marketing. We do rely on the following companies to run the business. Each one is listed with what it actually receives.
Runs the website and its servers. Sees the ordinary contents of web requests — your IP address, browser and the pages you request — in its logs.
Their privacy policy →Stores our PostgreSQL database, which holds your account, orders, shipping addresses, reviews, loyalty points and affiliate records. Hosted in the United States (AWS, Ohio region).
Their privacy policy →Our payment platform. Creates the payment for your order through its connected Stripe account and confirms whether it settled. Receives the order amount and payment identifiers.
Their privacy policy →Receives your card details directly from your browser, plus billing details you enter, Apple Pay or Google Pay tokens, and enough device information to screen for fraud. We never see or store your card number.
Their privacy policy →Sends our email. Receives your email address, your name, and the contents of the message — which for an order confirmation includes your order details and shipping address.
Their privacy policy →Receives the messages you type into the chat widget in order to generate a reply. See section 5 — this one deserves its own explanation.
Their privacy policy →Receives page views and the device, browser, approximate location and referrer information that come with them, tied to a cookie-based identifier rather than to your name.
Their privacy policy →Receives page views via the Meta Pixel, and — after an order is paid — the order total and currency only. It is NOT told what you bought: no product name, no compound, no category, no quantity. We do not send Meta your email, name, phone number or address in any form, hashed or otherwise. The only identifiers are Meta's own cookies and the IP address and browser your request arrives with. Nothing is sent at all if your browser sends a Global Privacy Control signal.
Their privacy policy →Email sent to Orders@MedvitaWellness.com is delivered to a Microsoft-hosted mailbox, so anything you write to us is stored there.
Their privacy policy →We also share your name, shipping address and the items you ordered with third-party fulfilment and shipping partners, so that your parcel can be packed and delivered. They receive what is needed to ship the order and nothing more: no prices, no payment information and not your email address.
We use Google Analytics 4 to measure how the site is used. We do not use it to build advertising audiences or to personalise ads across your devices, unless Google Signals is enabled on the account — a Google setting that, when switched on, links activity to signed-in Google users for advertising purposes. If we ever enable it, this policy will be updated to say so before we do.
4. PAYMENTS
Card details never touch our servers. When you pay, your browser sends the card number straight to Stripe and we receive back only a confirmation that the payment succeeded. The same is true of Apple Pay and Google Pay, which use your browser’s payment feature and hand Stripe a token rather than a card number.
What we do store is the order itself: what you bought, what it cost, the shipping address, and identifiers we can use to look the payment up if you contact us about it.
5. THE CHAT WIDGET USES AI
The chat assistant on this site is powered by Anthropic’s Claude. Anything you type into it is sent to Anthropic, a third-party company in the United States, so that a reply can be generated. That includes anything personal you choose to put in the box.
Two things worth knowing. First, please do not type payment card details, passwords or medical information into the chat. It is not the place for them, and we will never ask you for them there. Second, we do not store your chat messages in our own database — they are passed to Anthropic to answer and are not written to our records. Anthropic’s own handling of them is governed by its privacy policy.
If you would rather not use it, simply do not open the chat — nothing is sent to Anthropic unless you send a message.
6. REFERRALS AND AFFILIATES
If you arrive through someone’s referral link — a URL ending ?ref=CODE — we store that code in a cookie called mv_ref for 30 days so the person who referred you still gets credit if you register later. The cookie holds only the code. The first code wins: it is never overwritten, so nobody can take credit for a referral that was already attributed.
When you register or place an order using a referral or affiliate code, we record which code was used against your account and your order. That is how a referrer earns their reward and an affiliate earns commission.
If you apply to be an affiliate, we keep your application, and if it is approved we create a discount code in your name and a private dashboard link showing your sales and balance. Affiliate commission is calculated on the product subtotal only, never on shipping.
7. COOKIES, ANALYTICS AND HOW TO OPT OUT
What we set, and why:
- next-auth session cookies — keep you signed in. Essential; the site cannot log you in without them.
- mv_ref — referral attribution, 30 days, as described above.
- mv_admin — set only for our own staff signing into the admin area. Never set for customers.
- mv_research_ack — remembers that you completed researcher verification, so you are not asked again on every page. It is a strictly necessary first-party cookie and stores only two things: the version of the research-use terms you were shown, and the date and time you confirmed. It holds no name, email, address, IP or identifier of any kind. It lasts up to 180 days, after which you are asked to confirm again, and it is reset sooner if the terms change. It operates independently of advertising consent, analytics consent and Global Privacy Control, and is never used for tracking, profiling or advertising.
