SureAppoint Privacy Policy
FOUNDER-AUTHORIZED INTERIM POLICY
Published for current use by founder authorization on August 4, 2026. This interim policy remains subject to future review by qualified privacy counsel and prospective amendment and does not resolve SureAppoint's HIPAA, BAA, jurisdictional, or retention obligations.
Version: v1.0-2026-08-04
Effective date: August 4, 2026
SureAppoint legal entity: Passport Informatics, LLC
1. Scope
This Privacy Policy describes how SureAppoint handles information when practices use the appointment guarantee platform and when people review, accept, or authorize payment for an Appointment Guarantee.
SureAppoint is designed to preserve the evidence needed for an appointment guarantee without replacing the practice's scheduler, EMR, patient record, or general communication history.
This interim policy requires counsel to determine SureAppoint's legal role for each data category and relationship, including whether SureAppoint acts as a service provider, processor, business associate, independent controller, or in another capacity.
For clarity:
- Patient Subject means the person or people associated with the Practice-defined Appointment Unit.
- Guarantee Acceptor means the person who reviews and accepts the Practice Policy and maximum fee.
- Payment Authorizer means the person who authorizes possible future use of the Stripe-hosted payment method.
The roles may be filled by the same person or different people. SureAppoint does not create an account for any of these roles.
Document precedence
TODO (Legal Review): Approve this intended order of precedence before any document is published or signed:
- A signed amendment or order form, but only when it expressly identifies the provision it overrides.
- An applicable Business Associate Agreement or Data Processing Addendum, but only for its specific privacy, security, or data-processing subject matter.
- The Commercial Agreement.
- The Terms of Service.
- The Acceptable Use Policy.
- The Privacy Policy and Data Retention Policy, each for its specific subject matter.
No document may retroactively alter an accepted Appointment Guarantee, Policy Snapshot, Maximum Fee Snapshot, Payment Authorization, Practice Resolution, or historical evidence. If documents at the same level conflict, the more specific approved term controls only for its subject matter.
2. Privacy-first design
SureAppoint intentionally stores only the minimum patient information necessary to administer and prove an Appointment Guarantee.
The practice remains the authoritative source for:
- Attendance.
- Complete cancellation and rescheduling history.
- Clinical facts and appointment notes.
- Patient demographics not required for the guarantee.
- General patient communication history.
SureAppoint is authoritative only for the guarantee evidence supported by the platform, such as the accepted policy and fee, acceptance timestamps, delivery events, Stripe outcomes, Practice-authorized financial actions, and related audit evidence.
3. Information collected about practices and users
Depending on use and configuration, SureAppoint may collect:
- Practice and office name.
- Office phone number, email, support contact, provider name, and timezone.
- Legal, billing, or mailing contact information provided through onboarding or a commercial agreement.
- Authorized-user name, email address, authentication information, and account activity.
- Practice Policies, fee schedules, settings, and published policy provenance.
- Stripe connected-account references, onboarding status, capability status, and payment-activation evidence.
- Commercial agreement acceptance, approvals, and related timestamps.
- Support requests and operational communications.
- Security, audit, and technical records associated with account activity.
The Practice is responsible for keeping this information accurate.
4. Information collected about patients and Appointment Guarantees
Depending on the delivery method and guarantee, SureAppoint may collect:
- Patient Subject name.
- The minimum identity and authority information needed to distinguish the Guarantee Acceptor and Payment Authorizer.
- Mobile number and/or email address.
- The limited appointment date, time, office, and provider context needed to identify the guarantee.
- The immutable Practice Policy version and policy snapshot shown to the Guarantee Acceptor.
- The immutable maximum-fee snapshot shown to the Guarantee Acceptor.
- Guarantee Acceptor acceptance, Payment Authorizer authorization, payment-method security, revocation, replacement, and related timestamps.
- Secure-link creation, copy, submission, delivery, failure, expiry, and view evidence supported by the platform.
