Cookie Policy

Effective Date: 07/21/2026

This Cookie Policy explains how MedBox (“we,” “us,” or “our”) uses cookies and similar tracking technologies on our website https://medbox.com (the “Website”), our online shop, our patient portal and dashboard, and the MedBox by AmeriPharma app. It describes what these technologies are, why we use them, who sets them, and how you can control them. Key terms are defined below.

1. Definitions

  • Cookies: Small text files placed on your device when you visit a website, used to remember your actions and preferences.
  • Similar Technologies (Trackers): Other tools that work like cookies, including web beacons/pixels, SDKs, and the local storage and session storage technologies described in Section 3 below.
  • Personal Data: Information relating to an identified or identifiable individual, such as your name, email address, IP address, or device and browsing data.
  • Usage Data: Information collected automatically as you use the Website, such as pages visited, time spent on a page, and similar diagnostic data.

2. A Note on Cookies vs. Local Storage, ETags, and Other Trackers

Not every tool on our Website uses a traditional cookie. Some of our vendors instead use browser local storage or session storage (small pieces of data your browser holds for a site), or ETags (cache-validation tags that servers use to recognize a browser that’s already downloaded a file). A few send data directly to a server without storing anything on your device at all (sometimes called a “beacon” or “pixel”).

We treat all of these the same way we treat cookies in this policy — they’re disclosed here, grouped by purpose, and covered by the same choices and rights described below. That’s also how U.S. state privacy laws generally look at it: a business can’t avoid its notice and opt-out obligations just because it used local storage or an ETag instead of a cookie. If a technology is used to remember you, recognize your device, or track your activity across visits, we disclose it here regardless of its technical form.

Some cookies and storage in our records are set on our own domains (medbox.com or shop.medbox.com) rather than on a vendor’s domain — these are known as first-party cookies. This doesn’t mean we built the underlying code ourselves: several vendors below (for example, Cloudflare, Shopify, CallRail, Google, and TikTok) write some of their tracking data directly into storage on our domain instead of their own, typically because their tool is embedded directly in our pages. We’ve noted this within each vendor’s own row rather than listing it separately, so you can see which company is actually behind each piece of data. 

3. Categories of Cookies and Trackers We Use

We group the cookies and trackers on our Website into three categories, matching how our cookie consent manager presents choices to you. Not every vendor is active on every page — for example, some tools only run on our online shop (shop.medbox.com) or on specific landing pages.

A first-party cookie is one stored under our own domain, rather than a vendor’s domain — it’s a label based on where a cookie is stored, not necessarily who is responsible for it. Our cookie banner reflects this: some cookies appear under “AmeriPharma” or “get.medbox.com” simply because that’s the domain they’re stored on, even when the cookie actually belongs to a specific third-party vendor. Where that’s the case (for example, with Cloudflare, Shopify, CallRail, or YouTube), the details of what that vendor collects and why are described under that vendor’s own entry below — not repeated under AmeriPharma or get.medbox.com.

3.1 Required

These keep the Website running, secure, and functional. They can’t be switched off in our systems because the Website can’t work properly without them.

VendorPurposeData / Technology CollectedLegal BasisRetention
TrustArcStores and manages your cookie/tracker consent preferences.Which cookie categories you’ve chosen to accept or reject, remembered with a randomly generated ID so we can recall your choice on your next visit.Legal obligation13 months
CloudflareDetects malicious traffic, blocks bots, and keeps the Website and checkout secure (also used by several vendors below via Cloudflare Bot Management). Sets its __cf_bm cookie as first-party storage on our own domains.Your IP address, plus signals from your browser and device that Cloudflare uses to calculate a “bot score” — essentially, how likely you are to be a real visitor rather than an automated script.Legitimate interestSession
Amazon CloudFront / AWSContent delivery network and cloud hosting that stores and serves Website content quickly and securely.Your IP address and request details, plus a small caching tag that lets our servers check whether your browser already has the latest version of a page or file.Contract7 days
accessiBePowers our accessibility widget so the Website can be used with assistive technology.The accessibility settings you choose (like font size, contrast, or screen-reader mode), remembered so the widget doesn’t reset each visit, IP address, URL, plus a small caching tag for its script files.Legal compliance / legitimate interestPersistent (until preferences are reset)

3.2 Functional

These enable extra features and a smoother experience — things like chat support, forms, translations, our online shop, and bot/fraud protection. You can decline these, but some site features may not work as well.

