Privacy policy
PRIVACY POLICY
Mish Health Ventures PLLC DBA Venus Well and Venus and Mars Well
Last Updated: June 8, 2026
Website: https://joinvenuswell.com
Mish Health Ventures PLLC DBA Venus Well and Venus and Mars Well ("we," "our," or "us") operates this store and website, including all related information, content, features, tools, products and services, in order to provide you, the customer, with a curated shopping experience (the "Services"). Our store is powered by Shopify, which enables us to provide the Services to you. This Privacy Policy describes how we collect, use, and disclose your personal information when you visit, use, or make a purchase or other transaction using the Services or otherwise communicate with us. If there is a conflict between our Terms of Service and this Privacy Policy, this Privacy Policy controls with respect to the collection, processing, and disclosure of your personal information.
Please read this Privacy Policy carefully. By using and accessing any of the Services, you acknowledge that you have read this Privacy Policy and understand the collection, use, and disclosure of your information as described in this Privacy Policy.
This Privacy Policy also complies with applicable state privacy laws, including the California Consumer Privacy Act (CCPA), Nevada Consumer Health Data Privacy Law, and the Washington My Health My Data Act (MHMDA). Where state laws impose stricter requirements than federal law, we adhere to the stricter standard. This Privacy Policy should be read in conjunction with our Consumer Health Data Policy and Notice of Privacy Practices, which provide additional details on our data handling practices, patient rights, and state-specific compliance.
Personal Information We Collect or Process
When we use the term "personal information," we are referring to information that identifies or can reasonably be linked to you or another person. Personal information does not include information that is collected anonymously or that has been de-identified. We may collect or process the following categories of personal information, depending on how you interact with the Services, where you live, and as permitted or required by applicable law:
-
Contact details including your name, address, billing address, shipping address, phone number, and email address.
-
Financial information including credit card, debit card, and financial account numbers, payment card information, transaction details, form of payment, and payment confirmation.
-
Account information including your username, password, security questions, preferences and settings.
-
Transaction information including the items you view, put in your cart, add to your wishlist, or purchase, return, exchange or cancel and your past transactions.
-
Communications with us including the information you include in communications with us, for example, when sending a customer support inquiry.
-
Device information including information about your device, browser, or network connection, your IP address, and other unique identifiers.
-
Usage information including information regarding your interaction with the Services, including how and when you interact with or navigate the Services.
-
Health Information including medical history, lifestyle data, symptoms, treatment options, medical records, and other relevant information you provide when seeking healthcare services.
-
Sensitive Personal Information including health-related data, information about your sex life or sexual orientation, and sensitive demographic data such as race and ethnicity.
Personal Information Sources
We may collect personal information from the following sources:
-
Directly from you, including when you create an account, visit or use the Services, communicate with us, or otherwise provide us with your personal information.
-
Automatically through the Services, including from your device when you use our products or services or visit our websites, and through the use of cookies and similar technologies.
-
From our service providers, including when we engage them to enable certain technology and when they collect or process your personal information on our behalf.
-
From our partners or other third parties, including healthcare providers, labs, or pharmacies.
How We Use Your Personal Information
Depending on how you interact with us or which of the Services you use, we may use personal information for the following purposes:
-
Provide, Tailor, and Improve the Services. We use your personal information to provide you with the Services, including to process payments, fulfill orders, remember your preferences, send account-related notifications, process returns and exchanges, maintain your account, arrange shipping, and create a customized shopping experience for you.
-
Provide and Manage Healthcare Services. We use your information to facilitate healthcare services, verify your identity, maintain your health records, and coordinate with healthcare providers.
-
Marketing and Advertising. We use your personal information for marketing and promotional purposes, such as to send communications by email, text message or postal mail, and to show you online advertisements based on your activity and purchases.
-
Security and Fraud Prevention. We use your personal information to authenticate your account, provide a secure payment and shopping experience, detect and investigate potentially fraudulent or illegal activity, and secure our services.
-
Communicating with You. We use your personal information to provide customer support, respond to your inquiries, and maintain our business relationship with you.
