← PracticeWoven

Privacy Policy

Last updated: June 11, 2026

This Privacy Policy describes how PracticeWoven (“we,” “us”) handles personal information when you visit practicewoven.com, create an account, or build a site with us. It also explains our role in the data that visitors submit to sites our customers publish.

1. Two roles: our site vs. your site

For practicewoven.com and your PracticeWoven account, we decide how data is used — we are the controller, and this policy applies.

For the practice websites our customers publish, the practice is the controller: visitor data submitted there (including contact-form messages) belongs to the practice, is governed by the practice's own privacy policy, and is processed by us only on the practice's behalf and instructions. If you contacted a practice through a PracticeWoven-built site and want your information corrected or deleted, contact that practice; we support them in honoring such requests.

2. Information we collect

Account information: name, email address, sign-in identifiers, and plan/billing details. Site content: the text, images, and settings you add to your site, including practice details such as license information you choose to display. Form submissions: messages that visitors send through forms on customer sites, which we store on the practice's behalf, encrypted, and exclude from analytics. Usage data: standard logs (IP address, pages requested, browser type) for security and reliability, and product analytics about how the editor and dashboard are used.

3. How we use information

We use personal information to provide and improve the Service, set up and host your site, respond to support requests, process payments, send service notices, and protect the platform from abuse. If you use AI drafting features, the practice details and prompts you provide are sent to our AI provider to generate your draft; we do not permit our AI providers to use this content to train their models, and you should not include client information in prompts.

We do not sell personal information, do not share it for targeted advertising, and do not use the contents of form submissions on customer sites for any purpose of our own. Consumer health data that visitors share with a practice through its site is used solely to deliver it to that practice.

4. Who we share information with

Service providers that help us run the platform, under contracts limiting their use of data to providing their service to us: cloud hosting and content delivery (Vercel, Cloudflare), database and authentication (Supabase), AI text generation (Google), payment processing, and email delivery. We also disclose information when the law requires it, to protect the rights and safety of users and the public, or as part of a business transaction such as a merger — with notice to you in that case.

5. Cookies, analytics, and signals

We use cookies needed to keep you signed in and basic, privacy-respecting analytics on our own site. We do not use third-party advertising trackers, and we do not place advertising trackers on customer sites. Because we do not track visitors across third-party websites, our site does not respond differently to “Do Not Track” signals; we honor Global Privacy Control signals where state law gives them effect.

6. Retention, export, and deletion

We keep your account data while your account is active. You can export your site content and form submissions from the dashboard at any time. If you close your account, your data remains exportable for 60 days and is then deleted from production systems on our normal schedule, except where law requires retention. You may also ask us to delete specific data at any time.

7. Security

Data is encrypted in transit and at rest. Access to customer data is limited to personnel who need it to operate the Service, and form-submission contents are excluded from logs and analytics. No method of transmission or storage is perfectly secure; if a breach affects your data, we will notify you as the law requires.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to appeal a decision we make about a request. Email privacy@practicewoven.com and we will respond within the time your state's law requires. We will not discriminate against you for exercising these rights. Consistent with the California Online Privacy Protection Act, this policy lists the categories of information we collect and the categories of third parties with whom it may be shared.

9. Children

PracticeWoven and the sites it hosts are intended for adults. We do not knowingly collect personal information from children under 13; if you believe a child has provided it, contact us and we will delete it.

10. Changes and contact

If we materially change this policy we will notify account holders by email and post the change here before it takes effect. Questions or requests: privacy@practicewoven.com.