Privacy Policy
Last updated: July 21, 2026
This Privacy Policy explains how OptoMize handles information when you use our website and practice-management software. We keep it in plain language on purpose. If anything here is unclear, please ask us.
1. Who we are and our role
OptoMize provides practice-management software for independent optical shops (“the Service”). This policy explains what we collect and how we handle it.
For the patient records your practice enters, your practice is the data controller and OptoMize is a service provider (data processor) acting on your instructions. We do not decide how you use patient data; we store and process it so you can run your shop.
2. Information we collect
- Account & staff information — name, email, and role of the staff members you invite, handled through our authentication provider.
- Practice information — shop name, address, tax settings, branding, and configuration you enter.
- Patient records you enter — patient contact details, prescriptions, insurance details, purchase history, and notes. Some of this is protected health information (PHI). You choose what to enter.
- Payment records — the amount, method, reference number, and date of payments you record. OptoMize does not process card payments and does not store full card numbers.
- Usage & device data — basic, privacy-friendly analytics about how the marketing site and app are used (see §9).
3. How we use information
We use information to:
- provide and operate the Service for your practice;
- power features you invoke — insurance-split math, recall campaigns, inventory analysis, and AI insights — using your practice’s own data;
- authenticate users and enforce role-based access;
- send transactional messages you initiate (invoices, reminders, recalls);
- maintain security, prevent abuse, and meet legal obligations.
We do not sell your data, and we do not use patient data for advertising.
4. How your data is stored and protected
- Encryption — data is encrypted in transit (HTTPS/TLS) and at rest by our database provider.
- Tenant isolation— every record is scoped to your practice and enforced at the database level with row-level security, so one practice cannot access another’s data.
- Access control — staff see only what their assigned role permits (owner, manager, optician, front desk).
- Least privilege — administrative database access is limited to server-side operations and is never exposed to the browser.
5. Sub-processors
We rely on a small set of vetted providers to run the Service:
- Clerk — user authentication and account management.
- Supabase — database and storage (PostgreSQL), encrypted at rest; a Business Associate Agreement (BAA) is available on their paid plans.
- Vercel — application hosting and privacy-friendly web analytics.
- Anthropic (Claude API)— powers AI features. Content sent to the API is processed to generate your result and, per Anthropic’s commercial terms, is not used to train their models by default.
- Resend — transactional email delivery (invoices, reminders, recalls) when you choose to send them.
- Twilio — SMS delivery when you choose to send messages by text.
Each sub-processor is bound by its own agreement to protect the data it handles on our behalf.
6. AI features and your data
AI features answer questions and generate suggestions using your practice’s own data only. All calls to the AI provider happen server-side; prompts and responses are not exposed to the browser. Your data is never shared across accounts, and API inputs are not used to train the underlying models by default. You can use the Service without AI features.
7. Data retention
We retain your practice’s data for as long as your account is active so the Service works as expected. You can export your data at any time. If you close your account, we delete or de-identify your practice’s data within a reasonable period, except where we are required to retain certain records (for example, tax or legal obligations).
8. Your rights and choices
Depending on your location, you may have rights to access, correct, export, or delete personal data. Because your practice controls the patient records it enters, requests from patients should generally go to the practice; we assist practices in fulfilling them. To exercise rights over your own account data, or for help with a patient request, contact us at admin@optomize.net.
9. Cookies and analytics
Our public pages — the marketing site and the sign-in and sign-up screens — use privacy-friendly, cookieless analytics to understand aggregate traffic: page views and which links are clicked. We do not use advertising trackers.
Analytics stops at sign-up. We do not run it inside the application, so no page views, patient records, or staff activity from your practice are collected — and it never runs on the patient invoice links we send out. Where we record an interaction (for example, that a “start free trial” button was clicked, or that the ROI calculator was used), we store only that the event happened, never the figures or contact details entered. Authentication itself uses the cookies necessary to keep you signed in.
10. Our HIPAA posture
OptoMize is HIPAA-aware but not HIPAA-certified. We implement safeguards aligned with HIPAA principles — encryption in transit and at rest, role-based access control, tenant isolation, and a BAA with our database provider — but we do not currently represent the Service as fully HIPAA-compliant or certified. Practices remain responsible for their own HIPAA obligations, including how they collect, use, and disclose PHI. If your practice requires a signed Business Associate Agreement, contact us before entering PHI.
11. Children’s privacy
The Service is intended for use by optical shop staff, not by children. Patient records entered by a practice may relate to minors; those records are the practice’s data, handled under the practice’s direction and its own obligations.
12. Changes to this policy
We may update this policy as the Service evolves. Material changes will be reflected here with a new “last updated” date. Continued use of the Service after an update means you accept the revised policy.
13. Contact us
Questions about privacy? Email admin@optomize.net.