Privacy Policy
Effective Date: September 13, 2025
1) Scope
This Privacy Notice describes how OneDrugRehab collects, uses, discloses, and safeguards information when you use our unbiased directory and education Services.
We are not a HIPAA covered entity and generally do not act as a Business Associate. If we ever process information on behalf of a specific provider under a signed Business Associate Agreement (BAA), that processing will be handled under HIPAA/42 CFR Part 2 as applicable, and the provider’s HIPAA Notice will govern.
2) What we collect
Information you provide
-
Contact details: name, phone, email, city/ZIP, and your preferred time to be contacted.
-
Provider submissions: provider profile data, licensing/accreditation, services, insurance, photos, and administrative contacts.
-
Communications: messages to us, survey responses, or support requests.
Please do not include clinical or medical details (e.g., diagnoses, substances used, prescriptions, lab results) in general site forms.
Information we collect automatically
-
Device/usage: IP address, device/browser type, pages viewed, referral URLs, approximate location, timestamps.
-
Cookies/SDKs for essential operations, analytics, and (where used) advertising measurement. See “Cookies & tracking” below.
Information from third parties
-
Service providers that support hosting, analytics, security, email/SMS, payments, or customer support;
-
If you choose to interact with a provider via our forms, we may receive limited status information (e.g., message delivery success) to maintain consent logs.
3) How we use information
-
To operate, secure, and improve the Services;
-
To transmit your contact information to the specific provider you select so they can contact you about your request;
-
To enforce our Neutral Ranking & Advertising Policy and Terms;
-
To communicate with you (service notices, updates you requested);
-
For analytics and troubleshooting;
-
To comply with law, prevent fraud, and protect our rights.
We do not use your submissions to recommend or steer you to providers.
4) How we disclose information
We may disclose information to:
-
The provider you choose (your contact details only, as displayed in the form you submit);
-
Vendors/service providers under contract (hosting, analytics, email/SMS delivery, payment processors, security);
-
Legal and safety: to comply with law, lawful requests, or to protect rights, safety, or property;
-
Business transfers: in connection with a merger, acquisition, or asset sale (continuing protections will apply).
We do not sell personal information. If we ever engage in cross-context behavioral advertising, we will provide a “Do Not Sell or Share My Personal Information” link and honor opt-out signals where required.
5) SMS/text & email
If you consent to receive communications from a provider, we will pass your contact details and consent log to that provider. If you opt in to OneDrugRehab messages, we may send educational updates or service notices. Message/data rates may apply. Reply STOP to opt out, HELP for help.
6) Cookies & tracking
We use:
-
Essential cookies (security, session management);
-
Analytics (to understand usage and improve the Services);
-
Advertising measurement (only if/when we enable ads; we will provide appropriate disclosures and controls).
You can control cookies via browser settings. On pages that collect contact details, we minimize tracking and avoid embedding pixels that could capture form contents.
7) Data retention
-
Consent logs (e.g., TCPA text/checkbox copy, timestamp, IP, user-agent, provider chosen, page URL) are retained for at least 4 years.
-
Provider business records are retained while the account is active and for a reasonable period thereafter.
-
We keep other information as long as necessary for the purposes described or as required by law.
8) Security
We use reasonable administrative, technical, and physical safeguards (e.g., encryption in transit, access controls, audit logging for provider messages). No system is 100% secure.
If a breach occurs affecting your information, we will notify you consistent with applicable law (and, if applicable, the FTC Health Breach Notification Rule).
9) Your choices & rights
-
Limit submissions: avoid including clinical or medical details in general forms.
-
Marketing opt-outs: follow unsubscribe links or reply STOP to texts.
-
State privacy rights (CA, CO, CT, VA, UT, TX and others where applicable): you may request access, correction, deletion, portability, and to limit/opt out of certain processing (including “sharing” for targeted advertising if used). We will not discriminate for exercising rights.
How to submit a request: email [email protected] with “Privacy Request,” your name, contact method, and the state you reside in. We may verify identity and respond within the time required by law.
If we implement a “Do Not Sell or Share” link, you may use it and/or a Global Privacy Control signal; we will honor it where required.
10) Children’s privacy
The Services are not directed to children under 13 and we do not knowingly collect personal information from them. If you believe a child provided information, contact us and we will delete it.
11) International users
Our Services are intended for use in the United States. If you access from other jurisdictions, you do so at your own risk and consent to U.S. processing.
12) Changes to this Notice
We may update this Privacy Notice. Material changes will be posted with a new effective date. Continued use after an update constitutes acceptance.
13) Contact us
-
Privacy: [email protected]
-
Compliance: [email protected]
-
Support: [email protected]
