System notice:We're temporarily pausing new orders for scheduled maintenance. Please bear with us — we'll be back shortly. Your existing subscription and medication schedule are unaffected.
Last updated: February 2026 · Disclosure required by HHS OCR 2024 Online Tracking Technology Bulletin
We use a small number of third-party tools to keep the site working and to help us measure anonymous usage patterns. We never share your name, email, date of birth, medical history, weight, prescriptions, or any other Protected Health Information (PHI) with any tracker, advertising network, or social-media platform. We do not run advertising pixels (no Meta Pixel, no Google Ads, no TikTok Pixel, no LinkedIn Insight Tag).
Why we use it: Login session cookies + CSRF token. Required for the site to work — there's no opt-out, but they only live in your browser and contain no PHI.
What it receives: Authentication token (random string), tab session id (random string). Nothing identifying.
How to opt out: Not applicable — cookies are deleted when you log out or clear your browser.
Why we use it: Anonymous page-view counts and feature-usage metrics that help us improve the product.
What it receives: A one-way SHA-256 hash of your account id (we cannot reverse it), your role (patient / admin / prescriber / etc), the page path with all URL parameters stripped, and a coarse-grained event name (e.g. 'checkout_started'). Configured with: autocapture OFF, session recording OFF, IP address OFF, masked inputs ON. We have manually blocklisted $ip and $referrer.
How to opt out: Decline 'analytics' in the cookie banner, or open it again from the footer and toggle off.
Why we use it: When the site crashes, we record the JavaScript stack trace so we can fix the bug.
What it receives: The error message, the file/line where it happened, the page URL (with all query parameters stripped), and your browser version. We run a PHI scrubber that redacts anything that looks like an email, phone, address, dose number, or weight before the error is sent.
How to opt out: Sentry only fires on actual errors and never receives PHI by design. If you want it fully off, decline analytics in the cookie banner — Sentry's PII features are also gated by that toggle.
You can re-open the consent banner any time by clearing your browser's localStorage for this site, or by emailing us at the address below.
To delete or export your tracking-tool footprint, email privacy@glpflo.org with the subject line “Tracking data removal”. We respond within 30 days (HIPAA §164.524 / §164.526).
We respect your privacy.
We use cookies for essential site functionality (always on), and — only with your permission — for product analytics that help us improve your experience. We do not use advertising trackers and we never share Protected Health Information with third-party trackers. Privacy policy · Online tracking disclosure