VibedIn · Legal

VibedIn Privacy Policy

Last updated: August 10, 2026

This Privacy Policy explains how EMILE-E.tech Corp, a Florida corporation ("EMILE-E," "we," "us"), handles information in connection with the VibedIn client check-in service: the kiosk application, the web administration portal, and SMS notification delivery (together, the "Service"). It covers three groups of people: staff who use the Admin Portal, practitioners who receive SMS notifications, and clients who tap the kiosk in a practice's waiting room.

1. The short version

2. Information we collect

From the practice (Admin Portal). Account information (practice name, administrator name and email, password credentials), billing details processed by our payment processor, practitioner rosters (names and mobile phone numbers), office locations, and notification template settings.

From kiosk check-ins. The practitioner selected, the appointment time selected, the office location, a timestamp, and SMS delivery status. The kiosk does not collect names, contact details, health information, photos, or biometric information from clients, and has no camera or microphone function.

Automatically. Standard technical logs for security and reliability: device identifiers for managed kiosk tablets, portal sign-in events, IP addresses, and error logs.

3. How we use information

4. SMS notifications

Practitioner mobile numbers are provided to us by the practice, which is responsible for obtaining each practitioner's consent to receive operational messages. Notifications are delivered through Twilio, our SMS provider. Default notification templates contain no client-identifying information, and practices are required to keep it that way. Practitioners can opt out at any time by replying STOP or by asking their practice to remove their number.

5. How information is shared

We share information only with service providers that host and deliver the Service, currently: Google (Firebase: hosting, database, authentication) and Twilio (SMS delivery), plus a payment processor for billing. Each provider processes information only to provide its service to us. We may also disclose information if required by law, to protect the safety and security of the Service, or as part of a business transfer, in which case this policy continues to apply.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

6. HIPAA

Practices using the Service may be HIPAA covered entities. The Service is designed to minimize protected health information: check-in records identify the practitioner and time, not the client. To the extent we nonetheless create, receive, maintain, or transmit PHI on a practice's behalf, we act as a business associate, and an executed Business Associate Agreement governs that information.

7. Retention and deletion

Account and check-in data are retained while the practice's subscription is active. After cancellation, the practice may export its data for 30 days, after which we may delete it, subject to legal retention obligations and any BAA. Security logs are retained for a limited period for audit purposes.

8. Security

The Service runs on Google Cloud infrastructure with encryption in transit and at rest, tenant isolation between practices, authenticated access to the Admin Portal with automatic sign-out, and locked kiosk mode on managed tablets. No system is perfectly secure; if we learn of a breach affecting your information, we will notify affected customers consistent with applicable law and any BAA.

9. Your choices and rights

Practice administrators can review and update their account information, practitioner roster, and templates in the Admin Portal at any time. Practitioners who wish to stop receiving SMS can reply STOP or contact their practice. Depending on where you live, you may have rights to access, correct, or delete personal information we hold about you; contact us at privacy@emile-e.tech and we will respond consistent with applicable law. If you are a client of a practice, your relationship is with that practice; contact them first, and we will support their obligations.

10. Children

The Service is a business tool and is not directed to children. The kiosk may be tapped by a minor client of a practice, but it collects no identifying information from anyone.

11. Website visitors

Our marketing site (emile-e.tech) sets no advertising cookies and runs no third-party analytics or tracking scripts.

12. Changes and contact

We will post any material changes to this policy here and, for active customers, provide notice by email or in the Admin Portal at least 30 days before they take effect. Questions and requests: privacy@emile-e.tech, EMILE-E.tech Corp, Florida, USA.