Privacy Policy
Effective date:
August 16, 2026
Introduction
Ozone Wellness LLC, doing business as SignalRx
(“SignalRx,” “we,” “us,” or
“our”), operates
signal-rx.com and the related
account, intake, ordering, support, and telehealth services
(collectively, the “Services”). This Privacy Policy
explains the personal information we collect, how we use and disclose
it, and the choices that may be available to you.
For the website and non-clinical Services described in this Privacy
Policy, the business responsible for personal information is Ozone
Wellness LLC, doing business as SignalRx, 4370 S Tamiami Trail, Suite
151, Sarasota, FL 34231. Medical records and other protected health
information may instead be maintained by the treating professional
entity identified in the applicable Notice of Privacy Practices.
This Privacy Policy applies when you visit our website, create or use
an account, complete an intake or health update, communicate with us,
request a clinical review, place an order, or otherwise use the
Services. It also applies to information we receive from participating
clinicians, pharmacies, payment providers, shipping carriers, and
other service providers in connection with the Services.
By using the Services, you acknowledge the practices described in
this Privacy Policy. If you use the Services for another person, you
represent that you are authorized to act for that person and to
provide their information.
Limitations on Use by Minors
The Services are intended only for adults who are at least eighteen
(18) years old, or any older minimum age required by applicable law.
We do not knowingly provide the Services to, or collect personal
information through the Services from, anyone under eighteen. If you
believe a minor has provided information to us, please contact us
using the information below.
We may retain information when required by law, needed for patient
safety, or maintained as part of a clinical or transaction record
that we are not legally permitted to delete.
Health Information and Clinical Privacy
Some information collected through the Services concerns your health,
medical history, medications, allergies, treatment interests, or
clinical care. Depending on who holds the information and how it is
used, federal or state health-privacy laws may apply.
Licensed healthcare professionals—not Signal-RX software—make
eligibility, prescribing, treatment-approval, medication-order, and
renewal decisions. Signal-RX provides administrative and technology
services that support those clinical and fulfillment activities.
The treating clinical entity’s separate Notice of Privacy Practices
(“NPP”), or a joint notice if participating entities lawfully use one,
describes how HIPAA-regulated clinical information may be used and
disclosed and explains the rights that apply to those records. This
Privacy Policy is a website and services privacy policy. It does not
replace the applicable NPP.
Please use the secure patient portal for sensitive clinical
communications. Do not send medical information, questionnaire
answers, documents, selfies, identification images, photographs, or
other sensitive health information through ordinary email.
Information We Collect
The information we collect depends on how you use the Services. It
may include:
-
Identity and contact information, such as your
name, date of birth, email address, telephone number, account
identifiers, and state of residence. -
Billing and delivery information, such as billing
and shipping addresses, order details, transaction status, payment
confirmation, refunds, and related financial records. -
Health and intake information, such as sex assigned
at birth, height, weight, blood-pressure range, medical conditions,
current medications, allergies, nicotine use, reproductive status,
family and surgical history, treatment interests, and answers you
provide in an initial intake or periodic health update. -
Clinical-workflow information, such as review
status, requests for more information, provider decisions,
treatments approved for ordering, approval dates, and patient
portal or chart status. -
Order and fulfillment information, such as
prescribed-item orders, dispensing-pharmacy routing, shipment
status, carrier, tracking information, and delivery events. -
Communications, including support requests, secure
portal messages, and records showing that account, order, review,
dispatch, or tracking notices were sent. -
Technical information, such as IP address, browser
and device type, access times, security events, server logs, and
necessary cookie or session identifiers. -
Optional measurement and attribution information,
such as saved privacy choices, a Global Privacy Control signal,
random pseudonymous references, limited funnel and transaction
events, a Meta advertising click identifier
(fbclid), a Google advertising click identifier
(gclid), and an opaque measurement token, only as
described in Optional Measurement Choices below.
We collect information directly from you, from your use of the
Services, and from clinicians, clinical entities, payment providers,
pharmacies, carriers, and other service providers involved in your
care or transaction.
Identity Verification
When you accept our Terms and Privacy Policy and pay for an eligible
telehealth consultation, Signal-RX may automatically begin the
current server-to-server identity-verification sequence. We use
identity verification to confirm that the patient and account belong
together, protect patient and account security, prevent fraud, and
support legal and operational requirements. Identity verification
does not make a clinical, prescribing, treatment, or
medication-approval decision.
Signal-RX uses Vouched Identity, Inc. (“Vouched”) for this
sequence. Signal-RX first performs Vouched CrossCheck. If CrossCheck
returns a definite nonmatch, Signal-RX performs one date-of-birth
comparison. If either check verifies the patient, the automatic
identity-verification sequence is complete. If the second check does
not verify the patient, or if an automatic check has a technical,
ambiguous, malformed, timeout, or other operational failure, the
automatic sequence ends and the patient is directed to contact
support.
