Maro is a technology platform and patient experience brand. Independent licensed healthcare providers make their own clinical decisions, and licensed pharmacies handle dispensing and shipment where applicable. State-specific rights, notices, and consent requirements may vary.
Information we collect
We may collect information you provide directly, including your name, date of birth, contact information, shipping address, account credentials, payment details, communications with us, and information you submit during intake or support interactions.
We may also collect health-related information you choose to provide as part of a treatment request, as well as technical information such as IP address, browser type, device information, pages visited, referring URLs, and basic analytics data.
How we use information
We may use information to operate the platform, create and maintain your account, facilitate consultations with independent licensed providers, coordinate pharmacy fulfillment, process payments, provide customer support, improve the website, prevent fraud, comply with legal obligations, and communicate with you about your account, orders, and care journey.
HIPAA and Notice of Privacy Practices
Maro is a telehealth platform and patient-experience brand. Independent licensed healthcare providers make their own clinical decisions, and licensed pharmacies handle dispensing and shipment. Where Maro or its partners are subject to the Health Insurance Portability and Accountability Act (HIPAA), protected health information (PHI) is handled in accordance with applicable HIPAA obligations and business associate arrangements. This section, together with any Notice of Privacy Practices you receive from the applicable provider or covered entity, describes how PHI may be used and disclosed where HIPAA applies and your rights regarding it.
Uses and disclosures of PHI. Where HIPAA applies, PHI may be used and disclosed for treatment (coordinating care among providers, pharmacies, and support teams), for payment (billing, refunds, collections, and payment support for our cash-pay programs), and for healthcare operations (quality assessment, compliance, audits, credentialing, legal services, and platform operations). PHI may also be used or disclosed as required by law and for public-health and safety purposes permitted by law, such as reporting adverse reactions to medications.
Your rights regarding PHI. Subject to limits and exceptions under applicable law, you have the right to inspect and copy PHI we maintain; to request an amendment to PHI you believe is incorrect or incomplete; to request an accounting of certain disclosures; to request restrictions on certain uses and disclosures; to request confidential communications by alternative means or at an alternative location; to obtain a paper copy of any applicable Notice of Privacy Practices; and, where you have authorized a use or disclosure, to revoke that authorization in writing. To exercise these rights, contact our Privacy Officer at hello@marorx.com.
Transmission and security of PHI. Where HIPAA applies, we use administrative, technical, and physical safeguards designed to protect electronic PHI, including encrypted transmission technologies such as SSL/TLS where appropriate and access controls. No website, application, or electronic transmission can be guaranteed to be completely secure; if you believe your information may have been compromised, contact us promptly at hello@marorx.com.
Changes and complaints. We may change this notice, and a revised version will apply to PHI we already maintain and to information we receive in the future. If you believe your privacy rights have been violated, you may file a complaint with our Privacy Officer or with the Secretary of the U.S. Department of Health and Human Services. You will not be retaliated against for filing a complaint.
Privacy Officer. To exercise your rights, request a copy of any applicable Notice of Privacy Practices, or ask a question about our privacy practices, contact the Maro Rx LLC Privacy Officer at hello@marorx.com.
Your choices and rights
Depending on your relationship with us and where you live, you may have rights to access, correct, or delete certain personal information, opt out of certain communications, and request information about how your data is handled. You may also have rights concerning your health records through the relevant healthcare provider or covered entity.
To make a request, contact hello@marorx.com. We may need to verify your identity before completing certain requests.
State privacy rights
Privacy rights, notices, and consent requirements vary by where you live. This section summarizes rights that may apply to you; where laws overlap, we honor the protections that apply to your information.
California. The California Consumer Privacy Act (as amended by the CPRA) gives you the right to request the categories and specific pieces of personal information we have collected, the sources and purposes of collection, and the categories of third parties to which it is disclosed; to access, delete, and correct personal information; and to opt out of any “sale” or “sharing” of personal information for cross-context behavioral advertising. We do not sell personal information for money, and we will not discriminate against you for exercising these rights. Because of how the CCPA defines “share,” allowing advertising partners to set cookies may be treated as sharing, which you can opt out of using the advertising controls described above. Information governed by health-privacy laws such as HIPAA is generally exempt from the CCPA.
Other U.S. state privacy laws. If you live in a state with a comprehensive consumer privacy law — including Texas, Virginia, Colorado, Connecticut, Utah, Oregon, and Montana, and, as their laws take effect, states such as Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, and Tennessee — you may have the right to confirm whether we process your personal data; to access, correct, delete, and obtain a portable copy of it; and to opt out of targeted advertising, the sale of personal data, and certain profiling. Where these laws require consent before processing sensitive data (including health data), we obtain it where applicable, and we do not sell sensitive personal data.
Texas residents. Maro Rx LLC operates from Texas. Texas residents have rights under the Texas Data Privacy and Security Act (TDPSA), including the rights described above. We process and disclose sensitive data, including health data, only as needed to provide the products and services you request or with your consent where the TDPSA requires it, and we do not sell sensitive personal data.
Nevada residents. You may direct us not to sell certain personal information we have collected or will collect. We do not sell such information for monetary consideration, but you may submit a request to record your preference.
Universal opt-out signals. Where required by law, we recognize universal opt-out mechanisms such as the Global Privacy Control (GPC) as a valid request to opt out of the sale or sharing of personal information and of targeted advertising for the browser or device that sends the signal.
How to exercise rights and appeal. To make a request, email hello@marorx.com; we may need to verify your identity first. If we decline to act on your request, you may appeal by replying to our response or emailing hello@marorx.com with “Privacy appeal” in the subject line, and we will inform you in writing of the outcome. Where your state permits, you may also contact your state attorney general.
Consumer health data
Some states have laws that specifically govern “consumer health data” — information that identifies your past, present, or future physical or mental health status. These include Washington’s My Health My Data Act, Nevada’s consumer health data law, and health-data provisions of Connecticut’s privacy law. Where these laws apply to you, the following additional terms govern our handling of consumer health data.
We collect consumer health data that you provide through intake forms and through your use of our services in order to arrange telehealth care, fulfill prescriptions, provide support, and operate and improve the platform. Where these laws require it, we obtain your consent before collecting or sharing consumer health data for purposes beyond providing the products and services you request, and we do not sell consumer health data without a separate valid authorization.
Where these laws apply, you have the right to confirm whether we collect, share, or sell your consumer health data; to access it; to withdraw consent; and to request that it be deleted. To exercise these rights, email hello@marorx.com. Health information handled by your provider or another covered entity may instead be governed by HIPAA and the Notice of Privacy Practices described above.
Retention and security
We use administrative, technical, and physical safeguards designed to protect personal information and health information. No system is perfectly secure, and we cannot guarantee absolute security.
We retain information for as long as reasonably necessary for operational, legal, compliance, dispute-resolution, and recordkeeping purposes. If a data breach occurs, applicable notification laws may require notices to affected users and regulators.
Children, changes, and contact
Maro is intended for adults and is not directed to children under 18. We may update this Privacy Policy from time to time, and the updated version will be posted on this page with a new effective date.
Questions about privacy can be sent to hello@marorx.com.
