Privacy Policy
Last updated: May 2026
1. Who we are
Dentist Search is an independent dental directory service based in the UK. We operate the website at dentalfinder.co.uk. We are the data controller for personal data collected through this service.
This policy explains what data we collect, why we collect it, how long we keep it, and your rights under UK GDPR and the Data Protection Act 2018.
2. Data we collect
Account data
When you create an account, we collect:
- Email address
- Password (stored as a secure hash — we never see your plain-text password)
- Date and time of account creation
Alert preferences
When you set up monitoring, we collect:
- Which practices you are watching
- Your preferred notification channel (email and/or SMS)
- Mobile phone number (Plus and Pro plans only, for SMS alerts)
Payment data
Payments are processed by Stripe. We do not store your card number, CVV, or full card details. We receive a Stripe customer ID and subscription status from Stripe after a successful payment.
Usage data
We collect standard server logs including IP addresses, browser type, pages visited, and search queries. This data is used to operate and improve the service and is not linked to individual accounts unless required for security purposes.
AI advice conversations
If you use the AI Dental Advice feature, your messages are sent to Anthropic's Claude API to generate responses. We retain conversation history within your account session. We do not train AI models on your conversations. Please do not share sensitive personal health information in the chat.
3. Why we collect it — lawful basis
| Purpose | Lawful basis |
|---|---|
| Providing the search and alert service | Contract performance |
| Processing payments | Contract performance |
| Sending alert emails and SMS | Contract performance |
| Improving the service | Legitimate interests |
| Preventing fraud and abuse | Legitimate interests |
| Legal compliance | Legal obligation |
4. Who we share data with
We share data with the following third parties, only to the extent necessary to operate the service:
- Supabase — Database and authentication hosting. Data stored in EU region.
- Stripe — Payment processing. Subject to Stripe's privacy policy.
- Resend — Transactional email delivery (alert notifications, account emails).
- Twilio — SMS alert delivery for Plus and Pro subscribers.
- Anthropic — AI response generation for the Dental Advice feature.
- Vercel — Website hosting and infrastructure.
We do not sell your personal data to third parties. We do not share your data with dental practices or any other commercial entities.
5. How long we keep your data
- Account data — Retained for as long as your account is active, plus 12 months after closure.
- Alert history — Alert logs are retained for 12 months.
- Payment records — Retained for 7 years to comply with financial regulations.
- Server logs — Retained for 90 days.
6. Cookies
We use essential cookies only — specifically, a session cookie to keep you logged in. We do not use advertising cookies or third-party tracking cookies.
If we add analytics in future, we will update this policy and request consent where required.
7. Your rights under UK GDPR
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data (subject to legal retention obligations)
- Restrict or object to processing
- Data portability — receive your data in a machine-readable format
- Withdraw consent where processing is based on consent
- Lodge a complaint with the ICO (Information Commissioner's Office) at ico.org.uk
To exercise any of these rights, contact us via the contact page. We will respond within 30 days.
8. Security
We use industry-standard security measures including encrypted connections (TLS), hashed passwords, and row-level security on our database. We do not store payment card data. Despite these measures, no internet service can be guaranteed to be 100% secure — please use a strong, unique password for your account.
9. Changes to this policy
We may update this privacy policy from time to time. If we make material changes, we will notify you by email. Continued use of the service after changes are posted constitutes acceptance.
10. Contact
For privacy-related queries or to exercise your rights, contact us via the contact page.