Privacy Center

Your privacy, in plain language.

This page shows every cookie and tracking technology our website can use, what each one is allowed to see, and how to change your choices. Nothing beyond what's strictly necessary runs until you turn it on.

How we protect health-related browsing

  • Nothing optional loads first. Analytics and advertising technologies stay switched off until you choose to allow them — ignoring the banner keeps them off.
  • Treatment and condition pages, and the whole appointment request process, are treated as sensitive: advertising technologies are blocked there even if you have allowed advertising elsewhere.
  • What you type into a form never leaves this site for an analytics or advertising platform. We only ever record that a request was started or completed.
  • Web addresses are cleaned before measurement. Only these link tags are kept: utm_source, utm_medium, utm_campaign, utm_term, utm_content, page. Anything else, including search terms, names and email addresses in a link, is removed.
  • Other sites never receive the address of the page you came from, and the map is only contacted after you press "Load map".
  • We do not use session recording, heatmaps, keystroke capture, or chat/scheduling widgets that could capture what you type.

Cookie and technology inventory

Any technology not listed here is blocked by our security policy.

Tooth Acres Dentistry (first party)

In use · essential

Stores your cookie choices, accessibility preferences, and a bot/human verdict used to keep analytics honest.

ta_cookie_consent
our site, Until cleared (localStorage)
ta_cookie_anon_id
our site, Until cleared (localStorage)
ta_a11y_settings
our site, Until cleared (localStorage)
ta_visitor
our site, 30 minutes (cookie)

Never shared with it: names; emails; phone numbers; form values; health information

Lovable Cloud (Supabase) — hosted backend

In use · essential

Receives and stores appointment requests and consent records so the office can respond.

Never shared with it: advertising identifiers; analytics identifiers

Processes prospective-patient contact details. BAA / LEGAL REVIEW REQUIRED before treating as HIPAA-eligible storage.

Google Maps (embed)

In use · functional

Shows the office location and driving directions.

Google cookies (third party)
third party, Set by Google

Never shared with it: referrer URL; form values; appointment details

Click-to-load only. Nothing is requested from Google until the visitor presses 'Load map', and the iframe sends no referrer.

Google Analytics 4

Not currently running · analytics

Aggregate page and traffic measurement to improve the site.

_ga
our site, 2 years
_ga_<container>
our site, 2 years

Never shared with it: form values; appointment reason / message; symptoms, diagnoses, medications, insurance; email, phone, name; unsanitized URLs or page titles; Google Signals / ad personalization / remarketing

Loads only after ANALYTICS consent. ad_storage, ad_user_data and ad_personalization are denied and Google Signals is disabled, so analytics data cannot build advertising audiences.

Google Tag Manager

Not currently running · analytics

Tag container for analytics tags only.

Never shared with it: any advertising tag; form values; unsanitized URLs

Loaded only after ANALYTICS consent and only with Consent Mode defaults already denied, so container tags cannot fire outside their permitted category. MANUAL VERIFICATION REQUIRED inside the GTM UI that no advertising tags exist in the container.

Meta (Facebook) Pixel

Not currently running · advertising

Advertising measurement.

_fbp
our site, 3 months
fr
third party, 3 months

Never shared with it: any healthcare-sensitive page view; Lead / Schedule / Contact conversion events; advanced matching identifiers (hashed or not); form values; appointment details

Hard-blocked on all healthcare-sensitive pages and in the appointment workflow, even with advertising consent. No advanced matching, no conversion events. LEGAL/PRIVACY OFFICER REVIEW REQUIRED before enabling an ID.

Session replay / heatmaps (Hotjar, Clarity, FullStory, etc.)

Not used / removed · analytics

None — not used.

Never shared with it: everything — no session replay, heatmap, or keystroke capture is permitted

No session replay, heatmap, mouse-tracking or form-analytics vendor exists in this codebase, and the CSP blocks their domains.

Google reCAPTCHA

Not used / removed · essential

None — not used. Spam is handled by a honeypot field and server-side validation.

Never shared with it: form values

CSP allowances for reCAPTCHA were removed since no reCAPTCHA is loaded.

Questions or requests

To ask what information we hold, correct it, or have it deleted, email office@toothacresmountdora.com or call (352) 383-4414. These technical measures reduce privacy risk; they are not a legal opinion, and our privacy officer and counsel review them.