Privacy
Privacy, in plain English
Last updated September 2026
Chairside stores very little, because the thing most website companies store, patient information, is the thing this product is built to avoid.
The short version
- No patient information is stored in any Chairside system, ever
- What we do store is an order record: a name, an email, a phone number, a note about the practice, and the payment reference
- We keep order records for 24 months after your last order, and we delete them sooner if you ask
- Cookies and local storage are used for the sign-in session only, plus the Supabase keys an operator may paste at /setup
- No advertising cookies, no analytics trackers, no data sold to anyone
What Chairside collects
When the practice places an order, we keep an order record:
- The practice name, contact name, work email and phone number you typed into the order form
- Your city and state, and the public listing link you gave us
- Whatever you wrote in the notes box
- The tier ordered, the amount, the currency, the order reference, and the timestamps
- A payment reference from Stripe, which is not a card number
If you sign in to read a preview, we hold the email address you signed in with, any name you give us, and the login itself. Nothing else is required to use the preview.
The practice website we build may use information from the practice's public Google listing or other public listings: name, address, phone, hours, services and public reviews. That information was already public, and it is about the practice, not about a patient.
What Chairside never collects
- Patient names, phone numbers, email addresses, appointment details, or anything about someone's health
- Card numbers, card security codes, or bank details. Payments go through Stripe and the card data goes to Stripe, not to us
- Passwords, because there are none: signing in is by emailed link or through Google
- Your browsing history, your location, your contacts, or anything else a tracker would take
Requests made on a site we built for the practice are emailed straight to the practice. They are never stored. There is no Chairside database for a request to sit in, which means there is nothing on our side to lose or breach. Do not send us patient information in the notes box or by email, because we have no lawful reason to hold it and no reason to want it.
Cookies and local storage
We use browser storage for exactly three things:
- The sign-in session, so you stay signed in while you read your preview and leave comments
- The Supabase project URL and public anon key, if an operator pastes them at /setup on a deployed copy
- Nothing else
There are no advertising cookies, no analytics cookies, and no third-party tags. Clearing your browser storage signs you out and changes nothing else. One honest note: the pages load two web fonts from Google Fonts, which means Google receives the request for the font file, including your IP address. That is the only third-party request the marketing site makes.
How long we keep it
- Order records: 24 months after your last order, then deleted
- Order records, sooner: ask and we delete them, as long as we are not required to keep a payment record for tax purposes
- Payment records: kept by Stripe for as long as tax and accounting rules require. We can tell you what that means for your order if you ask
- Preview sites: deleted when a preview is declined or has expired, and when a practice cancels hosting without a copy being taken
- Site files: while you are hosted with us, and for 30 days after hosting stops, so you have time to take them
- Sign-in session: until you sign out and the session expires
Who can see it
One person at Chairside reads order records, and that person builds the site. We do not sell data and we do not share it with anyone for their own marketing. We use a small number of service providers to run the product:
- Supabase hosts the database and handles sign-in
- Cloudflare serves the sites
- Stripe takes the payment
- Resend sends the order emails, and Supabase sends the sign-in emails
Those providers process data in the United States on our instructions. We will also hand information over if a law or a court requires it, and we will tell you if we are allowed to.
Your choices
- Ask for a copy of what we hold about the practice: write to richard@grea.site
- Ask us to correct something that is wrong
- Ask us to delete the order record, and we will unless a payment record has to stay for tax
- Ask us to stop emailing you. The only emails we send are about your own order, so this usually means cancelling the order or the plan, but it is your call
Children, and who this is for
Chairside sells to dental practices. It is not for children, it is not designed for them, and we do not knowingly hold information about anyone under 18.
Changes to this page
If this page changes, the version at this address is the current one and the date at the top tells you when it changed. If a change affects what we do with an existing order record, we email the practices affected before it takes effect.
Contact
Privacy questions, deletion requests, or anything on this page go to richard@grea.site. A person reads it and answers. Prices on this page, gone over in full on the pricing page: $25 for a preview, then $250, $400, or $500 plus $25 a month. Last updated September 2026.