Privacy Policy
This Policy explains how Mindgrove Play handles personal information associated with our recreational facilitation website and services. We do not collect gambling stakes, betting histories, participant funds, or information for determining monetary prizes because we do not provide those activities.
1. Scope and our role
This Privacy Policy applies when you visit mindgroveplay.com, submit a website inquiry, ask for a proposal, communicate with us, book or pay for a service, attend a facilitated session, or otherwise interact with Mindgrove Play in a business context. It also applies to information an organizer provides about participants when reasonably necessary to plan a session.
For personal information covered by this Policy, Mindgrove Play generally acts as the business or controller that determines why and how the information is used. In limited cases, an organizational customer may direct us to handle participant information on its behalf; the applicable written agreement may describe those responsibilities in more detail.
2. Personal information we collect
| Category | Examples | Typical source |
|---|---|---|
| Identity and contact information | Name, email address, phone number, business or group name, mailing or billing address. | You, an authorized organizer, or your organization. |
| Inquiry and booking information | Requested service, group size, preferred date, venue, participant context, session objectives, accessibility requests, questions, proposal and booking status. | You or the booking organizer. |
| Transaction information | Invoice number, service purchased, amount, payment status, billing contact, refunds, and limited payment confirmation. Full card details are generally handled by the payment provider rather than stored by us. | You, Shopify, or a payment service provider. |
| Communications | Emails, form messages, call notes, preferences, feedback, support questions, and records needed to respond or document an agreement. | You and our communications with you. |
| Session and operational information | Attendance count, agreed adaptations, facilitator notes about pacing or materials, incident records where necessary, and organizer feedback. | Organizer, facilitator, or participant. |
| Device and website information | IP address, browser and device type, operating system, page interactions, referral information, approximate location derived from IP, cookie identifiers, security logs, and timestamps. | Your device and website technologies. |
| Business verification information | Information reasonably required by banks, payment providers, insurers, vendors, or professional advisers to establish and maintain legitimate business services. | You, service providers, or public business records. |
Please avoid sending sensitive personal information that is not necessary for your request. If an accessibility or safety accommodation requires relevant health information, provide only what is reasonably necessary for planning. We will use it for that purpose and handle it with additional care.
3. Sources of information
We collect information directly from you, from a person who organizes a session for you, automatically from your browser or device, from vendors that support the website and business operations, and from public records where reasonably necessary for fraud prevention, business verification, or legal compliance. If you provide information about another person, you should have authority to do so and should direct that person to this Policy when appropriate.
4. How and why we use personal information
We use personal information to:
- respond to inquiries and prepare accurate proposals;
- confirm availability, create bookings, issue invoices, process payments and refunds, and maintain transaction records;
- plan session format, difficulty, materials, timing, staffing, accessibility, and venue requirements;
- deliver the agreed recreational facilitation service and communicate operational updates;
- provide customer support, respond to concerns, and document resolutions;
- operate, maintain, secure, debug, and improve the website and internal systems;
- measure general website performance and understand which services are of interest, subject to cookie choices;
- protect participants, personnel, property, and the integrity of our services;
- detect or prevent fraud, abuse, prohibited wagering activity, security incidents, and unlawful conduct;
- comply with tax, accounting, insurance, legal, regulatory, and recordkeeping obligations;
- establish, exercise, or defend legal claims; and
- send service-related messages and, where allowed and chosen, occasional marketing communications that can be declined.
Where a legal basis is required, we rely on performance of a contract or steps requested before a contract, legitimate interests in operating and protecting the business, compliance with legal obligations, consent where required, and protection of vital interests in an emergency. We assess and balance legitimate interests against the rights of affected individuals.
5. Automated decisions
We do not use personal information to make solely automated decisions that produce legal or similarly significant effects about eligibility to participate. Standard website security and payment systems may automatically flag unusual activity for review, but a flag does not by itself determine a participant's legal rights.
8. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to complete an inquiry or booking, deliver a service, maintain business and tax records, honor legal rights, resolve disputes, enforce agreements, prevent fraud, and comply with law. Retention periods vary by record type.
As a general guide, unsuccessful routine inquiries may be retained for up to 24 months; booking, invoice, payment, and tax records may be retained for at least seven years or the period required by law; session-planning records are reviewed after the engagement and deleted or minimized when no longer needed; security logs are generally retained for a shorter operational period unless required for an investigation. We may retain de-identified information that can no longer reasonably identify a person.
9. Security
We use administrative, technical, and physical measures designed to protect personal information, including access controls, service-provider review, secure account practices, data minimization, and appropriate transmission protections. No system or method of transmission is completely secure. You are responsible for protecting your own devices and account credentials and for telling us promptly if you suspect unauthorized use.
10. Your privacy rights and choices
Depending on where you live and subject to legal exceptions, you may have the right to request access to personal information, correction of inaccurate information, deletion, restriction, portability, or withdrawal of consent. Residents of some U.S. states may also have rights to know categories and specific pieces of information, to correct or delete information, to opt out of sale, sharing, or targeted advertising, and to appeal a denied request.
We do not discriminate against a person for exercising an applicable privacy right. To make a request, use the contact information below and describe the right you wish to exercise. We may need to verify identity and authority using information reasonably related to the request. An authorized agent may submit a request where permitted, but we may request proof of authorization and direct identity verification. We will respond within the period required by applicable law and explain any permitted extension or denial.
You may stop non-essential marketing messages by using the opt-out method in the message or by contacting us. Service, booking, legal, and security messages may still be sent when necessary. Browser-based Global Privacy Control signals will be honored where legally required and technically recognized by our website configuration.
11. Children's privacy
The website is not directed to children under 13, and children may not submit inquiries or create bookings. Sessions involving minors must be arranged by an authorized adult or organization. We do not knowingly collect personal information online directly from a child under 13. If you believe a child provided information without appropriate authorization, contact us so we can review and delete it where required.
12. International access and transfers
Our operations are based in the United States. If you access the website from another country, information may be processed in the United States or in locations where our service providers operate. Those locations may have different data protection laws. Where required, we use contractual or other recognized safeguards for protected transfers.
13. Third-party sites and services
The website may rely on or link to independent services. Their privacy practices are governed by their own notices. We encourage you to review those notices before providing information. This Policy does not control a third party's independent processing.
14. Changes to this Policy
We may update this Policy to reflect legal, technical, operational, or service changes. The “Last updated” date identifies the current version. If a change materially affects how we use previously collected personal information, we will provide additional notice or request consent when required.
15. Contact and privacy requests
For privacy questions or to submit a request, contact:
Mindgrove Play
Email: sessions@mindgroveplay.com
Address: 1300 Oakridge Dr, Fort Collins, CO 80525
Phone: +1 304 871 8176
If applicable law gives you the right to complain to a privacy regulator, you may also contact the regulator in your place of residence. We encourage you to contact us first so we can address the concern directly.