Privacy Policy
Last updated July 29, 2026
1. Who this covers
This policy explains how Pencil (“we”, “us”) handles information. It covers two groups: the dental practices that subscribe to Pencil, and the patients who book appointments through a practice’s website.
For patient information, the practice is the data controller and we act as its service provider. We process patient data only to deliver the Service to that practice.
2. Information we collect from practices
- account details: name, email address, and password;
- location details: practice name, address, phone number, hours, and branding;
- billing details, processed by our payment processor — we never store full card numbers; and
- product usage and diagnostic logs.
3. Information we collect from patients
- the name, phone number, and email address entered in the booking form;
- the appointment time chosen and its later status;
- text messages exchanged with the practice through the Service; and
- a non-identifying advertising click identifier, where present, so the practice can measure which ads produce bookings.
4. How we use information
We use information to:
- create and manage appointments for the practice;
- send appointment confirmations, reminders, and follow-up messages the patient consented to receive;
- report booking and call volume back to the practice;
- report conversions to advertising platforms without attaching patient details;
- bill subscriptions and provide support; and
- keep the Service secure and diagnose problems.
We do not sell personal information, and we do not use patient data to train models.
5. Advertising measurement
When a practice runs ads, we can report that a booking occurred and tie it to the click that produced it. That report carries the click identifier and the fact of a booking — not the patient’s name, contact details, or any information about their condition or care.
6. Text messaging
Patients opt in to text messages in the booking form. Messages are sent from a number provisioned for the practice and identify the practice by name. Patients can reply STOP at any time to stop receiving messages, or HELP for help. Message and data rates may apply.
7. Call tracking
Where a practice enables call tracking, calls placed to the tracked number are connected to the practice’s real line and recorded in the practice’s dashboard for attribution and quality purposes. Practices are responsible for any call-recording disclosures their jurisdiction requires.
8. Service providers
We share information with vendors that operate parts of the Service on our behalf — hosting, telephony and messaging, payment processing, email delivery, and error monitoring. Each is bound to use the information only to provide its service to us.
9. HIPAA
Appointment information handled through the Service can constitute protected health information. We support business associate agreements with subscribing practices and configure our systems and vendors accordingly.
10. Retention
We keep appointment and message records for as long as the practice’s account is active, and afterwards only as long as needed to meet legal, accounting, or dispute-resolution obligations. Practices may request deletion of their data after cancellation.
11. Security
Data is encrypted in transit and at rest, access is limited to personnel who need it, and administrative access is logged. No system is perfectly secure, and we will notify affected practices promptly if a breach occurs.
12. Your choices
Patients should contact the practice they booked with to access, correct, or delete their information; we will assist the practice in responding. Practices can contact us directly. Depending on where you live, you may have additional rights under state or national privacy law.
13. Children
The Service is not directed to children. A parent or guardian is expected to book on behalf of a minor patient.
14. Changes
We may update this policy. Material changes will be announced in the application or by email before they take effect.
15. Contact
Privacy questions: support@usepencil.io.