Effective August 13, 2026
Privacy, in plain language.
We collect only what is needed to run your audit request and support fulfillment for Seenward.
What we collect
Contact and request fields from your intake form: business name, practice contact, email, address, website, service selection, and business context notes.
Automated records for operations: request status, report status, checkout state, and message-delivery history.
Technical and abuse-prevention fields: connection fingerprints, rate-limit counters, bot tokens, and request timestamps.
Public call-to-action measurement is stored only as daily aggregate counts; it does not store IP addresses, email addresses, cookies, referrers, or user-agent strings.
How we use information
Data is used to run the audit pipeline, coordinate deliverables, process payment, prevent abuse, and improve service reliability.
We do not process protected health information, patient records, appointment content, or clinical systems data.
We do not knowingly collect personal information from children under 13.
Service providers and subprocessors
Cloudflare supports hosting, database storage, network security, and anti-bot verification. Stripe handles payment authorization and checkout status. Resend delivers transactional email.
Configured AI benchmark providers may include OpenAI, Anthropic, Google, and xAI. They receive public practice identifiers and benchmark questions, not your checkout email, payment data, or private notes.
We do not intentionally store your card data. If you are in a state with separate financial-protection programs, this page applies only to our visibility service flow and not any regulated financial account holder rights.
See the Trust Center for the current data path and provider boundaries.
State and U.S. privacy rights
Privacy obligations vary by state, business size, data volume, and use. Rather than make you determine whether a particular threshold applies, we accept verified requests to access, correct, or delete contact information associated with your order, subject to legal and fraud-prevention exceptions.
- Know what contact information is associated with your request or order.
- Correct inaccurate contact information.
- Request deletion of eligible information.
- Receive equal service regardless of whether you exercise a privacy right.
This operational baseline is not a representation that every state privacy statute applies to Seenward.
California-specific rights
For California residents, rights may include, subject to eligibility:
- Access to known personal information we process.
- Deletion where permitted by law.
- Correction or updating of inaccurate account-contact details.
- Opt-out from sale or sharing where this business activity applies.
- Non-discrimination for exercising an applicable privacy right.
California rights are processed through the same verified request channel described below.
Privacy request process
Email audits@seenward.com and include:
- your full legal/business name
- the email used during request or checkout
- an order or request reference, if available
- the specific right(s) and action you want us to apply
Ownership is verified before we process any request. We respond within 45 days, with one 45-day extension when applicable under law.
Cancellation, refunds, and order control requests
Self-service cancellation and refund workflows are handled on the secured Manage order page using your purchase email and the reference included in your receipt or Seenward message.
Where your state law gives broader control rights, we combine those requests with fulfillment controls and keep an auditable action trail in secure operations records.
- Open one-click actions from your checkout success page.
- Use your latest email delivery with the direct manage link (if included).
- Open Manage order and enter your purchase email and order reference.
If you want to request deletion of personal data, use the same verified channel and include your request type in the notes. We process deletion and cancellation decisions without requiring manual email back-and-forth.
Security, retention, and incident response
We operate request verification, webhook signature checks, signed payment events, anti-bot checks, short-lived abuse controls, and no-store cache headers on sensitive endpoints.
- Contact and request records are retained under policy and typically purged around 30 days after fulfillment and legal requirements are met.
- Webhook and operations logs are retained for up to 180 days for fraud and reliability controls.
- Private report links expire around 30 days after delivery. Detailed prompts, answers, evidence, and technical findings are automatically removed 30 days after report delivery by the retention process.
- Emails, payment references, and operational identifiers are scrubbed after terminal outcomes and retention windows close.
If you suspect a security problem, email audits@seenward.com. Do not send passwords, patient information, or full payment details.
Do not sell / share and suppression choices
We do not sell your personal information for advertising or brokerage resale in our Seenward workflows.
If you want additional suppression preferences for optional marketing or notifications, include your request in the same verified rights channel.
Retention and deletion
Retention is policy-driven and reviewed against fulfillment status:
- Request context and order metadata are removed after delivery milestones or legal requirements are met.
- Completed report artifacts and delivery logs are retained where quality, support, and legal requirements justify continuity.
- Rate-limit and anti-abuse rows are short-lived for operations integrity.
Cookies and communications
Public pages do not rely on marketing tracking cookies. Anti-bot and payment pages load provider scripts required to secure checkout and form submissions.
You can request deletion of retained email-linked fields as part of a verified request.
Contact and updates
Policy updates are posted with a new effective date. For privacy, cancellation, and deletion questions: audits@seenward.com.