Privacy Policy
Version: 2.0
| Effective Date: 2025-04-15
| Last Updated: 2025-04-15
At SmileStarz, your privacy is our priority. We are committed to protecting your personal information and being
transparent about how we collect, use, share, and safeguard it. This Privacy Policy explains how SmileStarz
("we," "our," or "us") handles your information when you use our website, mobile apps, and membership services
(collectively, the "Services").
Privacy Policy Summary
What We Collect
- Contact information
- Account details
- Basic dental preferences
- Device information
- App usage data
How We Use It
- Provide membership services
- Connect you with providers
- Improve app experience
- Service and billing updates
- Legal compliance
Your Rights
- Access your data
- Request corrections
- Delete your account
- Opt out of marketing
- Control app permissions
This summary provides a quick overview of our privacy practices. Please read the full policy below for detailed information.
1. Information We Collect
a. Information You Provide
- Account Information: Name, email address, phone number, date of birth, mailing address, and account credentials.
- Profile Information: Profile pictures, family member details (for family plans), and preferences.
- Payment Information: Credit card details, billing address, and transaction history.
- Health-related Preferences: Basic preferences related to dental care needs (non-HIPAA protected information unless explicitly disclosed).
- Communications: Messages sent to our support team, feedback, and survey responses.
b. Information Automatically Collected
- Device Information: Device type, operating system, unique device identifiers, IP address, mobile network information, and browser type.
- Usage Data: Interactions with the app and website, features used, time spent, buttons clicked, and pages viewed.
- Location Information: Approximate location (if location services are enabled) to show nearby providers.
- Log Data: App errors, crashes, hardware settings, browser language, date/time of access, and referring website.
2. Data Categories
In accordance with Apple App Store and Google Play Store privacy requirements, we categorize data as follows:
a. Data Used to Track You
With your explicit consent, we may use some data for tracking purposes, including:
- Device identifiers (IDFA/GAID)
- Email address (hashed)
- IP address
Apple App Tracking Transparency (ATT) Compliance: Our iOS app requests permission before tracking your activity across other companies' apps and websites.
b. Data Linked to You
This information is associated with your identity:
- Identity: Name, email address, phone number
- Health: Dental preferences, appointment history
- Financial: Payment information, membership details
- Location: Approximate location (with permission)
- Usage Data: App interactions, feature usage
- Identifiers: User ID, device ID
c. Data Not Linked to You
This information is collected but not linked to your identity:
- Diagnostic information
- Anonymous usage statistics
- Crash reports
Data Type |
Collection Method |
Purpose |
Legal Basis |
Retention Period |
Shared With |
Name, Email, Phone |
User provided |
Account management |
Contract performance |
Account duration + 1 year |
Service providers |
Payment Info |
User provided |
Processing payments |
Contract performance |
As required by law |
Payment processors |
Dental Preferences |
User provided |
Service personalization |
Consent |
Account duration |
Dental providers |
Device ID |
Automatic |
Authentication, analytics |
Legitimate interest |
14 months |
Analytics partners |
Location |
Automatic (with permission) |
Provider matching |
Consent |
During session |
None |
Usage Data |
Automatic |
Service improvement |
Legitimate interest |
24 months |
Analytics partners |
3. How We Use Your Information
We use your information for the following purposes:
- Provide Services: Create and manage your SmileStarz membership, process payments, and enable access to participating providers.
- Improve Our Services: Analyze usage patterns, troubleshoot issues, and enhance app functionality and user experience.
- Communicate: Send service updates, billing alerts, appointment reminders, and respond to your inquiries.
- Marketing: With your consent, send promotional offers and information about related services (you can opt out anytime).
- Security: Protect our services, prevent fraud, and ensure compliance with our Terms of Service.
- Legal Compliance: Comply with applicable laws, regulations, and legal processes.
Data Minimization: We collect and process only the information necessary for these purposes.
We do not sell your personal information.
4. Basis for Processing Your Information
- To Provide Our Services: Contract performance and steps prior to entering a contract.
- Business Purposes: Legitimate interests (e.g., improving services and ensuring security).
- With Your Consent: For certain marketing or tracking.
- Legal Requirements: Compliance with applicable U.S. federal and state laws.
5. How We Share Information
We may share your information with:
- Service Providers (payments, hosting, analytics, support tools).
