Privacy Policy
Effective August 2026
Apsara Women’s Integrative Health is a direct-pay women’s integrative health practice. All care is provided personally by Seema Shah, MD, a physician licensed in California and board certified in obstetrics and gynecology. Care is delivered by telemedicine to patients located in California. This policy explains how we handle information you give us before you become a patient.
If you are a patient, your care and your financial obligations are governed by your Membership Agreement, the Practice Policies, and the Telemedicine and Treatment Consent. Those documents control if anything here conflicts with them.
What we collect
From you: your name, email address, and phone number when you join the waitlist or contact us; whatever you include in a message; scheduling information if you book an introductory call; and payment information, which is handled directly by our payment processor. We never receive or store full card numbers.
Automatically: IP address, browser and device type, pages viewed, and time spent, collected through cookies as described below.
We do not collect Social Security numbers, government ID numbers, biometric information, or precise location. We do not knowingly collect information from anyone under eighteen. If you believe a minor gave us information, write to hello@apsarawomenshealth.com and we will delete it.
How we use it
To respond to you, manage the waitlist and enrollment, schedule introductory calls, operate and improve our website, send educational or marketing messages if you opted in, and meet our legal obligations. We do not use this information to make any clinical decision about you or to build advertising profiles.
Who we share it with
Vendors who work for us, such as website hosting, email delivery, scheduling, and payment processing, and only so they can provide those services. Vendors that handle protected health information do so under written business associate agreements. We may also disclose information where the law requires it or to protect someone’s safety.
We do not sell your information, do not share it for cross-context behavioral advertising, and do not allow third parties to track you on our website for their own advertising.
Cookies
We use cookies necessary for the website to work and basic analytics showing how the site is used in aggregate. We do not use advertising cookies, retargeting pixels, or session replay tools. Most browsers let you refuse or delete cookies. We honor Global Privacy Control and similar browser opt-out signals.
Your California rights
Medical information under HIPAA and the California Confidentiality of Medical Information Act is exempt from the California Consumer Privacy Act. For the information we hold outside your medical record, we will honor your right to know what we have collected, to request deletion or correction, to opt out of any sale or sharing, which we do not do, and not to be treated differently for asking. Write to hello@apsarawomenshealth.com and we will verify your identity before responding.
Under California Civil Code Section 1798.83, you may ask about disclosures to third parties for their direct marketing. We do not make any.
Security and retention
We use encryption in transit, access controls, multi-factor authentication where available, and vendor review before adopting a tool. No system is perfectly secure. If a breach occurs, we will notify you as HIPAA and California law require.
Website inquiry and waitlist information is kept only as long as needed and then deleted. Medical records are kept at least ten years after your last visit, and longer where the law requires.
