← MyVital Harmony

Privacy Policy

Last updated: July 14, 2026

MyVital Harmony LLC (“MyVital Harmony”, “we”, “us”) operates myvitalharmony.com, a platform that independent healthcare and wellness businesses (“Businesses”) use to run online booking, payments, secure messaging, programs, and reporting. This policy explains what we collect, why, and the choices you have. It covers both Business accounts (owners and staff) and the clients and patients of those Businesses who book, pay, or use a client portal.

The two roles we play

For Business account information (your login, business profile, billing), we decide how data is used — we act as the data controller. For the information a Business keeps about its own clients (appointments, messages, notes), the Business decides — we process that data on the Business’s behalf and on its instructions. If you are a client of a Business using this platform, your care relationship — and most decisions about your information — belong to that Business; contact them first with questions about your records.

What we collect

Account data: name, email, password (stored as a hash by our authentication provider), business name, and role. Booking data: services, appointment times, and the contact details a client enters when booking. Payment data: processed by Stripe — card numbers never touch our servers; we keep references, amounts, and payout status. Messages and visit notes: stored in an isolated health-data vault, separated from operational data, with every access recorded in an audit log. Technical data: logs, approximate location from IP, and the cookies described below.

What we do NOT do

We do not sell personal information. We do not use client health information for advertising — we show no ads at all. Our AI drafting features never receive client or patient data; they operate only on the instruction a practitioner types. One Business’s data is never visible to another Business — isolation is enforced at the database layer on every query.

Who we share data with

Service providers who run parts of the platform under contract: Supabase (database and authentication), Vercel (hosting), Stripe (payments), Resend (transactional email), and Cloudflare (DNS/network). Each receives only what its function requires. We disclose information if the law compels us to, and in a merger or acquisition your data remains protected by this policy or one at least as protective.

Cookies

We use only functional cookies: keeping you signed in, remembering your language, and remembering which of your businesses is active. No advertising or cross-site tracking cookies.

Retention and deletion

Business data is retained while the account is active. Audit logs are append-only by design and retained for accountability. When a Business closes its account, we delete or anonymize its data within a commercially reasonable period, except where law requires longer retention (for example, payment records). Clients seeking deletion of their records should contact their Business, which controls them.

Security

Encryption in transit, per-tenant database isolation enforced on every query, a segregated vault for health-related content with per-view audit records, and role-based access controls throughout. No system is perfectly secure; we notify affected parties of breaches as the law requires.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information. Business account holders can exercise these directly at support@myvitalharmony.com. Clients of a Business should contact that Business; we support Businesses in honoring these requests.

Children

The platform is for adults. Businesses may keep records about minors in their care as permitted by law; those records are governed by the Business’s own policies.

Changes and contact

We’ll post changes here and update the date above; material changes get direct notice to account holders. Questions: support@myvitalharmony.com · MyVital Harmony LLC, Alaska, USA.

Privacy Policy — MyVital Harmony