This Privacy Policy explains how TherapyLink (“we”, “us”, “our”) — based in British Columbia, Canada— collects, uses, shares, and protects personal information when you use the TherapyLink website and application at therapylink.ca and app.therapylink.ca(collectively, the “Service”).
We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and the British Columbia Personal Information Protection Act (PIPA).
Questions? Contact our Privacy Officer at privacy@therapylink.ca.
1. Who we are
TherapyLink is a Canadian directory and matching service that helps patients find independent mobile (in-home) therapy practitioners offering services such as physiotherapy, massage therapy, and IV therapy. We do not provide health care services directly. Care is provided by the independent practitioners listed on our platform, who are responsible for their own clinical practice, licensing, and insurance.
2. Information we collect
2.1 Information you provide directly
- Account information— name, email address, phone number, password (stored as a hash, never in plaintext)
- Health-related preferences— the type of therapy you are seeking, brief health context you choose to share, and the number of people who will receive the service. We treat this as sensitive information.
- Location information— the city or service area you enter so we can match you with practitioners
- Booking information— appointments you initiate through the Service
- Communications— messages you send to practitioners through the in-app chat
- Practitioner profile information(if you register as a practitioner) — your credentials, biography, photo, languages spoken, service areas, pricing, and availability
2.2 Information collected automatically
- Device type, browser, IP address, approximate geographic location (city level), interaction logs, and a small number of cookies (see Section 9)
2.3 Google account information (practitioners only)
If you are a practitioner and choose to connect a Google account to sync your availability, we receive limited Google user data via the Google Calendar API. See Section 5 for details and your rights.
3. How we use your information
We use your personal information to:
- Match you with practitioners who serve your area and offer the service you need
- Enable communication between you and a practitioner via the in-app chat
- Facilitate booking by handing you off to our booking partner, Jane App
- Send transactional emails such as account creation, password reset, and message notifications
- Prevent fraud, abuse, and misuse of the platform
- Improve the Service and develop new features
- Meet legal obligations
We do not use your information for advertising, do not profile you for marketing, and do not sell your information to third parties.
4. Legal basis for processing
- Consent— for sensitive information including health-related preferences and Google Calendar data
- Contract— to provide the Service you've signed up for
- Legitimate interests— for fraud prevention and platform safety
- Legal obligation— when required by applicable Canadian law
5. Use of Google user data
When a practitioner connects their Google account, TherapyLink requests access to Google Calendar. We use this access solely to:
- Read existing calendar events to determine practitioner availability (so that TherapyLink does not double-book the practitioner against existing commitments)
- Create new calendar events corresponding to bookings made through TherapyLink, on the practitioner's primary calendar
TherapyLink's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, we:
- Do not use Google user data for serving advertisements
- Do not sell or transfer Google user data to third parties for advertising or other unrelated purposes
- Do not allow humans to read Google user data except in narrowly-permitted cases (e.g., with explicit user consent for support, or as required for security or legal compliance)
- Do not store more Google user data than is necessary to provide the Service
A practitioner may revoke TherapyLink's access to their Google account at any time via https://myaccount.google.com/permissions or by disconnecting from within the TherapyLink practitioner portal. When access is revoked, we delete the stored OAuth tokens promptly.
6. How we share your information
We share personal information only as needed, with:
- Practitioners you contact— your name, contact details you provide, the search/booking context you submit, and the chat messages you send
- Jane App, for booking handoff— the appointment details required to complete the booking on Jane, governed by Jane's privacy policy at janeapp.com/privacy
- Service providers that help us operate the Service — including Vercel (hosting), Supabase (database), our transactional email provider, Google (Calendar API only for connected practitioners), and our DNS provider. These providers process information on our behalf under written agreements.
- For legal reasons— where required by valid legal process, to protect rights, safety, or property, or to comply with applicable law
We do not sell personal information.
7. Retention
- Account information: while active + 12 months after closure
- Chat messages: 24 months
- Google Calendar OAuth tokens: until you revoke access or close your account, whichever comes first
- Server logs and operational data: 90 days
You may request deletion of your account at any time (see Section 8).
8. Your rights
Under PIPEDA and BC PIPA, you have the right to:
- Access the personal information we hold about you
- Correct information that is inaccurate or incomplete
- Withdraw consent for processing, subject to legal or contractual exceptions
- Request deletion of your account and associated information
- Lodge a complaint with the Office of the Privacy Commissioner of Canada or the BC Office of the Information and Privacy Commissioner
To exercise any of these rights, email privacy@therapylink.ca. We will respond within 30 days.
9. Cookies and similar technologies
We use a small number of cookies to keep you signed in, remember your session, and protect against cross-site request forgery. We do not use third-party advertising or tracking cookies. You may disable cookies in your browser, but parts of the Service may not function properly.
10. Security
- HTTPS encryption in transit
- Hashing of authentication credentials
- Access controls on our database and infrastructure
- Standard operational security practices
No system is perfectly secure. If we become aware of a breach involving your personal information, we will notify you and the relevant regulator as required by law.
11. Children
The Service is not directed to children under 16. We do not knowingly collect information from children under 16 without parental or guardian consent. If you believe a child has provided us with information, contact privacy@therapylink.ca and we will delete it.
12. International data transfers
Some of our service providers (e.g., Supabase, Google) may process data outside Canada, including in the United States. By using the Service, you understand that your information may be processed in jurisdictions with different privacy laws. We require these providers to maintain protection standards comparable to those required under Canadian law.
13. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top will reflect the most recent change. Material changes will be communicated by email to registered users or by a prominent notice within the Service.
14. Contact
Privacy Officer
TherapyLink
British Columbia, Canada
Email: privacy@therapylink.ca