← PracticeDocket
Privacy Policy
Last updated: August 31, 2026
PracticeDocket ("PracticeDocket", "we", "us", or "our") provides practice-management software for mental-health and wellness professionals ("Practitioners"). This Privacy Policy explains how we collect, use, share, and protect information when Practitioners and their clients use our websites and applications (the "Service"). By using the Service you agree to this Policy.
1. Our role and the data involved
PracticeDocket is a tool that Practitioners use to run their practices. Two kinds of relationships matter:
- PracticeDocket and the Practitioner (our customer). We are the data controller for the Practitioner's own account and business information.
- PracticeDocket and the Practitioner's clients. Information a Practitioner stores about their clients — including protected health information ("PHI") — is entered and controlled by the Practitioner. As to that information we act as a service provider / business associate, processing it only on the Practitioner's behalf and under our agreement with them.
If you are a client of a therapy practice, the practice — not PracticeDocket — decides what information is collected about you and how it is used. Please direct requests about your health records to your practice. See "Clients' information" below.
2. Information we collect
Practitioner and account information
- Name, email address, phone number, and sign-in credentials.
- Practice details you provide (practice name, address, license/NPI/tax identifiers, session types and fees, branding).
Client and practice data entered by Practitioners
- Client contact details, appointments, session notes, intake forms, tags, messages, and invoices.
- Health-related information (PHI) that a Practitioner chooses to record about their clients.
Payment information
- Billing and card details are collected and stored by our payment processor, Stripe. We do not store full card numbers on our systems.
Technical and usage information
- Log data such as IP address, device/browser type, timestamps, and actions taken in the Service (used for security and to operate the product).
- Audit records of who accessed or changed a record, which we retain to meet our security and compliance obligations.
3. How we use information
- To provide, maintain, secure, and improve the Service.
- To authenticate users and protect against fraud and unauthorized access.
- To process payments and send transactional messages (e.g., invitations, appointment confirmations, invoices, password resets).
- To provide customer support and respond to requests.
- To comply with legal obligations and enforce our terms.
We do not sell personal information, and we do not use client PHI for advertising.
4. How we share information
We share information only as needed to run the Service:
- Subprocessors / service providers that host and power the Service, including Amazon Web Services (hosting, storage, email delivery, and Amazon Chime for telehealth video), Stripe (payments), and Google (optional sign-in and, if enabled, calendar sync). These providers process data on our behalf under contract.
- At a Practitioner's direction — for example, sending an email to a client, or syncing PHI-free appointment blocks to a Practitioner's calendar.
- Legal and safety — where required by law, subpoena, or to protect rights, safety, and the integrity of the Service.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
5. Google user data
Connecting a Google Calendar is optional. When a Practitioner connects one, this
is exactly what we do with it, and nothing else.
- What we are allowed to do. We request four narrow permissions rather
than one broad one: free/busy times; the Practitioner's list of calendars
and their names; read-only access to events; and the ability to manage events on
calendars the Practitioner owns. We deliberately do not request access to calendars
that other people have shared with them.
- What we read. Busy times on the connected calendars, and — only while a
Practitioner is looking at their own Calendar page in PracticeDocket — the events
on them, including their titles.
- What we store. Start and end times only, as blocked ranges, so that
clients cannot book over a Practitioner's existing commitments.
We never store event titles, descriptions, locations, attendees, or any other
event content. Titles are passed through to the Practitioner's own screen and
kept nowhere — not in our database, not in our backups, and not in our audit logs.
- What we write. If the Practitioner turns it on, their PracticeDocket
sessions appear on their calendar as events showing client initials and location
only — never names, notes, or any clinical content. Events may be colour-coded by
service type, which the Practitioner chooses.
- What we never touch. We only ever create, change, or delete events that
PracticeDocket itself created. Every event we write carries an identifier we
generate, and our software refuses to send an update or a deletion for any other
identifier — a Practitioner's own appointments and personal events cannot be
modified or removed through this Service.
- Who else sees it. Nobody. Google Calendar data is never sold, never used
for advertising, never used to train any model, and never shared with third parties
or with human readers, except where a Practitioner directs it, or where the law
requires it, or as strictly necessary for security and to comply with applicable law.
- Turning it off. Disconnecting Google Calendar in Settings removes our
access, stops the sync, and deletes the imported busy blocks. Session events already
written to the Practitioner's calendar stay there, theirs to keep or delete. Access can also be
revoked at any time from your Google
Account.
PracticeDocket's use and transfer of information received from Google APIs to any
other app adheres to the
Google API
Services User Data Policy, including the Limited Use requirements.
6. Security
- Data is encrypted in transit (TLS) and at rest.
- Each practice's data is logically isolated (multi-tenant separation), and access is scoped so a Practitioner can reach only their own practice's data.
- Access to records is authenticated and audit-logged.
No method of transmission or storage is perfectly secure, but we work to protect your information using industry-standard safeguards.
7. Data retention
We retain Practitioner and client data for as long as the account is active and as needed to provide the Service, and thereafter as required to meet legal, accounting, or security obligations. Practitioners may request export or deletion of their practice's data as described in our Terms of Service; some records (such as audit logs and transaction records) may be retained where the law requires.
8. Clients' information
If you are a client, the therapy practice that invited you controls your information. To access, correct, or delete your records, or to ask how your information is used, contact your practice directly. We will assist the practice in fulfilling such requests as their service provider.
9. Your choices
- You may update your account information from within the Service.
- You may opt out of non-essential communications; we will still send transactional messages needed to operate the Service.
- Depending on where you live, you may have rights to access, correct, delete, or port your personal information. Contact us to exercise them.
10. Cookies
We use only the cookies and local storage necessary to keep you signed in and to operate the Service. We do not use third-party advertising cookies.
11. Children
The Service is intended for use by Practitioners. A Practitioner may record information about a minor client only with the appropriate consent under applicable law. We do not knowingly collect information directly from children.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be posted here with a new "Last updated" date, and where appropriate we will notify Practitioners.
13. Contact us
Questions about this Policy or your information: hello@practicedocket.com.