Privacy Policy
Mindu, Inc. Privacy Policy Last Updated: March 19, 2025
1. Introduction
This Privacy Policy describes how Mindu, Inc. ("Mindu," "we," "us," or "our") collects, uses, processes, and discloses your information, including personal information, in conjunction with your access to and use of the Mindu marketplace platform.
When you use our services, you trust us with your information. We are committed to keeping that trust. This Privacy Policy is designed to help you understand what information we collect, how we use it, and what choices and rights you have regarding your information.
By using Mindu, you agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of our services.
2. Information We Collect
2.1 Information You Provide to Us
Account Information: When you sign up for a Mindu account, we collect information you provide, such as your name, email address, phone number, date of birth, and payment information.
Profile Information: Information you add to your profile, such as a profile picture, biographical information, or location.
Listing and Transaction Information: If you list or purchase items on Mindu, we collect information about the items, descriptions, photos, pricing, transaction history, shipping information, and communications with other users regarding the transactions.
Communications: When you communicate with other Mindu users or with us, we collect information about your communication and any information you choose to provide.
Identity Verification: We may collect government identification documents (such as a driver's license or passport) or other authentication information as required by law, particularly for high-volume sellers under the INFORM Consumers Act. Payment Information: When you add a payment method to your Mindu account, we collect payment card information, bank account details, or information from other payment services. This information is processed by our third-party payment processor, Stripe, and we do not store complete payment information on our servers.
2.2 Information We Collect Automatically
Usage Information: We collect information about your interactions with our platform, including the pages or content you view, your searches, transactions, and other actions on Mindu.
Device Information: We collect information about the devices you use to access our services, including IP address, browser type, operating system, mobile carrier, and device identifiers.
Location Information: When you use certain features of our platform, we may collect information about your precise or approximate location as determined through data such as your IP address or mobile device's GPS.
Cookies and Similar Technologies: We use cookies, web beacons, pixels, and similar technologies to automatically collect information about you when you use our platform. More details about how we use these technologies are provided in Section 6 of this Privacy Policy.
Log Data: Our servers automatically record information created by your use of our services, including your interactions with our platform and the date and time of these interactions.
2.3 Information We Receive from Third Parties
Third-Party Services: If you link, connect, or login to your Mindu account with a third-party service (e.g., Google, Facebook), we may receive information from that service, such as your profile information and account information.
Partners and Service Providers: We may receive information about you from our business partners and service providers, such as Stripe for payment processing and Klaviyo for marketing communications.
Public Sources: We may collect information about you from publicly available sources.
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Providing, Improving, and Developing our Services
- Enabling you to use the Mindu platform and its features
- Processing transactions between buyers and sellers
- Providing customer service and responding to your inquiries
- Improving and optimizing our platform and user experience
- Developing new features and services
- Performing analytics and conducting research
- Debugging to identify and repair errors in our services
3.2 Maintaining a Safe and Secure Environment
- Verifying user identity, particularly for high-volume sellers under the INFORM Consumers Act
- Detecting and preventing fraud, spam, abuse, security incidents, and other harmful activities
- Conducting security investigations and risk assessments
- Enforcing our Terms of Service and other policies
- Verifying or authenticating information provided by you
3.3 Personalization
- Customizing content and experiences on our platform
- Suggesting listings or content that may be of interest to you
- Personalizing your experience based on your interactions with our platform
3.4 Marketing and Advertising
- Sending promotional communications about our services, features, and programs
- Delivering targeted marketing, service updates, and promotional offers through email and SMS
- Measuring the effectiveness of our marketing and advertising campaigns
- Inviting you to events and relevant opportunities
3.5 Legal and Compliance Purposes
- Complying with legal obligations
- Resolving disputes
- Enforcing our agreements, including our Terms of Service
- Responding to valid legal requests from law enforcement and other government agencies
4. How We Share Your Information
We may share your information in the following circumstances:
4.1 With Other Users
When you use Mindu, we share information with other users of the platform as necessary to facilitate transactions and marketplace functionality:
- If you are a buyer, we share certain information with the seller, including your shipping address and payment confirmation
- If you are a seller, we share certain information with the buyer, including your listing information and contact details
- For high-volume sellers who meet the INFORM Consumers Act threshold, we may be required by law to disclose certain information to buyers
Please note that once a transaction is completed, each party becomes an independent controller of the information they received and is responsible for complying with any applicable data protection laws in their use of that information. Mindu is not responsible for what another user does with your information if you provided it to them through a transaction, so please use caution and only provide what is necessary.
