Skip to content
Mimos

Privacy Policy

Last updated: August 9, 2026

This is our Privacy Policy. Mimos’s Terms of Use (EULA) are on a separate page. View the Terms of Use →

1. About this policy and who it is for

Mimos is a multi-tenant software-as-a-service (SaaS) platform that grooming businesses use to manage clients, pets, appointments, messaging and an online booking storefront. The platform is operated by Mimos Technology Inc. ("Mimos", "we", "us"), 108 W 39th St, STE1006 PMB2057 New York City, 10018 NY, USA.

This policy explains what personal data we process, why, on what legal basis, who we share it with, how long we keep it, and what rights you have. It applies to:

  • Grooming businesses that subscribe to Mimos (our direct customers) and the staff users within those businesses who hold an account.
  • Pet owners ("clients") whose details a grooming business stores in Mimos or who book through a business's online storefront.
  • Visitors to our website at joinmimos.com and to our application and booking pages.

2. Our role: controller and processor

Mimos plays two distinct data-protection roles. It is important to understand which applies to you.

We are the controller for personal data where we decide the purposes and means of processing — principally:

  • Account and staff-user data (registration, authentication, billing administration, support, security).
  • Technical and usage data we collect to run, secure and improve the platform.
  • Communications between us and our business customers.

We are a processor (and the grooming business is the controller) for the personal data a business enters or generates about its own clients and their pets — for example client contact details, pet records, appointment history, photos, vaccination records and message logs. We process that data only on the documented instructions of the business for the purpose of providing the service. Each business is responsible for having a lawful basis to collect this data and for responding to its own clients' privacy requests; our processing is governed by the data-processing terms in our Terms of Use, which function as our data processing agreement (DPA).

If you are a pet owner and want to access, correct or delete the information a grooming salon holds about you, please contact that salon directly — they control your record. We will assist them as their processor.

3. Personal data we process

The exact data present depends on how a business configures Mimos and what it chooses to record. The categories below reflect what the platform is capable of storing.

3.1 Business and staff-user accounts (Mimos as controller)

  • Identity & contact: first and last name, email address, phone number.
  • Authentication & security: hashed password, email-confirmation and password-reset tokens, "remember me" token, failed-login counters and lockout state, and sign-in metadata (timestamps and IP addresses of current/last sign-in).
  • Sign-in options: if you sign in with Google or Apple, we receive your name, email address and an account identifier from that provider; if you register a passkey, we store its public key — biometric data never leaves your device.
  • Profile: optional avatar photo, and — for staff who are bookable groomers — biography, specialties, calendar colour, hire date and commission percentage.
  • Working data: working hours, time-off (including any reason recorded), location assignments, and the business's configuration/settings.
  • Role & membership: which business(es) the user belongs to and their role (admin or member).

3.2 Client and pet data (Mimos as processor, on behalf of the business)

  • Pet owner ("client") details: name, email address(es), phone number(s), postal/billing address(es), free-text notes, acquisition source, household relationships, and tags/labels — whether entered manually or imported in bulk (for example from a CSV of the business's existing client list).
  • Messaging preferences and consent: whether the client consented to automated reminders/marketing messages, when consent was given or withdrawn, and the preferred channel (SMS, email or none).
  • Pet records: name, species, breed, date of birth, sex, size, weight, coat/temperament, allergies and medical notes, and pet photos (profile photo and grooming before/after photos).
  • Vaccination records: vaccine name/type, dates administered and expiring, verification and any override reason/notes, and an uploaded proof document (photo or PDF of a certificate).
  • Appointments & service history: bookings, times, status, price snapshots, appointment notes/special instructions, and which staff member performed the service.
  • Payments & deposits: where a business enables booking deposits, records of deposit amounts, status and Stripe payment references. Card details stay with Stripe; we never see or store them.
  • Consents & signatures: waiver/consent documents captured at check-in, including photo-consent flags, the signer's name and a digital signature payload, plus the document version/locale and timestamp.
  • Reviews & testimonials: ratings and free-text comments submitted by clients (some via tokenised links), and any testimonial author name/photo a business chooses to publish.
  • Communications: a log of messages sent to or received from clients, including the recipient phone/email, channel (SMS, WhatsApp, email), message body, direction, delivery status and any error.

Sensitive data note. Allergies and medical notes about pets are animal health information, not special-category personal data about a human. However, free-text fields (client notes, appointment notes, review comments) could contain whatever a user types. Businesses should avoid recording special categories of personal data about people in these fields.

