1. Introduction
Insurance.Dental ("we," "us," "our") operates a dental practice revenue intelligence platform at insurance.dental (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. We are committed to protecting the privacy and security of dental practice data, including any information that may be considered Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act ("HIPAA").
2. Information We Collect
- Account Information: Practice name, address, NPI number, email address, and contact details provided during registration.
- Claims Data: Dental claims data you upload, including CDT procedure codes, payer information, billed amounts, and reimbursement amounts. This data is used solely to generate your practice's revenue analysis.
- Usage Data: Browser type, IP address, pages visited, and feature usage patterns collected automatically to improve the Service.
- Payment Information: Subscription billing data is processed by Stripe. We do not store credit card numbers on our servers.
3. How We Use Your Information
- To provide revenue gap analysis, market intelligence, and negotiation briefings
- To compare your practice's reimbursement rates against anonymized market benchmarks
- To generate payer scorecards and trend analysis
- To communicate Service updates, security notices, and support responses
- To improve and develop new features
We never sell your data. We never share identifiable practice data with payers, competitors, or third parties for marketing purposes.
4. Data Security
- All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Our infrastructure is hosted on SOC 2 Type II and HIPAA-compliant cloud providers
- Role-based access controls limit internal data access
- We conduct regular security assessments and maintain audit logs
- Database backups use point-in-time recovery with encrypted storage
5. HIPAA Compliance
If your use of the Service involves Protected Health Information, we will enter into a Business Associate Agreement (BAA) with your practice. Under our BAA, we implement administrative, physical, and technical safeguards as required by the HIPAA Security Rule, and we limit our use and disclosure of PHI to the purposes permitted by the BAA and applicable law.
6. Data Retention
- Active account data is retained for the duration of your subscription
- Claims data you upload can be deleted at any time from your dashboard
- Upon account termination, we delete your practice data within 90 days
- Anonymized, aggregated benchmark data (which cannot identify any practice) may be retained indefinitely
7. Third-Party Services
We use the following third-party services that may process your data:
- Supabase (database hosting and authentication)
- Stripe (payment processing)
- Vercel (application hosting)
Each provider maintains its own privacy practices and security certifications.
8. Your Rights
You have the right to:
- Access the personal and practice data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Export your uploaded claims data
- Withdraw consent for optional data processing
To exercise these rights, contact privacy@insurance.dental.
9. Cookies and Tracking
We use essential cookies for authentication and session management. We do not use third-party advertising trackers. Analytics, if enabled, use privacy-respecting methods that do not track individual users across sites.
10. Children's Privacy
The Service is designed for dental practice professionals and is not intended for individuals under 18 years of age.
11. Changes to This Policy
We may update this Privacy Policy periodically. We will notify registered users of material changes via email and update the "Last Updated" date above.
12. Contact
For questions about this Privacy Policy or our data practices, email privacy@insurance.dental.