4.2 With Service Providers
We share information with third-party service providers who help us provide, maintain, and improve our services, including:
- Stripe: Our payment processor, which handles all payment transactions on our platform
- Klaviyo: Our marketing automation platform that helps us manage email and SMS communications
- Sharetribe: The platform provider we use to build and operate our marketplace
Other service providers who assist with hosting, data storage, analytics, customer support, fraud prevention, and technical services These service providers are contractually obligated to protect your information and are not allowed to use it for any purpose other than providing services to us. However, if any of these third-party providers suffer a data breach or misuse your data, we will take appropriate action, but note that they operate under their own privacy policies and responsibilities.
4.3 For Legal Reasons
We may share your information when we believe in good faith that disclosure is necessary to:
- Comply with any applicable law, regulation, legal process, or governmental request
- Enforce our Terms of Service and other policies
- Protect the rights, property, or safety of Mindu, our users, or others
4.4 With Your Consent
We may share your information with third parties when you expressly consent to the disclosure.
4.5 Business Transfers
If Mindu is involved in a merger, acquisition, bankruptcy, reorganization, sale of assets, or transition of service to another provider, your information may be sold or transferred as part of that transaction.
4.6 No Third-Party Advertising Sharing
At this time, Mindu does not share your personal information with third-party advertisers or ad networks for cross-context behavioral advertising. This means we are not "selling" or "sharing" your personal information as those terms are defined under the CCPA/CPRA.
If in the future we decide to partner with advertisers or use your data for targeted advertising beyond our own services, we will update this Privacy Policy and provide any required notices or opt-out mechanisms (such as a "Do Not Sell or Share My Personal Information" link) at that time.
5. Third-Party Services and Links
Mindu may contain links to third-party websites or integrate with third-party services (for example, payment gateways or social media login options). Please note that if you access a third-party website or service through our platform, their own privacy policy and terms will apply to any information you provide to them.
For instance, when you are redirected to Stripe's checkout or when you open a link to an external site posted by a user, you are interacting with those third parties, not Mindu. We are not responsible for the content, privacy practices, or security measures of any third-party websites or services.
We encourage you to review the privacy policies of those third parties before sharing your information with them. This Privacy Policy applies only to Mindu's collection and use of your information, and does not cover any third-party services that you may access through our platform.
Additionally, if you engage with Mindu on social media (for example, by clicking a "Share" button to post content to Facebook or Instagram), those interactions are governed by the privacy policies of the respective social media platforms.
6. Cookies and Tracking Technologies
We and our service providers use cookies and similar tracking technologies (such as web beacons and device identifiers) to provide and improve the Mindu experience. Cookies are small data files placed on your device that can remember your preferences and actions over time.
6.1 How We Use Cookies
- To keep you logged in by remembering your session
- To enable features like your shopping cart and account settings
- To understand how users navigate our site and which products are popular
- To gather aggregate usage statistics to improve our services
- To customize content based on your preferences and browsing history
6.2 Your Choices
Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies or alert you when cookies are being sent. However, if you choose to disable cookies, some essential features of Mindu may not function properly (for example, you may need to re-enter your login information repeatedly, or some interactive features might be unavailable).
We may use Google Analytics or similar analytics providers which set their own cookies to collect information about how users use our site. These analytics services help us analyze visitor activity but they do not identify you personally to us. You can opt out of Google Analytics by installing the Google Analytics opt-out browser add-on, or opt out of targeted advertising cookies through industry sites like the DAA's YourAdChoices.
