← Back to ToxPop

Privacy Policy

Effective: March 19, 2026 · Version v1.0

1. What We Collect

We collect information you provide when creating an account (email, name, practice name), data you enter into ToxPop (inventory logs, unit usage), and basic usage data to improve the service.

2. How We Use Your Data

We use your data to provide and improve the ToxPop service, authenticate your account, send important service updates, and process billing. We do not sell your data to third parties.

3. Data Storage & Security

Your data is stored securely using Supabase (PostgreSQL) with industry-standard encryption. We use row-level security to ensure users can only access their own data.

4. Data Sharing

We share your data only with trusted service providers necessary to operate ToxPop (e.g., cloud hosting, payment processing). All third parties are bound by confidentiality obligations.

5. Team Accounts

If you are part of a Med Spa team, your name, activity logs, and inventory usage are visible to the practice owner and other team members within your practice workspace.

6. Cookies

ToxPop uses cookies solely for authentication and session management. We do not use tracking or advertising cookies.

7. Your Rights

You may request access to, correction of, or deletion of your personal data at any time by contacting us. Account deletion removes all associated data from our systems within 30 days.

8. Changes to This Policy

If we make material changes to this policy, you will be notified in-app and required to accept the updated policy before continuing to use ToxPop.

9. Contact

Privacy questions? Email us at hello@toxpop.com