Our Commitment
Privacy Policy
Plain language about what information this website handles, what it doesn’t, and how patient information is protected in our client work.
Effective date: October 6, 2026
Who we are
Grand Vision Family Office LLC, doing business as Grand Vision One (“Grand Vision One,” “we,” “us”), provides practice operations and financial management services to owner-led private medical practices. This policy covers two things: how this public website (grandvisionone.com) handles information, and how patient information is protected in the services we provide to client practices.
What this website collects
Information you choose to send us. If you submit our contact or walkthrough form, we receive what you enter — typically your name, email, phone, and whatever you tell us about your practice. We use it for one purpose: to respond to you and prepare for the conversation you asked for. No drip campaigns, no list-building, no sale or rental of your information — ever.
Technical basics. Like nearly every website, our hosting provider (Cloudflare) processes standard technical data — IP addresses and request logs — to serve pages and protect the site from abuse. Images are served by Cloudflare Images, which receives the standard web requests needed to deliver those files. This website sets no advertising trackers and no analytics cookies.
Visit counts. We use Cloudflare Web Analytics to count page visits. It sets no cookies, doesn’t fingerprint your device and collects no personal information.
The first page of your visit. When you send the contact form, it includes the first page of this site you visited on that visit (for example, the page the letter’s QR code opens). That’s kept in your browser’s session storage until you close the tab, and is never stored in a cookie.
Counting what’s used. The site also keeps a simple count of a few actions, such as which buttons are used and whether the contact form was started, sent or hit an error. Each count records the action, the page it happened on, where the visit began and any campaign tags in the link you came from (for example a source and campaign name), and it is recorded by this website itself, not by a third party’s tracking tool. It does not record your IP address, your browser or device details or anything you type into the form, and it sets no cookie. If the link you came from carried campaign tags, they travel with the contact form too, so we can see which letter or link brought you here.
Patient information & HIPAA
This website does not collect, store, or display patient health information. The systems we operate for client practices are separate, access-controlled applications that run on infrastructure covered by Business Associate Agreements (BAAs), with encryption in transit and at rest, role-based access, and access logging.
Where Grand Vision One handles protected health information (PHI) in the course of serving a client practice, we do so as a business associate under HIPAA, governed by a Business Associate Agreement with that practice. We follow the minimum-necessary standard: we handle only the information a workflow requires.
Grand Vision One is not a healthcare provider and this website is not a patient portal. If you are a patient with questions about your medical records or your privacy rights, please contact your practice directly — your practice remains the steward of your health information.
How we share information
We share information from this website only with the service providers needed to run it (form delivery and hosting), and where the law requires disclosure. We do not sell personal information, and we do not share it for advertising.
Retention & your choices
Inquiry information is kept only as long as needed to handle your inquiry and any engagement that follows. You may ask us at any time to see, correct, or delete the information you sent through this website — email us at the address below and we’ll take care of it.
Security
All traffic to this website is encrypted with TLS. Within our client services, access to systems handling practice data requires multi-factor sign-in through the practice’s own identity provider (such as Google Workspace), is limited to the people who need it, and is logged.
Children
This website is intended for practice owners and administrators. It is not directed to children, and we do not knowingly collect information from anyone under 13.
Our browser extension
We distribute a browser extension to authorized staff at practices we serve, which moves medication and member records from a practice’s payer portal into that practice’s own system. What it reads, where it sends it, and what it never does are set out separately in our browser extension privacy policy.
Changes to this policy
If we change this policy, we’ll post the updated version here with a new effective date.
Contact
Questions about privacy — including anything about how we handle information — are welcome:
security@gvpracticemanagement.com · (515) 400-3013