6.3 "Do Not Track" Signals
Some browsers offer a "Do Not Track" (DNT) setting that lets you signal a preference not to have your online activities tracked. At this time, Mindu does not respond to DNT signals due to lack of a standard on how to interpret them, consistent with the practice of many online services. We will update this policy if that changes in the future.
For more information about our use of cookies and how to manage your choices, please contact us with any questions.
7. Data Security
We take data security seriously and implement technical, physical, and organizational measures to protect your personal information from unauthorized access, loss, or misuse. These measures include:
- Encryption of sensitive data in transit
- Secure hosting environments with modern security protocols
- Restricted access to personal data by our staff and service providers on a need-to-know basis
- Multi-factor authentication for internal systems
- Regular security assessments and penetration testing
- Physical and technical safeguards for our servers and facilities
However, no method of transmission over the Internet or electronic storage is completely secure. We cannot and do not guarantee that your information will be absolutely safe from intrusion. In particular, determined bad actors such as hackers or cybercriminals may sometimes defeat our security measures or those of our partners. Thus, we make no guarantee that information about you will not be accessed, viewed, or compromised by an unauthorized breach of our safeguards.
7.1 Your Responsibility
You play an important role in keeping your personal data secure. Please choose a strong, unique password for your Mindu account and do not share it with others. If you suspect any unauthorized access to your account or any security vulnerabilities, notify us immediately. Mindu will never email you asking for your password—beware of phishing attempts.
7.2 Data Breach Notification
In the event of a data breach that affects your personal information, we will notify you and the appropriate authorities as required by law.
8. Data Retention
We will retain your personal information only for as long as necessary to fulfill the purposes for which we collected it, unless a longer retention period is required or permitted by law. In practice, this means:
8.1 Active Accounts
For as long as you have an active account on Mindu, we will keep the information associated with your account. This allows us to provide our services to you (e.g. showing your listings, transaction history, etc.) on an ongoing basis.
8.2 Closed Accounts
If you choose to delete your account or if your account becomes inactive, we will initiate the deletion of your personal information. However, we may keep certain data for a period of time after account deletion for legitimate business purposes such as:
-To comply with our legal obligations
- To resolve disputes
- To enforce our agreements
- To protect our legal rights
- For example, records of transactions you participated in may be retained to handle chargebacks, tax obligations, or any potential legal claims related to the transactions.
8.3 Retention Periods
Specifically:
Account information: We retain your account information for as long as your account remains active, and for a reasonable period thereafter to maintain business records and comply with legal obligations.
Transaction data: We retain transaction records (purchase history, payment information, etc.) for at least 7 years to comply with tax and financial regulations.
Communications: We may retain communications between users, and between users and Mindu, for up to 3 years after the related transaction or account closure for dispute resolution and fraud prevention purposes.
Inactive accounts: If your account is inactive for more than 2 years, we may archive or delete certain data while retaining essential information as required by law. In many cases, when you delete your account, your personal data will be purged from our active systems within 30 days. Backup copies might persist for a limited time until rotated out.
In no event will we keep personal data longer than necessary. In line with industry best practices, we currently anticipate that most personal information will be completely deleted or anonymized within 5 years after your account closure, if not sooner, except where retention is required by law or justified by ongoing legitimate interests. In some instances, we may retain data for up to seven (7) years post-account closure to defend against legal claims or for certain required records, consistent with practices in the e-commerce industry.
Please note that, even if you request deletion, there are situations where we may refuse or delay deletion as permitted by law – for instance, if the information is needed to complete a transaction you initiated, to detect security incidents or fraud, to exercise free speech or other rights, to comply with a legal obligation, or for internal uses aligned with your expectations. If we cannot delete your data for one of these reasons, we will inform you of the reason in our response to your request.