VendorPurposeData / Technology CollectedLegal BasisRetention
LegitScriptDisplays and verifies our pharmacy accreditation/verification badge, confirming MedBox is a legitimate, licensed online pharmacy.Your IP address, browser type, and which pages you viewed while the badge loaded, used to confirm the badge is working.Legal compliance / legitimate interestSession
WordPress / WP EnginePowers our website infrastructure, hosting, and admin/user sessions.A session ID. If you’re a logged-in MedBox website administrator, it also includes your username, when your session expires, and a small scrambled fragment of your password so you can stay securely logged in. It also remembers your selected site language.ContractSession
TypeformPowers interactive forms and surveys.Your form or survey responses, a cookie that stops you from accidentally submitting the same form twice, and basic technical log data (like your IP address and browser type) used only to catch and fix errors.ConsentUp to 12 months after submission
IntercomLive chat and messaging inside our authenticated portal/dashboard.A session ID tied to your chat conversation, the messages you send us, and any account details you choose to share while getting support — which may include your name, email, or, if relevant to your question, prescription or insurance information. This is used to help our support team assist you and is handled under our HIPAA-compliant privacy practices.Contract / legitimate interestAs long as needed to provide support and manage your account
EmbedSocialEmbeds social media content and customer reviews.A session or persistent visitor ID, your IP address, the page that referred you, and which social posts or reviews you looked at.ConsentSession
CantoDelivers digital asset previews (images, video) for smoother browsing.A first-party session ID and a record of which images or videos you’ve already loaded, so pages load faster on repeat visits.ConsentSession
OptinMonsterDisplays lead-capture popups and campaign banners.Two small identifiers: one that recognizes you as a new or returning visitor (lasting up to 11 years), and one that resets after 20 minutes of inactivity. There’s also a flag remembering whether you’ve already responded to a popup, so we don’t show it again.ConsentUp to 12 months (some values up to 11 years)
TranslatePressProvides website translation and language preferences.Your selected language, your IP address, and basic browser information used to guess a default language for you.ConsentUp to 12 months
HighLevel / LeadConnectorSupports form submission, appointment scheduling, and protects forms from bots (Cloudflare Bot Management); also used for marketing automation (see the Advertising & Analytics table).A session or contact ID connected to any form or chat you submit, a record of your browsing activity stored locally in your browser, and a security signal (through Cloudflare) that helps block spam bots on our forms.Legitimate interest30 minutes (security cookie); local storage entries persist until cleared
Shopify / Shop AppPowers our online shop (shop.medbox.com), including cart, checkout, sign-in with Shop, and error monitoring. Writes most of its runtime and pixel-manager keys as first-party storage on our own domain (e.g. _shopify_test, __shopify_agent_context_events, _shs_state, signInWithShop:*, wpm-ri-*).What’s in your cart and your checkout progress, a Shop App ID if you use “Sign in with Shop,” and basic device/browser details used to catch fraud.ContractSession to 12 months, depending on function
BugsnagError monitoring for our online shop, used to detect and diagnose site bugs.A randomly generated ID with no connection to your identity, used only to calculate how stable our shop’s software is overall.Legitimate interestPersistent (until cleared)
hCaptchaDistinguishes human visitors from bots on forms and checkout to prevent fraud and abuse.Your IP address, browser type, operating system, and the time of your visit, as well as basic interaction signals such as mouse movement, scroll position, and touch input, used to tell the difference between a human visitor and a bot.Legitimate interestSession
UNPKGContent delivery network that serves open-source code libraries used to run parts of the Website.Your IP address and a small caching tag confirming whether your browser already has the latest version of a code library.Legitimate interestSession
Google Inc.Serves web fonts and other static design assets — including the Atkinson Hyperlegible font used for readability — from Google’s static content domain (gstatic.com). Your IP address and browser type, sent as part of loading the font file. Legitimate interest Session

3.3 Advertising

These help us understand how visitors use the Website and make ads more relevant to you — measuring performance, analyzing behavior, and limiting how often you see the same ad.

