Legal · privacy

Privacy policy in plain English.

A clear read on what New Wave collects, what we do with it, and how providers and clients on the platform stay in control of their own data.

1. Scope

This policy describes how WVMF Holdings LLC, doing business as New Wave ("New Wave," "we," or "us"), handles personal information when you visit newwaveapp.com or newwaveweightloss.com, use the provider platform, or interact with the branded client portals built on top of it — including portals served from a provider's own custom domain.

It applies whether you reach the platform as a prospective provider, an active clinic operator, or a client of a clinic running the New Wave protocol.

2. What we collect

We collect the information you provide directly — name, email address, practice details, and anything you share in scheduling forms or onboarding conversations.

We collect operational data from the platform: pages visited, dashboard interactions, and booking activity. We do not sell this data.

Clinic-branded portals run on domains we provision; the clinic remains the controller for client information entered there, including any health information.

3. Health information

Clinics on the platform are healthcare providers, and the information their clients record — weight, measurements, session notes, coach messages — may be protected health information under HIPAA. That information belongs to the clinic and its client: we process it on the clinic's behalf, store it in access-controlled infrastructure covered by healthcare data-protection agreements with our cloud vendors, and never use it for advertising or sell it to anyone.

Notifications we send outside the platform (email or text reminders) are deliberately content-free: they tell you something is waiting in the app without including the substance of it.

4. Google user data

Providers can optionally connect a Google Calendar to their workspace. When they do, New Wave requests access to calendar events (the https://www.googleapis.com/auth/calendar.events scope) and uses it for exactly two things: reading events to compute busy times so booked slots don't collide with the provider's existing commitments, and creating or deleting a minimal "New Wave session" event when a session is booked or cancelled. The busy-time computation keeps only start and end times — event titles, descriptions, and guest lists are not stored. Events we create contain no client names or health information.

OAuth tokens are stored server-side with restricted access, are never exposed to browsers or other users, and are deleted — after being revoked with Google — when the provider disconnects the integration. We do not use Google user data for advertising, do not sell it, and no humans read it except with the provider's explicit permission, or where necessary for security, compliance, or legal reasons.

New Wave's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

5. How we use it

We use the information to deliver the platform — onboarding, support, billing, scheduling, and product improvements. We use aggregate, de-identified data to study outcomes across cohorts.

We never use identifiable client data to market to clients of other clinics on the platform.

6. How we share it

With service providers who help us run the platform — cloud hosting, email and text delivery, payment processing — under contracts that restrict their use of the data.

With law enforcement if required by a valid legal process. We notify you unless prohibited.

In the event of a corporate transaction (merger, acquisition), with the acquiring entity, under the same protections described here.

7. Retention

We keep information for as long as the relationship is active, plus the period required to meet legal, accounting, and regulatory obligations.

Providers can request deletion of their account data through the dashboard. Some records (transactional, tax, audit) are retained for the statutory period.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, or port your information, and to object to certain processing.

To exercise any of these rights, email admin@newwaveweightloss.com from the address on file. We respond within 30 days.

9. Security

We use industry-standard safeguards — encryption in transit and at rest, least-privilege access, audit logging — and review them regularly. No system is perfectly secure; we describe known risks honestly during onboarding.

10. Contact

Questions: admin@newwaveweightloss.com. Postal mail: WVMF Holdings LLC (dba New Wave), 17434 Spirit Lane SE, Yelm, WA 98597.

Questions about how your data is handled?

We answer them ourselves. No ticket queue, no template replies.