Privacy
Effective January 1, 2020
Last Updated: September 16, 2026
This Privacy Statement explains how Opnmynd LLC dba Mindloft ("Mindloft," "we," "us," or "our") handles personal information through this website and our related nonclinical consulting, coaching, education, business-support, and communication services. It applies to other websites we operate only when they expressly link to this Statement as their applicable notice.
Clinical services are provided by Mindloft Family Therapy Incorporated dba Mindloft Care. Part II contains that practice's HIPAA Notice of Privacy Practices. That notice and applicable health-privacy law govern protected health information held by the clinical practice or handled on its behalf. The general disclosures in Part I do not authorize uses of protected health information that health-privacy law prohibits.
Where we process information solely for another business or clinical provider, we follow the applicable agreement and legal requirements. We may direct a rights request to the organization responsible for the information and assist that organization as required.

Information we collect and its sources
Contact and account information. We collect information you provide when you contact us, request a consultation, register, or enter a service relationship. This may include your name, email address, telephone number, business name, job title, mailing address, and account details.
​
Service and transaction information. We collect information relevant to the services you request, such as business goals, coaching questionnaires, assessment responses, scheduling details, purchase history, billing information, payment status, and correspondence. Payment providers process payment credentials through the payment channels they operate.
Communication information. We collect messages you send and information needed to record and honor your preferences. For SMS, this may include your mobile number, the consent language shown to you, the time and method of opt-in, message history, delivery information, and opt-out records.
​
Technical information. Our website and service providers may collect IP addresses, browser and device details, pages viewed, referring pages, approximate location inferred from an IP address, and security or error logs.
​
Sources. Information comes directly from you, from your interactions with our systems, and from service providers supporting those interactions. An organization sponsoring your services or an authorized referral source may also provide relevant contact and service information. We do not require detailed medical information in general website inquiries.
How we use information
We use contact and service information to answer inquiries, arrange consultations, provide agreed services, administer accounts, process payments, and communicate about your requests. We use technical information to operate the website, diagnose errors, prevent misuse, and maintain security.
​
We use communication preferences to send the messages you request and to honor opt-outs. We use information for marketing only where permitted and with the consent required for the communication channel. We may also maintain records to meet legal requirements, resolve disputes, and document our agreements and compliance.
​
We do not treat acceptance of this Statement as permission for every use of your information. We obtain separate consent or authorization when required. Clinical information is subject to HIPAA protections, rather than the general marketing provisions of this section.
When we disclose information
Service providers. We may disclose information to providers of website hosting, secure communications, scheduling, payment processing, business software, technical support, and other services needed to operate our business. We require protections appropriate to the information and the services. Providers may use information on our behalf only as authorized and permitted by law.
​
Your instructions and professional support. We may disclose information at your direction or as authorized in your service agreement. An employer or other sponsor does not automatically receive private coaching conversations, assessment responses, or clinical records because it pays for a service. Any reporting arrangement must be explained in the applicable agreement or consent. We may provide necessary information to professional advisers subject to appropriate confidentiality duties.
​
Legal and safety purposes. We may disclose information when required by law or when legally permitted to protect rights, investigate misuse, or respond to a serious safety concern. We evaluate applicable confidentiality restrictions before disclosing health information.
​
Business changes. A merger, acquisition, or reorganization may require limited disclosure or transfer of business information, subject to applicable law and continuing privacy obligations. This paragraph does not authorize the sale or transfer of SMS consent for another sender's use. It does not authorize a transfer or use of clinical records that health-privacy law prohibits.
Sale and advertising disclosure: We do not sell personal information or share it for cross-context behavioral advertising, and we have not done so during the preceding 48 months.
Cookies, analytics, and tracking choices
Cookies and similar technologies may support site functions, security, and saved preferences. Additional tools may measure website use or support third-party features. Browser settings can restrict or delete cookies, but some website features may not function correctly when necessary cookies are blocked.
​
A cookie preference or acceptance of this Statement is not a HIPAA authorization. We do not permit tracking tools to disclose protected health information for advertising without a valid legal basis and any required authorization. Health-related forms and patient systems require a separate privacy and security review.
