Who we are
TMJDirectory ("we," "us") is an independent, U.S.-operated directory of TMJ/TMD-focused providers, owned and operated by Stanley Wellness LLC. This one policy covers everything on tmjdirectory.com: the provider directory and all of our educational content — articles, guides, facts pages, the glossary, quizzes, and self-assessments. One site, one operator, one policy. Contact: [email protected] or the contact form.
Reading our content collects nothing about you beyond the aggregate analytics described below — no account, sign-up, or personal information is required to use any educational page on this site.
What we collect
If you're a visitor
- Voluntary submissions: What you enter in the contact form (name, email, phone, message, opt-in choices) or the symptom-routing quiz (name, email, symptom checkboxes, and the resulting educational pattern).
- Search & browsing: A random session ID in your browser so favorites and card views work without identifying you; the general searches you run (location, specialty); and brief IP logging for security and rate-limiting.
- Analytics (only with your consent): Google Analytics loads only if you accept it in our cookie banner; declining or ignoring the banner means no analytics script runs and no analytics cookie is set. If accepted, we see aggregate traffic — pages visited, rough geography, device type. See the Cookie Policy to change your choice.
If you're a provider
- Listing information: Name, credentials, specialty, business name, address, phone, email, website, social handles, bio, photos, schedule link, tags, insurance participation. Some may have been compiled from public sources before you claimed the listing; once claimed, it's yours to correct or remove.
- Verification information: When requested, license number, issuing state, expiration, and NPI — used only to verify your listing.
- Account data: Your email for magic-link sign-in (we never store passwords) and sign-in timestamps.
- Listing analytics: Aggregate counts of how visitors interact with your card (views, clicks, favorites) — shown to you in your dashboard.
What we deliberately do NOT collect
TMJDirectory is a directory, not a medical records system. We do not ask for and do not want: diagnoses, treatment history, imaging (MRI/X-ray), intake forms, insurance ID numbers, or Social Security numbers. Please do not include medical details in contact-form messages beyond what's needed to route your question. Clinical information belongs with the provider you choose, under their own privacy practices. Our quiz collects only symptom checkboxes for educational routing — not a medical questionnaire tied to care.
Why we collect it (and our legal bases)
- To operate the directory: show listings, run search, respond to messages (performance of our service to you).
- To send transactional email: sign-in links, claim confirmations, application receipts (necessary for the service).
- To send marketing only where you opted in — newsletter and area-claim alerts (consent; withdraw any time via the unsubscribe link).
- To keep the site safe: spam prevention, abuse and fraud detection (legitimate interest).
- To improve the site with aggregate analytics (legitimate interest, minimized).
AI usage
We use AI tools to help build the site — drafting and editing educational content (always subject to human review), generating site artwork and icons, and writing software. AI is not used to make individualized decisions about you: it does not diagnose, does not match visitors to providers, and does not decide search rankings. Listing order follows disclosed, deterministic rules (claimed and Premium listings appear above unclaimed ones). AI does not replace professional judgment — nothing AI-assisted on this site is medical advice.
Where data lives and how it's protected
Data is stored with Supabase (Postgres, U.S. region), encrypted in transit (TLS) and at rest. Row-level security limits what each role can read: anonymous visitors see only public display fields; providers can read and edit only their own records; submissions like contact messages are readable only by operations. Sign-in uses one-time magic links — no stored passwords. The site is served through Cloudflare, which provides TLS and bot protection. Administrative access is limited to the operator.
Third-party services
- Supabase — database, authentication, file storage.
- Cloudflare — hosting, DNS, CDN, security.
- Resend — transactional email delivery. Our email provider records basic delivery and engagement metrics (delivered, bounced, opened); our emails contain no advertising trackers.
- Google Analytics — aggregate traffic measurement (details & opt-out).
- Stripe — payment processing if and when you purchase a paid service; card details go directly to Stripe and never touch our servers.
- OpenStreetMap / Nominatim, Zippopotam — converting a ZIP or city you type into map coordinates; your search text is sent to these services to perform the lookup.
Each processes data only as needed to provide its service to us. We do not sell personal information to anyone, and we do not share it for cross-context behavioral advertising.
