Summary and scope
This Privacy Policy covers four things: the public Kanurra website at kanurra.com (the “Website”); the Kanurra Member Account Notifications text messaging program sent from (888) 814-4197 (the “Text Program”); the Kanurra Member Offers marketing text program sent from (888) 814-7677 (the “Offers Program”); and the calls and texts our sales team uses to follow up with businesses that ask to hear from us, including through our lead forms on Facebook and Instagram (the “Sales Program”). That is all it covers. The Text Program, the Offers Program, and the Sales Program each have their own section below. Their program terms are at kanurra.com/sms, kanurra.com/member-offers, and kanurra.com/sales-texts.
The Website exists to explain how Kanurra works (a pharmacy benefit manager that earns one flat, disclosed per-employee-per-month (PEPM) administrative fee and nothing else), to let you book a 30-minute claims-audit call, and, on campaign landing pages, to take a request for a claims review through a lead form. The Website (not the Text Program) is built for businesses: brokers, third-party administrators, and self-funded employer plan sponsors. The Website is not built for patients or consumers. The Text Program and the Offers Program are for members of plans that Kanurra administers.
The Website is separate from the Kanurra pharmacy-benefit system (the “System”). The System is where member and claims data are held once a plan is administered by Kanurra. The System is governed by the plan and services agreement and by HIPAA Business Associate Agreements, not by this policy. The next section makes that wall explicit.
Here is our stewardship promise, in plain words: we collect the minimum we need to run the site and respond to you, we do not sell it, and we name everyone who touches it. The rest of this document is the detail behind that sentence.
This website does not handle PHI
This is the part that matters most, so we will be blunt about it.
- The Website does not collect, process, or store Protected Health Information (“PHI”) as defined under HIPAA. Do not submit PHI, member data, or patient data through the booking form or any other form on this site.
- When Kanurra provides services to a health plan or an employer plan sponsor, it acts as that plan’s Business Associate. Any PHI that Kanurra creates, receives, maintains, or transmits is handled inside the System, never on this Website.
- PHI is governed solely by HIPAA and HITECH, the applicable Business Associate Agreement between Kanurra and the covered entity, and the plan and services agreement, not by this Privacy Policy.
- This Privacy Policy is NOT a HIPAA Notice of Privacy Practices. To learn how your PHI is used and disclosed, request the Notice of Privacy Practices from your health plan or plan sponsor.
- As a business associate, Kanurra generally does not issue its own Notice of Privacy Practices. Covered entities (your health plan or plan sponsor) issue those.
Promotion submissions are the one place this policy covers claims data, and they do not come through this Website. Under a Kanurra promotion, an employer may send us a pharmacy claims extract so we can prepare a repricing analysis. That extract is required to have every HIPAA identifier removed, including exact dates of service, which places it outside the definition of PHI. It is submitted through a separate secure intake link, never through a form on this Website. What we may do with it, how long we keep it, and how to have it deleted are governed by Section 1.14 of the Promotion Terms at kanurra.com/promotion-terms, which is more specific than this policy and controls for those materials. Identified claims data is accepted only under an executed Business Associate Agreement and is handled inside the System under HIPAA, not under this policy.
Information we collect
On the Website, we collect two kinds of information, and only two. What the Text Program, the Offers Program, and the Sales Program collect, including what you enter on our lead forms on Facebook and Instagram, is described separately in their own sections below.
Information you give us. When you book a claims-audit call on the /audit page, you give us your name, your business email, and anything you type into the booking form. This is collected through our scheduling provider, iClosed. On our campaign landing pages (/lp-airpods-hr and /lp-airpods-cfo) you give us your name, business email, phone number, company, and the answers you select about your organization. That form is collected through our form provider, Tally.
