OneWave
Product Stack Math Pricing Features Clinics Compare
Coming soon

Privacy Policy

Last updated: June 10, 2026

OneWave ("OneWave," "we," "us," or "our") provides a software platform (OneWave Systems, Inc., operating as OneWave at app.onewavesystems.com and through the OneWave mobile apps, the "Service") that sports medicine and performance clinics ("Clinics") use to manage scheduling, treatment programs, communications, and billing for their patients and athletes ("Patients"). This Privacy Policy explains what information we collect, how it is used and shared, and the choices available to you.

This Policy applies to Clinic staff and administrators ("Staff"), Patients, and visitors to our websites. By using the Service, you agree to the collection and use of information as described here.

1. Who controls your information

OneWave is provided to Clinics on a business-to-business basis. If you are a Patient, your Clinic is generally the "data controller" (or equivalent) for your health and treatment information — your Clinic decides what information is collected about you and how your care is documented. OneWave acts as a service provider / data processor on the Clinic's behalf for that information, processing it only to provide, secure, and support the Service and as instructed by the Clinic.

For information you give us directly as a Clinic owner or Staff member (such as account, subscription, and billing information), and for the operation of our own websites and apps, OneWave acts as the controller.

If you have questions about your health records, the best first step is usually to contact your Clinic directly, since they manage your care relationship. You're welcome to contact us as well — see Contact Us below.

2. Information we collect

2.1 Account and profile information

  • Name, email address, phone number, and password (or Google sign-in identifier if you use "Sign in with Google").
  • Role within the Service (Patient, Clinic staff, clinic admin) and the Clinic(s) you're associated with.
  • Profile details such as date of birth, profile photo, and emergency contact information, where collected by your Clinic.

2.2 Health and treatment information

Where you are a Patient, your Clinic and its Staff may enter or record, and the Service may store and display:

  • Treatment and rehabilitation programs, exercise plans, and progress notes.
  • Clinical/SOAP notes, medical history, and treatment templates entered by Staff.
  • Physical performance testing results (e.g., strength, mobility, and movement-screen data).
  • Wellness survey responses and other patient-reported outcomes.
  • Appointment, scheduling, and attendance records.

This information is sensitive, and we limit access to it to the Patient, the Patient's treating Clinic and authorized Staff, and OneWave personnel or systems that need it to operate the Service (e.g., for backups, security, and support).

2.3 Wearable and fitness data

If you choose to connect a wearable or fitness account, the Service can import data from providers including Apple Health, Health Connect, Whoop, Oura, Fitbit, Garmin, and Google Fit. Depending on the provider and your authorization, this may include steps, heart rate, sleep, recovery scores, active minutes, and calorie data, which may be shown to your Clinic as part of your wellness or recovery program.

Connecting a wearable account is optional and controlled by you. You can disconnect a wearable provider at any time from your account settings, which stops new data from being imported; previously imported data is handled per the retention practices described below.

2.4 Billing and payment information

Clinic subscription payments and, where enabled, patient invoice payments are processed through Square. We do not store full payment card numbers on our servers — Square handles card data directly and provides us limited information needed for billing, such as payment status, invoice amounts, and a reference/transaction ID.

2.5 Messages and communications

  • In-app messages between Patients and Clinic Staff.
  • Email notifications and account communications, sent via our email provider (SendGrid).
  • SMS/text messages, sent via our messaging provider (Twilio), where a Clinic has enabled SMS and you've provided a phone number.
  • Push notifications to the OneWave mobile app, where enabled on your device.

2.6 Community features

If your Clinic enables community/social features (such as "WaveCommunity"), your profile information, posts, and direct messages within that community are visible to other members of that community as described in the relevant in-app settings. Community content is separate from your private clinical record.

2.7 Usage, device, and diagnostic information

We use limited analytics and error-monitoring tools to keep the Service reliable and to understand how features are used:

  • PostHog — product analytics such as page views and feature usage, tied to an internal user identifier.
  • Sentry — crash and error reports to help us diagnose and fix bugs. We configure Sentry not to send personal data by default.

We also automatically collect standard technical information such as IP address, browser/app version, device type, and timestamps of activity.

2.8 Cookies and similar technologies

Our web app uses essential cookies/local storage to keep you signed in and remember preferences (such as theme), and may use analytics cookies from the providers above. You can control cookies through your browser settings, though disabling essential cookies may prevent the Service from working correctly.

3. How we use information

  • To provide, maintain, and secure the Service, including scheduling, treatment programs, messaging, and billing.
  • To enable Clinics and Staff to deliver care and communicate with their Patients.
  • To process payments and manage subscriptions via Square.
  • To send transactional communications (appointment reminders, invoices, account notices) via email, SMS, and push notification.
  • To monitor, debug, and improve the Service's performance and reliability.
  • To detect, investigate, and prevent fraud, abuse, and security incidents.
  • To comply with legal obligations and enforce our Terms of Service.

We do not sell personal information, and we do not use Patient health information for advertising.

4. How information is shared

  • Within your Clinic. Patient information is shared with the Patient's treating Clinic and the Staff at that Clinic who need it to provide care, scheduling, billing, and communications.
  • Service providers. We share information with vendors who help us operate the Service, including hosting/infrastructure providers, Square (payments), Twilio (SMS), SendGrid (email), Google (sign-in), and PostHog/Sentry (analytics and error monitoring). These providers are only authorized to use information as needed to provide their services to us.
  • Legal and safety. We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of OneWave, our users, or others.
  • Business transfers. If OneWave is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy (or a policy at least as protective).

5. Data retention

We retain account and clinical information for as long as your account or your Clinic's account is active, and for a reasonable period afterward to comply with legal, tax, and recordkeeping obligations (which, for clinical records, may be longer than for general account data) and to resolve disputes. Clinics are responsible for instructing us regarding retention or deletion of their Patients' records, subject to applicable law.

6. Data security

We use technical and organizational measures designed to protect information against unauthorized access, alteration, disclosure, or destruction, including encryption in transit, access controls, and restricted internal access to clinical data. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. Your choices and rights

  • Access and correction. You can review and update much of your profile information directly in the app, or by asking your Clinic or contacting us.
  • Wearables. You can connect or disconnect wearable integrations at any time.
  • Communication preferences. You may be able to opt out of non-essential SMS, email, or push notifications, subject to your Clinic's settings. We may still send transactional and account-related messages.
  • Deletion and data requests. Depending on your location, you may have rights to request access to, correction of, or deletion of your personal information. Because Clinics control Patient records, we may direct certain requests to your Clinic, or process them on the Clinic's behalf.

To exercise these rights, contact us at hello@onewavesystems.com.

8. Children's privacy

OneWave is used by athletes of varying ages, including minors, but accounts for minors are created and managed by a Clinic and/or a parent or legal guardian, in line with the Clinic's own consent and intake process. We do not knowingly allow minors to create their own accounts without Clinic or guardian involvement. If you believe a minor has provided us with information outside of this process, please contact us at hello@onewavesystems.com.

9. International data transfers

OneWave and its service providers may process and store information in countries other than your own. Where required, we use appropriate safeguards for such transfers in accordance with applicable law.

10. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above and, where appropriate, notify Clinics or Patients through the Service or by email.

11. Contact us

Questions about this Privacy Policy or how your information is handled can be sent to hello@onewavesystems.com.

OneWave Systems, Inc.
Canada
OneWave
© OneWave Systems
Privacy Policy · Terms of Service