We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. By clicking "Accept", you consent to our use of cookies.
Privacy Policy
Last updated: 2/3/2026
Introduction
Mindful Family ("we", "our", or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, process, and store your personal information when you use our platform at mindful.family (the "Service"), including our website and mobile applications.
Information We Collect
Personal Information
- Account information (name, email, username)
- Profile information (avatar, bio, professional credentials)
- Contact details for practitioners and venue owners
- Payment information (processed securely through Stripe and RevenueCat)
- Content you create (posts, comments, recipes, courses)
- Communications through our messaging system
- Identity verification documents (for practitioner verification via Yoti)
Automatically Collected Information
- Device information (IP address, browser type, device type, operating system)
- Usage data (pages visited, actions taken, time spent)
- Cookies and similar tracking technologies
- Push notification tokens (if you enable notifications)
Location Data
Our "Near Me" feature uses location data to help you find practitioners, venues, events, and services in your area. We collect and process location data as follows:
Types of Location Data
- Precise GPS Location: With your explicit consent, we collect precise GPS coordinates from your device to show you nearby services and enable distance-based search filtering
- Address Information: When you manually enter an address or postcode for search purposes
- IP-Based Location: Approximate location based on your IP address for regional content
How We Use Location Data
- Display nearby practitioners, venues, events, and job listings
- Calculate distances between you and service providers
- Filter search results by distance radius
- Show relevant local content and recommendations
Location access is optional and requires your explicit consent. You can disable location access at any time through your device settings or browser permissions. The Service will still function without location access, but distance-based features will be unavailable.
Push Notifications
We use OneSignal to deliver push notifications to your device. When you opt-in to notifications, we collect:
- Device push notification tokens
- Notification preferences and settings
- Notification interaction data (opens, dismissals)
Types of Notifications
- New messages from other users
- Booking confirmations and reminders
- Course updates and new content
- Community activity (likes, comments, follows)
- Special offers and platform updates (with your consent)
You can manage your notification preferences in your account settings or disable them entirely through your device settings.
Video Content & Live Streaming
Our platform supports video content and live streaming through Livepeer. When you use these features, we collect:
- Video content you upload or stream
- Stream metadata (duration, quality, viewer counts)
- Chat messages during live streams
- Viewer interaction data (joins, leaves, reactions)
Video Data Processing
- Videos are processed and stored through Livepeer's infrastructure
- Live streams are temporarily stored and may be recorded if the host enables recording
- Stream recordings are stored according to host preferences and our retention policies
Messaging & Chat Data
When you use our messaging features, we collect and store:
- Direct messages between users
- Group chat messages in communities and courses
- Live stream chat messages
- Message timestamps and read receipts
Message Retention
- Direct messages are retained until deleted by the sender or account deletion
- Community and group messages are retained as long as the group exists
- Live stream chat messages may be retained with stream recordings
- Deleted messages are permanently removed within 30 days
In-App Purchases & Subscriptions
We process payments and subscriptions through multiple providers:
Stripe (Web Payments)
- Payment card details are processed directly by Stripe
- We receive only transaction confirmations and subscription status
- We do not store your full card numbers
RevenueCat (Mobile App Purchases)
- In-app purchases through Apple App Store are processed via RevenueCat
- Purchase history and subscription status are synced to your account
- Refunds and subscription management follow App Store policies
Payment Data We Store
- Transaction IDs and purchase dates
- Subscription status and renewal dates
- Payment provider references (not card details)
- Purchase history for courses, events, and services
How We Use Your Information
We use your personal data for the following purposes:
- Providing and maintaining our Service
- Processing your transactions and bookings
- Verifying practitioner credentials and certifications
- Facilitating communication between users
- Sending service-related notifications
- Improving and personalizing our Service
- Ensuring platform safety and security
- Displaying relevant nearby services and content
- Processing subscription and purchase transactions
- Delivering live streaming and video content
- Complying with legal obligations
Legal Basis for Processing
We process your personal data under the following legal bases:
- Contract: Processing necessary for the performance of our contract with you
- Consent: Processing based on your explicit consent (e.g., location data, push notifications, marketing)
- Legal Obligations: Processing required to comply with our legal obligations
- Legitimate Interests: Processing necessary for our legitimate business interests (e.g., fraud prevention, platform security)
Data Sharing and Third Parties
We share your information with the following service providers:
Payment Processing
- Stripe - Web payment processing
- RevenueCat - Mobile in-app purchase management
- Apple - App Store purchases (via RevenueCat)
Infrastructure & Services
- Supabase - Database, authentication, and file storage
- Netlify - Website hosting and serverless functions
- Livepeer - Video processing and live streaming
- OneSignal - Push notification delivery
Verification & Communication
- Yoti - Identity verification for practitioners
- Resend - Email delivery service
Other Sharing
- Other users - when you interact through our platform (public profiles, messages, community posts)
- Practitioners and venue owners - when you make bookings or inquiries
We ensure all third-party service providers comply with GDPR and maintain appropriate security measures through data processing agreements.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:
- Account data: Retained while your account is active and for 30 days after deletion
- Transaction records: Retained for 7 years for legal and tax compliance
- Messages: Retained until deleted by user or account deletion
- Location data: Not stored permanently; used only for real-time search
- Video content: Retained according to creator settings and platform policies
- Verification documents: Retained for the duration of verification validity
When you delete your account, we will delete or anonymize your personal data within 30 days, except where we are legally required to retain certain information.
Your Data Protection Rights
Under GDPR, you have the following rights:
- Right to access: Request a copy of your personal data
- Right to rectification: Request correction of inaccurate data
- Right to erasure: Request deletion of your personal data ("right to be forgotten")
- Right to restrict processing: Request limitation of how we use your data
- Right to data portability: Receive your data in a portable format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Withdraw consent at any time for consent-based processing
To exercise any of these rights, please contact our Data Protection Officer using the contact details below.
Security Measures
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure authentication with row-level security policies
- Regular security assessments and updates
- Access controls and authentication measures
- Staff training on data protection
- Incident response procedures
- Secure payment processing through PCI-compliant providers
Children's Privacy Protection
Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
We comply with the Children's Online Privacy Protection Act (COPPA) and do not knowingly collect personal information from children under 13 without verifiable parental consent.
Users between 13-17 years old may use our Service with parental consent and supervision. Parents can contact us to review, modify, or delete their child's personal information.
Data Breach Notification
In the event of a data breach that may result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.
Notification Process
- We will notify affected users via email within 72 hours
- We will provide clear information about the nature of the breach
- We will explain the likely consequences and measures taken
- We will provide contact information for further inquiries
International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States, where some of our service providers are located:
- Supabase (United States)
- Stripe (United States)
- RevenueCat (United States)
- OneSignal (United States)
- Livepeer (United States)
We ensure appropriate safeguards are in place through Standard Contractual Clauses, adequacy decisions, and data processing agreements with all providers.
Contact Us & Data Protection Officer
For any questions about this Privacy Policy or to exercise your rights, please contact our Data Protection Officer at:
Data Protection Officer:
Email: privacy@mindful.family
General Support: support@mindful.family
Address: United Kingdom
Response Time: We will respond to all inquiries within 30 days
If you are in the UK, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your personal data in accordance with applicable data protection laws.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page, updating the "Last updated" date, and sending you an email notification for significant changes. You are advised to review this Privacy Policy periodically for any changes.