Effective Date: January 6, 2026
Surescripts, LLC, together with its subsidiaries and affiliates (collectively, “Company” “us,” “we,” or “our”), is committed to protecting the privacy of Personal Data (i.e., information reasonably related to a specific individual). This Privacy Notice describes how we handle Personal Data that we collect through our websites, including www.surescripts.com, social media accounts, mobile applications, and other online interactions and communications such as email (collectively, our “Digital Properties”), in-person events, and through other online and offline interactions (for example, if you negotiate a contract on behalf of one of our business customers that you represent).
If you are a resident of California, Nebraska, or Texas, you have additional rights with respect to your Personal Data. Please read Section 9 (Supplemental U.S. State Privacy Disclosures) below.
2. Types of Personal Data We Collect
4. How We Disclose Personal Data
5. Cookies and Other Tracking Technologies
6. Data Security and Data Retention
9. Supplemental U.S. State Privacy Disclosures
10. Contact Us
Scope: This Privacy Notice applies to information we collect about individuals, such as general website visitors and users of our Script Corner mobile platform (“Individuals”), as well as information we collect about the personnel of our business partners in business-to-business interactions, including vendors and business customers (“Business Contacts”). This Privacy Notice does not apply to:
- Information that we handle to perform services on behalf of our business customers (as a “processor” or “service provider”), including business customers that are healthcare providers. In those cases, our business customers (not Surescripts) control how your information is handled, so we encourage you to review our customers’ privacy policies.
- “Protected health information” (“PHI”) that is subject to the Health Insurance Portability and Accountability Act (“HIPAA”). We handle PHI as a “business associate” on behalf of our business customers, such as health plans, healthcare providers, pharmacies, and health technology companies. Our business customers’ privacy policies apply to PHI instead of this Privacy Notice, and you should contact that business customer with questions or to exercise any rights under HIPAA. If you have questions about your rights and obligations related to the secure exchange of your “protected health information” among providers, health systems, hospitals, and other healthcare organizations for purposes related to treatment, payment, healthcare operations, and secondary use, please review our Health Information Exchange (HIE) Privacy Notice here.
- Information about job applicants or our employees, contractors, or agents. If you are a California resident applying for a job with us, please review our Privacy Notice for job applicants here.
Changes: We may update this Privacy Notice from time to time. Please check this Privacy Notice periodically for updates. If required by law, we will obtain your consent or attempt to notify you by posting on our Digital Properties if there are material changes to this Privacy Notice.
1. Sources of Personal Data
We collect Personal Data about you from the following sources:
- Directly from you. We may collect Personal Data you provide to us directly, such as when you contact or interact with us through our Digital Properties, interact with us in person, sign up for offers or newsletters, communicate with us, respond to surveys or questionnaires, place or customize orders, or sign up for an account or other services.
- Data collected automatically and through tracking technologies. We may automatically collect information or inferences about you, such as through cookies, pixels, tags, scripts, and other tracking technologies (“Cookies”), when you interact with our Digital Properties. This may include information about how you use and interact with our Digital Properties, information about your device, and internet usage information.
- From third parties. We may collect Personal Data from third parties, such as service and content providers, business partners, our affiliated companies and subsidiaries, data brokers, analytics providers, advertising networks, social media companies, or other parties who interact with us.
- From publicly available sources. We may collect Personal Data about you from publicly available sources, such as public profiles and websites.
We may combine information that we receive from the various sources described in this Privacy Notice, including third party sources, and use and disclose the combined information for the purposes identified below.
2. Types of Personal Data We Collect
We may collect the following types of Personal Data. Except as otherwise specified, we may collect this Personal Data about both Individuals and Business Contacts:
- Identifiers, such as your name, email address, physical address, telephone number, other business contact information, and device identifiers (e.g., cookie IDs and IP address).
- Information Protected Under State Law, such as signatures; the content, timing, and method of communications you have with us, such as online chats, calls, and emails; and information you share with or upload to our Digital Properties, such as reviews and comments.
- Demographic information, such as age (including birthdates), marital status, and gender.
- Commercial information, such as information related to your transactions products or services purchased, obtained, or considered; or other purchasing or consuming histories or tendencies.
- Internet or other electronic network activity information, such as your browsing history (including browser type and pages viewed), preference information (including marketing and purchasing preferences), account settings (including any default preferences), and other information regarding your interactions with and use of our Digital Properties. For more information about Cookies, please see Section 5 (Cookies and Other Tracking Technologies).
- Geolocation data, such as your location as derived from your IP address as well as your precise geolocation.
- Audio, electronic, visual, or other sensory information, such as photographs taken at events, call recordings, and video recordings of our premises.
