FountainFountain
AboutProvidersSafetyContactGet the app
Skip to content

Legal

Privacy Policy

Fountain Health Technologies Inc. · Last updated: 2026-09-12

See also: Terms of Service

This policy explains how Fountain Health Technologies Inc. (“Fountain”, “we”, “us”) handles personal information in the Fountain app and on fountainhealth.ca. It covers what we collect, why, who can see it, where it goes, how long we keep it, and what you can do.

Fountain lets you send a request to a walk-in clinic or pharmacy you choose in Kitchener–Waterloo, and brings back their answer. Fountain does not diagnose, treat, assess or triage you, and does not recommend a place or a treatment.

The short version:

  • Your record and your request go to the clinic or pharmacy you choose, when you send the request. No other clinic or pharmacy gets them.
  • Fountain staff can see your account, your record and your requests. Each time they open them in our staff console, we record it, and you can see those entries (section 7). That access is for running the service and being able to answer for it — never to sell your information, never for advertising or marketing, and never out of curiosity. Everyone who can reach it is bound by confidentiality.
  • Our database and servers are in Canada. Some services we use are outside Canada, and section 8 names them.
  • We do not sell your information or use it for advertising.
  • You can delete your account in the app. Sealed copies of your requests are kept, as section 12 explains.

On this page

  1. WHO IS RESPONSIBLE FOR YOUR INFORMATION
  2. WHAT WE COLLECT FROM YOU
  3. WHAT WE COLLECT AUTOMATICALLY
  4. HOW WE USE YOUR INFORMATION
  5. TEXTS AND NOTIFICATIONS WE SEND YOU
  6. WHAT THE CLINIC OR PHARMACY SEES
  7. WHAT FOUNTAIN STAFF CAN SEE
  8. SERVICES THAT WORK FOR US
  9. OTHER TIMES WE MAY SHARE INFORMATION
  10. WHERE YOUR INFORMATION IS STORED
  11. HOW LONG WE KEEP YOUR INFORMATION
  12. DELETING YOUR ACCOUNT
  13. SEEING, COPYING AND CORRECTING YOUR INFORMATION
  14. WITHDRAWING YOUR CONSENT
  15. HOW WE PROTECT YOUR INFORMATION
  16. IF SOMETHING GOES WRONG
  17. AGE
  18. PEOPLE WHO WORK AT CLINICS AND PHARMACIES
  19. THE WEBSITE
  20. CHANGES TO THIS POLICY
  21. CONTACT AND COMPLAINTS

1. WHO IS RESPONSIBLE FOR YOUR INFORMATION

Fountain Health Technologies Inc. is an Ontario company. We are responsible for the personal information we collect to run the app and the website. Canada’s federal privacy law, the Personal Information Protection and Electronic Documents Act (PIPEDA), applies to it.

When you send a request, the clinic or pharmacy that receives it becomes responsible for your information as part of its health records. Under Ontario’s Personal Health Information Protection Act (PHIPA), that place is a “health information custodian”.

For that clinic or pharmacy, Fountain is an electronic service provider under PHIPA. We host the copy of your information that the place reads on its web board, on its counter tablet and on the intake sheet it prints. We can alert the place about your request by text, email, push notification or an automated phone call, depending on the alerts the place has set up. When a request ends, we seal a copy of your record and the request as they stood at that moment, and keep it (section 11).

Fountain is accountable for how it handles personal information. Section 21 says where to write.

2. WHAT WE COLLECT FROM YOU

Your sign-in:

  • Your email address, your mobile number, or your Apple or Google account, depending on how you sign in. If you use Apple or Google, we receive the name, email address and any other profile details they share with us.

About you:

  • Your first and last name as they appear on your health card, and a preferred name if you add one.
  • Your date of birth and your sex at birth.
  • Your mobile number. It is verified with a code we text you, and we record which number we text and when it was verified.
  • An email address, from your sign-in or if you add one.
  • Your home address, as one line.

Your coverage:

  • Three yes-or-no answers: whether you have OHIP, out-of-province coverage, or private insurance. We never ask for health card, insurance card or member numbers.

Your health record:

  • Allergies, with how severe they are and the reaction.
  • Medications, with strength and how often you take them.
  • Ongoing conditions, with the year each started and any note you add.
  • Whether you are pregnant or breastfeeding, where that applies.
  • Whether you are immunocompromised or take a blood thinner. These are marked from the conditions and medications you list.
  • When you said you have none of something, and when you last confirmed that a section is still accurate.