3.3 Data collected automatically

  • Session and authentication cookies (see §6).
  • Server and security logs including IP address, request metadata and user-agent, used for operating, securing and debugging the service. Passwords, tokens, OTP codes and similar secrets are filtered out of our logs.
  • Performance and tracing telemetry via our application-performance-monitoring provider (see §7), consisting of request and tracing metadata.
  • Product analytics events (e.g. funnel/usage events with a session identifier and the authenticated user, where applicable).
  • Mobile push tokens for staff who use the companion iOS or Android app (device token, platform, environment, last-seen time). Push is delivered via Apple Push Notification service (APNs) on iOS and Firebase Cloud Messaging (FCM) on Android; the token data collected is the same on both platforms.
  • First-party website telemetry on joinmimos.com: aggregate counts of pages viewed, traffic source, scroll depth and clicks on calls to action. It uses no cookies — a visit identifier is held in your browser’s session storage and disappears when you close the tab — and it never records what you type into a form.
  • Google Analytics 4 on joinmimos.com. It loads on every page in a restricted, cookieless mode; only if you accept the analytics category does it set first-party cookies (_ga, _ga_<id>) holding a pseudonymous identifier and record the pages you view, how you arrived, and your device, browser, language and approximate location.
  • Google click identifiers on joinmimos.com. If you accept the advertising category and you arrive from a Google advertisement, we keep the identifier Google added to the link (gclid, gbraid or wbraid). It travels with you to the sign-up page, and if you create an account we send it, with the time, to Google Ads so the account can be matched to the advertisement you clicked. We never send your name, your email address, or anything you typed. Without your consent to advertising the identifier is not kept at all.
  • Subscription and purchase data for Mimos Pro (our paid plan). When you subscribe through the App Store or Google Play, we process the store transaction identifier, the product identifier (e.g. the monthly or yearly plan), a pseudonymous per-account identifier the app sends to the store (Apple appAccountToken / Google obfuscatedAccountId, derived from your account ID) and the resulting entitlement/subscription status. If you subscribe on the web through Stripe, we process your Stripe customer and subscription identifiers, the product identifier and the subscription status. We process this solely to grant and manage access to Mimos Pro.

We do not store payment-card numbers or bank-account details; Mimos is not a payment processor.

4. Why we process data and our legal bases

Where the GDPR (EU/EEA), Brazil's LGPD, or other applicable data protection laws apply, we rely on the following bases:

PurposeExamplesLegal basis
Provide the service to businessesCreate/maintain accounts, store client & pet records, run bookingsPerformance of a contract
Process client/pet data for a businessHosting and operating the business's CRM dataProcessor acting on the business's instructions (the business relies on its own basis)
Authentication & account securityLogin, password reset, lockout, rate limitingLegitimate interests / contract
Service communicationsConfirmations, password resets, invitations, appointment reminders/notificationsContract / legitimate interests; consent for client marketing/reminder messages where required
Reliability & security monitoringError tracking, performance monitoring, abuse preventionLegitimate interests
Comply with legal obligationsTax/accounting records, responding to lawful requestsLegal obligation
Improve the productAggregated/usage analyticsLegitimate interests

For our own marketing to businesses, or where consent is otherwise required, we rely on consent, which you may withdraw at any time.

5. Client messaging and consent

Mimos can send SMS and email messages to a business's clients (for example appointment reminders and confirmations), with WhatsApp messaging available where enabled. WhatsApp messages are sent from the business's own WhatsApp Business number through Meta's WhatsApp Business Cloud API, with Mimos acting as a Meta "Tech Provider" on the business's behalf. The platform records and enforces messaging consent: a client's consent status and timestamp are stored, and automated client messages are gated on that consent. Clients can withdraw consent at any time by contacting the business or following opt-out instructions where provided. Message logs are retained as part of the business's records (see §9).

6. Cookies and similar technologies

Mimos uses a small number of strictly necessary cookies to operate. These include:

  • A session cookie (e.g. _pet_crm_session) to keep you signed in and protect against cross-site request forgery. It is HttpOnly, SameSite=Lax and (in production) Secure (HTTPS-only).
  • A "remember me" cookie set only if you choose that option at sign-in, so you stay logged in across browser sessions; it is cleared on logout.

Because these cookies are essential to providing a service you request, they do not require consent under the ePrivacy rules. Separately, only after you accept the advertising category do we load Meta Pixel on the web or activate the Meta SDK in the mobile apps. We may use a pseudonymous account identifier, installation, device or advertising identifiers where available and permitted, and limited interaction, registration and subscription events to measure campaigns and attribute results. On iOS we also request App Tracking Transparency (ATT) permission. You can reject or withdraw this consent at any time through web cookie preferences or Privacy in the app; withdrawal stops future use and deliveries.