Cookies, Do Not Track & Global Privacy Control
Covered in full in the Cookie Policy: Google Analytics cookies, functional localStorage (session ID, favorites, sign-in), and Cloudflare security cookies. No advertising pixels. We honor Global Privacy Control (GPC) signals as an opt-out of data sale/sharing where state law requires — and because we don't sell or share data for advertising in the first place, both GPC and Do Not Track users get the same minimal-tracking experience as everyone else.
How long we keep things (retention)
- Contact-form and quiz submissions: kept while we work them and for up to 24 months, then deleted or anonymized.
- Provider listings and accounts: kept while the listing is active; deleted or de-identified on verified request.
- Anonymous analytics events: tied to a random session ID, kept in aggregate.
- Security and diagnostic logs: when an error occurs or for security screening, our hosting and database providers record log data (IP address, device and browser type, timestamps of the interaction). These logs are short-lived — typically days to weeks — and used only for functionality, debugging, and abuse prevention.
Your rights & how to exercise them
Regardless of what state or country you live in, we honor the same core set of rights for everyone:
- Access / download my data — ask, and we'll send you a copy of the personal data we hold about you, in a portable, machine-readable format on request.
- Correct my data — we'll fix inaccuracies (providers: claiming your listing is the fastest path).
- Delete my data — we'll erase your personal data, except the minimum we must keep for legal or security reasons, and we'll tell you if anything is retained and why.
- Opt out of marketing — every marketing email has an unsubscribe link; opt-ins are off by default.
- Opt out of targeted advertising / sale of data — we do not sell personal data and do not share it for cross-context behavioral (targeted) advertising, so there is nothing to opt out of; if that ever changes, we will build the opt-out before the feature launches.
Submitting a request
Email [email protected] (suggested subject: "Access Data Request", "Delete Data Request", or "Correct Data Request") with enough information for us to (1) verify you are the person the data belongs to — usually by confirming control of the email address you used on the site — and (2) understand what you're asking for. An authorized agent may submit a request on your behalf with proof of your written permission. We use the information in a request only to verify and fulfill it.
We respond within 30 days for most requests and within any shorter period a specific state law requires (up to 45 days with notice of extension where the law allows). We don't charge for requests unless they are excessive or repetitive, and we will never discriminate against you for exercising your rights — no denied service, different prices, or reduced quality.
Appeals
If we decline a request, we'll explain why. You may appeal by replying with "Consumer Appeal" in the subject line; a second review will be completed within 45 days. If your appeal is denied, you may contact the attorney general or data-protection regulator in your state or country.
California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you specific rights, all of which are covered by the process above: the right to know (the categories of personal information we collect, the sources, our purposes, and the third parties we disclose it to — all described in this policy), the right to access specific pieces of your information, the rights to correct and delete, the right to opt out of sale or sharing, the right to limit use of sensitive personal information, and the right to non-discrimination.
In CCPA terms, the categories we collect are: identifiers (name, email, phone, ZIP); professional information (for providers: credentials, license details on request); internet activity (pages visited, card interactions); coarse geolocation (from IP or the ZIP you search); and — only if you choose to submit the symptom quiz — information that may be considered sensitive personal information. We collect them from you, from your device, and (for unclaimed provider listings) from public sources; we disclose them only to the service providers listed above for the business purposes described.
- We do not sell personal information and have not sold it in the preceding 12 months.
- We do not share personal information for cross-context behavioral advertising. Because of this, no "Do Not Sell or Share" link is required — but you can always email us with "Opt-Out Request" and we'll confirm.
- Sensitive personal information (quiz symptom selections) is used only to show you the educational result you asked for and is never used to infer characteristics for advertising.
- Shine the Light (Civil Code §1798.83): we do not share personal information with third parties for their own direct marketing.
- We honor Global Privacy Control (GPC) signals as an opt-out of sale/sharing where required — though since we don't sell or share, the signal changes nothing in practice.
Other U.S. state privacy rights
If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive consumer privacy law, you have substantially the same rights — confirmation of processing, access, correction, deletion, portability, opt-out of targeted advertising and sale, opt-out of profiling with significant effects (we don't do such profiling), and the right to appeal a denial. All of these are honored through the request process above, for every visitor, whether or not your state's law technically applies to a business of our size.
