OpticianOS
Effective 31 July 2026 Version 1.0

Privacy Policy

This policy explains what information OpticianOS handles, where it is stored, who else receives it, and what you can ask us to do with it. It covers visitors to this website, the practices that use the platform, and the patient information those practices store in it.

01Who we are

OpticianOS is practice management software for independent optometry and optical practices. It is operated by Benjamin Wright, a sole proprietor based in British Columbia, Canada. In this policy, "OpticianOS", "we" and "us" mean that operator.

You can reach us at privacy@opticianos.com for any privacy question, access request, correction or complaint. A postal address is available on request.

We are subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act (PIPA).

02Two different roles

The distinction below decides who you should contact, so it comes first.

For our own purposes

When you visit this website, or when a practice signs up and its staff use the platform, we decide how that information is handled. This policy governs it directly.

On behalf of a practice

Patient information inside the platform belongs to the practice that entered it. The practice decides what is collected, who may see it, how long it is kept, and what patients are told. We hold and process that information on the practice's instructions, as its service provider — we do not use it for our own purposes.

If you are a patient of a practice that uses OpticianOS and you want to see, correct or delete your records, contact the practice directly. They control those records, and they can act on your request immediately. If you contact us instead, we will refer you to them.

03Visitors to this website

This website sets no cookies, runs no analytics and loads nothing from third-party servers — the fonts are served from our own domain. Nothing you do here is tracked or profiled, and there is no consent banner because there is nothing to consent to.

Our web server keeps ordinary access logs — IP address, the page requested, timestamp, browser user-agent — for security and troubleshooting. These are deleted on a rolling basis, normally within 30 days, and are not used to build any profile of you.

If you email us, we keep the email and our reply so we have a record of the exchange.

04Information in the platform

Patient information (held for the practice)

  • Name, date of birth, and contact details including phone number and email
  • Appointment history, bookings and reminders
  • Intake and health questionnaire responses submitted before an appointment
  • Eyeglass and contact lens prescriptions and related clinical measurements
  • Orders, work orders and lab status, purchase history, and any store credit or loyalty balance
  • A record of messages sent to the patient by the practice through the platform

Some of this is health information and we treat all of it as sensitive.

Practice and staff information

  • Staff name, work email, role and permissions
  • Authentication data — passwords are stored only as salted hashes, never in a readable form
  • An audit trail of significant actions taken in the system, which exists precisely so a practice can see who did what
  • Practice details: locations, opening hours, inventory, and business performance figures

05Why we handle it

We handle information only to provide and support the service the practice has asked for:

  • Running the practice's bookings, records, dispensing and point-of-sale workflows
  • Sending the appointment reminders, confirmations and recall notices the practice configures
  • Showing the practice its own business analytics
  • Keeping the service secure, diagnosing faults, and taking backups
  • Meeting our legal obligations

We do not sell personal information. We do not share it with data brokers, we do not use it for advertising, and we do not use patient information to develop or market our product.

06Where it is stored

The platform and its database run on servers located in Toronto, Ontario, Canada, operated by DigitalOcean. Patient information is stored there.

Traffic to and from the platform is encrypted with TLS. Credentials for connected services — such as a practice's payment or Google connections — are additionally encrypted at rest.

Backups are encrypted on our server before they are uploaded, then stored with an offsite backup provider (Backblaze) whose facilities may be outside Canada. Because the encryption happens first, that provider holds only ciphertext and has no ability to read the contents. We periodically test that backups can actually be restored.

07Who else receives it

We use the service providers below. Each receives only what it needs for its function. Several are located in the United States, which means the information they hold may be accessible to authorities there under the laws of that country.

Service providers
ProviderPurposeWhat it receivesLocation
DigitalOceanHosting and databaseAll platform dataCanada
BackblazeOffsite backupsEncrypted backups only — unreadable to the providerUnited States
TwilioText messagingPatient mobile number and the message content sentUnited States
Anthropic, OpenAIAI assistance for staffOperational and business data only — patient records are blocked (see section 8)United States
GoogleBusiness Profile, Search Console, AnalyticsThe practice's own business listing and website traffic data — no patient informationUnited States
Cal.comOnline appointment bookingName, contact details and requested appointment timeUnited States
Square, Clover, Shopify, StripePayment processing, where the practice connects oneTransaction details; card data goes to the processor, not to usUnited States

We may also disclose information if the law requires it — for example a court order or a valid demand from a regulator — or to establish or defend a legal claim. If a practice's account is ever transferred as part of a sale of the business, we would notify practices first.

08Artificial intelligence

The platform includes AI features that help staff with operational work: drafting a message, summarising business performance, suggesting a reply to a public review.

