Privacy Policy

Your data, your rights,
our responsibility

This policy explains what personal and health information MyoMesh collects, how it is used, who it is shared with, and how it is protected — in plain language.

Last updated: August 24, 2026  |  Effective: February 22, 2026
1

Who We Are

MyoMesh is a cloud-based practice management platform designed for registered health professionals including massage therapists, physiotherapists, chiropractors, and other regulated and unregulated practitioners. The platform provides tools for scheduling, clinical documentation, billing, analytics, and team management through the MyoMesh web platform, MyoMesh Book, MYOMESH Notes, public booking pages, and embedded booking widgets.

References to "MyoMesh," "we," "us," or "our" in this policy refer to the legal entity operating the MyoMesh platform. References to "Subscriber" or "Participating Business" refer to a practice, studio, owner, or administrator using MyoMesh. References to "Professional User" refer to an authorised owner, administrator, or practitioner. References to "Client" or "Client User" refer to an end patient or client whose information is held by a Participating Business or who uses MyoMesh Book or another client-facing booking service.

When processing personal health information on behalf of a Subscriber, MyoMesh acts as a Health Information Custodian Agent, information manager, or equivalent role depending on the applicable provincial legislation (PHIPA in Ontario, HIA in Alberta, PHIA in Newfoundland and Labrador, and the applicable framework in all other provinces and territories). The Subscriber — as the regulated health professional — remains the primary Custodian or trustee of their clients' records under whichever provincial legislation applies to their practice.

2

Information We Collect

We collect information in four broad categories: information about a Subscriber's practice and Professional User accounts, information about clients and their health records, information a Client User provides through MyoMesh Book or another booking service, and operational information generated automatically through use of the platform.

2.1 Account & Practice Information

Identity & Contact

Business name, address, province, postal code, phone number, booking URL, and business logo.

Authentication Credentials

Email address and hashed password managed by Firebase Authentication. We do not store plaintext passwords.

Billing Information

Payment method tokens provided by Stripe. We do not store full card numbers. Billing address, currency, and plan selection are stored.

Staff Profiles

Name and email address of practitioners you invite. Their role (Owner, Admin, Practitioner), approved session types, pay rates, and calendar integration credentials.

2.2 Client Health Records

This is the most sensitive category of information handled by MyoMesh and is treated as Protected Health Information (PHI). Subscribers enter this information directly into the platform on behalf of their clients.

Demographics

Full name, date of birth, gender and pronouns, address, phone, email, emergency contact, and occupation.

Clinical Information

Reason for visit, medical history, current medications, known allergies, past surgeries, relevant diagnoses, pain levels, and body chart annotations.

Session Records

Appointment history, session type, assigned practitioner, SOAP notes, treatment plans, progress milestones, and session outcomes.

Financial Records

Invoice history, payment method used, amounts charged, outstanding balances, package usage, and promotional discounts applied.

Consent & Waivers

Liability waiver status, digital signature name and timestamp, and intake form responses.

Lifestyle Information

Exercise level, type of work, stress level, sleep quality, and other intake form responses where collected.

2.3 Client Account, Booking & Plan Information

When a Client User creates an account, connects with a Participating Business, or uses a booking page, widget, or MyoMesh Book, we may collect:

  • Account information: Name, email address, phone number, Firebase user identifier, email-verification status, and authentication information.
  • Studio relationship information: The Participating Business selected by the Client User, the matching client-record identifier, and any request-to-join, lead, approval, or recognition status.
  • Booking information: Selected session or class type, date, time, practitioner, booking and cancellation status, waitlist position, attendance or check-in status, and reminder preference.
  • Package and membership information: Plans offered, purchases, eligibility, expiry or renewal status, remaining uses, and the plan applied to a booking.
  • Payment information: Amount, currency, transaction reference, payment status, and limited payment-method details returned by the payment processor. Full card numbers are collected directly by Stripe and are not transmitted to or stored by MyoMesh.

