Privacy Policy
Last Updated: December 4, 2025
GetExpanded ("us", "we", or "our") operates the GetExpanded website at www.getexpanded.org (the "Service"). This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data. GetExpanded is operated by 13738248 Canada Inc.
We use your data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this policy.
1. Medical Disclaimer
IMPORTANT: We are not doctors or medical professionals. GetExpanded is not a medical service provider and does not provide medical advice, diagnosis, or treatment. The information provided on our website is for informational purposes only and is not intended to be a substitute for professional medical advice, diagnosis, or treatment regarding palatal expansion, airway health, jaw development, sleep apnea, or any other medical conditions.
2. Information Collection and Use
We collect several different types of information for various purposes to provide and improve our Service to you.
Types of Data Collected
2.1 Account Data
When you create an account on our Service, we collect:
- Email address
- Password (encrypted and securely stored)
- Account creation date
- Authentication tokens and session data
Account data is stored securely using Supabase authentication services. We use industry-standard encryption and security practices to protect your account information.
2.2 Provider Submission Data
When you submit provider information through our provider submission form, we collect:
- Provider name and type (orthodontist, surgeon, therapist, sleep doctor)
- Location information (country, state/province, city)
- Website information
- Device types and services offered
- Additional notes about the provider
Our provider submission form allows for anonymous submissions. We do not require personal information from users submitting provider information to our directory. All submissions are reviewed before being published.
2.3 Provider Dashboard Data
When you use the Provider Dashboard to manage listings, we collect:
- Listing claim requests and verification information
- Provider profile updates and edits
- Premium listing customizations (logo, banner, video, social links)
- Dashboard activity and usage patterns
2.4 Payment and Subscription Data
When you subscribe to Premium Listings, payment processing is handled by our third-party payment processor, Dodo Payments. We collect and store:
- Customer ID for subscription management
- Subscription status and billing period
- Payment history references
We do not store full credit card numbers, CVV codes, or other sensitive payment details. All payment information is processed and stored securely by Dodo Payments in accordance with PCI-DSS standards. Please refer to Dodo Payments' privacy policy for information about how they handle your payment data.
2.5 Provider Directory Information
Our Service includes a comprehensive directory of providers specializing in:
- Palatal expansion devices (RPE, MSE, MARPE, DOME, SARPE, FME, FMA)
- Airway orthodontics and facial development
- Jaw surgery and oral & maxillofacial surgery
- Myofunctional therapy
- Sleep medicine and sleep apnea treatment
This information may include provider names, locations, websites, services offered, devices provided, patient notes, and verification status. This information is collected from various sources, including direct submissions from providers and users. By submitting provider information to our directory, you consent to the public display of that information on our Service.
2.6 Website Analytics and Usage Data
We may collect information on how the Service is accessed and used ("Usage Data"). This Usage Data may include information such as your computer's Internet Protocol address (e.g., IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers, and other diagnostic data.
2.7 Provider Listing Analytics
For provider listings, we collect analytics data to help providers understand how their listings are performing. This includes:
- Listing impressions: When a listing appears in search results
- Profile views: When a user visits a provider's profile page
- Website clicks: When a user clicks on the provider's website link (Premium only)
- Social media clicks: When a user clicks on social media links, tracked by platform (Premium only)
- Traffic sources: How users found the listing (search, direct, location pages) (Premium only)
- Geographic data: General region/country of visitors based on IP address (Premium only)
This analytics data is aggregated and provided to providers who have claimed their listings. Basic analytics (impressions and profile views) are available to all claimed listings. Premium analytics are available only to premium listing subscribers. Analytics data is retained for up to 24 months.
2.8 Cookies and Session Data
We use cookies and similar tracking technologies to maintain your session and provide a personalized experience. These include:
- Authentication cookies: To keep you logged in and secure your session
- Preference cookies: To remember your settings and preferences
- Analytics cookies: To understand how you use our Service and improve it
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service, including the Provider Dashboard.
2.9 Community Platform Integration
We operate a Discord community server for users to connect and share experiences. When you join our Discord community, you are subject to Discord's privacy policy and terms of service in addition to our own.
2.10 Email Communication Preferences
When you create an account with GetExpanded, you have the option to opt in to receive marketing and promotional emails. We collect and store:
- Your email opt-in/opt-out preference
- Whether you have subscribed to receive marketing communications
- Your email communication history with us
This preference is stored in our database and used to manage which communications we send to you. You can change your email preferences at any time through your account settings or by clicking the unsubscribe link in any marketing email.
