Privacy policyVersion 1.0Effective September 28, 2026
We keep your question, not your chart.
This policy took effect on September 28, 2026 and was last updated on that date. It covers what the Lunivexa inquiry desk stores, how paid ads reach this site, and how you get your data out or deleted. Seven parts. Pick one.
Data we hold
Who runs this site
Lunivexa, trading at lunivexa.us, is the controller of the data described here. Postal address: 73 Workshop Way, Büro 5, Austin, Texas 51576, Austin, Texas, United States. Email [email protected], phone +1 (530) 555-0805. The desk writes reference cards on adult sleep medicines. It does not prescribe, dispense or sell anything, so there is no account, no password, no payment and no card data anywhere on this site.
What reaches us
Four sources. Nothing else on the site records you.
- The inquiry form. It writes your name, phone, email, address (city and state is plenty), the kind of enquiry, your message, the medicine and dose you typed in the specification line, and the consent tick. With it, automatically: your IP address, your browser's user-agent string, the referring URL, the moment the form was rendered and the moment it was sent.
- The support chat. The conversation itself, plus a name, phone or email only if you give one. A token sits in your browser so you can come back to the same thread.
- Technical and log data. Our host's server logs record IP address, time, requested page and user-agent for every request.
- Cookie and click identifiers. Your consent choice is stored in the browser under
site_consent_v2. If you arrive from a paid ad, the link carries a click identifier:gclid,msclkidorfbclid. Part 02 covers those.
We never ask for a diagnosis, date of birth, insurance number or a photo of a prescription label. If you send one anyway, we delete that part and answer the rest.
What each piece is for
- Form and chat content: to read your question, send the card and the prescriber question sheet, and follow up if a card you received is corrected.
- IP, user-agent, timestamps and the hidden honeypot fields: to stop spam and automated submissions.
- Server logs: to keep the site running and trace faults or abuse.
- Consent record: to remember what you chose so the banner does not ask again on every page.
- Click identifiers and ad cookies, only after you allow them: to count which paid campaigns lead to an enquiry, so money stops going to ads that bring nobody.
Legal basis for each use
| Purpose | Data | Legal basis |
|---|---|---|
| Answering your enquiry | Form fields, chat messages | Consent (the tick box), and contract: steps you ask us to take before any agreement |
| Spam and abuse prevention | IP, user-agent, timestamps | Legitimate interest in a working inbox |
| Running the site | Server logs | Legitimate interest |
| Remembering your choice | site_consent_v2 | Legal obligation to record consent, and legitimate interest |
| Ad measurement | gclid, msclkid, fbclid, ad cookies | Consent only. Withdraw it any time |
| Correction notices | Email address | Legitimate interest in telling you a card was wrong |
Ads and measurement
Where paid visitors come from
We buy ads. Google Ads, Microsoft Advertising and Meta Ads send traffic to this site today. When you click one of those ads, the platform adds an identifier to the link:
- Google Ads adds
gclid. - Microsoft Advertising adds
msclkid. - Meta Ads adds
fbclid, where a campaign runs there.
That identifier tells the platform which click led to which visit. We use it to see whether an ad produced an enquiry. It is not linked to the text of your question and it is never sent with the name of a medicine you asked about.
Consent Mode v2
Every page loads with Google Consent Mode v2 defaults set before anything else runs. Four signals start at denied: ad_storage, ad_user_data, ad_personalization and analytics_storage. They stay denied until you press Allow in the cookie banner. Press Decline, or withdraw later through "Cookie settings" in the footer, and all four go straight back to denied. While they are denied, no advertising or analytics cookie is written and the platforms receive only cookieless, aggregate pings.
The same rule applies to the Microsoft and Meta tags. No choice, no ad storage.
Who receives data
- Google Ireland Ltd / Google LLC, for Google Ads. Receives
gclidand the consent signals. - Microsoft Ireland Operations Ltd, for Microsoft Advertising. Receives
msclkid. Its own handling is set out in the Microsoft privacy statement at privacy.microsoft.com/privacystatement. - Meta Platforms Ireland Ltd, for Meta Ads. Receives
fbclidwhere a campaign runs there. - Our hosting provider, which serves this site, keeps the server logs and stores the enquiry database.
- Our mail provider, which carries the notification of a new enquiry to the desk inbox and carries our reply back to you.
We do not sell your data. We do not hand enquiry text to any ad platform.
Data leaving the country
The desk works from the United States, so a question sent from Europe travels here. The ad platforms named above also move data between the EU and the US. Those transfers rely on the EU-US Data Privacy Framework where the recipient is certified, and on the European Commission's standard contractual clauses otherwise. You can ask us which one covers a given recipient.
The support chat
The chat button in the corner opens a thread with the desk. Your first message creates a token. The token lives in your browser's local storage so that closing the tab does not lose the conversation. Clear your browser storage and the token is gone; the transcript on our side stays for its retention period unless you ask us to delete it.