2.4 Usage & Technical Data

When you use the MyoMesh platform, we automatically generate and collect the following operational data:

  • Audit log entries: every access, edit, export, and deletion of client health records — including the user's identity, timestamp, IP address, and a description of the action taken.
  • Session metadata: login timestamps, session duration, inactivity timeouts, and device information.
  • Error and diagnostic logs used to monitor platform stability and investigate security incidents. These logs do not contain client health record content.
  • Platform usage patterns used in aggregate, anonymised form to improve product features.

2.4 MyoMesh Book Client App

When a Client App User creates or uses a MyoMesh Book account, we collect and process information needed to provide the app's booking features. This information is linked to the user's account and, after the user connects with a participating studio, to the corresponding client record maintained by that studio.

  • Account information: Name, email address, a unique account identifier, and an encrypted or hashed authentication credential managed by Firebase Authentication. A phone number may be used if multi-factor authentication is enabled.
  • Studio and booking information: Participating studios connected to the account; appointment and class selections; booking, cancellation, and waitlist activity; and the status and usage of packages or memberships.
  • Purchase information: Purchase amounts, transaction status, package or membership purchased, and Stripe transaction identifiers. Card details and billing postal codes are entered into Stripe's secure payment fields and are not stored by MyoMesh.
  • Reminder information: If the user chooses to enable booking reminders, the app collects a device push token and notification preference. Reminder notifications may include the studio name and the date and time of a booking. Reminders are optional and can be disabled in the app or in iOS Settings.
  • Technical information: IP address, device or operating-system information, authentication events, and error or diagnostic information needed for security, fraud prevention, troubleshooting, and reliable app operation.

MyoMesh Book does not request access to precise location, contacts, photos, microphone, camera, or health data stored by Apple Health. We do not use Client App User data for third-party advertising or cross-app tracking.

3

How We Use Your Information

We use collected information only for the purposes described below. We do not sell personal information to third parties. We do not use client health records for advertising, profiling, or any purpose unrelated to service delivery.

Permitted Purposes
  • Service delivery: Providing scheduling, clinical documentation, billing, and analytics features to Subscribers.
  • Account management: Creating and maintaining your account, processing billing, sending subscription-related communications.
  • Security and compliance: Maintaining audit logs, enforcing session timeouts, preventing unauthorised access, and detecting abuse.
  • Support: Responding to support requests, diagnosing technical issues, and providing onboarding assistance.
  • Legal obligations: Retaining records as required under applicable Canadian provincial health privacy legislation and federal law, responding to lawful access requests.
  • Platform improvement: Analysing anonymised, aggregated usage data to improve product features. No individual health records are used for this purpose.
  • Communications: Sending service notifications, security alerts, billing notices, and (with consent) product updates. You may opt out of marketing communications at any time.
  • Client booking services: Matching a verified Client User to a Participating Business, displaying availability, processing bookings and waitlists, applying packages or memberships, recording check-in, and sending requested reminders.
4

Health Information & Canadian Privacy Law

MyoMesh is designed for regulated and allied health practitioners across Canada and is built to support compliance with applicable personal health information legislation in every Canadian province and territory. The specific legislation that applies to a Subscriber depends on the province or territory in which they practice. MyoMesh's platform features — including audit logging, role-based access, session timeouts, and data export — are designed to meet or exceed the requirements of all Canadian provincial health privacy frameworks.

Applicable Legislation by Province
  • Ontario: Personal Health Information Protection Act (PHIPA, 2004)
  • Alberta: Health Information Act (HIA) + Personal Information Protection Act (PIPA)
  • British Columbia: Personal Information Protection Act (PIPA)
  • Quebec: Act respecting the protection of personal information in the private sector (Law 25, as amended by Bill 64, fully in force September 2023)
  • Newfoundland & Labrador: Personal Health Information Act (PHIA)
  • New Brunswick, Nova Scotia, Prince Edward Island, Saskatchewan, Manitoba, Northwest Territories, Nunavut, Yukon: Federal Personal Information Protection and Electronic Documents Act (PIPEDA) applies in the absence of substantially similar provincial legislation. Some provinces have additional health-sector guidance.

Note: Quebec, British Columbia, and Alberta have been deemed to have substantially similar privacy legislation to PIPEDA by the federal government. Subscribers in those provinces should comply with their provincial legislation as the primary applicable law.