Consumer health data (Washington My Health My Data and similar laws)
Some states — including Washington and Nevada — regulate "consumer health data" collected by websites even outside HIPAA. The only thing we collect that could qualify is the symptom quiz: checkboxes you voluntarily select to receive an educational result pointing you toward provider types. We use quiz responses only for that purpose and to respond if you asked us to; we do not sell consumer health data, do not share it with advertisers, and do not use it for any form of profiling. You may access or delete your quiz responses through the request process above. Searching the directory itself (location, specialty) is not tied to your identity.
International visitors (GDPR and other laws)
TMJDirectory is operated from the United States and aimed at U.S. audiences, but if you visit from the EU, UK, or EEA, the GDPR (or UK GDPR) applies to your personal data, and you have the rights of access, rectification, erasure ("right to be forgotten"), restriction of processing, objection, data portability, and withdrawal of consent — all honored through the request process above. Our legal bases are described in "Why we collect it" (consent for marketing; performance of the service; legitimate interests, minimized, for security and analytics). Your data is processed and stored in the United States; where GDPR requires safeguards for that transfer, we rely on our processors' Standard Contractual Clauses and equivalent mechanisms. You also have the right to lodge a complaint with your local supervisory authority. Visitors from other jurisdictions (for example, Australia's Privacy Act) may exercise the same rights through the same process, including complaint escalation to your local regulator (for Australian residents, the Office of the Australian Information Commissioner).
HIPAA and health information
TMJDirectory is a directory and publisher, not a healthcare provider, and we are not a "covered entity" under HIPAA. We do not provide, bill for, or facilitate medical care; we display provider information and let you make contact directly. We do not operate a care message center, store intake forms, or handle medical records — and we ask you not to send us any (see "What we deliberately do NOT collect" above). When you contact a provider using details on a listing, whatever you share goes directly to that provider under their privacy practices — ask them for their Notice of Privacy Practices. Health-adjacent data we do hold (quiz symptom selections) is handled under the consumer-health-data section above and applicable state laws, not HIPAA.
For providers (professional members)
If you claim or create a listing, we additionally collect and hold: your professional information (credentials, specialty, practice details, and — on request for verification — license number, issuing state, expiration, and NPI); your account email and sign-in timestamps; and aggregate analytics about your own listing. Sources are you, state licensing authorities and the NPI Registry (verification lookups), and public records (pre-claim listing data). We use this to operate your listing, verify credentials, and show you your own analytics — never for advertising. If and when paid subscriptions begin, payment details go directly to Stripe; we never see or store card numbers.
Remember that your listing and full profile are public by design — everything you choose to publish there (bio, photos, contact details) is visible to anyone, and public pages may be copied or cached by search engines and other services we don’t control. Publish only what you want public.
You can review and update your information any time from your provider dashboard. Deleting your personal data generally means removing your listing and account — email us and we'll complete it, except where a legal obligation requires limited retention. Note that pages removed from the site may persist temporarily in search-engine caches we don't control.
Providers: take-down requests
If your listing was compiled from public information and you want it removed rather than claimed, email us or use the contact form ("Dispute or correction"). We remove verified requests within 7 business days.
If something goes wrong (security incidents)
We maintain a written internal incident-response plan. If a breach affects your personal data, we will investigate, contain it, and notify affected people and authorities as required by applicable state breach-notification laws — promptly and plainly, telling you what happened, what data was involved, and what we're doing about it.
Children's privacy
TMJDirectory is not intended for or directed to children under 13, and we do not knowingly collect personal data from them. If we learn we have inadvertently received such information, we will delete it promptly — if you believe a child under 13 has provided us data, email [email protected]. Users between 13 and the age of majority in their state should use the site only with a parent or guardian's consent; a parent using the site on behalf of a minor (for example, seeking pediatric TMJ care) is treated as the user, and their information is handled under this policy.
Changes
Material changes get a new "Last updated" date at the top of this page, and where reasonable we'll notify newsletter subscribers and signed-in providers.
Contact
[email protected] · contact form · See all policies at /legal.
\n