- Professional or employment-related information, (for Business Contacts) such as job title; organization; professional licenses; credentials; affiliations; and other professional information.
- Inferences drawn from any of the information we collect about your preferences or behavior, including your interests based on your interactions with our Digital Properties.
- Sensitive Personal Information (for Individuals), including precise geolocation.
We may collect, use, or create anonymized, de-identified, or aggregated information for any purpose permitted by law. To the extent we process de-identified information, we will maintain and use the information in deidentified form and will not attempt to reidentify the information unless permitted by applicable law.
3. How We Use Personal Data
We may use Personal Data for the following purposes:
- To provide you or your company with products and services, such as making our Digital Properties, products, and services available to you, including through the use of our AI tools; personalizing our Digital Properties, products, and services to you; registering, verifying, and maintaining your account with us; providing and delivering you the goods and services you or the company that you represent requests; providing customer service; processing or fulfilling orders and transactions (including processing payments); verifying customer information and eligibility for certain programs or benefits; communicating with you (including soliciting feedback and responding to requests, complaints, and inquiries); hosting informational webinars; and providing similar services or otherwise facilitating your relationship with us.
- For our internal business purposes, such as day-to-day operation of our business; maintaining internal business records, such as accounting, document management, and similar activities; enforcing our policies and rules; management reporting; auditing; and IT security and administration.
- For our internal research and product improvement purposes, such as verifying and maintaining the quality and safety of our products and services; improving our products and services, including developing or training algorithms or AI tools; designing new products and services; developing and improving algorithms, artificial intelligence, or machine learning tools and models; evaluating the effectiveness of our advertising and marketing efforts; and debugging and repairing errors with our systems, networks, and equipment.
- For legal, safety or security reasons, such as complying with legal, reporting, and similar requirements; investigating and responding to claims against us, our personnel, and our customers; for the establishment, exercise or defense of legal claims; protecting our, your, our customers’, and other third parties’ safety, property or rights; detecting, preventing, and responding to security incidents and health and safety issues (including managing the spread of communicable diseases); and protecting against malicious, deceptive, fraudulent, or illegal activity.
- In connection with a corporate transaction, such as if we acquire assets of another business or sell or transfer all or a portion of our business or assets, including through a sale in connection with bankruptcy and other forms of corporate change.
- For marketing and targeted advertising, such as marketing our products or services or those of our affiliates, business partners, or other third parties. For example, we may use Personal Data we collect to personalize advertising to you (including by developing product, brand, or services audiences and identifying you across devices/sites); to make personalized product recommendations; to analyze interactions with us or our Digital Properties, or to send you newsletters, surveys, questionnaires, promotions, or information about events or webinars. We may use AI to improve the quality, speed, and value of our marketing analysis. You can unsubscribe from our email marketing via the link in the email, by responding “STOP” to the text message, or by contacting us using the information in Section 10 (Contact Information) below.
We only use and disclose Sensitive Personal Information for the following purposes: (i) performing services or providing goods reasonably expected by an average consumer; (ii) detecting security incidents; (iii) resisting malicious, deceptive, or illegal actions; (iv) ensuring the physical safety of individuals; (v) for short-term, transient use, including non-personalized advertising; (vi) performing or providing internal business services; (vii) verifying or maintaining the quality or safety of a service or device; or (viii) for purposes that do not infer characteristics about you.
4. How We Disclose Personal Data
We may disclose the categories Personal Data described above to third parties, including to the categories of recipients described below:
- Affiliates and subsidiaries, including parent entities, corporate affiliates, subsidiaries, business units, and other companies that share common ownership.
- Service providers that work on our behalf to provide products and services you request or to support our relationship with you, such as IT providers, Internet service providers, web hosting providers, software service providers, data analytics providers, and companies that provide business support services, financial administration, and event organization.
- Law enforcement, government agencies, and other recipients for legal, security, or safety purposes, such as when we disclose information to comply with law or legal requirements, to enforce or apply our policies, terms, and agreements, and to protect our, our customers’, or third parties’ safety, property or rights.
- Other entities in connection with a corporate transaction, such as if we acquire assets of another entity, or sell or transfer all or a portion of our business or assets, including through a sale in connection with bankruptcy and other forms of corporate change.
- The public, such as when you have an opportunity to make comments regarding us or our products or services that we may share with the public, including comments on our blog posts and reviews on our product pages. Any Personal Data in comments, reviews, or other content that you share in public areas of our Digital Properties may be read, collected, or used by other users or the public.
- Entities to which you have consented to the disclosure.
