Privacy Policy
Last updated: July 15, 2026
This Privacy Policy explains how Mindfullume collects, uses, discloses, and protects personal data when you use our website, contact us, or book services. By using our services, you acknowledge this policy.
1. Data We Collect
- Identity and contact details: name, email address, and phone number.
- Inquiry details you submit through contact forms, including subject and message content.
- Booking details: selected service, date, time slot, and verification status.
- For organisation-sponsored bookings: your pseudonym, one-time portal login codes, and login session data.
- Payment-related metadata from Stripe (for example, payment status and session identifiers). We do not store full card details on our servers.
- Technical and usage information such as IP address, browser/device data, and interaction metrics collected through analytics and anti-abuse tools.
2. How We Use Personal Data
- Provide and manage psychology, counselling, and booking services.
- Verify requests and prevent abuse (including bot protection via Google reCAPTCHA).
- Process and confirm payments through Stripe.
- Send service communications such as verification codes, booking updates, and contact responses.
- Create or manage session scheduling information (for example through calendar integrations).
- Monitor performance and improve service quality, reliability, and user experience.
- Comply with legal, regulatory, accounting, and security obligations.
3. Legal Bases for Processing
Depending on your location and applicable law, we process data under one or more of the following legal bases: your consent, performance of a contract (or pre-contractual steps), our legitimate interests in operating and securing the service, and compliance with legal obligations.
4. Sharing and Third-Party Processors
We do not sell your personal data. We may share data with trusted service providers that process data on our behalf:
- Vercel (hosting, performance monitoring, and analytics).
- Supabase (database hosting and storage of booking, account, and related data).
- Stripe (secure payment processing).
- Google reCAPTCHA (spam and abuse prevention).
- Resend (transactional email delivery).
- Google Calendar API (scheduling and session event management where applicable).
- Upstash (rate limiting and abuse protection).
- Sponsoring organisations, for partner-programme bookings, limited to the billing information described in the Organisation-Sponsored Bookings section below.
5. Organisation-Sponsored Bookings
Some sessions are sponsored by an organisation you belong to (for example, your employer or an NGO) through our partner programme. If you book through the partner portal, the following also applies:
- We set up your account from details your organisation provides (such as your name and work email) and assign you a pseudonym.
- You sign in with a one-time code sent to your email. We store short-lived login sessions so you stay signed in, and these expire over time.
- Your organisation is billed by invoice. When anonymity is enabled for your organisation, the invoice and related emails to it reference only your pseudonym and the session details (service, date, time, and price), never your name, email, or the fact that a specific person attended.
- Your therapist at Mindfullume can see your real identity in order to deliver the session and for scheduling. Your organisation cannot, when anonymity is enabled.
- If anonymity is not enabled for your organisation, your name may appear on invoices shared with it. Your organisation can tell you which arrangement applies.
6. Payments
Payments are processed by Stripe. Mindfullume does not store full payment card numbers, CVC codes, or full card expiration details on its own servers. Payment data handling is subject to Stripe's privacy and security practices.
7. Retention
We retain personal data only as long as necessary for the purposes described in this policy, including service delivery, security, dispute resolution, and legal compliance. Some booking-related data is processed in short-lived temporary storage during verification flows (for example, temporary booking tokens may expire after approximately 15 minutes).
8. International Data Transfers
Our service providers may process personal data in countries other than your own. Where required, we take steps intended to ensure appropriate safeguards for international transfers.
9. Security
We use reasonable technical and organizational measures to protect personal data. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your Privacy Rights
Depending on applicable law, you may have rights to:
- Request access to personal data we hold about you.
- Request correction of inaccurate or incomplete personal data.
- Request deletion of personal data where legally permitted.
- Object to or request restriction of certain processing activities.
- Request a portable copy of certain data where applicable law provides this right.
- Withdraw consent where processing is based on consent.
To exercise these rights, please reach out through our contact page. We may need to verify your identity before completing your request.
11. Children's Privacy
Our services are not directed to children under the age required by applicable law for independent consent. If you believe a child has provided personal data without proper authorization, please reach out through our contact page so we can review and take appropriate action.
12. Policy Updates
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the "Last updated" date above.
13. Contact
If you have any privacy questions or requests, please reach out through our contact page.