On our website at joinmimos.com we also ask for consent to analytics cookies. Google Analytics 4 loads on every page, but until you accept the analytics category it runs in a restricted mode: it sets no cookies, uses no identifier, and sends Google only the page address, your device and browser, and an approximate location derived from your IP address. Only if you accept do we set first-party analytics cookies (_ga, _ga_<id>, lasting up to 24 months) that link your visits together. Google Signals and ads personalisation are switched off, so these cookies are not used to build advertising audiences. Rejecting takes one click, and you can change or withdraw your choice at any time under “Cookie preferences” in the site footer.

Only after you accept the advertising category do we load the Google Ads tag on the sign-up pages of app.joinmimos.com. It reads the click identifier from the link you arrived on and sets Google advertising cookies (_gcl_*) lasting up to 90 days. When you complete the sign-up form it reports that single conversion to Google Ads. The report may be sent from your browser or from our own servers; either way it carries the click identifier and the time, and nothing you typed. You can change or withdraw this consent at any time under “Cookie preferences” in the site footer, or under Privacy in the app, and withdrawal stops any further use.

7. Service providers and sub-processors

We share personal data with the third parties below strictly to provide the service. Each is bound by data-protection terms. This list may change; we will keep it current.

ProviderRoleData involved
RenderApplication hosting, managed PostgreSQL database, backups, logsAll application data
Cloudflare R2Object storage for uploaded filesPhotos (avatars, pet, grooming, testimonials), logos, vaccination proofs
Redis (managed)Background-job queue / cacheTransient job data referencing records
ResendTransactional email deliveryRecipient name & email, message content (confirmations, resets, invitations, reminders)
SweegoTransactional SMS delivery (appointment reminders, confirmations)Recipient phone number (E.164), message content
Google — Google Analytics 4Website audience measurement on joinmimos.com. Loads on every page in a restricted mode that sets no cookies and uses no identifier; cookies and analytics identifiers are used only after you accept the analytics categoryIn restricted mode: page address, referrer, device, browser, language and approximate location derived from your IP address, with no cookie or persistent identifier. After acceptance: additionally a pseudonymous cookie identifier (_ga, _ga_<id>) linking your visits
Google — Google AdsAdvertising measurement for joinmimos.com and the sign-up pages. Loaded only after you accept the advertising category. Lets Google match a sign-up to the advertisement that was clicked.The Google click identifier (gclid, gbraid or wbraid), the time of the sign-up, an internal reference for that event, and Google advertising cookies (_gcl_*). No name, email address or telephone number.
Meta Platforms (WhatsApp Business Cloud API)WhatsApp message transmission using the business's own WhatsApp Business number (Mimos acts as Tech Provider; Meta bills the business directly for conversations)End-client phone number/WhatsApp ID, message content, delivery metadata
Apple Push Notification service (APNs)iOS push notifications to staff appDevice push token, notification content
Google — Firebase Cloud Messaging (FCM)Android push notifications to the staff appDevice push token, notification content
Apple — App Store / StoreKitProcessing the Mimos Pro subscription and sending us transaction and entitlement dataTransaction identifier, product identifier, pseudonymous per-account identifier (appAccountToken), subscription status
Google — Google Play BillingProcessing the Mimos Pro subscription and sending us transaction and entitlement dataPurchase/transaction identifier, product identifier, pseudonymous per-account identifier (obfuscatedAccountId), subscription status
StripeProcessing the Mimos Pro subscription on the web (Stripe Checkout) and, where a business enables them, booking-deposit payments through the business's connected Stripe account (Stripe Connect)Stripe customer and subscription identifiers, product/price identifier, subscription status; for deposits, payment identifiers and amounts (no card details)
DatadogApplication performance monitoring (production)Request/tracing metadata
SlackInternal operational alerts to Mimos (e.g. new sign-ups/bookings)Limited account/booking metadata
Companion mobile backend webhookNotifying our mobile app of data changesAccount ID, event type, timestamp (signed)
Fontshare (Indian Type Foundry)Serves the web font used in the interfaceThe browser's IP/user-agent when loading the font
Meta Platforms — Meta Pixel / Meta SDK / Conversions APIAdvertising measurement and campaign attribution, only after applicable consent (and ATT on iOS where required)Pseudonymous account identifier; installation, device or advertising identifiers where permitted; limited interaction, registration and subscription events; and campaign metadata — never customer, pet, appointment, message or note content

Planned (not yet active): error tracking via Sentry is integrated in our codebase but is not enabled in production, so it is not processing personal data today. If we turn it on, we will update this section; error reports may then include IP address, request headers and the identifiers of the affected user.

