Effective Date: April 12, 2025
1. Who We Are
Our website address is: https://mindbodypivot.com/
This policy outlines how we collect, use, and protect your personal information when you use this site. It does not cover information collected inside the clinical relationship — that is governed separately by our HIPAA Notice of Privacy Practices and by the agreements you sign when you become a client.
2. Information We Collect
We collect a deliberately small amount of information on this site:
- Contact information you choose to share. When you reach out via email or schedule through our booking system, you provide your name, email address, and any details you include in your message. If you opt in to our newsletter, we keep the email address you provided.
- Aggregate, privacy-preserving analytics. We use Plausible Analytics, a cookieless analytics tool that records aggregate traffic patterns (pages visited, referrer, approximate country, device type) without tracking individual visitors, assigning persistent identifiers, or storing personal data on your device.
- Server logs. Like most websites, our hosting provider temporarily records request metadata (IP address, user agent, timestamp) for reliability and abuse prevention. These logs are not used for analytics or advertising and are retained only as long as operationally necessary.
We do not run advertising pixels, third-party marketing trackers, or session replay on this site.
3. Cookies and Tracking Technologies
This site does not use cookies for analytics or advertising. Plausible is specifically designed to work without cookies.
We may set a small number of strictly necessary cookies or local storage entries to remember UI preferences (for example, whether a user has dismissed a banner). None of these are used to identify you personally, build a profile, or share data with third parties.
We do not participate in targeted advertising networks, and there are no advertising partners (Google Ads, Meta, LinkedIn, etc.) receiving data from this site.
4. How We Use Your Information
We use the limited information described above to:
- Respond to inquiries you send us.
- Deliver services you have requested (including clinical services, which are governed separately by our HIPAA Notice).
- Send the newsletter, if you have opted in.
- Understand how the site is used in aggregate, so we can improve it.
- Maintain site reliability and prevent abuse.
- Comply with legal obligations.
We do not sell personal information, and we do not share it with third parties for their own marketing purposes.
5. SMS Communications (Text Messaging)
If you choose to provide your phone number for SMS communications (e.g., appointment reminders), the following applies:
- Consent: We will obtain your explicit consent before sending you marketing-related SMS messages. For non-marketing messages like appointment reminders, consent may be implied by providing your number for that purpose, and we will be clear about the type of messages you will receive.
- Purpose: We will only use your phone number to send messages for the specific purpose(s) you agreed to.
- Opt-Out: You can opt out of receiving SMS messages at any time by replying "STOP" to any message you receive from us. You may receive a final confirmation message after opting out. For help, reply "HELP".
- Frequency: Message frequency may vary depending on the service or updates.
- Rates: Message and data rates may apply depending on your mobile carrier plan.
- Sharing: We do not sell or share your phone number with third parties for their own marketing purposes. We may share your number with our SMS service provider solely for the purpose of sending the messages you requested.
6. Embedded Content from Other Websites
Pages on this site may include embedded content from third-party services (for example, our SimplePractice scheduling widget on the booking page, or an embedded video). That content behaves as if you visited the other website directly. The third party may collect data according to its own policies, and you should review those separately.
7. Who We Share Your Data With
We do not sell your personal information. We share information only in the following narrow circumstances:
- Service providers that run infrastructure on our behalf — for example, our website host, our scheduling system (SimplePractice), our email and newsletter provider, and our aggregate analytics provider (Plausible). Each is bound by their own data-processing terms and uses information only to provide the contracted service.
- Legal requirements. If required by law, regulation, legal process, or enforceable governmental request (e.g., subpoena).
- Protecting rights. If we believe disclosure is necessary to protect the rights, property, or safety of our practice, our clients, or the public.
8. How Long We Retain Your Data
- Inquiries and correspondence are retained for as long as necessary to respond and to keep reasonable business records.
- Newsletter subscriptions are retained until you unsubscribe.
- Aggregate analytics retained by Plausible do not contain personal data.
- Clinical records (for clients) are retained according to the HIPAA Notice of Privacy Practices and applicable Utah law — longer than web data, and under stricter rules.
9. What Rights You Have Over Your Data
Depending on your location and applicable law, you may have rights regarding your personal data:
- Access: You can request a copy of the personal data we hold about you.
- Correction: You can request correction of inaccurate personal data.
- Deletion: You can request that we erase personal data we hold about you, subject to certain exceptions (for example, records we are obliged to keep for legal, security, or health-record purposes).
- Opt-Out of SMS: You can withdraw consent for SMS messages at any time by replying STOP.
- Newsletter: You can unsubscribe at any time using the link in any newsletter email.
To exercise these rights, please contact us using the information below.
10. Where Your Data Is Sent
Our service providers (hosting, scheduling, analytics, email) operate in the United States and may process data through standard cloud infrastructure. Plausible processes aggregate analytics in the European Union.
11. Data Security
We implement reasonable administrative, technical, and physical security measures to protect your personal information. However, no internet transmission or electronic storage is 100% secure.
12. Children's Privacy
Our services are generally not directed to individuals under the age of 18 (or applicable age of majority). We do not knowingly collect personal information from children without appropriate parental consent where required by law (e.g., COPPA). If you believe we have inadvertently collected information from a child, please contact us to request deletion.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post any changes on this page and update the "Effective Date" at the top. We encourage you to review this policy periodically.
14. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us via email at: hello@mindbodypivot.com
