1 · Overview
This Privacy Policy explains how ClinicalVillage collects, uses, and protects your personal information when you use the platform.
2 · Information we collect
You give us
- Account details: name, email, password (stored hashed), phone number, role
- Profile content: school, program, specialty, credentials, license details, facility information, bio, photos, location
- Documents: professional licenses, MOUs, certifications — stored in private storage
- Messages: the body of inquiries and threaded conversations between users
- Payment: handled by Stripe — we never see or store your card number, only a customer ID and transaction metadata
We collect automatically
- Log data: IP address, browser type, pages visited, timestamps
- Cookies and similar technologies — see the Cookie Policy
3 · How we use your information
- To operate the platform and provide the matching, messaging, and subscription features you sign up for
- To verify credentials and approve listings
- To send transactional emails: verification, password reset, payment receipts, inquiry notifications
- To send occasional product updates (you can opt out anytime)
- To detect, investigate, and prevent fraud, abuse, and unauthorized access
- To comply with legal obligations
4 · How we share information
We share information only when it's necessary to operate the platform:
- With other users: only the information you explicitly publish on your profile or listing is visible to other users. Your email address is never shown publicly.
- With service providers: Stripe (payments), our email provider, our hosting provider — each is contractually bound to protect your data.
- For legal reasons: when required by law or to protect the rights and safety of ClinicalVillage and its users.
We do not sell your personal information.
5 · Where data is stored
Our database is hosted on infrastructure provided by our hosting provider. Backups are encrypted at rest and retained for a limited period for disaster recovery.
6 · Security
We use industry-standard measures to protect your information, including:
- HTTPS encryption for all data in transit
- bcrypt password hashing
- Sensitive documents stored outside the public webroot and served only through an authenticated proxy
- CSRF protection on all state-changing requests
- Rate limiting on login and other sensitive endpoints
No system is impenetrable, but we take security seriously and disclose breaches promptly when they affect you.
7 · Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Delete your account and associated data
- Export your data in a portable format
- Object to certain uses, including marketing emails
Reach us at privacy@clinicalvillage.com to exercise these rights.
8 · Retention
We keep your data for as long as your account is active. After you delete your account, we retain a minimal record (transaction history, audit logs) for a limited period to meet legal and accounting obligations.
9 · Cookies
See our Cookie Policy for details on the cookies we use.
10 · Children
ClinicalVillage is not directed to children under 18. We do not knowingly collect personal information from anyone under 18.
11 · Changes
We may update this policy. Material changes will be announced via email and a clear in-product notice at least 14 days in advance.
12 · Contact
Privacy questions? Reach us at privacy@clinicalvillage.com.