Last updated: July 30, 2026
Mumzie Holdings LLC, doing business as Mumzie ("we", "us", or "our"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our practice management platform for birth and postpartum doulas ("Platform" or "Service").
Please read this Privacy Policy carefully. By using the Platform, you consent to the practices described in this policy. If you do not agree with this policy, please do not use the Platform.
We collect information that you voluntarily provide when you:
When you access the Platform, we automatically collect:
We use cookies and similar technologies to keep you logged in, remember preferences, understand usage, improve the Platform, and provide analytics and performance data.
On public marketing pages, we use optional analytics to measure anonymous, aggregated site traffic only after you allow analytics in Privacy choices. Our public-site analytics do not use cookies, persistent visitor identifiers, or cross-site tracking. Mumzie removes query strings other than standard campaign tags and replaces public profile slugs before an event is sent. Public-site analytics are not used on authenticated, booking, or legal pages and do not receive care content or custom properties.
Optional analytics, experimentation, and advertising technologies are used only after you allow the corresponding category in Privacy choices. We retain a pseudonymous receipt of each public privacy choice with the category decisions, policy version, source, and timestamp. The receipt does not include your name, email address, account identifier, care content, or browsing history. You can allow or decline each optional category independently and change your choices at any time using Privacy choices.
After a provider creates an account, Mumzie sends an analytics service provider a limited set of server-generated service lifecycle events to measure registration, setup, activation, and service adoption. These events use only provider and organization identifiers plus lifecycle fields such as role, locale, practice type, and account age. They never include client identifiers, names, email addresses, care content, or free text. This service measurement is separate from optional browser analytics.
If you allow analytics, Mumzie uses a random first-party identifier to keep anonymous feature experiment assignments consistent. Mumzie evaluates flags on its servers and sends an analytics service provider a limited exposure event containing the experiment key, variation key, feature key, and a pseudonymous identifier. The identifier is your account UUID after sign-in or the random visitor UUID before sign-in. Names, email addresses, care content, health information, and URL query strings are not included. Declining or withdrawing analytics prevents the visitor identifier from being created or removes it and prevents exposure events.
You can control cookies through your browser settings. Disabling cookies may limit your ability to use certain Platform features.
We may receive information from calendar integrations, payment processors, and analytics providers when needed to provide the Service.
When you choose to connect Google Calendar, Mumzie receives OAuth access and refresh tokens and accesses events on your primary Google Calendar. The event data we access may include event identifiers, titles, start and end times, and event status.
We use Google Calendar data only to provide the calendar integration features you request through Mumzie: identifying scheduling conflicts, displaying availability, and creating, updating, or deleting Mumzie appointment events in your Google Calendar. When Mumzie creates or updates an event, it sends the appointment title, start and end times, location, and any notes included in that appointment.
Mumzie accesses Google Calendar events when needed to provide these features and does not store copies of events retrieved solely for conflict checking. We store the Google Calendar event identifier needed to maintain a synced Mumzie appointment and retain OAuth tokens only while your Google Calendar remains connected.
We do not sell, rent, or disclose Google Calendar data to advertisers, ad networks, analytics providers, data brokers, or other independent third parties. Our infrastructure providers may process Google Calendar data only as necessary to host, secure, and operate the Service on our behalf, subject to contractual confidentiality and security obligations. Google Calendar data is not used for advertising or to develop, improve, or train generalized artificial intelligence or machine learning models.
We protect Google Calendar data using encryption in transit, encryption at rest provided by our infrastructure providers, secure server-side handling of OAuth credentials, and access controls. You may disconnect Google Calendar at any time from Settings. When you disconnect, Mumzie deletes the OAuth tokens associated with the connection. You may also request deletion of your Mumzie account and associated personal information by contacting hello@gomumzie.com.
We do not sell your personal information.
We share information when you direct us to, such as when you make your profile public or share client information with backup doulas.
We share information with service providers that perform database and authentication services, payment processing, hosting and content delivery, video call infrastructure, server-side feature rollout, analytics, experimentation, and anonymous public-site measurement on our behalf. Analytics and experimentation service providers do not receive care content, custom properties, or visitor identifiers from public-site measurement.
These providers are contractually obligated to use your information only to provide services to us and to maintain appropriate security measures.
After you allow advertising technologies, we may share limited public-page interaction and conversion data with advertising partners for campaign measurement and ad delivery. We do not intentionally send client records, care content, booking details, or Protected Health Information through advertising tags.
We may disclose information if required by law, court order, subpoena, legal process, government request, or regulatory request, or to protect our rights, property, safety, users, or the public.
If Mumzie Holdings LLC is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
Account deletion
When you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required for legal or legitimate business purposes.
We retain your information for as long as your account is active or as needed to provide services. We may also retain and use information to comply with legal obligations, resolve disputes, enforce agreements, and maintain business records.
We implement appropriate technical and organizational measures to protect your information, including encryption in transit and at rest, secure authentication, access controls, security monitoring, employee training, and incident response procedures.
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
You have the right to access personal information we hold about you and to receive a copy of your data in a portable format.
You can update or correct account information at any time through your account settings.
You can request deletion of your account and personal information by contacting hello@gomumzie.com.
You can opt out of marketing communications by using unsubscribe links or updating notification preferences.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
Data Transfers
Your information may be transferred to and processed in the United States. We use appropriate safeguards, such as Standard Contractual Clauses, to protect information during international transfers.
If you are in the European Economic Area, United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR).
For users on subscription tiers with HIPAA-ready infrastructure enabled, we implement additional safeguards for Protected Health Information (PHI).
The Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete it.
The Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties and encourage you to review their privacy policies.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on the Platform with an updated Last updated date or by sending an email notification for significant changes.
Your continued use of the Platform after changes take effect constitutes acceptance of the revised Privacy Policy.
If you have questions or concerns about this Privacy Policy or our data practices, please contact us.