Privacy policy.
The short version. The public site collects what you type into two forms (a consultation request and a free website check) plus ordinary security logs. We don't run advertising trackers or third-party analytics. Clients who use the portal get an email login, and files they upload are stored on Cloudflare in the United States. We don't sell personal information.
1. What we collect
On the public website
- Consultation request — your name, practice, email, current website address, your message and any inspiration links you add.
- Free website check — your practice, email, current website address and message.
- Form security — forms are protected by Cloudflare Turnstile. When you submit, we record the time you spent on the page and your IP address (it appears in the notification we receive and is used briefly to rate-limit abuse).
- Security and traffic logs — the site runs on Cloudflare, which logs requests (IP address, browser, pages requested, timestamps) to serve the site and block abuse. We keep only an aggregate daily page-view count of our own; we do not build per-visitor profiles.
- Email — whatever you send to our addresses. Email we send you goes through a delivery service (Brevo) that records whether a message was opened and which links were clicked; we can't switch that off on the relay, so please treat any email from us as trackable.
In the client portal and during a project
- Portal sign-in — a one-time code sent to your email; a signed session cookie keeps you logged in. We record sign-in attempts by IP to limit abuse.
- Project files — photos, video, documents and text you upload or send for your website. These are stored in Cloudflare R2 in the United States and are used only to build and maintain your site.
- Payments — processed by Stripe. We receive confirmation and invoice details; we never see or store full card numbers.
- Tracked report links — when we send you a report link, opening it records the visit, time on page, scrolling, browser type, referrer and a hashed (one-way) IP, so we know the report reached you. Those links are protected by Turnstile.
- Patient photo and testimonial releases — if your practice uses our release kiosk, it collects the patient's name, date of birth, contact details and signature. That information is protected health information handled for your practice under a signed Business Associate Agreement and is used only to document the authorization.
- Automated mail handling — inbound receipts and replies to our role addresses may be classified by an AI model running on Cloudflare to route them correctly. The content is not used to train models.
2. How we use it
- To respond to consultation and website-check requests, scope a project and deliver the services you engage us for.
- To run, secure and improve the site and portal.
- To invoice and collect payment, and to keep business records.
- To send service messages about your project. We don't send marketing email to prospects unless they ask for it, and you can opt out of any marketing at any time.
3. Who we share it with
Only service providers that run our infrastructure, and only for those purposes: Cloudflare (hosting, storage, security, email routing, AI classification), Stripe (payments), Brevo (outbound email delivery), and jsDelivr, a content-delivery network that serves one animation library to the homepage and so receives your IP address when the page loads. We don't sell personal information and don't share it for cross-context behavioral advertising. We may disclose information if the law requires it or to protect our rights or someone's safety. All data is processed in the United States.
4. Cookies
The public site sets no cookies of its own. Cloudflare Turnstile may set a security cookie on forms and tracked report links. The client portal and staff tools use signed session cookies to keep you logged in. There are no advertising or analytics cookies.
5. Retention
Form submissions arrive as email and are kept as long as the conversation and any resulting project require. Project files are kept for the life of your engagement and a reasonable period after, or deleted sooner on request once your site is live and handed over. Security logs are kept for a short rolling period. Payment and invoice records are retained as required for accounting and tax purposes. Patient releases are retained for as long as your practice's HIPAA obligations require.
6. Security
Everything is served over HTTPS. Files live in access-controlled storage; portal access is per-client and by one-time code. No system is perfectly secure — tell us right away at info@sitealigners.com if you think an account has been compromised.
7. Your choices and rights
Email us to access, correct or delete the information we hold about you, or to close a portal account. Residents of states with consumer-privacy laws may have additional rights, which we honor regardless of where you live. Blocking cookies in your browser won't break the public site; the portal needs its session cookie to work. We don't respond to browser "Do Not Track" signals because there is no common standard, but we also don't track you across other sites.
8. Children
Our services are for dental practices. We don't knowingly collect information from anyone under 18, except patient information handled for a practice under a signed authorization and BAA as described above.
9. Changes and contact
We'll post changes here and update the effective date. SiteAligners · Commerce Township, Michigan · info@sitealigners.com. See also our terms of service.