1. INTRODUCTION
Toothsome, Inc. ("Toothsome," "we," "us," or "our") is committed to protecting the privacy of individuals who use our platform and services. This Privacy Policy describes how we collect, use, disclose, and protect information when you use our website, mobile applications, and related services (collectively, the "Platform").
This Privacy Policy applies to employees who receive dental benefits through our Platform ("Members"), employers who sponsor dental benefit programs ("Employers"), and dental providers who participate in our network ("Providers").
This Privacy Policy describes our information practices; using the Platform does not itself provide consent where applicable law requires it. For consumer health data covered by Washington law, the collection and sharing rules in our Consumer Health Data Privacy Policy control.
Washington residents: the Washington My Health My Data Act requires a separate policy for consumer health data. Ours is the Consumer Health Data Privacy Policy, and it is a companion to this one. See Section 10.3.
2. INFORMATION WE COLLECT
2.1 Information You Provide
We collect information you provide directly to us, including:
Account Information: Name, email address, phone number, mailing address, and password when you create an account.
Employment Information: Employer name, employee ID, hire date, and benefit eligibility information (for Members).
Provider Information: Practice name, address, NPI number, state license number, and tax identification number (for Providers).
Transaction Information: Receipts, invoices, payment amounts, dates of service, and procedure codes submitted for reimbursement.
Communications: Messages, emails, and other communications you send to us.
2.2 Information We Collect Automatically
When you use our Platform, we automatically collect:
Device Information: Device type, operating system, browser type, and unique device identifiers.
Usage Information: Pages visited, features used, time spent on the Platform, and interaction patterns.
Location Information: General location based on IP address.
2.3 Information from Third Parties
We may receive information from:
Employers: Employee roster information, benefit amounts, and eligibility data.
Payment Processors: Employer administration-fee invoice payment confirmations and status only; not member reimbursement or settlement information.
3. HOW WE USE YOUR INFORMATION
We use the information we collect to:
Provide Services: Process reimbursements, verify eligibility, and facilitate transactions between Members, Employers, and Providers.
Communicate: Send account notifications, transaction confirmations, and respond to inquiries.
Improve Our Platform: Analyze usage patterns, troubleshoot issues, and enhance user experience.
Comply with Legal Obligations: Meet regulatory requirements, respond to legal requests, and enforce our agreements.
Prevent Fraud: Detect and prevent fraudulent activity, abuse, and security incidents.
4. HOW WE SHARE YOUR INFORMATION
We share information in the following circumstances:
4.1 With Your Employer
We share the information needed to pay approved reimbursements through payroll and complete related payroll tax reporting: your name, employee identifier, email address, reimbursement number, date of service, and approved amount. We do not share clinical details or specific procedure information with Employers.
4.2 With Service Providers
We share information with service providers who assist us in operating our Platform:
Amazon Web Services (AWS): Cloud infrastructure and data storage. AWS processes and stores data on our behalf. We maintain a Business Associate Agreement with AWS as required by HIPAA.
Google Workspace: Business email, document storage, and collaboration tools. We maintain a Business Associate Agreement with Google as required by HIPAA.
Moov Financial, Inc.: Licensed payments provider that Toothsome uses to invoice employers for Toothsome's administration fee and to collect those invoice payments. Moov receives employer billing and payment information only. No member information, member funds, or member bank-account information is sent to Moov, and Moov does not access health information, procedure codes, or clinical data.
SendGrid: Email delivery services. Our emails are designed to contain no protected health information; emails use generic language and do not include clinical details.
For service providers who access protected health information, we maintain Business Associate Agreements as required by HIPAA. For service providers who only process operational data such as payments, no Business Associate Agreement is required.
4.3 With Providers
We share Member eligibility status and Toothsome ID with Providers to verify benefit coverage. We do not share detailed personal information with Providers beyond what is necessary for eligibility verification.
4.4 For Legal Purposes
We may disclose information when required by law, subpoena, court order, or government request, or when we believe disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
4.5 Business Transfers
If Toothsome is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your information.
