Privacy policy
This site sets no cookies and runs no page-view analytics, advertising pixels, session recorders, or chat widgets. It keeps a small first-party attribution record for the current browser session and processes only the bounded fields submitted through the workflow review form. That form is not for patient information or PHI.
Published July 24, 2026
Updated July 25, 2026
What this policy covers
This policy covers this public website and its workflow review request. Patient information handled later under an executed business associate agreement is outside this website flow and must be governed by the applicable service agreement, BAA, and reviewed operating controls. Do not submit patient information through this website or during a pre-contract workflow review.
What happens when you read the site
Dental Revenue Desk’s pages load self-hosted fonts and site assets. They do not load an analytics SDK, tag manager, ad pixel, session recorder, or third-party chat script. The site sets no cookie.
The site is hosted on Vercel. Vercel may process standard request metadata such as IP address, request time, requested path, browser information, and server diagnostics under its own privacy policy. Application code in this repository does not add a request-body or visitor analytics log, but Vercel’s platform-level records remain outside that application boundary.
The one-session first-touch record
On the first page viewed in a browser tab, the site may place one record in first-partysessionStorage. It contains only:
- the known site path first viewed;
- allowlisted
utm_source,utm_medium, andutm_campaigntokens; and - the referring site’s hostname, when present.
The record excludes raw URLs, arbitrary query parameters, search terms, cookies, names, email addresses, and patient fields. Values must pass fixed character and length rules, and defined patient/member identifier patterns are discarded. It remains in the current browser session and is sent only if the visitor submits the workflow review form. Browser private modes may block storage; the form still works without attribution.
What the workflow review form collects
The form asks for a work email and selections for location count, practice management system, approximate monthly verification volume, and current bottleneck. It also sends the non-PHI and contact confirmations, a random submission identifier used for duplicate detection, and any safe first-touch fields described above. It has no name field, practice name field, free-text message, patient field, or file upload.
| Data | Purpose | Processor or location |
|---|---|---|
| Site request metadata | Hosting, security, and delivery | Vercel platform |
| Bounded first-touch tokens | Attribute a submitted request to its first known source | First-party browser session storage; then the submitted form |
| Work email and selected business/workflow fields | Prepare and respond to the requested workflow review | Dental Revenue Desk’s Vercel function, then Formspree and email delivery |
| HMAC-derived request key, keyed payload fingerprint, and random submission ID | Best-effort burst limiting and duplicate suppression | Temporary memory in a warm Vercel function instance |
| Accepted request in the current delivery mailbox | Receive and respond to the requested workflow review | The current working contact is syed@roadmastersins.com; the mailbox provider, tenancy, access list, and lifecycle remain an owner launch gate |
How the owned form boundary works
The browser posts to a same-origin Dental Revenue Desk endpoint before an accepted request reaches Formspree. That endpoint rejects unknown fields, arrays, duplicate URL-encoded form keys, oversized values, invalid choices, missing confirmations, and a named set of PHI-like patterns. JSON is parsed using the hosting runtime, so this policy does not claim detection of duplicate keys after JSON parsing. The endpoint forwards only normalized allowlisted fields. The application does not log the request body, email address, attribution values, IP address, user agent, origin, or processor response text.
The rate limit and duplicate cache are held in memory and reduce repeated submissions to a warm function instance. They are not a globally durable limit across regions, restarts, or separate serverless instances. For up to ten minutes, the duplicate cache stores the random submission ID and a server-keyed HMAC fingerprint derived from the normalized lead, including the email; it does not store the plaintext lead in that cache. A downstream timeout may leave delivery uncertain, so the endpoint returns an explicit ten-minute wait period and never auto-retries. A later retry can still duplicate a request already accepted by Formspree; the mechanism does not promise exactly-once delivery. Vercel still receives the HTTPS request before application validation.
Formspree and email delivery
Accepted fields are forwarded to Formspree, Inc., which processes form submissions and sends them by email. Formspree’s current privacy policy says the service may use information in the United States and other countries where it operates, describes Formspree as a service provider when processing submissions for a website, and states its own retention basis. See the Formspree privacy policy, last updated April 24, 2022.
The current working privacy contact uses the owner’s syed@roadmastersins.com mailbox on a different domain. A monitored same-domain mailbox, the final mailbox provider and tenancy, its access list, any later CRM or export, backup behavior, and the complete deletion path are operational launch dependencies that have not yet been published as completed controls. The site therefore makes no broader retention, backup, or deletion guarantee.
Do not submit patient information or PHI
Formspree’s current policy tells customers not to use the service to collect sensitive personal data. HHS cloud-computing guidance also explains that a cloud provider which creates, receives, maintains, or transmits ePHI for a covered entity or business associate is a business associate and requires a HIPAA-compliant BAA. The website form is therefore intended only for the bounded business and workflow fields shown on the page.
The absence of free text and the server checks reduce risk; they cannot prove that every work email or possible string is free of patient information. If you believe patient information was submitted, stop using the form and notify syed@roadmastersins.com. The cross-system incident, retention, and deletion procedure remains under legal and security review.
Retention and privacy requests
Dental Revenue Desk has not published a fixed retention period for workflow review requests. Formspree describes its own retention and legal exceptions in its policy. Until the complete mailbox, export, backup, correction, and deletion workflow is approved and tested, this page does not promise a fixed deletion time or a result across systems.
Privacy questions and requests can be sent to syed@roadmastersins.com. The owner will review the request against the systems actually in use and any applicable legal retention requirement; this is a contact path, not a claim that an untested cross-system process is complete.
Changes, legal review, and contact
The effective date changes when the site’s data behavior or this description changes. Legal-entity and BAA-counterparty confirmation, plus legal and security review of the website flow and offshore operating model, remain pending as of July 25, 2026. Contact Syed Ali at syed@roadmastersins.com with privacy questions.