Your emergency contact:

  • The name, phone number and relationship of someone to reach if needed. This is information about another person, so add it only with their permission. It is shared with each clinic or pharmacy you send a request to. We never check it.

Your settings:

  • Whether push notifications and text messages are on.

Each request you send:

  • The clinic or pharmacy you chose.
  • Now, or Later with one to three of the times the place offers, all on one day, which can be today or a later day.
  • The reason you picked, up to three other symptoms, and how long you have had it, when the app asks.
  • Anything you write in your own words (up to 500 characters).
  • Your answers to that place’s own questions (up to 300 characters each).
  • Whether you want a doctor’s note.
  • The time you confirmed that none of the listed emergency signs applies to you.
  • Your consent to share the request with that place, and the wording you agreed to. You agree again each time you send, including when you pick different times after a place could not take the ones you picked.
  • What happens next: the place’s answer, the time it gives you, any note it adds, when you arrived or said you would be late, and whether the visit was cancelled, completed or missed.

If you tap an emergency sign:

  • Before you send a request, the app shows the same short list of emergency signs to everyone. If you tap one, the request stops and is not sent. We record which sign you tapped and what you chose next: calling 911, finding an emergency department, or going back.

From older versions of the app:

  • We may hold a gender identity and a preferred language recorded by older versions of the app. The current app does not ask for either. If we hold them, we keep them with your profile. Your preferred language is shown to the clinic or pharmacy you send a request to. Your gender identity is not.

When you contact us:

  • If you email us or use a contact form, we collect your name, your email address and what you write, and use them to answer you.

3. WHAT WE COLLECT AUTOMATICALLY

Location:

  • If you allow it, the app uses your phone’s location while you are using it, to show how far away places are. The location is sent with each search for nearby places. We do not save it to your account or your record. The app works without location.

Records of what happens:

  • When something happens that matters for your information, such as creating your account, agreeing to these documents, giving consent, sending a request or tapping an emergency sign, we record what happened and when. For events your app reports to us, we also record your IP address and the user agent (a short description of the app and device software that sent it).
  • If our server refuses a request, for example because it is not allowed, we record that with the IP address and user agent.

Push notifications:

  • If push notifications are on, a push token for your phone, and whether it is an iPhone or an Android phone.

App usage:

  • The app tells us which screens and steps are used, for example opening the app, moving through setup, choosing a place and sending a request. These events carry a random id made each time the app starts, not your account. We note whether an event came from a Fountain test account, but we do not store which account sent it. Events never include the reason you picked, your other symptoms, how long you have had them, or anything you wrote. Older versions of the app sent these events while you were signed in, and our server stored them with your account; we deleted those events from our database when this version was released, and copies in our database provider’s backups are replaced as those backups roll over, within 7 days.

Daily use:

  • To count how many people use Fountain each day, we record your account’s internal number (not your name) and account type once a day.

Crash reports:

  • If the app crashes or hits an error, it sends a report to Sentry in the United States. A report includes the type of phone and its software, the app version and what went wrong. Screenshots and records of your taps are turned off, and we do not attach your name or your account. Email addresses, long numbers and code-like strings are removed from error messages before a report is sent. Each time you open the app, it also tells Sentry that it started and whether that use ended in a crash. This is not linked to your account.
  • The web board that clinics and pharmacies use sends crash reports to Sentry in the same way, with search terms and link codes removed from web addresses. Our server also sends Sentry a report when it hits an error it did not handle: what went wrong and where in our code, without your name or your account. The counter tablet does not send crash reports.

Server logs:

  • Our servers log errors, including the path of the web address involved, without what was typed or sent with it. Our own log messages show only the last four characters of a phone number, email address or push token we sent something to, but an error passed on from a provider can include the full number.

Texts you send us:

  • If you text Fountain’s number, we store your number and the first 500 characters of your message, even if the number does not match any account.

App lock:

  • If you turn on app lock, your phone checks your face, fingerprint or passcode. We never receive that information. The app keeps only a setting on your phone that says app lock is on.

