Privacy Policy
Last updated June 23, 2026
This Privacy Policy explains how Mintpath (“MintClinic,” “we,” “us”) collects, uses, and protects information when you use the MintClinic platform and websites. MintClinic is software for hearing-care clinics. For protected health information (PHI) that a clinic stores in MintClinic, the clinic is the HIPAA Covered Entity and we act as its Business Associate under a signed Business Associate Agreement (see our BAA).
Information we collect
Account and clinic data
Names, work email addresses, role assignments, clinic names and locations, and billing details you provide when you create or administer a workspace.
Patient information (on behalf of clinics)
When a clinic uses MintClinic, it stores patient records, appointments, audiograms, clinical notes, orders, and claims. We process this PHI only to serve that clinic under our BAA. We never use it for our own purposes or sell it.
Usage and device data
Log data such as IP address, browser type, pages viewed, and timestamps, used to operate, secure, and improve the service.
How we use information
- To provide, maintain, and secure the MintClinic platform.
- To authenticate users and enforce per-tenant access controls.
- To process subscription billing through our payment processor.
- To provide support and communicate about your account.
- To detect, prevent, and respond to fraud, abuse, and security incidents.
How we protect information
- Isolation: every database query is scoped to a single clinic using PostgreSQL row-level security.
- Encryption: TLS with verified certificates in transit; AES-256 at rest.
- Access control: least-privilege roles, multi-factor authentication, and an immutable, hash-linked audit log of access to clinical records.
- Secrets: credentials are stored in a managed vault, never in source code.
Sharing and subprocessors
We do not sell personal information. We share data only with vetted subprocessors that help us run the service (cloud hosting, database, authentication, and payment processing), each bound by contractual confidentiality and security obligations. A current list of subprocessors is available on request.
Data retention
We retain clinic and patient data for as long as the clinic maintains its account, and afterward only as required to comply with legal obligations. On termination, PHI is returned or destroyed in accordance with the BAA.
Your rights
Patients should direct requests to access, correct, or delete their records to their clinic, which controls that data. For account information we hold directly, contact us using the details below.
Cookies
We use strictly necessary cookies for authentication and session security. We do not use advertising cookies.
Changes
We may update this policy and will revise the “last updated” date above. Material changes will be communicated to account administrators.
Contact
Questions about this policy: privacy@mintpath.ai.
This document describes our current practices in plain language. It is provided for transparency and is not legal advice; the controlling terms for any clinic are those in its executed agreements with Mintpath.