Appointment data can reveal health information. We treat patient identity, appointment context, templates, provider identifiers, and delivery data as sensitive unless it is clearly operational-only.
Clinic usersNames, email addresses, login identity, workspace roles, billing authority, support requests, and audit records for account activity.
Clinic setupClinic name, timezone, sender and reply-to details, phone, website, booking link, templates, merge fields, and automation rules.
Booking-calendar connectionCliniko API keys and Calendly OAuth credentials are handled as backend secrets. The database stores secret references, fingerprints, connection status, verification details, and the setup data needed for the connected workflow.
Patient and appointment dataFetched from the connected Cliniko or Calendly account when needed to match rules, schedule messages, render merge fields, or confirm send eligibility. This can include names, email addresses, provider IDs, booking time and type, practitioner or host, location, booking status, timezone, and any communication preferences the provider supplies.
Campaign audience and consentWhen a clinic uses Campaigns, we store the synced recipient name, email address, provider ID, audience status, consent source and evidence, and the available fields used for filtering. Cliniko marketing preferences can be synchronised. Calendly does not provide a marketing preference, so invitees remain ineligible until a clinic user records permission or confirms that selected Calendly event types already collect it.
Email delivery dataScheduled-message and campaign-recipient state, test-send details, provider message IDs, delivery outcomes, skip reasons, bounces, complaints, opens, clicks, unsubscribes, and redacted operational logs.
Billing dataStripe customer, subscription, checkout, portal, invoice, trial, and plan metadata. Payment card details are handled by Stripe, not stored by MyHealthFollowup.