4.1 Our Role Under Canadian Health Privacy Legislation

Regardless of province, MyoMesh acts as an agent or custodian agent of the Subscriber in relation to personal health information. We collect, use, and retain PHI only as necessary to provide the platform services, only in accordance with the Subscriber's instructions and applicable law, and never for our own commercial purposes. In the terminology of Ontario's PHIPA, we act as a Health Information Custodian Agent; under Alberta's HIA, we act as an information manager; under other provincial frameworks, our role is equivalent.

4.2 Audit Trail

Every access to, edit of, export of, and deletion of a client health record is logged in a tamper-evident audit trail. Log entries include the date and time, the identity of the user who performed the action, the affected client record, and a description of the action. Audit logs are retained for a minimum of 10 years — the period required under Ontario's PHIPA, Alberta's HIA, and consistent with best practices for health information custodians across all Canadian jurisdictions. Subscribers can access, filter, and export their organisation's full audit log at any time from the Compliance section of Settings.

4.3 Session Security

To protect client health records from unauthorised access on shared or unattended devices, the platform automatically logs out inactive sessions. The inactivity timeout is configurable by the Subscriber (5, 10, 15, or 30 minutes). Each auto-logout is recorded in the audit log.

4.4 Client Data Rights

Under Canadian provincial health privacy legislation, clients have the right to access and request correction of their own personal health information. Subscribers are responsible for fulfilling these requests in accordance with the legislation that applies in their province. MyoMesh provides tools to export a complete individual client record (demographics, session history, clinical notes, body charts, invoices, and audit trail entries) from the client's profile at any time to assist Subscribers in meeting their obligations.

Subscriber Reminder — All Provinces

If you are a Health Information Custodian, trustee, or equivalent under the health privacy legislation of your province, you are responsible for ensuring that your collection and use of client health information meets the requirements of the Act that applies to your practice. This includes obtaining appropriate consent where required and fulfilling client access requests. MyoMesh provides the tools — the legal obligations as Custodian or equivalent remain yours.

5

HIPAA (U.S. Practitioners)

For Subscribers operating in the United States who are subject to the Health Insurance Portability and Accountability Act (HIPAA), MyoMesh acts as a Business Associate in relation to any Protected Health Information (PHI) or Electronic Protected Health Information (ePHI) entered into the platform.

5.1 Technical Safeguards

MyoMesh implements the required technical safeguards for ePHI under the HIPAA Security Rule, including:

  • Access controls: Role-based access ensuring staff can only access the data appropriate to their role (Owner, Admin, Practitioner).
  • Audit controls: Automated audit logging of all access and modification of health records, as described in Section 4.2.
  • Integrity controls: Data is stored in Google Cloud Firestore with built-in integrity protections.
  • Transmission security: All data in transit is encrypted using TLS 1.2 or higher. All connections are served over HTTPS.
  • Authentication: Unique user identification and automatic session logout as described in Sections 6 and 7.

5.2 Business Associate Agreement

U.S. Subscribers who require a Business Associate Agreement (BAA) to satisfy their HIPAA obligations should contact us at hello@myomesh.ca. We will enter into a BAA with covered entities and business associates as required by law. Use of the platform by U.S. covered entities prior to execution of a BAA is at the Subscriber's risk.

6

Security & Infrastructure

MyoMesh is built on Google Firebase and Cloud Firestore, which provides enterprise-grade security infrastructure maintained by Google Cloud. Below is a summary of the technical and organisational measures in place.

TLS 1.2+ Encryption in Transit AES-256 Encryption at Rest Role-Based Access Control PHIPA Audit Logging Configurable Session Timeout Google Cloud Infrastructure

6.1 Encryption

All data stored in Cloud Firestore is encrypted at rest using AES-256 by Google Cloud. All data transmitted between your browser and MyoMesh servers is encrypted in transit using TLS 1.2 or higher. The platform is accessible only over HTTPS; unencrypted HTTP connections are not accepted.