SMS privacy and mobile information
We use your mobile number, messages, and consent records to provide the SMS services you select, respond to your requests, document permission, and process opt-outs. Accepting website terms or entering a mobile number does not automatically provide marketing consent.
​
Mobile information, SMS opt-in data, and consent will not be sold, rented, or shared with third parties, affiliates, or lead generators for their marketing or promotional purposes. Consent is not transferable to another sender. These restrictions apply notwithstanding any general disclosure language elsewhere in this Statement.
​
Our messaging providers, carriers, and technical support providers may process the information needed to deliver messages and operate the messaging service. They may not use information received on our behalf for their own marketing. We may retain or disclose limited consent or message records when legally required, subject to applicable confidentiality requirements.
​
You may also contact privacy@mindloft.com or communicate an opt-out through another reasonable method. Message frequency varies. Message and data rates may apply. ​
Health information and confidential communications
HIPAA coverage depends on the information involved and the capacity in which an organization handles it. Nonclinical coaching records are not automatically clinical records. Information we handle as a business associate of a covered clinical provider remains subject to applicable HIPAA duties and our agreement with that provider.
​
Use the designated secure patient channel for medical records, symptoms, treatment details, and other sensitive clinical information. Ordinary email and SMS may be intercepted, misdirected, or seen by people who can access your device or account. A communication preference does not waive our legal safeguarding duties. Contact the clinical practice to request a confidential alternative.
Information security and retention
We use administrative, technical, and physical safeguards appropriate to the information we handle. These safeguards include limiting access according to job responsibilities and applying appropriate requirements to service providers. No website, transmission method, or storage system can guarantee absolute security.
​
We assess suspected security incidents and provide notices when applicable law requires them. Please contact us if you suspect unauthorized access or believe information was sent to the wrong recipient. Do not send detailed sensitive information in an initial report through ordinary email.
​
We retain information for as long as reasonably necessary for the purpose for which it was collected and for applicable legal obligations. Retention depends on the service relationship, the sensitivity of the information, accounting requirements, consent documentation, security needs, and legal holds.
​
We retain limited opt-out information when necessary to avoid contacting you again. Clinical records follow the clinical practice's record-retention requirements. Closing a website account or submitting a deletion request does not automatically require deletion of medical, transaction, or legally required records. We delete or appropriately de-identify information when there is no continuing lawful need to retain it
Your choices and privacy requests
You may contact us to review or correct contact information, change communication preferences, or request access to or deletion of personal information. Where applicable privacy law gives you additional rights, you may request a portable copy, opt out of sale, sharing, or targeted advertising, limit qualifying uses of sensitive information, and appeal a denied request where an appeal right applies. We will not unlawfully discriminate against you for exercising privacy rights.
Submit a request to hello@mindloft.com, through [Insert privacy request form or website method], or by calling [Insert designated privacy request number; use a toll-free number where required]. We may verify your identity and an authorized agent's authority. We will explain a denial and any available appeal process. You may ask us to reconsider a denial through the same contact channels.
​
For California requests covered by the California Consumer Privacy Act, we generally respond to access, correction, and deletion requests within 45 calendar days. An extension may apply when permitted and explained. Other requests follow their applicable deadlines. Some medical information is exempt from that Act and instead remains subject to health-privacy laws.
Children and clinical consent
Our general business and marketing website is not directed to children under 13. We do not knowingly collect their personal information through those general features. Contact us if you believe a child provided information through an inappropriate website channel.
​
This statement does not prohibit lawful clinical services for minors. The clinical practice handles information about minors through its clinical processes and follows applicable consent, confidentiality, parental-access, and representative rules.
External services and processing locations
We use external services for some business funtions. An external website or independently operated service may have different privacy practices. You may request a list of third party processors at privacy@mindloft.com. Our own legal obligations continue to apply when a vendor processes information on our behalf.
Changes to this Statement
We may revise this Statement and update its effective date. We will give notice of material changes through the website or another appropriate channel. We will obtain new consent when required before using information in a materially different way. Continued browsing does not replace legally required consent or a HIPAA authorization.
Contact
Opnmynd LLC dba Mindloft
Attention: Privacy Officer
Email: privacy@mindloft.com
Mailing address: PO Box 3340, Tustin, CA 92781-3340
