PRIVACY POLICY
What data we collect from providers and practices, why we collect it, who we share it with, how long we keep it, and the privacy rights you can exercise.
Effective: July 25, 2026 · Last updated: July 25, 2026
At a glance
- Who we serve. We sell compounded topical anesthetic preparations to licensed healthcare and aesthetic providers only. This is a business-to-business site.
- No patient data. We do not collect patient-identifiable health information from your practice, and we are not acting as a HIPAA covered entity or business associate for ordinary ordering data.
- We never sell your personal information and we do not share it for cross-context behavioral advertising.
- We use our own first-party analytics — no third-party advertising or cross-site tracking cookies.
- We honor opt-out preference signals, including Global Privacy Control (GPC) and "Do Not Track," automatically.
- You have rights to access, correct, delete, and opt out. See Your California privacy rights and Other US state rights, or email privacy@medicainenumb.com.
1. Who we are & scope
MediCaine (“MediCaine,” “we,” “us,” or “our”) sells compounded topical anesthetic preparations to licensed healthcare and aesthetic providers through medicainenumb.com. MediCaine is a brand operated by ALWAYS Rx Compounding Pharmacy (“ALWAYS Rx”), the licensed compounding pharmacy that is the parent company and data controller for this and its related brands. This policy also covers our sibling brand alwaysnumb.com, which serves the aesthetic / med-spa vertical and is operated by the same company through a shared back office. When we say “our sites” we mean both.
This policy explains how we handle personal information collected through our sites, by email or phone, and in the course of fulfilling orders. It applies to the licensed providers, practice staff, and site visitors who interact with us. Because the California B2B exemption under the CCPA expired on January 1, 2023, we treat our business buyers as “consumers” with full privacy rights, and this policy is written accordingly.
Not a HIPAA notice. We collect provider-side ordering information, not patient records. We are not a HIPAA covered entity or business associate with respect to ordinary sales and fulfillment data, and we do not collect protected health information (PHI) about your patients. Do not send us patient-identifiable information; if you do, we will treat it as confidential and delete it when it is no longer needed.
2. Information we collect
We collect only what we need to verify your eligibility to purchase, compound and ship your order, support you, keep required records, and secure and improve our sites. The table below maps each category of personal information (using California’s statutory categories) to where it comes from, why we use it, who we disclose it to, and how long we keep it.
| Category of personal information | Examples | Sources | Business purpose | Disclosed to | Retention |
|---|---|---|---|---|---|
| Identifiers | Practice name, contact name, email, phone, shipping address, account/order IDs, IP address, device identifiers | You (order & contact forms); automatically from your browser/server logs | Create and fulfill orders; communicate about orders; account security; fraud prevention | Cloudflare (hosting/DB), Resend (email), shipping carrier | Order records: 3+ years (see §8). Logs: up to 12 months. |
| Professional / employment information | NPI number, state license number and state, optional DEA number, provider type, practice affiliation | You; public NPI Registry (verification) | Verify you are a licensed provider eligible to purchase; label compounded preparations; regulatory recordkeeping | Cloudflare (DB); NPI Registry is a public government lookup source | Retained with the order record (3+ years, see §8) |
| Commercial information | Products/formulations ordered, sizes, quantities, auto-reorder preference, order history, notes/special instructions | You (configurator & order form) | Compound and ship your order; support; reorder reminders; recordkeeping | Cloudflare (DB), Resend (email) | 3+ years (see §8) |
| Financial information | Payment-processor token and last-four/brand of card; billing name | Our PCI-DSS payment processor (returned after you pay) | Process payment; match payments to orders; refunds | iPOSPays / Dejavoo (processor) | Per PCI-DSS and tax/accounting rules. We never receive or store full card numbers or CVV. |
| Internet / electronic activity | Pages viewed, configurator steps, buttons/links clicked, referring source, UTM campaign parameters, approximate device type | Automatically, via our first-party analytics (see §11) | Understand how our sites are used; measure and improve them; measure our own marketing | Not disclosed to third parties; stored in our own systems | Up to 24 months, then aggregated or deleted |
| Geolocation (coarse) | Approximate country/region derived from IP at the network edge | Automatically (Cloudflare edge) | Security, fraud prevention, coarse analytics. We do not collect precise (GPS-level) location. | Cloudflare | Up to 24 months (with analytics) |
| Inferences | Lead/lifecycle stage, product interest, likelihood to reorder | Derived from the above | Prioritize support and relevant, non-third-party outreach about products you can lawfully buy | Not disclosed to third parties | Until you opt out or we delete the underlying records |
We do not knowingly collect Social Security numbers, government ID numbers, racial or ethnic data, biometric data, precise geolocation, or the contents of your private communications.