Information collected automatically. When you visit the Website, our hosting provider, Vercel, records standard server-log data: your IP address, browser and device type, the pages you view, timestamps, and similar usage data. Separately, the iClosed scheduler on /audit is an embed loaded from app.iclosed.io; visiting that page transmits your IP address and basic request data to iClosed even if you never type or submit anything. The lead form on our campaign landing pages works the same way: it is an embed loaded from tally.so, so visiting those pages transmits your IP address and basic request data to Tally before you enter anything.
Cookies and tracking technologies. The Website uses the Meta Pixel, an advertising measurement tool from Meta Platforms, Inc. Unless your browser sends an opt-out signal (see below), the pixel loads on every page, records page views, and sets advertising cookies (_fbp and, after a click on one of our ads, _fbc) that let Meta connect your visit to ads we run on Meta platforms. The iClosed scheduling embed on /audit sets the cookies it requires to function. We also use PostHog, a product-analytics tool, described in the next paragraph; it sets its own cookies to recognize your browser across pages of a visit. We honor the Global Privacy Control (GPC) browser signal: when your browser sends it, neither the Meta Pixel nor PostHog loads, no session is recorded, and no data is sent to Meta or PostHog. This covers the lead form on our campaign landing pages too: the form is an embedded frame served by Tally, but the conversion event for it is sent by us from the page around the frame, so the same signal suppresses it.
Product analytics and session recording. We use PostHog, operated by PostHog, Inc. (United States), to understand how visitors use this Website. PostHog records the pages you view, clicks and other interactions, and a replay of your session: a reconstruction of what was on your screen and how you moved through the page. Every value typed into a form field on this Website is masked before it leaves your browser, so recordings do not contain what you type. The iClosed scheduler is a separate embedded frame that PostHog cannot see into, so the name, email address, and phone number you give when booking a call are never part of a recording. We do not create a PostHog profile for anonymous visitors, we never send PostHog health information or claims data, and nothing PostHog collects is used for advertising. PostHog does not load at all when your browser sends the GPC signal.
Advertising measurement. When a booking is completed on /audit, we also send Meta a server-side “Schedule” conversion event so we can measure whether our ads lead to booked calls. That event contains your email address and phone number only in hashed (SHA-256) form, your IP address and browser user-agent, Meta’s own cookie and click identifiers, and generic campaign labels (UTM parameters). It never contains health information, claims data, or anything you would tell us on the call, and it is suppressed entirely when your browser sends the GPC signal. Submitting the lead form on a campaign landing page sends a second conversion event of the same shape and under the same limits, recorded as a “Lead”. It is sent by us rather than by Tally: when the form reports a completed submission, our own page decides what reaches Meta, and it sends the same hashed contact details, identifiers, and campaign labels listed above and nothing you answered about your plan or your organization. It is suppressed by the GPC signal in exactly the same way. Meta and PostHog are the only two such providers we use; if we add another, we will update this section to name it and describe what it collects before relying on it.
CCPA categories. For state-law clarity, the data above maps to two statutory categories: identifiers (name, email, phone number, IP address) and internet or other electronic network activity (pages viewed, usage data, and the masked session recordings described above).
Notice at collection. The booking form on /audit links to this policy at the point of collection, so you can see what we collect and why before you submit anything.
How we use information
We use this data only for what the Website, the Text Program, the Offers Program, and the Sales Program are for:
- To schedule, confirm, and hold the claims-audit meeting you request.
- To respond to your inquiry and follow up about it.
- To operate, secure, debug, and improve the Website.
- To comply with law and enforce our terms.
- To measure and improve our own advertising, through the Meta Pixel and conversion events described above.
- To understand how the Website is used and where it confuses people, through PostHog analytics and session recordings.
- To send the text messages you agreed to receive and to honor HELP and STOP requests, as described in the Text messaging section below, and the Member Offers texts you agreed to receive, as described in the Member Offers section below.
We do not profile you beyond that advertising measurement, and we do not make any automated decisions that produce legal or similarly significant effects about you on this Website.
If we send you a marketing follow-up email, every such message includes an unsubscribe link. For recipients in the EU or UK, we send marketing email only on the basis of your consent.
