Privacy policy
Last updated 22 September 2026
Lynqpod is software for dental practices: booking pages, a patient portal, practice operations and marketing reports. This policy explains what personal data Lynqpod handles, why, and your rights. Questions: scott@lynqpod.com.
Who is responsible for your data
- If you are a patient of a dental practice that uses Lynqpod (for example on its booking page or patient portal), the practice is the controller of your data and Lynqpod processes it on the practice's behalf and on its instructions. To exercise your rights, contact the practice; we will help it respond.
- If you work at a practice that uses Lynqpod, your employer (the practice) is the controller of the data it keeps about you in Lynqpod, and Lynqpod is its processor.
- For this website, enquiries to us and the accounts of practices we work with, Lynqpod is the controller.
What we handle
- Booking requests and the patient portal: the details a patient gives (name, email address, phone number, date of birth, and anything they choose to write), the appointment asked for, and confirmation that the email address is theirs (a six-digit code). Where a practice books straight into its clinical system, the details that system needs to register a new patient (such as title, sex and address).
- Practice records: appointment, patient and payment information synchronised from the practice's own clinical system (for example Dentally), used to run the practice's bookings, reports and pay calculations.
- Practice staff accounts: name, username, role and sign-in activity.
- How a booking arrived: the campaign details in the link a visitor arrived on (such as utm_campaign) and whether it carried an advertising click identifier, kept in that browser tab and with the booking request, so the practice can see which adverts bring patients. No third-party advertising scripts run on Lynqpod booking pages.
- Visitor recordings (only where a practice switches them on): a replay of how a visitor used the page, recorded only after the visitor agrees. Anything typed into forms is not recorded.
Advertising accounts (Google Ads and Meta)
If a practice connects its Google Ads or Meta advertising account to Lynqpod, we access that account only to read its own campaign costs and to send it the practice's own conversion results (booked and attended appointments, and a value the practice chooses: what the patient paid, a flat figure, or nothing). We do not use this data for any other purpose, sell it, or use it to advertise. Access tokens are stored encrypted and are deleted when the practice disconnects. Patient names and contact details are not sent to Google or Meta; only the platform's own click identifier is used, unless the practice separately switches on hashed contact matching for Meta.
Lynqpod's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data (Google Ads)
This section covers the data Lynqpod receives through Google APIs when a practice connects its Google
Ads account with Google sign-in. Lynqpod asks for one permission only: Google Ads
(https://www.googleapis.com/auth/adwords).
What we access: the list of Google Ads accounts the signed-in user can reach (account id, name and currency), so the practice can choose its own; for the chosen account, each campaign's id, name and daily cost, clicks and impressions for the last 30 days; and the names of Lynqpod's own conversion actions in that account.
What we change in the Google Ads account: if they do not already exist, Lynqpod creates the conversion actions "Appointment booked" (and "Attended appointment" if the practice asks for it), and it uploads the practice's own offline click conversions to them: Google's click identifier from the advert link, the time of the booking or visit, and a value.
About that value, plainly. The practice chooses one of three things: the amount that patient actually paid, a flat figure the practice sets for every appointment of that kind, or no value at all. Where the real amount is sent it carries no name, email or phone number, but it is joined to Google's own click identifier, so Google can associate it with the person who clicked. A practice that does not want that sends a flat figure or nothing, and the adverts are still measured by appointments. Lynqpod never creates, edits or deletes campaigns, adverts, budgets, bids, keywords or users.
How we use it: only to show that practice its own advertising cost and cost per booked or attended appointment inside Lynqpod, and to report its own results back to its own Google Ads account. We do not use Google user data for advertising, to build profiles, for credit or lending decisions, or to develop, improve or train artificial intelligence or machine learning models, and we do not sell it.
With whom we share, transfer or disclose Google user data:
- The practice that connected the account: its own staff who are allowed to see Marketing in Lynqpod. It is never shown to any other practice or Lynqpod customer.
- Google: the conversion uploads described above go back only to the same Google Ads account they relate to.
- Our hosting providers, Amazon Web Services (servers) and MongoDB Atlas (database), which store and process it on our behalf, under contract, only so that Lynqpod can run, and are not allowed to use it for anything else.
- Where the law requires it, for example a valid court order, or to protect the security of the service or its users.
We do not share, transfer, sell or disclose Google user data to anyone else, including data brokers, advertising platforms (Meta included) or information resellers. No human at Lynqpod reads it except with the practice's permission for support, for security reasons, or where the law requires it.
Storage, security and deletion: the Google access token is encrypted at rest and never shown in the app. When a practice clicks Disconnect, Lynqpod revokes the token with Google and deletes it at once; the campaign cost figures already shown in its reports are deleted when the practice asks us to or when its contract ends. A user can also remove Lynqpod's access at any time at myaccount.google.com/permissions. To ask for deletion, email scott@lynqpod.com or see Data deletion.
Lynqpod's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Why we use it
- To provide the service a practice has engaged us for (its contract with us, and its own lawful bases, such as providing care and arranging appointments).
- To keep the service secure and working, and to answer enquiries (our legitimate interests).
- Where a practice chooses to send appointment results to Google or Meta, or to record visits, on the basis the practice has set out to its patients and visitors.
Who we share it with
- The practice itself, and the clinical system it uses (such as Dentally), where it has connected it.
- Service providers who run the infrastructure Lynqpod is built on, including cloud hosting (Amazon Web Services and MongoDB Atlas) and email delivery, under contract and only to provide the service.
- Google or Meta, only as described in the advertising section above and only when a practice has connected and switched it on. For Google user data specifically, see Google user data.
- Where the law requires it.
We do not sell personal data. For details of hosting locations and the safeguards that apply to them, contact scott@lynqpod.com.
How long we keep it
Patient and practice records are kept for as long as the practice keeps them in Lynqpod and removed at the practice's request or at the end of its contract. Booking-page visit statistics are deleted after about 13 months, and visitor recordings after the period the practice sets (30 days by default). Advertising access tokens are deleted when an account is disconnected.
Security
Access to Lynqpod is limited by role, and staff sign in with individual accounts. Passwords are stored hashed, and connection secrets and access tokens are encrypted at rest. Patients confirm their email address with a one-time code before a booking is sent.
Your rights
You have the right to ask for a copy of your data, to have it corrected or deleted, to object to or restrict its use, and to data portability, as UK data protection law provides. If you are a patient, contact your practice first. You can also contact us at scott@lynqpod.com, and you have the right to complain to the Information Commissioner's Office (ico.org.uk).
Changes
We will update this page when how we handle data changes, and change the date at the top.