Privacy Policy

Last Updated: September 18, 2020

Mindleap Health Inc. (“Mindleap” “us“, “we“, or “our“) takes your privacy seriously. This Privacy Policy describes our policies and practices concerning the collection, use, and disclosure of Personal Information of users of our Services, (“Users”), such as clients and Specialist. This Privacy Policy does not address our privacy practices in respect of our employees, which are described in our Employee Privacy Policy. If you are an employee of Mindleap, please read our Employee Privacy Policy. If you are unsure which Privacy Policy applies to you, please contact our Privacy Officer for more information.

This Privacy Policy forms part of our Terms of Use. Capitalized terms not defined in this Privacy Policy have the meanings provided in the Terms of Use. As used in this Privacy Policy, “Services” includes https://specialist.mindleap.health/

We do not sell your Personal Information to third-parties.

A. What Personal Information Do We Collect?

We collect several different types of information for various purposes to provide and improve our provision of services and delivery of products to you and other persons. We will collect only the minimum amount of Personal Information required to achieve the purpose of the collection. By using our Services, purchasing any products or services available through the Services, or by providing Personal Information to us, you consent to our Privacy Policy.

The application of this Privacy Policy is limited to Personal Information and does not apply to business information to the extent it is not also Personal Information. Canadian privacy legislation defines “Personal Information” broadly as information about an identifiable individual or as information that allows an individual to be identified.

The types of Personal Information that we may collect about you includes:

  • Information we require and request when you register an account on the Services;
  • Contact and residency information, such as your full name, home or business address, telephone number, personal email address;
  • Emergency contact information;
  • Your username and any ID assigned to you by us;
  • Biographical information, such as your birthday and gender;
  • Your image and voice when you use the video-chat functionality of the Services;
  • Profile photos you upload to the Services;
  • Information concerning your goals, habits, emotions, mood, and circumstances;
  • Health related information, including medical and clinical history, medications and supplements you take or have taken, and information about your medical conditions (including mental disorders);
  • Information about your preferences, including preferences for Specialists;
  • Information about you in notes prepared by Specialists;
  • Information about yourself that you submit on the Services;
  • Location information, such as your GPS coordinates.
  • Payment and financial information, such as billing, banking information, credit card information; and
  • Cookies and website Usage Data.

We also collect any other Personal Information you voluntarily provide to us. For example, if you submit Personal Information to us through any of our online forms, PDF forms, physical forms, by email, text, the chat function on the Services, by telephone, or in person, we may collect that Personal Information and may use and disclose it as set out in this Privacy Policy or as otherwise described to you at the time of collection.

Information Mindleap Collects from Specialists

If you are a Mindleap Specialist, we may also collect the following Personal Information:

  • Your tax ID number;
  • Information about your skills, training, qualifications, and credentials;
  • Background checks and record verification information;
  • Ratings, review, and feedback about you; and
  • Other information we may request during the registration process which you voluntarily provide us.

We use this information to pre-screen Specialists, to maintain quality standards on the Services, facilitate payments by clients to Specialists, and to help clients and Specialists find each other on the Services.

Feedback About Other Users

We collect feedback, ratings, and comments about Specialists from clients. We use this information to help clients match with appropriate and suitable Specialists and to maintain quality standards on the Services.

Information Collected About Persons Under Age 18

We do not intend to collect data from or about anyone under the age of 18. If you believe that we have collected the Personal Information of anyone under the age of 18, please contact our Privacy Officer at privacyoffice@mindleap.health or at the address provided in the Contact Information section below.

Website Usage

Like most other web services, we may monitor traffic patterns, website and App usage, and related website and App information to optimize your use of our Services (“Usage Data”). This Usage Data may include information such as your device’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our website or App that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

We use mobile analytics to gain insights on how our App works on your phone. Such analytics may record how often you use the App, when you use the App, events that happen within the App, performance data, crash logging, aggregated usage, and the source from which you downloaded the App.