6.2 Role-Based Access Control

Every user account in MyoMesh is assigned one of three roles — Owner, Admin, or Practitioner. Access to client records, financial data, staff management, and compliance settings is restricted based on these roles. The account Owner holds the highest level of privilege and is the only user who can perform irreversible actions such as full account data deletion.

6.3 Session Management

Sessions are managed by Firebase Authentication. The platform automatically logs out users after a configurable period of inactivity (between 5 and 30 minutes), ensuring that unattended devices do not expose client health records. Each automatic session termination is recorded in the audit log.

6.4 Google Cloud Security

MyoMesh's backend infrastructure runs on Google Cloud Platform, which maintains ISO 27001, SOC 2, and SOC 3 certifications, and is independently audited on an ongoing basis. Google Cloud's security programme and certifications are available at cloud.google.com/security.

6.5 Payment Security

MyoMesh does not store credit card numbers, card verification codes, or full bank account details. Payment processing is handled entirely by Stripe, which is certified to PCI DSS Level 1 — the highest level of payment card security certification. MyoMesh receives and stores only a tokenised reference to the payment method.

7

Multi-Factor Authentication

MyoMesh supports and encourages Multi-Factor Authentication (MFA) for all user accounts. MFA is implemented through Firebase Authentication and provides a second layer of verification beyond a password, significantly reducing the risk of unauthorised account access even if login credentials are compromised.

7.1 Staff Invitation Verification

When a Subscriber invites a new staff member to their practice, an email invitation is sent to the practitioner's verified email address. The invited user must click a unique, time-limited link in that email to create their account. This email verification step ensures that only the intended recipient can activate a staff account, and that the email address used for calendar invites and client communications is confirmed as valid.

7.2 Recommendations

Security Recommendation

We strongly recommend that all account holders enable MFA in their account settings, use a unique password for their MyoMesh account, and configure the shortest practical session timeout for their clinical environment. These measures are especially important in shared-device settings such as treatment rooms.

8

Data Retention

We retain different categories of data for different periods, based on legal requirements and legitimate operational need.

Retention Schedule
  • Client health records and session data: Retained for the lifetime of the active subscription and for 30 days following account cancellation to allow data export.
  • Audit log entries: Retained for a minimum of 10 years in compliance with the requirements of Ontario's PHIPA, Alberta's HIA, and consistent with best practices for health information custodians under all applicable Canadian provincial legislation.
  • Billing records and invoices: Retained for 7 years in accordance with standard accounting and tax obligations.
  • Authentication and session logs: Retained for 90 days for security monitoring purposes.
  • Error and diagnostic logs: Retained for 30 days.
  • Mobile push tokens: Retained while reminders are enabled and removed when the token is disabled, replaced, invalidated, or deleted as part of the associated client record.
  • Deleted client records: Removed from active systems within 30 days of deletion. Residual copies in backup systems are overwritten within 90 days.
  • Client app accounts: When a Client App User completes the in-app deletion process, the MyoMesh Book login, reminder tokens, and app-to-studio connections are deleted. Booking, payment, package, membership, waiver, and health records held by a participating studio may be retained by that studio where needed to provide services or meet accounting, regulatory, or legal obligations. Deleting the app account does not itself cancel a future booking or recurring membership.

8.1 Account Cancellation

When a Subscriber cancels their account, full access to the platform continues until the end of the final billing period. Following that, the Subscriber has a further 30-day window to download their complete organisation data. After this window closes, active client records are deleted. Audit logs are retained separately for the 10-year statutory period, regardless of account status.

8.2 Data Deletion on Request

Account Owners may request deletion of all organisation data at any time from the Account section of Settings. This action is irreversible. We strongly recommend downloading a full organisation data export before initiating deletion. Upon confirmation, all client records, session data, notes, invoices, and staff accounts are permanently deleted from active systems. Statutory records (audit logs, billing records) are retained only to the extent required by law.

9

Your Rights

Depending on your location, you may have specific statutory rights regarding your personal information. The rights described below apply to Subscribers', Professional Users', and Client Users' own account information. Client rights concerning booking, payment, or health records held for a Participating Business are addressed in Section 4 and should normally be exercised through that business as the primary custodian or controller. MyoMesh will assist the business where required.