- Participating Providers (to confirm eligibility and facilitate appointments).
- Business Partners (with consent, for complementary services).
- Legal/Authorities when required by law or to protect rights/safety.
- Business Transfers relating to mergers/acquisitions.
Data Protection: Third parties must maintain confidentiality/security and only process for specified purposes.
No Third-Party Marketing: We don’t share personal info for others’ direct marketing without consent.
6. Third-Party Services and SDKs
Service/SDK |
Purpose |
Data Accessed |
Privacy Policy |
Google Maps SDK |
Location services, provider mapping |
Location data, search queries |
Link |
Firebase |
App performance, crash reporting |
Device info, crash data |
Link |
Freshworks SDK |
Customer support, ticket management |
Contact info, support requests, chat history |
Link |
Stripe |
Payment processing |
Payment info |
Link |
Heap Analytics |
User journey analytics |
Usage patterns, clicks, interaction data |
Link |
These third-party services may collect information for their own purposes. Review their privacy policies for more information.
7. Cookies & Tracking Technologies
We use cookies to store preferences, enable sign-in, personalize content, analyze usage, and protect security.
Types of Cookies We Use
- Essential – required for basic functionality.
- Functional – enhanced features/personalization.
- Analytics – understanding usage patterns.
- Marketing – only with consent.
Your Cookie Choices
- Our consent banner
- Browser/device settings
Do Not Track
We respond to DNT signals by disabling non-essential tracking.
8. App Permissions
Our app may request permissions (you can change these in device settings):
Permission | Purpose | Required? |
Camera | Scan cards or IDs | Optional |
Location | Find nearby providers | Optional |
Notifications | Reminders & updates | Optional |
Storage | Save membership/cards | Optional |
9. Data Security
- Encryption: TLS in transit; industry-standard at rest.
- Access Controls: Role-based access.
- Authentication: MFA for admin access.
- Testing: Regular assessments and scans.
- Training: Security awareness for staff.
- Vendor Management: Contracted protections.
No security measure is 100% secure; we strive to protect your data but cannot guarantee absolute security.
10. Data Retention
We retain personal information as long as necessary to provide services, comply with laws, resolve disputes, and enforce agreements.
Selected Retention Periods
- Account: Life of account + 1 year
- Payments: As required by law (e.g., 7 years)
- Usage Data: 24 months, then aggregated/anonymized
- Comms: Account duration + 1 year
- Marketing Prefs: Until opt-out + 30 days
11. Your Privacy Rights
All Users
- Access your data
- Request correction or deletion
- Unsubscribe from marketing
- Control app permissions
California Residents (CCPA/CPRA)
- Right to Know, Delete, Opt-Out of Sale/Sharing
- Right to Limit use of sensitive data
- Right to Non-Discrimination
How to Exercise Your Rights
We respond to verified requests within legally required timeframes (typically 30 days). Additional information may be required to verify identity.
12. Children's Privacy
Our services are not directed to children under 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we learn we’ve collected information from a child without parental consent, we will delete it promptly.
For family plans, we collect only minimal information for added dependents and require adult consent.
13. Data Processing Locations
SmileStarz is based in the United States. While designed for U.S. users, your information may be processed in the U.S. and other countries where our providers operate. We use appropriate safeguards and contractual protections for international transfers.
14. Data Breach Notification
- Investigate the incident and remediate
- Notify affected users without undue delay if required
- Provide information and protective steps
- Notify authorities as required
15. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by posting the updated policy, emailing your account address, and/or showing an in-app notice. The “Last Updated” date indicates the most recent revision.
Version History
- Version 2.0 (April 15, 2025): Comprehensive update to align with app store requirements and enhance transparency.
- Version 1.0 (January 21, 2025): Initial privacy policy.
17. Legal Disclaimer
SmileStarz is not a healthcare provider or insurer. It is a dental savings membership program designed to facilitate access to participating providers and manage membership benefits, eligibility, and visit redemptions. Clinical care is provided solely by licensed professionals.
SmileStarz is not dental insurance. We do not guarantee care outcomes or provider availability. All clinical care is the responsibility of the participating provider.
This Privacy Policy is not a contract for dental services or a guarantee of privacy rights beyond those provided by applicable laws.