Privacy policy

What we store, who can see it and how to get it corrected or removed, in plain words.

Updated . MindMaster is made by Modoware. Contact admin@modoware.com.

What we store

We store only what is needed to run your practice in MindMaster.

  • Account details: your name, your email address and a hashed copy of your password.
  • Practice details: the practice name, the hours you see clients, your usual session length and fee, and the settings for your booking link.
  • Client records and notes: the contact details, intake notes, emergency contacts, sessions, case notes, follow-up tasks and fees that you or your team type in.
  • Booking requests: the name, phone number and chosen time that a client submits through your booking link.
  • Technical logs: the time of each request, the page or endpoint it called and the IP address it came from, kept for a short time so we can find and fix faults.

Who can see it

Your practice's records are visible only to the users of your practice. Every record is tied to your practice, and no other practice can see it.

Modoware staff look at a practice's records only when you ask for help through a support ticket, and only for as long as that ticket needs. Our admin console shows counts and practice names, never client names or notes.

We never sell your data, and we never share it with advertisers or anyone else, apart from the companies listed under Who we work with, which act on our instructions.

Where it is stored

Your data lives on a server in Singapore run by DigitalOcean. Everything travels between your browser and that server over HTTPS, so it is encrypted on the way. Passwords are stored as hashes, which means nobody can read them, including us.

Emails we send

We send email through Brevo. You may receive:

  • A welcome email when you create your practice.
  • A few setup reminders in your first weeks if parts of your practice are not set up yet.
  • A daily summary of your sessions, only if you switch it on in Settings.
  • An email each time a client books or cancels through your booking link, with their name and phone number.
  • A password reset link when you ask for one.

To stop the daily summary, switch it off in Settings. To stop any other email, write to admin@modoware.com and we will turn it off. Password reset emails only go out when you ask for one.

Analytics and cookies

Google Analytics runs only on our public pages, such as the home page and the guides. It does not run inside the app or on any booking page, so nothing about your clients or their appointments is sent to Google. IP addresses are anonymised.

The app uses your browser's storage to keep you logged in between visits. We do not use advertising cookies.

Who we work with

Three companies process data on our behalf, each for the one purpose named here:

  • DigitalOcean, which hosts the server and the database in Singapore.
  • Brevo, which delivers the emails listed above. It receives the recipient's email address and the content of that email.
  • Google Analytics, which counts visits to our public pages only.

Your responsibilities as a practitioner

You decide what goes into MindMaster about your clients, so you are the data controller for those records, and we process them on your behalf.

You are responsible for having your clients' consent to keep their records here, for what you write in your notes, and for keeping your password to yourself. If a client asks what you hold about them, the tools in the next section let you answer.

Your clients' rights

A client can ask you to see, correct or delete what you hold about them. You can:

  • Export every client, session, note and task as CSV files from Settings, at any time.
  • Correct a client's details on their page, at any time.
  • Ask us to delete a client's record by writing to admin@modoware.com. We do it within 30 days and confirm by email.
  • Close your whole account by writing to admin@modoware.com. Export first, because we cannot bring the data back afterwards.

How long we keep data

We keep your data for as long as your account exists. When you ask us to delete a client's record or to close your account, the data is removed from the live database within 30 days, and copies in our backups expire within 30 days after that.

Technical logs are kept for a short time to find and fix faults, then discarded.

Changes to this policy

If we change this policy in a way that matters to you, we will email the address on your account before the change takes effect, and we will update the date at the top of this page.

Contact

For any question, request or complaint about your data, write to admin@modoware.com. A person reads every message, and we aim to reply within a working day.

See also the terms of service.