We do not sell Personal Data for monetary value. However, our use of certain website technologies and advertising practices may constitute a “sale” or “sharing” of information. We do not knowingly sell data about minors under 18. In the past 12 months, we may have sold or shared your identifiers, commercial information, internet or other electronic network activity information, non-precise geolocation data, and inferences to the following third parties:
- Advertisers, ad platforms and networks, and social media platforms;
- Third parties whose Cookies we use as described in Section 5 (Cookies and Other Tracking Technologies);
- Commercial data partners to whom we make information available for their own marketing purposes; and
- Partners who work with us on promotional opportunities, including co-branded products and services.
5. Cookies and Other Tracking Technologies
Our Digital Properties and authorized third parties use Cookies to collect information about you, your device, and how you interact with our Digital Properties.
- Types of Cookies
We and the third parties that we authorize may use:
- Cookies, which are a type of technology that install a small amount of information on a user’s computer or other device when they visit our Digital Properties. Some Cookies exist only during a single session and some are persistent over multiple sessions over time.
- Pixels, web beacons, and tags, which are types of code or transparent graphics that contain a unique identifier. In addition to the uses described below, these technologies provide information about interactions with our Digital Properties, (including communications such as email we may send to you) and help us customize our marketing activities. In contrast to Cookies, which are stored on a user’s device hard drive, pixels, web beacons, and tags are embedded invisibly on our Digital Properties.
- Session replay tools, which record your interactions with our Digital Properties, such as how you move throughout our Digital Properties and engage with our webforms.
- Embedded scripts and SDKs, which allow us to build and integrate custom experiences on our Digital Properties. Embedded scripts are temporarily downloaded onto your device from our web server, or from a third party with which we work, and are active only while you are connected to our Digital Properties and are deleted or deactivated thereafter.
We may use both first-party Cookies, which are set by us, and third-party Cookies, which are set by other parties. Some of the Cookies we use may last solely for your browsing session and are deleted when you close your browser, while others are persistent and stored after you close your browser.
- Purposes for Using Cookies
We and authorized third parties use these technologies for purposes including:
- Strictly Necessary, such as determining when you are signed in, determining when your account has been inactive, providing you with privacy disclosures and choices, and for troubleshooting and security purposes (including preventing fraud and malicious behavior);
- Functionality/Personalization, such as remembering language preferences and pages and products you have viewed in order to enhance and personalize your experience when you visit our Digital Properties;
- Performance/Analytics, such as analyzing how our websites are used to understand which pages within our Digital Properties are most popular and how users move around them. For example, we use Google Analytics to help us improve the user experience. Google Analytics may use Cookies to perform their services. To learn how Google Analytics collects and processes data, please visit: “How Google uses data when you use our partners’ sites or apps” located at https://policies.google.com/technologies/partner-sites; and
- Targeting/Advertising, such as conducting advertising and content personalization on our Digital Properties and those of third parties; tracking activity over time and across properties to develop a profile of your interests and advertise to you based on those interests (“interest-based advertising”); providing you with offers and online content that may be of interest to you; and measuring the effectiveness of advertising campaigns and our communications with you, including identifying how and when you engage with one of our emails.
- Types of Data Collected
These Cookies collect data about you and your device, such as your IP address, location (both approximate and precise) cookie ID, device ID, Ad ID, operating system, device type, device settings and other device information, browser used, browser history, search history, pages viewed, search queries, login information, and information entered into webforms, and information about how you interact with our Digital Properties (such as pages on our Digital Properties that you have viewed).
- Disclosures of your Data
We may disclose information to third parties or allow third parties to directly collect information using these Cookies on our Digital Properties, such as social media companies, advertising networks, companies that provide analytics (including providers of ad tracking and reporting services), security providers, and others that help us operate our business and Digital Properties.
- Your Choices
As described in Section 9 (Supplemental U.S. State Privacy Disclosures) below, residents of certain states may be able to disable Cookies that constitute a “sale,” “sharing,” or “targeted advertising,” as those terms are defined under applicable laws.
In addition, you may be able to control how we use Cookies through your browser settings. Please be aware that if you disable the use of Cookies, the functionality of our Digital Properties may be negatively impacted, and certain areas or features may not display or work correctly. If you change computers, devices, or browsers; use multiple computers, devices, or browsers; or delete your Cookies, you may need to repeat this process for each computer, device, or browser.
Do Not Track. Some browsers have incorporated Do Not Track preferences. At this time, we do not honor Do Not Track signals.
6. Data Security and Data Retention
Although we maintain reasonable security safeguards, no security measures or communications over the Internet can be 100% secure, and we cannot guarantee the security of your information.