B. Why Do We Collect Your Personal Information?

In general, we collect, use, and disclose Personal Information so as to provide the Services to you, to facilitate coaching relationships between Specialists and clients, to better understand product and service needs and to offer and deliver relevant information, products, and services to meet those needs. As well, we collect Personal Information to provide our users of our Services with newsletters and relevant information concerning our activities and developments in the industry.

More specifically, we use the collected Personal Information for various purposes, such as:

  • To supply you with the requested content, products, opportunities, or services, including the use of our online store and in-App purchases;
  • To facilitate transactions and for other billing-related purposes;
  • To facilitate refunds, returns, and account registration;
  • To help clients and Specialists find each other;
  • To facilitate transactions and communications between clients and Specialists;
  • To facilitate and support the provision of Specialist Services from Specialists to clients;
  • To verify and authenticate account and registration information;
  • To verify and enforce compliance with our Services’ Terms of Use;
  • To supervise and monitor use of the Services;
  • To confirm if you meet our eligibility for use of the Services;
  • To build your profile on the Services;
  • If you are a Specialist, to rate and review the quality of your Specialist Services on the Services;
  • To allow you to participate in interactive features of our Services when you choose to do so;
  • To help you analyze and track your mental health and to see your progress over time;
  • If you are Specialist, to help you analyze and track your clients’ mental health and to see their progress over time;
  • To tailor our services to you;
  • To support research, if you have consented to participate in such research;
  • To provide insights and analysis on use and users of our Services, in an aggregate and de-identified form. For example, we might publish aggregated and de-identified information in scientific journals or contribute such information to scientific research. We also may use such information assess the demographics of Users and gain other valuable insights on our Users and their use of our Services.
  • To manage your account and provide you with requested services;
  • To respond to inquiries and provide customer support;
  • To notify you about changes to our products and services;
  • To gather analysis or valuable information so that we can improve our products and services;
  • To monitor the usage of our Services;
  • To detect, prevent and address technical and security issues;
  • To verify your identity, protect against error and fraud, and conduct investigations;
  • To serve you with relevant search results;
  • To provide you with news, special offers and general information about other content, products, services, opportunities, and events which we offer that are similar to those you have already purchased, engaged with, or enquired about unless you have opted not to receive such information;
  • To communicate with you about our Services and other related matters;
  • To market the Services to you;
  • To contact you, your emergency contacts, or emergency services if we or your Specialist believe you are at risk of harm or may be the cause or victim of a criminal act;
  • For any other purposes that are disclosed to you and to which you consent;
  • To protect the safety of you, other Users, our staff, and the public;
  • to defend or enforce our legal rights and interests; and
  • For any purposes required or authorized by law, including responding to law enforcement requests.

Your phone calls or enquiries via online-chat with Mindleap representatives may be recorded for quality assurance, training, and management purposes, and to keep a record of our commitments to you.

C. Cookies

In addition to any information that you choose to submit to us, we or selected third parties may use a variety of technologies to collect and analyze certain information concerning how you access and use our Services. We use a variety of technologies to collect, analyze, store, and use this information, including the following:

  • Cookies – a cookie is a file placed on a device when a user visits a website. Cookies can be temporary (e.g. session) or permanent (e.g. persistent).
    • Session Cookies – We use Session Cookies to operate our Services. Session cookies are set when you log into any of our websites. These cookies contain a user’s authentication details, and, where authorized, the settings for the admin area interface of our websites. Session cookies for logins will expire every 15 days.
    • Comments Cookies – When a user leaves a comment on any of our websites, WordPress automatically sets a cookie containing the user’s name, email address, and URL. This cookie allows WordPress to automatically fill username, email, and URL fields on the user’s subsequent visits. The comment cookie expires in 347.222 days or 30000000 seconds.
    • Authentication Cookies – These help us establish whether you have been authenticated to use https://specialist.mindleap.health/.
  • Facebook Conversion Tracking Pixel – We use the Facebook Conversion Tracking Pixel analyze the effectiveness of our ads on Facebook and Instagram and understand who comes to our website from those platforms. This technology allows us to track the actions of users of our Services after they have been redirected to our Services as a result of clicking on an advertisement on Facebook or Instagram. This allows us to measure the effectiveness of our marketing campaigns on Facebook and Instagram. From our perspective, the collected data is and remains anonymous. To our knowledge, we cannot link the collected data to an identifiable individual. However, Facebook can link such data with your Facebook or Instagram account and may use such data for their own advertising purposes, in accordance with Facebook’s Data Policy located at: https://www.facebook.com/policy.php. Facebook Conversion Tracking Pixel enables Facebook and its partners to display advertisements to you outside of our website and the Facebook and Instagram platforms. This will result in a cookie being stored on your device.

