Privacy Policy

Last updated September 05, 2026

This Privacy Policy explains how BodyWorkr, LLC ("BodyWorkr," "we," "us") handles information in connection with the BodyWorkr software and the Bodyworkr.com website (together, the "Service"). It applies to the practices that subscribe to BodyWorkr and their staff, and it explains how we handle information about their clients.

Our two roles

BodyWorkr plays two different roles depending on whose information is involved:

  • For the practices and staff who use BodyWorkr, we decide how account information is handled, and this policy describes what we do.
  • For a practice's clients, we handle information on the practice's behalf and under its direction. The practice — not BodyWorkr — decides what client information to collect and how it is used. If you are a client of a practice that uses BodyWorkr, see "If you are a client of a practice" below.

Information we collect

Practice and staff accounts. Name, email address, phone number, postal address, a hashed password, two-factor authentication settings, preferences and language, API tokens you create, and subscription and billing identifiers (see "Payments" below). Where a practice enables client or portal logins, a client user's account includes similar login details (such as email and a hashed password).

Sign-in with a third-party account. You may be able to sign in using a third-party account, such as Google, Microsoft, Facebook, or X (formerly Twitter). If you do, we receive basic profile information from that provider — typically your name, email address, and an account identifier — to create and authenticate your account. What the provider shares is governed by your settings and agreement with that provider.

Client information (handled for a practice). Depending on what the practice chooses to collect: name and preferred name, email, phone, address, date of birth, gender, referral source, communication preferences, appointment history, and health-related information the practice records — such as intake and consent form responses, medications, contraindications, and session notes — along with any photos or documents the practice uploads. Intake and consent forms may also capture e-signature details (the signer's name, the date and time, and the IP address and browser used) as a record that the form was signed.

Payments. For your BodyWorkr subscription, our processor Stripe handles your card details; we store identifiers and limited details such as the card brand and last four digits, plan, and charge history — not full card numbers. For payments a practice takes from its own clients through a connected provider such as Square, that provider handles the card; we store reconciliation records (amounts, tips, fees, refunds, and provider reference IDs).

Usage and technical information. When you use the Service we automatically collect log and device information and first-party usage analytics, which include IP address, pages and actions, and similar technical details, so we can operate, secure, and improve the Service.

How we use information

  • to provide and operate the Service, including scheduling, records, and forms;
  • to send appointment and practice communications — such as confirmations, reminders, and cancellations — on a practice's behalf to its clients. We deliver these through one or more channels, currently email and, as it rolls out, text message (SMS), and may add other channels such as push notifications in the future. Which messages a client receives, and on which channels, follow the preferences and opt-ins the practice and its clients set;
  • to process your subscription and payments;
  • to provide support and respond to you;
  • to secure the Service, prevent fraud and abuse, and troubleshoot errors;
  • to understand and improve how the Service is used; and
  • to meet our legal obligations.

How information is shared

We do not sell personal information. We share information only with the service providers we use to run the Service, and only as needed for them to perform their function. The providers below are representative examples, not a complete list — we may use other or additional providers to operate the Service, and we work to keep this section reasonably accurate and up to date:

  • Amazon SES — sending email (confirmations, reminders, account and support messages);
  • Twilio — sending text-message (SMS) communications, such as appointment reminders and confirmations, where enabled;
  • Stripe — processing your BodyWorkr subscription;
  • Square — for practices that connect it, to enable the practice's own client payments (only client identity information is shared to enable checkout — never session notes or clinical flags);
  • PostHog — error monitoring and product analytics;
  • Amazon S3 — storing uploaded files, such as documents and photos;
  • our hosting and infrastructure providers — where the Service and its data are stored and run.

We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a business transfer such as a merger or acquisition.

Health and clinical information

Some information a practice records in BodyWorkr is health-related — for example intake responses, medications, contraindications, and session notes. We store this information and make it available to the practice; the practice directs how it is used and is responsible for the consents and notices its clients are entitled to. As noted in our Terms of Service, BodyWorkr does not hold itself out as a HIPAA "business associate" and does not enter into Business Associate Agreements as part of the standard Service.

How we store and protect information

We use reasonable administrative, technical, and organizational measures to protect information, including access controls and two-factor authentication. Two-factor authentication is available on every account, and because we do not consider a password by itself to be sufficient, we strongly encourage practice owners to enable it. Uploaded files are stored with our cloud storage provider, and other records are held in our databases on our infrastructure. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

How long we keep information

We keep information for as long as an account is active and as needed to provide the Service, and afterward as needed to meet legal, accounting, or reporting obligations or to resolve disputes. When an account is closed, we delete or de-identify information in the ordinary course, though signed consent and form records may be retained where they serve as a legal record.

Your choices

  • Account information. You can review and update your account details in your settings, or contact us for help.
  • Communications. You can opt out of non-essential messages, and manage which channels reach you (such as email or text message) through your preferences or by following the opt-out instructions in a message (for example, replying STOP to a text). We still need to send essential account and transactional messages.
  • Access and deletion. You may ask us to access, correct, or delete your account information, subject to our legal obligations. Depending on where you live, you may have additional rights — contact us to exercise them.

If you are a client of a practice

If a massage or bodywork practice uses BodyWorkr, your records are held by that practice, and the practice decides how your information is used. To see, correct, or delete your information, or to change your communication preferences, please contact the practice directly — they are the right party to help, and we will support their request.

Cookies

We use cookies that are necessary to sign you in and keep you signed in (for example, session and "remember me" cookies), and, in production, a small amount of analytics. We do not use third-party advertising cookies.

Children

The Service is intended for practices and their staff and is not directed to children. A practice may keep records for a minor client only with the appropriate consent, and is responsible for obtaining it.

Where information is processed

BodyWorkr is based in the United States and processes information in the United States.

Changes to this policy

We may update this Privacy Policy from time to time. When we make a material change, we will update the "Last updated" date above and, where appropriate, ask you to review and accept the new version.

Contact

Questions about this policy or your information? Email us at hello@Bodyworkr.com.