$5 in points when you sign upFree local delivery on orders of $35+
GWB
Pharmacy
Shop allCold, cough & fluAllergy & sinusPain & feverVitamins & supplementsSkin careHome healthBenefit cards
HomePrivacy

Privacy Policy

Last updated: May 8, 2026

Placeholder. This policy is a working draft and must be reviewed by counsel before public launch.

1. Introduction

GWB Pharmacy LLC (“we”, “us”) operates the online over-the-counter (OTC) store at gwbpharmacy.com and the brick-and-mortar pharmacy at 4211 Broadway, Suite 27, New York, NY 10033. This policy explains what information we collect through this website, how we use it, and the choices you have. The HIPAA Notice of Privacy Practices governing prescription services is published separately at /hipaa.

2. Information we collect

We collect three categories of information:

  • Account & profile. Name, email, phone, and shipping address that you provide when you create an account or place an order.
  • Transactional. Order contents, totals, fulfillment method, and a payment-method token returned by our processor (we do not store full card numbers).
  • Technical. Your IP address and browser user-agent, which arrive with every request and are kept in short-lived server logs. We use them to stop abuse — rate limiting sign-in attempts and form submissions — and for nothing else. We do not build a profile of the pages you view, because we run no analytics of any kind.

We do not knowingly collect Protected Health Information (PHI) through this website, and the database has no columns to hold it — drug names, prescription numbers, prescriber details and dates of birth were physically removed from the schema so a future mistake cannot store them. This website is over-the-counter only and does not store prescription information. Our secure prescription handoff is not switched on yet, so please call the pharmacy or come to the counter for anything involving a prescription — we will not ask you to type it here. Prescription privacy is covered separately in our HIPAA Notice.

3. How we use information

  • To process orders, deliveries, returns, and refunds.
  • To create and secure your account, verify identity, and prevent fraud.
  • To communicate with you about orders, account activity, and (with your opt-in) promotions and pharmacy news.
  • To find and fix faults, using crash reports that have request contents, cookies and account identifiers stripped out of them.
  • To meet legal, tax, and regulatory obligations.

4. Who else sees your information

We share only what a provider needs to do its job. This is the complete list, and it is generated from the same file the application reads — so a provider cannot be added without appearing here.

  • Supabase — Database, sign-in, and product image storage. Your account email, name, phone, saved addresses, order history, basket, reward-point balance and saved items.
  • Vercel — Website hosting and delivery. Every request to the site, which includes your IP address and browser user-agent in short-lived operational logs.
  • Stripe — Card payments, sales-tax calculation and payment fraud screening. Your card details go from your browser to Stripe directly and never touch our server. We send them your name, email, billing and shipping address and the order amount.
  • Resend — Sending email. Your email address and the contents of the message — an order confirmation, a contact-form reply, or a prescription-related request you submit.
  • EasyPost, and USPS or UPS — Shipping rates, labels and tracking. The recipient name, delivery address and parcel weight for orders you ask us to ship. Nothing about what is inside the parcel.
  • Sentry — Crash and error reports, so we can fix faults. The error itself and the page it happened on. Request bodies, cookies, headers, query strings and account identifiers are stripped before the report is sent, and we do not record screen sessions.
  • BestRx — Pharmacy management system (prescription services). Prescription information you enter into the pharmacy's own secure form. When this is switched on you are typing into BestRx, not into this website.

All of them process data in the United States. We do not sell your personal information, and we do not share it for cross-context behavioural advertising — we run no advertising at all. We may disclose information when the law requires it, or to protect someone's safety.

5. Cookies and similar technologies

We use 6 cookies and browser-storage keys in total. They keep you signed in, hold your basket, screen the payment form for fraud, and remember accessibility settings you chose yourself. That is all of them.

We run no analytics, advertising or tracking — no tag manager, no advertising pixel, no session recording, no data broker. Our typefaces are served from our own servers, so loading a page here does not tell a font company you visited. This is also why you are not looking at a cookie banner: everything we set is strictly necessary or a preference you set, so there is nothing to consent to. Each one is listed individually, with its name and lifetime, in our Cookie Policy. Clearing cookies in your browser signs you out and empties your basket; nothing else is affected.

6. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal information; to object to certain uses; and to withdraw consent. New York and California residents have additional rights under state law. Three of these you can exercise yourself, without asking us:

  • Correct it — edit your name, phone and email on your profile.
  • Delete it — close your account from /account/delete. If you have never ordered, everything is erased outright. If you have, your orders stay (section 7 explains why) and everything else — name, phone, addresses, saved items, reward points, rewards card — is deleted and the account is locked. The page tells you which of the two applies to you before you confirm.
  • Withdraw marketing consent — untick it on your profile, or use the unsubscribe link in any marketing email. It takes one click and needs no account.

For anything else — a copy of your data, a portability request, an objection, or erasure of something we have had to retain — email gwbpharmacy@gmail.com from the address on your account. We will not charge you and we will not make you create an account to ask.

7. Data retention

We keep your account information for as long as your account is open. When you close it, everything listed in section 6 is deleted straight away.

Order records are the exception. A pharmacy has to keep records of what it sold for tax and pharmacy-board purposes, so past orders survive an account closure, including the delivery address the order was sent to. We cannot delete those on request while that obligation runs, and we would rather say so here than let you find out afterwards. Once the retention period ends they are deleted or stripped of anything identifying.

Prescription records held by the pharmacy are separate from this website, are kept for the period pharmacy law requires, and are covered by our HIPAA Notice.

8. Children

This site is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13.

9. Security

We use TLS in transit, encrypted storage, role-scoped database access, and least-privilege staff permissions. No system is perfectly secure; please use a unique password and tell us if you suspect unauthorized access.

10. Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top reflects the most recent change. For material changes, we will notify account holders by email.

11. Contact

Questions about this policy? Email gwbpharmacy@gmail.com or write to GWB Pharmacy LLC, 4211 Broadway, Suite 27, New York, NY 10033.