This Privacy Policy describes how Get Tides PLLC, an Arizona professional limited liability company doing business as Tides ("Get Tides", "Tides", "we", "us", or "our"), collects, uses, shares, and protects information when you visit our website, create an account, complete a health assessment, purchase a compound protocol, or otherwise interact with our services (together, the "Services").
Health information you provide to us in connection with a clinical encounter is also governed by our HIPAA Notice of Privacy Practices, which takes precedence over this Privacy Policy to the extent of any conflict for Protected Health Information (PHI).
We share your information only as described here. Everywhere we refer to a service-provider role, we mean a category of vendor bound by written agreement to use your information solely to provide the service to us. We name categories, not specific companies, so that a routine vendor change does not silently make this Policy inaccurate. A current list of the specific vendors within each category is available on request.
Your health intake and related information is shared with the licensed clinician reviewing your case for the purpose of providing treatment.
We engage vendors in the following categories to operate the Services. Every vendor is limited to using your information solely for the services they provide to us. HIPAA treats these relationships differently depending on what the vendor does; the current status of each Business Associate Agreement (BAA) is disclosed in our HIPAA Notice of Privacy Practices. Two categories (compounding pharmacy and payment processor) are exempt from the BAA requirement by regulation. Two categories (transactional email and hosting) require a BAA under HIPAA; we describe the current status of each in the HIPAA Notice.
| Category | Purpose | Data processed |
|---|---|---|
| Compounding pharmacy | Prescription dispensing and fulfillment | Name, mailing address, prescribed compound, dose, quantity |
| Payment processor | Card tokenization, authorization, capture | Card token, billing details, transaction records |
| Transactional email provider | Account, order, and care-related email delivery | Email address, message content related to your account and care |
| Hosting and database infrastructure | Application hosting, database storage, request logs | Account data, health intake, order records, request logs, IP address |
| Clinical AI service provider | Non-PHI decision-support helpers for our clinical team | De-identified context only: age, state, compound, dose, cycle, clinical facts. Direct identifiers (name, email, date of birth, phone, address, patient / account / order IDs) are stripped from the request before it leaves our infrastructure. Enforced at the code boundary and by a build-time check. |
We may disclose information when we believe in good faith that disclosure is required to comply with law, a valid subpoena or court order, to protect the rights, property, or safety of Tides, our patients, or others, or as otherwise permitted by HIPAA.
If Tides is involved in a merger, acquisition, financing, reorganization, or sale of all or a portion of its assets, your information may be transferred as part of that transaction. Any successor entity will continue to be bound by this Privacy Policy and our HIPAA Notice, or will give you the opportunity to opt out.
We will share your information for purposes beyond those listed above only with your explicit consent.
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. We do not use your health information for marketing by third parties. We do not load third-party fonts, analytics, or advertising trackers on any page of the Services where health information is displayed, entered, or inferable from the URL. The typefaces used on our website are self-hosted; there is no font-CDN connection to a third party on those pages. We do not send identifiable health information to any third-party AI service, whether for training, inference, or any other purpose.
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) gives you the right to know what personal information we collect, to request deletion, to correct inaccurate information, to data portability, to opt out of sale or sharing (which we do not do), and to limit the use of sensitive personal information. Sensitive personal information under the CPRA includes health information. To exercise any of these rights, contact us at privacy@gettides.com. We respond within 45 days as required by law. We will not discriminate against you for exercising your rights. Health information that is also PHI is governed by HIPAA and, where applicable, the California Confidentiality of Medical Information Act, not the CCPA.
If you reside in a state with a comprehensive consumer privacy law (including Colorado, Connecticut, Delaware, Florida, Illinois, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia), you may have rights similar to those above, which may include the right to access, correct, delete, port, or limit certain uses of your personal information. Contact us at privacy@gettides.com or the address below to exercise them.
We retain your information for as long as your account is active and as needed to provide the Services. After you request account closure, we retain medical records for the longer of (a) the retention period required by the law of the state in which the prescribing clinician is licensed (typically seven to ten years, longer for minors) and (b) the period required by any applicable federal regulation. Records required by law to be retained will not be deleted before the applicable retention period elapses. Non-medical records such as marketing preferences are retained only as long as needed for their purpose.
We rely on our hosting and database provider's encryption at rest, and industry-standard transport-layer encryption (TLS) for data in transit. Access to production data is role-based and scoped to the smallest surface required for each service. Access from the application to protected tables enforces row-level policies at the database layer. We evaluate every service provider that handles patient information for privacy and security posture and require a written data-processing agreement. For vendors that meet the HIPAA definition of Business Associate, a Business Associate Agreement is required; the current status of each such agreement is disclosed in our HIPAA Notice of Privacy Practices. No method of electronic transmission or storage is perfectly secure, and we cannot guarantee absolute security.
The Services are intended only for individuals aged 18 and over. We do not knowingly collect personal information from children under 18. Our intake form collects your date of birth, and our servers reject any submission where the date of birth resolves to an age under 18; the check runs before any account is created, any payment is authorized, or any intake record is stored. If you believe we have collected information from a child under 18, please contact us at privacy@gettides.com and we will delete the information.
The Services are offered only to residents of the United States, and only in the states where our clinicians are licensed. If you access the Services from outside the United States, you do so at your own risk and are responsible for compliance with local law. Your information will be processed and stored in the United States.
Our website may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies before providing information.
Some browsers transmit a "Do Not Track" signal. Because there is no industry-standard interpretation of these signals, we do not respond to them individually. We do not engage in cross-site tracking regardless of a Do Not Track signal.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or a prominent notice on the Services before the changes take effect. The "Effective date" at the top of this page reflects when the current version took effect.
If you have questions about this Privacy Policy or want to exercise any of your rights, contact us at:
Get Tides PLLC · Privacy Officer
2942 N 24th St Ste 115
PMB 859402
Phoenix, Arizona 85016-7849, United States
Email: privacy@gettides.com
Phone: (480) 910-1157