Legal
Privacy Policy
Last updated: September 15, 2026
Overview
Mindbody Sync ("the App") is a HubSpot marketplace application that helps businesses synchronize contact and deal data between Mindbody and HubSpot. This policy describes what information we process when you install and use the App.
Information we process
- HubSpot account data: portal ID, OAuth tokens, and CRM records you choose to sync (for example contacts, deals, and line items), including mapped custom properties.
- Mindbody account data: site ID, site API key, and staff username/password you provide, plus client, sale, contract, appointment, and visit data needed for sync.
- Operational logs: sync run status, errors, and webhook delivery metadata used to operate and troubleshoot the App.
- Billing data: Stripe customer and subscription identifiers, billing email, and subscription status. Card numbers stay with Stripe.
- Session data: a signed session cookie so you can access your tenant dashboard after HubSpot install.
How we use information
We use this information only to:
- Authenticate your HubSpot and Mindbody connections
- Perform the syncs and mappings you configure
- Show reports and diagnose sync failures
- Maintain security, prevent abuse, and improve reliability
We do not sell customer personal data. We do not use synced CRM or Mindbody records for advertising.
Storage and security
Connection secrets (OAuth tokens, API keys, staff passwords, webhook signature keys) are encrypted at rest. Data is stored in our application database and processed on our hosting provider. Access is limited to operating the App for your tenant.
Third-party services
The App exchanges data with HubSpot and Mindbody under your authorization. Payment is processed by Stripe; we do not store full card numbers. Hosting and database providers process data on our behalf to run the App. Their use of data is governed by their own terms and privacy policies, in addition to this policy.
Retention
We retain connection and sync data while your installation remains active and for a reasonable period afterward for security, billing, and dispute resolution. You may request deletion of your tenant data by contacting support.
Your choices
- Uninstall the HubSpot app to revoke HubSpot OAuth access
- Remove or update Mindbody credentials in Settings
- Disable sync types or directions in Settings
- Contact support to request export or deletion of tenant data
Contact
Privacy and support requests: [email protected]