No-Show Recovery

Draft, to be reviewed by the owner before launch. Plain-English summary of how the product works today; not legal advice.

Privacy policy

No-Show Recovery helps dental practices text their own waitlist when an appointment opens. This page explains what we collect, who helps us run the service, how long we keep data and how to have it deleted.

What we collect, and what we deliberately don't

About your staff: name, email address, a hashed password, and sign-in activity needed to keep the account secure.

About your practice: name, address and phone, timezone, the business details and business contact you enter for carrier verification, and your billing status.

About waitlist patients (entered by your practice): a first name or initials, a mobile number, a waitlist priority, whether and how they agreed to receive texts (source, date, and your practice's confirmation), and whether they opted out.

About openings: the appointment time and length, and optionally a short generic label and a provider or chair name such as "Chair 3".

About messages: the texts we send for your practice (they contain only the patient's first name, your practice name and the appointment time), their delivery status, and the patient's replies to the keywords we act on (YES, NO, STOP, START, HELP). Any other reply is not stored.

We do not collect, and the service blocks: last names, dates of birth, email addresses of patients, procedures or treatment types, reasons for a visit, diagnoses, notes, insurance or any other medical or clinical information. Our forms, CSV import and integration endpoint accept only the fields above and reject clinical-looking text.

We are not a HIPAA business associate

No-Show Recovery is built to stay outside HIPAA: it only handles the minimum needed to refill an appointment slot and never receives medical or treatment information. We are therefore not a business associate of your practice and do not sign business associate agreements. Your practice agrees not to enter protected health information (see the Terms), and confirms this when setting up the account.

Who processes data for us

  • Twilio: sends and receives text messages and provides your toll-free number (United States).
  • Resend: sends our emails (confirmations, password resets, invitations).
  • Dodo Payments: our merchant of record. It takes your payment and card details; we never see or store card numbers.
  • Our hosting provider: runs the application and database on a server we operate.
  • Sentry: error reports, only if enabled. Reports are scrubbed of phone numbers and emails.
  • Mixpanel (EU data residency): product analytics, described in the next section.

Each processes data only to provide its service to us. We do not sell data or use it for advertising.

Product analytics

We use Mixpanel, hosted in the European Union, to understand how the product is used and to fix what is confusing. It sets a cookie on kentehq.com so a visit to our website and to this app count as one visitor.

  • What we send: the pages visited (web address without any query string except utm_ and ref campaign tags), the sign-up, sign-in and sign-out actions, and counts and outcomes such as how many waitlist patients were added, how many texts were sent, whether an opening was refilled, and plan changes.
  • Who it is attached to: an internal account number for your practice. Profile fields are limited to plan, sign-up date, country and the app name. Never your name, email address or phone number.
  • What we never send: patient names, phone numbers, appointment times, or message text. We don't record sessions, keystrokes or form input.

We do not sell this data or use it for advertising. If your browser sends Do Not Track or Global Privacy Control, analytics stays off entirely.

How we protect it

Patient phone numbers are encrypted in our database. Provider tokens and your integration secret are encrypted at rest. Connections use HTTPS. Logs keep only the last four digits of a phone number. Each practice can see only its own data.

Your role

Your practice decides who is on its waitlist and is responsible for having each patient's consent to receive texts; you confirm that consent each time you add patients. You are responsible for not entering medical or treatment information.

How long we keep it

  • Waitlist entries (name, number, consent and opt-out status) and their offers: deleted 90 days after the entry was added or its consent was last re-confirmed by an import. Add the patient again to keep them on the list.
  • Message logs and import records: deleted 90 days after they were created.
  • Openings: deleted 90 days after the appointment time.
  • When an owner deletes the account: texting stops and staff access ends immediately, the subscription is cancelled and the Twilio subaccount and number are closed. The practice's remaining data is permanently deleted 30 days later.

Because opt-outs are deleted with the entry, the carrier's own opt-out list for your number is what continues to block texts to someone who replied STOP. Records our payment provider must keep for tax and legal reasons are held by them under their own policy. Backups are overwritten on their normal rotation.

Deleting your data and your rights

Owners can delete the account from Account settings. Staff can delete their own account. A patient can reply STOP at any time, and can ask the practice or us to remove their record; email support@kentehq.com and we will respond within 30 days.

Contact

No-Show Recovery is operated by Accidental Genius LTD (trading as Kente HQ), a company registered in Ghana.

Email support@kentehq.com.

Back to the home page
Privacy policy · No-Show Recovery