Last updated: [DATE]
This Privacy Policy explains how [COMPANY LEGAL NAME] ("InfiniteApp", "we") collects, uses, and protects information in connection with the InfiniteApp platform (the "Service").
Account data we control: names, work emails, sign-in identifiers, roles, billing contacts, support messages, and usage/diagnostic data for people who use the Service. We are the "controller"/accountable party for this data.
Clinic data we process on behalf of clinics: the operational content a clinic and its staff put into their workspace (messages, schedules, checklists, inventory, documents). Each clinic owns and controls this data; where it includes protected health information, our Business Associate Agreement with that clinic governs. For questions about clinic content, contact the clinic — we act on their instructions.
Account registration details (name, email); authentication data via Google Identity Platform (we never see passwords for Google sign-in); subscription and billing records (payment card details are handled by our payment processor [Stripe, Inc.] and never touch our servers); support tickets; device and log data (IP address, browser type, timestamps) for security and reliability; and in-app usage events used to operate the Service. We do not sell personal information and we do not use advertising trackers in the Service.
To provide and secure the Service; authenticate users; process payments; provide support; send transactional messages (invites, receipts, service announcements); monitor abuse and enforce terms; comply with law; and improve the Service using aggregate, de-identified statistics.
We share information only with: infrastructure subprocessors (Google Cloud — Firestore, Cloud Storage, Cloud Functions, Identity Platform, hosted in the United States, us-central1); our payment processor [Stripe]; professional advisors as needed; and authorities when legally required. A current subprocessor list is available at [URL]. We require subprocessors handling regulated health data to sign appropriate agreements (e.g., Google's HIPAA Business Associate Addendum).
Encryption in transit and at rest; per-clinic data isolation enforced by server-side security rules and authenticated identity claims; role-based access; audit logging of administrative actions; and least-privilege access for our personnel. No method of transmission or storage is 100% secure, but we work to protect your information consistent with industry practice and, for PHI, with HIPAA.
Account data is kept while an account is active and as needed for legal and tax purposes. Clinic workspace data is retained per the clinic's subscription; after termination, clinics may export their data, and we delete it per our retention schedule and the BAA. Backups roll off on a fixed cycle [DEFINE].
Depending on where you live (e.g., Canada's PIPEDA, California's CCPA/CPRA, other state laws), you may have rights to access, correct, delete, or port your personal information, and to object to certain processing. Contact [privacy email] to exercise rights over account data; requests about clinic content are forwarded to the responsible clinic. We do not discriminate for exercising rights. [Attorney: add state-specific disclosures and a "Notice at Collection" if targeting California.]
We are a Canadian company hosting data in the United States. By using the Service you understand your information is processed in the U.S. and Canada. [Attorney: PIPEDA cross-border language; Quebec Law 25 if applicable.]
The Service is a workplace tool for clinics and is not directed to children under 16; we do not knowingly collect their information.
We will post updates here and notify account owners of material changes. Contact: [privacy email], [COMPANY LEGAL NAME], [ADDRESS].