This supplemental notice is provided for individuals residing in states that have enacted comprehensive state privacy laws. It explains your rights regarding your personal data and how we handle your personal data. Certain terms in this supplemental notice are defined by applicable state law and their meanings may differ from the meanings applied elsewhere on our website.
Sources of Personal Data
We collect personal data from the following categories of sources:
- Your device or browser
- Directly from you when you provide information
- Our affiliates and business partners
- Data verification services & data brokers
- Marketing vendors and advertising networks
- Social media
- Healthcare providers
Personal Data We May Collect
We collect or process the following categories of personal data:
- Identifiers, such as real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, signature, physical characteristic or description, telephone number, insurance policy numbers, employment status, or employment history
- Characteristics of protected classifications, such as race, sex, disability, national origin, marital status
- Commercial information, including records of personal property, products or services purchased, obtained, or considered or other purchasing histories or tendencies
- Biometric information
- Internet or other electronic network activity, including, but not limited to, browsing history, search history, and information regarding interactions with the site
- Geolocation data
- Audio, electronic, visual, thermal, olfactory, or similar information
- Professional or employment-related information
- Education information
- Inferences drawn from any of the information identified above to create a profile about you that reflects your preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligences, abilities, and aptitudes
We collect or process the following categories of sensitive personal data:
- Social security number
- Driver’s license number
- Passport number
- State identification card
- Medical information
- Health insurance information
- Financial information such as, bank account information, credit or debit card number, account log-in, account numbers, required security or access code, password, or credential(s) allowing access to the account
- Precise geolocation
- Racial or ethnic origin, religious or philosophical beliefs, or union membership
- Genetic data
- Biometric information, such as audio, electronic, visual, thermal, olfactory, or similar information
- Personal information collected and analyzed concerning your sex life or sexual orientation
- Personal information collected and analyzed concerning your health
Processing, Disclosure, and Retention of Personal Data
The categories of data collected and listed above will be processed, disclosed, sold, shared, and retained as described below:
Processing Purpose
Business Purposes:
- To perform the business services you have requested and/or to provide reasonably expected goods
- To develop new products and services
- To provide personalized and non-personalized offers and services based on your interactions with our site/product or affiliated vendors utilizing your browsing history, search history, and interactions with our site products, or services
- To detect security incidents that compromise the availability, integrity, authenticity, and confidentiality of stored or transmitted personal information
- To prevent malicious, deceptive, fraudulent, or illegal actions and to prosecute those responsible for those actions
- To protect our rights, property, and safety or the rights, property, and safety of others
- To perform services, such as maintaining or servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying information, processing payments, providing financing, providing analytic services, or providing storage
- To verify, analyze, maintain, or enhance the quality or safety of our products and services
- To offer or provide employee benefits and services
- To comply with legal obligations
Commercial Purposes:
- For targeted advertising. We utilize cookies, pixels, and other advertising technology to provide users personalized ads.
- For profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer
Categories of Third Parties to which we Disclose that Personal Data
- Our vendors and service providers
- Healthcare providers
- Advertising networks, who may use your browsing history, search history, and information regarding your interaction with the site
- Our affiliates and business partners
- Law enforcement, when required by law
Categories of Third Parties to which we “Sold” or “Shared” that Personal Data
- Our vendors and service providers
- Healthcare providers
- Advertising networks, who may use your browsing history, search history, and information regarding your interaction with the site
- Our affiliates and business partners
- Law enforcement, when required by law
We do not knowingly sell or share personal data of residents under the age of 16.
Retention
- We retain your data in accordance with applicable contracts, Terms of Service, regulatory/legal obligations, or as otherwise allowed.
There are times when personal data is disclosed externally with other companies, organizations, or individuals when we have a good faith belief that access, use, preservation, or disclosure of that data is reasonably necessary to:
- Meet applicable laws, regulations, legal processes, or enforceable governmental requests
- Enforce applicable Terms of Service, including investigation of potential violations
- Detect, prevent, or otherwise address fraud, security, or technical issues
- Protect against harm to the rights, property or safety of our users, McKesson, or the public as required or permitted by law
- Engage in a merger, acquisition, reorganization, or sale of all or a portion of the business’s assets
We sell or share deidentified information. Deidentified information is data that is no longer considered individually identifiable and has been deidentified in compliance with either the HIPAA expert determination method or the HIPAA safe harbor method as described in Sections 164.514(b)(1) and (2) of the Code of Federal Regulations.
Your Rights
If you or your authorized representative would like to exercise one of your rights, please contact us by clicking HERE or call this toll-free number at 1-833-925-0545. If required by applicable state privacy laws, we will request certain identifying information from you or your authorized representative to verify your identity. We will honor your request if it is in compliance with applicable state privacy laws. Questions and concerns can be emailed to Privacy@McKesson.com.
Contact Information
If required by your state, we will provide you the opportunity to appeal certain decisions made by us related to your rights. For each request you submit, we will inform you of the action we have taken in response to your request. If your state requires it, you will be provided the opportunity to appeal our decision by following the instructions in our response.
If you have questions or concerns about this Privacy Notice, you may contact us at Privacy@McKesson.com.