Last Updated: March 2026

Privacy Policy

1. Introduction

Medispot Inc. ("Medispot," "we," "us," or "our") operates the trymedispot.com platform. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Platform. By using the Platform, you agree to the practices described in this Policy. We comply with applicable US privacy laws including the California Consumer Privacy Act (CCPA) and applicable federal laws.

2. Information We Collect

We collect the following categories of information:

Account Information
name, email address, phone number, and password when you register.
Profile Information
for Providers, business name, address, professional license numbers, insurance documentation, and Stripe Connect account information.
Booking Information
treatments booked, appointment dates and times, booking status, and payment transaction records.
Payment Information
we use Stripe to process payments. Medispot does not store full credit card numbers. Stripe's privacy policy governs the handling of your payment data.
Usage Data
IP address, browser type, pages visited, and interaction data collected automatically through cookies and similar technologies.
Communications
messages you send to Medispot support.

3. How We Use Your Information

We use your information to:

  • operate and provide the Platform;
  • process bookings and payments;
  • communicate with you about bookings, account activity, and platform updates;
  • administer the rewards and referral program;
  • verify Provider credentials;
  • detect and prevent fraud and abuse;
  • comply with legal obligations; and
  • improve the Platform.

We do not sell your personal information to third parties.

4. Information Sharing

We share your information only in the following circumstances:

With Providers
when you complete a booking, we share your name and contact information with the relevant Provider so they can fulfill your appointment. We do not share your identity with Providers prior to booking completion.
With Service Providers
we share data with trusted third-party vendors including Stripe (payment processing), Supabase (database infrastructure), Resend (transactional email), and Vercel (hosting). These vendors are contractually obligated to protect your data.
For Legal Compliance
we may disclose information when required by law, court order, or to protect the rights and safety of Medispot or others.
Business Transfers
in the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction with appropriate notice to you.

5. Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. We retain booking and transaction records for a minimum of 7 years for legal and financial compliance purposes. You may request deletion of your account and associated data by contacting us at hello@trymedispot.com, subject to our legal retention obligations.

6. Cookies and Tracking

We use essential cookies to operate the Platform (session management, authentication). We do not use third-party advertising cookies or sell data to advertisers. You may disable cookies in your browser settings, though some Platform features may not function correctly without them.

7. Security

We implement industry-standard security measures including encrypted data transmission (HTTPS/TLS), secure authentication, and row-level security on our database. However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security of your data.

8. Your Privacy Rights

Regardless of where you live in the United States, Medispot extends the following privacy rights to all users:

  • The right to know what personal information we collect, how it is used, and with whom it is shared.
  • The right to request a copy of the personal information we hold about you.
  • The right to request deletion of your personal information, subject to our legal retention obligations.
  • The right to correct inaccurate personal information we hold about you.
  • The right to opt out of the sale of your personal information. Medispot does not sell personal information to third parties.
  • The right not to be discriminated against for exercising any of these rights.

Residents of states with specific consumer privacy laws — including but not limited to California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other states with enacted privacy legislation — are entitled to additional rights under those laws. Medispot will honor requests consistent with applicable state law regardless of your state of residence.

To exercise any of these rights, contact us at hello@trymedispot.com. We will respond to verified requests within 45 days as required by applicable law.

9. Children's Privacy

The Platform is not intended for users under the age of 18. We do not knowingly collect personal information from minors. If we become aware that a minor has provided us with personal information, we will delete it promptly.

10. Third-Party Links

The Platform may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the Platform. Your continued use of the Platform after changes take effect constitutes acceptance of the revised Policy.

12. Contact

For privacy-related questions or to exercise your rights, contact us at:

Medispot Inc.
hello@trymedispot.com