5. PROTECTED HEALTH INFORMATION
Certain information we collect may constitute Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"). We handle PHI in accordance with HIPAA requirements and our Business Associate Agreements with Employers and Providers.
5.1 Your Rights Regarding PHI
You have the right to:
Access: Request a copy of your PHI that we maintain.
Amendment: Request correction of PHI you believe is inaccurate or incomplete.
Accounting of Disclosures: Request a list of certain disclosures we have made of your PHI.
Restriction: Request restrictions on how we use or disclose your PHI.
Confidential Communications: Request that we communicate with you in a specific manner or at a specific location.
To exercise these rights, contact us at privacy@toothsome.io.
5.2 Minimum Necessary Standard
We apply the minimum necessary standard when using or disclosing PHI, meaning we limit the PHI used or disclosed to the minimum amount necessary to accomplish the intended purpose.
6. DATA SECURITY
We implement appropriate technical and organizational measures to protect your information, including:
Encryption: Data is encrypted in transit using TLS and at rest using AES-256 encryption.
Access Controls: Access to personal information is limited to authorized personnel who need it to perform their job functions.
Monitoring: We monitor our systems for security incidents and unauthorized access.
Training: Our team receives regular training on privacy and security practices.
While we strive to protect your information, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security.
7. DATA RETENTION
We retain your information for as long as necessary to provide our services and fulfill the purposes described in this Privacy Policy. Specifically:
Account Information: Retained for the duration of your account and for six (6) years after account closure.
Transaction Records: Retained for seven (7) years to comply with tax and regulatory requirements.
Communications: Retained for three (3) years or as required by law.
When information is no longer needed, we securely delete or anonymize it.
8. YOUR CHOICES
8.1 Account Information
You can update your account information by logging into your account or contacting us at support@toothsome.io.
8.2 Communications
You can opt out of promotional communications by following the unsubscribe instructions in our emails. You cannot opt out of transactional communications related to your account or benefit administration.
8.3 Cookies
Most web browsers are set to accept cookies by default. You can usually modify your browser settings to decline cookies, but this may affect your ability to use certain features of our Platform.
9. CHILDREN'S PRIVACY
Our Platform is not intended for children under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will take steps to delete that information.
10. STATE-SPECIFIC RIGHTS
10.1 California Residents
If you are a California resident, you have rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act (Cal. Civ. Code §1798.100 et seq.).
What is and is not covered. Most of the health information we hold about you is Protected Health Information or medical information, and California law excludes it from these rights (Cal. Civ. Code §1798.145(c)(1)(A)). It is governed instead by HIPAA and by Section 5 of this Privacy Policy. The rights below apply to the rest of the personal information we hold about you.
Notice at Collection: At or before the point we collect personal information from you, we tell you the categories we are collecting, the purposes we will use them for, whether we sell or share them, and how long we keep each category. Sections 2, 3 and 7 of this Privacy Policy are that notice.
Right to Know: You can request the categories of personal information we collected about you, the categories of sources, our business or commercial purpose for collecting it, the categories of third parties we disclosed it to, and the specific pieces of personal information we hold.
Right to Delete: You can request that we delete personal information we collected from you, subject to the exceptions in the statute — including information we must retain to complete a transaction, to comply with a legal obligation, or to meet the tax and regulatory retention periods described in Section 7.
Right to Correct: You can request that we correct inaccurate personal information we maintain about you. We will use commercially reasonable efforts to correct it as you direct.
Right to Opt Out of Sale or Sharing: We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding twelve months. Because we do not sell or share, we do not offer a "Do Not Sell or Share My Personal Information" link. If that ever changes, we will update this Privacy Policy and provide the opt-out mechanism before the change takes effect.
