Privacy Policy

Last updated: December 5, 2025

Mumzie ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our practice management platform for birth and postpartum doulas ("Platform" or "Service").

Please read this Privacy Policy carefully. By using the Platform, you consent to the practices described in this policy. If you do not agree with this policy, please do not use the Platform.

1. Information We Collect

1.1 Information You Provide

We collect information that you voluntarily provide when you:

  • Create an account: Name, email address, phone number, password
  • Set up your profile: Profile photo, bio, tagline, service area, credentials, certifications, specialties, languages spoken
  • Use the Platform: Client information, appointment details, contract content, invoice data, messages
  • Subscribe to paid services: Billing information, payment method details (processed by Stripe)
  • Contact support: Communication content, attachments

1.2 Information Collected Automatically

When you access the Platform, we automatically collect:

  • Device information: Device type, operating system, browser type and version
  • Log data: IP address, access times, pages viewed, referring URL
  • Usage data: Features used, actions taken, time spent on pages
  • Location data: General geographic location based on IP address

1.3 Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Keep you logged in to your account
  • Remember your preferences and settings
  • Understand how you use the Platform
  • Improve our services and user experience
  • Provide analytics and performance data

You can control cookies through your browser settings. However, disabling cookies may limit your ability to use certain features of the Platform.

1.4 Information from Third Parties

We may receive information from:

  • Calendar integrations: Calendar event data (Google Calendar, Outlook)
  • Payment processors: Transaction status, payment confirmation (Stripe)
  • Analytics providers: Aggregated usage data

2. How We Use Your Information

2.1 Provide and Improve the Service

  • Create and manage your account
  • Process transactions and send related information
  • Enable core features (scheduling, contracts, invoicing, client management)
  • Provide customer support
  • Personalize your experience
  • Analyze usage patterns to improve the Platform

2.2 Communications

  • Send transactional emails (appointment confirmations, invoice receipts)
  • Send service-related announcements
  • Respond to your inquiries and support requests
  • Send marketing communications (with your consent, which you can withdraw at any time)

2.3 Security and Legal

  • Detect, prevent, and address fraud or security issues
  • Enforce our Terms of Service
  • Comply with legal obligations
  • Protect our rights, property, and safety

3. How We Share Your Information

🔒 We do not sell your personal information.

3.1 With Your Consent

We share information when you direct us to, such as when you make your profile public or share client information with backup doulas.

3.2 Service Providers

We share information with third-party service providers who perform services on our behalf:

SupabaseDatabase and authentication services
StripePayment processing
VercelHosting and content delivery
Daily.coVideo call infrastructure

These providers are contractually obligated to use your information only for the purposes of providing services to us and to maintain appropriate security measures.

3.3 Between Providers and Clients

When you use the Platform, certain information is shared between Providers and Clients as necessary to facilitate the services:

  • Providers see Client names, contact information, and booking details
  • Clients see Provider profiles, including name, photo, bio, credentials, and availability

3.4 Legal Requirements

We may disclose your information if required by law or in response to:

  • Court orders, subpoenas, or legal process
  • Government or regulatory requests
  • To protect our rights, property, or safety, or that of our users or the public

3.5 Business Transfers

If Mumzie is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.

4. Data Retention

We retain your information for as long as your account is active or as needed to provide you services. We may also retain and use your information to:

  • Comply with legal obligations
  • Resolve disputes
  • Enforce our agreements
  • Maintain business records

Account deletion: When you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal or legitimate business purposes.

5. Data Security

We implement appropriate technical and organizational measures to protect your information, including:

  • 🔒Encryption of data in transit (TLS/SSL) and at rest
  • 🔒Secure authentication and access controls
  • 🔒Regular security assessments and monitoring
  • 🔒Employee training on data protection
  • 🔒Incident response procedures

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

6. Your Rights and Choices

6.1 Access & Portability

You have the right to access the personal information we hold about you and to receive a copy of your data in a portable format.

6.2 Correction

You can update or correct your account information at any time through your account settings.

6.3 Deletion

You can request deletion of your account and personal information by contacting us at privacy@mumzie.com.

6.4 Marketing Opt-Out

You can opt out of marketing communications at any time by clicking the "unsubscribe" link in our emails or updating your notification preferences.

7. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: You can request information about the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: You can request deletion of your personal information, subject to certain exceptions.
  • Right to Opt-Out: You have the right to opt out of the "sale" of your personal information. Note: We do not sell personal information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise these rights, contact us at privacy@mumzie.com.

8. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):

  • Legal Basis: We process your data based on consent, contract performance, legal obligations, and legitimate interests.
  • Right to Restriction: You can request that we restrict processing of your data in certain circumstances.
  • Right to Object: You can object to processing based on legitimate interests.
  • Data Portability: You can receive your data in a structured, machine-readable format.
  • Right to Lodge a Complaint: You can file a complaint with your local data protection authority.

Data Transfers: Your information may be transferred to and processed in the United States. We use appropriate safeguards (such as Standard Contractual Clauses) to protect your information during international transfers.

9. HIPAA and Health Information

For users on HIPAA-compliant subscription tiers, we implement additional safeguards for Protected Health Information (PHI):

  • Business Associate Agreement (BAA) governs our handling of PHI
  • Enhanced security measures for PHI
  • Access controls and audit logging
  • Breach notification procedures

If you are a healthcare provider, you are responsible for determining whether HIPAA applies to your practice and ensuring compliance with your obligations under HIPAA.

10. Children's Privacy

The Platform is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete that information.

11. Third-Party Links

The Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the new policy on the Platform with an updated "Last updated" date
  • Sending an email notification for significant changes

Your continued use of the Platform after the changes take effect constitutes your acceptance of the revised Privacy Policy.

13. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

Privacy inquiries:privacy@mumzie.com
General support:support@mumzie.com
Data requests:privacy@mumzie.com

We will respond to your request within 30 days.