Last Updated: March 3, 2026
Your privacy is critically important to us. As a medical cannabis platform, we are committed to protecting your sensitive health-related information with the highest standards of data security and privacy compliance.
Weedable ("Company," "we," "us," or "our") operates the Weedable mobile application and website at weedable.com (collectively, the "Platform"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Platform.
We understand that cannabis-related data is particularly sensitive. We are committed to handling your information responsibly and in compliance with applicable privacy laws, including the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and applicable state cannabis privacy regulations.
| Category | Data Collected | Purpose |
|---|---|---|
| Account Information | Name, email, phone number, date of birth | Account creation, age verification, communication |
| Identity Verification | Government-issued photo ID, selfie verification | Age and identity verification (21+ compliance) |
| Medical Information | Medical cannabis card number, expiration date, issuing state | Medical cannabis purchase eligibility verification |
| Payment Information | Credit/debit card details, billing address | Payment processing (handled by Stripe) |
| Order Information | Purchase history, delivery addresses, fulfillment preferences | Order processing and fulfillment |
| Communication Data | Live stream chat messages, support inquiries | Community features, customer support |
We treat medical cannabis card information and purchase history as sensitive health-related data. This information receives enhanced protection and is never sold, shared for advertising purposes, or disclosed to third parties except as required for order fulfillment or by law.
We implement the following safeguards for medical cannabis-related data:
While Weedable is not a covered entity under HIPAA, we voluntarily adopt HIPAA-aligned security practices for medical cannabis data. This includes administrative, physical, and technical safeguards to protect the confidentiality and integrity of your health-related information.
We use your information for the following purposes:
We share your information only in the following circumstances:
When you place an order, we share necessary information with the Seller to fulfill your order, including your name, contact information, delivery address (if applicable), and order details. For medical cannabis orders, we share verification status (not your actual medical card details) with the Seller.
We use trusted third-party service providers for:
We may disclose your information when required by law, including:
We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We do not share your data with data brokers or advertising networks.
We implement industry-standard security measures including:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account Information | Duration of account + 3 years | Legal compliance, dispute resolution |
| Purchase History | 7 years | State cannabis regulatory requirements, tax records |
| Medical Card Data | Duration of card validity + 1 year | Eligibility verification, regulatory compliance |
| ID Verification Images | Deleted after verification (max 30 days) | Age verification only |
| Payment Data | Managed by Stripe per PCI DSS | Payment processing |
| Chat Messages | 90 days | Community safety, moderation |
If you are a California resident, you have the right to:
Regardless of your location, you may:
The Platform is strictly for users aged 21 and older. We do not knowingly collect information from anyone under 21. If we discover we have collected information from a person under 21, we will immediately delete that information and terminate the associated account.
The Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.
With your consent, we may send push notifications about live streams, order updates, deals, and other Platform features. You can manage notification preferences in the app settings or through your device settings at any time.
We may update this Privacy Policy from time to time. We will notify you of material changes through the Platform, via email, or by posting a prominent notice. Your continued use of the Platform after changes take effect constitutes acceptance of the updated policy.
For privacy-related questions, data requests, or concerns:
We will respond to all privacy requests within 45 days as required by applicable law.