How we share information (subprocessors)
We do not sell or rent your personal information. For information collected on the Website only, we do share limited data with Meta for advertising measurement, as described above; under some state laws that counts as “sharing” for cross-context behavioral advertising, and the Your privacy rights section explains how to opt out. Nothing from the Text Program or the Offers Program is shared with Meta, and no call records, text records, or text consent from the Sales Program are either.
We use a small number of subprocessors and advertising partners to run the Website, the Text Program, the Offers Program, and the Sales Program. Here they are, by name and function:
- iClosed (United States): demo and audit scheduling. The scheduler is an embed loaded from app.iclosed.io, so visiting /audit transmits your IP address and basic request data to iClosed on page load, before you enter anything. When you complete the form, iClosed also receives the name, email, and answers you enter, and its own subprocessors (for example, a messaging provider used for reminders) may process that data under iClosed’s terms.
- Meta Platforms, Inc. (United States): advertising measurement. Through the Meta Pixel, Meta receives page-view and device data and sets the advertising cookies described above; when you book a call or submit a lead form on the Website, Meta also receives a conversion event containing the email and phone number you entered on that Website form (hashed), IP address, user-agent, its own identifiers, and campaign labels. It never receives Text Program or Offers Program numbers, consent, or message data. Meta processes this Website data under its own terms and may use it for its own advertising purposes. None of it is sent when your browser sends the GPC signal.
- PostHog, Inc. (United States): product analytics and session recording. PostHog receives page-view, click, device, and IP data, plus a masked replay of your visit. Form values are masked in your browser before they are sent, and the iClosed frame is not visible to it. PostHog acts as our processor and does not use this data for its own advertising. Nothing is sent when your browser sends the GPC signal.
- Tally (Tally BV, Belgium): the lead form on our campaign landing pages. The form is an embed loaded from tally.so, so visiting those pages transmits your IP address and basic request data to Tally on page load, before you enter anything. When you submit the form, Tally also receives your name, business email, phone number, company, and the answers you select. Tally acts as our processor and stores form responses in the European Union. Tally acts only as our form provider: it is not instructed to load any advertising or analytics tool of its own inside the form frame, and the conversion event for a submission is sent by us from the page around it, under the GPC rule described above.
- Vercel (Vercel Inc., United States): website hosting, edge/CDN delivery, and server request logs. Processes visitor IP addresses and request metadata.
- Twilio (Twilio Inc., United States): the messaging provider for the Text Program. Twilio processes your mobile number on our behalf, along with the short message text (which never includes drug names, diagnoses, or claim dollar amounts), the keywords you text us (such as START, HELP, and STOP), and delivery status. It processes them only to deliver our messages. It does the same for the Offers Program. It receives nothing from the Website. Twilio is also the calling and messaging provider for the Sales Program, where it processes the phone numbers involved, call timing and status, any call recording we make, and the texts we exchange with you, only to carry those calls and messages.
- HubSpot (HubSpot, Inc., United States): customer relationship management for the Sales Program. HubSpot holds the contact details and answers you give us on a lead form or booking form, and a log of our calls, emails, and texts with you. It processes them on our behalf only and receives no member or claims data.
We serve our fonts from our own infrastructure, so visiting the Website does not transmit your data to a third-party font provider.
Subprocessors and other service providers receive data only under contract, only with appropriate privacy and confidentiality obligations, and only to perform services for us.
Beyond these, we disclose Website information only where required by law (legal process, or to protect safety and rights) or in connection with a business transfer such as a merger or acquisition.
All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
In every case we collect and share the minimum necessary.
Text messaging
This section covers the Text Program: Kanurra Member Account Notifications, sent from our toll-free number (888) 814-4197. It sends account notifications and customer care messages only (claim status, prior authorization updates, and replies to help desk requests). It sends no marketing. The full program terms, including how to opt in and opt out, are at kanurra.com/sms.
