Privacy Policy
Last Updated: January 10, 2026
1. Introduction
Metabolic Restore ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website metabolicrestore.health and use our services.
Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the site or use our services.
2. Information We Collect
2.1 Personal Information
We collect personal information that you voluntarily provide to us when you:
- Schedule a discovery call or consultation
- Register as a client
- Contact us via email or contact forms
- Subscribe to our newsletter or blog updates
- Participate in surveys or promotions
This information may include:
- Name
- Email address
- Phone number
- Date of birth
- Billing and payment information
2.2 Health Information
As a functional medicine practice, we collect Protected Health Information (PHI) when you become a client, including:
- Medical history
- Symptoms and health concerns
- Laboratory test results
- Treatment plans and protocols
- Progress notes and consultation records
HIPAA Compliance: We comply with the Health Insurance Portability and Accountability Act (HIPAA) and implement appropriate safeguards to protect your health information.
2.3 Automatically Collected Information
When you visit our website, we automatically collect certain information about your device and browsing activity:
- IP address
- Browser type and version
- Operating system
- Pages visited and time spent on pages
- Referring website
- Device type (desktop, mobile, tablet)
2.4 Cookies and Tracking Technologies
We use cookies, web beacons, and similar technologies to:
- Remember your preferences
- Analyze website traffic and usage patterns
- Improve website functionality
- Deliver targeted content
You can control cookies through your browser settings. Note that disabling cookies may limit your ability to use certain features of our website.
3. How We Use Your Information
We use the information we collect to:
- Provide Services: Deliver functional medicine consultations, testing coordination, and personalized health protocols
- Client Management: Maintain client records, schedule appointments, and manage your health journey
- Communication: Send appointment reminders, test results, protocol updates, and health education materials
- Billing: Process payments and manage billing inquiries
- Website Improvement: Analyze website usage to improve user experience
- Marketing: Send newsletters, blog updates, and promotional materials (with your consent)
- Legal Compliance: Comply with applicable laws and regulations
- Security: Detect, prevent, and address fraud and security issues
4. How We Share Your Information
We do not sell your personal or health information. We may share your information with:
4.1 Service Providers
- Practice Better: Our HIPAA-compliant client portal and practice management system
- Laboratory Partners: CLIA-certified labs for test processing (e.g., DUTCH testing, GI-MAP)
- Payment Processors: Secure payment processing services
- Email Service Providers: For client communications (HIPAA-compliant)
- Website Hosting: Netlify for website hosting and delivery
All service providers are contractually obligated to protect your information and use it only for the purposes we specify.
4.2 Legal Requirements
We may disclose your information if required to:
- Comply with legal obligations, court orders, or government requests
- Enforce our Terms of Service
- Protect the rights, property, or safety of Metabolic Restore, our clients, or others
- Prevent fraud or security threats
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.
4.4 With Your Consent
We may share your information with third parties when you provide explicit consent.
5. Data Security
We implement industry-standard security measures to protect your information:
- Encryption: All data transmitted to and from our website is encrypted using SSL/TLS
- Secure Storage: Health information is stored in HIPAA-compliant, encrypted databases
- Access Controls: Limited access to personal information on a need-to-know basis
- Regular Audits: Periodic security assessments and updates
- Staff Training: All staff are trained in HIPAA compliance and data protection
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
6. Your Privacy Rights
6.1 HIPAA Rights
As a healthcare client, you have the right to:
- Access: Request access to your health records
- Amendment: Request corrections to your health information
- Accounting: Request an accounting of disclosures of your health information
- Restrictions: Request restrictions on certain uses and disclosures
- Confidential Communications: Request communications via specific methods or locations
6.2 General Privacy Rights
You have the right to:
- Opt-Out: Unsubscribe from marketing emails at any time
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your personal information (subject to legal and contractual obligations)
- Data Portability: Request transfer of your data to another service provider
- Object: Object to certain processing of your information
6.3 California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to opt-out of the sale of personal information (Note: We do not sell personal information)
- Right to deletion
- Right to non-discrimination for exercising your rights
6.4 Exercising Your Rights
To exercise any of these rights, please contact us at:
- Email: chris@metabolicrestore.health
We will respond to your request within 30 days.
7. Data Retention
We retain your information for as long as necessary to:
- Provide our services and maintain client records
- Comply with legal, regulatory, and professional obligations
- Resolve disputes and enforce agreements
Health Records: In accordance with state and federal laws, we retain client health records for a minimum of 7 years after the last date of service.
Marketing Data: We retain marketing communication data until you unsubscribe or request deletion.
8. Third-Party Links
Our website may contain links to third-party websites (e.g., laboratory partners, educational resources, Practice Better client portal). We are not responsible for the privacy practices of these third-party sites. We encourage you to review their privacy policies before providing any personal information.
9. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately, and we will delete the information.
10. International Users
Our services are based in the United States. If you access our website from outside the United States, your information will be transferred to, stored, and processed in the United States. By using our services, you consent to this transfer.
11. Analytics and Advertising
We use Google Analytics to analyze website traffic and usage patterns. Google Analytics uses cookies to collect information such as:
- Pages visited
- Time spent on site
- Referring websites
- Device and browser information
Google Analytics does not collect personally identifiable information. For more information on how Google uses data, visit: https://policies.google.com/privacy
You can opt-out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:
- Posting the updated policy on our website with a new "Last Updated" date
- Sending an email notification to registered clients
We encourage you to review this Privacy Policy periodically. Your continued use of our services after changes are posted constitutes acceptance of the updated policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
For HIPAA-related privacy concerns, you may also file a complaint with:
U.S. Department of Health and Human Services
Office for Civil Rights
200 Independence Avenue, S.W.
Washington, D.C. 20201
Phone: 1-877-696-6775
Website: https://www.hhs.gov/ocr/privacy
14. Consent
By using our website and services, you consent to this Privacy Policy and our collection, use, and disclosure of your information as described herein.