This Privacy Policy describes how GLP1Zoom("we," "us," or "our") collects, uses, and shares information when you visit our website at GLP1Zoom.com (the "Site"). By using the Site, you agree to the practices described below.
GLP1Zoom is a comparison and editorial site for GLP-1 weight loss and diabetes medications and the telehealth providers that prescribe them. GLP1Zoom is not a pharmacy, healthcare provider, insurance company, or manufacturer. We do not sell, prescribe, dispense, or ship any medication. We earn commission when users sign up with our partner telehealth providers.
Information we collect
We collect information in three ways: information you provide directly, information collected automatically, and information from third parties.
Information you provide
- Newsletter subscription: Your email address when you sign up for GLP1Zoom price alerts.
- Contact forms: Your name, email, and message content if you contact us via forms or email.
- Optional inputs in calculators and quizzes: Self-reported preferences such as budget range or goal. These inputs are processed in-session and are not stored against an account.
Information collected automatically
- Device and browser data: IP address, user agent, screen size, locale, timezone.
- Usage data: Pages you visit, links you click, time spent on pages, referrer URL.
- Cookies: See the Cookies section below.
Information from third parties
- Affiliate networks: Conversion data (whether a user who clicked a partner link completed a signup) from our affiliate partners. This data is anonymous to us.
- Analytics providers: Aggregated usage statistics from our analytics provider.
How we use information
- To operate, maintain, and improve the Site and its content.
- To send you the newsletter you subscribed to.
- To respond to your inquiries.
- To measure the effectiveness of affiliate partnerships and editorial content.
- To detect, prevent, and address fraud and security issues.
- To comply with legal obligations.
How we share information
We do not sell your personal information. We share limited information only as follows:
- Service providers (sub-processors): Vendors that process information on our behalf under written data-processing agreements. Current list:
- Hetzner Online GmbH (Germany) — VPS hosting, infrastructure logs.
- Cloudflare, Inc. (United States) — CDN, DDoS protection, edge IP-to-state geolocation. IP addresses transit Cloudflare edge before reaching our origin.
- Resend (Plaid Labs Inc.) (United States) — transactional and newsletter email delivery.
- Plausible Analytics (Plausible Insights OÜ) (Estonia, EU) — cookieless, IP-anonymized aggregate pageview analytics. No cross-site tracking.
- Sentry (Functional Software, Inc.) (United States) — JavaScript error monitoring. PII scrubbed before transmission; no form input contents.
- Anthropic, PBC(United States) — AI assistant inference for the "Ask GLP1Zoom" tool. We send the question and recent chat turns; we do not send your identity. See /ai-privacy.
- Affiliate partners:When you click a partner link, your browser is directed to the partner's site. The partner sets its own cookies and applies its own privacy policy. We receive only aggregate conversion data, not your personal details.
- Legal compliance: When required by law, court order, or to protect rights, safety, or property.
- Business transfers: In connection with a merger, acquisition, or sale of assets.
Cookies and tracking
We use cookies and similar technologies to operate the Site, remember your preferences (such as announcement bar dismissal), and measure usage. You can manage cookies through your browser settings or our cookie consent banner. Disabling cookies may limit some features.
We use the following categories: strictly necessary (required for the site to function), analytics (anonymous usage measurement), and affiliate tracking (to attribute partner signups). We do not use cookies for advertising or cross-site tracking.
Your privacy rights (CCPA and state laws)
If you are a resident of California, Virginia, Colorado, Connecticut, or another US state with a consumer privacy law, you have the following rights:
- Right to know: Request a copy of the personal information we hold about you.
- Right to delete: Request deletion of your personal information, subject to legal retention obligations.
- Right to correct: Request correction of inaccurate information.
- Right to opt out of sale or sharing: GLP1Zoom does not sell or share personal information for cross-context behavioral advertising. There is nothing to opt out of, but you can submit a request to confirm this status.
- Right to non-discrimination: We will not deny services or charge different prices for exercising your rights.
To exercise any of these rights, email [email protected]. We will respond within 45 days as required by law.
Data retention
We retain personal information only as long as needed for the purposes for which it was collected, plus any period required or permitted by law. Specific retention windows:
| Data category | Retention period | Reason |
|---|---|---|
| Newsletter subscriber email | Until unsubscribe + 30 days | Suppression list to honor opt-out |
| Contact form submissions | 24 months | Audit + dispute response |
| Server access logs (incl. IP) | 30 days raw, then aggregated | Security + abuse investigation |
| Affiliate click attribution | 30 days (per click cookie window) | Commission settlement window |
| Aggregated analytics (Plausible) | 26 months | Year-over-year trend reporting |
| Error reports (Sentry) | 90 days | Debugging + reliability |
| Editorial account (admin only) | Active + 12 months after offboarding | Audit trail for byline accuracy |
| Audit logs (admin actions) | 7 years | SOC 2 / business records standard |
After the retention window we either delete or irreversibly de-identify the data. Backups are purged on a rolling 35-day cycle.
Global Privacy Control (GPC) & Do Not Track
When your browser sends a Global Privacy Control signal, we treat it as a valid opt-out of analytics and affiliate-attribution cookies for the duration of the session, per California Privacy Protection Agency guidance (11 CCR § 7025). We additionally honor the legacy Do Not Track header as a non-binding opt-out of analytics.
Security
We use industry-standard technical and organizational measures to protect information. No method of transmission or storage is 100% secure. We cannot guarantee absolute security but we work to promptly notify users of any breach that affects them, in accordance with applicable law.
Children's privacy
GLP1Zoom is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided information, contact us and we will delete it.
International users
GLP1Zoom is operated in the United States and is intended for US residents. We do not currently offer services to residents of the European Economic Area or the United Kingdom. If you access the Site from outside the US, you do so at your own initiative and are responsible for compliance with local laws.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last reviewed" date at the top of the page. Material changes will be communicated via the newsletter or a prominent notice on the Site.
HIPAA & protected health information
GLP1Zoom is not a HIPAA-covered entity. We do not provide healthcare, do not issue prescriptions, and do not exchange Protected Health Information (PHI) with patients, providers, or pharmacies. Information you voluntarily type into our calculators or the AI assistant is processed in-session only and is not stored against an account or shared with telehealth partners. Do not send PHI through our contact forms; if you have a question about your treatment, contact the prescribing clinician directly.
Contact & data-subject rights submissions
For privacy questions, data-subject access / deletion / correction requests, or to exercise CCPA / state privacy rights:
- Email: [email protected] (most requests resolved within 10 business days, statutory maximum 45 days)
- Mail: see /contact-info for the legal service address.
- California GPC opt-out:automatic — see "Global Privacy Control" section above.
- EU / UK supervisory authority complaint: EU and UK visitors may also lodge a complaint with their local Data Protection Authority. We currently do not target EU/UK residents.
See also: Terms of Use, Affiliate Disclosure, Medical Disclaimer.