For these checks, Signal-RX may provide Vouched with the
patient’s name, date of birth, email address, telephone number,
home address, and the Internet Protocol address associated with the
consultation checkout. A server-to-server check may begin after
verified payment and, for a newly created account, after secure
account setup is complete. Signal-RX’s identity-verification
plugin reads the checkout IP address from the WooCommerce order only
when performing the check and does not copy or separately retain the
raw IP address in its own identity-verification tables, logs, URLs, or
scheduler records. Review the
Vouched End User Privacy Statement
and
Vouched End User Terms.
Under the current policy, Signal-RX does not ask a patient to upload
a government-issued identification document, selfie, facial image, or
biometric data for automatic identity verification and does not
start, resume, or retry a photo-ID or Visual verification session.
When automatic verification does not complete, the patient is
directed to contact support. Do not email medical information,
documents, selfies, or identification images to support.
Visual jobs invoked before August 16, 2026 are historical and remain
contained. Signal-RX continues to accept and authenticate an already
authorized signed callback, reconcile the historical job, provide
bounded support, and complete deletion and retention duties without
unlocking or initiating another capture. Historical records may
reflect a government-issued identification document, facial image, or
biometric processing that occurred before the current policy took
effect. The applicable notice is the
Vouched Biometric Privacy Notice.
Signal-RX retains encrypted operational Vouched job and session
references for up to 30 days so that historical verification,
reconciliation, support, and deletion can be completed safely. An
authorized operator requests deletion of the corresponding Vouched
job before those local operational references are removed. Signal-RX
may retain a limited, non-clinical audit record showing the notice
version, consent or acceptance evidence, verification outcome, and
operational events as required for security, compliance, dispute
resolution, and recordkeeping.
How We Use Information
We may use personal information to:
- provide, operate, maintain, and improve the Services;
- create and secure accounts and verify identity or eligibility;
-
collect intake information and make it available to participating
clinicians for human review; -
coordinate clinical reviews, patient-portal activity, prescriptions,
orders, and six-month health updates; -
process payments, prevent fraud, maintain transaction records, and
address refunds or disputes; -
route approved orders to dispensing pharmacies and coordinate
shipping and tracking; -
send necessary account, security, review, decision, order,
fulfillment, support, and tracking communications; -
respond to requests, investigate errors, protect the Services, and
enforce our terms and policies; and -
comply with legal, regulatory, recordkeeping, safety, and
professional obligations.
Routine service emails are designed to be neutral and to avoid
questionnaire answers and treatment names. Sensitive clinical
information should be communicated through the secure patient portal.
Signal-RX does not sell personal or health information. We do not use
questionnaire answers, diagnoses, treatment interests, prescription
details, or clinical records for advertising. Consent-gated
Advertising attribution, when you separately allow it and the
applicable systems are operating, uses only the limited identifiers
and events described below. The Services do not provide automatic
clinical approvals, automatic refills, or automatic medication
shipments.
Cookies and Similar Technologies
We and service providers acting for us use cookies and similar
storage that are necessary to operate and protect the Services. These
technologies support functions such as signing in, maintaining a
secure session, remembering a cart, completing checkout, protecting
against fraud, and keeping account features working.
We do not load Meta or Google advertising pixels or software
development kits, place third-party advertising cookies, or use
browser-based cross-site behavioral advertising trackers on the
Services. If you enable Advertising attribution and the applicable
systems are operating, the consent-gated server-side process described
below may use an advertising click identifier. Your browser does not
contact Meta or Google directly through that process. Some necessary
features, such as secure payment fields, hosted fonts, security tools,
or verification services, may cause your browser to make technical
requests to the provider of that feature.
You can configure your browser to block or delete cookies, but
blocking necessary cookies may prevent account, cart, checkout, or
security features from working. If our tracking practices materially
change, we will update this Privacy Policy and provide any choice or
notice required by law.
Optional Measurement Choices
SignalRx provides a privacy popup and a persistent footer control
labeled “Your Privacy Choices.” These controls let you
separately allow or decline Site measurement and Advertising
attribution, and let you reopen and change those choices. A saved
choice is required before either optional purpose can operate. An
enabled Global Privacy Control signal keeps Advertising attribution
off while leaving Site measurement as a separate choice.
