Privacy Policy

Effective September 28, 2026 · Eden Platforms LLC, hello@edenplatforms.io

Privacy at a Glance

TopicSummary
Information we handleClinic account and site content; and, for Clinics, callback-request, shop-order, review, and gallery-consent information. Booking happens in the Clinic’s own system, not on Eden. Stripe handles card numbers.
WhyTo operate Clinic sites, forms, shops, account services, security, and Clinic-directed communications.
Who receives itThe service providers listed below, acting to provide the platform. We do not sell personal data or use patient, customer, or Clinic data to advertise Eden.
Health dataElevate is not designed for clinical records or PHI. Clinics should not upload PHI.
Your choicesClinic users can contact us about account information. Patients and customers should contact their Clinic first.

This is a short summary. The sections below, including the service-provider list, retention, and rights information, control if there is a difference.

1. Who This Covers

Eden Elevate is a platform where medical-aesthetics practices (“Clinics”) run branded clinic websites for their patients and shop customers. This policy covers two groups:

  • Clinic users, owners and team members who subscribe to and operate the platform. For your account data, Eden is the responsible party (controller).
  • Patients and shop customers, people who request a callback, leave a review, buy retail products, or otherwise interact with a Clinic’s site. These people are customers of their Clinic, not of Eden. We process their data on the Clinic’s behalf so the Clinic’s site can operate (Eden acts as a service provider / processor; the Clinic is the controller of its patient and customer relationships). People with questions about how their data is used should contact the Clinic first.

2. What We Collect

From Clinic users: name, email, phone (optional), password (stored as a secure hash by our authentication provider), profile photo (optional), clinic branding and content (logo, colors, treatment library, testimonials, product catalog, gallery), subscription and billing status, and Stripe Connect account status once linked. Payment card details are collected and stored by Stripe, never by Eden.

From patients and shop customers (on behalf of the Clinic): name, email, phone, and, where the Clinic has enabled the feature, home address (for shop orders that ship), order history, coupon codes used, refund history, and the name and email a person submits through the Clinic’s callback-request form. That form deliberately accepts no message, treatment interest, or other health-related content, and Eden forwards it to the Clinic by email without retaining a copy. Card details are handled by Stripe; Eden never stores card numbers.

Patient photographs. A Clinic may upload before-and-after or single treatment photographs to its site’s gallery. These are identifiable images of real people. The Clinic is responsible for holding written consent from each pictured patient before publishing. Eden stores an audit trail of consent confirmations (which admin confirmed, when, and where the consent record is held) so the Clinic and Eden can demonstrate the consent basis for publication. Withdrawing consent takes photographs off the live site immediately, and Eden hard-deletes photographs 12 months after a Clinic’s subscription ends (see Retention).

Automatically: authentication session cookies (required for login), and standard server logs (IP address, timestamps, requests) kept for security and reliability. Our public marketing sites use PostHog in cookieless mode: it records page views in aggregate and stores nothing in your browser, so no identifier persists between visits and there is no cross-site tracking. Inside the signed-in Clinic dashboard, PostHog also records which product features are used, using a first-party cookie limited to the dashboard host; it never runs on Clinic sites.

3. How We Use Data

To operate the platform: authenticate Clinic users, host the Clinic’s public site, accept and forward callback requests, run the retail shop end-to-end (products, cart, coupons, Stripe checkout, orders, refunds, shipping notifications), display the gallery with the consent controls the Clinic has enabled, process subscriptions, prevent abuse, and provide support.

Emails patients and customers receive from the platform are sent on behalf of the Clinic (for example: order confirmations, shipping notifications, refund confirmations, and any marketing sends the Clinic composes). A callback request is delivered to the Clinic only — the platform sends no acknowledgement to the person who submitted it. The Clinic controls these; Eden provides the delivery machinery.

Booking. Every “Book” button on a Clinic’s site opens the Clinic’s own booking system (for example Jane, Fresha, Zenoti, or Boulevard) in that system’s own pages. Eden does not take, hold, or transmit appointment details: no date, time, treatment, or patient information for a booking reaches Eden, and Eden does not receive confirmation that an appointment was completed. The only thing Eden records is an anonymous count of clicks on Book buttons, together with which page of the site (for example a treatment page) the click came from, so the Clinic can see whether the site is generating booking interest. Anything entered after the click is governed by that booking provider’s own terms and privacy policy.

