Privacy Policy
Who this policy is about
This Privacy Policy is published by Maureen's Massage (Maureen Leonie Reid, LMT MA78217), a Florida-licensed massage therapist operating as a sole proprietorship. If you have a question, a concern, or a request about your privacy or this policy, contact me at hello@maureensmassage.com, or by mail at 3589 E Gulf to Lake Hwy, Inverness, FL 34453.
When this policy applies, and what happens when it changes
This policy is dated at the top of the page. If I make a material change, I post the full, updated policy — not just a note that something changed — before the change takes effect, and I keep every prior version. Ask me for one and I will send it to you. If a change is material, continuing to book after the new version's effective date means you accept it.
Square's Privacy Notice, Data Processing Addendum and Buyer Terms are Square's own documents, published at https://squareup.com/us/en/legal. I point you to them there rather than restating them, so you always see Square's current version. I re-check their version dates at least once a year (last checked: Buyer Terms 2026-03-16, DPA 2026-03-16).
What I collect
When you book with me, I collect the contact information you give at booking (name, phone, email) and the health-history intake you complete through Square before your first session. During a session I keep brief session notes — what areas we worked on, pressure, anything you asked me to remember for next time. I do not have a "we collect nothing" policy: booking and intake both collect real information, and I would rather tell you exactly what than say otherwise.
Why I collect it
I use what I collect to schedule and perform your service, to meet Florida's record-keeping duties for massage therapists, and to keep your information confidential. I do not use it for marketing. Under Florida law, using a client's information to solicit or market goods or services requires a specific written release or authorization from that client — absent that, I don't do it.
How Square is involved
I use Square to run my booking calendar, process payment, and hold your intake and session records. Square processes that information on my behalf, under its own Privacy Notice, Data Processing Addendum, and Consumer Health Data notices — I link to those rather than summarizing them, so you always see Square's current version. I don't control how Square itself processes data once it's in Square's systems. If you created a Square account to book (rather than booking as a guest), the parts of that relationship that are between you and Square directly are governed by Square's own notices, not this policy.
I do not sell your information
I do not sell, rent, or trade your personal information to anyone, for any purpose. Your card details are never stored on my systems — payment is processed by Square, and Square holds that data, not me.
If there's ever a data breach
If your personal information is involved in a security breach, I will notify you as required by applicable law. I do not promise a specific number of days beyond what the law requires.
How long I keep information, and how I dispose of it
I keep client records for as long as I am in practice. I do not delete them on a schedule, because a client who comes back after several years is better served if I still have the history. When I no longer need to retain information, I dispose of it by shredding paper records and permanently deleting electronic records so they cannot practicably be read or reconstructed.
About HIPAA
Your information is protected under Florida law and my professional commitment to confidentiality as your licensed massage therapist. As a cash-pay solo practice that does not conduct the electronic transactions HIPAA regulates, HIPAA does not apply to this practice. If you have a concern about how your information is handled, you can contact me directly, or you can raise it with the Florida Department of Health under s. 456.057, or with the Federal Trade Commission under the FTC Act.
Sharing information with your care team
If it's ever appropriate to share information about your care with another provider involved in it, I do so only under the written authorization you give at intake, naming the specific people or care team it covers. I keep a log of any such disclosure as Florida law requires. The checkbox you see at Square checkout agreeing to my cancellation policy is a separate thing entirely — it does not authorize any disclosure of your information, and I do not treat it as if it did.
If that changes
This site does not currently use analytics or advertising tools, and I do not run promotional email marketing — no newsletters, no offers, no campaigns. Messages that are part of the service itself are different, and I do send those: booking confirmations, reminders, and a thank-you note after a visit that may invite you to leave a review. If that ever changes, I will update this policy — before the new feature goes live, not after — to describe it. Promotional marketing to clients specifically will only ever happen after both that update and a specific written release from you under Florida law. I do not upload client contact lists to any third-party advertising platform, and I do not use tracking pixels.
Every sentence here is a promise
Everything this policy says about what I collect, how I use it, and who I share it with is meant to match exactly what actually happens. If I ever add or change a feature that touches your information, I review and update this entire policy before that feature goes live, not after.
Florida's Digital Bill of Rights applies only to businesses with more than $1 billion in annual gross revenues. I am well below that threshold and am not a "controller" under that law.
Florida does not currently have a consumer-health-data law of its own. If you are located in a state with its own consumer health data law (for example, Washington, Nevada, or Connecticut), that state's law may separately apply to you; this policy does not attempt to restate those laws.
If you'd like to read more about small-business data security generally, the FTC publishes practical guidance ("Start with Security") and NIST publishes a Small Business Corner — both are good starting points, and I ask vendors I use, including Square, about their own security practices.
I do not record phone calls or sessions. Florida requires the consent of every party to a conversation before it can be recorded, and I don't record client conversations without that.