The Text Program is for members of plans that Kanurra administers. It sends messages only to the account holder of a mobile number, or someone authorized to use it, who has opted in.
Text messaging originator opt-in data and consent will not be shared with any third parties.
We never sell, rent, or share mobile numbers or text messaging opt-in consent with third parties or affiliates for their marketing or promotional purposes. None of it is used for advertising measurement or sent to Meta or PostHog.
Twilio, our messaging provider, processes this information on our behalf only to deliver our messages to you. It is not a third party we share your information with, and it may not use it for any other purpose.
What we collect. When you join the Text Program, we collect:
- Your mobile number.
- A consent record: the date and time you opted in, the mobile number, who gave consent, the method (a text keyword, or a yes given to our help desk on a call), the keyword you texted or the version of the script the agent read, the version of the consent disclosure in force at the time, and for a call, the ID of the agent who logged it. For a call, that logged record is our proof of consent.
- Message logs: the messages we send you, the keywords you text us (such as HELP and STOP), and whether each message was delivered.
- Your opt-out status, including the date and time you opted out.
How we use it. Only to send the messages you agreed to receive, to answer HELP requests, to honor STOP requests, and to keep proof of consent and opt-out as the law and carrier rules require. None of it is used for advertising, and none of it is sent to Meta or PostHog. Our legal basis for the Text Program is your consent.
No drug names, diagnoses, or dollar amounts in texts. Our text messages never include drug names, diagnoses, or claim dollar amounts. They tell you that something on your account changed and ask you to call the help desk, or log in to your Kanurra account, for the details.
How this fits with HIPAA. This policy governs only your texting number, your consent and opt-out records, and the message logs. Your member record, including your claims, prior authorizations, and any phone number held for plan administration, stays in the System under HIPAA and the Business Associate Agreement, not under this policy. The Text Program is not used to send the details of that record: texts are limited to short notices that point you to the help desk.
Retention. We keep consent records, opt-out records, and message logs while your number is enrolled and for at least four years after you opt out or your enrollment ends, or longer where law, a legal hold, or our agreements with your plan require. We keep an opt-out record for as long as needed to honor it, never to contact you.
Member Offers texts
This section covers the Offers Program: Kanurra Member Offers, marketing texts sent from our toll-free number (888) 814-7677 about pharmacy benefits in your plan and features of the Kanurra app. It is separate from the Text Program and uses a different number. The full program terms, including how to opt in and opt out, are at kanurra.com/member-offers.
The Offers Program sends messages only to a mobile number whose account holder, or someone authorized to use it, texted the keyword OFFERS (or START) to (888) 814-7677 after the disclosure on that page. Stopping the Offers Program does not stop the Text Program, and the reverse.
Text messaging originator opt-in data and consent will not be shared with any third parties.
We never sell, rent, or share mobile numbers or text messaging opt-in consent with third parties or affiliates for their marketing or promotional purposes. None of it is used for advertising measurement or sent to Meta or PostHog. Twilio, our messaging provider, processes this information on our behalf only to deliver our messages to you. It is not a third party we share your information with, and it may not use it for any other purpose.
What we collect. Your mobile number; a consent record (the date and time you texted the keyword, the mobile number, the keyword, and the version of the disclosure in force at the time); message logs (the messages we send you, the keywords you text us, and whether each message was delivered); and your opt-out status, including the date and time you opted out.
How we use it. Only to send the messages you agreed to receive, to answer HELP requests, to honor STOP requests, and to keep proof of consent and opt-out as the law and carrier rules require. Our legal basis for the Offers Program is your consent.
No health information decides what you get. Every number in the Offers Program receives the same messages. We do not use your claims, prescriptions, or other health information to choose, write, or time an Offers Program message, and the messages never include drug names, diagnoses, or claim dollar amounts. Anything about your own prescriptions or account comes only through the Text Program. No pharmacy, drug manufacturer, or other company pays Kanurra to send an Offers Program message.
