Privacy
What we collect, where it lives, who can reach it, and how long we keep it.
Last updated: 2026-08-22
Two different relationships
Aster handles two kinds of information, and our obligations differ for each. Confusing them is the commonest error in a policy like this, so we state it first.
Clinic information — the account owner's name and email, staff profiles, billing details for the subscription, and the usage data needed to run the service. We decide what happens to this, and we are accountable for it under PIPEDA.
Patient information — appointments, clinical notes, forms, invoices, insurance details. We do not decide what happens to this. The clinic is the health-information custodian; Aster acts as its agent and service provider, and we handle patient information only on the clinic's instructions and only to provide the service. If you are a patient, your clinic is the right place to ask to see, correct, or withdraw consent for your record.
Where the data lives
Personal health information is stored and processed in Canada. The database and file storage are hosted in the Canadian region of our infrastructure provider, and application servers run in a Canadian region.
Health information is not placed in analytics, error reports, edge caches, or content delivery networks. Our error reporting scrubs identifiers before anything is transmitted, and files are served through short-lived signed links rather than a public CDN.
Two categories of ordinary business data do leave Canada, and we would rather say so than have you find it in a subprocessor list: transactional email and SMS are relayed by providers with United States infrastructure, and subscription payments (what a clinic pays us) are processed by a payment provider outside Canada. Neither carries clinical content — a reminder message says a clinic name, a date and a time.
Who else processes data for us
We use a small number of subprocessors. We do not allow a subprocessor to handle personal health information until a written data processing agreement is in place requiring confidentiality and restricting its use of the data to providing its service to us.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | Canada (ca-central-1) |
| Vercel | Application hosting | Canada |
| Stripe | Payment processing, subscription billing | United States |
| SendGrid | Transactional email | United States |
| Twilio | SMS reminders and notifications | United States |
| Inngest | Background job scheduling | United States |
| Sentry | Error reporting (scrubbed of identifiers) | United States |
We will give clinics notice before adding a subprocessor that handles personal health information.
What we collect and why
From clinic staff: name, email, phone, professional designation and licence details, and sign-in credentials. We use these to operate accounts, to print correct practitioner details on receipts and claims, and to secure access.
From patients, on the clinic's behalf: identifying and contact details, appointment history, clinical records the practitioner writes, intake forms, payment and insurance information. We collect this because the clinic asked us to hold it, and we use it only to provide the service to that clinic.
We do not sell personal information. We do not use patient information to train machine learning models. We do not use it for advertising.
Analytics and cookies
The cookies Aster sets are the ones the service needs to function: they keep you signed in, remember which clinic you are working in, and protect forms against cross-site request forgery. There is no advertising cookie and no cross-site tracker on any Aster page.
We measure how the product is used — which pages are slow, which features get reached, where a workflow is abandoned — because we would rather fix what is actually broken than guess. Three limits apply to that measurement, and they are commitments rather than intentions:
- No personal health information, ever. Analytics never receives a patient name, contact detail, health number, appointment detail, or anything written in a chart. A page is identified by its route pattern, not by the record it was displaying.
- No personal information reaches an analytics provider. Where a session has to be distinguished from another session, it is distinguished by an opaque identifier that means nothing outside our own systems — not by a name, an email address, or a clinic's patient list.
- Never for advertising. We do not build advertising profiles, run ad-network pixels, create lookalike audiences, or sell, share or broker this data. It is used to improve Aster and for nothing else.
We do not place third-party analytics on the surfaces where a patient enters health information — online booking, intake forms and the patient portal — beyond what is needed to keep those pages working and secure.
Any analytics provider we use appears in the subprocessor table above. Because none of them receives personal health information, adding one does not carry the notice obligation described there — but the limits in this section apply to every one of them, and they are terms we impose on the provider, not preferences we express to it.
Access and audit
Access is restricted by role within each clinic, and each clinic's data is isolated from every other clinic's at the database level, not only in application code.
Reads of clinical records are logged, not only changes. A clinic can see who opened a given patient's chart and when. Our own staff do not access clinic data except where a clinic asks us to for support, or where the law requires it.
How long we keep it
Clinical records are kept for as long as the clinic's account is active, because the clinic — not Aster — is subject to the professional record-retention periods that apply in its province, and those are measured in years.
When a clinic closes its account it can export everything first, in open formats, at no charge. We then delete the account data within 90 days, except where we are required to keep records longer. Sign-in sessions expire automatically.
Your rights
If you are clinic staff, you can ask us for a copy of the information we hold about you, ask us to correct it, or ask us to delete it where we are not required to keep it.
If you are a patient, contact your clinic. They hold the record and they can produce, correct, or restrict it using the tools in the product. If your clinic cannot help, we will assist them — but we will not act on a patient's record without the custodian's instruction, because we are not entitled to.
You may complain to the Office of the Privacy Commissioner of Canada, or to your provincial privacy commissioner. In Ontario, that is the Information and Privacy Commissioner of Ontario.
Breach notification
If personal health information in our care is lost, stolen, or accessed without authorisation, we will notify the affected clinic without unreasonable delay and give them what they need to meet their own notification duties. Notifying patients is the custodian's decision and duty; we support it, we do not pre-empt it.
Contact
Privacy questions: privacy@asterapp.ca
See also our Terms of Service and, for clinics, the Data Protection & Agent Agreement.