Scope and Applicability

This Privacy Policy describes how SheffLaces (operated by ASTRA IFAME) collects, uses, discloses, and safeguards information about you when you access or use our website, products, and services in the United States. This Policy applies to information collected online through shefflaces.com and any related pages where it is posted. By using our services, you acknowledge that you have read and understood this Policy.

Effective Date: September 26, 2025

Identity of the Business and Contact Information

Business Name: SheffLaces (owned and operated by ASTRA IFAME)

Postal Address: 160 Spear St, San Francisco, CA 94105, United States

Email: [email protected]

Definitions

For purposes of U.S. privacy laws (including the California Consumer Privacy Act as amended by the California Privacy Rights Act, “CCPA/CPRA,” and similar state laws), “Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household. “Sensitive Personal Information” includes data such as precise geolocation, health-related information, and account log-in credentials. “Sale” means disclosure of Personal Information for monetary or other valuable consideration. “Share” means disclosure of Personal Information for cross-context behavioral or targeted advertising.

Categories of Information We Collect

The types of information we may collect include:

  • Identifiers and Contact Information: name, email address, IP address, device identifiers, and, if you choose to provide it, phone number.
  • Online and Device Activity: browsing history on our site, pages viewed, content interactions, timestamps, referral URLs, approximate location (derived from IP), browser and device data, and diagnostic logs.
  • Commercial and Preference Information: service preferences, saved medications or comparisons, bookmarks, and interaction history with price-check tools or alerts.
  • Health-Related Information (Self-Reported): conditions, symptoms, medications, dosages, and related preferences that you voluntarily enter to use our comparison and guide features. This information may be considered Sensitive Personal Information under certain state laws.
  • User-Generated Content and Communications: inquiries, feedback, survey responses, reviews, and messages you send to us.
  • Inferences: insights drawn from the information listed above to tailor content, recommendations, or features.

We generally do not collect payment card numbers because we do not sell prescription drugs; if we offer paid services or subscriptions in the future, payment processing would be handled by a third-party processor subject to its own privacy terms.

Sources of Information

  • Directly from you: when you create preferences, submit forms, request communications, or use interactive tools.
  • Automatically: through cookies, pixels, SDKs, and similar technologies when you use our site.
  • Service providers and partners: analytics providers, advertising partners, and, where applicable, licensed pharmacy data sources that supply pricing and availability information.
  • Publicly available sources: where permitted by law.

Purposes for Use

  • Provide and improve services: operate our website, deliver drug comparisons, disease guides, and price checks, maintain functionality, and develop new features.
  • Personalization: tailor content, suggestions, and comparisons to your interests.
  • Communications: respond to inquiries, send administrative notices, newsletters, or updates (you can opt out of marketing at any time).
  • Analytics and research: measure performance, understand usage, and enhance quality and safety.
  • Security and fraud prevention: protect accounts, detect, prevent, and investigate fraudulent or malicious activity.
  • Compliance: meet legal, regulatory, and reporting obligations and enforce our terms.
  • Advertising: provide, measure, and improve non-intrusive, interest-based advertising where permitted by law.

Our Role and HIPAA Notice

SheffLaces provides informational services and comparison tools. We are not a healthcare provider, health plan, or healthcare clearinghouse, and we generally are not a “covered entity” or “business associate” subject to the Health Insurance Portability and Accountability Act (HIPAA). Any health-related information you provide on our site is governed by this Privacy Policy and applicable state privacy laws, not HIPAA, unless we expressly state otherwise in a separate agreement.

No Medical Advice

Content on SheffLaces is for informational purposes only and is not a substitute for professional medical advice, diagnosis, or treatment. Always seek the advice of your physician or other qualified health provider with questions you may have regarding a medical condition.

How We Disclose Information

We may disclose your information as follows:

  • Service Providers/Processors: to hosting, analytics, customer support, security, and other vendors who process information on our behalf under contractual restrictions.
  • Advertising and Analytics Partners: to facilitate measurement, attribution, and delivery of targeted or contextual ads, subject to your choices and applicable law.
  • Pharmacy and Pricing Partners: to obtain and display pricing, availability, or to fulfill features you request (we do not transmit your health information to pharmacies without your direction).
  • Affiliates and Corporate Transactions: to our affiliates, and in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality.
  • Legal and Safety: when required by law or to protect rights, safety, and security, or to enforce our terms.
  • With Your Direction or Consent: when you ask us to share information or otherwise consent.

Cookies and Tracking Technologies

We use cookies, web beacons, pixels, SDKs, local storage, and similar technologies to operate our site, remember preferences, perform analytics, and support advertising. You can manage cookies via your browser settings and, where provided, our on-site cookie controls. Disabling cookies may affect site functionality.

