Privacy policy
What we collect
NurtureSite collects information you provide when creating an account, completing onboarding, and using our services. This includes your name, email, business details, website content, and form submissions from your generated websites.
Appointments and booking
When you enable online booking, visitors may provide their name, contact information, chosen service, and appointment time. If you enable deposits, payment-related metadata is processed by Stripe on your connected business account. Confirmed appointments may sync to your NurtureSite dashboard for visibility. We process this data to operate scheduling features you configure—not to sell appointment data to third parties.
Practice-software integrations
A practice administrator may authorize a read integration with supported practice-management software, currently Open Dental, to match attributed website leads and measure booked or completed appointment outcomes. NurtureSite retains in factory MySQL only keyed-hash patient and appointment references plus appointment timing and status, for 90 days. We do not retain raw PMS identifiers or clinical/chart data, and this integration data is never stored in a client-site database.
Connection credentials and metadata are application-encrypted. In the current self-hosted deployment, NurtureSite controls the encryption and hashing keys separately from routine data backups. Cloudflare terminates inbound TLS before forwarding traffic through the protected tunnel to the self-hosted application.
A future migration of this data to GCP or AWS would occur only after an applicable business associate agreement is in place and only on HIPAA-eligible services. These data-minimization and security controls do not by themselves constitute HIPAA compliance or certification.
Restaurant POS integrations
A restaurant administrator may authorize an integration with supported point-of-sale platforms, currently Toast and Omnivore (Olo), to match attributed website leads to guests and orders, sync menus and hours, and link online ordering. NurtureSite retains in factory MySQL only keyed-hash guest and order references plus order timing and status, for 90 days. We do not retain raw POS identifiers or payment card data, and POS credentials are never stored in a client-site database.
Food-order payments are processed by Toast/Olo (or the restaurant’s merchant account). NurtureSite Stripe is used for reservations and deposits you enable on the website — not for POS food orders. Vendor API location fees (for example approximately $30/location/month for Omnivore-class access) may be passed through when you enable those connections with disclosure.
Google Calendar and Microsoft Outlook sync
If you enable staff calendar sync on a website you operate through NurtureSite, an authorized administrator or staff member may connect a Google Calendar or Microsoft Outlook account. This connection is optional and initiated only by someone with access to your website admin.
What we access. With your authorization, NurtureSite uses Google Calendar and Microsoft Graph APIs to:
- Read calendar availability (free/busy) from the calendars you select, so existing events can block online booking slots and reduce double-booking.
- Read your calendar list so you can choose which calendar to use.
- Create, update, and delete calendar events on the calendar you select when appointments are confirmed, rescheduled, or cancelled through your booking system.
- Create a dedicated bookings calendar in your connected account when you choose that option.
We do not use calendar access to read email, contacts, Drive/OneDrive files, or unrelated calendar data beyond what is needed for scheduling. We do not sell calendar data.
How it works. OAuth sign-in is completed through NurtureSite's secure broker. Access tokens are stored in encrypted form with your website's scheduling configuration. NurtureSite processes this data on your behalf as part of the scheduling service you enable.
How to disconnect. An authorized user can disconnect Google or Microsoft at any time from Scheduling → Staff & hours in the website admin. Disconnecting stops new calendar reads and writes. Previously created events may remain in your external calendar until you remove them there.
Google's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Sharing, transfer, and disclosure of Google user data
This section covers Google user data NurtureSite receives through Google APIs, including Google Calendar, Google Search Console, Google Business Profile, and Google sign-in when you choose those features.
We do not sell, rent, or share Google user data with advertisers, data brokers, or information resellers. We do not transfer or disclose Google user data to third parties for advertising, retargeting, credit, lending, or to train generalized AI or ML models. We do not use Google Workspace or Calendar APIs to develop, improve, or train non-personalized AI or ML models.
We share, transfer, or disclose Google user data only as needed to provide the features you enable, and only with:
- Google, when we call Google APIs on your behalf (for example, reading free/busy times, writing a booking event to your calendar, or fetching Search Console metrics).
- You and authorized staff on the NurtureSite website admin, so you can manage scheduling, SEO Blog, and connected accounts.
- Infrastructure processors that host or transmit the service: Cloudflare (TLS, CDN, and tunnel) and NurtureSite’s self-hosted application and databases, where encrypted OAuth tokens and related scheduling or SEO records are stored solely to operate those features. See our subprocessors list.
- Legal authorities if required by law, regulation, or valid legal process.
- A successor if NurtureSite is involved in a merger, acquisition, or asset transfer, in which case Google user data would transfer under this policy.
We do not transfer or disclose Google user data to third parties for purposes other than those listed above.
How we protect it. Calendar and other Google OAuth tokens are stored encrypted. Traffic to NurtureSite is encrypted in transit (HTTPS/TLS). Access is limited to the website operator’s authorized admin users and systems needed to run the feature.
Retention and deletion. We keep Google OAuth tokens and related Google user data only while the connection is enabled. Disconnecting Google Calendar, Search Console, or Google Business Profile from website admin stops new access and we delete stored tokens for that connection. Appointment events already written to Google Calendar remain in your Google account until you remove them there. You may also request deletion by contacting us at the email below.
Google Search Console (SEO Blog)
If you connect Google Search Console for SEO Blog features, we read search performance data (queries, impressions, clicks, and average position) on your behalf using Google's API. This data is stored in your NurtureSite account and used only to suggest blog topics and show ranking context. You can disconnect Search Console at any time to stop new data collection.
How leads flow
When a visitor submits a contact form on your website, the submission is transmitted securely to NurtureSite and appears in your dashboard. We may send you email alerts for new leads. Leads are stored in your account and linked to your projects.
How we use your information
We use this information to provision and operate your websites, deliver leads to your dashboard, send account-related communications, and improve our services. We do not sell your personal information or your customers' lead data.
AI features
When you use AI content tools, we send relevant business and content context to model providers solely to generate the output you request. We do not use your lead data to train public AI models.
Website analytics (data processor)
Every NurtureSite website includes first-party analytics. We collect anonymous usage statistics on your behalf (page views, traffic sources, conversion events) only after your visitors grant consent. This data is stored in NurtureSite systems and shown in your customer dashboard. Optional third-party marketing pixels (e.g. Google Analytics, Facebook) load only when visitors consent to marketing cookies.
Retention
We retain your account data while you maintain an active account or trial. If you cancel, your website may move to preview-only status per your plan terms. Contact us if you need a copy of your data before closing your account.
Your rights
You can view leads and website content in your dashboard at any time. For questions about access to your data or account deletion, contact us using the email address listed on our website.
Subprocessors
We use trusted infrastructure and service providers to operate NurtureSite (hosting, email, payments, voice, analytics, and AI). A current list is maintained in our subprocessors documentation. We require appropriate data protection terms with vendors that process personal data on our behalf.
Contact
For questions about this policy, contact us at sales@mg.nurturesite.com.