- Practice-authorized charge, reduction, forgiveness, refund, and dispute evidence.
- Stripe references, statuses, and transaction outcomes needed to reconcile the guarantee.
- Security and audit events needed to protect the Service and preserve evidence.
SureAppoint does not create patient accounts or a longitudinal patient portal.
5. Information intentionally not collected
SureAppoint is not designed to request or store:
- Clinical notes, diagnoses, treatment plans, or medical histories.
- Insurance information.
- Date of birth.
- Home address.
- Government identification numbers.
- The Practice's complete patient record.
- General scheduling or attendance history.
- General patient messages or an ongoing conversation history.
- Full card numbers, bank credentials, Stripe passwords, or identity documents submitted to Stripe.
Practices should not enter this information into fields that do not request it. If unnecessary information is submitted to support or another free-text channel, SureAppoint may need to handle it long enough to respond, secure it, and dispose of it under the approved retention process.
6. How information is used
SureAppoint may use information to:
- Create and deliver secure appointment links.
- Display appointment, Practice Policy, and maximum-fee information.
- Record Guarantee Acceptor acceptance and Payment Authorizer authorization.
- Facilitate payment-method setup and Practice-authorized payments through Stripe.
- Preserve immutable policy and fee evidence.
- Record truthful delivery and guarantee states.
- Support refunds, payment disputes, security review, and reconciliation.
- Authenticate users and enforce tenant boundaries.
- Provide founder-led onboarding and customer support.
- Operate, secure, diagnose, and maintain the Services.
- Meet applicable legal, accounting, security, and compliance obligations.
SureAppoint does not use patient information to make clinical, scheduling, attendance, factual-dispute, or enforcement decisions.
7. Participant information and Practice information
The Practice provides the patient and appointment information required to create an Appointment Guarantee. The Practice decides which policy and maximum fee to present and whether a later charge, reduction, forgiveness, or refund is appropriate.
The Guarantee Acceptor provides acceptance. The Payment Authorizer provides payment-method information and authorization. Payment details are submitted directly to Stripe. The Patient Subject, Guarantee Acceptor, Payment Authorizer, or cardholder should direct appointment, attendance, policy, or charge questions to the originating Practice.
The final policy must state who handles access, correction, deletion, or other privacy requests for each category. It must not imply that SureAppoint can change immutable accepted evidence or the Practice's separate patient record.
8. Stripe-hosted payment information
Stripe hosts the payment interface and stores payment information. SureAppoint does not receive or store a Payment Authorizer's full card number.
SureAppoint receives and stores limited Stripe references, statuses, and transaction outcomes needed to confirm that a payment method was secured, process an expressly Practice-authorized charge, reconcile a refund, and track a dispute.
Stripe handles information under its own terms and privacy notices. The final policy must accurately describe the relationship among Stripe, SureAppoint, the Practice, the Guarantee Acceptor, and the Payment Authorizer after counsel reviews the connected-account model.
9. Cookies and similar technologies
SureAppoint uses cookies or similar browser storage needed for authenticated sessions, security, and essential application operation.
This interim policy does not assert that a cookie banner is or is not required. Before publication, the technical owner and counsel must:
- Inventory every cookie, SDK, analytics tool, and tracking technology used in Production.
- Classify each item by purpose and duration.
- Decide whether notice, consent, or a separate Cookie Policy is required.
- Confirm that no advertising or marketing tracker is described unless it is actually present and approved.
10. Third-party processors and service providers
SureAppoint relies on service providers to operate the platform. Current categories include:
- Stripe: Connected-account onboarding, payment-method storage, payment processing, refunds, and disputes.
- Vercel: Application hosting and related infrastructure.
- Neon: Managed PostgreSQL database infrastructure.
- Enabled email or SMS providers: Transactional secure-link delivery, when configured.
- Authentication, security, and operational providers: Only as actually deployed and approved.