10

Third-Party Services

MyoMesh integrates with the following third-party services to provide its features. Each third party processes data only as described below and is bound by its own privacy terms and applicable data-protection obligations. We require service providers that process user data on our behalf to use appropriate safeguards and provide the same or equivalent protection described in this policy. We do not authorise any third party to use Subscriber, Professional User, Client, or Client User data for its own advertising or unrelated commercial purposes.

Provider Purpose Data Shared
Google Firebase & Cloud Firestore Authentication, database storage, backend infrastructure, and mobile push delivery. Account and client data is stored in Firestore. Authentication credentials are managed by Firebase Auth. When a Client User enables app reminders, a Firebase Cloud Messaging device token is linked to the matching studio client record. Privacy policy →
Apple Push Notification Service Delivery of optional MyoMesh Book notifications on Apple devices. A device push token and privacy-minimal reminder content are transmitted through Apple's notification service. Notification delivery is subject to Apple's terms and device settings. Privacy policy →
Stripe Subscriber billing and client payment processing for participating studios and practices. Payment method details, billing or postal address, purchase or subscription amount, and transaction information. Card numbers are collected directly by Stripe and are never transmitted to or stored by MyoMesh. Privacy policy →
PayPal Optional client-facing payment processing within the platform. Client payment details handled by PayPal's hosted flow. MyoMesh receives only transaction confirmation. Privacy policy →
Google Calendar Optional calendar integration for automatic appointment event creation. Session date, time, client first name, and practitioner name for calendar event creation. Requires explicit OAuth authorisation by each practitioner. Privacy policy →
Microsoft Outlook / Azure Optional calendar integration for automatic appointment event creation. Same as Google Calendar. Requires explicit MSAL authorisation. Privacy policy →
Intuit QuickBooks Optional accounting integration for income and expense synchronisation. Invoice amounts, session types, and payment status. No client health information is shared with QuickBooks. Privacy policy →
SMS Provider (Twilio) Optional SMS appointment reminders and notifications. Client phone number, first name, and appointment date and time. SMS is an optional add-on and is only active if purchased by the Subscriber. Privacy policy →
OpenAI (MyoMind AI) AI processing for the optional MyoMind clinical intelligence feature. De-identified note content only — identifiers are removed in the browser and again server-side before transmission. Governed by an executed Business Associate Agreement and Zero Data Retention amendment; content is not retained or used for training. See Section 16. Privacy policy →

Google Workspace API — Limited Use Disclosure

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

11

International Data Transfers

MyoMesh's primary data infrastructure is hosted on Google Cloud Platform. Google Cloud data residency is determined by the region configuration at the time of account creation. Canadian Subscribers' data is stored in data centres located in Canada by default.

Certain third-party integrations — such as Stripe and Twilio — may involve data processing in the United States or other jurisdictions. These providers maintain appropriate safeguards for international transfers including Standard Contractual Clauses where applicable. By enabling these integrations, Subscribers consent to any associated cross-border data transfers.

The optional MyoMind AI feature involves processing of de-identified clinical content by OpenAI on US infrastructure, under an executed Business Associate Agreement and Zero Data Retention amendment. No identifiable personal health information leaves Canada, and no content is retained by the AI provider after processing. Full disclosure is provided in Section 16 and in the Data Processing Agreement.

If you require specific data residency guarantees, contact us at hello@myomesh.ca before enabling any third-party integrations.

12

Cookies, Browser & Device Storage

MyoMesh uses browser and mobile-device storage mechanisms to maintain sessions, protect work in progress, remember app choices, and improve performance. On public marketing pages only, visitors may choose to allow Meta Pixel so we can measure advertising performance and reach people who have shown interest in MyoMesh. Meta Pixel is not loaded inside authenticated MyoMesh accounts, clinical records, client intake, booking, or notes workflows.

