SureAppoint Acceptable Use Policy
FOUNDER-AUTHORIZED INTERIM POLICY
Published for current use by founder authorization on August 4, 2026. This interim policy remains subject to future review by qualified counsel and prospective amendment.
Version: v1.0-2026-08-04
Effective date: August 4, 2026
1. Purpose
This Acceptable Use Policy protects patients, practices, payment providers, and the integrity of the SureAppoint appointment guarantee platform.
It applies to each Practice and Authorized User. It supplements the Terms of Service and Commercial Agreement.
The participant terms have the meanings stated in the Terms of Service:
- Patient Subject: The person or people associated with the Practice-defined Appointment Unit.
- Guarantee Acceptor: The person who accepts the Practice Policy and Accepted Maximum.
- Payment Authorizer: The person who authorizes possible future use of the Stripe-hosted payment method.
The roles may be filled by the same person or different people.
Document precedence
TODO (Legal Review): Approve this intended order of precedence before any document is published or signed:
- A signed amendment or order form, but only when it expressly identifies the provision it overrides.
- An applicable Business Associate Agreement or Data Processing Addendum, but only for its specific privacy, security, or data-processing subject matter.
- The Commercial Agreement.
- The Terms of Service.
- The Acceptable Use Policy.
- The Privacy Policy and Data Retention Policy, each for its specific subject matter.
No document may retroactively alter an accepted Appointment Guarantee, Policy Snapshot, Maximum Fee Snapshot, Payment Authorization, Practice Resolution, or historical evidence. If documents at the same level conflict, the more specific approved term controls only for its subject matter.
2. Use the platform only for its intended purpose
SureAppoint may be used to:
- Present a Practice-authored appointment policy and maximum fee.
- Record Guarantee Acceptor acceptance.
- Secure the Payment Authorizer's payment method through Stripe without collecting payment that day.
- Preserve guarantee evidence.
- Support a later, explicit Practice decision to charge, reduce, or forgive an eligible fee.
SureAppoint must not be used as an EMR, scheduler, patient portal, collections platform, CRM, messaging platform, or tool for clinical decisions.
3. Fraud and misrepresentation
The Practice and its users must not:
- Create a false or misleading Practice account.
- Misrepresent a Practice's identity, office, provider, authority, or Stripe account.
- Create an Appointment Guarantee for a fabricated appointment, except for a founder-approved synthetic walkthrough that uses designated synthetic information and does not create a live charge.
- Create fake participant identities to fabricate Production activity or payment evidence, accept a guarantee without authority, misrepresent the Patient Subject, or manipulate acceptance evidence.
- Submit false evidence to SureAppoint, Stripe, a card issuer, a Patient Subject, Guarantee Acceptor, Payment Authorizer, or another party.
- Use the Services to conceal fraud, money laundering, unauthorized activity, or another illegal purpose.
4. Fake or inaccurate appointments
Every Appointment Guarantee must correspond to a real Practice-defined Appointment Unit maintained in the Practice's own scheduler or EMR.
The Practice must not knowingly send:
- The wrong office or provider.
- A false appointment date or time.
- A policy that does not apply to the appointment.
- A fee schedule that the Practice did not intend to use.
- A guarantee identifying the wrong Patient Subject, Guarantee Acceptor, Payment Authorizer, or delivery contact.
Material errors must be corrected through the approved replacement-guarantee process. The Practice must not edit, reinterpret, or misstate historical acceptance evidence.
5. Excessive, unlawful, or unauthorized charges
The Practice must not:
- Charge more than the Guarantee Acceptor's Accepted Maximum.
- Increase the fee after Guarantee Acceptor acceptance.
- Charge without an accepted policy and Stripe-confirmed secured payment method.
- Charge after the Payment Authorization has been revoked.
- Charge automatically or use automation to bypass the required Practice decision.
- Split one fee into multiple charges to avoid a limit or safeguard.
- Charge for an event the Practice has not reasonably determined occurred.
- Apply a policy or fee unlawfully, unfairly, deceptively, or inconsistently with the Guarantee Acceptor's acceptance.
- Use SureAppoint to collect unrelated debt or balances.
If the Practice intended a higher fee than the Guarantee Acceptor accepted, the Practice must absorb the difference or create a valid replacement guarantee before acceptance. It may not retroactively increase the accepted fee.
Revocation prevents future use of the Payment Authorization for a new charge or retry. It never rewrites historical evidence and does not automatically reverse a completed financial action. A replacement guarantee requires a new secure link, fresh acceptance, and a new Payment Authorization.