4. HOW WE USE YOUR INFORMATION

We use your information to:

  • run your account and keep your health record;
  • show nearby clinics and pharmacies, with the hours, wait times and status posted for each place;
  • send your request to the clinic or pharmacy you choose, when you send it;
  • alert that place that a request is waiting, by text, email, push notification or an automated call to its front-desk phone, depending on the alerts the place has set up;
  • confirm a visit on that place’s behalf, if the place has turned on automatic confirmation;
  • show you where your request stands, and send you texts and notifications about it (section 5);
  • act on a YES or NO you text back;
  • verify phone numbers with a code;
  • let Fountain staff run, support and fix the service, and do what you ask us to, such as an export, a deletion or a cancellation (section 7);
  • count how Fountain is used and how many requests each place receives;
  • find and fix crashes and errors;
  • keep Fountain secure, prevent misuse, and keep a tamper-evident log of what happens to your information (a log built so that any change to it can be detected); and
  • meet our legal obligations.

We do not sell your information. We do not use it for advertising, and there are no advertising trackers in the app or on the website. If we want to use your information for a purpose this policy does not describe, we will ask you first.

5. TEXTS AND NOTIFICATIONS WE SEND YOU

Once your mobile number has been verified, text messages are on unless you turn them off. Push notifications are on in Fountain unless you turn them off, and your phone must also allow them.

We send you a message when:

  • a clinic or pharmacy confirms your visit;
  • your visit time changes;
  • it is time to head out, 30 minutes before a Later visit, unless we only just told you the time;
  • you have a visit on a later day: at 7 p.m. Toronto time the evening before, a text asks you to reply NO if you cannot make it, unless your visit was confirmed after 6:30 p.m. that evening;
  • your request ends, for example because the place did not reply in time, could not take it or cancelled, or because Fountain cancelled it; and
  • a place marks you as missed (push notification only).

Our messages can name the clinic or pharmacy and the visit time. They do not include the reason for your visit or anything else from your health record. But the name of a clinic or pharmacy and a visit time can say something about your health to anyone who sees your phone.

We do not send marketing messages.

Replying to a text:

  • If you text NO within a day after a reminder, including the 30-minute “time to head out” text, we cancel the visit that reminder was about, unless it has already ended, been cancelled or been checked in — then nothing changes, and we tell you so.
  • Otherwise, including when we have not sent you a reminder in the past day, a NO cancels your next confirmed visit, which can be a visit today.
  • YES gets the same “nothing changes” reply when that visit is no longer active; otherwise we note your reply, and your visit stays as it is.
  • Only a text that is just one short answer counts. Words such as NOT COMING count as NO (CANCEL does not: like STOP, it stops all texts from Fountain’s number), and OK or CONFIRM count as YES.
  • A question, or any other reply, changes nothing and gets a short text pointing you to the app.
  • We act on these replies only when they come from your verified number.
  • Reply STOP to stop all texts from Fountain’s number, and START to get them again. STOP is handled by our text-message provider, so the switch in the app will still show text messages as on.

We keep every text sent to Fountain’s number, as section 3 says.

To turn messages off, open Profile, then Notifications, and use the “Push notifications” and “Text messages” switches. You can also turn off notifications for Fountain in your phone’s settings. Reminders follow these two switches. There is no separate reminder switch.

Fountain does not email you about your requests. If you sign in with email, our sign-in provider, Supabase, sends you emails through Resend to confirm your address or reset your password.

6. WHAT THE CLINIC OR PHARMACY SEES

When you send a request, the clinic or pharmacy you chose can see your record and your request on its web board and counter tablet, and on the intake sheet it can print. Until your request ends, the place sees your record as it is now, including changes you make after you send.

Your record:

  • your legal, first, last and preferred names, and your preferred language if we hold one;
  • your date of birth, age and sex at birth;
  • your phone number, email address and home address;
  • your emergency contact;
  • your coverage answers;
  • whether you are pregnant, breastfeeding, immunocompromised or on a blood thinner;
  • your allergies, medications and conditions, with their details; and
  • when you said you have none of something, and when you last confirmed your record.

Your request:

  • Now or Later, and the times you asked for;
  • the reason, other symptoms and how long you have had them;
  • your own words and your answers to that place’s questions;
  • whether you want a doctor’s note; and
  • the time you confirmed that no emergency sign applies.

No other clinic or pharmacy sees them. If you later send a request to a different place, that is a new sharing with that place only, and it is not told where you sent it before.

The staff at a clinic or pharmacy share one login, so our records show that the place acted, not which person there did. We record when your request is first shown to the place, and when it is opened, printed or copied there.