3. Provider credentials (NPI, DEA, state license)
Because we sell prescription-grade compounded preparations, we must confirm that a buyer is a licensed provider. We collect your NPI number, state license number and state, and (optionally) DEA number as professional credentials for three purposes: (1) verifying your eligibility to purchase, (2) labeling the compounded preparation with the correct provider information, and (3) satisfying pharmacy-board and controlled-substance recordkeeping obligations. NPI numbers may be verified against the public NPI Registry maintained by CMS.
We treat these credentials as confidential ordering information. We do not sell them and we do not disclose them for advertising. We keep them with the associated order record for the retention period described in §8.
4. How we use your information
- Verify provider eligibility (including NPI Registry checks) before an order is approved and shipped
- Compound the formulation you ordered, labeled with your verified provider information
- Ship the compounded preparation to your verified practice address
- Send order confirmations, shipping notifications, payment links, and reorder reminders
- Provide operational support and answer questions about your order or formulation
- Prevent fraud and abuse and secure our sites and systems
- Maintain the regulatory records required by state boards of pharmacy and the DEA
- Measure and improve our sites and our own first-party marketing
- Comply with law and enforce our terms
We do not use your personal information for automated decisions that produce legal or similarly significant effects about you, and we do not use it for cross-context behavioral advertising.
5. How we disclose your information & our subprocessors
We share the minimum information necessary with a small, fixed set of service providers (also called “processors” or “subprocessors”) who are contractually bound to use it only to perform services for us. Unlike many policies in our industry, we name ours:
| Subprocessor | Function | Data it may process | Region |
|---|---|---|---|
| Cloudflare | Site hosting, edge security, database (D1), and Zero Trust access control for our admin | All site and order data at rest | United States / global edge |
| iPOSPays / Dejavoo | PCI-DSS compliant payment processing (hosted payment page) | Card data (they process it; we receive only a token), billing name, amount | United States |
| Resend | Transactional and notification email delivery | Recipient email, name, order details in the message | United States |
| Shipping carrier | Delivery of your order | Recipient name, practice shipping address, phone | United States |
| NPI Registry (CMS) | Public government lookup used to verify an NPI | NPI number you provide is checked against public records | United States |
We may also disclose personal information (a) to comply with law, subpoenas, or lawful government requests; (b) to protect our rights, safety, and property, or those of others; and (c) in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor this policy or notify you of any material change. We will update the list above when we add or change a subprocessor; the current version always governs.
6. Sale / share status & opt-out preference signals
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA and comparable state laws. We have not sold or shared personal information in the preceding 12 months. We also do not disclose the personal information of anyone we know to be under 16 for money or other valuable consideration.
Global Privacy Control (GPC) and Do Not Track. We honor opt-out preference signals. If your browser or a browser extension sends a Global Privacy Control (GPC) signal or a “Do Not Track” signal, we automatically treat it as a valid request to opt out of any sale or sharing and we exclude your activity from marketing use. Because these signals are applied automatically at the browser level, a signal that we honor is reflected in how our first-party analytics flags and processes your visit. If you also provide an email or account identifier, we will apply your opt-out to that identifier as well; contact privacy@medicainenumb.com to confirm or extend it.
Because we do not sell or share personal information, exercising these signals does not reduce the products, prices, or service you receive.
7. Sensitive personal information
“Sensitive personal information” has a specific legal meaning (for example, Social Security or government ID numbers, precise geolocation, account log-in plus password, racial or ethnic origin, health, biometric, or sex-life data). We do not collect sensitive personal information in the ordinary course of business, and we do not use or disclose any such information for purposes that would trigger the “Limit the Use of My Sensitive Personal Information” right. Note that professional credentials such as NPI, DEA, and state-license numbers are not classified as “sensitive personal information” under California law — they are identifiers / professional information, and we handle them as described in §3. Payment-card details that could qualify as sensitive are handled entirely by our PCI-DSS payment processor; we never receive the full card number or CVV.
8. How long we keep your information
We keep each category of personal information only as long as needed for the purpose it was collected, or as long as the law requires — whichever is longer. Our retention is not open-ended; the main drivers are:
- Order, compounding, and provider-verification records — at least 3 years. California pharmacy law (16 CCR §1735.3) requires compounding records to be kept in a readily retrievable form for a minimum of three years, and DEA rules require controlled-substance acquisition/disposition records to be kept for three years. Order records, the credentials tied to them, and NPI-verification records are retained on this basis.
- Payment records — per PCI-DSS guidance and applicable tax/accounting requirements.
- Analytics and coarse geolocation — up to 24 months, after which data is aggregated or deleted.
- Server/security logs — up to 12 months.
- Marketing preferences and inferences — until you opt out or ask us to delete, subject to the record-keeping floors above.
When a retention period ends and no legal hold applies, we delete or de-identify the information.