- Google Analytics cookies — measure site usage.
Two things people often assume are cookies but are not: your cart is kept in your browser’s own local storage and never sent to us until you check out, and the age confirmation is kept in session storage that clears when you close the tab.
To opt out of analytics: install Google’s browser opt-out add-on, or block cookies for this site in your browser settings. Blocking analytics does not affect shopping. Blocking the session cookies will stop you signing in.
Global Privacy Control. If your browser or an extension sends a Global Privacy Control (GPC) signal, we treat it as a valid request to opt out of any sharing of your personal information. You do not need to contact us separately if you send that signal.
We do not show a cookie consent banner. The cookies we set are the ones described above — sign-in, referral attribution and analytics — and you can block any of them in your browser.
8. HOW LONG WE KEEP IT, AND HOW TO GET IT DELETED
We keep your account and its order history for as long as your account exists, because that is what lets you look up what you ordered. Some records outlive an account by necessity — an order we shipped is a financial record.
How long we keep things:
- Order and transaction records — about seven years, because tax and accounting rules require us to be able to produce them.
- Closed or deleted accounts — personal data is removed within 90 days of the request, apart from the order records above.
- Support and complaint email — up to two years, so we can pick up the thread if you write again.
- Newsletter and waitlist sign-ups — until you unsubscribe, or until the thing you asked to be told about has happened.
- Affiliate applications we declined — up to one year.
To ask for deletion, email Orders@MedvitaWellness.com from the address on your account and say what you want removed. We will confirm it is you before acting. There is currently no self-service delete button in your account — a request by email is the way to do it, and we handle it by hand.
Some things we may have to keep even after a deletion request: records of a completed purchase where tax or accounting rules require it, and a minimal note that a deletion was carried out. Data already sent to the companies in section 3 is subject to their own retention — deleting your account here does not by itself erase it from their systems, though each of them offers its own route to request that.
9. YOUR RIGHTS
Whoever and wherever you are, you can ask us to:
- Show you what we hold — a copy of your account, orders and addresses.
- Correct it — you can edit most of it yourself in your account; email us for the rest.
- Delete it — see section 8.
- Stop marketing email — use the unsubscribe link in any marketing email, or ask us. You will still get transactional email about orders you have placed.
- Opt out of analytics — see section 7.
- Opt out of sale or sharing — there is nothing to opt out of. We do not sell personal information and we do not share it for anyone else’s advertising. If that ever changes, this policy will say so before it does.
To exercise any of these, email Orders@MedvitaWellness.com from the address on your account.
We will respond to a verifiable request within 45 days. If we need longer we will tell you why before that deadline passes. We may have to confirm your identity first — usually by checking that the request comes from the email address on the account — because handing someone else’s data to whoever asks would be the greater harm.
If you are a California resident, you also have the right to know what we collect and why, to request a copy, to ask for deletion, and to opt out of any sale or sharing of your personal information. We will never charge you more, give you worse service, or treat you differently for exercising any of these rights.
10. SECURITY
The site is served only over HTTPS. Passwords are stored as bcrypt hashes, never as text. Password reset links are stored as hashes too, are single-use, and expire. Payment card details never reach our servers at all. Access to the admin area is password-protected and separate from customer accounts.
No system is perfect, and we would rather say that than claim otherwise. In the event of a data breach affecting personal information, we will notify affected users and the relevant authorities as required by applicable law, without undue delay.
11. AGE
This site is for adults aged 21 or over. You confirm your age before entering and again when you create an account. We do not knowingly collect information from anyone under 21. If you believe a minor has given us their information, email us and we will remove it.
12. WHERE YOUR DATA IS HELD
Everything is held in the United States. Our database is hosted there, and every company in section 3 is US-based or processes data in the US. We sell and ship only within the United States and do not knowingly serve customers in the EU or the UK, so your information is not transferred out of the country.
13. CHANGES
If we change this policy we will update the date at the top. If a change materially affects how we use information we already hold, we will say so rather than leaving you to spot the diff.
14. CONTACT
MedVita Wellness · Orders@MedvitaWellness.com · medvitawellness.com
For anything about an order, the same address reaches us. See also our Terms of Service, Shipping Policy and Refund Policy.