3. Use of Data
GetExpanded uses the collected data for various purposes:
- To provide and maintain the provider directory service
- To create and manage your user account
- To authenticate your identity and secure your account
- To process and review provider submissions
- To verify listing claims and manage provider access
- To process Premium subscription payments and manage billing
- To verify provider information and maintain directory accuracy
- To improve our search and filtering functionality
- To create and maintain SEO-optimized provider profiles and device pages
- To generate sitemaps and improve website discoverability
- To provide customer support and respond to inquiries
- To analyze website usage and improve user experience
- To create and publish blog content about airway health and expansion devices
- To detect, prevent and address technical issues
- To send service-related communications (account verification, subscription updates)
3.1 Email Communications
GetExpanded sends emails for the following purposes:
- Transactional emails: Account verification, listing submission approvals, claim approvals, subscription notifications, and account updates
- Notification emails: Important updates about your submissions, claims, and Premium subscriptions
- Marketing emails: Platform updates, feature announcements, listing-related news, and relevant opportunities (sent only with your opt-in consent)
All transactional and notification emails are essential for account management and service delivery. You cannot opt out of these communications. Marketing emails are optional and sent only to users who have explicitly opted in. You can unsubscribe from marketing emails at any time.
3.2 Email Service Provider - Resend
We use Resend as our email service provider for sending transactional, notification, and marketing emails. Resend processes your email address and email content on our behalf and complies with email marketing regulations, including CAN-SPAM and CASL (Canada's Anti-Spam Legislation).
When we send emails through Resend, your email address and any identifying information necessary for email delivery may be processed by Resend. Please refer to Resend's privacy policy for information about how they handle your data.
4. Data Storage and Processing
Our provider data, user accounts, and application data are stored securely in our Supabase database. Provider submissions are processed through our API and reviewed before publication. We use Vercel's hosting infrastructure, which may involve data processing in various global locations.
5. Data Retention
We retain your personal data only for as long as necessary for the purposes set out in this Privacy Policy:
- Account data: Retained until you delete your account or request deletion
- Provider listings: Retained until removed by the provider or GetExpanded
- Payment records: Retained as required by applicable tax and accounting laws
- Usage data: Retained for up to 24 months for analytics purposes
6. Data Protection and Scraping Prevention
We implement measures to protect our data and prevent unauthorized scraping or harvesting of our provider directory. Automated data collection, scraping, or harvesting of our website content is strictly prohibited without our express written consent.
7. Transfer of Data
Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.
If you are located outside Canada and choose to provide information to us, please note that we transfer the data, including Personal Data, to Canada and process it there.
Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
13738248 Canada Inc. will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.
8. Disclosure of Data
8.1 Legal Requirements
GetExpanded may disclose your Personal Data in the good faith belief that such action is necessary to:
- To comply with a legal obligation under Canadian law
- To protect and defend the rights or property of 13738248 Canada Inc.
- To prevent or investigate possible wrongdoing in connection with the Service
- To protect the personal safety of users of the Service or the public
- To protect against legal liability
9. Security of Data
The security of your data is important to us. We implement appropriate technical and organizational security measures to protect your personal data, including:
- Encryption of data in transit using HTTPS/TLS
- Secure password hashing and storage
- Regular security updates and monitoring
- Access controls and authentication requirements
However, remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
10. Your Privacy Rights
Under Canadian privacy legislation, including PIPEDA (Personal Information Protection and Electronic Documents Act), you have certain rights regarding your personal information:
- The right to access personal information we have about you
- The right to correction of inaccurate or incomplete personal information
- The right to deletion of your account and associated personal data
- The right to withdraw consent where we rely on your consent to process personal information
- The right to data portability to receive your data in a structured format
- The right to complain to the Privacy Commissioner of Canada if you believe we have violated your privacy rights
To exercise any of these rights, please contact us using the information provided below. We may ask you to verify your identity before responding to such requests.
11. Third-Party Services
We may employ third-party companies and individuals to facilitate our Service:
- Vercel - Website hosting and infrastructure
- Supabase - Database, authentication, and backend services
- Dodo Payments - Payment processing for Premium subscriptions
- Discord - Community platform integration
- Resend - Email service provider for transactional, notification, and marketing emails
These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose. We encourage you to review the privacy policies of these third-party services.
12. Links to Other Sites
Our Service contains links to provider websites and other sites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.
We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services, including provider websites listed in our directory.
13. Children's Privacy
Our Service does not address anyone under the age of 18 ("Children").
We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.
14. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top of this Privacy Policy.
For significant changes, we may also notify you by email if you have an account with us. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
15. Contact Us
If you have any questions about this Privacy Policy, please contact us:
- By email: getexpanded@proton.me
- Through our Discord community server