This policy explains what [ENTITY] (“Mindhyv”, “we”, “us”) does with personal data across mindhyv.com and the Mindhyv application at app.mindhyv.com. The data controller is [ENTITY], [REGISTERED ADDRESS].
The short version
- We collect what we need to run accounts, bookings, and payouts — not more.
- We do not sell personal data.
- Payment card details go to our payment provider, not to us.
- You can access, export, correct, or delete your data by emailing [email protected].
1. What we collect
You give us
- Account details — name, email, password hash, and optionally a phone number.
- Profile and storefront content — business name, bio, service listings, pricing, availability, portfolio images, and location or service area.
- Verification data — identity documents, business registration, licences, or insurance evidence, depending on the badge. See how verification works.
- Payout details — bank or payout account information and the tax identifiers the payment provider requires.
- Transaction and communication records — bookings, orders, invoices, messages between buyers and sellers, reviews, and dispute submissions.
- Support correspondence — what you send us and our replies.
We collect automatically
- Technical data — IP address, browser and device type, pages viewed, referring URL, and timestamps.
- Usage data — searches, listings viewed, and feature interactions, used to improve the product and detect abuse.
What we do not collect: we never receive your full card number, CVC, or bank login. Those go directly to our payment provider. Our free tools — the calculators, generators, and builders under tools — run in your browser; the figures you type into them are not sent to us or stored on our servers.
2. Why we use it, and our legal basis
| Purpose | Legal basis |
|---|---|
| Creating and running your account; delivering bookings and payouts | Performance of a contract |
| Charging subscriptions and platform fees | Performance of a contract |
| Verification, fraud prevention, and dispute handling | Legitimate interests; legal obligation |
| Tax, accounting, and anti-money-laundering records | Legal obligation |
| Service emails you cannot opt out of (receipts, security, policy changes) | Performance of a contract; legitimate interests |
| Marketing emails and newsletters | Consent — withdraw any time via the unsubscribe link |
| Analytics and product improvement | Consent or legitimate interests, per [COOKIE APPROACH] |
We do not use your data to make automated decisions with legal effects on you, other than automated fraud and risk screening — where a decision blocks or holds your account or payout, you can ask a human to review it.
3. What other people can see
Your public storefront — business name, listings, prices, portfolio, service area, reviews, and any verification badges — is visible to anyone, including search engines. Your email address, payout details, verification documents, and private messages are not public. When a booking is made, the buyer and seller see the contact and scheduling details needed to complete it.
4. Who we share it with
We use processors to run the Service. Each is bound by contract to use data only on our instructions:
- Payment processing and payouts — [PAYMENT PROVIDER]
- Identity and business verification — [VERIFICATION PROVIDER]
- Hosting and infrastructure — [HOSTING / DATABASE PROVIDER]
- Transactional email — [EMAIL PROVIDER]
- Analytics — [ANALYTICS PROVIDER, or “none”]
- Customer support tooling — [SUPPORT PROVIDER]
We also disclose data when the law requires it — valid legal process, a regulator, or to protect someone's safety — and in a merger or acquisition, in which case we will tell you before your data moves to a new controller. We do not sell personal data, and we do not share it with third parties for their own advertising.
5. International transfers
Some processors operate outside [JURISDICTION]. Where data leaves that region we rely on [TRANSFER MECHANISM — e.g. Standard Contractual Clauses, adequacy decision] and assess the safeguards in place. You can ask us for details of the mechanism used for a specific transfer.
6. Cookies
We use cookies that are strictly necessary — keeping you signed in, remembering your plan context, and security. [COOKIE APPROACH: list any analytics or preference cookies, the consent mechanism, and how to change the choice.] You can clear or block cookies in your browser, though sign-in will stop working without the necessary ones.
7. How long we keep it
- Account and profile data — while your account is open, then deleted or anonymised within [RETENTION PERIOD] of closure.
- Transaction, invoice, and tax records — [STATUTORY PERIOD], because we are legally required to keep them.
- Verification documents — [RETENTION PERIOD] after a check completes or an account closes.
- Messages and dispute records — [RETENTION PERIOD], so a dispute can be reopened or audited.
- Server and security logs — [RETENTION PERIOD].
Public reviews you have left may stay visible after your account closes, detached from your profile, so the record for the seller stays intact.
8. Security
We use encryption in transit, hashed passwords, access controls limiting staff access to what their role needs, and logging of administrative actions. No system is perfectly secure; if a breach affects your personal data we will notify you and the relevant regulator as the law requires.
9. Your rights
Depending on where you live, you can ask us to:
- give you a copy of your data, or export it in a portable format;
- correct data that is wrong or incomplete;
- delete data we no longer have a legal reason to keep;
- restrict or object to processing based on legitimate interests;
- withdraw consent for marketing or optional analytics at any time.
Email [email protected] and we will respond within [RESPONSE PERIOD — e.g. one month]. Exercising these rights costs nothing and we will not treat you differently for it. If you are unhappy with our response you can complain to [SUPERVISORY AUTHORITY].
10. Children
Mindhyv is for people 18 and over. We do not knowingly collect data from children. If you believe a child has given us data, email [email protected] and we will delete it.
11. Changes to this policy
We will post changes here and update the date at the top. For material changes we will email account holders at least [NOTICE PERIOD] before they take effect.
12. Contact
Privacy questions or requests: [email protected], or write to [ENTITY], [REGISTERED ADDRESS]. [DATA PROTECTION OFFICER / EU-UK REPRESENTATIVE, if one is required]. See also our terms of service.