Connected Mimos products. If a pet owner links their Mimos Pets profile and authorises sharing, the business can view the profile sections the owner chose to share (for example identity, grooming notes, behaviour, allergies, conditions, medication and vaccinations). This sharing is controlled by the pet owner's authorisation in Mimos Pets and can be revoked there.

We do not sell personal data or share it for third-party ad targeting. Communication with Meta is limited to the measurement and attribution described above and is activated only with your consent.

8. International data transfers

Our primary application infrastructure — application servers, database and background jobs — is hosted in the European Union (Frankfurt). Some providers may nevertheless process data outside the country where you are located, including in the United States. Where data is transferred out of the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant), or a provider's adequacy/Data Privacy Framework certification. Details of the safeguards for a specific transfer are available on request at [email protected].

9. Data retention

  • Account and staff-user data is retained for as long as the business's subscription is active and for a reasonable period afterwards, then deleted or anonymised, subject to legal retention obligations (e.g. tax/accounting).
  • Client, pet, appointment, photo and vaccination records are retained for the business (the controller) for as long as it keeps them. Some records use soft deletion (marked deleted and hidden but retained) so history and appointment records stay consistent; they are not automatically purged.
  • Change history / audit trail. For integrity and accountability, changes to key records are versioned in an audit log and retained for the life of the account unless purged.
  • Message logs are retained as part of the business's communication records.
  • Account closure / deletion. When a business account is deleted, its associated data (memberships, clients, pets, appointments, services, invitations, etc.) is removed. On request we will delete or return a business's data in line with our DPA and applicable law.
  • Backups are retained for a limited rolling window and then overwritten; deletion requests are honoured in active systems immediately and propagate as backups cycle out.

If you would like a specific retention schedule documented, contact us at [email protected].

10. How we protect data

  • Encryption in transit: HTTPS/TLS is enforced across the application (HSTS/force_ssl in production); cookies are Secure and HttpOnly.
  • Password protection: passwords are hashed with bcrypt (work factor 12) and never stored or logged in plain text.
  • API access: programmatic access uses bearer tokens stored only as a salted HMAC-SHA256 digest (the raw token is never persisted); tokens can be revoked and expired.
  • Abuse prevention: rate limiting on sign-in, sign-up, password-reset and OTP endpoints, and account lockout after repeated failed logins.
  • Log hygiene: passwords, tokens, OTPs and other secrets are filtered from application logs.
  • Tenant isolation: each business's data is logically segregated per account.
  • Access control: role-based permissions (admin/member) and policy checks gate access within an account.
  • Mobile session security: the mobile app stores its session token in the device's secure storage (iOS Keychain / Android Keystore), optionally protected by device biometrics where you enable them; biometric data never leaves your device and is handled entirely by the operating system.

No system is perfectly secure, but we take reasonable and appropriate technical and organisational measures to protect personal data and will notify affected parties and regulators of a personal-data breach where the law requires.

11. Your rights

Subject to applicable law (such as the GDPR and the LGPD), you may have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten") in certain circumstances.
  • Restrict or object to certain processing, including processing based on legitimate interests and direct marketing.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time where processing is based on consent.
  • Lodge a complaint with your local data protection or supervisory authority.

How to exercise your rights:

  • If Mimos is the controller (your account/staff-user data), contact us at [email protected]. We will respond within the timeframe the law requires (one month under the GDPR, extendable). We may need to verify your identity.
  • If your data was entered by a grooming business (i.e. you are that business's client), contact that business — it is the controller. We will support it in fulfilling your request: Mimos gives businesses built-in tools for this, including a per-client data export in a machine-readable format and a two-step erasure flow.

12. Children

Mimos is intended for businesses and adults. It is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us and we will delete it.

13. Automated decision-making

We do not use the personal data described here to make decisions producing legal or similarly significant effects about you solely by automated means.

14. Changes to this policy

We may update this policy to reflect changes in the product, our providers or the law. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice (e.g. in-app or by email). Continued use after the effective date constitutes acceptance where permitted by law.

15. Contact us

Questions, requests or complaints about privacy:

Email: [email protected]

Postal: Mimos Technology Inc., 108 W 39th St, STE1006 PMB2057 New York City, 10018 NY, USA

This English version is the reference text. Translations into other languages may be provided for convenience; in case of conflict, the English version prevails.