Cookies are files with small amounts of data which may include an anonymous unique identifier. Cookies are sent to your browser and are stored on your device. Tracking technologies may also be used, such as beacons, tags, and scripts, to collect and track information and to improve functionality and performance of our website, including tailoring our website to increase the relevancy of content displayed to you.

When you visit our websites, we may use any of the above technologies to collect information such as the type of Internet browser, operating system and device you use, the domain name of the website from which you came, your preferences, date and duration of the visit, number of visits, average time spent on our website, pages viewed and number of cookies accumulated. We use cookies to improve and customize your experience and to analyze and measure information about visitors’ on our websites, and on other platforms, and for the other purposes identified above.

Subject to the features of your browser, you can reset your browser to either to notify you when you have received a cookie or to refuse to accept cookies. However, if you refuse to accept cookies, you may not be able to use some of the features available on our Services.

Manage Your Cookie and Other Technology Preferences

We obtain your consent to our information collection technologies by providing you with transparent information in our Privacy Policy and providing you with the opportunity to make your choice whether to use our Services. You have the right to object to the use of information collection technologies. Regular cookies may generally be disabled or removed by tools that are available as part of most commercial

browsers, and in some but not all instances can be blocked in the future by selecting certain settings. Each browser you use will need to be set separately and different browsers offer different functionality and options in this regard. Also, these tools may not be effective regarding Flash cookies or HTML5 cookies. For information on disabling Flash cookies go to Adobe’s website (www.adobe.com).

To opt-out of the Facebook Conversion Tracking Pixel, please visit: https://www.facebook.com/ads/website_custom_audiences

Please be aware that if you disable or remove these technologies some parts of our Services will not work. When you revisit any of our websites, your ability to limit cookies is subject to your browser settings and limitations.

D. Withdrawal of Consent

You may withdraw your consent to our collection, use, and disclosure of your Personal Information at any time, subject to legal and/or contractual restrictions and reasonable notice. Your withdrawal of consent to our collection, use and disclosure of your Personal Information may impact our ability to provide you with products and services and may impact your ability to use our Services or receive Specialist Services. To withdraw consent, please contact our Privacy Officer at privacyofficer@mindleap.health or by using the contact information provided below in our Contact Information section.

E. Transfer of Information

In some cases, your information, including Personal Information, may be transferred to — and maintained and processed on — computers located outside of Canada. Therefore, your Personal Information may be available to government authorities under lawful orders and laws applicable in those foreign jurisdictions. When we transfer your Personal Information to a third party to provide administrative, processing, or other services, we use appropriate measures to require that the party will only use your Personal Information to perform the services we specified.

If you are located outside Canada please note that your data, including Personal Information, may be transferred to Canada and processed there or in other countries. By using any of our products or services, or by sending us any Personal Information, you consent to such transfers.

Mindleap will endeavour to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Information will take place to a third party organization unless such organization is obligated to maintain adequate security safeguards over your Personal Information.

Disclosure of Personal Information

Generally, we do not disclose your Personal Information to third parties without your consent. However, in order to provide you with the Services and other products, services, and opportunities, we may need to transfer your Personal Information to our employees, contractors, consultants and other parties who require such information to assist us with providing the Services to you and with managing and administering our relationship with you, including:

  • third parties that provide services to us or on our behalf;
  • IT and security consultants, only to the minimum extent necessary for them to provide us with such services and only subject to strict confidentiality obligations;
  • third parties that assist Mindleap in the provision of services to you (such as web services providers); and
  • third parties whose services we use to conduct our business (such as payment processors and other financial services providers).

