Recommend products your patients will actually use.
DentalDrop Shop lets you send personalised product recommendations (called Smile Scripts) directly to your patients. They order in minutes. You earn commission. Built for UK dental practices, GDPR-compliant from day one.
How it works
Three steps from appointment to order
01
Send a Smile Script
After an appointment, open your dashboard, search for products, add a personal note, and send. The patient receives a branded email with a secure link.
02
Patient orders directly
The patient clicks the link, sees exactly what you recommended, and checks out. No login friction; they're authenticated automatically via the link.
03
You earn commission
Every purchase made through a Smile Script earns your practice commission. Track conversions and earnings in real time from your dashboard.
Data & compliance
Built around your duty of care.
We understand that sharing patient data (even just a name and email) is a serious decision. Here is exactly what we do with it, and the protections we have in place.
Data minimisation
We only receive what you send: patient name and email. No clinical records, treatment notes, or special category health data ever leave your practice.
Formal Data Processing Agreement
When you register, you enter into a DPA with us under UK GDPR. We are the processor; you remain the controller of your patients' data at all times.
Single purpose only
Patient data is used solely to send and fulfil the Smile Script. We never use it for unrelated marketing or share it with third parties for their own purposes.
72-hour breach notification
If a data breach occurs involving patient data, we notify you within 72 hours, in line with our obligations as a data processor under UK GDPR.
Patient rights respected
Where a patient contacts us to exercise a data right (access, erasure, etc.), we promptly loop in your practice and action the request within the statutory timeframe.
Patients know they're sharing
Every patient accepts our Terms and Privacy Policy before accessing their Smile Script. We log the version accepted, the timestamp, and the IP address.
Our full Privacy Policy & Data Processing Agreement is publicly available. We recommend sharing it with your Caldicott Guardian or practice manager before registering.
Security
Technical protections you can point to.
TLS encryption
All data in transit is encrypted using TLS 1.3. No data is ever sent over an unencrypted connection.
Row-level security
Database access is enforced at the row level. A clinician from one practice can never access another practice's patient data.
PCI-DSS payments
Payments are handled by Stripe, a PCI-DSS Level 1 certified provider. We never see or store card details.
Encrypted at rest
All data is stored on Supabase infrastructure with AES-256 encryption at rest, hosted in the EU/UK.
FAQs