Patient records are not sent to AI providers. This is enforced in two places rather than left to policy: the AI assistant is not given any tool that can read patient records, and an outbound guard inspects every request at the network boundary and blocks it if patient data is present. A record of the block is kept.

Other things worth stating plainly:

  • Data we send to these providers through their APIs is not used to train their models.
  • AI output is a draft. Staff review it, and nothing reaches a patient without a person approving it.
  • AI features do not provide clinical or medical advice and are not used to make clinical decisions.

09Data received from Google

A practice may connect its Google account so that OpticianOS can show its marketing and visibility data in one place. Connecting is optional, and the practice chooses to do it.

What we ask for, and why

  • Business Profile (business.manage) — to read the practice's own Business Profile, its performance figures and its reviews, and to publish posts or review replies that the practice has approved.
  • Search Console (webmasters.readonly) — read-only access to the practice's website search performance.
  • Google Analytics (analytics.readonly) — read-only access to the practice's website traffic figures.

All of this is information about the practice's own business — its listing, its website, its traffic. It contains no patient information, and we never send patient information to Google.

How we use it

Solely to provide the features the practice connected it for: displaying analytics and visibility reporting in the practice's own dashboard, and drafting Business Profile content that a staff member reviews and approves before anything is published. We do not use it for advertising, we do not sell it, we do not transfer it to anyone except the service providers in section 7 as needed to run the service, and we do not use it to train AI models.

OpticianOS's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Withdrawing access

A practice can disconnect Google at any time from the Connections page inside OpticianOS, or revoke our access directly at myaccount.google.com/permissions. On disconnection we delete the stored access and refresh tokens immediately, and delete data retrieved from Google within 30 days.

10Text messages

The platform sends appointment reminders, confirmations and recall notices by text on the practice's behalf, through Twilio. The practice decides who is messaged and is responsible for having the patient's consent, including under Canada's anti-spam legislation.

Message content is limited to what the notice requires. Patients can stop messages by replying STOP, or by asking the practice.

11How long we keep it

Patient information is kept for as long as the practice's account is active, and for as long as the practice's own retention obligations require — optometry practices in British Columbia must keep clinical records for periods set by their regulator, and the practice, not us, decides that.

When a practice closes its account we make its data available for export, then delete it from our live systems within 30 days. Encrypted backups age out on their own rotation, normally within 90 days, after which the data is gone from those too.

Website access logs: normally 30 days.

12Security

Measures currently in place include:

  • TLS encryption for all traffic, and encryption at rest for connected-service credentials
  • Role-based access control, so staff see only what their role allows
  • Rate limiting and automatic account lockout after repeated failed sign-in attempts
  • An audit trail of significant actions
  • Encrypted offsite backups, with restores tested rather than assumed
  • Each practice's data isolated from any other's

We will not claim more than that. No system is perfectly secure, we hold no third-party security certification such as SOC 2 or ISO 27001, and we are not a HIPAA-regulated entity — that is United States law and it does not apply to a Canadian practice.

13Your rights

Under PIPEDA and BC PIPA you may ask to see the personal information we hold about you, ask us to correct it if it is wrong, ask how it has been used and who it has been given to, and withdraw consent where consent is the basis for handling it.

Write to privacy@opticianos.com. We will respond within 30 days, without charge in ordinary cases. We may need to confirm your identity first. If we cannot act on a request, we will tell you why.

Again: if your information is in a practice's records, ask the practice — it holds those records and can act faster than we can.

14If something goes wrong

If a breach of security safeguards occurs that creates a real risk of significant harm, we will notify the affected practices without unreasonable delay, along with what we know and what we are doing about it, and report to the Office of the Privacy Commissioner of Canada and the Office of the Information and Privacy Commissioner for British Columbia as required. Practices are responsible for notifying their own patients, and we will give them what they need to do so.

15Children

This website is not directed at children, and we do not knowingly collect information from them through it. Practices do treat minors, and a patient record may relate to a child — that record is created and controlled by the practice under its own consent process, and the practice is responsible for obtaining consent from a parent or guardian where required.

16Changes

If we change this policy we will update the effective date at the top and post the new version here. For changes that materially affect how information is handled, we will notify practices directly before the change takes effect.

17Contact and complaints

Questions, requests and complaints: privacy@opticianos.com. We would rather hear a complaint directly and fix it.

You also have the right to complain to a regulator:

  • Office of the Privacy Commissioner of Canada — priv.gc.ca
  • Office of the Information and Privacy Commissioner for British Columbia — oipc.bc.ca

Terms of Service →