Psychedelic Beacon
Washington My Health My Data Act

Consumer Health Data Privacy Policy

This is a standalone consumer health data privacy policy. It is not a paragraph inside a generic privacy page. Effective August 28, 2026.

Psychedelic Beacon (psychedelicbeacon.com) is a US directory of ketamine clinics and licensed psilocybin providers in Oregon, Colorado, and New Mexico. Visitors can search listings, see published prices, and see license-verification signals. Providers can claim a listing and subscribe for listing tools.

We do not provide medical care, book sessions, take payment for treatment, take a cut of sessions, or sell leads. Stripe processes provider listing subscriptions only. Nothing on this site is medical advice.

1. What this policy covers

Washington’s My Health My Data Act (MHMDA) treats some information as consumer health data when it is linked or reasonably linkable to a person and relates to health status or seeking health care. Because this site is a directory of mental-health and psychedelic treatment providers, a search, a “near me” lookup, a profile view, or a waitlist signup can indicate that someone is considering care.

This policy describes those practices as they exist in the product today. We apply the same disclosures to visitors nationwide. Public business information on a listing (clinic name, address, published prices, license marks) is directory content, not a visitor’s consumer health data.

This policy does not claim that we collect things we do not. We do not collect medical records, diagnoses, prescriptions, insurance claims, treatment notes, or payment for sessions.

2. Categories of consumer health data we collect

Directory browsing and search

You can read the directory without an account. When you use the site, our first-party tracker may record:

  • The page path you viewed and the referring site’s domain
  • Search text you enter (clinic name, city, treatment type, or zip code), result counts, and which listings were shown or clicked
  • Profile events: listing views, scroll depth, time on page, and clicks on phone, website, directions, or email links on a listing
  • Device type (mobile, tablet, or desktop) derived from the user-agent; screen size, timezone, and a few bot-detection signals (webdriver flag, plugin count, language count, color depth)
  • Approximate city and region from Vercel request headers (not a street address)
  • A short visitor hash and session hash. These are derived server-side from IP address + user-agent + a daily rotating salt. Raw IP is not stored on the analytics event. The tracker does not set cookies, use localStorage, or build a cross-day device fingerprint.

If you use “find clinics near me,” the browser asks for location permission. Coordinates are placed on the search URL (/search?lat=&lng=) so we can sort listings by distance. If you search a 5-digit zip code, we send that zip to Zippopotam.us to get a city and coordinates.

Waitlist and legal-update emails

Some state and blog pages let you ask to be emailed when providers go live or when there is material legal or approval news. That form stores your email, the state you selected, and an optional source tag (for example FDA-approval tracker, ibogaine tracker, or DT120 tracker) in our state_waitlist table. We send a confirmation email. If an operator email is configured, we also send ourselves a signup notice.

Provider claim, login, and listing management

Consumer accounts for patients do not exist. Sign-in is for providers claiming or managing a listing. We collect:

  • Work or practice email, used to send a magic-link or one-time code through Supabase Auth
  • Claim details: name, role, phone, business email if different, optional NPI or license / OPS number, and any ownership-dispute explanation
  • Listing edits the owner submits (contact details, hours, pricing, insurance accepted, photos). Photos are stored in a public Supabase storage bucket so they can appear on the listing.

Provider subscription payments

Paid plans (Growth $39/month and higher) are listing subscriptions for analytics tools — not treatment fees. When a claimed-listing owner upgrades, we create or reuse a Stripe customer with their account email and metadata linking the Supabase user and clinic. Card numbers and bank details are collected by Stripe on Stripe’s checkout or billing portal. We do not store full payment-card numbers. We do not process payments for sessions.

3. Categories of sources

  • You, when you search, grant location, open a listing, click a contact link, or submit a waitlist or claim form
  • Your browser and device (user-agent, optional geolocation)
  • Vercel, which provides hosting and approximate geo headers from the request IP
  • Providers, when they claim a listing or edit public profile fields
  • Public sources we use to build the directory itself (clinic websites, state license registries). That is listing content, not a visitor’s file.

4. How we use this data

  • Operate search, maps, and listing pages
  • Measure how a listing is found and used so a claimed provider can see views, contact-link clicks, search terms that led to their listing, referrer domains, and (on higher plans) approximate visitor region and device mix
  • Send the waitlist or tracker emails you asked for
  • Verify listing ownership and email providers about claim status
  • Process and support provider subscriptions through Stripe
  • Filter bots and obvious abuse on the tracker endpoint
  • Understand aggregate traffic via Google Analytics and Vercel Analytics

We do not use consumer health data to rank listings as “top rated,” to sell placement, or to write editorial scores. Directory signals that appear on listings (license verified, review count where a listing already shows one) are about the provider, not a score we assign to a visitor.

