Privacy Policy
This Privacy Policy describes how jsdf, LLC collects, uses and discloses information when You use RevCanvas, and tells You about Your privacy rights. We use information to provide and improve the Service. By using the Service, You agree to the collection and use of information as described here.
Interpretation and Definitions
Capitalized words have the meanings below, whether singular or plural.
- Account means a unique account created for You to access the Service.
- Company (“the Company”, “We”, “Us” or “Our”) refers to jsdf, LLC, 1520 W. Wolfram St, Chicago, IL 60657.
- Customer means the dental practice, dental service organization or other organization that subscribes to the Service and invites Users into its Organization.
- Organization means a Customer’s workspace in the Service, including its Locations, Users and Customer Data.
- Customer Data means remittances, explanations of benefits (EOBs), EDI 835 files, claims, screenshots, notes, comments and other content submitted to the Service by or for a Customer.
- Protected Health Information (PHI) has the meaning given in the Health Insurance Portability and Accountability Act of 1996 and its regulations (HIPAA).
- Cookies are small files placed on Your Device by a website.
- Device means any device that can access the Service, such as a computer, phone or tablet.
- Personal Data is any information that relates to an identified or identifiable individual.
- Service means the RevCanvas website at https://revcanvas.com, the web application, the RevCanvas mobile app, the RevCanvas API and related services.
- Service Provider means a third party that processes data on behalf of the Company to operate, secure or support the Service.
- Usage Data means data collected automatically through use of the Service, such as the duration of a page visit.
- User or You means an individual invited by a Customer to use the Service, or a visitor to our website.
Users vs. Patient Information
We handle two kinds of information differently. User information is data about the dental team members who use RevCanvas. Patient information is PHI contained in Customer Data, such as patient names, dates of birth, subscriber IDs, procedures and payment amounts on an EOB. We process patient information only on behalf of the Customer, as described in Patient Information (PHI) below.
Information We Collect About Users
Personal Data. We collect information that identifies or contacts You, including:
- Name and email address
- Organization, role and assigned Locations
- Password (stored only in hashed form) or, if You use Sign in with Google, a Google-verified email address
- Preferences, assignments, follows, comments and a history of actions You take in the Service
- Information You submit through our demo request form, such as name, practice name, email and phone number
Usage Data. Usage Data is collected automatically. It may include Your IP address, browser type and version, the pages You visit, the time and date of Your visit, time spent on pages, device identifiers, sign-in times and counts, failed sign-in attempts and other diagnostic data.
Tracking Technologies and Cookies
We use Cookies and similar technologies to operate and analyze the Service. You can set Your browser to refuse Cookies, but You may then be unable to sign in or use parts of the Service.
- Necessary / Essential Cookies (Session Cookies, administered by Us). These authenticate Users, remember the Location You selected and prevent fraudulent use of Accounts. The Service cannot work without them.
- Functionality Cookies (Persistent Cookies, administered by Us). These remember choices such as “remember me” so You don’t have to sign in on every visit.
- Analytics. We use product analytics to understand how the Service is used, including page views and feature usage tied to Your Account. Our public website also uses Google Tag Manager to measure visits. We do not use analytics to build advertising profiles.
- Bot protection (administered by Cloudflare Turnstile). Our sign-in, password reset and demo request forms use Turnstile to block automated abuse.
Use of Your Personal Data
We may use User Personal Data to:
- Provide and maintain the Service, including monitoring its use.
- Manage Your Account, including invitations, sign-in, roles and access to Locations.
- Contact You by email about assignments, comments on records You own, password resets, invitations, security notices and changes to the Service.
- Respond to requests, including demo requests and support requests.
- Secure the Service, including rate limiting, account lockout after repeated failed sign-ins, and investigating suspected unauthorized access.
- Provide support. With authorization from the Customer or when needed to resolve a support issue, authorized Company staff may access an Organization or temporarily view the Service as a User. Every such session is logged.
- Improve the Service, including analyzing usage trends and the effectiveness of features.
- Business transfers, to evaluate or complete a merger, sale, financing or reorganization, subject to this Policy.
We do not sell Personal Data or PHI, and we do not use PHI for marketing or advertising.
Patient Information (PHI)
When a Customer uploads remittances, EOBs or 835 files, or sends them through the API or mobile app, the Customer Data may contain PHI. For that data:
- We act as a Business Associate of the Customer under HIPAA. Our handling of PHI is governed by the Business Associate Agreement (BAA) between us and the Customer, which controls over this Policy where they conflict.