Retention. We keep consent records, opt-out records, and message logs while your number is enrolled and for at least four years after you opt out or your enrollment ends, or longer where law or a legal hold requires. We keep an opt-out record for as long as needed to honor it, never to contact you.
Sales calls and texts
This section covers the Sales Program: how our sales team follows up with businesses that ask to hear from us. It is separate from the Text Program. It uses a different phone number, it exists for business conversations, and it never involves member or claims data. Its text messaging terms are at kanurra.com/sales-texts.
Lead forms on Facebook and Instagram. Some of our lead forms are hosted by Meta on Facebook and Instagram, not on the Website. When you submit one, Meta collects and passes to us your name, business email, phone number, job title, the answers you select about your organization (such as company size, department, and whether you can access your pharmacy claims data), and whether you checked the optional box agreeing to receive text messages. Meta handles what you enter on its platforms under its own terms and privacy policy.
Calls. If you give us your phone number, we may call you from a Kanurra phone number about your inquiry. We keep a record of each call: the phone numbers, the date and time, the length, and the outcome. If we record a call, we tell you at the start of the call. You can ask us to stop calling at any time, on a call or by email to hello@kanurra.com, and we will add your number to our internal do-not-call list and honor it.
Texts. We text you only if you checked the optional box on a lead form or otherwise gave us your express written consent to receive texts. When you opt in, we keep a consent record: the date and time, the mobile number, the name you entered, the form you submitted, and the version of the consent language shown on it. We also keep the texts we exchange, the keywords you send (such as HELP and STOP), and your opt-out status.
Text messaging originator opt-in data and consent will not be shared with any third parties.
We never sell, rent, or share mobile numbers or text messaging opt-in consent with third parties or affiliates for their marketing or promotional purposes. Twilio and HubSpot process this information on our behalf only, as described in the subprocessors section above. They are not third parties we share it with, and they may not use it for any other purpose.
How we use it. To respond to your inquiry, follow up, schedule a call, tell you about Kanurra’s services, honor STOP and do-not-call requests, and keep proof of consent and opt-out as the law and carrier rules require. Call records, text records, and text consent are not used for advertising and are not sent to Meta or PostHog.
No health information. The Sales Program is for business conversations. Please do not give us health information about yourself or anyone else by text or on a sales call.
Anti-spam policy
Kanurra prohibits advertising or promoting kanurra.com, or any other Kanurra website, through unsolicited commercial email or other unsolicited messages. This applies to our employees and contractors and to any agent, affiliate, or vendor acting on our behalf.
Email that mentions or links to our websites goes only to people who have a business relationship with us or who asked to hear from us. Every such message identifies Kanurra as the sender, and we honor requests to stop promptly. Anyone found advertising our websites through unsolicited messages loses their relationship with Kanurra.
To report a message that breaks this policy, email hello@kanurra.com and include the full message, with its headers if you can.
Data retention
We keep data only as long as we need it for the purposes above.
- Booking-form contact data (name, email, form answers): we retain this for 24 months after your last interaction with us, then delete or anonymize it.
- Server logs and usage data: we retain these for up to 90 days for security, debugging, and abuse prevention, then delete or anonymize them.
- Promotion submissions (a claims extract sent to us under a promotion, and the analysis we prepare from it): we retain these for no longer than 12 months and delete them sooner on written request, subject only to a copy we are required to keep by law or legal hold. See Section 1.14 of the Promotion Terms.
- Text Program records (consent records, opt-out records, and message logs): we retain these as described in the Text messaging section above, so we can show when and how you consented and make sure an opt-out is always honored.
- Offers Program records (consent records, opt-out records, and message logs): we retain these as described in the Member Offers section above.
- Sales Program records: lead-form contact data, call records, and text logs are kept for 24 months after your last interaction with us, then deleted or anonymized. Text consent and opt-out records are kept for at least four years after you opt out. A do-not-call request is kept for at least five years, and for as long as needed to honor it.