VendorPurposeData / Technology CollectedLegal BasisRetention
Google AnalyticsMeasures how visitors use the Website so we can understand and improve it.A randomly generated ID that tells you apart from other visitors, plus which pages you viewed, how long you stayed, where you came from, and general actions like clicks or video views.ConsentUp to 26 months
CallRailTracks phone call activity and attributes calls to marketing sources/campaigns. Writes some tracking values (calltrk-*) as first-party storage on our own domain, including on landing pages.Which page or ad campaign led to your call, plus the call’s time, duration, and source.ConsentUp to 2 years
PostHogAnalyzes user behavior via session replay, heatmaps, and click reports.Which pages and features you use, and your IP address, for general analytics. If you specifically opt in to session recording, we also capture a replay of your mouse movement, clicks, and scrolling on the page.Consent1 year
PixelYourSiteManages and fires connected advertising pixels (e.g., Meta, Pinterest) and tracks on-site actions for marketing analytics.Which actions you take on the site (like viewing a page or clicking a button), passed along to connected ad platforms, plus your cookie preferences for those platforms.Consent7 days
Convert.comRuns A/B testing and website optimization experiments.Which version of a page you were shown as part of a test, which pages you viewed during that test, and basic browser/device details.ConsentUp to 6 months
Google Ads Conversion TrackingMeasures ad performance and conversions across the Google Ads network (including the Google Display/DoubleClick ad exchange). Writes some click-ID data (_gcl_ls) as first-party storage on our own domain.A click ID connecting you to a specific Google ad, which ad or campaign led you to sign up or start service with us, and basic browser/device details — shared with the broader Google Ads/Display network.ConsentUp to 12 months
YouTubeEmbeds video content and tracks engagement. Writes some values (e.g. __sak, ytidb::LAST_RESULT_ENTRY_KEY, yt-icons-last-purged) as first-party storage on our own domain when videos are embedded.Basic interaction data from videos you watch, browser/device details, and a few small technical identifiers that remember playback preferences and avoid reloading icons unnecessarily.Consent6 months
Meta PixelTracks interactions for Facebook and Instagram advertising.A Pixel ID and Meta’s own visitor cookie, which buttons you click and where they take you, and any additional details we choose to send (like completing a sign-up).Consent180 days
X (Twitter) PixelCollects data for advertising on the X platform.A cookie and click ID and basic device/browser information, used to measure ad performance on X.Legitimate interest / consent where applicable90 days
Reddit PixelTracks interactions for Reddit advertising.Your IP address, browser details, the page that referred you, sign-up or page-view events, your email address in scrambled (hashed) form, your mobile advertising ID, and a Reddit-assigned click ID.ConsentUp to 12 months
Pinterest TagTracks conversions and behavior for Pinterest advertising.Your email address in scrambled (hashed) form, your Pinterest login state if you’re logged into Pinterest in the same browser, and details about which ads led to a conversion.Consent1 year
RumbleEmbeds video content and tracks engagement.Small identifiers embedded in videos or ads, your IP address, and device/browser details, used to confirm whether you actually viewed a specific video or advertisement.Consent60 days
Bing Ads (Microsoft)Provides remarketing and conversion tracking across Microsoft properties.A click ID tied to a specific Microsoft ad, your IP address, browser/device details, and whether you signed up or started service after clicking that ad.ConsentUp to 13 months
ActiveCampaignPowers email marketing and CRM automation, and protects related forms from bots (Cloudflare Bot Management).Recordings of how you interact with our marketing pages (mouse movement, clicks, pages visited), browser/device details, and email engagement data (like opens and clicks) if you’re subscribed to our emails.Consent30 minutes
TikTok PixelCollects preferences and events for TikTok advertising. Writes some session data (tt_appInfo, tt_pixel_session_index, tt_sessionId) as first-party storage on our own domain, including on landing pages.An ad/event ID, page details and button clicks, the time of your visit, your IP address, and a cookie that links your visit to a TikTok ad account.Consent13 months
HighLevel / LeadConnector (Marketing Automation)Attributes marketing campaigns and supports CRM-driven advertising follow-up.Which ad or link brought you to the site, and a contact ID connected to your CRM record if you’ve submitted a form.ConsentVaries by function

