Snapback Health

Privacy Policy

Last updated: May 17, 2026 · Effective date: May 17, 2026

1. Introduction

Snapback Health Technologies LLC ("Snapback Health," "we," "us," or "our") is committed to protecting the privacy and security of your personal and health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our patient recovery portal at snapbackhealth.com and app.snapbackhealth.com (the "Service").

We act as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") to your healthcare provider, and we are committed to the protection of Protected Health Information ("PHI") in accordance with HIPAA, the Health Information Technology for Economic and Clinical Health Act ("HITECH"), and applicable state privacy laws.

2. Information We Collect

We collect the following categories of information when you use our Service:

3. How We Use Your Information

We use your information solely for the following purposes:

We do not use your information for advertising, marketing to third parties, or sale to data brokers.

4. How We Share Your Information

We do not sell your personal information or health data to any third party under any circumstance. We share your information only in the following limited circumstances:

SMS Data Restriction: No mobile information, including phone numbers, opt-in data, or SMS message content, will be shared with any third parties or affiliates for marketing or promotional purposes under any circumstances. Mobile information is used solely for delivery of recovery reminders you have explicitly opted in to receive.

5. SMS / Text Message Reminders

If you choose to receive SMS reminders, you explicitly consent to receive automated text messages from Snapback Health at the mobile number you provide.

Your SMS opt-in consent is logged with timestamp in our database for audit purposes. SMS is disabled by default for all reminder types — you must affirmatively enable SMS for each reminder type you wish to receive via text message.

A complete description of our SMS reminder program, including a visual demonstration of the opt-in flow, is available at snapbackhealth.com/sms-opt-in.

6. Data Security

We implement comprehensive administrative, physical, and technical safeguards to protect your health information in accordance with HIPAA Security Rule requirements:

While we implement industry-standard safeguards, no method of electronic transmission or storage is one hundred percent secure. We cannot guarantee absolute security and encourage you to use strong, unique passwords and notify us immediately of any suspected unauthorized access.

7. Data Retention

We retain your health information for as long as your account is active or as required by applicable law. Specifically:

You may request deletion of your account and personal identifiers by contacting us at john.oshea@snapbackhealth.com, subject to the legal retention requirements above.

8. Your Rights Under HIPAA and Applicable Law

You have the following rights regarding your health information:

To exercise any of these rights, contact us at john.oshea@snapbackhealth.com. We will respond within thirty days as required by HIPAA.

9. Minor Patients

We recognize that patients of all ages may require post-surgical care. Minor patients (under 18) may use our platform only when their healthcare provider has invited them and a parent or legal guardian has provided consent on their behalf. For patients under 13, a parent or guardian must create and manage the account and provide consent under the Children's Online Privacy Protection Act. For patients aged 13 to 17, a parent or guardian must provide consent before the patient uses the Service. Healthcare providers are responsible for obtaining appropriate parental or guardian consent before inviting minor patients to the platform.

10. International Users

The Service is intended for use by patients of healthcare providers located in the United States. We do not market the Service to individuals outside the United States. If you access the Service from outside the United States, you do so at your own risk and acknowledge that your information will be processed in the United States in accordance with U.S. law.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or industry standards. We will notify you of material changes by email to your registered address or through a prominent notice in the patient portal at least thirty days before changes take effect. Your continued use of the Service after the effective date of changes constitutes your acceptance of the updated Policy.

12. California Residents — Additional Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Confidentiality of Medical Information Act. These include the right to know what categories of personal information we collect, the right to delete personal information (subject to HIPAA retention requirements), and the right to opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising. To exercise these rights, contact us at john.oshea@snapbackhealth.com.

13. Contact Us

If you have questions about this Privacy Policy, our privacy practices, or how we handle your health information, or to exercise any of your rights, please contact our Privacy Officer:

You may also file a HIPAA complaint with the U.S. Department of Health and Human Services Office for Civil Rights at https://www.hhs.gov/hipaa/filing-a-complaint/index.html.