Vastrid
Sign inTerms of ServiceSupport

Privacy Policy

Effective and last updated: September 20, 2026

This Privacy Policy explains how Vastrid collects, uses, discloses, and protects information when you use our websites, applications, and related services (the “Service”). Vastrid is a healthcare content operating system for clinics. This policy applies to business users, clinic account data, and visitors to Vastrid-controlled pages.

1. Information we collect

  • Account and team information: name, email address, authentication records, account role, clinic membership, and support communications.
  • Clinic and content information: clinic name, website, location, providers, service and audience settings, content strategy, calls to action, imported or generated artifacts, edits, approvals, publishing status, and import provenance.
  • Integration information: identifiers, configuration, authorization status, encrypted access credentials or tokens, and data returned by services you connect, including Google and WordPress.
  • Billing information: subscription status and Stripe customer, checkout, or subscription identifiers. Stripe processes payment card and bank information; Vastrid does not store complete payment card numbers.
  • Usage and technical information: feature activity, request and error logs, browser and device information, IP address, timestamps, and diagnostic information needed to operate and secure the Service.
  • Content outcome information: when an authorized clinic deploys a Vastrid outcome connector, it may send an artifact identifier, event type, page context, and an anonymous browser-session key. Vastrid hashes the session key for daily deduplication and may use IP address transiently for rate limiting.

2. How we use information

We use information to authenticate users; provide clinic workspaces; generate, organize, analyze, recommend, and publish content; operate integrations; process subscriptions; provide support; detect abuse; troubleshoot errors; measure content outcomes; improve reliability and product features; communicate service information; and comply with legal obligations.

3. Google API data

If you connect a Google service, Vastrid accesses only the data and permissions needed for the feature you choose:

  • Google Business Profile: account and location identifiers and details, local post content and status, and available post performance data. Vastrid uses this information to let authorized users select a clinic location, prepare or publish posts, and display available results.
  • Google Analytics: read-only property, traffic, engagement, and related reporting data used to show content performance and recommendations.
  • Google Search Console: read-only site, query, page, impression, click, and position data used to show search performance and recommendations.
  • Google identity: basic account identity such as email address when you choose Google sign-in or when needed to complete an authorized connection.

Google authorization tokens are stored in encrypted form and used only to provide and maintain the connected feature. Vastrid does not sell Google user data, use it for advertising, or share it with independent third parties for their own purposes. Google data may be processed by infrastructure and service providers acting for Vastrid, disclosed when required by law, or sent to a destination you expressly direct.

Vastrid’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect supported Google integrations in Vastrid and can also revoke Vastrid’s access in your Google Account. To request deletion of Google-derived data retained by Vastrid, email support@vastrid.com. Revocation stops future access but does not automatically remove content you already directed Vastrid to publish or records we must retain for security, billing, or legal reasons.

4. AI processing

When you request AI-assisted generation, editing, classification, or analysis, relevant clinic settings, instructions, and content may be sent to OpenAI or another disclosed AI service provider acting for Vastrid. Do not submit PHI, patient records, patient names, or patient-identifying information. AI features are intended for clinic marketing content, not patient care or clinical decision-making.

5. Local storage and similar technologies

Vastrid and its authentication provider use browser storage, session storage, and similar technologies to keep you signed in, maintain security, remember interface preferences, preserve onboarding or clinic context, and support core application functions. When a new clinic-owner account is first created, Vastrid may load Google’s conversion tag once to measure advertising sign-up conversions. Vastrid does not load advertising trackers during ordinary application use and does not use them for remarketing in the application. A clinic’s own website and connected platforms may use technologies governed by that clinic’s or platform’s policy.

6. When we disclose information

We disclose information only as needed to operate the Service, follow your instructions, protect users and the Service, complete a business transaction, or comply with law. Service providers may include:

  • Supabase for authentication, databases, and related application infrastructure;
  • Railway for application hosting and operational infrastructure;
  • OpenAI for requested AI-assisted features;
  • Google for sign-in and the Google services you connect;
  • Stripe for subscription and payment processing;
  • Resend for transactional or support email;
  • Amazon Web Services for hosted assets; and
  • WordPress and other destinations you connect when you ask Vastrid to import, draft, update, schedule, or publish content.

Providers process information under their applicable agreements and policies. We may also disclose information to professional advisers, authorities, or counterparties when reasonably necessary for legal compliance, safety, fraud prevention, or a merger, financing, acquisition, or sale of assets. We do not sell personal information or share it for cross-context behavioral advertising.

7. Retention

We retain information while an account is active and as reasonably necessary to provide the Service, preserve user-directed content and audit history, resolve disputes, enforce agreements, maintain security, satisfy tax and legal obligations, and support legitimate business operations. Retention varies by data type and context. We may retain de-identified or aggregated information that no longer identifies a person.

8. Security

We use administrative, technical, and organizational safeguards designed to protect information, including access controls, tenant-scoped authorization, encryption for supported credentials and tokens, and operational monitoring. No system is completely secure, and we cannot guarantee that information will never be accessed, lost, altered, or disclosed improperly.

9. Your choices and rights

You may update many clinic and account details in the Service, disconnect supported integrations, and manage an eligible subscription through the billing portal. You may request access, correction, export, or deletion of personal information by emailing support@vastrid.com. We may need to verify your identity and authority for the clinic. Rights and exceptions vary by location, and some information may be retained where legally permitted or required.

10. Children

The Service is a business product and is not directed to children under 18. We do not knowingly collect personal information directly from children through Vastrid accounts. Do not enter information about child patients or any other patients into the Service.

11. International processing

Vastrid and its providers may process information in the United States and other countries. Those countries may have different privacy laws from your location. Where required, we use appropriate contractual or other safeguards for cross-border processing.

12. Changes to this policy

We may update this Privacy Policy as the Service or applicable requirements change. We will update the date above and provide additional notice when required. Your continued use after an update is subject to the revised policy.

13. Contact

For privacy questions or requests, email support@vastrid.com.

© 2026 Vastrid. Terms of Service