At ChairFill, accessible from our application platform, we are committed to maintaining the highest standard of privacy, transparent billing, and compliance with global financial platforms like Stripe.
ChairFill uses Google OAuth to access your Google Business Profile on your behalf. We request only the permissions necessary to manage your business listings, posts, photos, and review responses. We comply with Google's API Services User Data Policy, including the Limited Use requirements.
You may revoke ChairFill's access to your Google account at any time via your Google Account settings at myaccount.google.com/permissions.
To comply with the Google API Services User Data Policy, we clearly disclose how ChairFill accesses, uses, stores, and retains your Google user data.
2.1 Data Accessed
Our application requests access to your basic Google profile information (such as name and email address) and specific Google Business Profile data necessary to manage your dental clinic's online presence. For Google Calendar integration, we request access to your calendar solely to read existing appointments and create new booking events on your behalf.
2.2 Data Usage
We use this data solely to authenticate your account, set up your ChairFill dashboard, audit dental clinic profiles, manage reviews and alerts to optimize your business operations, and schedule appointments via Google Calendar. ChairFill's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
2.3 Data Sharing
ChairFill does not sell, trade, or share any Google user data with third-party applications, external organizations, or advertising platforms. All data remains confidential and is used strictly for the app's core functionalities as described in this policy.
2.4 Data Storage & Protection
Your Google user data is securely stored in Supabase-hosted databases with encryption at rest and in transit. Access is restricted to authorized ChairFill systems only. We implement industry-standard security protocols to prevent unauthorized access, alteration, or disclosure of your information.
2.5 Data Retention & Deletion
We retain Google user data only for as long as your account is active with ChairFill. Upon account deletion or access revocation, all associated Google user data is permanently deleted within 30 days. Users can request complete deletion of their account and all associated Google user data at any time by contacting us at support@getchairfill.com or using the data deletion option within the application settings.
ChairFill integrates with Google Calendar to manage appointment scheduling. Our application accesses your calendar data solely to create new appointment events and read existing slots to prevent double-bookings.
To ensure maximum privacy, we do not store your private Google Calendar event details. We only store appointment information that you or your patients explicitly provide through ChairFill, along with the associated Calendar Event ID strictly for management and syncing purposes.
We do not share your Google Calendar data with any third parties. You may revoke Calendar access at any time via myaccount.google.com/permissions.
4.1 Compliance with Google API Services User Data Policy
Our application's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use and transfer of raw or derived user data received from Google Workspace APIs will strictly adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4.2 AI/ML Integration and Data Privacy
To provide our core automation and analysis features, our application integrates with Google Cloud Vertex AI as a compliant infrastructure.
We do not utilize any non-compliant or generalized public third-party AI models that train on your data.
Google Workspace/Calendar user data accessed through our application is processed securely within Google Cloud Vertex AI and is used solely to execute the features requested by the user.
Data processed via Vertex AI is encrypted, kept isolated within our secure cloud environment, and is never used by Google to train its foundation models.
ChairFill complies fully with Meta's Platform Terms and the WhatsApp Business Policy. WhatsApp messaging features are conducted solely to facilitate authorized clinic-patient communication on your behalf.
We access the WhatsApp Business API to:
We strictly prohibit the use of our platform for sending unsolicited promotional or spam messages. Patient phone numbers and chat metadata collected via the API are encrypted at rest, stored securely, and used exclusively for internal clinic communication purposes.
We do not sell, rent, or share WhatsApp contact data with third parties. Users retain full control and may disconnect the WhatsApp integration at any time directly from the ChairFill settings dashboard, which immediately revokes API data access.
You have the right to request complete deletion of your clinic's data from our systems at any time. To delete your data, email us at support@getchairfill.com. We will process your request within 7 business days and confirm deletion via reply email.
Your First Month: ChairFill gives every dental practice its first 30 days in full — no credit card is required to start, and no invoice is issued for that period. One first month is available per practice, identified by the clinic's phone number and Google Business Profile listing.