-
Analytics and Improvements. We conduct research and analysis to improve our Services and enhance user experience.
-
Legal Reasons. We use your personal information to comply with applicable law, respond to valid legal process, enforce our terms and policies, and protect our rights and the rights of others.
How We Disclose Personal Information
In certain circumstances, we may disclose your personal information to third parties for legitimate purposes subject to this Privacy Policy:
-
With Shopify and other vendors and third parties who perform services on our behalf, including IT management, payment processing, data analytics, customer support, cloud storage, fulfillment, and shipping.
-
With healthcare providers and business associates under signed agreements requiring compliance with HIPAA and applicable laws. PHI is disclosed only to the minimum extent necessary to accomplish the intended purpose.
-
With business and marketing partners to provide marketing services and advertising. Our business and marketing partners will use your information in accordance with their own privacy notices. Depending on where you reside, you may have a right to opt out of targeted advertising based on your online activity. You can exercise this right at https://joinvenuswell.com/pages/data-sharing-opt-out.
-
When you direct, request, or otherwise consent to our disclosure of certain information to third parties, such as to ship you products or through your use of social media widgets or login integrations.
-
In connection with a business transaction such as a merger or bankruptcy, to comply with any applicable legal obligations, to enforce our terms of service or policies, and to protect or defend the Services and our users.
We do not sell your personal information.
Relationship with Shopify
The Services are hosted by Shopify, which collects and processes personal information about your access to and use of the Services in order to provide and improve the Services for you. Information you submit to the Services will be transmitted to and shared with Shopify as well as third parties that may be located in countries other than where you reside. To learn more about how Shopify uses your personal information and any rights you may have, please visit the Shopify Consumer Privacy Policy at https://www.shopify.com/legal/privacy/app-users. You may also exercise certain rights with respect to your personal information through the Shopify Privacy Portal at https://privacy.shopify.com/en.
Third Party Websites and Links
The Services may provide links to websites or other online platforms operated by third parties. If you follow links to sites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such sites. Our inclusion of such links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the Services.
Online Analytics and Advertising
We may use third-party web analytics services such as Google Analytics and Meta/Facebook Ads to collect and analyze usage information. These services help us understand how users interact with our Services and assist with personalized advertising. You may opt out of cross-device tracking and tailored advertisements through your mobile device settings or applicable opt-out tools provided by these services.
Children's Data
The Services are not intended to be used by children, and we do not knowingly collect any personal information about children under the age of 18. If you are the parent or guardian of a child who has provided us with their personal information, you may contact us using the contact details set out below to request that it be deleted. As of the effective date of this Privacy Policy, we do not have actual knowledge that we "share" or "sell" (as those terms are defined in applicable law) personal information of individuals under 16 years of age. If services for minors are offered in the future, additional consents and policies will apply.
Security and Retention of Your Information
We use a variety of security measures, including encryption and access controls, to protect your personal information. Please be aware that no security measures are perfect or impenetrable, and we cannot guarantee absolute security. In addition, any information you send to us may not be secure while in transit. We recommend that you do not use unsecured channels to communicate sensitive or confidential information to us.
All staff members undergo regular training on HIPAA compliance, data security, and our privacy policies to ensure they understand their responsibilities for protecting protected health information (PHI) and sensitive data.
How long we retain your personal information depends on different factors, such as whether we need the information to maintain your account, to provide you with Services, comply with legal obligations, resolve disputes, or enforce other applicable contracts and policies. PHI is retained for a minimum of six (6) years, as required by HIPAA regulations. Once information is no longer required, we securely delete or anonymize it.
In the event of a data breach involving your PHI or personal information, we will notify you as required by law. Notifications will be made no later than 60 days after the discovery of the breach, in accordance with HIPAA regulations, and will include details about the breach, the type of information involved, steps you can take to protect yourself, and actions we are taking to mitigate harm and prevent future incidents. We will also notify the U.S. Department of Health and Human Services (HHS) as required.
Your Rights and Choices
Depending on where you live, you may have some or all of the rights listed below in relation to your personal information. These rights are not absolute, may apply only in certain circumstances and, in certain cases, we may decline your request as permitted by law.
