SmileCare ("we", "us", or "our") is a dental clinic management software platform. This Privacy Policy explains how we handle information collected through our website at smilecareapp.com (the "Site") and our software platform (the "Platform").
1.Information We Collect
1.1 Information You Provide to Us
When you contact us through the Site (e.g., requesting a demo, submitting the contact form), we collect:
- Your name and email address
- Your clinic name and any message you provide
- Your IP address and browser user agent
1.2 Information Collected Automatically
When you visit the Site, we automatically collect:
- Device and browser information (type, version, language)
- Pages visited, time spent, and referral source
- Approximate geographic location based on IP address
We use standard analytics tools that do not identify individual users.
1.3 Patient Data (Not Collected by Us)
SmileCare is self-hosted software. Patient data — including names, contact details, medical histories, treatment records, and billing information — is stored in each clinic's own Supabase database instance or self-hosted server. We do not access, transmit, or store this data. All patient data remains under the exclusive control of the clinic that operates the deployment.
2.How We Use Your Information
We use the information collected through the Site to:
- Respond to demo requests and inquiries
- Provide product information and support
- Improve our website and marketing materials
- Send product updates and newsletters (only if you opt in)
- Comply with legal obligations
We do not sell, rent, or share your information with third parties for marketing purposes.
3.Cookies and Tracking
The Site uses minimal cookies for functionality (e.g., remembering your preferences) and anonymous analytics to understand how visitors use the site. You can disable cookies in your browser settings. Doing so will not prevent you from accessing the Site's content.
4.Data Retention
Information collected through the Site (contact form submissions, analytics data) is retained for up to 24 months, after which it is automatically deleted or anonymized. You may request earlier deletion of your personal data at any time by contacting us at the email below.
5.Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your personal data
- Object to or restrict certain processing
- Withdraw consent for marketing communications
- Receive a copy of your data in a portable format
To exercise any of these rights, contact us.
6.Healthcare Data Compliance (HIPAA / GDPR)
6.1 HIPAA (United States)
SmileCare is not a Business Associate under HIPAA. We do not create, receive, maintain, or transmit Protected Health Information (PHI) on behalf of any covered entity. Each clinic that deploys SmileCare is responsible for:
- Configuring its Supabase project or self-hosted database with appropriate security measures
- Implementing Business Associate Agreements (BAAs) with its hosting providers as needed
- Ensuring encryption, access controls, and audit logging meet HIPAA requirements
- Maintaining compliance with the HIPAA Security Rule and Privacy Rule
SmileCare includes technical features that support HIPAA compliance, including row-level security, audit logging, role-based access control, and encrypted data transmission via TLS. However, technical features alone do not constitute HIPAA compliance — organizational and administrative safeguards must also be implemented by the clinic.
6.2 GDPR (European Union)
For clinics operating in the European Union, SmileCare supports GDPR compliance through:
- Data minimization — clinics control what data they collect and store
- Right to access and export — patient data can be exported from the database
- Right to erasure — clinics can delete patient records directly
- Consent management — clinical photo marketing consent is tracked with timestamps
- Audit trails — all data access and modifications are logged
Each clinic is responsible for appointing a Data Protection Officer (DPO) if required, conducting Data Protection Impact Assessments (DPIAs), and ensuring lawful bases for processing patient data.
6.3 PIPEDA (Canada) and Other Jurisdictions
Clinics in Canada and other jurisdictions are responsible for ensuring their use of SmileCare complies with applicable privacy laws. SmileCare's self-hosted architecture gives clinics full control over data storage, retention, and access.
7.Data Security
The Site is served over HTTPS. Information submitted through contact forms is transmitted securely. On the Platform side, SmileCare includes the following security features for clinic deployments:
- Row-level security (RLS) on all database tables
- Role-based access control with granular per-module permissions
- Audit logging of all critical actions
- Session management and login history tracking
- Protected privileged columns (role, active status) from unauthorized modification
- URL validation to prevent JavaScript injection in stored data
- Non-negative amount constraints on financial records
8.Third-Party Services
The Site and Platform may reference or integrate with the following third-party services:
- Supabase — Database hosting, authentication, and file storage (used by clinics for their own deployments)
- Google Fonts — Web font delivery for the Site
Each clinic's use of Supabase is governed by Supabase's own terms and privacy policy. We do not control how Supabase processes data stored in clinic-owned projects.
9.Children's Privacy
The Site and Platform are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
10.International Data Transfers
Since SmileCare is self-hosted, data remains in whatever jurisdiction the clinic's Supabase project or server is located. We do not transfer patient data across borders. Information collected through the Site (contact forms, analytics) may be processed in the United States.
11.Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be posted on the Site. Continued use of the Site after changes constitutes acceptance of the updated policy.
12.Contact Us
If you have questions about this Privacy Policy or how we handle data, contact us:
- Email: sales@smilecareapp.com
- Website: smilecareapp.com
Have questions about how SmileCare handles data or how your clinic can stay compliant? Our team is happy to walk you through the self-hosted architecture and security configuration.