After the First Month: Your account becomes read-only until you choose a paid plan. For a short period afterwards ChairFill continues to acknowledge patients who contact you, but stops taking bookings. You are never charged without adding a payment method and selecting a plan. A paid month begins on the day payment is made — not when the first month ended — so no paid days are ever lost by subscribing late. Active subscriptions renew per their billing cycle via our secure payment gateways (Stripe / Razorpay).
Payment Processing Security: ChairFill processes payments via Stripe and Razorpay. Payment card data is never stored on our servers. All transactions are handled securely by the respective payment processor in accordance with PCI-DSS standards.
7-Day Refund Window: Following an automated or manual subscription charge, users can submit a refund request within 7 calendar days.
Valid Refund Criteria: To maintain structural compliance and fair usage, refunds are strictly granted under circumstances of verifiable technical failure or when a core integrated feature fails to execute within the dashboard.
Post 7-Days Policy: Any cancellation or refund request submitted after 7 days of the billing transaction will not be eligible for a refund. Services will remain active until the conclusion of the current billing cycle.
9.1 Who is responsible for what. When a dental practice uses ChairFill, the practice is the Data Fiduciary (Data Controller) for its patients' information and decides why it is collected. ChairFill acts as the practice's Data Processor: we process patient information only on the practice's instructions, only to provide the service, and we do not sell it, share it for advertising, or use it to train AI models.
9.2 What we hold, and why.
9.3 Consent. Patient information reaches ChairFill when a patient contacts the practice themselves — a WhatsApp message, a website enquiry, a phone call — or when practice staff enter a booking. We record when consent was given and through which channel. Consent can be withdrawn at any time by telling the practice, or by replying STOP to any WhatsApp or SMS message, which immediately ends automated messaging. Withdrawing consent does not undo processing that already lawfully happened.
9.4 Your rights. Under the DPDP Act (and, for UK patients, the UK GDPR) you may:
9.5 What erasure actually removes. We are direct about this because the honest answer is not "everything". Your name, phone number and message history are removed and cannot be recovered. The appointment record itself — its date, time and treatment — is kept without you identifiable in it, because a dental practice is required to be able to show that a treatment took place, and tax and contract law can require those records to be retained. Nothing that remains identifies you.
9.6 Grievance Officer. If you believe your data has been handled wrongly, contact our Grievance Officer using the details below. We aim to acknowledge every complaint within 7 days and to resolve it within 90 days, as the DPDP Rules require. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India.
Grievance Officer: Data Protection Contact, CHAIRFILL
Email: privacy@getchairfill.com
Address: Hindupur, Sri Sathya Sai, Andhra Pradesh – 515201, India
Response: acknowledged within 7 days · resolved within 90 days
9.7 Where your data is stored. The database is hosted by Supabase in Frankfurt, Germany (Supabase's Central EU region). It was in Supabase's East US region until 3 August 2026. The application runs on Cloudflare's global network. Patient messaging is delivered through Meta (WhatsApp and Instagram) and Twilio (SMS), calendar synchronisation and AI processing through Google, each under its own terms.
Stated plainly: patient data does not stay inside your country. The database itself now sits in the EEA, so no transfer safeguard is needed for it under UK or EU law; for India the transfer is permitted by the DPDP Act, which allows transfers except to territories the Central Government restricts. Messaging, calendar and AI providers still process outside the EEA, and those transfers rely on Standard Contractual Clauses. Some jurisdictions — the UAE and Saudi Arabia among them — require health data to remain in-country, and ChairFill does not currently meet that. Practices there should contact us before connecting patient information rather than assume it is covered.
The full list of providers, what each receives and where it processes it, is at getchairfill.com/subprocessors.
9.8 How long we keep it. Patient information is retained while the practice's account is active. After the account closes it stays available for export for 30 days, is then deleted from live systems, and ages out of routine backups over a further 90 days. Erasure requests are honoured sooner, as described in 9.5. Billing and transaction records are kept longer where tax and accounting law requires it.
For integration updates, technical troubleshooting, data deletion requests, or subscription/refund assistance, please reach out directly to our dedicated desk:
Support & Helpdesk Email: support@getchairfill.com
Official Entity: CHAIRFILL
Address: Hindupur, Sri Sathya Sai, Andhra Pradesh – 515201, India