When data is no longer needed for the stated purposes, we delete or anonymize it.
Our subprocessors and advertising partners (iClosed, Tally, Vercel, Meta, PostHog, Twilio, HubSpot) retain data according to their own policies and data processing agreements. Session recordings expire on PostHog’s standard retention schedule for our plan.
Your privacy rights and choices
You have rights over your personal information, and we honor them.
Core rights. You can ask us to access, correct, delete, or port your personal information, and you can object to or restrict certain processing. To exercise any of these, email us at the address in the Contact section.
GDPR and UK GDPR. If you are in the EU or UK, you have the right to access, rectification, erasure, restriction, portability, objection, to withdraw consent, and to lodge a complaint with a supervisory authority. Our legal bases are: the booking form is processed to take steps at your request before a contract and on our legitimate interest in responding to inquiries; any marketing email is on consent; the Text Program and the Offers Program are on consent. We are a US-focused B2B business and do not target EU or UK visitors, so we have not appointed an Article 27 representative; the Meta Pixel described above is aimed at our US advertising and is suppressed for any browser sending an opt-out signal. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects under Article 22.
International transfers. We process data in the United States. Where EU or UK personal data reaches our subprocessors, those transfers rely on the subprocessors’ own transfer mechanisms, such as Standard Contractual Clauses or an applicable certification framework, as described in their data processing terms.
Verification and timelines. We will verify your identity before acting on a request. An authorized agent may act for you with signed permission or a power of attorney. We respond within 45 days for CCPA requests and within one month for GDPR requests, with extensions only where the law allows.
To exercise any right, email privacy@kanurra.com.
Security
We apply reasonable administrative and technical safeguards to the limited contact data and logs we hold, and we work only with subprocessors that maintain their own security programs.
We will be honest about the limit, though: no method of transmitting or storing data over the internet is perfectly secure, and we cannot guarantee absolute security.
If a breach involving your personal information occurs, we will notify affected individuals and authorities as required by law.
For security questions or to report a vulnerability, email security@kanurra.com.
Children’s privacy
The Website is not directed to children. The Website is intended for business users. The Text Program and the Offers Program send messages only to the account holder of a mobile number, or someone authorized to use it, who has opted in.
We do not knowingly collect personal information from anyone under 13, the standard under COPPA. We do not knowingly sell or share the personal information of minors, and we do not offer consent-based processing of minors below the applicable EU or UK age of digital consent. If we learn we have collected information from a child, we will delete it. If you believe a child has provided us information, email privacy@kanurra.com.
Third-party links and embeds
The Website links to and embeds tools operated by third parties. The iClosed scheduler embed on /audit, the Tally lead form on our campaign landing pages, the Meta Pixel, and the PostHog analytics script are the main ones; any maps or video embeds we add later would be others.
These third parties operate under their own privacy policies, and we are not responsible for their practices. For the scheduler, our advertising partner, and our host specifically, see the subprocessor list above.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will indicate them by updating the effective date and posting the revised policy to this page.
For changes that materially affect how we use personal information you already gave us, we will take additional reasonable steps to notify you, such as a notice on the site or, where we have your email, by email.
Contact us
For privacy questions, requests, or complaints, email privacy@kanurra.com.
Legal entity: Kanurra, Inc. (“Kanurra”).
Kanurra Pharmacy LLC, an Idaho limited liability company, is a wholly owned subsidiary of Kanurra, Inc. It does not operate the Website and processes no information collected through it. Information collected through the Website is controlled by Kanurra, Inc. The corporate structure is set out at kanurra.com/pharmacy.
Mailing address: New York, NY.
If you are in the EU or UK, you also have the right to lodge a complaint with your local data protection supervisory authority.
Governing law and dispute terms for this Website are set out in the Terms of Service, and for the Text Program and the Offers Program in their program terms at kanurra.com/sms and kanurra.com/member-offers. Governing-law state is New York.