5. Categories shared, and who receives them

We share consumer health data only as described here. We have no affiliates. We do not share waitlist emails with listed clinics.

Claimed providers (service of the listing). If you view or interact with a listing, events tied to that listing can appear on the owner’s dashboard: view and lead counts, search queries that produced an impression or click, referrer domain, approximate region, and device type. Free plans see basic view and lead counts. Paid plans see more of those breakdowns. Events are not labeled with your name or email. Search text you typed can still be identifying in context.

Processors we actually use in this app:

  • Supabase — database, authentication, and photo storage for accounts, claims, waitlist rows, and analytics events
  • Vercel — hosts the site, runs API routes, and provides Vercel Analytics plus the geo headers used on tracker events
  • Google Analytics (measurement ID G-4L14E871CR) — page-view measurement, including the URL. Search URLs can include a query, zip, or coordinates
  • Resend — transactional email (waitlist confirmations, claim receipts, magic-link mail Supabase sends through the configured provider, and operator notices)
  • Stripe — provider subscription checkout and billing portal. Processor only; not used for session fees
  • Zippopotam.us — zip-to-city geocoding when you search a US zip code
  • OpenStreetMap tile servers — map tiles for clinic pins. Tile requests reflect the map viewport (clinic locations or, on a near-me search, the area around the coordinates you shared)

We also load Leaflet marker images from unpkg.com. That request does not include your search query. Yahoo Finance is called only for public stock quotes on the pipeline tracker and is not used for consumer health data.

6. Sale of consumer health data

We do not sell consumer health data. We do not sell leads. Provider subscriptions pay for listing tools on this directory. They are not a purchase of visitor identities.

7. Cookies and similar technologies

What the codebase actually sets or loads:

  • Supabase Auth cookies after a provider signs in (session). These are required for the dashboard and claim flow.
  • Google Analytics cookies from the gtag script in the site layout.
  • Vercel Analytics in the site layout (first-party web analytics).
  • An internal admin impersonation cookie used only when an admin is viewing a clinic dashboard for support. It is not used for visitors.

The first-party listing tracker posts to /api/track and is written to be cookieless. We do not run a separate advertising pixel, and we do not use a cookie-consent banner in this product today.

8. Precise location and geofencing

Precise location is collected only if you click “find clinics near me” and the browser grants permission, or if you type a zip code we geocode. We use that location to return nearby listings. We do not geofence healthcare facilities to identify, target, or advertise to consumers.

9. Retention

We do not run an automatic deletion job in this repository. In practice:

  • Waitlist rows stay until you unsubscribe (reply “unsubscribe”) or we delete them after a request
  • Analytics events stay so claimed providers can see listing performance, until we delete them after a valid request or they are no longer needed for that purpose
  • Provider account, claim, and subscription records stay for the life of the listing relationship and as needed for billing and security
  • Visitor hashes use a daily salt, so the same IP and browser do not keep one stable identifier across days in our first-party tracker

10. Your rights

If this policy applies to you, you may:

  • Confirm whether we are collecting, sharing, or selling consumer health data about you
  • Access the consumer health data we hold about you
  • Ask us to delete that data
  • Withdraw consent for collection or sharing that relies on consent (for example, a waitlist signup or a near-me location grant)
  • Use an authorized agent to make a request on your behalf

You can stop sharing precise location by denying or resetting location permission in your browser. You can avoid waitlist collection by not submitting the form.

11. How to make a request

Email eric@psychedelicbeacon.com with the subject line Consumer Health Data Request. Tell us which right you want to exercise and how we can find your data (for example the email you used on a waitlist or claim, or enough detail about a search session that we can look).

An authorized agent may email from their address and include your name, your contact email, and proof they are allowed to act for you. We may need to verify identity before we complete a request. We will respond within 45 days, or tell you if we need a further 45 days.

12. Appeals

If we deny a request, email eric@psychedelicbeacon.com with the subject line Consumer Health Data Appeal and explain why you disagree. We will review the denial and reply in writing within 45 days. If you are not satisfied after that appeal, you may contact the Washington State Attorney General.

13. Changes

If we collect a new category of consumer health data, use it for a new purpose, or share it with a new category of recipient, we will update this page and change the effective date. Material changes will be posted here before they take effect.

14. Contact

Privacy and consumer health data requests: eric@psychedelicbeacon.com.

Psychedelic Beacon · psychedelicbeacon.com

This page is about data practices. It is not medical advice and not a Terms of Service. Listing contact happens on the provider’s own channels. We do not book treatment.

Back to the directory