Privacy Policy
Last updated: June 29, 2026
This policy explains what data Gracero collects, why we collect it, how we use it, and what control you have over it. It applies to clinic owners, clinic staff, and the end clients whose information is stored on the platform.
Short version: we collect what we need to run the platform. We do not sell your data. We do not use it to train AI models. You can export or delete it anytime.
1. Who this policy covers
Gracero interacts with three groups of people. Each has different data touchpoints:
- Clinic owners and administrators — the people who create a Gracero account and manage the subscription. We collect account, billing, and usage data from you directly.
- Clinic staff — providers, front desk coordinators, and other team members added to a Gracero account by the owner. We collect login credentials and activity logs.
- End clients — the people who book appointments, receive treatments, and interact with a clinic that uses Gracero. Clinic owners enter and manage end-client data. Gracero processes it on their behalf.
For end-client data, the clinic is the data controller — they decide what to collect and how to use it. Gracero is the data processor — we store and process it according to the clinic's instructions and this policy.
2. What we collect
Information you provide directly
| Data type | Examples | Why we need it |
|---|---|---|
| Account information | Name, email, phone, clinic name, business address | Create and manage your account |
| Billing information | Payment method (processed by our PCI-compliant payment processor — we do not store raw card numbers) | Process subscription payments |
| Client records | Client names, contact info, appointment history, treatment notes, consent forms, before-and-after photos | Provide the clinic management features you signed up for |
| Communications | Support emails, chat messages, feature requests | Respond to your requests and improve the product |
Information collected automatically
| Data type | Examples | Why we need it |
|---|---|---|
| Usage data | Pages visited, features used, clicks, session duration | Understand how clinics use the platform so we can improve it |
| Device and browser data | IP address, browser type, operating system, screen resolution | Security monitoring, bug diagnosis, and platform optimization |
| Log data | Login timestamps, API calls, error logs | Security auditing and troubleshooting |
3. How we use your data
We use your data for these specific purposes and nothing else:
- Operate the platform — store your records, process bookings, send appointment reminders, handle payments, and run the features you configure.
- Communicate with you — send transactional emails (booking confirmations, payment receipts, password resets), product updates, and respond to support requests.
- Improve the product — analyze aggregate usage patterns to identify bugs, prioritize features, and improve performance. We use anonymized, aggregate data for this — not individual client records.
- Protect the platform — detect fraud, prevent abuse, and maintain security through login monitoring and anomaly detection.
- Meet legal obligations — comply with tax reporting, respond to valid legal process, and maintain records as required by law.
4. What we do not do with your data
To be direct:
- We do not sell your data to anyone. Not to advertisers, data brokers, or other companies.
- We do not use your client records to train machine learning or AI models.
- We do not share individual client data with other clinics on the platform.
- We do not read your client records unless you specifically ask us to (for support or data migration assistance).
- We do not display ads on the platform.
5. Who we share data with
We share data only with the following categories of service providers, and only to the extent necessary for them to perform their function:
- Cloud infrastructure — our hosting provider stores your data in encrypted form. Servers are located in the United States.
- Payment processors — PCI-compliant processors handle card transactions. They receive the minimum information required to process a payment.
- Communication services — SMS and email providers deliver appointment reminders, marketing campaigns, and transactional messages on your behalf.
- Analytics — we use analytics tools to understand aggregate platform usage. These tools receive anonymized usage data, not client records.
We do not share data with service providers for their own marketing purposes. All service providers are bound by data processing agreements.
We will disclose data if required by a valid subpoena, court order, or government investigation. If legally permitted, we will notify you before disclosing your data in response to legal process.
6. Data security
- Encryption at rest — all stored data is encrypted using AES-256.
- Encryption in transit — all connections use TLS 1.2 or higher.
- Access controls — internal access to customer data is restricted by role, logged, and reviewed. Support staff can only access your data when you request assistance.
- Backups — automated encrypted backups run daily. Backups are retained for 90 days.
- Monitoring — we monitor for unauthorized access attempts, anomalous activity, and infrastructure issues around the clock.
- Incident response — if a data breach occurs, we will notify affected customers within 72 hours and provide details on what data was affected and what steps we are taking.
No system is perfectly secure. We implement industry-standard safeguards, but we cannot guarantee absolute security. For details on our security practices, see our HIPAA & Security page.
7. HIPAA and health-related data
Gracero is HIPAA-conscious. The platform handles treatment notes, consent forms, and before-and-after photos — information that may qualify as protected health information (PHI) depending on how your clinic operates.
We follow HIPAA-aligned practices for data storage, access controls, and encryption. If your clinic requires a Business Associate Agreement (BAA), contact security@gracero.ai. BAAs are available on Professional and Enterprise plans.
Gracero is a business-management platform, not a covered entity under HIPAA. Clinics are responsible for determining their own HIPAA obligations and configuring the platform accordingly.
8. Cookies and tracking
Cookies we use
- Essential cookies — authentication tokens, session management, and security. These are required for the platform to function. You cannot opt out.
- Analytics cookies — aggregate usage tracking to understand how clinics use the platform. You can opt out through your browser settings or our cookie preferences.
What we do not use
- No advertising cookies or ad retargeting pixels.
- No cross-site tracking.
- No fingerprinting.
9. Your rights
Regardless of where you are located, you have these rights over your data:
- Access — request a copy of the data we hold about you.
- Correction — request correction of inaccurate data.
- Deletion — request deletion of your data. We will delete it from active systems within 30 days. Encrypted backups are purged within 90 days.
- Export — download your data in a standard format through the platform's export tools at any time.
- Opt out of marketing — unsubscribe from marketing emails using the link at the bottom of any marketing email. Transactional emails (payment receipts, security alerts) cannot be opted out of.
For California residents (CCPA)
California residents have additional rights under the California Consumer Privacy Act: the right to know what personal information we collect and how we use it, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell personal information.
For EU/UK residents (GDPR)
If you are located in the European Union or United Kingdom, our legal basis for processing your data is: contract performance (operating the platform you subscribed to), legitimate interest (security monitoring, product improvement), and consent (marketing communications). You have the right to withdraw consent at any time without affecting the lawfulness of prior processing. You may also lodge a complaint with your local data protection authority.
For end clients
If you are a client of a clinic that uses Gracero and want to exercise your data rights, contact your clinic directly. The clinic controls your data. Gracero processes it on their behalf. If the clinic is unresponsive, contact us at privacy@gracero.ai and we will assist.
10. Data retention
- Active accounts — we retain your data for as long as your account is active.
- After cancellation — you have 30 days to export your data. After 30 days, data is deleted from active systems. Encrypted backups are purged within 90 days.
- Legal requirements — some data (billing records, tax documents) may be retained longer to comply with legal obligations, typically 7 years for financial records.
- Anonymized data — aggregate, anonymized usage statistics that cannot identify any individual may be retained indefinitely for product improvement.
11. Children's privacy
Gracero is a business platform for clinic operators. It is not directed at individuals under 18. We do not knowingly collect data from minors. Clinics that treat minor clients are responsible for obtaining parental consent and managing minor client data in compliance with applicable law.
12. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email to account owners at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision. Previous versions are available upon request.
13. Contact
Privacy questions or data requests: privacy@gracero.ai
Security concerns: security@gracero.ai
General inquiries: hello@gracero.ai
Gracero Inc. · Registered in Delaware, USA