Privacy & data disclosure
This page describes what the ASHER Growth Portal application itself accesses, stores and transmits. It is specific to this portal and stands alone from Asher Health's general company policies.
Two separate kinds of data
1. Partner CRM data — appointment and contact records that already exist in a partner practice's own CRM sub-account, mirrored into the portal so the practice can report on them.
2. Personal calendar data — optional, only if a user connects a work calendar. This is used solely for busy-time conflict checking and is kept separate from CRM data.
Sign-in data
Signing in uses Google or Microsoft. The portal receives your basic account identity (email address, and the name/profile the provider returns) and uses it only to identify your account and decide what you may see. The portal does not read your mailbox, files or contacts for sign-in.
External partner users reach partner data only through an explicit membership of a specific partner company, recorded in the portal by a Super Admin. Internal ASHER staff signing in with a verified joinasher.com address are provisioned according to the portal's configured administrator domain policy rather than an individual invitation.
Partner CRM data the portal stores
For each connected partner sub-account, the portal mirrors and stores:
- Contact identifiers and contact details as provided by the CRM (such as name, email, phone), and CRM contact tags used for confirmation status.
- Appointment records: CRM appointment id, calendar id, assigned user, start/end times, status and cancellation state.
- Outcomes recorded in the portal: attendance, sales outcome and any revenue value entered by an authorized user.
- Message history for a contact, read from the CRM where available, shown read-only.
- Integration state: CRM location id, connection settings, encrypted CRM access credentials, and operational event records (opaque ids and processing results only).
Access is company-scoped and enforced on the server: a partner user's requests are restricted to the company they belong to.
Personal calendar connection (optional)
Connecting a personal work calendar is optional. When connected via Google:
- The portal requests identity scopes (
openid, email, profile) and the read-only calendar scopehttps://www.googleapis.com/auth/calendar.readonly. No mail, files, contacts or calendar-write scopes are requested. - The calendar connection is brokered by Nylas, a third-party calendar-integration provider. Nylas holds the calendar authorization grant on the portal's behalf.
- The portal stores: the connection/grant identifier, provider, the connected account's email address as reported by the provider, the company the connection belongs to, connection status and last error, and for each calendar its identifier, display name, time zone, primary and read-only flags, plus your conflict-calendar selection.
- For conflict checking the portal queries Nylas for the selected calendars over a bounded date window and requests only the
whenandbusyfields; it keeps busy start and end times only. Event titles, descriptions, attendees, locations and conferencing details are not requested, parsed or stored by this path. - The portal does not create, edit or delete events in your personal calendar.
- Microsoft personal-calendar connection is not enabled in this portal.
- External Google calendar access is currently in controlled testing pending provider approval, so new connections may be limited to approved test accounts.
A separate availability feature can write generic busy blocks into the practice's CRM calendar based on those busy intervals. Those blocks carry times only — no personal event details. The feature is off by default; each user turns it on for their own connection and company, and it can only produce CRM blocks once a Super Admin has mapped that user to a CRM staff member and calendar. Turning it off removes the blocks the portal created.
Writes the portal performs
The portal writes back to the practice CRM only: appointment attendance updates, sales outcome and revenue values recorded by an authorized user, the confirmation contact tag, and generic availability busy blocks when a user has enabled that feature. It performs no writes to a personal Google calendar.
Automatic deletion of mirrored contact records from CRM deletion events is deliberately disabled in this release: such events are acknowledged and ignored. Appointment deletion events only mark a mirrored appointment as deleted after the CRM authoritatively confirms the appointment is gone for that company; any ambiguous answer leaves records untouched.
Services that receive data
- GoHighLevel (the practice CRM) — source of appointment/contact data; receives the writes listed above.
- Nylas — calendar authorization and read-only calendar access, when a calendar is connected.
- Google / Microsoft — sign-in identity; Google additionally for read-only calendar access if connected.
- Supabase — the database and authentication service that stores portal data and user sessions.
- Lovable — the platform that builds and hosts the portal application.
The application contains no advertising or analytics-advertising integration, and it sends no calendar or CRM data to any AI, machine-learning or model-training service. Data obtained from Google APIs is used only for the busy-time conflict checking described above.
Google API Services disclosure
The portal's use of Google sign-in and Google Calendar data complies with the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only for the purposes described on this page — authentication and optional read-only calendar busy-time conflict checking — and is not sold, transferred, or used for advertising.
Disconnecting and removal
You can disconnect a personal calendar from the portal's Settings → Calendar Connections at any time. Disconnect first removes any CRM availability blocks the portal created, then asks Nylas to revoke the calendar grant, then deletes the stored connection and calendar selection for that company. The revocation request is best effort: if the provider call fails, the portal still removes its own stored connection but the upstream authorization may remain until it is removed at the provider. You can always remove the portal's access directly in your Google Account's third-party access settings.
Busy intervals are read on demand for conflict checking and are not retained as an event archive. What is retained for a connection is: the grant identifier, provider, connected account email, the company it belongs to, connection status and last error, plus each calendar's identifier, display name, time zone, primary and read-only flags, and your conflict-calendar selection.
CRM records mirrored into the portal are removed or changed through the CRM and the portal's administrators; the portal does not offer a self-service purge, and no promise of immediate or automatic deletion is made here. To request removal of specific data, contact charlene.laganson@joinasher.com. A formal retention schedule for this portal has not been published; requests are handled case by case.
What this page does not claim
This portal makes no certification claim of any kind (including HIPAA, SOC 2 or ISO), and no independent audit or production security verification is asserted here. This disclosure describes how the application is built, not a compliance attestation.
General Asher Health policies
Asher Health's general company policies are published separately at joinasher.com/privacy-policy. They are provided as a general reference; the disclosure on this page is what applies to the Growth Portal application. See also the portal terms of use.
