Clearly Straight Event

Privacy Policy

This policy explains in plain English what information the event intake app may collect, why it is used, and how it may be shared to support the clear-aligner event workflow.

Last updated: May 31, 2026

Information this app may collect

The app may collect customer information such as name, email, mobile phone number, patient or dependent name and date of birth where applicable, relationship or guardian details, consent responses, dental and medical history answers, typed signature, clinical photos, scan files, payment status or order references, admin workflow metadata, and technical or security metadata.

Technical and security metadata may include information needed to operate the app, protect accounts, investigate errors, preserve audit context, and confirm that photos, scans, payment references, and manufacturer handoff steps were handled correctly.

How information is used

Information may be used for event intake, clear-aligner evaluation and planning, clinical photo and scan collection, manufacturing handoff, checkout and payment reconciliation, customer support, security, audit records, troubleshooting, and event operations.

How information may be shared

Information may be shared with Smile BOXX or event staff, dental, treatment, or manufacturing partners as needed to review and process a case, infrastructure vendors such as hosting, database, and private object-storage providers, and Shopify or the hosted checkout/payment provider. Information should be shared only as needed for the workflow and related operational, security, support, or legal obligations.

Payments

Payments are handled through hosted Shopify checkout or a related checkout provider. This app should not collect full payment card numbers, full card security codes, or full card details.

Security practices

The app is designed to use private object storage, signed links for controlled file access, limited admin access, audit and security controls, and PHI-aware handling patterns. The app is also designed so PHI is not intentionally placed in normal logs, public URLs, or object keys. No system can promise absolute security, and operational practices must continue to be reviewed as the workflow changes.

Retention

Information may be retained for reasonable operational, clinical review, payment reconciliation, manufacturer handoff, audit, support, security, and legal purposes. Retention periods may vary depending on the type of information, the status of the case, and applicable requirements.

Access, correction, and choices

Customers may contact the Smile BOXX team with questions about access, correction, or updates to information submitted through the app. Some records, such as consent, payment, audit, clinical, or manufacturer workflow records, may need to be preserved for operational or legal reasons.

Minors and dependents

When information is submitted for a minor or dependent, the app collects parent, guardian, or relationship details so the event workflow can confirm who is providing information and consent. Parents or guardians should provide accurate dependent information and contact the Smile BOXX team if corrections are needed.

Security incidents

If a security incident affects information handled by the app, appropriate action will be taken based on the facts and applicable law. This may include investigation, remediation, documentation, and notifications when legally required.

No sale or advertising sharing

Personal information and health-related information collected through this app should not be sold. The app is not intended to share personal or health information for third-party advertising purposes unless that practice is explicitly approved, documented, and legally reviewed before use.