9. Your Rights and Choices
You have certain rights and choices regarding your personal information. Mindu is committed to honoring your rights under applicable laws, including CCPA/CPRA for California residents and similar laws in other states.
9.1 Access and Correction
You can access, update, and in some cases delete your personal information directly through your Mindu account and editing your profile or settings. For example, you can change your contact information or update your shipping address at any time.
If any personal information we have is inaccurate or outdated, please correct it through your account or let us know so we can correct it. In some cases, you may have the right to request details about the personal information we hold about you and to request a copy of that information in a portable format.
9.2 Deletion
You have the right to request deletion of your personal information, subject to certain exceptions. You can request deletion by contacting us at the email or address provided below (or using any self-service deletion feature we may offer in your account settings).
Once we verify your identity and confirm the request, we will delete your personal information from our records and direct any service providers to do the same, unless an exception applies. As noted in our Data Retention section, if we must retain certain data for legal or operational reasons, we will inform you.
We will respond to deletion requests within the timeframe required by law (generally within 45 days under CCPA, unless an extension applies). Please note: If you have ongoing transactions or pending disputes, we may delay closing your account or deleting certain information until those activities are completed, consistent with legal requirements.
9.3 Opt-Out of Marketing Communications
If you receive promotional emails or newsletters from us, you can opt out at any time by:
- Clicking the "unsubscribe" link in those emails
- Adjusting your account email preferences
- For SMS marketing messages, reply "STOP" to any promotional text message from us
Please note that even if you opt out of marketing messages, we may still send you transactional or administrative emails (for example, emails about an order you placed, changes to terms, or notifications of important service updates). These are not promotional, but rather necessary for us to provide our services.
9.4 California Privacy Rights
If you are a California resident, you have the rights enumerated under the CCPA/CPRA, which include:
- The right to know what personal information we collect about you
- The right to delete your personal information
- The right to correct inaccurate personal information
- The right to opt-out of sale/sharing of your personal information (note that we do not currently sell or share your personal information as defined by law)
- The right to limit use of sensitive personal information
- The right to non-discrimination for exercising these rights
This Privacy Policy is intended to provide the disclosures required by CCPA, such as describing the categories of personal information we collect (Section 2 above), the purposes for collection (Section 3), the categories of third parties with whom we share information (Section 4), and your rights and choices (this section).
You or your authorized agent can make requests to access, delete, or correct your data as described above by contacting us. We will verify your identity (or the agent's authority) before fulfilling the request.
California's "Shine the Light" law (Civil Code § 1798.83) also allows residents to ask us once a year for a notice describing what categories of personal information we share with third parties for those third parties' direct marketing purposes. However, Mindu does not share personal information with third parties for direct marketing without consent.
9.5 Other State Privacy Rights
Residents of certain other states (such as Connecticut, Colorado, Virginia, and Utah) have similar rights under their respective privacy laws. For example, these laws may allow you to confirm if we process your data, access and obtain a copy of it, request deletion or correction, and opt out of targeted advertising or sales.
Mindu will honor the applicable rights for residents of any state with a comprehensive privacy law. If you are a resident of one of these states, you may exercise your rights in the same way as described above for California consumers (i.e., by contacting us to make a request). We will handle your request in accordance with the relevant state law requirements and within the required timeframes.
9.6 Authorized Agents
If you want to designate an authorized agent to exercise your rights on your behalf, we will take steps to verify both you (to ensure it's really your data) and the agent's authorization. For instance, we may require a signed permission from you for the agent or other proof of authority, and we may still ask you to verify your identity directly.
9.7 Non-Discrimination
Mindu will not discriminate against you for exercising any of your privacy rights. This means we won't deny you services, charge different prices, or provide a different level of quality just because you made a privacy rights request.
However, please understand that deleting certain data (like an account or transaction history) might limit our ability to offer you the full Mindu marketplace experience (for example, if you delete your data, you cannot use the service because we no longer have the information needed to provide it).