Site analytics and Smart Links. Eden provides each Clinic with cookie-free analytics for its site: page visits, an anonymous daily estimate of visitors (derived on our servers from the request and never stored in a form that identifies a person), the referring site, booking-button clicks, callback requests, and shop orders. A Clinic may also create “Smart Links” — trackable links for social media, e-mail, print or QR codes. A visitor who arrives through one carries a campaign identifier in their browser for the length of that visit only; it identifies the link, not the visitor, and it lets the Clinic see which promotions led to visits, booking clicks and shop purchases. Eden uses this information to report site performance to the Clinic and to suggest improvements. No advertising pixels, cross-site tracking or persistent visitor profiles are used. Cookieless analytics does not by itself remove every consent obligation in every jurisdiction; each Clinic remains responsible for its own notices and can turn site analytics off in its settings.

We do not sell personal data. We do not use patient, customer, or clinic data to advertise Eden to anyone.

4. Health Information and Regulated Data

Eden Elevate is not a HIPAA-covered medical records system, and it is not designed to store clinical notes, treatment records, diagnoses, or protected health information (“PHI” as defined under HIPAA or equivalent laws). Clinics should not upload PHI to the platform. Retail purchases, callback requests (name and email only), reviews, and marketing photographs are the intended data types.

The Clinic is responsible for meeting any regulatory obligations that apply to it, including state and federal medical, cosmetic, and consumer-protection rules in the jurisdictions where it operates and where its patients live.

5. Service Providers (Subprocessors)

We use these providers to run the platform:

ProviderPurpose
SupabaseDatabase, authentication, file storage (including gallery photographs)
StripeSubscription billing and retail-shop payment processing (Stripe Connect)
Amazon Web ServicesApplication hosting (United States, us-east-2)
ResendTransactional and platform email delivery
SentryError monitoring (application errors only, not customer data)
PostHogCookieless page-view analytics on our marketing sites; product analytics inside the Clinic dashboard
GoDaddy / DNS providersCustom domain routing (domain names only)
FedExShipping rates, labels, pickups and tracking, only when a Clinic connects its own FedEx account (recipient name, phone, delivery address, parcel details)
UPSShipping rates, labels, pickups and tracking, only when a Clinic connects its own UPS account (recipient name, phone, delivery address, parcel details)

Data is stored and processed in the United States. If you access the platform from outside the U.S., your data is transferred to the U.S.

6. Retention

  • Active accounts: retained while the account operates.
  • When a Clinic’s subscription ends: the public site enters a 30-day grace period during which the Clinic can re-subscribe and resume operation with no data loss. After the grace period the site is unpublished; the Clinic may export its data (orders, customer records, treatment library, testimonials, gallery consent audit) for up to 30 more days.
  • Patient photographs specifically: to limit long-term exposure of identifiable patient images, photographs are archived at the end of the grace period and permanently deleted 12 months after that point, whether or not the Clinic resubscribes. A Clinic that returns after archival will need to re-upload and re-confirm consent for any images it wants to publish again.
  • Shop orders and receipts: retained as required for tax and consumer-protection reasons for the periods those laws require, then deleted or anonymised in the ordinary course.
  • Security logs: retained for a limited period for abuse prevention.
  • Deletion requests: honored as described in Section 7, except where retention is legally required (e.g., billing and tax records).

7. Your Rights

Clinic users may access, correct, or delete their account information by contacting us or using in-product settings. Patients and shop customers should direct requests to the Clinic (the controller of their data); we support Clinics in fulfilling those requests, and where the law grants a patient or customer direct rights against us, we honor them.

Depending on where you live (for example, California, Colorado, Virginia, or the UK/EU) you may have additional rights: access, deletion, correction, portability, opt-out of certain processing, and the right not to be discriminated against for exercising them. To exercise any right: hello@edenplatforms.io.

8. Security

Data is encrypted in transit (TLS) and at rest by our infrastructure providers. Access to production data is restricted. Two-factor authentication is available to all dashboard users. Row-level security policies deny access to Clinic data by default; every read and write goes through explicit authorisation checks. No system is perfectly secure; we will notify affected users of a breach as required by law.

9. Cookies

On our marketing sites we set no analytics cookies: page-view analytics there is cookieless and stores nothing in your browser. In the signed-in Clinic dashboard we use cookies for authentication and session security, plus one first-party analytics cookie (PostHog) limited to the dashboard host; you can opt out by enabling Do Not Track in your browser, which we honor. We do not use third-party advertising cookies. Clinic sites carry no analytics cookies: Eden’s site analytics (section 3) set nothing in the browser beyond a campaign identifier kept in session storage for the length of a visit that began from a Smart Link. A Clinic may add its own third-party scripts, which is not our default and is the Clinic’s responsibility to disclose.

10. Age

The platform and Clinic sites are intended for adults (18+). Medical-aesthetics services are adult services; we do not knowingly collect data from children. If we learn we have, we will delete it. The Clinic is responsible for handling any additional consent or verification its own jurisdiction may require for minors.

11. Changes

We will post updates here and, for material changes, notify Clinic account emails at least 30 days in advance.

12. Contact

Eden Platforms LLC, hello@edenplatforms.io