9. Your California privacy rights (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know / access the specific pieces and categories of personal information we have collected, the sources, the purposes, and the categories of recipients
- Delete personal information we hold about you, subject to legal exceptions (including the pharmacy/DEA recordkeeping obligations in §8)
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information (we do neither — see §6)
- Limit the use of sensitive personal information (we do not collect or use it in a way that triggers this — see §7)
- Non-discrimination — we will not deny you products, charge a different price, or provide a different quality of service for exercising your rights. We do not offer financial incentives in exchange for personal information.
How to exercise your rights
Submit a request by emailing privacy@medicainenumb.com or by using our privacy request form. Because we operate exclusively online and have a direct relationship with our customers, we are not required to maintain a toll-free number; email and our online request channel are the two ways to reach us.
- Verification. To protect your information, we will verify your request by matching the details you provide (such as email, order number, and practice information) against our records before acting on a know, delete, or correct request.
- Authorized agents. You may use an authorized agent to submit a request. We may ask the agent for proof of your written permission and may still ask you to verify your identity directly.
- Timing. We will confirm receipt within 10 business days and respond substantively within 45 days. If we need more time, we will tell you and may extend once by up to an additional 45 days.
- Appeal. If we decline your request, you may appeal by replying to our decision or emailing privacy@medicainenumb.com with “Appeal” in the subject line.
Shine the Light. California’s “Shine the Light” law (Civil Code §1798.83) lets California residents ask about personal information shared with third parties for their direct marketing. We do not share personal information with third parties for their own direct marketing.
10. Other US state privacy rights
If you are a resident of another state with a comprehensive privacy law (including Virginia, Colorado, Connecticut, Texas, Utah, Oregon, Montana, and others in effect in 2026), you have comparable rights to access, correct, delete, and obtain a portable copy of your personal data, to opt out of targeted advertising, sale, and certain profiling, and to appeal a denied request. We honor recognized universal opt-out mechanisms (including GPC) as described in §6. To exercise any of these rights, or to appeal, email privacy@medicainenumb.com. If we deny your appeal and you are in a state that provides it, you may contact your state Attorney General. Residents of the EU/UK who contact us may exercise applicable GDPR/UK-GDPR rights through the same address.
11. Cookies & first-party analytics
We use our own first-party analytics to understand how visitors use our sites and to improve them. This uses a randomly generated identifier stored in your browser (localStorage) and records page views, the pages and steps you interact with, your approximate location (country/region derived from your IP — we do not store your full IP address), your device type, and the referring source or campaign that brought you to the site (for example, UTM parameters). This data stays in our own systems.
We do not use third-party advertising networks, cross-site tracking cookies, or ad pixels. As explained in §6, we honor your browser’s Global Privacy Control and “Do Not Track” signals: when one is present, your activity is flagged and excluded from marketing use. You can also clear the identifier at any time by clearing your browser storage. This information is never sold, and you may request access to or deletion of it under §9.
12. Payment processing
Payments are handled on a hosted page by our PCI-DSS compliant processor, iPOSPays / Dejavoo. You enter your card details directly with the processor. We receive only a payment token and limited transaction metadata (such as the card brand, last four digits, and amount). We never receive or store your full card number or CVV.
13. Security & data location
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including encryption in transit (HTTPS/HSTS), security headers and a content-security policy, access control on our admin through Cloudflare Zero Trust, least-privilege data sharing, and monitoring. Our data is stored in the United States. No method of transmission or storage is perfectly secure, but we work to protect your information and to promptly address issues. See our Security & Data Handling page for technical detail on our controls.
14. Children
Our sites and products are intended for licensed professionals and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a minor has provided us information, contact us and we will delete it.
15. Business-customer data processing addendum (DPA)
If your organization requires a data processing addendum or a completed vendor security questionnaire before purchasing, we are glad to provide one. Email privacy@medicainenumb.com with your request.
16. Changes to this policy & version history
We review this policy at least once a year and update it when our practices change. Material changes will be posted here with a new “Last updated” date, and where a change affects information we already hold about you, we will take reasonable steps to notify you.
| Date | Summary of change |
|---|---|
| Jul 25, 2026 | Full rewrite to CCPA/CPRA structure: added the collection grid, named subprocessor list, GPC/opt-out-signal handling, per-category retention with pharmacy/DEA legal basis, sensitive-PI clarification, other-US-state rights and appeal, and version history. |
| Jun 3, 2026 | Initial published privacy policy. |
17. How to contact us
For any privacy question or to exercise a right:
- Email: privacy@medicainenumb.com (or hello@medicainenumb.com)
- Phone: (310) 889-0733
- Mail: ALWAYS Rx Compounding Pharmacy, 2001 Westwood Blvd, Los Angeles, CA 90025
- Phone: 310-877-7795
MediCaine is a brand operated by ALWAYS Rx Compounding Pharmacy, 2001 Westwood Blvd, Los Angeles, CA 90025. This policy governs medicainenumb.com and alwaysnumb.com.