Additionally, in order to provide you with products or services, we may need to transfer your Personal Information to third party technology companies for the purposes of processing and storing your Personal Information. Our business necessitates using: (a) cloud storage and hosting providers; (b) email services providers, including email marketing service providers; and (c) and payment processors including Stripe. We consider these services, platforms, and applications to be integral to our delivery of products and services to you.

So that you are able to receive the Specialist Services from Specialist, we disclose certain Personal Information about you to the Specialists. For example:

  • When you authorize disclosure of Personal Information from your Account to Specialists, we will disclose that information to such Specialists;
  • We disclose information on your public profile to Specialists who view your profile;
  • We disclose Specialist Notes (i.e. notes each specialist records during and after your sessions) to any Specialist who is engaged to provide you with Specialist Services; and
  • Specialists and clients can view and hear each other when using our video-chat functionality through the Services.

Under certain circumstances, Mindleap may disclose your Personal Information if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

We reserve the right to disclose Personal Information to a third party in the event that we merge with or are acquired by a third party, or as part of the negotiations leading up to such merger or acquisition. As used in the previous sentence, a merger includes the sale of substantially all of the assets of Mindleap to a third party. We may also disclose your Personal Information for any other purpose permitted by law or to which you consent.

We may disclose your Personal Information in the good faith belief that such action is necessary to:

  • To protect and defend the rights or property of Mindleap Health Inc.;
  • To prevent or investigate possible wrongdoing in connection with our products or services;
  • To protect the personal safety of you, other Users, or the public; or
  • To protect against legal liability.

F. Third-Party Service Providers

To administer and operate our Services and to provide you with other products and services, we may need to provide third-party service providers with access to your Personal Information.

1. Hosting and Data Storage
Our websites are hosted on the WordPress platform that is provided by a company named Automattic Inc. All Personal Information collected on our websites is collected by WordPress’ systems. To learn about WordPress’ privacy practices, please visit Automattic’s Privacy Notice and Cookie Policy.

We also use various “plugin” software made available by third-party vendors who service WordPress users. Our use of plugins may result in Personal Information being shared with the third-party vendors of the plugins.

2. Analytics Services

Google Analytics
We use Google Analytics. Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google Analytics collects information anonymously and uses the data collected to track and monitor the use of our website. This data is shared with other Google services. Google may use the collected data to contextualize and personalize the ads of its own advertising network.

Google collects various types of data from users, including IP addresses, ISP information, browser type, operating system, URL clickstream information (to, through, and from our website), including dates, times, cookies, length of time spent on pages, links clicked, and other related site visit information.

You can opt-out of having made your activity on our Services available to Google Analytics by installing the Google Analytics opt-out browser add-on. The add-on prevents the Google Analytics JavaScript (ga.js, analytics.js, and dc.js) from sharing information with Google Analytics about visits activity.

For more information on the privacy practices of Google and how Google uses your data, please visit the Google Privacy Terms web page: http://www.google.com/intl/en/policies/privacy/ and www.google.com/policies/privacy/partners/.

3. Behavioral Remarketing/Retargeting Services
We use remarketing (aka retargeting or online behavioural advertising) services to advertise on third party websites to you after you visit our website. We and our third-party vendors use cookies to inform, optimize and serve ads based on your past visits to our website.

Google AdWords
Google AdWords remarketing service is provided by Google Inc.
You can opt-out of Google Analytics for Display Advertising and customize the Google Display Network ads by visiting the Google Ads Settings page: http://www.google.com/settings/ads.
To opt-out, Google also recommends installing the Google Analytics Opt-out Browser Add-on – https://tools.google.com/dlpage/gaoptout – for your web browser. Google Analytics Opt-out Browser
Add-on provides visitors with the ability to prevent their data from being collected and used by Google Analytics.
For more information on the privacy practices of Google, please visit the Google Privacy Terms web page: http://www.google.com/intl/en/policies/privacy/.