-
Right to Access / Know. You may have a right to request access to personal information that we hold about you.
-
Right to Delete. You may have a right to request that we delete personal information we maintain about you.
-
Right to Correct. You may have a right to request that we correct inaccurate personal information we maintain about you.
-
Right of Portability. You may have a right to receive a copy of the personal information we hold about you and to request that we transfer it to a third party, in certain circumstances and with certain exceptions.
-
Right to Opt Out of Sale or Sharing for Targeted Advertising. Depending on where you reside, you may have a right to opt out of the "sale" or "share" of your personal information or to opt out of the processing of your personal information for purposes considered to be "targeted advertising." You can exercise this right at https://joinvenuswell.com/pages/data-sharing-opt-out. If you visit our website with the Global Privacy Control opt-out preference signal enabled, we will treat this as an opt-out request for the device and browser you use to visit the website. To learn more, visit https://globalprivacycontrol.org/.
-
Managing Communication Preferences. We may send you promotional emails, and you may opt out of receiving these at any time by using the unsubscribe option in our emails. If you opt out, we may still send you non-promotional emails, such as those about your account or orders.
-
Right to Accounting of Disclosures. You have the right to request an accounting of certain disclosures of your PHI made by us, including disclosures for purposes other than treatment, payment, and healthcare operations. Requests can be made by contacting our Privacy Officer.
You may exercise any of these rights by contacting us using the contact details provided below. We will not discriminate against you for exercising any of these rights. We may need to verify your identity before processing your requests. You may also designate an authorized agent to make requests on your behalf; we will require proof of authorization and may need to verify your identity directly with you. We will respond to your request in a timely manner as required under applicable law.
Cookie Preferences
We reserve the right to implement cookies and similar tracking technologies to improve user experience, analyze website traffic, or provide personalized content. Any updates to our use of cookies will be reflected in this Privacy Policy and, where required by law, we will notify users and obtain their consent before using such technologies. You can manage your cookie settings through your browser settings.
Complaints
If you have complaints about how we process your personal information, please contact us using the contact details provided below. Depending on where you live, you may have the right to appeal our decision or lodge your complaint with your local data protection authority.
International Transfers
Please note that we may transfer, store, and process your personal information outside the country you live in. If we transfer your personal information out of the European Economic Area or the United Kingdom, we will rely on recognized transfer mechanisms like the European Commission's Standard Contractual Clauses, or equivalent contracts issued by the relevant competent authority of the UK, as relevant, unless the data transfer is to a country that has been determined to provide an adequate level of protection.
State-Specific Privacy Rights
California Residents (CCPA)
If you are a resident of California, the California Consumer Privacy Act (CCPA) grants you the following rights:
-
Right to Know: You can request details about the categories and specific pieces of personal information we collect about you.
-
Right to Delete: You can request that we delete your personal information, subject to certain exceptions.
-
Right to Opt-Out of Sale: We do not sell personal information, but you can request to opt-out of sharing for advertising purposes.
-
Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
To make a request, please contact us at megan@venusandmarswell.com. We may need to verify your identity before responding.
Texas Residents
Under Texas law, we may process your sensitive personal information (such as health data) in accordance with your consent. You have the right to request that we limit the use of your sensitive information for purposes other than providing you with the services you have requested. To request a limitation on the use of your sensitive data, please contact us at megan@venusandmarswell.com.
Nevada Residents
Nevada residents may opt out of the sale of "personally identifiable information" by contacting us at megan@venusandmarswell.com. While we do not currently sell personal information, we will process your request should our practices change.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will post the revised Privacy Policy on this website, update the "Last Updated" date, and provide notice as required by applicable law. Your continued use of the Services after any changes are posted constitutes your acknowledgment of the updated Privacy Policy.