If you have any questions about your rights or how to exercise them, you can always contact us at the information provided in the Contact Us section of this Policy.
10. Children's Privacy
Mindu is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13 years old. Our services are general audience services intended for adults (and teens at least 13 or older in some cases, with parental permission where required).
If you are under 13, please do not attempt to register for Mindu or send any personal information about yourself to us. If we learn that we have inadvertently collected personal information from a child under 13, we will promptly delete that information from our records.
For minors over 13 (e.g. 13–17 years old) who may use Mindu (for example, a teenager selling or buying kids' items with parent supervision), we expect that any such use is done with parental consent and supervision. California residents under 18 years old who are registered users of Mindu may request removal of content or information they have posted on our site by contacting us directly. We will then make reasonable good-faith efforts to remove the content from public view or anonymize it, as required by California law.
Parents or guardians with concerns about children's personal information may contact us (see Contact Us below). If you believe we have unknowingly collected information from a child under 13, please let us know so we can take appropriate action.
11. International Data Transfers
Your personal information may be stored and processed in the United States and other countries where our service providers maintain facilities. By using our services, you consent to the transfer of information to countries that may have different data protection rules than your country.
When we transfer personal information from the EEA, UK, or Switzerland to countries that have not been deemed to provide an adequate level of protection, we use appropriate safeguards, such as the Standard Contractual Clauses approved by the European Commission.
Users in the European Union or other regions with data transfer restrictions should note that Mindu is primarily focused on U.S. operations.
12. Limitation of Liability and Disclaimer of Warranties
12.1 No Warranties
While we strive to protect your information and maintain a secure, reliable service, Mindu provides its services "as is" and makes no guarantees or warranties of any kind, express or implied, regarding the security of your data or the performance of the platform. We cannot promise that our site will be error-free, uninterrupted, or 100% secure at all times. You use Mindu at your own risk.
12.2 Limitation of Liability
To the maximum extent permitted by law, Mindu (including our owners, employees, and affiliates) shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of data, opportunity, reputation, or profits, arising out of or relating to this Privacy Policy or our handling of your personal information.
In no event will Mindu's total liability to you for any claims relating to your data exceed the amount (if any) you paid us for using our services in the 12 months preceding the event giving rise to the liability. This limitation applies whether the claim is based on warranty, contract, tort, or any other legal theory, even if we have been advised of the possibility of such damages.
12.3 Third-Party and Force Majeure Events
Mindu will not be responsible for any damages or liability resulting from causes outside our reasonable control. This includes, without limitation:
- Failures of telecommunications, power, or equipment
- Cyber-attacks or hacks by third parties
- Acts of government
- Natural disasters
- Acts of God
- War or terrorism
- Civil disturbances
- Any other force majeure events
If a data breach or incident occurs despite our safeguards due to circumstances beyond our control, we will take appropriate steps to notify and assist affected users, but we disclaim liability for the resulting harm to the extent allowed by law.
We also assume no liability for the actions of third-party service providers or affiliates that receive data as described in this Policy, provided that we did not willfully neglect to uphold our own data protection obligations.
12.4 No Waiver
Any failure by Mindu to enforce any part of this Privacy Policy shall not be deemed a waiver of our right to enforce it later.
Some jurisdictions do not allow the exclusion or limitation of certain warranties or liabilities, so some of the above limitations may not fully apply to you. In such cases, our liability will be limited to the fullest extent permitted by applicable law.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time in response to changing legal, technical, or business developments. We will post the updated Privacy Policy on our website and, if the changes are significant, we will provide a more prominent notice, such as by sending you an email or displaying a notice on our platform.
Your continued use of our services after any changes to this Privacy Policy indicates your acknowledgment of the modified terms. If we make a material change that affects the way we handle previously collected personal information, we will provide you with an opportunity to consent to the new practices, if required, or to delete your data if you object.
