MYSTC PRIVACY POLICY
Last Updated: April 6, 2025
1. INTRODUCTION
Mystc ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website located at mystc.io, our mobile applications, and all related services (collectively, the "Services").
Please read this Privacy Policy carefully. By accessing or using the Services, you acknowledge that you have read, understood, and agree to be bound by all the terms of this Privacy Policy and our Terms of Service.
2. INFORMATION WE COLLECT
We collect several types of information from and about users of our Services:
2.1 Personal Information
Personal information is information that identifies you as an individual or relates to an identifiable individual. We may collect the following types of personal information:
2.1.1 Account Information
- Name
- Email address
- Phone number
- Mailing address
- Date of birth
- Profile picture
- Account credentials (username and password)
2.1.2 Payment Information
- Credit/debit card details
- Billing address
- Payment transaction history
2.1.3 Health and Wellness Information
- Information you provide about your health concerns
- Wellness goals
- Energy healing preferences
- Session notes and feedback
- Any other information you choose to share with Practitioners
2.1.4 Practitioner Information
For users who register as Practitioners, we may also collect:
- Professional qualifications
- Experience and specialties
- Insurance information
- Background check information
- Service offerings and rates
- Availability schedule
2.2 Usage Information
We may automatically collect certain information about your device and how you interact with our Services, including:
- IP address
- Device type and operating system
- Browser type and version
- Time zone setting
- Pages visited and features used
- Time spent on pages
- Referring website
- Search terms used to find our Services
- Click patterns and interactions with the Services
- Session duration and timing
2.3 Location Information
With your consent, we may collect precise location information from your mobile device when you use our mobile applications. You can disable location services through your device settings.
2.4 Communications
If you contact us directly, we may receive additional information about you, such as your name, email address, phone number, the contents of your message, and any other information you choose to provide.
3. HOW WE COLLECT INFORMATION
We collect information through various methods:
3.1 Direct Collection
Information you provide to us when you:
- Register for an account
- Complete your profile
- Book or provide services
- Make payments
- Communicate with other users
- Contact our support team
- Complete surveys or provide feedback
3.2 Automated Collection
Information collected automatically through:
- Cookies and similar technologies
- Server logs
- Web beacons
- Pixel tags
- Mobile device identifiers
- Analytics tools
3.3 Third-Party Sources
Information we may receive from third parties:
- Payment processors
- Identity verification services
- Background check providers
- Social media platforms (if you connect your account)
- Marketing partners
- Public databases
4. HOW WE USE YOUR INFORMATION
We use your information for various purposes, including:
4.1 Providing and Improving the Services
- Creating and managing your account
- Connecting clients with appropriate Practitioners
- Processing payments and transactions
- Facilitating communication between clients and Practitioners
- Providing customer support
- Analyzing usage patterns to improve the Services
- Developing new features and services
4.2 Communication
- Sending service-related notifications
- Providing updates about your bookings
- Responding to your inquiries
- Sending promotional communications (with your consent)
- Conducting surveys and collecting feedback
4.3 Security and Compliance
- Verifying your identity
- Detecting and preventing fraud
- Enforcing our Terms of Service
- Protecting the security of our Services
- Complying with legal obligations
4.4 Personalization
- Customizing your experience
- Recommending Practitioners based on your preferences
- Tailoring content and marketing communications
- Remembering your settings and preferences
5. INFORMATION SHARING AND DISCLOSURE
We may share your information in the following circumstances:
5.1 Between Users
- When clients book sessions with Practitioners, we share relevant information to facilitate the service
- Client information shared with Practitioners may include name, contact information, and health/wellness concerns
- Practitioner information shared with clients may include name, qualifications, specialties, and ratings
5.2 Service Providers
We may share information with third-party vendors who perform services on our behalf, including:
- Payment processors
- Cloud storage providers
- Analytics providers
- Customer support services
- Email and communication services
- Identity verification services
- Marketing and advertising partners
5.3 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court order, government request).
5.4 Business Transfers
If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction.
5.5 With Your Consent
We may share your information with third parties when you have given us your consent to do so.
5.6 Aggregated or De-identified Data
We may share aggregated or de-identified information that cannot reasonably be used to identify you with third parties for various purposes, including data analysis, research, and service improvement.
6. DATA SECURITY
We implement appropriate technical and organizational measures to protect the security of your personal information. However, please be aware that no method of transmission over the Internet or method of electronic storage is 100% secure.
