Updated at
Privacy Policy
Last updated: 28/06/2026
Introduction
Sano Health Management ("Sano," "we," "us," or "our") operates the Sano platform, including the website at sano.healthcare and any associated mobile applications (the "Platform"). This Privacy Policy explains what personal information we collect, how we use and disclose it, and the choices and rights you have.
We respect your privacy. The information you trust us with stays with us. We do not sell your sensitive personal information. We do not sell health data to advertisers. We do not share Protected Health Information (PHI) for marketing purposes.
By using the Platform, you acknowledge this Privacy Policy. We will update it as needed and notify you of material changes.
Two Categories of Information
Your information on Sano falls into two categories with different protections:
1. General Personal Information. Collected by Sano Health Management and Sano Medical Group. Includes name, email address, billing/shipping address, phone, device data, and similar. Governed by this Privacy Policy and applicable state privacy laws.
2. Protected Health Information (PHI). Collected by Sano Medical Group and Providers. Includes your medical history, diagnoses, prescriptions, lab results, treatment plans, and clinical communications. Governed by HIPAA, California state law, and the Medical Group's separate Notice of Privacy Practices, not by this Privacy Policy.
Sano may sometimes process PHI on behalf of the Medical Group as its Business Associate under a HIPAA-compliant Business Associate Agreement. In that role, Sano handles PHI strictly per HIPAA and the BAA, not under this Privacy Policy.
Information We Collect
Information you provide:
• Account information: name, email, phone, address, date of birth, ZIP code
• Payment information: card number, billing address (processed by Stripe)
• Communications you send through the Platform
• Photos or documents you upload
Information collected automatically:
• Device identifiers and browser information
• IP address and approximate location (city/state level)
• Usage data: pages visited, clicks, time spent, navigation paths
• Cookies and similar technologies (see Cookies section)
Information from third parties:
• Service providers (e.g., Stripe for payment processing)
• Marketing partners (with your consent)
How We Use Your Information
We use the personal information we collect to:
• Provide and operate the Platform
• Process your payments and Membership
• Send service-related communications (appointment reminders, billing, security alerts)
• Send marketing communications, where you have consented
• Improve our services and develop new features
• Detect, prevent, and address fraud and security issues
• Comply with legal obligations
How We Share Your Information
We share personal information only as described below:
With the Medical Group and your Providers. To facilitate your clinical care. This sharing is necessary for Sano Medical Group to provide medical services to you.
With service providers. We share information with vendors who help us operate the Platform, such as Stripe (payment processing), Practice Better (hosting), and analytics providers. These vendors are contractually required to protect your information.
With Commercial Labs or Pharmacies. When your Provider orders labs or prescribes medication, we share necessary information with these partners so they can fulfill your order. You will have a direct relationship with these providers for billing and fulfillment.
For legal compliance. We may disclose information to comply with legal obligations, respond to subpoenas, or protect rights, property, or safety.
Business transfers. In the event of a merger, acquisition, or sale, your information may transfer to the acquiring entity, subject to the same privacy commitments.
We do not sell your personal information. We do not share PHI for marketing. We do not allow advertising networks to track your health-related activity on Sano. We are not in the data-sale business — your trust is our differentiator.
Cookies and Similar Technologies
We use cookies and similar technologies for: (a) essential platform functions (sign-in, security); (b) understanding how Members use the Platform (analytics); (c) remembering your preferences. We do not use cookies to deliver targeted advertising on health-related pages. You can control cookies through your browser settings.
Your Choices and Rights
Access, Correction, Deletion. You may access, correct, or delete your personal information at any time by emailing hello@sano.healthcare or through your account settings.
Marketing Opt-Out. You may unsubscribe from marketing emails by clicking "unsubscribe" in any marketing message, or by emailing hello@sano.healthcare. Service-related communications (billing, appointment reminders) cannot be opted out of while you are an active Member.
Do Not Sell. We do not sell personal information. There is nothing to opt out of.
Global Privacy Control. If your browser sends a Global Privacy Control signal, we will treat it as an opt-out of any non-essential data sharing.
California Privacy Rights
California residents have specific rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
• Right to know what personal information we collect and how we use it
• Right to request access to, correction of, or deletion of your personal information
• Right to opt out of sale or sharing of personal information (Sano does not sell or share)
• Right to limit the use of sensitive personal information
• Right to non-discrimination for exercising your rights
To exercise these rights, contact hello@sano.healthcare. We will verify your identity before fulfilling your request and respond within 45 days as required by law.
Data Retention
We retain personal information for as long as necessary to provide the Service, comply with legal obligations (including HIPAA's 6-year retention requirement for PHI handled as a Business Associate), resolve disputes, and enforce our agreements. Medical records held by Sano Medical Group are retained per California law (minimum 7 years for adult patients).
Data Security
We use industry-standard administrative, physical, and technical safeguards to protect your information, including encryption at rest (AES-256) and in transit (TLS 1.2+), access controls, audit logging, and annual security risk assessments. No system is perfectly secure; you are responsible for keeping your account credentials confidential.
Children's Privacy
Sano is not for individuals under 18. We do not knowingly collect personal information from anyone under 13. If we learn we have collected information from a child under 13, we will delete it promptly.
International Users
Sano operates in California and Florida only. If you are accessing the Platform from outside the United States, please do not enroll. The Platform is governed by U.S. law.
Changes to This Privacy Policy
We will update this Privacy Policy as necessary. Material changes will be communicated by email or in-platform notification. The "Last updated" date at the top reflects the most recent change.
Contact
Privacy questions or requests:
Email: hello@sano.healthcare