14. Miscellaneous Provisions
14.1 Severability
If any provision of this Privacy Policy is held to be invalid or unenforceable by a court or regulator, that provision will be deemed severed from this Policy and will not affect the validity and enforceability of the remaining provisions. The remaining sections of the Policy will continue in full force.
14.2 No Third-Party Beneficiaries
This Privacy Policy does not create rights enforceable by third parties. It only governs the relationship between you and Mindu regarding your personal information.
14.3 Relationship to Terms of Service
This Privacy Policy is incorporated into our Terms of Service, which govern your use of Mindu. In the event of any conflict between this Privacy Policy and the Terms of Service regarding privacy matters, this Privacy Policy will control. For all other matters, the Terms of Service will control.
15. Additional Information for California Residents
This section provides additional disclosures required by the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
15.1 Categories of Personal Information We Collect
In the past 12 months, we have collected the following categories of personal information:
- Identifiers (such as name, email address, phone number, and address)
- Commercial Information (such as products purchased or considered, and other purchasing histories)
- Financial Data (such as payment card information and bank account details)
- Internet or Network Activity Information (such as browsing history and interactions with our website)
- Geolocation Data (such as IP address and physical location)
- Sensory Information (such as audio, electronic, visual, or similar information)
- Professional or Employment-Related Information (if provided in your profile)
- Inferences drawn from any of the above to create a profile about a consumer
15.2 Sources of Personal Information
We collect the personal information listed above directly from you, automatically when you use our services, and from third parties as described in Section 2 of this Privacy Policy.
15.3 Purposes for Collecting Personal Information
We collect the personal information listed above for the business and commercial purposes described in Section 3 of this Privacy Policy.
15.4 Disclosure of Personal Information
In the past 12 months, we have disclosed the following categories of personal information for business purposes to the following categories of recipients:
- Category of Personal Information
- Categories of Recipients
- Identifiers
- Service providers, Payment processors, Marketing platforms, Other users, Legal authorities
- Commercial Information
- Service providers, Payment processors, Other users
- Financial Data
- Payment processors
- Internet or Network Activity Information
- Service providers, Analytics providers
- Geolocation Data
- Service providers, Analytics providers
- Sensory Information
- Service providers, Customer support providers
- Professional or Employment-Related Information
- Service providers
- Inferences
- Service providers, Marketing platforms
15.5 Sale or Sharing of Personal Information
Mindu does not sell your personal information as defined by the CCPA. However, under the CPRA, certain data disclosures for targeted advertising or analytics purposes may be considered "sharing." To the extent we engage in such practices, you have the right to opt out of such sharing.
15.6 Retention of Personal Information
We retain categories of personal information as described in Section 8 of this Privacy Policy.
15.7 Your Rights Under the CCPA/CPRA
As a California resident, you have the following rights:
- Right to Know: You have the right to request information about the personal information we collect, use, disclose, and sell.
- Right to Delete: You have the right to request the deletion of your personal information, subject to certain exceptions.
- Right to Correct: You have the right to request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: You have the right to opt out of the sale of your personal information or the sharing of your personal information for cross-context behavioral advertising purposes.
- Right to Limit Use of Sensitive Personal Information: You have the right to limit the use of your sensitive personal information to purposes necessary to provide the services.
- Right to Non-Discrimination: You have the right not to be discriminated against for exercising your CCPA rights.
To exercise these rights, please refer to Section 9 of this Privacy Policy.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Email: hello@lovemindu.com Mailing Address: Mindu, Inc. 1178 Broadway, Fl 3 #4316 New York, NY 10001
CCPA-Specific Contact Information:
If you are a California resident exercising your rights under the CCPA, you can contact us via email at hello@lovemindu.com or by mail at the address provided above. As our compliance program develops, we may add additional contact methods.
We will respond to your inquiries as soon as reasonably possible, generally within 30 days. For requests regarding your personal data (access, deletion, etc.), we will verify your identity for security. We are here to help and are committed to resolving any privacy issue to your satisfaction.
Thank you for trusting Mindu with your secondhand shopping and selling needs.