Contact
Should you have any questions about our privacy practices or this Privacy Policy, or if you would like to exercise any of the rights available to you, please contact us:
Mish Health Ventures PLLC DBA Venus Well and Venus and Mars Well
Email: privacy@venusandmarswell.com
Address: 212 N. 2nd St. STE 100, Richmond, KY 40475, United States
CONSUMER HEALTH DATA PRIVACY POLICY
Mish Health Ventures PLLC DBA Venus Well and Venus and Mars Well
Last Updated: June 8, 2026
This Consumer Health Data Privacy Policy supplements the Mish Health Ventures PLLC DBA Venus Well and Venus and Mars Well Privacy Policy (the "Privacy Policy") and applies to personal data defined as "consumer health data" ("CHD") by the Washington State My Health My Data Act ("MHMDA") and Nevada's Consumer Health Data Privacy Law ("Nevada CHD Law"). It also incorporates the concept of Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), ensuring that data related to your health and wellness is handled with the highest privacy and security standards.
For the purposes of this policy, PHI refers to individually identifiable health information that relates to your past, present, or future physical or mental health, healthcare services, or payment for healthcare. Undefined capitalized terms have the meaning set forth in the Privacy Policy.
Categories of Consumer Health Data Collected
As described further in our Privacy Policy, and depending on how you interact with Mish Health Ventures PLLC DBA Venus Well and Venus and Mars Well and applicable law, we may collect the following categories of CHD as broadly defined in the MHMDA and Nevada CHD Law:
-
Individual health conditions, treatment, diseases, or diagnoses β e.g., in connection with you seeking healthcare services or medications from us.
-
Social, psychological, behavioral, and medical interventions β e.g., through the collection of your medical history as part of the treatment services you seek.
-
Health-related surgeries or procedures β e.g., through the collection of health-related surgeries or procedures within your medical history.
-
Use or purchase of prescribed medication β e.g., through your purchase of medication or your medical history provided to us.
-
Bodily functions, vital signs, symptoms, or measurements of health information β e.g., as part of seeking healthcare services or medications.
-
Diagnoses, diagnostic testing, treatment, or medication β e.g., through medical history collected by us, or when you seek healthcare services or medications.
-
Gender-affirming care information β e.g., through the collection of your medical history.
-
Reproductive or sexual health information β e.g., as part of your medical history when seeking healthcare services or medications.
-
Genetic data β e.g., when included in your medical history.
-
Data that identifies a consumer seeking healthcare services β e.g., medical records collected by us.
-
Other information that may be used to infer, derive, or extrapolate data related to the above or other health information.
Patient Rights
In addition to the rights provided under the MHMDA and Nevada Consumer Health Data Privacy Law, individuals have rights under HIPAA, including:
-
Right to Access: Request access to and obtain a copy of your Protected Health Information (PHI).
-
Right to Amend: Request amendments to your PHI if you believe it is incorrect or incomplete.
-
Right to Restrict Disclosures: Request restrictions on certain uses or disclosures of your PHI.
-
Right to Confidential Communications: Request that communications regarding your health information be sent via alternative means or to alternative locations.
-
Right to Accounting of Disclosures: Receive a record of certain disclosures of your PHI made by us. For a full explanation of your rights, please refer to our Notice of Privacy Practices.
Sources of Consumer Health Data
As described in our Privacy Policy, we collect CHD from the following sources:
-
Directly from you β e.g., when you provide information to us while using our services.
-
Automatically through your use of the Services β e.g., via cookies or device information.
-
Social media and other content platforms.
-
Other third-party sources β e.g., healthcare providers, labs, or pharmacies.
Purposes for Collection of Consumer Health Data
We may collect and use CHD for the following purposes, as directed by you or with your consent:
-
To provide and manage the Services β e.g., processing your healthcare requests.
-
To analyze and improve the Services.
-
For advertising and marketing purposes.
-
For legal purposes, including complying with laws or establishing, exercising, or defending legal rights.
How and Why We Share Consumer Health Data
We may share CHD for business purposes with the categories of entities described in the "How We Disclose Your Information" section of our Privacy Policy. We may share CHD for the following reasons:
-
To deliver products and services to you, including to complete transactions initiated by you.
-
To maintain consistency in the level of service across our products and services.
-
To enhance our products, services, and your customer experience.
-
With your consent, such as for certain advertising or promotional efforts.