Twitter remarketing service is provided by Twitter Inc.
You can opt-out from Twitter’s interest-based ads by following their instructions: https://support.twitter.com/articles/20170405.
You can learn more about the privacy practices and policies of Twitter by visiting their Privacy Policy page: https://twitter.com/privacy

Facebook’s Conversion Tracking Pixel service is provided by Facebook Inc.
You can learn more about Facebook Pixel here: https://www.facebook.com/business/help/742478679120153
To opt-out from Facebook Pixel, follow these instructions from Facebook: https://www.facebook.com/ads/website_custom_audiences
Facebook adheres to the Self-Regulatory Principles for Online Behavioral Advertising established by the Digital Advertising Alliance. You can also opt-out from Facebook and other participating companies through the Digital Advertising Alliance in the USA http://www.aboutads.info/choices/, the Digital Advertising Alliance of Canada in Canada http://youradchoices.ca/ or the European Interactive Digital Advertising Alliance in Europe http://www.youronlinechoices.eu/, or opt-out using your mobile device settings.
For more information on the privacy practices of Facebook, please visit Facebook’s Data Policy page: https://www.facebook.com/privacy/explanation.

4. Payments
Many of our products and services require payment from you. Additionally, our Services may facilitate payments by you to Specialists. When payment is required, we use third-party services for payment processing (e.g. payment processors).
Third-party payment processors use of your Personal Information is governed by their Privacy Policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.
The payment processors we work with are:

Stripe’s Privacy Policy can be viewed at https://stripe.com/en-ca/privacy

G. Information Retention

We retain your Personal Information only for so long as necessary to fulfill the uses identified in this Privacy Policy and as necessary for us to comply with our legal requirements. Once we no longer need your Personal Information to fulfill these purposes, or if you delete your Account, we will delete your Personal Information, subject to reasonable processing times. Any data maintained afterwards will be De-Identified Data only, except that some Personal Information might be maintained as archives on our data recovery or backup systems – such Personal Information will be deleted in the normal course of expiry of our backup files. Additionally, and despite the foregoing, we may continue to maintain your Personal Information if necessary to comply with applicable law, court order, to carry out investigations, or to defend or enforce our legal rights and interests.

H. Safeguards and Risks

Mindleap uses appropriate safeguards to ensure that your Personal Information is protected against loss, theft, misuse, unauthorized access, disclosure, or alteration. These include security of our physical premises, and various security safeguard software and firewalls to prevent unauthorized computer access.

While we endeavour to keep your Personal Information safe, our collection, use, and disclosure of your Personal Information is not without risks. For example, our security safeguards may be compromised by viruses, hacking attempts, or physical break-ins. Consequently, we cannot guarantee the security of your Personal Information. If your Personal Information was wrongfully accessed, there is a risk that you may suffer a harm, such as identity or credit card theft, embarrassment, loss of employment, or financial loss.

Please be careful whenever sending Personal Information to us via email. Email is generally not a secure means of transferring information. We therefore cannot guarantee that this information will not be lost or used in a fraudulent manner and we encourage the use of email encryption to communicate with us.

I. Access and Rectification

You have a right to challenge the accuracy and completeness of your Personal Information and to have it amended, as appropriate. You also have a right to request access to your Personal Information and receive an accounting of how that information has been used and disclosed, subject to certain exceptions prescribed by law. For example, if the requested information would reveal Personal Information about another individual, your request for access may be limited or denied.

To request access or to amend your Personal Information, please write to our Privacy Officer at privacyofficer@mindleap.health or at the address provided in our Contact Information section below.

J. Links to Other Sites

Our Services may contain links to other sites that are not operated by us. If you click on a third party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.

K. Age Restriction


We do not knowingly collect or maintain Personal Information from people under 18 years old. If we learn that Personal Information of people under 18 years old has been collected by us, we will take appropriate steps to delete this information unless we are legally required to keep it.

If you are the parent or legal guardian of a minor under 18 years old who uses our website, then please contact us at the address below to have your child’s account terminated and Personal Information deleted.

By using the Services, you confirm that you are at least 18 years old. In the event that you are over the age of 18 but under the age of majority in your jurisdiction, you are not permitted to use our Services.