The place’s answer, the time it gives you and any note it adds come back to you in the app.

Alerts to the clinic or pharmacy:

  • Texts, emails and push notifications to the place speak about requests in general terms. For example, they say that a patient is waiting, that a visit was confirmed or cancelled, or how many visits are booked today and when. They do not include your name or health details.
  • The automated call to the place’s front-desk phone says that a patient is waiting and, for a Later request, the earliest time you offered. It does not say your name or why you are coming.

The one-tap link:

  • The text we send the place includes a link it can use to answer without signing in. Anyone who opens that link, on any device, can see what it shows, including if the text is forwarded.
  • While your request is waiting, the link shows the reason, how long you have had it, your age range (for example “30s”), the times you asked for, and the place’s name. It keeps showing them until shortly after the reply time runs out. It never shows your name or contact details.
  • After that, the link shows only the outcome. About a day after the reply time runs out, it shows nothing.
  • We record when the link is opened while your request is waiting, and when the place answers through it.

Once a clinic or pharmacy has your information, it keeps it under its own legal duties, including rules on how long health records must be kept. Section 13 explains how to see or correct its record.

7. WHAT FOUNTAIN STAFF CAN SEE

Staff access exists so that Fountain can be run and answered for, and for nothing else. We do not sell your information, we do not use it for advertising or marketing, and no one at Fountain may look at your record out of curiosity. What staff use it for is running and supporting the service, fixing problems, doing what you ask us for, and keeping a record of who did what so that it can be traced afterwards — by you, by a clinic or pharmacy, or by a regulator. Everyone who can reach your information is bound by confidentiality, every use of the console is recorded (below), and section 15 lists what protects it.

Fountain staff who use our operator console can see everything about you and your requests. That includes your account and sign-in details, your health record, each request with what you wrote, the sealed copies, the messages we sent about your requests, and the record of what happened to them.

Staff use this to run and support Fountain, fix problems, answer questions from you or from a clinic or pharmacy, and do what you ask us to, such as an export, a deletion or a cancellation. From the console, staff can also cancel a request, send an alert to a place again, suspend an account, and clear or resend a phone code. They can move a confirmed visit by the same rules a place follows: a Later visit only to another time you offered, and a Now visit only to another time the same day. You are told when a request of yours is cancelled or moved.

Each time a staff member opens your record, one of your requests, or a list that shows your name in the console, we record it. The entry says who it was, when, what was shown, and that it was about you. After you delete your account, an entry about a request names the request rather than you. These entries go into our tamper-evident log.

You can see these entries in the record log that comes with your export (section 13). They read, for example, “A member of Fountain staff opened your record”, “A member of Fountain staff opened one of your requests” or “Your name appeared in a list a Fountain staff member opened”. You can ask us for details, including which staff member it was (section 21).

Authorized Fountain engineers can also work in our database directly, to maintain and repair it. That kind of access does not go through the console, so it does not appear in your record log. Staff and engineers who can reach your information are bound by confidentiality.

Staff access entries are kept with the rest of the log, for as long as section 11 says.

8. SERVICES THAT WORK FOR US

We use the companies below to run Fountain. Each receives only what it needs to do its job for us. Twilio and Google may also use some of it for their own purposes, as the list says. We remain responsible for information we send them.

  • Supabase, on Amazon Web Services in Montréal, Canada: our database, its backups, and sign-in. Supabase sends sign-in codes by text through Twilio and sign-in emails through Resend.
  • DigitalOcean, in Toronto, Canada: our application servers.
  • Cloudflare, a worldwide network: stands in front of our servers and the website, so it handles the traffic to them, including IP addresses.
  • Twilio, in the United States: sends our texts, receives texts sent to our number, and makes the automated calls to clinic and pharmacy phones. The voice on those calls is made by Amazon Polly, through Twilio. Twilio may also use records of those texts and calls, and message content it checks for spam or abuse, to run and protect its own service, under its own privacy policy.
  • Resend, in the United States: sends emails to clinics, pharmacies and Fountain staff, and the emails that confirm a patient’s email address or reset a password.
  • Google Firebase Cloud Messaging and Apple Push Notification service, worldwide: deliver push notifications, including the place name and time.
  • Google Maps Platform, in the United States: suggests addresses as you type your home address. Our server sends Google the text you type, not your location or your IP address. Google may also use it for its own purposes, under Google’s Privacy Policy (policies.google.com/privacy).
  • CARTO, in the United States: map images. Your phone asks CARTO for them, so CARTO receives your IP address and the map area shown.
  • Sentry, in the United States: crash and error reports.
  • Web3Forms, run by Web3Creative in India: delivers messages from the website’s forms to our inbox. “Contact support” in the app opens the website’s contact form, so what you type there goes through Web3Forms.

