Skip to main content
1UTHEALTHLTD®
Policies

Privacy Policy

Plain-English information for visitors, customers and account holders.

This page describes the current application data flows observed in 1UTHEALTHLTD® services. It is not a promise that data is kept for a particular length of time: no fixed retention schedule is currently configured in the application and the Director/legal adviser must approve the final schedule.

Who is responsible?

The service is operated under 1UTHEALTH LTD for the 1UTHEALTHLTD® brand. Contact privacy support at privacy@1uthealthltd.com. A verified registered-office address is not included until Director confirmation.

Information we handle

  • Account identity and profile information supplied through Clerk, such as a verified email and name.
  • Checkout and order information: contact details, delivery and billing addresses, order lines, payment status and fulfilment records. Card details are handled by Stripe and are not stored by this application.
  • Support information: name, email, enquiry type and message.
  • Newsletter email and marketing-consent records.
  • Optional analytics events after consent, plus the local cookie-choice record.
  • Expo device tokens and platform information when an authenticated customer enables order notifications.
  • Angela messages and the page/catalogue context sent with a chat request. A visitor may include health-related text; please do not send unnecessary special-category information.
  • Operational logs and security events. Request and cookie headers are redacted in the configured logger.

Why it is used

The information supports checkout, delivery, customer support, account access, order history, notification delivery, security, troubleshooting, consent records and the operation of Angela. Optional analytics is off until a visitor chooses it. The legal basis for each purpose, and any special-category-data position, requires Director/legal confirmation before final publication.

Service providers

The current flow uses PostgreSQL for application records, Replit-managed Clerk for authentication, Stripe for checkout and payment processing, Replit AI Integrations/OpenAI for Angela, Expo notification services for opted-in push delivery, Google Analytics only after optional consent, App Storage for controlled media, and Titan SMTP only if all delivery settings and explicit enablement are present. The protected email outbox remains disabled when those settings are absent.

Sharing and international processing

Data is sent only to the service providers needed for the selected feature, as described above. The locations, transfer mechanisms and processor terms for each provider must be checked by the Director/legal adviser before launch; this page does not invent those details.

Your choices and rights

  • Use the account area to review account details, addresses and authenticated order history.
  • Request a private, expiring data export from the account area.
  • Request deletion from the account area after explicit confirmation.
  • Reject or withdraw optional analytics consent from Cookie settings.
  • Unsubscribe from marketing messages or contact privacy support.

Some order, payment, tax, fraud, chargeback or accounting evidence may need to be minimised rather than immediately erased. The exact categories and periods are not yet fixed and require legal approval.

Children and health information

The store is not designed to collect children’s personal information directly. Product warnings and the health disclaimer remain important. Angela is general information only, not medical or veterinary advice; seek a qualified professional for health questions.

Privacy questions can be sent to privacy@1uthealthltd.com.