When your choice is successfully saved, SignalRx sets a signed
first-party __Host-srx_consent cookie. It contains the two
choices, policy version, revision, decision source, issue and expiry
times, and a random pseudonymous receipt identifier. It does not
contain a patient name, account, order, form, product, URL, advertising
click identifier, or questionnaire answer. The cookie is host-only,
Secure, HttpOnly, SameSite=Lax, and retained for no more than 180 days.
When the corresponding private storage is configured, SignalRx also
keeps the same decision in an encrypted, HMAC-addressed consent
receipt so the saved choice and exact revision can be rechecked before
optional capture or dispatch.
When Site measurement is enabled, operating, and allowed by your saved
Site choice, SignalRx may record limited funnel and transaction events,
such as a landing, consultation start, intake submission without the
answers, secure handoff, checkout load or submission, verified
payment, refund, or repeat payment. An event may include its type and
time, the website surface, random pseudonymous funnel or attribution
references, and, for payment or refund events, amount, currency, and a
broad payment class such as provider review or medication. SignalRx
may send internal cost and contribution fields to its private AWS
service for reporting, but does not project those internal economics
to an advertising platform. These event records do not include a
questionnaire answer, diagnosis, requested treatment or specific product,
prescription detail, clinical record, payment-card number, or direct
patient or account identity.
When Advertising attribution is enabled, operating, and allowed by
your saved Advertising choice, SignalRx may recognize a Meta
fbclid or a Google gclid in a landing link.
The browser removes a recognized identifier from the visible URL
early and holds the candidate only in a private browser closure.
SignalRx forwards it only after rechecking the saved
same-revision consent, confirming that Global Privacy Control is off,
consuming a one-use ticket, and confirming the private AWS service is
ready. A failed or disallowed candidate is discarded and is never
queued by WordPress.
A permitted identifier is sent once through a fixed-host AWS client
using source-isolated SRX1-signed channels for Meta, Google, and event
traffic. AWS returns an opaque attribution token. SignalRx stores a
private encrypted and HMAC-addressed binding that may connect the
pseudonymous consent subject, funnel, form, account, and order aliases
needed for permitted measurement and withdrawal. It sets only one
first-party measurement cookie, __Host-srx_measure,
containing the opaque token. That cookie is host-only, Secure,
HttpOnly, SameSite=Lax, unavailable to browser JavaScript, and retained
for no more than 90 days.
When the corresponding transport and platform processing are
configured and operating, the fixed-host AWS service may use a Meta
identifier and permitted conversion event data to make a server-side
request to the Meta Conversions API, or use a Google identifier and
permitted conversion event data to make a server-side request to a
Google Ads conversion API. Permitted conversion data may include the
event type and time, pseudonymous references, amount, currency, and
broad payment class described above. Meta and Google may process the
identifier and conversion data under their own terms and privacy
policies. The SignalRx browser and WordPress package contain no Meta
or Google pixel, software development kit, credential, direct platform
host, or direct platform exporter; those platform requests, when
authorized and operating, are server-to-server through the AWS
service.
These optional functions operate only while each applicable
configuration, readiness, saved-consent, and security gate succeeds.
If a function is not configured, ready, or allowed, that Site event,
paid-click capture, AWS dispatch, or platform conversion request does
not occur. Refusal, an invalid or stale consent record, a policy
mismatch, an ambiguous request, or a processing failure turns the
affected optional purpose off. This description of the supported
consent-gated design does not mean that every optional function is
active on every visit.
The signed consent cookie and encrypted consent receipt are retained
for no more than 180 days. The opaque measurement cookie and private
token and link state are retained for no more than 90 days.
Unacknowledged encrypted event or withdrawal deliveries are retained
for no more than 24 hours. Raw browser click candidates are not queued
and are destroyed after capture, refusal, ambiguity, failure,
dismissal, or navigation. Turning Site measurement off suppresses
Site-scope events and removes its local funnel and source state without
revoking separately allowed Advertising attribution. Turning
Advertising attribution off, or enabling Global Privacy Control,
clears __Host-srx_measure, suppresses pending Advertising
events, removes the local token binding after an opaque-token
revocation is durably queued, and requests revocation through AWS.
Withdrawal does not guarantee deletion of a conversion already
accepted by Meta or Google; their retention and deletion practices
also apply. You may also submit a privacy request as described below.