- We use PHI only to provide the Service to the Customer: extracting claim and payment data, matching remittances, routing records to the right Location, preparing data for posting to the Customer’s practice management system, and supporting the Customer.
- Automated extraction. We send documents and screenshots to Google’s Gemini API to extract claim, procedure and payment data. This processing is covered by our agreements with Google and is not used to train Google’s models.
- Patients. Patients do not have Accounts. Patients who want to access, correct or delete their information should contact their dental practice, which controls that data. We will assist Customers with those requests as required by the BAA.
Sharing Your Information
We share information only in these situations:
- With Service Providers that host, process or deliver the Service under confidentiality and security obligations (and a BAA where they handle PHI).
| Service Provider | Purpose |
|---|---|
| Amazon Web Services | Hosting, file storage (S3), email delivery (SES) and message queues |
| AI document extraction (Gemini API), Sign in with Google and website analytics (Google Tag Manager) | |
| Cloudflare | Bot protection on sign-in and contact forms (Turnstile) |
- Within Your Organization. Users in the same Organization can see the records, assignments, comments and history of that Organization.
- For business transfers, in connection with a merger, sale of assets, financing or acquisition. We will give notice before Your Personal Data becomes subject to a different privacy policy.
- With Your consent, or the Customer’s consent, for any other purpose.
Retention of Your Personal Data
We retain User Personal Data for as long as Your Account is active and as needed to comply with legal obligations, resolve disputes and enforce our agreements. Usage Data is generally kept for a shorter period, unless it is used to strengthen security or improve the Service, or we are legally required to keep it longer.
We retain Customer Data, including PHI, for the term of the Customer’s subscription. After termination, we return or destroy Customer Data as set out in the Customer’s agreement and BAA.
Transfer of Your Personal Data
We store and process data in the United States. If You access the Service from outside the United States, You consent to the transfer of Your information to the United States, where data protection laws may differ from those in Your jurisdiction. We will not transfer Personal Data to an organization or country without adequate controls in place, including security of Your data.
Access, Correction and Deletion
You may ask Us to access, correct or delete the Personal Data We hold about You. Your Organization’s administrators can update or deactivate Your Account. Because Your Account belongs to the Customer, We may need to coordinate requests with the Customer. We may retain information where We have a legal obligation or lawful basis to do so.
Disclosure of Your Personal Data
Business transactions. If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred, as described above.
Law enforcement. We may disclose Personal Data if required by law or in response to valid requests by public authorities, such as a court or government agency. For PHI, we will follow the BAA and HIPAA, including notifying the Customer where permitted.
Other legal requirements. We may disclose Personal Data in the good-faith belief that it is necessary to:
- Comply with a legal obligation
- Protect and defend the rights or property of the Company
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of Users or the public
- Protect against legal liability
Usage of Your Personal Data from Google
For Users who choose Sign in with Google, we adhere to the Google API Services User Data Policy, including its Limited Use requirements. We receive only Your Google-verified email address and basic profile information, and use them to authenticate You to an Account Your Organization already created. Sign in with Google never creates a new Account.
Security of Your Personal Data
We protect data with measures including encryption in transit, access controls that separate each Organization’s data, role-based permissions, hashed passwords, account lockout after repeated failed sign-ins, and logging of staff access. No method of transmission over the Internet or electronic storage is 100% secure, and We cannot guarantee absolute security. If We discover a breach affecting PHI, We will notify the affected Customer as required by HIPAA and the BAA.
Account Security and Enforcement
We may use Account, Device, authentication and Usage Data to authenticate Users, secure Accounts, investigate suspected unauthorized access or Account sharing, prevent fraud or misuse, and enforce our Terms of Service.
Children’s Privacy
The Service is intended for dental professionals and is not directed to children under 13. We do not knowingly collect Personal Data from children as Users. Patient information about minors may appear in Customer Data and is handled as PHI under the Customer’s BAA.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the new version on this page and update the “Last updated” date. For material changes, We will notify You by email or a prominent notice in the Service before the change takes effect.
Contact Us
If You have questions about this Privacy Policy, contact us at jason@revcanvas.com or jsdf, LLC, 1520 W. Wolfram St, Chicago, IL 60657.