Effective September 10, 2026
Privacy Policy
This policy explains what personal information Klinefy collects, why, who it is shared with, and the choices you have. It covers clinic staff, patients, and visitors to our website.
1.Who we are and the two roles we play
Klinefy (“Klinefy”, “we”, “us”) is operated by Klinefy. We provide software that clinics use to publish services and packages, take payments, and give patients a portal.
For clinic and staff accounts, and for visitors to klinefy.com, we decide how personal information is used, so we are the controller. For patient information that a clinic collects through its storefront, pay page or portal, the clinic decides why and how it is used; we process it on the clinic’s behalf and instructions. Patients with questions about their information should contact their clinic first.
2.What we collect
Staff account information. Your name, email address, password (stored only as a hash), role, clinic, time zone, and the actions you take in the console, which are written to an audit log so clinics can see who changed prices, approved plans or recorded payments.
Sign in with Google. If you choose to sign in with Google, Google sends us your name, email address and profile picture, and a token that lets us confirm it was you. We use them only to create or find your Klinefy account and to show your name in the console. We do not receive your Google password, contacts, calendar, files or any other Google data, and we do not use Google data for advertising. You can revoke Klinefy’s access from your Google account’s security settings at any time; your Klinefy account then continues with email and password sign-in.
Clinic content. Your catalog, prices, storefront text and branding, locations, and the messages you send patients through Klinefy.
Patient information (processed for the clinic). Name, email address, phone number, the services and packages in a plan, prices and installment schedules, payment records, session balances, and any note a patient adds when submitting a plan. Klinefy is built for contact and purchase records; it does not ask for clinical notes, diagnoses or lab results.
Payment information. Card details are entered on Stripe’s pages and stored by Stripe on the clinic’s Stripe account. We receive only what Stripe returns: the last four digits, card brand, and payment outcomes.
Usage and device information. Pages visited, features used, browser type, approximate location from your IP address, and error reports. We use a session cookie to keep you signed in and product analytics to understand how the console is used; analytics events never include patient names, plan contents or amounts.
Communications. Emails and messages you exchange with us, and delivery records for emails and texts the service sends (recipient, template, time, status), which we keep so clinics can see what was sent.
3.Why we use it
- To run the service: sign-in, catalogs, storefronts, plans, payment links, installment charges, receipts, session balances and the patient portal.
- To send the emails and texts the service needs: confirmations, sign-in links, payment links, receipts, failed-payment notices, and clinic notifications.
- To keep the service secure: detecting abuse, rate-limiting, and keeping an audit trail of sensitive actions.
- To support clinics and improve the product, using aggregated usage data and, when you contact us, the details you share.
- To meet legal obligations, such as tax and payment-network rules that apply to transactions.
We do not sell personal information and we do not use it for third-party advertising.
4.Who we share it with
We share personal information with the providers below, who process it on our behalf under contracts that restrict their use of it; with a clinic’s staff, for that clinic’s patients and records; with Stripe, which is also an independent controller for payment processing under its own privacy policy; and with authorities when the law requires it. If Klinefy is acquired or merges, information may transfer to the successor under this policy.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | database, authentication and file storage | United States |
| Cloudflare | hosting, networking and DDoS protection | Global edge network |
| Stripe | payment processing and card storage, on each clinic's own Stripe account | United States |
| optional sign-in with a Google account (OAuth) | United States | |
| Resend | transactional email delivery | United States |
| NotifyGW | text and WhatsApp message delivery | United States |
| PostHog | product analytics (usage events, never clinical data) | United States |
5.Cookies
We use a strictly necessary cookie to keep you signed in, and a first-party analytics cookie to measure how the console is used. We do not use advertising cookies. You can clear or block cookies in your browser; blocking the session cookie means you cannot stay signed in.
6.How long we keep it
- Clinic accounts and content: for as long as the clinic’s account is open, then 30 days for export, then deleted, except records we must keep for tax, payment or legal reasons.
- Patient plans, payments and receipts: for as long as the clinic keeps them; payment records are kept for the period payment and tax rules require.
- Audit logs and message delivery records: 24 months.
- Analytics: aggregated after 12 months.
- Backups: rotated within 30 days of deletion.
7.How we protect it
Data is encrypted in transit and at rest. Each clinic’s records are isolated at the database level so one clinic’s staff cannot read another’s. Access to production systems is limited to the people who operate the service and is logged. Card numbers never touch our systems. No method is perfect; if we learn of a breach affecting your information, we will notify the affected clinic, and individuals where the law requires, without undue delay.
8.Your choices and rights
Depending on where you live, you may have the right to access, correct, export or delete your personal information, to object to or restrict certain processing, and to complain to a data-protection authority. Staff can update their profile in the console and can ask us to delete their account. Patients should contact their clinic, which controls their records; we will help the clinic respond. You can also write to us at hello@klinefy.com and we will answer within 30 days. You can stop receiving text messages by replying STOP, and you can revoke Google sign-in as described in section 2.
9.Health information
Klinefy is designed for cash-pay clinics and stores contact and purchase information, not clinical notes. Whether information a clinic places in Klinefy is protected health information under HIPAA or similar law is the clinic’s determination. Clinics that are covered entities must have a business associate agreement with us before storing protected health information, as set out in the Terms of Service.
10.Children
The console is for adults acting for a clinic. Patients under 18 may appear in a clinic’s records only where a parent or guardian deals with the clinic on their behalf; we do not knowingly collect information directly from children.
11.International transfers
Our providers store and process data primarily in the United States. If you use the service from elsewhere, your information is transferred to and processed there, with the safeguards our provider contracts require.
12.Changes to this policy
We will post changes here and update the date at the top. For material changes we will email account owners before the changes take effect.
13.Contact
Klinefy · hello@klinefy.com · klinefy.com
Questions about this document: hello@klinefy.com