How We Disclose Information
We disclose personal information only as reasonably necessary to
provide the Services, operate our business, protect patients and the
Services, or comply with law. Recipients may include:
-
Participating clinicians and clinical entities that
evaluate intake information, provide care, prescribe when
appropriate, maintain clinical records, or communicate through the
patient portal. -
Operational service providers that support website
hosting, accounts, forms, workflow management, clinical records,
secure portals, email, security, maintenance, and technical support. -
Consent-gated measurement and attribution providers,
including the fixed-host AWS service and, when you allow
Advertising attribution and the applicable systems are operating,
Meta or Google for the limited server-side conversion processing
described in Optional Measurement Choices. -
Payment and financial-service providers that
authorize transactions, prevent fraud, and manage payments,
refunds, disputes, or related services. -
Dispensing pharmacies and shipping carriers that
fill approved prescriptions, prepare packages, deliver orders, and
provide shipment status. -
Professional advisers such as attorneys,
accountants, auditors, insurers, and compliance consultants when
their work requires the information. -
Government authorities and other parties when we
believe disclosure is required by law, legal process, professional
obligations, or is reasonably necessary to prevent fraud, protect
safety, enforce agreements, or protect legal rights. -
Parties to a business transaction involving a
merger, financing, acquisition, restructuring, sale of assets, or
similar event, subject to applicable confidentiality and legal
requirements.
Service providers are permitted to use information for the work they
perform for us and as otherwise allowed by their agreements and
applicable law. De-identified or aggregated information that cannot
reasonably identify an individual may be used or disclosed as
permitted by law.
Transactions and Payment Processing
When you pay for a review, medication, shipping, or another Service,
payment credentials are handled through Easy Pay Direct and its
gateway and processing partners. These providers process the
information needed to authorize and complete the transaction.
Signal-RX receives transaction status, payment identifiers, and
limited information needed to manage the order, accounting, refunds,
disputes, and fraud prevention.
Payment providers maintain their own privacy and security practices.
Their processing of payment credentials is governed by their
agreements, notices, and applicable law.
Your Choices and Privacy Rights
Depending on where you live and subject to legal exceptions, you may
have the right to request access to personal information, obtain a
copy, correct inaccuracies, request deletion, or limit certain uses or
disclosures. You may also have the right to use an authorized agent,
withdraw consent where processing depends on consent, and appeal a
denied request.
Signal-RX does not sell personal information. Depending on the law
that applies, consent-gated disclosure of an advertising identifier
and conversion event to Meta or Google may be treated as
“sharing,” targeted advertising, or another regulated use.
You may decline or withdraw Advertising attribution through Your
Privacy Choices, and we honor Global Privacy Control for that purpose,
as described above. We will provide any additional notice or control
required by applicable law.
To protect your information, we may verify your identity and account
ownership before completing a request. An authorized agent may be
required to provide proof of authority, and we may verify the request
directly with you. We may deny or limit a request where allowed by
law, including when information must be retained for clinical,
transaction, security, legal, or safety purposes. Exercising a privacy
right will not result in unlawful discrimination.
Submit website and account privacy requests to
support@signal-rx.com. If an
appeal right applies, reply to our decision or email us with
“Privacy Appeal” in the subject line. Requests for medical records,
amendments to clinical records, or other rights under an applicable
NPP should be directed to the treating clinical entity through the
secure patient portal or the process stated in that NPP.
Data Retention
We retain information for the period reasonably necessary for the
purpose for which it was collected and to meet clinical,
recordkeeping, transaction, tax, accounting, security, dispute,
contractual, and legal obligations. Retention periods vary by the
type of information and the entity responsible for it.
Clinical charts and prescription records are retained by the
responsible clinical entity under its policies and applicable law.
Intake submissions, questionnaire snapshots, review history, order
records, workflow records, and operational copies may be retained by
Signal-RX and its service providers under applicable schedules,
agreements, and legal requirements.
When information is no longer required, it may be deleted,
de-identified, or securely disposed of, subject to technical
limitations, backup cycles, legal holds, and lawful retention
requirements.
Security
We use reasonable administrative, technical, and physical safeguards
intended to protect personal information. Depending on the system and
information involved, safeguards may include authentication,
role-based access, secure transmission, activity records, restricted
exports, backups, vendor controls, and procedures for investigating
suspected incidents.
No method of storage or transmission is completely secure, and we
cannot guarantee absolute security. You are responsible for protecting
your account credentials and for notifying us if you believe your
account has been compromised.
If an incident requires notification, we will provide notice in
accordance with the law that applies to the affected information and
entity. Depending on the circumstances, obligations may arise under
HIPAA, the FTC Health Breach Notification Rule, state breach or
consumer-health laws, or more than one framework.
Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to the Services,
our practices, or applicable law. We will post the revised policy and
update the effective date. When required, we will provide additional
notice before a material change takes effect.
Contacting Us
For questions about this Privacy Policy or to submit a website or
account privacy request, contact:
4370 S Tamiami Trail, Suite 151
Sarasota, FL 34231
support@signal-rx.com
Please do not include medical details in email. Use the secure patient
portal for clinical questions, medical-record requests, or sensitive
health information.
