This policy explains how wemark ("wemark", "we", "us", or "our") collects, uses, stores, and protects information in connection with the pulse platform and the wemark website at wemark.ca. pulse is software for dental practices in Canada; wemark studio is our services arm. wemark is based in Toronto, Ontario, Canada.
This policy covers the pulse software platform (including its features, such as track) and our marketing website. If you connect a Google account to pulse, the section "Google account data" below describes exactly what we access and why.
Patient health information is handled separately. When a dental practice uses pulse, the practice, not wemark, is the health-information custodian for its patients under Ontario's Personal Health Information Protection Act (PHIPA) and comparable Canadian laws. wemark processes patient information only on the practice's behalf, under our agreement with the practice, and does not use it for our own purposes. If you are a patient, please contact your dental practice about your health records.
Who this policy is for
pulse is a business-to-business platform. Our direct users are dental practices ("clinics") and the staff a clinic authorizes to use the platform. This policy addresses the information of those clinics and users, the limited information of website visitors, and the third-party account data a clinic chooses to connect.
Information we collect
Information you provide
When a clinic signs up for or uses pulse, or contacts wemark, we may collect: the clinic's name and business details; account holder and authorized-user names, email addresses, and phone numbers; sign-in credentials; billing and subscription details; and the content of messages you send us.
Information collected automatically
When you use pulse or visit our website, we automatically collect limited technical and usage data (such as device and browser type, IP address, pages viewed, and actions taken) through cookies and similar technologies, to operate the service, keep it secure, and understand how it is used. Our marketing website uses analytics to measure traffic.
Information a clinic connects from third-party accounts
pulse's track feature lets a clinic connect its own marketing and online-presence accounts so the clinic can see its performance in one dashboard. This includes Google accounts (see below) and may include other services such as Meta. We access these accounts only after the clinic explicitly authorizes the connection, and only to display the clinic's own data back to that clinic.
Google account data
If a clinic chooses to connect its Google accounts to pulse, Google asks the clinic to grant pulse permission ("scopes"). pulse requests only the scopes it needs, uses them on a read-only basis, and uses the data solely to display the connecting clinic's own marketing performance inside pulse.
The Google permissions pulse requests, and why
- Google Business Profile (
auth/business.manage): to read the clinic's own Business Profile(s) and their performance, such as listing views, calls, direction requests, and reviews, so the clinic can see its local-search presence. We use this access only to read; we never create, edit, publish, respond to, or delete anything in the profile. Google does not offer a read-only Business Profile permission, so this is the only scope available for the read-only use described here. - Google Analytics (
auth/analytics.readonly): to read the clinic's Google Analytics (GA4) metrics, such as website sessions, traffic sources, and conversions, so pulse can show website performance and marketing return. - Google Search Console (
auth/webmasters.readonly): to read the clinic's search-performance data, such as clicks, impressions, average position, and top queries and pages, so pulse can show organic-search (SEO) performance.
What we store, and how
When a clinic connects a Google account, we store: an encrypted authorization token (a "refresh token") that lets pulse retrieve data on the clinic's behalf; the identifier and label of the account, property, or location the clinic selects; and the metric values we retrieve, so the dashboard loads quickly. The token exchange happens on our servers; we never see or store your Google password, and tokens are never written to our logs. Refresh tokens are held in an encrypted secrets vault, separate from ordinary application data.
How we use Google data, and how we do not
- We use Google account data only to display the connecting clinic's own data back to that clinic inside pulse.
- We do not sell Google data, use it for advertising, or share it with third parties for their own purposes.
- We do not use Google data to train, develop, or improve generalized artificial-intelligence or machine-learning models.
- Humans do not read your Google data except where you ask us for support, where required for security or to comply with law, or in aggregated, de-identified form to operate the service.
pulse's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting and revoking access
A clinic can disconnect a Google account at any time from within pulse's track settings; when it does, we delete the stored authorization token. You can also review and revoke pulse's access directly from your Google Account at myaccount.google.com/permissions.
How we use information
- To provide, operate, secure, and improve pulse and our services
- To set up and manage clinic accounts and authorized users
- To display each clinic's connected marketing and presence data back to that clinic
- To process billing and administer subscriptions
- To respond to your requests and provide support
- To comply with our legal and regulatory obligations
How we share information
We do not sell, rent, or trade personal information. We share information only:
- With service providers ("subprocessors") that host and operate the platform on our behalf, including our cloud hosting and database providers, under agreements that limit their use of the information to providing services to us;
- With a clinic's own authorized users, within that clinic's account;
- When required by law, legal process, or to protect the rights, safety, and security of our users, the public, or wemark; and
- In connection with a business transfer (such as a merger or acquisition), subject to this policy.
Where information is stored and how we protect it
We use reputable infrastructure providers to host pulse and store its data. We protect information with measures appropriate to its sensitivity, including encryption in transit, encryption of authorization tokens at rest in a secrets vault, access controls, and tenant isolation so one clinic cannot access another clinic's data. No method of transmission or storage is completely secure, but we work to protect your information and to limit access to those who need it.
Data retention and deletion
We keep information for as long as a clinic's account is active and as needed to provide the service, then for any additional period required to meet legal, accounting, or security obligations. When a clinic disconnects a third-party account, we delete the associated authorization token. A clinic may request deletion of its account data by contacting us at the address below; we will honour such requests subject to our legal obligations.
Your privacy rights
Subject to applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA), you may request access to the personal information we hold about you, ask us to correct it, or withdraw consent for certain uses. To exercise these rights, contact us using the details below. For patient health records, contact your dental practice, which is the custodian of that information.
International transfers
Our service providers may process or store information in countries outside Canada, including the United States. Where this occurs, the information remains subject to safeguards consistent with this policy and applicable law.
Children
pulse is a business tool intended for use by dental practices and their staff. It is not directed to children, and we do not knowingly collect personal information directly from children through the platform.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of pulse after a change takes effect means you accept the updated policy.
Contact us
If you have questions about this policy or how we handle information, contact us at:
wemark
Toronto, Ontario, Canada
privacy@wemark.ca