Storage Types Used
  • localStorage: Used to cache your organisation's settings, user identity, and UI preferences (such as dark mode) locally in your browser to reduce loading time. This data never leaves your device unless explicitly synced to Firestore.
  • Firebase Authentication cookies: Firebase sets a session cookie to maintain your authenticated session. This cookie is strictly necessary for platform functionality and cannot be disabled while you are logged in.
  • MyoMesh Book device storage: Used to remember the selected studio, reminder preference, reminder prompt state, and authenticated session. Removing the app clears app-local data but does not delete the Client User account or cloud records held by a Participating Business.
  • MYOMESH Notes device storage: Used to maintain the authenticated session and temporarily preserve unsigned note drafts so a Professional User can recover work in progress. Drafts may contain personal health information and are removed after signing, when cleared by the user, or after 30 days.
  • Meta Pixel on public marketing pages: If a visitor selects “Allow” in the advertising-cookie notice, Meta Pixel may receive the page visited, browser and device information, and marketing actions such as viewing pricing or submitting a practice enquiry. We use this information to measure Meta advertisements, build advertising audiences, and improve campaign performance. Visitors may decline without losing access to the website or the MyoMesh service.
  • No advertising tracking in the platform: Meta Pixel and other third-party advertising trackers are not loaded in authenticated accounts or clinical, client, intake, booking, and notes areas. MyoMesh does not send patient information, clinical information, or personal health information to Meta for advertising.
13

Data Breach Notification

In the event of a security incident that results in the actual or suspected unauthorised access to, use, or disclosure of personal health information, MyoMesh will act promptly in accordance with applicable law.

Breach Response Process
  • Containment: We will immediately take steps to contain and remediate the incident.
  • Assessment: We will assess the nature, scope, and likely impact of the breach on affected individuals.
  • Subscriber notification: We will notify affected Subscribers without unreasonable delay, and in any event within 72 hours of becoming aware of a confirmed breach involving their organisation's data, where required by law.
  • Regulatory notification: Where required by applicable Canadian provincial health privacy legislation (including PHIPA, HIA, PHIA), PIPEDA, HIPAA, GDPR, or Quebec's Law 25, we will notify the relevant regulatory authority within the prescribed timeframe.
  • Individual notification: Where the breach creates a real risk of significant harm to individuals, we will notify affected individuals in accordance with applicable requirements.

Subscribers who become aware of a potential security incident involving their MyoMesh account — including lost devices, compromised credentials, or suspicious activity — should immediately contact us at hello@myomesh.ca and change their password.

14

Children's Privacy

Subscriber and Professional User accounts may only be created by individuals who are 18 years of age or older. We do not knowingly collect personal information from persons under 18 for the purpose of creating a Subscriber or Professional User account.

Participating Businesses may hold health and booking records for clients who are minors as part of legitimate clinical or wellness services. A minor may use client-facing services only with the involvement and consent of a parent, legal guardian, or other authorised representative, subject to applicable law and the Participating Business's policies. The Participating Business is responsible for obtaining any consent required before collecting information from or about a minor client.

15

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will notify you by email at the address associated with your account at least 30 days before the changes take effect.

The "Last updated" date at the top of this policy reflects the most recent revision. Continued use of the MyoMesh platform after the effective date of a revised policy constitutes your acceptance of those changes.

16

MyoMind AI & De-identified Processing

MyoMind is an optional AI-powered clinical decision-support feature. When a practitioner uses MyoMind, the content of the selected note is automatically de-identified before it leaves the practitioner's browser: client names, email addresses, phone numbers, health card numbers, dates of birth, and street addresses are removed or replaced. A second server-side pass repeats this filtering before any content reaches the AI provider.

De-identified content is processed by OpenAI OpCo, LLC (USA) under an executed Business Associate Agreement and Zero Data Retention amendment (June 18, 2026). Under these agreements, submitted content is not retained after processing and is not used to train AI models. AI responses are returned to the practitioner and saved only where the practitioner chooses to save them. No identifiable personal health information is transmitted to the AI provider, and no personal health information is stored outside Canada.

Full technical and contractual disclosure of the MyoMind data flow, including cross-border transfer considerations, is set out in Section 7 of the Data Processing Agreement and Section 17 of the Terms of Service.