Targeted Advertising, Sale, and Sharing

We may engage in activities that constitute “sharing” or “targeted advertising” under certain state laws when we allow third parties to collect or receive device data, online activity, or inferences to deliver ads tailored to your interests. We do not sell your Personal Information for money. You can opt out of sale/sharing or targeted advertising by adjusting your cookie preferences (where available) and by contacting us at [email protected]. If you are a California resident, you may also exercise these rights through a “Do Not Sell or Share My Personal Information” mechanism if provided on our site.

Notice at Collection for California Residents

We collect the categories of Personal Information listed in the “Categories of Information We Collect” section for the purposes described in “Purposes for Use.” We retain Personal Information for the periods described in “Data Retention.” We do not sell Personal Information for money but may “share” Personal Information for cross-context behavioral advertising. Categories that may be shared for advertising include identifiers, online and device activity, commercial information, and inferences. We collect Sensitive Personal Information only if you voluntarily provide health-related inputs to use our tools; we use such information solely to provide requested services and to improve them, and we do not use it to infer characteristics about you beyond those services.

U.S. State Privacy Rights

Depending on your state of residence (e.g., California, Colorado, Connecticut, Utah, Virginia), you may have the following rights, subject to legal exceptions:

  • Access and Portability: request access to and a copy of Personal Information we maintain about you.
  • Correction: request that we correct inaccurate Personal Information.
  • Deletion: request deletion of Personal Information we collected from you.
  • Opt Out: opt out of sale, sharing, and targeted advertising.
  • Limit Use of Sensitive Personal Information (CA): request that we limit use of Sensitive Personal Information to certain permissible purposes.
  • Non-Discrimination: not be discriminated against for exercising your privacy rights.

How to Exercise Your Rights

You may submit a request by emailing [email protected]. Please describe the right you wish to exercise and provide sufficient information for us to verify your identity.

Verification and Authorized Agents

We will verify requests using information reasonably related to your account or interactions with us. Authorized agents may submit requests on your behalf where permitted by law, provided they supply proof of authorization and we can verify your identity.

Appeals of Decisions

Residents of states such as Colorado, Connecticut, and Virginia may appeal our decision regarding a privacy request by replying to our response and indicating “Appeal.” We will review and respond within the timeframe required by applicable law.

Nevada Privacy Rights

Nevada residents may opt out of the sale of “covered information” by contacting [email protected]. We do not currently sell covered information as defined by Nevada law.

Do Not Track and Global Privacy Control

Some browsers transmit “Do Not Track” signals. Our services do not currently respond to DNT signals. Where legally required (e.g., in California and Colorado), we treat a valid Global Privacy Control (GPC) signal as a request to opt out of sale/sharing or targeted advertising for the browser that sends the signal.

Data Retention

We retain Personal Information for as long as necessary to fulfill the purposes described in this Policy, comply with our legal obligations, resolve disputes, and enforce agreements. Typical retention periods include:

  • Account, preferences, and saved items: while your account or preferences remain active and for up to 24 months after inactivity unless you request deletion sooner.
  • Communications and support records: up to 3 years.
  • Analytics data: up to 26 months.
  • Server logs and security records: approximately 12–24 months.
  • Health-related inputs you provide: retained as long as needed to provide the requested features and for up to 24 months after your last use, unless you delete them or request deletion earlier.

Security

We implement reasonable administrative, technical, and physical safeguards designed to protect Personal Information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. However, no method of transmission over the Internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.

International Users

Our services are intended for users in the United States and are operated from the United States. If you access the services from outside the United States, you understand that your information may be transferred to, stored in, and processed in the United States, where laws may differ from those of your jurisdiction.

Third-Party Services and Links

Our site may reference or link to third-party services, including licensed pharmacies, advertisers, analytics providers, and social media. We are not responsible for the privacy practices of third parties. We encourage you to review their privacy policies before providing them with information.

Children's Privacy

Our services are not directed to children under 13, and we do not knowingly collect Personal Information from children under 13. If we learn that we have collected Personal Information from a child under 13, we will delete it. California residents under 16 have additional rights regarding sale or sharing of Personal Information; we do not knowingly sell or share the Personal Information of users we know to be under 16.

Email Communications

If you subscribe to updates or otherwise receive commercial emails from us, you can opt out at any time by using the unsubscribe mechanism in the email or by contacting [email protected]. We may still send you non-promotional, transactional messages related to your use of the services.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will take appropriate steps to notify you, such as by posting the updated Policy with a new effective date. Your continued use of the services after an update constitutes acceptance of the revised Policy.

Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

ASTRA IFAME
160 Spear St, San Francisco, CA 94105, United States
Email: [email protected]

Write a comment