A&A Family Pharmacy
Website Privacy Policy
Effective date: April 23, 2026 · Last updated: April 23, 2026
1. About this policy and its scope
This Website Privacy Policy explains how A&A Med Solutions LLC d/b/a A&A Family Pharmacy (“A&A Family Pharmacy,” “we,” “us,” or “our”) collects, uses, and shares information through our website at aafamilypharmacy.comand any subdomains we operate (the “Site”). It covers ordinary website data: analytics, cookies, contact-form submissions, IP addresses, browser and device data, and information you provide through general forms that do not involve your medications, health conditions, or insurance.
This policy does not govern Protected Health Information (PHI). Our collection, use, and disclosure of PHI — information related to your prescriptions, diagnoses, treatment, payment, or pharmacy services — is governed by our Notice of Privacy Practices under the Health Insurance Portability and Accountability Act (HIPAA). If there is any conflict between this policy and the Notice of Privacy Practices regarding PHI, the Notice of Privacy Practices controls. You can read it at aafamilypharmacy.com/notice-of-privacy-practices or request a paper copy from the pharmacy.
2. Information we collect
Information you give us directly
When you use a form on the Site — for example, the contact form, a general inquiry, or an email-subscription form — we collect the information you provide, such as your name, email, phone number, subject, and message. When you use the Prescription Transfer form, you may also provide information that is PHI (medications, prescriber, insurance); that information is handled under the Notice of Privacy Practices, not this policy, but the non-PHI metadata surrounding your submission (timestamp, IP address, browser user-agent) is covered here.
Information collected automatically
When you visit the Site we automatically collect:
- Device & connection data: IP address (in truncated or hashed form where feasible), browser type and version, operating system, referring URL, language preference, and general geographic region inferred from IP.
- Usage data: pages viewed, time on page, clicks, scroll depth, and the date/time of your visit.
- Cookies and similar technologies: small data files stored on your device. See section 4.
Information from third parties
We do not buy personal information from data brokers. If you reach us through a review platform, social network, or online directory, we receive only what you choose to send.
3. How we use website information
We use non-PHI website information to:
- Operate, secure, and improve the Site and fix technical problems.
- Respond to inquiries and provide requested information.
- Protect against fraud, abuse, and unauthorized access.
- Understand aggregate usage trends so we can improve content and navigation.
- Comply with legal obligations and enforce our Terms of Use.
We do not sell your personal information, and we do not use your website data for targeted advertising on third-party platforms.
5. Third-party services we use
We rely on a small number of vendors to run the Site. Current vendors include:
- Vercel Inc. — our hosting, content delivery, and infrastructure provider. Vercel processes server-side request logs (including IP addresses) for security and performance purposes.
- Google Maps / Google Search links— outbound links to Google services. When you click one, Google's privacy policy applies.
- Email delivery providers (when you contact us) — used to transmit your message to our team.
If we add or change a vendor that materially affects this policy, we will update the policy and the “Last updated” date. Any third-party service that touches PHI operates under a HIPAA Business Associate Agreement (BAA) and is described in our Notice of Privacy Practices, not here.
7. How long we keep information
Analytics / logs: typically 14 months or less, then deleted or aggregated.
Contact-form submissions: typically 24 months, unless a longer period is needed to respond to your request or comply with law.
Prescription-transfer submissions (non-PHI metadata): retained consistent with pharmacy recordkeeping; PHI is retained per the Notice of Privacy Practices and Florida pharmacy law (typically four years from the last dispensing event, per Fla. Admin. Code 64B16-28.140).
8. Your rights and choices
All visitors can:
- Ask what personal information we hold about you and request a copy.
- Ask us to correct inaccurate information.
- Ask us to delete information, subject to legal retention requirements.
- Opt out of non-essential communications (every marketing email has an unsubscribe link).
Florida residents— under the Florida Digital Bill of Rights (Fla. Stat. §501.71 et seq., effective July 1, 2024) — may have additional rights if the controller meets the statute's revenue/volume thresholds. A&A Family Pharmacy is a local retail pharmacy and does not currently meet those thresholds, but we voluntarily extend access, correction, deletion, and opt-out-of-sale rights to Florida residents on request.
California residents— under the CCPA/CPRA — have rights to know, delete, correct, and opt out of “sale” or “sharing.” We do not “sell” or “share” personal information as those terms are defined under California law. To exercise any right, contact us using the details in section 12.
Other U.S. states (Colorado, Connecticut, Virginia, etc.) — we honor comparable rights on request even where our size may place us below a statutory threshold.
Do Not Track (DNT) and Global Privacy Control (GPC).Because there is no common standard for DNT, we do not respond to DNT headers. We do honor Global Privacy Control signals as a valid opt-out of any “sale” or “sharing” for jurisdictions that recognize it.
9. Children's privacy
The Site is intended for adults. We do not knowingly collect personal information from children under 13 in violation of the Children's Online Privacy Protection Act (COPPA). If you believe a child has submitted information to us, contact us and we will delete it.
10. Security
We use reasonable administrative, technical, and physical safeguards — HTTPS/TLS in transit, access controls, logging, and vendor due diligence. No system is perfectly secure. Do not send sensitive health information by unencrypted email; use the forms provided on the Site, call the pharmacy, or visit us in person.
11. Changes to this policy
We may update this policy to reflect changes in our practices, our vendors, or the law. When we do, we will update the “Last updated” date at the top and, for material changes, post a notice on the Site.
12. Contact us
Privacy Officer: Navneet Johar
A&A Family Pharmacy
7938 Pines Blvd, Pembroke Pines, FL 33024Phone: (954) 987-5230
Email: pharmacynav@gmail.com
For PHI-related matters (prescriptions, insurance, health conditions), see our Notice of Privacy Practices.