Before publication, the provider list, legal names, processing purposes, locations, and contractual terms must be verified. The final policy should not name a provider that is not used or omit a material provider that is used.
SureAppoint does not sell patient information. Counsel must approve the exact statutory language concerning sale, sharing, targeted advertising, and cross-context behavioral advertising for every applicable jurisdiction.
11. Transactional communications
SureAppoint may send a secure appointment link through a configured email or SMS provider. These messages are transactional and one-way. SureAppoint does not provide a patient messaging inbox or appointment conversation service.
Appointment questions and replies are directed to the originating Practice. The final policy and communications terms must address applicable consent, carrier, sender-identification, STOP/HELP, and recordkeeping requirements before automated delivery is enabled.
12. Security
SureAppoint uses administrative, technical, and organizational safeguards designed to protect information appropriate to the nature of the Services. Current product boundaries include tenant-scoped access, encrypted secrets, hashed secure-link lookup, restricted payment handling, audit evidence, and provider verification.
No security measure can guarantee absolute security. This interim policy does not promise that unauthorized access, loss, misuse, or service interruption can never occur.
The final policy must align with the approved incident-response process, customer-notification commitments, and any contractual security schedule.
13. Data retention and disposal
SureAppoint retains information only for as long as it serves an operational, legal, financial, security, or evidentiary purpose. Information that no longer serves those purposes is deleted, de-identified, or retained only where required by law or contractual obligations.
Different categories may require different treatment:
- Immutable policy and fee evidence may need to remain available to prove what the Guarantee Acceptor accepted.
- Contact information may no longer be necessary after delivery, guarantee disposition, and any applicable dispute period.
- Financial and audit evidence may need to remain for accounting, payment reconciliation, disputes, or legal obligations.
- Raw or temporary technical data should not be retained indefinitely when durable event identity and reconciliation evidence are sufficient.
- Founder-created test data should not be treated as customer production history.
SureAppoint does not promise one fixed retention period for every category. Category-specific durations remain to be finalized during legal review and documented in the Data Retention Policy.
Deletion or anonymization may be delayed when information is subject to a legal hold, active dispute, security investigation, accounting requirement, or other lawful preservation obligation.
14. Privacy choices and requests
The final policy must explain applicable rights and request procedures based on the relevant jurisdiction and SureAppoint's legal role. Counsel must determine:
- Whether a Patient Subject, Guarantee Acceptor, Payment Authorizer, or authorized representative should submit a request to the Practice, SureAppoint, or both.
- How identity and authority will be verified without collecting unnecessary information.
- How correction requests interact with immutable acceptance evidence.
- Which records may be deleted, anonymized, restricted, or retained.
- Applicable appeal and response procedures.
SureAppoint should not promise a right or response process that has not been legally and operationally approved.
Revocation prevents future use of the Payment Authorization for a new charge or retry. It never rewrites the original acceptance, authorization, delivery, or financial history and does not automatically reverse a completed financial action. Any replacement guarantee requires a new secure link, fresh acceptance, and a new Payment Authorization. A revocation request is handled under the Payment Authorization Revocation and Replacement Procedure.
15. Children and responsible parties
Version 1.0 does not implement separate participant accounts or a multi-appointment family workflow. The Patient Subject, Guarantee Acceptor, and Payment Authorizer may nevertheless be different people. Counsel must determine whether any age-related eligibility, parental consent, guardian authority, or payment-authorization language is required for the intended Practice use before the final policy is published.
16. Changes to this policy
SureAppoint will notify affected customers of future material changes to this policy or its subprocessors through the approved customer contact channel. The final policy must state when those changes become effective.
A change to this Privacy Policy does not alter an immutable Practice Policy or maximum-fee snapshot already accepted for an Appointment Guarantee.
17. Contact information
Privacy inquiries: support@sureappoint.com
Postal address: Use the SureAppoint legal entity information and business
mailing address stated in the applicable Commercial Agreement.
Practice appointment questions: Contact the Practice identified in the
secure appointment communication.