Login Username or email address *Required Password *Required Remember me Log in Lost your password? Register Email address *Required A link to set a new password will be sent to your email address. When you register for an account, newsletter, program, or donation initiative on Forehealth, we collect and store additional personal data to fulfill that registration request. This Registration Privacy Policy explains exactly what information we collect at registration, why we need it, and how we protect it. 1. What We Collect During Registration Account Registration (Optional): Full Name Email Address (used as login ID) Password (hashed/encrypted) Optional Profile Information: Date of Birth, Gender, City/Country Newsletter/Promotional Sign-Up: Name (optional) Email Address Marketing Preferences (e.g., product updates, donation stories, special promos) Free Fish Oil Program / Donation Application: Full Name Contact Details: Email, Phone (optional) Brief Description of Financial or Health Need (max 300 words) Consent Checkbox for Data Collection & Sharing Optional Demographics (e.g., age bracket, household income range) for research purposes 2. Purpose of Registration Data Account Management: Enable secure login, order tracking, and personalized dashboard (order history, saved addresses). Communications: Send transaction confirmations, shipping notifications, password-reset emails, and program updates (e.g., application status). Marketing & Personalization: Tailor newsletters and promotional offers based on your preferences and site activity (only if you consent). Program Eligibility & Fulfillment: Verify eligibility for “Free Fish Oil Program” and ensure confidentiality when reviewing applications. 3. How We Protect Registration Information Encryption & Hashing: Passwords are stored as salted hashes. Sensitive fields (e.g., email) are encrypted at rest. Access Controls: Only authorized personnel (customer-care and program-review staff) have secure access to registration data. Audit Logs: Every access/administrative action relating to registration data is logged and reviewed periodically. Secure Transmission: All form submissions occur over HTTPS (SSL/TLS) to protect data in transit. 4. Third-Party Tools & Data Sharing Email Service Provider (e.g., Mailchimp, SendGrid): We share your name and email address only if you opt into our newsletter or promotional lists. They are contractually obligated to keep your data confidential and use it solely to deliver Forehealth communications. Donation Program Partners: In limited cases, anonymized application-verification details (no sensitive personal identifiers) may be shared with partner NGOs strictly to assess need. Full consent is obtained on the application form. Analytics Providers: We use Google Analytics (anonymized IP address) to measure site-usage patterns. No personal identifiers are passed. 5. Retention & Deletion of Registration Data Account Data: Retained as long as your account is active or until you request deletion. Newsletter Data: Retained until you unsubscribe or request removal. Program/Application Data: Retained for up to 12 months after application decision, then securely archived or deleted, unless legal/regulatory requirements mandate longer retention. 6. Your Rights & Choices (Registration Context) Access & Edit: At any time, log into your account to view or update your personal details. Withdraw Consent: You can opt out of marketing emails by clicking “Unsubscribe” in any newsletter or by contacting privacy@forehealth.net. Delete Account: Submit a deletion request to privacy@forehealth.net. Once verified, we will disable your account and purge your data (except for transaction histories required by law). Correct Inaccuracies: Email us at privacy@forehealth.net if any of your registration data is incorrect or incomplete. 7. Security & Breach Notification We implement reasonable safeguards in line with PDPA and industry best practices. In the unlikely event of a data breach involving registration data, we will notify affected users within 72 hours of discovery and inform the Personal Data Protection Commission (PDPC) as required by law. Register