Weedable Weedable ← Back to Home

Privacy Policy

Last Updated: March 3, 2026

Your privacy is critically important to us. As a medical cannabis platform, we are committed to protecting your sensitive health-related information with the highest standards of data security and privacy compliance.

1. Introduction

Weedable ("Company," "we," "us," or "our") operates the Weedable mobile application and website at weedable.com (collectively, the "Platform"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Platform.

We understand that cannabis-related data is particularly sensitive. We are committed to handling your information responsibly and in compliance with applicable privacy laws, including the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and applicable state cannabis privacy regulations.

2. Information We Collect

2.1 Information You Provide

Category Data Collected Purpose
Account Information Name, email, phone number, date of birth Account creation, age verification, communication
Identity Verification Government-issued photo ID, selfie verification Age and identity verification (21+ compliance)
Medical Information Medical cannabis card number, expiration date, issuing state Medical cannabis purchase eligibility verification
Payment Information Credit/debit card details, billing address Payment processing (handled by Stripe)
Order Information Purchase history, delivery addresses, fulfillment preferences Order processing and fulfillment
Communication Data Live stream chat messages, support inquiries Community features, customer support

2.2 Information Collected Automatically

  • Device Information: Device type, operating system, unique device identifiers, mobile network information
  • Usage Data: Pages viewed, features used, time spent on the Platform, live streams watched
  • Location Data: Approximate location (city/state level) to verify you are in a legal cannabis state. We do not track precise GPS location without your explicit consent.
  • Log Data: IP address, browser type, access times, referring URLs

3. Sensitive Health Information

We treat medical cannabis card information and purchase history as sensitive health-related data. This information receives enhanced protection and is never sold, shared for advertising purposes, or disclosed to third parties except as required for order fulfillment or by law.

3.1 Medical Cannabis Data Protections

We implement the following safeguards for medical cannabis-related data:

  • Encryption: All medical card information is encrypted at rest and in transit using AES-256 encryption
  • Access Controls: Only authorized personnel with a legitimate business need can access medical data
  • Data Minimization: We collect only the minimum medical information necessary to verify eligibility
  • Retention Limits: Medical card images are deleted after verification; only the card number and expiration are retained
  • No Advertising Use: Medical cannabis data is never used for targeted advertising or shared with ad networks

3.2 HIPAA Considerations

While Weedable is not a covered entity under HIPAA, we voluntarily adopt HIPAA-aligned security practices for medical cannabis data. This includes administrative, physical, and technical safeguards to protect the confidentiality and integrity of your health-related information.

4. How We Use Your Information

We use your information for the following purposes:

  • Service Delivery: Processing orders, facilitating live streams, managing your account
  • Legal Compliance: Age verification, purchase limit enforcement, state regulatory compliance, METRC/seed-to-sale tracking
  • Communication: Order updates, live stream notifications, customer support
  • Platform Improvement: Analytics, bug fixes, feature development (using anonymized/aggregated data)
  • Safety and Security: Fraud prevention, abuse detection, platform integrity

5. Information Sharing

We share your information only in the following circumstances:

5.1 With Dispensary Sellers

When you place an order, we share necessary information with the Seller to fulfill your order, including your name, contact information, delivery address (if applicable), and order details. For medical cannabis orders, we share verification status (not your actual medical card details) with the Seller.

5.2 With Service Providers

We use trusted third-party service providers for:

  • Payment Processing: Stripe (PCI DSS Level 1 compliant)
  • Live Streaming: Mux (video infrastructure)
  • Cloud Infrastructure: AWS (SOC 2 Type II certified)
  • Analytics: Anonymized usage analytics only

5.3 Legal Requirements

We may disclose your information when required by law, including:

  • Response to valid legal process (subpoena, court order, warrant)
  • State cannabis regulatory audits or investigations
  • Protection of our rights, safety, or property
  • Emergency situations involving potential harm

5.4 We Never Sell Your Data

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We do not share your data with data brokers or advertising networks.

6. Data Security

We implement industry-standard security measures including:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • Multi-factor authentication for administrative access
  • Regular security audits and penetration testing
  • Incident response procedures with 72-hour breach notification
  • Employee security training and background checks

7. Data Retention

Data Type Retention Period Reason
Account Information Duration of account + 3 years Legal compliance, dispute resolution
Purchase History 7 years State cannabis regulatory requirements, tax records
Medical Card Data Duration of card validity + 1 year Eligibility verification, regulatory compliance
ID Verification Images Deleted after verification (max 30 days) Age verification only
Payment Data Managed by Stripe per PCI DSS Payment processing
Chat Messages 90 days Community safety, moderation

8. Your Privacy Rights

8.1 California Residents (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know: Request disclosure of the categories and specific pieces of personal information we collect
  • Delete: Request deletion of your personal information (subject to legal retention requirements)
  • Correct: Request correction of inaccurate personal information
  • Opt-Out: Opt out of the sale or sharing of personal information (we do not sell your data)
  • Non-Discrimination: Exercise your rights without discriminatory treatment

8.2 All Users

Regardless of your location, you may:

  • Access and download your personal data
  • Update or correct your account information
  • Delete your account and associated data
  • Opt out of marketing communications
  • Manage notification preferences

9. Children's Privacy

The Platform is strictly for users aged 21 and older. We do not knowingly collect information from anyone under 21. If we discover we have collected information from a person under 21, we will immediately delete that information and terminate the associated account.

10. Third-Party Links

The Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.

11. Push Notifications

With your consent, we may send push notifications about live streams, order updates, deals, and other Platform features. You can manage notification preferences in the app settings or through your device settings at any time.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes through the Platform, via email, or by posting a prominent notice. Your continued use of the Platform after changes take effect constitutes acceptance of the updated policy.

13. Contact Us

For privacy-related questions, data requests, or concerns:

  • Privacy Officer: privacy@weedable.com
  • General Inquiries: support@weedable.com
  • Website: weedable.com

We will respond to all privacy requests within 45 days as required by applicable law.

© 2026 Weedable. All rights reserved. | Terms | Privacy | Home