If you sign in with Apple or Google, that company handles your sign-in as an independent business, under its own terms and privacy policy.

9. OTHER TIMES WE MAY SHARE INFORMATION

  • If the law requires it, for example under a court order or a warrant. Where the law allows, we will tell you.
  • If Fountain is sold or merges with another company, the information we are responsible for may pass to the new owner, as far as the law allows. The new owner must keep protecting it as this policy says, and we will tell you in the app.

We never share your information with advertisers or data brokers.

10. WHERE YOUR INFORMATION IS STORED

Our database and its backups are in Montréal, and our application servers are in Toronto.

Some information is handled outside Canada by the services in section 8:

  • texts we send to you, to clinics and pharmacies, and to our staff, and texts we receive;
  • automated calls to clinics and pharmacies;
  • emails to clinics, pharmacies and our staff;
  • push notifications;
  • the address text you type;
  • map requests;
  • crash reports; and
  • messages sent through the website’s forms.

Cloudflare carries traffic through data centres around the world. Backups and logs kept by these services may also be stored outside Canada.

While information is outside Canada, the laws of that country apply to it, and its courts, police and security agencies may be able to get it under those laws.

11. HOW LONG WE KEEP YOUR INFORMATION

We keep information for two reasons: to run the service, and so that what happened can be traced and answered for afterwards. We do not keep it to sell, to build a profile of you, or to market to you. Some of the periods below are set by law — Ontario clinics and pharmacies must keep their own records for years, and some legal claims can be brought long after the visit — and where we have not yet set a period, the entry says so rather than leaving you to assume one.

  • Your profile and health record: until you delete your account. We do not delete accounts for inactivity.
  • Your requests: while you have an account. Section 12 says what happens to them after you delete it.
  • Sealed copies: when a request ends, we seal a copy of your record and the request as they stood at that moment. From then on, it is what the clinic or pharmacy sees. We keep it until the later of 15 years after it was sealed and 15 years after your 18th birthday, and then a daily job deletes it. The database is built to refuse any change to a sealed copy, and any deletion before its date. Only a deliberate change to the database itself, by an authorized engineer, could remove that protection. We keep sealed copies this long for two reasons. Ontario clinics and pharmacies must keep their own records for at least 10 years. Also, some legal claims can be brought up to 15 years after the events.
  • The record log: what happened to your information, your consents and staff access entries, including after you delete your account. The log is kept in yearly sections. We delete a year’s section only after every sealed copy made in that year has reached the end of its time. Even then, we keep it while an access request, a complaint or a legal hold involves it. A legal hold is when a legal case or order requires us to keep information. Consent records, and the wording you agreed to, are kept at least as long as the sealed copies they relate to.
  • App usage events: 180 days.
  • Daily-use entries: 400 days, or until you delete your account.
  • Counts of requests to our server, with no personal details: 45 days.
  • Phone verification codes: stored only in scrambled form, and deleted once used or after 5 wrong tries. Unused codes expire after 10 minutes and are deleted within the hour.
  • Push tokens: until you sign out (if your phone can reach us), until the push service says the token no longer works, or until you delete your account.
  • Messages we send you, and the codes behind the one-tap links for your requests: until you delete your account. We have not yet set a shorter limit.
  • Texts you send to Fountain’s number: until you delete your account. Texts from a number that is not on any account are kept, and we have not yet set a time limit.
  • Information about clinics, pharmacies and their staff (section 18): we have not yet set a time limit.
  • After you delete your account: a record of your account’s internal number and that the account was deleted. We have not set a time limit for it.
  • If you sign in but never finish setting up, or the app does not accept your date of birth: your sign-in, until you ask us to delete it or someone else verifies the same mobile number on their Fountain account. Your sign-in is your email address, mobile number, or Apple or Google account. Deleting in the app needs a finished account, so write to support@fountainhealth.ca.
  • Crash reports: up to 90 days, at Sentry.
  • Server logs: 90 days, at DigitalOcean. Records of the texts sent and received through Twilio: Twilio shows them to us for 13 months and then keeps them in an archive. We have not yet set a shorter period. Other records our providers keep: for the periods those providers set.
  • Messages you send us by email or through the website’s forms: in our support inbox until we delete them. We have not yet set a time limit. Web3Forms keeps its own copy of messages sent through the website’s forms for up to 3 years, unless we set a shorter period.

