Privacy Center
Your privacy, in plain language.
This page shows every cookie and tracking technology our website can use, what each one is allowed to see, and how to change your choices. Nothing beyond what's strictly necessary runs until you turn it on.
How we protect health-related browsing
- Nothing optional loads first. Analytics and advertising technologies stay switched off until you choose to allow them — ignoring the banner keeps them off.
- Treatment and condition pages, and the whole appointment request process, are treated as sensitive: advertising technologies are blocked there even if you have allowed advertising elsewhere.
- What you type into a form never leaves this site for an analytics or advertising platform. We only ever record that a request was started or completed.
- Web addresses are cleaned before measurement. Only these link tags are kept:
utm_source, utm_medium, utm_campaign, utm_term, utm_content, page. Anything else, including search terms, names and email addresses in a link, is removed. - Other sites never receive the address of the page you came from, and the map is only contacted after you press "Load map".
- We do not use session recording, heatmaps, keystroke capture, or chat/scheduling widgets that could capture what you type.
Cookie and technology inventory
Any technology not listed here is blocked by our security policy.
Tooth Acres Dentistry (first party)
In use · essentialStores your cookie choices, accessibility preferences, and a bot/human verdict used to keep analytics honest.
- ta_cookie_consent
- — our site, Until cleared (localStorage)
- ta_cookie_anon_id
- — our site, Until cleared (localStorage)
- ta_a11y_settings
- — our site, Until cleared (localStorage)
- ta_visitor
- — our site, 30 minutes (cookie)
Never shared with it: names; emails; phone numbers; form values; health information
Lovable Cloud (Supabase) — hosted backend
In use · essentialReceives and stores appointment requests and consent records so the office can respond.
Never shared with it: advertising identifiers; analytics identifiers
Processes prospective-patient contact details. BAA / LEGAL REVIEW REQUIRED before treating as HIPAA-eligible storage.
Google Maps (embed)
In use · functionalShows the office location and driving directions.
- Google cookies (third party)
- — third party, Set by Google
Never shared with it: referrer URL; form values; appointment details
Click-to-load only. Nothing is requested from Google until the visitor presses 'Load map', and the iframe sends no referrer.
Google Analytics 4
Not currently running · analyticsAggregate page and traffic measurement to improve the site.
- _ga
- — our site, 2 years
- _ga_<container>
- — our site, 2 years
Never shared with it: form values; appointment reason / message; symptoms, diagnoses, medications, insurance; email, phone, name; unsanitized URLs or page titles; Google Signals / ad personalization / remarketing
Loads only after ANALYTICS consent. ad_storage, ad_user_data and ad_personalization are denied and Google Signals is disabled, so analytics data cannot build advertising audiences.
Google Tag Manager
Not currently running · analyticsTag container for analytics tags only.
Never shared with it: any advertising tag; form values; unsanitized URLs
Loaded only after ANALYTICS consent and only with Consent Mode defaults already denied, so container tags cannot fire outside their permitted category. MANUAL VERIFICATION REQUIRED inside the GTM UI that no advertising tags exist in the container.
Meta (Facebook) Pixel
Not currently running · advertisingAdvertising measurement.
- _fbp
- — our site, 3 months
- fr
- — third party, 3 months
Never shared with it: any healthcare-sensitive page view; Lead / Schedule / Contact conversion events; advanced matching identifiers (hashed or not); form values; appointment details
Hard-blocked on all healthcare-sensitive pages and in the appointment workflow, even with advertising consent. No advanced matching, no conversion events. LEGAL/PRIVACY OFFICER REVIEW REQUIRED before enabling an ID.
Session replay / heatmaps (Hotjar, Clarity, FullStory, etc.)
Not used / removed · analyticsNone — not used.
Never shared with it: everything — no session replay, heatmap, or keystroke capture is permitted
No session replay, heatmap, mouse-tracking or form-analytics vendor exists in this codebase, and the CSP blocks their domains.
Google reCAPTCHA
Not used / removed · essentialNone — not used. Spam is handled by a honeypot field and server-side validation.
Never shared with it: form values
CSP allowances for reCAPTCHA were removed since no reCAPTCHA is loaded.
Questions or requests
To ask what information we hold, correct it, or have it deleted, email office@toothacresmountdora.com or call (352) 383-4414. These technical measures reduce privacy risk; they are not a legal opinion, and our privacy officer and counsel review them.