Sensitive Personal Information: California treats personal information collected and analyzed concerning your health as sensitive personal information (Cal. Civ. Code §1798.140(ae)). We use sensitive personal information only to provide the services you and your employer have asked us for, and for the purposes the statute permits without a right to limit — administering your benefit, substantiating a reimbursement request, securing our systems, and preventing fraud. We do not use or disclose sensitive personal information to infer characteristics about you, and we do not use it for advertising. Because we do not process sensitive personal information for the purpose of inferring characteristics about you, the right to limit does not attach (Cal. Civ. Code §1798.121(d)). We will honor such a request in any event, and we will provide the limitation mechanism if our practices ever change.
Right to Non-Discrimination: We will not deny you goods or services, charge you a different price, or provide you a different level of service because you exercised any of these rights.
How to exercise these rights. Email privacy@toothsome.io, or write to us at the address in Section 13. We will verify your identity before responding. You may use an authorized agent. We respond within forty-five (45) days, which we may extend once by a further forty-five (45) days by telling you why (Cal. Civ. Code §1798.130(a)(2)).
10.2 Texas Residents
If you are a Texas resident, you have rights under the Texas Data Privacy and Security Act, including the right to access, correct, delete, and obtain a copy of your personal data, and the right to opt out of targeted advertising, sale, and profiling. We do not sell personal data, do not use it for targeted advertising, and do not profile you. To exercise these rights, contact us at privacy@toothsome.io.
10.3 Washington Residents
If you are a Washington resident, or if your health data is collected in Washington, the Washington My Health My Data Act (chapter 19.373 RCW) gives you rights over consumer health data — information linked or reasonably linkable to you that identifies your past, present, or future physical or mental health status (RCW 19.373.010(8)).
Information that is Protected Health Information under HIPAA is excluded from that definition (RCW 19.373.100(1)(a)(i)). That exclusion applies to the data, not to us: health-related information we hold that is not PHI is consumer health data, and the Act applies to it in full.
Because the Act requires a separate policy for this data, we maintain one: Consumer Health Data Privacy Policy. It describes the categories of consumer health data we collect and why, our sources, what we share and with whom, and how to exercise your rights to confirm and access, to withdraw consent, and to delete — including the appeal process if we refuse a request.
In summary: we do not sell consumer health data; we collect and share it only as necessary to provide the service you request, and we ask for your separate consent before any other collection or sharing; and we do not use geofencing around health care facilities. Contact privacy@toothsome.io to exercise any of these rights.
11. IF THERE IS A DATA BREACH
If your information is involved in a data breach, we will tell you. This section describes the obligations we operate under and the clocks that run.
Our internal commitment is to work to the strictest applicable deadline and the broadest applicable content requirement. Where the rules below differ, the shortest deadline is the one we meet.
11.1 Protected Health Information
Where a breach involves unsecured PHI, the HIPAA Breach Notification Rule applies (45 CFR §§164.400–414).
Our role. For most of the PHI we hold, Toothsome is a business associate of your employer's health plan or of a dental provider, not the covered entity. Under 45 CFR §164.410, a business associate must notify the covered entity of a breach without unreasonable delay and no later than 60 calendar days after discovery, and must identify each individual affected and provide the information the covered entity needs for its own notice. We also comply with any shorter reporting deadline in the applicable Business Associate Agreement. The covered entity then notifies you, unless it has delegated that to us.
Notice to you. Individual notice must be provided without unreasonable delay and in no case later than 60 calendar days after discovery of the breach (45 CFR §164.404(b)). The notice will describe what happened, the date of the breach and the date of discovery, the types of information involved, the steps you should take to protect yourself, what we and the covered entity are doing to investigate and mitigate, and how to reach us with questions (45 CFR §164.404(c)(1)).
Media and HHS. If a breach affects more than 500 residents of a single state or jurisdiction, notice must also go to prominent media outlets serving that area, within the same 60-day limit (45 CFR §164.406). The Secretary of Health and Human Services must be notified at the same time as individuals when a breach affects 500 or more individuals, and through an annual log filed within 60 days after the end of the calendar year when it affects fewer than 500 (45 CFR §164.408(b), (c)).