The widget checks for new replies every five seconds, and only while it is open. Closed, it sends nothing.
Name, phone and email are optional in the chat. Leave them blank and you can still ask a question. Don't type anything you would not want a stranger to read over your shoulder: the chat is for "what does the ramelteon label say about fatty meals", not for your medical history.
For an emergency, don't use the chat. Call 911. For a mental health crisis, call or text 988.
Retention and security
How long we keep each thing
| Record | Kept for | Then |
|---|---|---|
| Enquiries and their email copies | 24 months | Deleted |
| Chat transcripts | 12 months | Deleted |
| Server and access logs | 90 days | Overwritten |
| Record of a consent choice | 12 months | The banner asks again |
Twenty-four months for enquiries is deliberate. If a card is corrected under our accuracy guarantee, we need to know who received the old version.
How it is protected
Every page and form is served over HTTPS. The enquiry database sits behind a password-protected operator panel that is not linked from the public site. Access is limited to the people who answer the desk. Spam is filtered with hidden honeypot fields and a render-time check, not with a third-party tracking captcha. We keep what we collect small on purpose: the less we hold, the less there is to lose.
Your rights
If you write from Europe: GDPR
Under the GDPR you can ask for access to what we hold on you, rectification of anything wrong, erasure, restriction of how we use it, portability in a machine-readable file, and you can object to processing based on legitimate interest. Where we rely on consent, you can withdraw it at any time; withdrawing does not undo what was lawful before.
US state privacy rights
California residents have rights under the CCPA as amended by the CPRA: to know what we collect, to delete it, to correct it, to opt out of sale or sharing for cross-context behavioral advertising, and to limit use of sensitive data. Residents of other states with privacy laws in force, including Texas, Virginia, Colorado and Connecticut, have similar rights. We don't sell personal data. Sharing a click identifier with an ad platform can count as "sharing" under the CCPA, so Decline in the banner is your opt-out, and we will not treat you differently for using it.
Global Privacy Control
If your browser sends the Global Privacy Control signal (the Sec-GPC header), we treat it as an opt-out of sale and sharing. The four Consent Mode signals stay denied and we don't ask you again.
Not for anyone under 18
Every card on this site is written for adults. The site is not meant for children and we don't knowingly take data from anyone under 18. If a message comes from a minor, we delete it and reply only to say they should speak to their own prescriber or a parent.
Complaints
Tell us first if you can; most problems are fixed in one email. You can also complain to your state Attorney General, and in California to the California Privacy Protection Agency. Visitors in Europe may complain to the data protection authority of their country.
When this policy changes
A new version gets a new version number and date at the top of this page. If the change affects what we collect or who receives it, the cookie banner appears again so you can choose afresh, and anyone with an open enquiry is told by email.
A person to talk to
Email [email protected], call +1 (530) 555-0805, or write to Lunivexa, 73 Workshop Way, Büro 5, Austin, Texas 51576, United States. The same people who answer medicine questions answer privacy ones.
Accessibility
We aim for WCAG 2.2 level AA. People who read medicine cards include people with low vision, tremor, and a 2 a.m. brain. That shapes the build.
- Every page has a skip link, one main heading and a logical heading order.
- Every control works from the keyboard, with a visible teal focus ring. Tap targets are at least 44 pixels.
- Body text contrast on the off-white ground exceeds 12:1. The ice-teal accent is never the only carrier of meaning; OFF-LABEL is spelled out, not just coloured.
- The night route diagram on the home page carries a text description, and every number on it is repeated in the text beside it.
- Motion respects "reduce motion": the diagram appears fully drawn and still.
- Pages reflow to a 320-pixel screen and to 400% zoom without sideways scrolling.
Known gap: dose tables on narrow phones scroll sideways inside their own box. It is the price of keeping every column. If that or anything else gets in your way, email [email protected] and we will send the card as plain text or read it to you on the phone.
Data request
How to use any of these rights
- Email [email protected] with "Data request" in the subject, or post a letter to Lunivexa, 73 Workshop Way, Büro 5, Austin, Texas 51576, United States.
- Say what you want: a copy, a correction, deletion, a restriction, a portable file, or an opt-out.
- Write from the email address you used with us, or give the name and rough date of your enquiry. That is our identity check. We won't ask for ID documents.
- You get an answer within 10 days. If the request is complex, we tell you inside those 10 days what is taking longer and why.
An authorised agent can make a request for you with your signed permission. There is no charge. We will not refuse a request because it is inconvenient; we refuse only where the law requires us to keep a record, and then we say which record and for how long.
Related: the cookie policy lists every cookie by name, and the terms of use set out the medical disclaimer. Questions about a medicine go through the contact page.