6. Government-program and eligibility restrictions
Under the current operating rule, the Practice must not use SureAppoint for a Patient Subject who is a Medicaid beneficiary or eligible for both Medicare and Medicaid (dual-eligible), unless future legal review and written SureAppoint approval expressly permit that use.
The Practice must screen for excluded Patient Subjects using its own system of record. This interim policy does not establish the final treatment of Medicare-only Patient Subjects or other government programs. Counsel must approve the final eligibility language.
7. Credential and account security
The Practice and its users must not:
- Share credentials with an unauthorized person.
- Allow a former employee or contractor to retain access.
- Use another Practice's account.
- Attempt to obtain another user's password, session, token, or authentication information.
- Publish or transmit secure links, credentials, API keys, webhook secrets, or provider secrets outside their intended use.
- Disable or evade authentication, tenant isolation, or security controls.
The Practice must promptly report suspected account compromise through
support@sureappoint.com, the founder support and security contact.
8. Attempts to bypass safeguards
Users must not:
- Alter or fabricate delivery, acceptance, payment, refund, or audit states.
- Mark a copied or submitted link as delivered without provider confirmation.
- Intentionally open patient-facing links from office workflows to manufacture or misrepresent Viewed evidence.
- Reuse, regenerate, or manipulate secure links to misrepresent participant action.
- Retry an uncertain payment in a way that risks duplicate charging.
- Bypass payment-activation gates, Stripe account checks, accepted maximums, confirmation screens, or authorization requirements.
- Probe, scrape, reverse engineer, disrupt, or test the Services without written authorization.
- Introduce malicious code or interfere with another Practice's use.
9. Abuse of Stripe
The Practice must comply with Stripe's terms and must not:
- Use another person or Practice's Stripe account.
- Submit false onboarding, identity, banking, tax, or business information.
- Use Stripe through SureAppoint for an unsupported or prohibited business or transaction.
- Attempt to bypass Stripe review, restrictions, or account requirements.
- Manipulate charges, refunds, disputes, or connected-account records.
- Ask SureAppoint support to receive or handle Stripe passwords, API keys, bank credentials, full card information, or identity documents.
10. Abuse of patients
The Practice and its users must not use SureAppoint to:
- Mislead a Patient Subject, Guarantee Acceptor, or Payment Authorizer about who sent the link or why it was sent.
- Conceal the policy or maximum fee.
- State or imply that a charge occurs when the payment method is saved.
- State or imply that SureAppoint, rather than the Practice, decides whether a fee applies.
- Threaten, harass, shame, discriminate against, or pressure a Patient Subject, Guarantee Acceptor, or Payment Authorizer.
- Send deceptive, excessive, or unrelated messages.
- Use guarantee evidence to misrepresent the underlying appointment facts.
- Retaliate against a Patient Subject, Guarantee Acceptor, Payment Authorizer, or cardholder for raising a question or payment dispute.
The Practice must provide a working office contact for participant appointment, policy, and charge questions.
11. Improper information collection
Users must not enter unnecessary patient information into SureAppoint, including:
- Clinical notes or diagnoses.
- Insurance information.
- Date of birth.
- Home address.
- Government identification numbers.
- Full card or bank information.
- Passwords, provider secrets, or identity-document images.
The Practice remains responsible for maintaining complete patient and appointment records in its own systems.
12. Illegal activity
The Services may not be used in violation of applicable healthcare, payment, privacy, consumer-protection, communications, sanctions, anti-fraud, or other law.
The Practice must not use SureAppoint where its policy, fee, Patient Subject category, participant authority, or intended charge is prohibited.
13. Investigation and enforcement
SureAppoint may preserve relevant evidence, restrict payment activity, suspend access, or terminate use when reasonably necessary to investigate or address a suspected violation.
SureAppoint may act immediately for fraud, abuse, unlawful activity, material security concerns, or other serious misuse. When appropriate and legally permitted, SureAppoint will communicate the reason for a suspension and explain any available remediation or reinstatement process.
SureAppoint does not automatically adjudicate factual disputes between a Practice and a Patient Subject, Guarantee Acceptor, Payment Authorizer, or cardholder. Any enforcement decision under this policy should be based on the integrity and safety of the Services, not a clinical or attendance determination.
14. Reporting concerns
Report suspected misuse to:
Abuse contact: support@sureappoint.com
Security contact: support@sureappoint.com
Legal notices: Use the SureAppoint legal entity information and business
mailing address stated in the applicable Commercial Agreement.
Do not include full card numbers, bank credentials, passwords, API keys, identity documents, or unnecessary patient information in a report.