POLICY VERSION 1.2 · PENDING FORMAL LEGAL REVIEW
Website Privacy & Consumer Health Data Policy
This policy explains how MSBB LLC, doing business as Ms. B’s Medical Home Supply, handles information submitted through this website and describes Nevada consumer-health-data practices.
1. Scope
This policy applies to this website, customer accounts, product browsing, order requests, callback requests, assistant interactions, and approved careers-interest workflows. It does not replace a separate Notice of Privacy Practices when HIPAA applies to a particular activity.
2. Information we may receive
We may receive account identifiers supplied by the sign-in platform; name and contact information; product interests, quantities, variants, payer type, optional plan name, delivery or pickup preference, callback time, assistant-to-human handoff requests, acknowledgment records, and essential technical and security information. A human-support handoff may place the customer’s name, selected contact method, contact value, preferred response time, general question, timestamp, and reference number into controlled internal support records and a private Google Chat notification space when that connection is active. Live-chat messages are stored in the website’s controlled conversation database so the authorized owner can reply through an access-restricted staff console. The customer’s temporary conversation credential remains in that browser session and is not included in the Google Chat alert. Approved sources are the customer or authorized caregiver, the authentication provider, the customer’s device and essential site operations, and authorized service providers.
3. Information this public website must not collect
Do not submit diagnoses, clinical notes, prescriptions, dates of birth, Social Security numbers, Medicare or Medicaid numbers, insurance member IDs, insurance-card images, payment-card information, authentication secrets, or other sensitive health information through public forms or the virtual assistant. We will provide approved secure instructions when sensitive information is required.
4. How information is used
Information may be used to respond to requests, review product interest, explain general documentation or coverage steps, coordinate callbacks, support account access, operate and secure the website, investigate errors or misuse, maintain required records, improve accessibility and service, and comply with applicable obligations.
5. Service providers and disclosures
Information may be processed by authorized personnel and approved hosting, authentication, Google Workspace, communications, security, payment, shipping, professional, legal, and operational service providers only as needed for an approved purpose. Additional consumer-health-data categories, recipients, or purposes require notice and affirmative voluntary consent when applicable. We may also disclose information when required by law or to protect safety and legal rights. Public forms are not a HIPAA-secure clinical intake channel.
6. Sale, advertising, and tracking
MSBB LLC does not currently sell customer information or consumer health data and does not currently use consumer health data for behavioral advertising. Third-party cross-site collection of consumer health data is not authorized. Essential cookies, sessions, security controls, and device-local preferences may support authentication, navigation, reliability, and interface choices.
7. Retention and security
We use data minimization, access controls, authentication, operational logs, monitoring, and retention requirements appropriate to the record. No internet system is completely secure. Records may be retained for company, legal, payer, accreditation, transaction, tax, dispute, audit, incident, complaint, or legal-hold requirements.
8. Accounts, authentication, and support records
Account authentication is platform-managed. MSBB LLC does not receive or store the customer’s authentication password. The authentication provider’s own privacy terms also apply. When an account is created or its basic profile is updated, an access-controlled Google Workspace support ledger may record the customer’s name, account email, phone number, contact preference, account status, event type, and timestamp. The ledger does not receive passwords, authentication tokens, payment data, insurance identifiers, medical information, delivery gate codes, driver instructions, or uploaded documents. Authorized support personnel may use the ledger only after identity verification and manual access approval; it does not permit staff to bypass authentication.
9. Optional customer reviews
After a completed delivery, an authenticated customer may receive an optional invitation to rate the product and their experience. Reviews must not include medical, insurance, payment, birth-date, authentication, or account-security information. A review is published only when the customer affirmatively chooses publication. Public reviewer names are minimized, and reviews may be moderated for prohibited content and authenticity. Choosing whether to submit or publish a review does not affect service, coverage, or customer rights.
10. Optional electronic chat records
A customer may separately consent to receive a support-chat record by email or text message. We use the chosen destination or an account-level preference, record the consent and delivery status, and may use approved email or text-message providers to deliver the record. Email may include the conversation and a private link; text messages provide the private link. Links expire after 30 days. Keep the link confidential. Electronic delivery is optional, may fail or be delayed, and is not appropriate for sensitive health, insurance, payment, or authentication information. A customer may change or withdraw the account preference at any time.
11. Your privacy choices and requests
You may browse or request as a guest, decline optional information, sign out, and use the About & Contact page to request access, correction, deletion, or information about processing. Do not include sensitive information in the initial public request. We verify identity using a proportionate method, respond within applicable timeframes, document the outcome, and explain any lawful denial or retention requirement.
12. Children
This website is not directed to children under 13. A parent, guardian, or authorized caregiver should manage requests for a minor and should not submit sensitive information through public forms.
13. Changes and policy version
We may revise this policy when the website, law, service providers, or business practices change. Material changes require review and updated notice or consent when applicable. The policy version shown above identifies the current public summary of controlled policy IT-017 version 1.2.