4. Managing Your Preferences

You have the right to decide whether to accept or reject cookies. You can exercise your cookie preferences by clicking on the appropriate opt-out links provided:

  • Cookie Consent Manager: Click “Privacy Choices” or “Your Privacy Choices” in the Website footer to turn categories on or off.
  • Browser Settings: Most browsers let you block or delete cookies and clear local storage through their settings. Doing so may affect how well parts of the Website work.
  • Global Privacy Control (GPC): We honor GPC and other recognized universal opt-out signals as a request to opt out of the sale/sharing of personal data and targeted advertising, where applicable under state law.
  • Third-Party Opt-Outs:
    • Google Ads Settings – adssettings.google.com
    • Meta Ad Preferences – facebook.com/adpreferences
    • Pinterest Personalization Settings – help.pinterest.com
    • Digital Advertising Alliance – optout.aboutads.info
    • Your Online Choices – youronlinechoices.com

    Opting out doesn’t mean you’ll see fewer ads overall — it means the ads you see will be less tailored to your interests.

    5. Your Privacy Rights

    Depending on where you live, state privacy laws (for example, in California, Colorado, Connecticut, Virginia, Utah, Oregon, Texas, and a growing number of other states) may give you rights over the personal data collected through cookies and similar technologies, including the right to:

    • Know what personal data we’ve collected about you and why.
    • Access a copy of that data.
    • Correct inaccurate personal data.
    • Delete personal data we’ve collected.
    • Opt out of the sale or sharing of personal data, and of targeted advertising.
    • Opt out of profiling used for certain automated decisions.
    • Not be discriminated against for exercising any of these rights.
    • Appeal a decision we make about your request (available under several state laws).

    You can exercise these rights using the Cookie Consent Manager described above, or by contacting us using the details in Section 9. If you’re a California resident, you can also review our separate “Your Privacy Choices” page. We do not sell personal data for money, but some cookies described above may meet the broader definition of a “sale” or “sharing” under certain state laws (for example, advertising cookies that share data with ad networks); the opt-out tools in Section 4 let you turn these off.

    6. Sensitive and Health-Related Information

    As a licensed pharmacy, MedBox handles protected health information (PHI) and, in some cases, other health-related information. We maintain administrative, physical, and technical safeguards for PHI in accordance with HIPAA.

    We do not use advertising or analytics cookies to collect prescription, clinical, or other PHI, and we do not use PHI for targeted advertising. Certain functional tools used in our authenticated portal, dashboard, or support workflows may process account, prescription, insurance, or support-related information when needed to provide services or assist you. When those tools process PHI on our behalf, they are used for MedBox operations and are covered by appropriate business associate agreements.

    Account, prescription, clinical, and support-related information submitted through the authenticated portal or support tools is handled under our HIPAA Notice of Privacy Practices and Privacy Policy, not for advertising or sale. Some state laws may separately protect “consumer health data”; where those laws apply, we do not use cookies to sell or share such data for targeted advertising without the consent those laws require.

    7. Children’s Privacy

    Our Website is not directed to children, and we do not knowingly use cookies or trackers to collect personal data from children in a manner inconsistent with the federal Children’s Online Privacy Protection Act (COPPA) or applicable state children’s privacy and age-appropriate design requirements. If you believe a child has provided us with personal data, please contact us using the details in Section 9.

    8. Changes to This Policy

    We may update this Cookie Policy periodically to reflect changes in our practices, our vendors, or applicable law. When we do, we’ll update the Effective Date above. We encourage you to check back from time to time.

    9. Contact Us

    If you have questions about this Cookie Policy or want to exercise a privacy right, contact us at:

    • Email: [email protected]
    • Phone: (800) 270-7091
    • Mail: AmeriPharma MedBox, 23041 Avenida De La Carlota, Suite 210 & 310, Laguna Hills, CA 92653