17

Mobile Applications

This section explains the data practices specific to MyoMesh Book and MYOMESH Notes. The rest of this Privacy Policy also applies to both applications.

17.1 MyoMesh Book

MyoMesh Book is a client-facing application used to find and connect with a Participating Business, create or verify a client account, view availability, book or join a waitlist, check in to eligible classes, manage upcoming bookings, and view or purchase packages and memberships. One MyoMesh login may connect to multiple Participating Businesses, but each business relationship and its bookings, plans, payments, and policies remain separate.

For records created or held as part of a Client User's relationship with a Participating Business, that business is the primary custodian or controller and MyoMesh processes the information as its service provider or agent. A new account or request to join may be provided to the selected business as a lead or prospective-client record so the business can review and respond to the request. Depending on the business's settings, the Client User may be required to match an existing client email or receive approval before viewing availability or booking.

17.2 MyoMesh Book Notifications

Push notifications are optional. Permission is requested through the device operating system when a Client User chooses to enable reminders. If permission is granted, MyoMesh receives a Firebase Cloud Messaging registration token and links it to the verified client record at the selected Participating Business. The token is used only for operational app notifications such as upcoming-booking and class check-in reminders. Reminder text is designed to be privacy-minimal and may include the business name and appointment time but not clinical note content.

A Client User may disable reminders in MyoMesh Book or in the device's notification settings. Disabling operating-system permission may prevent delivery even if the in-app preference remains enabled. We do not use notification tokens as advertising identifiers or for cross-app tracking.

17.3 MYOMESH Notes

MYOMESH Notes is a professional clinical-documentation application available only to authorised Professional Users. It accesses the same organisation membership, client records, appointments, clinical notes, templates, body-chart entries, measurements, and audit controls as the MyoMesh web platform. Information created or changed in the app is synchronised with the Subscriber's MyoMesh records in accordance with the user's role and permissions.

To protect work in progress, MYOMESH Notes may temporarily store an unsigned note draft on the device. Because a draft can contain personal health information, Professional Users must secure the device, avoid sharing it, and promptly report loss or suspected unauthorised access. Signed notes are stored in the Subscriber's cloud record; removing the app does not delete those records.

17.4 Device Authentication

MYOMESH Notes may use Face ID, Touch ID, or the device passcode to unlock the app. Biometric matching is performed by the device operating system. MyoMesh receives only the result of the authentication check and does not receive, store, or have access to facial images, fingerprints, or biometric templates.

17.5 Payments, Tracking & App Stores

Purchases made in MyoMesh Book relate to real-world services supplied by the selected Participating Business. Card and billing information is collected by Stripe on behalf of that business as described in Section 10. MyoMesh does not use information from either mobile application for third-party advertising or cross-app behavioural tracking.

Apple or another app marketplace may independently collect download, purchase-history, device, crash, or diagnostic information under its own privacy policy. MyoMesh does not control information collected directly by an app marketplace.

17.6 Access, Correction & Deletion

Client Users may permanently delete their MyoMesh Book login from Account > Delete account in the application. Completing that flow deletes the Firebase Authentication account and removes app-specific studio links and push-notification tokens. Requests concerning appointments, payments, memberships, packages, intake forms, waivers, or health records should normally be directed to the relevant Participating Business, which remains responsible for the underlying client relationship and any legally required retention. Those studio-controlled records are not automatically erased when the MyoMesh login is deleted.

Deleting an application from a device, deleting the MyoMesh Book login, or signing out does not cancel bookings, memberships, subscriptions, or recurring payments. Client Users should cancel those items through an available control or contact the relevant Participating Business. Privacy requests may also be submitted using the contact details in Section 18.

18

Contact & Privacy Requests

Questions, concerns, or requests relating to this Privacy Policy or the handling of your personal information should be directed to:

Privacy enquiries & data subject requests:
hello@myomesh.ca
Please include "Privacy Request" in the subject line.

Security incidents & breach reporting:
hello@myomesh.ca

Accessibility concerns:
accessibility@myomesh.ca

In-app support: Available through the support chat inside your MyoMesh dashboard.

We aim to respond to all privacy requests within 5 business days, and to resolve them within 30 days.