-
To protect our company and others β e.g., enforcing our Terms of Service, Privacy Policy, or contracts with you.
-
To comply with legal obligations.
-
In connection with any potential acquisition, merger, or purchase involving our business assets.
We may share CHD with the following categories of third parties:
-
Healthcare Providers and Services: For the provision of health services.
-
Service Providers: For business operations such as payment processing, shipping, or analytics.
-
For Legal Compliance: To regulatory agencies, as required by law or in response to legal requests or governmental inquiries.
-
Business Transfers: In connection with business transactions such as mergers or acquisitions.
-
At Your Direction or With Your Consent: Including sharing with other users if you post in public forums or interact with other users.
We reserve the right to create Aggregate/De-Identified Data from the information we collect and to disclose such data at our discretion.
Breach Notification
In the event of a breach involving your Consumer Health Data (CHD) or Protected Health Information (PHI), Mish Health Ventures PLLC DBA Venus Well and Venus and Mars Well will notify you as required under HIPAA regulations and applicable state laws. Notifications will include:
-
A description of what happened.
-
The type of information involved.
-
Steps you can take to protect yourself.
-
What we are doing to investigate, mitigate harm, and prevent future incidents.
For more details on our breach notification process, please see our Notice of Privacy Practices.
How to Exercise Your MHMDA or Nevada CHD Law Rights
Depending on your jurisdiction, you may have the following rights under the MHMDA or Nevada CHD Law:
-
Confirmation: Request to confirm whether we are collecting, sharing, or selling your CHD.
-
Access: Request access to your CHD.
-
Deletion: Request deletion of your CHD.
-
Withdraw Consent: Withdraw consent to the collection or sharing of your CHD.
To exercise these rights, please submit your request by contacting us using the information below. We may contact you for further information to authenticate your identity. We will not request sensitive personal or financial information for identity authentication, and no employee will ask for your password.
If your request is denied, you may appeal the decision by contacting us. If you are a Washington resident and your appeal is denied, you can contact the Washington State Attorney General at www.atg.wa.gov/file-complaint. If you are a Nevada resident and your appeal is denied, you can contact the Nevada Attorney General at ag.nv.gov/Complaints/File_Complaint.
Updates to This Consumer Health Data Policy
We reserve the right to change this CHD Policy at any time to reflect updates in the law, our data collection and usage practices, the features of our Services, or advances in technology. We will make the revised policy accessible through the Services. The date this policy was last updated is noted at the top of this document. By continuing to use our Services after amendments are posted, you acknowledge the updated policy.
Contact Us
If you have any questions about this Consumer Health Data Policy or our privacy practices, please contact us at:
Mish Health Ventures PLLC DBA Venus Well and Venus and Mars Well
Email: privacy@venusandmarswell.com
Address: 212 N. 2nd St. STE 100, Richmond, KY 40475, United States
HIPAA NOTICE OF PRIVACY PRACTICES
Mish Health Ventures PLLC DBA Venus Well and Venus and Mars Well
Effective Date: November 20, 2024
Last Updated: June 8, 2026
1. Purpose
This document summarizes the permitted uses and disclosures of patient protected health information ("PHI") as permitted by the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") Standards for Privacy of Individually Identifiable Health Information (the "Privacy Rule"), as amended by the Health Information Technology for Economic and Clinical Health Act (the "HITECH Act") and any regulations promulgated thereunder, including the HIPAA Omnibus Final Rule.
2. Scope
This policy applies to all Company staff members and applicable Business Associates.
3. Privacy Policy Statement
Mish Health Ventures PLLC DBA Venus Well and Venus and Mars Well ("the Company") is committed to complying with the HIPAA Privacy Rule. The Company recognizes the need to protect the privacy of PHI in order to facilitate the effective delivery of health care. These Privacy Policies and Procedures are designed and intended to ensure the Company's compliance with the Privacy Rule. The Company adopts these Policies and Procedures to protect the PHI that it creates and maintains from unauthorized use, disclosure, or access, and to maintain the confidentiality and integrity of that PHI. These Policies and Procedures also ensure that individuals have rights related to their PHI. Through the Company's Notice of Privacy Practices, individuals are informed of the Company's legal duties and these Policies and Procedures, as well as their individual rights with respect to their PHI.