Your Personal Data will be retained as long as necessary to fulfill the purposes we have outlined above unless we are required to do otherwise by applicable law. This includes retaining your Personal Data to provide you or your company with the products and services requested and interact with you; maintain our business relationship with you or your company; improve our business over time; ensure the ongoing legality, safety and security of our services and relationships; or otherwise in accordance with our internal retention procedures. Once you or your company has terminated your relationship with us, we may retain your Personal Data in our systems and records in order to ensure adequate fulfillment of surviving provisions in terminated contracts or for other legitimate business purposes, such as to enable easier future user onboarding, in order to demonstrate our business practices and contractual obligations, or to provide you with information about our products and services in case of interest.
7. Children's Privacy
Our Digital Properties are intended for individuals 18 years of age and older. The Digital Properties are not directed at, marketed to, nor intended for, children under 18 years of age. Generally, we do not knowingly collect any information, including Personal Data, from children under 18 years of age. If you believe that we have inadvertently collected Personal Data from a child under the age of 18, please contact us at the address in Section 10 (Contact Information) below, and we will take prompt steps to delete the information.
8. External Links
Our Digital Properties may contain links to external sites or other online services that we do not control, including those embedded in third party advertisements or sponsor information. We are not responsible for the privacy practices or data collection policies of such third-party services. You should consult the privacy notices of those third-party services for details on their practices.
9. Supplemental U.S. State Privacy Disclosures
- Data Subject Rights
If you are a resident of California, Nebraska, and Texas, you have certain rights regarding Personal Data, such as:
- Right to Know. You may have the right to request information about the categories of Personal Data we have collected about you, the categories of sources from which we collected the Personal Data, the purposes for collecting, selling, or sharing the Personal Data, and to whom we have disclosed your Personal Data and why. You may also request the specific pieces of Personal Data we have collected about you.
- Right to Delete. You may have the right to request that we delete Personal Data that we have collected about you.
- Right to Correct. You may have the right to request that we correct inaccurate Personal Data that we maintain about you.
- Right to Opt Out of Sales, Sharing, and Targeted Advertising. You may have the right to opt out of selling, sharing, and targeted advertising (as such terms are defined under applicable laws). You can exercise the Right to Opt Out of Sale, Sharing, and Targeted Advertising by accessing the “Your Privacy Choices” link in the footer of our website and turning the “Allow Sale/Sharing/Targeted Advertising” toggle to the “off” position and by emailing us at privacyoffice@surescripts.com.
You may exercise the rights available to you by emailing us at privacyoffice@surescripts.com, or by calling us at 833-713-5186.
To the extent required by law, we will honor opt-out preference signals sent via browser.
We will not discriminate against you for exercising your privacy rights.
Nevada residents: Individuals may contact us at privacyoffice@surescripts.com to inquire about the right to opt out of the sale of Personal Data.
In order to process rights requests, we may need to obtain information to locate you in our records or verify your identity depending on the nature of the request.
- For Requests to Opt-Out of Sale, Sharing, and Targeted Advertising: We collect your name and email to locate you in our records.
- For Requests to Know, Delete, and Correct: We collect information necessary to verify your identity and that you are a resident of a state that provides for these rights, including first and last name, mailing address, email address, telephone number, and relationship to the Company. In some cases, we may request different or additional information, including a signed declaration that you are who you say you are. We will inform you if we need such information.
Authorized Agents: Authorized agents may exercise certain rights on behalf of an individual by submitting a request via privacyoffice@surescripts.com. Authorized agents may submit Requests to Opt Out of Sale, Sharing, and Targeted Advertising on behalf of California, Nebraska, and Texas residents. Authorized agents may additionally submit Requests to Know, Delete, or Correct on behalf of California residents.
- If you designate an authorized agent to submit a Request to Know, Delete, or Correct, we may reach out to you directly to verify your own identity or to confirm that you provided the authorized agent with permission to submit the request.
- If you designate an authorized agent to submit a Request to Opt Out of Sale, Sharing, and Targeted Advertising, we may seek additional information directly from the authorized agent to process the request.
Appeal: If we deny your rights request, you may have the right to appeal. To submit an appeal, email us at privacyoffice@surescripts.com. We will inform you in writing our response to your appeal.
- Additional Data Processing Disclosures for California Residents
California Shine the Light: If you are a California resident, you may opt out of sharing your Personal Data subject to California Civil Code §1798.83 (the “Shine the Light law”) with third parties for those third parties’ direct marketing purposes by emailing privacyoffice@surescripts.com.
10. Contact Information
If you have questions regarding this Privacy Notice, please contact us at:
Surescripts, LLC
2550 S Clark Street
Arlington, Virginia 22202
privacyoffice@surescripts.com
833-713-5186
Contact Us
If you have any questions regarding this Privacy Notice or would like to exercise your rights, please contact us at:
Surescripts, LLC
2550 S Clark Street
Arlington, Virginia 22202
Dean Riggott Photography
Surescripts