Privacy Policy

Effective date: September 23, 2026
Last updated: September 23, 2026

This Privacy Policy explains how Sano Operations LLC (“Sano,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information through our websites, applications, and services, including the Sano business operations platform (collectively, the “Service”).

1. Scope and our role

This Policy applies to visitors to our website, people who communicate with us, account holders, trial users, and authorized users of customer workspaces.

For account, billing, website, and direct-business information, Sano generally determines why and how personal information is processed. For information submitted by an organization into its Sano workspace, the organization generally controls the information and Sano processes it to provide the Service. Questions about workspace information should first be directed to the organization that provided or controls it.

2. Information we collect

Information you provide

We may collect:

  • name, email address, password credentials in protected form, job title, and profile information;

  • organization name, team, role, responsibility, workspace-access, and membership information;

  • workflow, work-item, comment, activity, evidence, attachment, and other operational content;

  • billing contact, subscription, plan, invoice, and transaction information;

  • communications, support requests, survey responses, and feedback; and

  • information submitted through demo, contact, trial, signup, or marketing forms.

Payment-card information is processed by our payment provider. Sano does not intend to store full payment-card numbers.

Information provided by an organization

Organization administrators and other authorized users may provide information about members, invitees, employees, contractors, or other personnel, including names, work email addresses, roles, teams, responsibilities, and assigned work.

Information collected automatically

When you use our websites or Service, we may automatically collect:

  • device, browser, operating-system, language, and approximate location information derived from IP address;

  • IP address, timestamps, pages or features viewed, referring pages, and interaction data;

  • authentication, security, error, diagnostic, and audit logs; and

  • cookie, analytics, advertising-attribution, and similar technology data.

3. How we use information

We use personal information to:

  • create and secure accounts and workspaces;

  • provide, operate, maintain, and troubleshoot the Service;

  • process invitations, access decisions, subscriptions, and payments;

  • display assignments, responsibilities, history, notifications, and organizational activity to authorized users;

  • communicate about accounts, support, security, product changes, trials, subscriptions, and requested information;

  • understand usage and improve usability, reliability, security, and product performance;

  • measure marketing and website effectiveness;

  • detect fraud, abuse, security threats, and violations of our Terms;

  • comply with law, enforce agreements, and protect rights and safety; and

  • create aggregated or de-identified information that does not reasonably identify an individual.

We do not use Customer Data to train a general-purpose artificial-intelligence model.

4. How we disclose information

We may disclose personal information:

Within your organization

Information may be visible to authorized members and administrators according to workspace roles, permissions, assignments, teams, and organizational access settings. Activity history may preserve prior actions even after a person is deactivated.

To service providers

We use vendors that help provide hosting, databases, authentication, email, customer support, analytics, bot protection, security, and payment processing. They may process information only to provide contracted services or as otherwise permitted by law.

For legal and safety reasons

We may disclose information when reasonably necessary to comply with law or legal process; enforce our agreements; investigate fraud, abuse, or security incidents; or protect the rights, property, and safety of Sano, our customers, users, or others.

In a business transaction

Information may be transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets. We will require the recipient to handle personal information consistently with applicable law.

With your direction or consent

We may disclose information when you or your organization instructs us to do so or when you provide consent.

5. Sale, sharing, and targeted advertising

Sano does not sell personal information for money.

Our public website may use analytics and advertising technologies to measure visits, understand campaign performance, and reach potential customers. Depending on the law that applies to you, disclosures through advertising cookies or similar technologies may be considered “sharing,” “targeted advertising,” or a “sale,” even when no money is exchanged.

You may use available browser or cookie controls and may contact us at courtney@sanooperations.com to request an opt-out where applicable. We do not knowingly sell or share personal information of anyone under 18.

6. Cookies and similar technologies

We and our providers may use cookies, pixels, local storage, and similar technologies for:

  • essential authentication and security;

  • preferences and functionality;

  • performance and analytics; and

  • advertising attribution on the public website.

You can control cookies through your browser settings. Blocking essential cookies may prevent account login or other Service functions. Where required, we will provide additional cookie choices or consent controls.

7. Data retention

We retain personal information for as long as reasonably necessary to provide the Service, maintain legitimate business and security records, comply with law, resolve disputes, and enforce agreements.

Retention depends on the type of information and why it is processed. Account and workspace information may remain while an organization has an active trial or subscription. After expiration or termination, information may be retained for a limited period before deletion or de-identification. Some records may remain longer in backups, audit trails, transaction records, or legal holds.

Deactivation removes a person’s active access but may preserve their name, assignments, and historical actions so the organization retains an accurate operational record.

8. Security

We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, authentication protections, tenant separation, logging, and encryption provided by our infrastructure. No system is completely secure, and we cannot guarantee absolute security.

You are responsible for protecting your credentials, managing organizational access, and promptly notifying us of suspected unauthorized use.

9. Your choices and privacy rights

Depending on where you live and applicable law, you may have the right to request:

  • access to personal information we hold about you;

  • correction of inaccurate information;

  • deletion of personal information;

  • a portable copy of certain information;

  • restriction of or objection to certain processing;

  • withdrawal of consent where processing is based on consent; or

  • an opt-out from certain sales, sharing, or targeted advertising.

To submit a request, email courtney@sanooperations.com with the subject “Privacy Request.” We may need to verify your identity and authority. If the information is controlled by your organization, we may refer the request to that organization or assist it in responding.

We will not discriminate against you for exercising an applicable privacy right. You may use an authorized agent where permitted by law. If we deny a request, you may ask us to reconsider by replying to our decision.

10. Marketing communications

You may unsubscribe from marketing emails using the link in the message or by contacting us. We may still send nonmarketing communications about accounts, security, transactions, subscriptions, or requested support.

11. Children

The Service is intended for business use by adults and is not directed to children under 13. Individuals must be at least 18 to create an account. We do not knowingly collect personal information directly from children through account registration.

Customers may not submit children’s personal information or student education records unless Sano has expressly authorized that use in a separate written agreement and all required permissions and safeguards are in place. If you believe a child’s information was submitted improperly, contact us.

12. International use

Sano is based in the United States. If you access the Service from another country, information may be processed in the United States and other locations where our service providers operate. Those locations may have different data-protection laws. Customers that require international transfer terms or a data-processing agreement should contact us before submitting regulated personal information.

13. Third-party websites and services

Our websites may link to services we do not control. Their privacy practices are governed by their own policies, and this Policy does not apply to them.

14. Changes to this Policy

We may update this Privacy Policy as our practices, Service, or legal obligations change. We will post the updated Policy and revise the effective date. If a change materially affects how we handle personal information, we will provide additional notice when required.

15. Contact us

For privacy questions or requests, contact:

Sano Operations LLC
Email: csano@sanooperations.com
Website: https://www.sanooperations.com