L. Contact Information

If you have any questions or concerns about this Privacy Policy or the handling of your Personal Information, if you wish to withdraw your consent to our use or disclosure of your Personal Information, or to request access to or update any of your Personal Information we have on file, please contact our Privacy Officer at:

Attn: Privacy Officer
Mindleap Health Inc.
612- 1330 Burrard Street
Vancouver, BC
V6Z 2B8


If any complaint or inquiry is not handled to your satisfaction, you may contact:

Privacy Commissioner of Canada
112 Kent Street
Ottawa, Ontario
K1A 1H3

Telephone: 613.995.8210
Toll free: 1.800.282.1376.

Commission d’accès à l’information du Québec
480 St. Laurent
Suite 501
Montreal, Quebec
H2Y 3Y7

Telephone: 514.873.4196
Toll Free: 1.888.528.7741

M. Changes to this Privacy Policy

We may change this Privacy Policy from time to time. Any changes will be posted on our Services and will be effective upon posting. The date at the top of the Privacy Policy lets you know when this Privacy Policy was last updated. Please check from time to time to ensure you are aware of our current policy.

N. Terms Applicable to Persons in the European Economic Area and the UK

This Section N applies only to persons in the United Kingdom and the European Economic Area (“EEA”).

Mindleap complies with the principles of the General Data Protection Regulation (“GDPR”). The six guiding principles of the GDPR are:

  • Lawfulness, transparency, and fairness;
  • Purpose limitation;
  • Data minimization;
  • Accuracy;
  • Storage limitation; and
  • Confidentiality and integrity.

Legal Basis for Processing

We process (i.e. use) the personal data you provide us in contact forms, application forms, and registration forms (e.g. contact information, such as your name, email address, phone number; and payment and tax information) because, by submitting the information requested on those forms, you have sent us that personal data and consented to our processing of it. Similarly, by requesting Specialist Services through the Services, you consent to us processing your personal data, including personal data submitted to us by Specialists, as necessary for us to provide our Services and to enable Specialists to provide you with Specialist Services.

You can withdraw your consent at any time. You will not be penalized for withdrawing your consent, but it may negatively effect your ability to receive services through the Services. Withdrawing your consent does not cause our prior processing of your personal data to become unlawful.

We and our third-party service providers process Usage Data to provide us with information about the usage and users of our Services. We use this to gain valuable insights and improve our products and services. Consequently, the lawful basis for processing that data is that it is in our legitimate interests.

We also process your personal data where legally required. For example, we may need to process your personal data if a court orders us to do so.

Transfers of Data outside of the EU

When we collect, use, and disclosure your personal data, that personal data may be transferred to countries outside of the EEA or United Kingdom. These countries may not have the same privacy protection and data laws as the country from which you provided your data.
If you are located in the EEA or United Kingdom, we will only transfer your personal data outside of the EEA or United Kingdom (as applicable) if:

  • The country to which your personal data will be transferred has been granted adequacy status by the European Commission; or
  • We have established appropriate safeguards respecting the transfer, such as entering into Standard Contractual Clauses with the recipient.

Your Rights under the General Data Protection Regulation (“GDPR”)

If you would like to know what personal data we hold about you, to request its removal, or to exercise any of your other rights under the GDPR, please contact us at dataprotectionofficer@mindleap.health.

Under the GDPR, you have rights related to your personal data:

  • The Right to Access and Rectification – You may request a copy of your personal data free of charge and request that corrections be made to it if it is inaccurate or incomplete.
  • The Right to Erasure – You may require us to delete your personal data in certain circumstances.
  • The Right to Object to Processing – You may object to the processing of your personal data by us.
  • The Right to Restriction of Processing – You may require us to restrict or limit how we process your personal data in certain circumstances.
  • The Right to Data Portability – You have the right to access and receive your personal data in a structured, commonly used, and machine readable format.
  • The Right Not to be Subject to a Decision Based Solely on Automated Decision-Making, Including Profiling
  • The Right to Withdraw your Consent to the Collection and Processing of Your Personal Data
  • The Right to Complain to an EEA data protection authority about our handling of your personal data.

The rights set out above are in summary format and are subject to limitations and exceptions as set out in the GDPR.