When an incident is a breach. An impermissible use or disclosure of PHI is presumed to be a breach unless a documented risk assessment shows a low probability that the information was compromised, weighing the nature and extent of the PHI, who received it, whether it was actually acquired or viewed, and the extent to which the risk has been mitigated (45 CFR §164.402). The burden of demonstrating that required notifications were made, or that an incident was not a breach, is ours (45 CFR §164.414(b)). Information that is encrypted to the standard the Secretary specifies is not "unsecured," and a breach of properly encrypted data with uncompromised keys generally does not require notice.
11.2 State Breach Notification Laws
State law applies in addition to HIPAA, on its own clocks, and reaches information that is not PHI. For the states where we operate:
Washington. We must notify affected Washington consumers in the most expedient time possible, without unreasonable delay, and no more than 30 calendar days after the breach was discovered (RCW 19.255.010(8)). If a single breach requires notice to more than 500 Washington residents, we must also notify the Washington Attorney General within 30 days of discovery (RCW 19.255.010(7)). The notice must be in plain language and must give our name and contact information, the types of personal information involved, the time frame of exposure including the dates of the breach and of its discovery, and the contact details of the major credit reporting agencies where the breach exposed personal information (RCW 19.255.010(6)). Washington's definition of personal information expressly includes health insurance identifiers and information about your medical history or physical or mental condition (RCW 19.255.005(2)(a)(i)(G), (H)). A HIPAA covered entity that complies with the federal rule is deemed to comply as to PHI, but the notice to the Washington Attorney General is still required (RCW 19.255.030(1)).
Texas. We must notify affected individuals without unreasonable delay and not later than the 60th day after we determine that the breach occurred (Tex. Bus. & Com. Code §521.053(b)). If a breach involves at least 250 Texas residents, we must notify the Texas Attorney General not later than the 30th day after that determination, describing the nature and circumstances of the breach and the number of Texas residents affected (Tex. Bus. & Com. Code §521.053(i)). Texas's definition of sensitive personal information includes information about an individual's physical or mental health, the health care provided to them, and payment for that care (Tex. Bus. & Com. Code §521.002(a)(2)).
California. We must notify affected California residents within 30 calendar days of discovery or notification of the breach (Cal. Civ. Code §1798.82(a)). If a breach affects more than 500 California residents, we must submit a sample copy of the notice to the California Attorney General within 15 calendar days of notifying those residents (Cal. Civ. Code §1798.82(f)). The notice must identify us, describe the breach and the types of information involved, give the date or date range if it can be determined, say whether notice was delayed for a law enforcement investigation, and provide credit reporting agency contact details where required (Cal. Civ. Code §1798.82(d)). California's definition of personal information includes medical information and health insurance information (Cal. Civ. Code §1798.82(h)). A HIPAA covered entity that complies fully with section 13402(f) of the HITECH Act is deemed to have satisfied the content requirements of subdivision (d) (Cal. Civ. Code §1798.82(e)). That deeming reaches the notice content only: it does not change the 30-day deadline, the Attorney General filing, or any other requirement of the section.
If residents of other states are affected, we notify them under their own state's law.
11.3 What We Do
On discovering an incident we contain it, preserve the evidence, and determine what data was involved, whose, and whether it was encrypted. We run the risk assessment, we notify on the shortest applicable clock, and we keep a record of the decision and its basis. We notify our payment partner and other service providers on their contractual clocks where financial data is involved.
Our full internal breach-response procedure, including the state-by-state deadline matrix, is maintained separately as an operational document.
12. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on our Platform prior to the effective date of the changes. An update to this policy, or your continued use of the Platform, does not substitute for consent where required by law. We obtain consent before any new collection, use, or sharing of consumer health data where Washington law requires it.
13. CONTACT US
If you have questions about this Privacy Policy or our privacy practices, please contact us:
Toothsome, Inc. 3550 N Lakeline Blvd, Unit 170, PMB 1022 Leander, TX 78641
Email: privacy@toothsome.io
For HIPAA-related inquiries or to exercise your rights regarding Protected Health Information, please contact our Privacy Officer at privacy@toothsome.io.
Document Version: 2.2 · Last Updated: September 27, 2026