12. DELETING YOUR ACCOUNT

You can delete your account in the app: Profile → Delete my account. You can also email support@fountainhealth.ca, and we will delete it for you once we have checked that the account is yours. The page fountainhealth.ca/delete-account explains both ways.

When your account is deleted:

  • Any request in progress is cancelled.
  • Your profile, health record and login are deleted.
  • Your requests are unlinked from your account, and your own words and your answers to a place’s questions are removed from them. The reason, other symptoms, how long, the times, what happened and any note from the place remain.
  • Your push tokens, your phone verification codes, the messages we had for you and the one-tap links for your requests are deleted.
  • Texts you sent to Fountain’s number from the mobile number on your account are blanked, so the number and the words are gone. Texts from any other number are not.
  • Your daily-use entries are deleted.

What stays:

  • A sealed copy of each request you sent, for the time section 11 says. It keeps your details as they were when the request ended. The clinic or pharmacy you sent it to can still open that copy in the history on its Fountain board or tablet.
  • The clinic or pharmacy keeps its own record under its own legal duties, including anything it printed or copied.
  • The record log, including consents and staff access entries, for the time section 11 says.
  • A record of your account’s internal number and that the account was deleted.
  • App usage events, which are not linked to your account, until they are 180 days old.
  • Copies held by our service providers, such as crash reports and message records, for the periods they set.

Deleting your account does not disconnect Fountain from your Apple or Google account. If you signed in with Apple or Google, you can remove Fountain in your Apple or Google account settings.

13. SEEING, COPYING AND CORRECTING YOUR INFORMATION

  • See and change: your profile and health record are in the app, and you can edit them at any time.
  • Export: Profile → Privacy & security → Export my data makes a copy of your profile, your requests and your record log. The record log lists what happened to your information and when, and which version of each document you agreed to. For requests sent from older versions of the app, it may show that you gave consent without the wording. The copy is made on your phone and goes only where you share it.
  • Ask us: you can ask us for more, including which Fountain staff member opened your record and when, what we hold about you, how we have used it, and who we have shared it with. Write to privacy@fountainhealth.ca (section 21). We answer within 30 days. If we need more time, which can be up to 30 more days, we will tell you before the first 30 days end. We will say why, by when we will answer, and that you can complain to the Office of the Privacy Commissioner of Canada.
  • Correct: if something else we hold about you is wrong, write to privacy@fountainhealth.ca and ask us to correct it.
  • Sealed copies: a sealed copy is never changed, even to correct it. If part of one is wrong, tell us at privacy@fountainhealth.ca. We will keep a written record of your correction, or of your disagreement if we do not agree. Where it matters, we will also tell the clinic or pharmacy that received it.
  • The clinic’s or pharmacy’s own record: to see or correct it, ask that clinic or pharmacy in writing. Under PHIPA it must answer within 30 days, and it may extend that once, by up to 30 days.

14. WITHDRAWING YOUR CONSENT

You can withdraw your consent at any time, subject to legal limits. There is no single button for it. Instead:

  • To stop texts or push notifications, turn them off (section 5), or reply STOP to a text.
  • To stop the app using your location, turn off location access for Fountain in your phone’s settings.
  • To stop sharing, stop sending requests. Nothing is shared with a place until you send it a request.
  • To stop everything, delete your account (section 12).

A request you already sent stays with the clinic or pharmacy that received it, and we keep its sealed copy for the time section 11 says. Withdrawing consent cannot undo that. Some things are needed for Fountain to work: without sharing your record with the place you choose, you cannot send a request. Some things cannot be switched off while you have an account: daily-use entries, app usage events, crash reports and the record log (sections 3 and 11). We use them to count use, fix errors and keep a record of what happens to your information. If you want to withdraw a consent and are not sure how, write to privacy@fountainhealth.ca (section 21).