These Policies and Procedures will be amended and/or supplemented as necessary and appropriate to comply with changes in the law or regulations, or to reflect changes related to the Company's privacy obligations or material changes to the uses or disclosures of PHI. If a change requires revisions to the Privacy Notice, the Company will not implement the change before the effective date of the revised Privacy Notice, unless the Privacy Officer deems it necessary to apply the change to PHI created or received before that effective date.
4. Key Definitions
"Protected Health Information" is information that (1) identifies or could be reasonably used to identify an individual, (2) is created or received by a HIPAA covered entity (a health care provider, health plan, or health care clearinghouse), and (3) relates to the past, present, or future physical or mental health of the individual, the provision of health care to the individual, or the past, present, or future payment for the provision of health care to the individual.
A "Business Associate" is a person or entity, other than a member of a covered entity's workforce, that creates, receives, maintains, or transmits PHI on behalf of a covered entity for a function or activity regulated by HIPAA. The HIPAA Final Rule expands the definition of "business associate" to include subcontractors that create, receive, maintain, or transmit PHI on behalf of a business associate. Business associate functions or activities include claims processing or administration, data analysis, utilization review, quality assurance, billing, benefit management, practice management, and repricing.
5. How We Use and Disclose PHI
We may use and disclose your PHI for the following purposes:
-
Treatment: To provide, coordinate, or manage your healthcare and related services.
-
Payment: For billing and payment activities related to your healthcare.
-
Healthcare Operations: For activities necessary to operate and improve our practice, including quality assessment and improvement, training, and accreditation.
-
Business Associates: PHI may be disclosed to Business Associates under signed agreements requiring compliance with HIPAA and applicable laws. These agreements ensure that Business Associates protect PHI and use it only for the purposes for which they were engaged.
-
Legal Compliance: As required by law, including in response to court orders, subpoenas, or government requests.
-
Public Health Activities and Safety: As permitted or required by law to prevent serious threats to health or safety.
The Company will use or disclose only the minimum necessary PHI to accomplish the intended purpose, except as required by law or authorized by the individual.
6. Patient Rights Under HIPAA
-
Right to Access: Request access to and obtain a copy of your PHI.
-
Right to Amend: Request amendments to your PHI if you believe it is incorrect or incomplete.
-
Right to Restrict Disclosures: Request restrictions on certain uses or disclosures of your PHI.
-
Right to Confidential Communications: Request that communications regarding your PHI be sent via alternative means or to alternative locations.
-
Right to Accounting of Disclosures: Receive a record of certain disclosures of your PHI made by us, including disclosures for purposes other than treatment, payment, and healthcare operations.
-
Right to a Copy of This Notice: You have the right to receive a paper copy of this Notice upon request.
7. Data Security and Breach Notification
We use a variety of security measures, including encryption and access controls, to protect your PHI. All employees undergo regular training on HIPAA compliance, data security, and our privacy policies.
In the event of a breach involving your PHI, we will notify you as required by law no later than 60 days after the discovery of the breach, in accordance with HIPAA regulations. Notifications will include a description of the breach, the types of information involved, steps you can take to protect yourself, and actions we are taking to mitigate harm and prevent future incidents. We will also notify the U.S. Department of Health and Human Services (HHS) as required.
8. Retention of PHI
PHI is retained for a minimum of six (6) years, as required by HIPAA regulations. Once information is no longer required, we securely delete or anonymize the data.
9. Complaints
If you believe your privacy rights have been violated, you may file a complaint with us or with the U.S. Secretary of Health and Human Services. To file a complaint with us, please contact our Privacy Officer using the information below. We will not retaliate against you for filing a complaint.
10. Contact β Privacy Officer
Mish Health Ventures PLLC DBA Venus Well and Venus and Mars Well
Email: privacy@venusandmarswell.com
Address: 212 N. 2nd St. STE 100, Richmond, KY 40475, United States
Website: https://joinvenuswell.com
Β

