1. Scope and roles
This Privacy Policy applies to the SmilePing website, application, public booking pages, support interactions, and related services (collectively, the "Services").
SmilePing acts as the organization responsible for personal information used to operate its website, accounts, billing, security, and business relationships. When a business customer imports client records or uses SmilePing to communicate with its clients, SmilePing generally processes that information on the customer's instructions. The customer remains responsible for deciding why the information is collected and how it may be used.
This policy does not replace a customer's own privacy notice. If you received a SmilePing-powered message from a business, that business is usually the best first contact for questions about the underlying client record.
2. Information we collect
Depending on how the Services are used, we may collect:
- Account and organization information: name, business name, email address, role, authentication identifiers, preferences, and account settings.
- Customer-provided client data: contact details, appointment and service history, booking status, communication preferences, offers, notes, and imported spreadsheet or PMS data.
- Communications: message content, replies, delivery status, support requests, callback requests, and records needed to maintain a follow-up history.
- Billing information: subscription plan, billing status, Stripe customer and subscription identifiers, and limited payment-method details such as card brand and last four digits. Full card details are handled by Stripe.
- Technical and usage information: IP address, browser and device information, timestamps, pages viewed, feature interactions, diagnostic logs, and security events.
We receive information directly from users, from business customers and their authorized imports or integrations, from client interactions with messages and booking pages, and from service providers that support the Services.
3. How we use information
We use personal information to:
- provide, configure, maintain, and secure the Services;
- identify follow-up opportunities and manage recall, rebooking, callback, cancellation, no-show, consultation, and lapsed-client workflows;
- draft and deliver messages, process replies, provide booking links, and stop follow-ups when a client books or opts out;
- authenticate users, manage permissions, process subscriptions, and provide support;
- measure performance, troubleshoot problems, prevent fraud or misuse, and improve reliability;
- send product or service communications where permitted and honor communication choices; and
- comply with law, enforce agreements, and protect the rights and safety of SmilePing, our customers, and others.
We do not use customer-provided client data for unrelated advertising.
4. AI-assisted features and messaging
SmilePing uses automated rules and artificial intelligence to help identify relevant follow-ups, draft messages and replies, summarize conversations, recommend next steps, and support booking workflows. These features may use client history, appointment context, prior messages, business instructions, active goals, and approved offers.
AI output can be incomplete or inaccurate. Business customers control their follow-up settings and are responsible for reviewing workflows and messages where review is required. SmilePing is not a medical provider, and AI-generated content is not medical advice.
We may send the minimum information reasonably needed to contracted AI and infrastructure providers to operate these features. Customer-provided client data is not used to train a general-purpose AI model unless the customer expressly agrees.
Business customers are responsible for having the notices, permissions, and other lawful authority required to contact their clients. Recipients can use supported opt-out instructions, and customers must honor applicable consent and communication laws.
7. Retention, security, and international processing
We retain personal information only as long as reasonably needed to provide the Services, maintain required business and security records, meet legal obligations, resolve disputes, and enforce agreements. Retention may vary by data type, account status, customer instructions, and contractual requirements. We delete or de-identify information when it is no longer required, subject to backups, fraud prevention, legal holds, and audit obligations.
SmilePing uses administrative, technical, and organizational safeguards designed for the sensitivity of the information, including access controls, encryption, tenant separation, monitoring, and audit records. No system can guarantee absolute security. Please contact us promptly if you believe an account or communication has been compromised.
We and our service providers may process information in Canada, the United States, and other locations where providers operate. Information may therefore be subject to the laws of those jurisdictions. We use contractual and technical protections appropriate to the transfer and the information involved.
8. Your privacy rights and choices
Depending on your location and relationship with SmilePing, you may have the right to request access, correction, deletion, restriction, or portability of personal information; withdraw consent where processing relies on consent; object to certain processing; or complain to a privacy regulator. You will not be discriminated against for exercising an applicable privacy right.
Account users can update some information in the Services. Other requests can be sent to hello@smileping.com. We may need to verify your identity and authority before completing a request. Authorized agents may submit requests where permitted by law.
If SmilePing holds your information for one of our business customers, please contact that business first. We will assist the customer with a verified request as required by contract and applicable law.
9. Healthcare information and children
Where SmilePing processes protected health information for a US HIPAA covered entity or business associate, the applicable Business Associate Agreement and customer instructions govern that processing. This Privacy Policy is not a Business Associate Agreement. Customers should not submit protected health information unless their SmilePing account and written agreement authorize that use.
The Services are designed for businesses and their authorized users, not for use by children. We do not knowingly create accounts for children under 16. A business customer may hold information about a minor when legally permitted and remains responsible for obtaining any required parental or guardian authorization.
10. Changes and contact
We may update this policy as the Services, providers, or legal requirements change. We will post the revised policy here and update the effective date. If a change materially affects how we use personal information, we will provide additional notice where required.
SmilePing Privacy
hello@smileping.com