15. HOW WE PROTECT YOUR INFORMATION

  • Information is encrypted while it travels between your phone, our servers and our database.
  • Our database provider encrypts the data it stores (AES-256).
  • Our server gives your information only to your signed-in account, to the clinic or pharmacy you sent a request to, and to Fountain staff. Sections 6 and 7 explain the one-tap link and direct database access.
  • Our tamper-evident log links each entry to the one before it, so changing or removing an entry can be detected.
  • The database is built to refuse changes to a sealed copy (section 11).
  • Phone verification codes and one-tap link codes are stored only in scrambled (hashed) form.
  • We check that messages about texts and calls really come from Twilio, and we limit how often requests can be made to our server.
  • Each time Fountain staff open your record, one of your requests, or a list that shows your name in the console, it is recorded (section 7).
  • You can turn on app lock, so Fountain opens only after your face, fingerprint or passcode.

No security is perfect.

16. IF SOMETHING GOES WRONG

If a breach of our safeguards creates a real risk of significant harm to you, we will tell you and report it to the Office of the Privacy Commissioner of Canada as soon as we can. We keep a record of every breach.

If the breach involves information we hold for a clinic or pharmacy, we will also tell that place. Under PHIPA, the place must then tell you, and tell you that you can complain to the Information and Privacy Commissioner of Ontario.

17. AGE

Fountain is for people 16 and over. The app does not accept a date of birth under 16. There are no parent or guardian accounts: each account is for one person, and its requests are about that person. We rely on the date of birth you give. We do not check it. If you signed in but the app did not accept your date of birth, we keep your sign-in until you ask us to delete it at support@fountainhealth.ca, or until someone else verifies the same mobile number (section 11).

18. PEOPLE WHO WORK AT CLINICS AND PHARMACIES

This section is for staff at the clinics and pharmacies that use Fountain.

  • Each place has one shared login for its web board and counter tablet. We record what is done under that login, not under a person’s name.
  • When the web board or tablet tells us a request was opened, printed or copied, we record the IP address and a short description of the browser or device.
  • A place can give us mobile numbers and email addresses for alerts. These may be a staff member’s own. Each one is verified with a code before we send alerts about requests to it.
  • We keep the front-desk phone number that our automated calls ring. It is not verified with a code.
  • If a browser or tablet turns on alerts, we keep its push token and a short description of the browser or device.
  • We keep a history of when each board or tablet was online, and of each wait time posted for a place.
  • For automated calls, Twilio tells us whether the call was answered, and whether it reached a person or voicemail.

We use this information to send alerts and run Fountain for that place. Crash reports from the web board go to Sentry (section 3). The rest of this policy applies to this information too.

19. THE WEBSITE

  • fountainhealth.ca does not set cookies and does not use analytics.
  • It may keep two small notes in your browser. One is a graphics setting for slower devices, which expires after 14 days. The other, on the Get the app page on a phone, notes that you were already sent to the app store, and is cleared when you close the tab.
  • The contact form sends your name, email address, topic and message. The provider waitlist form sends your name, business, city, role and email address, and your phone number and message if you add them. Both go through Web3Forms to our inbox.
  • Cloudflare delivers the website, so it receives your IP address and browser details.
  • Links to the App Store, Google Play and social media take you to services with their own privacy policies.

20. CHANGES TO THIS POLICY

The “Last updated” date at the top is this policy’s version. When we make a change that matters, the app shows you the new version and asks you to accept it before you continue. If you accepted an earlier version, including in an older version of the app, you will be asked to accept this one. When we only fix wording, we change the date but do not ask again. Changes apply from their date.

We keep a record of each version you accept: which document, its date, and a fingerprint of its exact wording.

21. CONTACT AND COMPLAINTS

Questions, requests and complaints about privacy go to:

Fountain Health Technologies Inc.
Privacy: privacy@fountainhealth.ca

Everything else: support@fountainhealth.ca

Contact form: fountainhealth.ca/contact

If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) about how Fountain handles your personal information. For a clinic’s or pharmacy’s record of your health information, or anything else under PHIPA, you can complain to the Information and Privacy Commissioner of Ontario (ipc.on.ca).

FountainKitchener-Waterloo, Ontario
Get the appSafetyFor pharmacies and clinicsContactProvider login →

If this is an emergency, call 911 or go to your nearest emergency department.

Fountain Health Technologies Inc. · Terms · Privacy · Delete account · info@fountainhealth.ca