Our security measures include:
- Encryption of sensitive information
- Secure server infrastructure
- Regular security assessments
- Access controls and authentication requirements
- Staff training on data protection
- Incident response procedures
7. DATA RETENTION
We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. The criteria used to determine our retention periods include:
- The length of time we have an ongoing relationship with you
- Whether there is a legal obligation to which we are subject
- Whether retention is advisable in light of our legal position (such as for statutes of limitations, litigation, or regulatory investigations)
8. YOUR PRIVACY RIGHTS
Depending on your location, you may have certain rights regarding your personal information:
8.1 Access and Portability
You may request access to the personal information we hold about you and request a copy of your information in a structured, commonly used, and machine-readable format.
8.2 Correction
You may request that we correct inaccurate or incomplete personal information about you.
8.3 Deletion
You may request that we delete your personal information in certain circumstances.
8.4 Restriction
You may request that we restrict the processing of your personal information in certain circumstances.
8.5 Objection
You may object to our processing of your personal information in certain circumstances.
8.6 Withdrawal of Consent
Where we rely on your consent to process your personal information, you have the right to withdraw your consent at any time.
8.7 Complaint
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal information violates applicable law.
To exercise any of these rights, please contact us at privacy@mystc.io.
9. CHILDREN'S PRIVACY
Our Services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will take steps to delete such information as soon as possible.
10. INTERNATIONAL DATA TRANSFERS
Your information may be transferred to, and maintained on, computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those in your jurisdiction.
If you are located outside the United States and choose to provide information to us, please note that we transfer the information to the United States and process it there. Your submission of such information represents your agreement to that transfer.
11. COOKIES AND SIMILAR TECHNOLOGIES
11.1 Cookies
We use cookies and similar tracking technologies to track activity on our Services and hold certain information. Cookies are files with a small amount of data that may include an anonymous unique identifier.
11.2 Types of Cookies We Use
- Essential Cookies: Necessary for the functioning of the Services
- Preference Cookies: Remember your preferences and settings
- Analytics Cookies: Help us understand how users interact with our Services
- Marketing Cookies: Used to deliver relevant advertisements and track marketing campaign performance
11.3 Your Choices
Most web browsers allow you to control cookies through their settings preferences. However, if you limit the ability of websites to set cookies, you may impact your overall user experience.
12. THIRD-PARTY LINKS AND SERVICES
Our Services may contain links to third-party websites, services, or applications that are not operated by us. This Privacy Policy does not apply to such third-party services. We encourage you to review the privacy policies of any third-party services you access.
13. MARKETING COMMUNICATIONS
We may send you marketing communications about our Services, but you can opt out of receiving these at any time by:
- Following the unsubscribe instructions in any marketing email we send
- Updating your communication preferences in your account settings
- Contacting us directly at privacy@mystc.io
14. SPECIAL NOTICE FOR HEALTH INFORMATION
14.1 Not Covered by HIPAA
While Mystc is not a covered entity under the Health Insurance Portability and Accountability Act (HIPAA), we voluntarily implement many HIPAA-inspired safeguards to protect your health and wellness information.
14.2 Health Information Protections
We treat any information related to your health and wellness with the highest level of confidentiality and implement appropriate security measures to protect such information.
14.3 Practitioner Confidentiality
All Practitioners on our platform are required to maintain the confidentiality of client information and are prohibited from disclosing such information except as permitted by our Terms of Service and applicable law.
15. CALIFORNIA PRIVACY RIGHTS
If you are a California resident, you have specific rights regarding your personal information under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
15.1 Right to Know
You have the right to request information about the personal information we have collected about you, including the categories of information, sources, purposes of collection, and categories of third parties with whom we share the information.
15.2 Right to Delete
You have the right to request deletion of personal information we have collected from you, subject to certain exceptions.
15.3 Right to Opt-Out
You have the right to opt-out of the sale or sharing of your personal information, if applicable.
15.4 Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA/CPRA rights.
To exercise your California privacy rights, please contact us at privacy@mystc.io.
16. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.
You are advised to review this Privacy Policy periodically for any changes.
Significant changes will be communicated to you directly when possible (e.g., by email if we have your contact information).
17. CONTACT US
If you have any questions about this Privacy Policy, please contact us at:
Email: privacy@mystc.io
By using the Mystc platform, you acknowledge that you have read and understood this Privacy Policy.