Privacy Policy
Effective 4 October 2026
This is SmileSort Ltd's privacy notice for everyone who visits smilesort.com or holds a SmileSort account — dentists, practice staff, and site visitors. It covers your own personal data, not your patients'. If you're a dentist and want to know how your patients' data is handled, that's governed by our Data Processing Agreement — see Section 1 below for why that's a separate document.
1. Scope — what this policy covers
SmileSort plays two different roles, and they're governed by two different documents:
- Your own account data (your name, email, professional details, billing information) — SmileSort is the controller, and this Privacy Policy governs it.
- Your patients' clinical data (the photographs and records you upload about them) — SmileSort is the processor, you're the controller, and our Data Processing Agreement governs it. This policy doesn't cover that relationship.
2. Data we collect
When you create and use a SmileSort account, we collect:
- Account details: email, full name, professional title, avatar image, GDC (dental registration) number, practice name.
- Usage data: which onboarding/product-tour steps you've completed — used only to avoid showing you the same guidance twice, never to profile you.
- Billing data: handled directly by our payment processor, Stripe — we hold your Stripe customer/subscription reference, not your card details.
- Marketing preference: whether you’ve said yes to product updates and tips by email — at signup, where the box is unticked by default, or later in Settings → Data & Privacy — with when and where you said it. You can change it there at any time, or with the unsubscribe link in any of those emails.
- First-touch attribution: if you arrived via a marketing link, we record the referring site and campaign tags against your account, once, at signup — never a persistent cross-visit tracking identifier.
If you use our public resource downloads without an account, we collect the email address you provide and, if you tick the box, your marketing preference for that download — this is never linked to a SmileSort account unless you separately sign up with the same address.
If you send us a feature suggestion from our Features page, we keep what you wrote. We don’t ask for your name or email address with it. If you’re signed in when you send it, it’s linked to your account; otherwise it’s anonymous. Please don’t include patient details in a suggestion.
4. How we use it, and why that's lawful
| Purpose | Lawful basis |
|---|---|
| Providing the Service — your account, storage, billing | Article 6(1)(b) — necessary to perform our contract with you |
| Security, fraud prevention, keeping the Service running | Article 6(1)(f) — our legitimate interest, balanced against your rights |
| Product analytics (first-party, non-identifying) | Article 6(1)(f) — legitimate interest in understanding how the product is used |
| Feature suggestions you send us | Article 6(1)(f) — legitimate interest in improving the product from your feedback |
| Measuring our adverts: public-site visits, sign-ups and plans started (Meta Pixel) | Article 6(1)(a) — your consent, given by choosing “Accept all” on the cookie banner, withdrawable at any time |
| Emails about your account and plan — getting started, your trial, plan changes — and keeping your email profile with Klaviyo up to date for them | Article 6(1)(f) — our legitimate interest in telling you what you need to know about the service you signed up for |
| Marketing emails — product updates and tips | Article 6(1)(a) — your explicit consent, given at signup, in Settings or at a resource download, withdrawable at any time |
| Legal and regulatory compliance | Article 6(1)(c) — necessary to comply with our legal obligations |
6. International transfers
Cloudflare is a US company, and Supabase's contracting entity is registered in Singapore (even though the data itself is hosted in the UK). Both transfers are covered by that provider's own Data Processing Addendum, independently confirmed to incorporate the EU Standard Contractual Clauses and the UK's International Data Transfer Addendum.
Klaviyo, Inc. is a US company. Transfers to it rely on its certification under the EU–US Data Privacy Framework and its UK extension, and on the EU Standard Contractual Clauses and the UK Addendum in its Data Processing Agreement.
If you accept the Meta Pixel, Meta may transfer that data to Meta Platforms, Inc. in the US, under Meta's own transfer safeguards (it is certified under the EU–US Data Privacy Framework and its UK extension).
7. How long we keep it
- While your account is active, we keep your account data for as long as you have an account.
- If you cancel, your account stays read-only and exportable for 30 days, then every patient record, photograph and login is permanently and automatically deleted. Billing records stay with Stripe for as long as tax law requires, and product usage statistics are kept only in anonymous form.
- Deleted records inside an active account are held in Trash for 28 days before permanent removal.
- A resource-download email (submitted without an account) is deleted automatically after 24 months. Email us to have it deleted sooner.
- A feature suggestion is deleted automatically after 24 months. If you delete your account, any suggestions you sent stop being linked to it.
- Your email profile with Klaviyo is kept while you have an account. When the account is deleted — by you, or automatically after cancellation — we ask Klaviyo to delete it too. If you unsubscribe from marketing emails, Klaviyo keeps a record that you did, so you aren’t sent them again.
8. Your rights
Under UK GDPR, you can ask us to:
- give you a copy of the personal data we hold about you (access);
- correct it if it's wrong (rectification);
- delete it (erasure) — or do this yourself any time via account deletion;
- restrict or object to certain processing;
- receive it in a portable format (portability) — our self-service export does this directly;
- withdraw marketing consent at any time — in Settings → Data & Privacy, or with the unsubscribe link in any marketing email — with no effect on the Service itself.
Email privacy@smilesort.com for any of these. You can also complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), though we'd appreciate the chance to put things right first. SmileSort Ltd is on the ICO's register of data controllers under registration number ZC258400.
9. Security
How your data is actually protected — tenant isolation, encryption, access control — is described in full on our Security & Trust page, rather than repeated here.
10. Children
SmileSort is a professional tool for registered dental practices and their staff. It isn't directed at children, and we don't knowingly collect personal data from anyone under 18.
11. Changes to this policy
We may update this policy as the Service or the law changes. For a material change, we'll notify you by email or an in-product notice before it takes effect.
12. Contact
Questions about this policy, or a request about your data? privacy@smilesort.com