MiaoDesk, Inc. — Privacy Policy MiaoDesk, Inc. — 隐私政策
Effective Date:生效日期: April 29, 2026 · Last Reviewed:最近审查: April 29, 2026
1. Scope and Who This Policy Covers 1. 适用范围及适用对象
This Privacy Policy ("Policy") applies to MiaoDesk, Inc. ("MiaoDesk," "we," "our," or "us"), a Delaware corporation. It governs how we collect, use, disclose, and protect personal information in connection with:
本隐私政策("政策")适用于特拉华州法人公司 MiaoDesk, Inc.("MiaoDesk"、"我们"或"我方")。本政策规定了我们在以下情形中如何收集、使用、披露和保护个人信息:
- The MiaoDesk AI phone receptionist platform and related software-as-a-service ("Service");
- Our website located at miaodesk.com and any associated subdomains;
- Telephone calls routed through the MiaoDesk platform, including inbound calls to massage studio client lines; and
- All integrations with third-party services, including Mindbody and Twilio.
- MiaoDesk AI 电话接待员平台及相关软件即服务("服务");
- 我们位于 miaodesk.com 的网站及任何相关子域名;
- 通过 MiaoDesk 平台路由的电话,包括按摩工作室客户线路的来电;以及
- 与第三方服务(包括 Mindbody 和 Twilio)的所有集成。
This Policy covers two categories of data subjects:
本政策涵盖两类数据主体:
- Studio Clients — End consumers (massage clients) who call a studio phone line powered by MiaoDesk.
- Studio Operators — Massage studio owners, managers, and employees who contract with MiaoDesk as business customers.
- 工作室客户 — 拨打由 MiaoDesk 驱动的工作室电话线路的终端消费者(按摩客户)。
- 工作室运营者 — 作为商业客户与 MiaoDesk 签订合同的按摩工作室所有者、管理者和员工。
If you are a Studio Operator, your use of MiaoDesk is also governed by the MiaoDesk Terms of Service and any applicable Data Processing Agreement ("DPA"). This Policy does not apply to third-party websites or services linked from our platform.
如您是工作室运营者,您对 MiaoDesk 的使用还受 MiaoDesk 服务条款及任何适用的数据处理协议("DPA")的约束。本政策不适用于从我们平台链接的第三方网站或服务。
2. Personal Information We Collect 2. 我们收集的个人信息
2.1 Information Collected Automatically During Calls 2.1 通话中自动收集的信息
When a Studio Client calls a MiaoDesk-powered phone line, we automatically collect the following information:
当工作室客户拨打由 MiaoDesk 驱动的电话线路时,我们会自动收集以下信息:
- Caller telephone number (CLI/ANI) transmitted via Twilio;
- Call metadata: date, time, duration, and call disposition (answered, missed, voicemail);
- Full audio recordings of the conversation between the caller and the MiaoDesk AI agent;
- Real-time speech-to-text transcripts generated during the call; and
- Language preference inferred from the caller's choice of English or Mandarin Chinese.
- 通过 Twilio 传输的来电电话号码(CLI/ANI);
- 通话元数据:日期、时间、时长及通话状态(已接听、未接听、语音邮件);
- 来电者与 MiaoDesk AI 助手对话的完整录音;
- 通话期间生成的实时语音转文字转录;以及
- 根据来电者选择英语或普通话所推断的语言偏好。
2.2 Appointment and Transaction Data 2.2 预约与交易数据
To fulfill appointment booking, modification, and cancellation requests, we collect and process:
为完成预约、修改和取消请求,我们收集并处理:
- Caller's stated name and, where provided, date of birth;
- Appointment preferences: service type, preferred therapist, requested date and time;
- Existing appointment records retrieved from Mindbody on behalf of the Studio Operator;
- Confirmation numbers and transaction identifiers generated by Mindbody; and
- Any health or service preferences voluntarily disclosed during the call (e.g., deep-tissue preference, injury disclosures).
- 来电者所报姓名,以及(如提供)出生日期;
- 预约偏好:服务类型、偏好的理疗师、请求的日期和时间;
- 代表工作室运营者从 Mindbody 获取的现有预约记录;
- Mindbody 生成的确认号和交易标识符;以及
- 通话期间自愿披露的任何健康或服务偏好(例如深层组织按摩偏好、伤病披露)。
Health-related information disclosed during calls (e.g., "I have a lower back injury") may constitute sensitive personal information under applicable law. See Section 5 for how we handle such data.
通话期间披露的健康相关信息(例如"我有腰伤")在适用法律下可能构成敏感个人信息。有关我们如何处理此类数据,请参阅第 5 节。
2.3 Information Collected from Studio Operators 2.3 从工作室运营者处收集的信息
When a Studio Operator creates and manages a MiaoDesk account, we collect:
当工作室运营者创建和管理 MiaoDesk 账户时,我们收集:
- Business name, address, and contact information;
- Billing information (processed by Stripe; MiaoDesk does not store raw payment card data);
- Mindbody site ID and API credentials (stored encrypted at rest);
- Twilio phone number assignments and SIP configuration;
- Usage data: call volume, agent configuration settings, and platform analytics; and
- Communications with MiaoDesk support.
- 商业名称、地址和联系信息;
- 账单信息(由 Stripe 处理;MiaoDesk 不存储原始支付卡数据);
- Mindbody 站点 ID 和 API 凭据(静态加密存储);
- Twilio 电话号码分配和 SIP 配置;
- 使用数据:通话量、助手配置设置和平台分析;以及
- 与 MiaoDesk 支持团队的通信。
2.4 Website and Analytics Data 2.4 网站与分析数据
When you visit miaodesk.com, we collect standard web analytics data including IP address, browser type, pages visited, and referral source. We use this data to improve the website and measure marketing effectiveness. We do not use cross-site tracking cookies for advertising purposes.
当您访问 miaodesk.com 时,我们收集标准的网络分析数据,包括 IP 地址、浏览器类型、访问页面和引荐来源。我们使用这些数据改进网站并衡量营销效果。我们不使用跨站点跟踪 Cookie 用于广告目的。
3. How We Use Personal Information 3. 我们如何使用个人信息
We use the personal information described in Section 2 for the following purposes:
我们将第 2 节中描述的个人信息用于以下目的:
| Purpose目的 | Legal Basis法律依据 | Retention Period保留期限 |
|---|---|---|
| AI call handling & appointment bookingAI 通话处理与预约 | Contract performance / legitimate interests合同履行 / 合法利益 | Duration of call + 90 days (recordings)通话时长 + 90 天(录音) |
| Mindbody API read/write for bookings通过 Mindbody API 读写预约 | Contract performance合同履行 | Synced to studio's Mindbody account同步至工作室的 Mindbody 账户 |
| Call quality assurance & AI model improvement通话质量保证与 AI 模型改进 | Legitimate interests (opt-out available)合法利益(可选择退出) | Anonymized; model training uses de-identified data only匿名化;模型训练仅使用去标识化数据 |
| Fraud detection & platform security欺诈检测与平台安全 | Legitimate interests / legal compliance合法利益 / 法律合规 | 90 days90 天 |
| Billing and subscription management (Stripe)账单与订阅管理(Stripe) | Contract performance合同履行 | Per Stripe retention policy依据 Stripe 保留政策 |
| Regulatory compliance & legal obligations法规合规与法律义务 | Legal obligation法律义务 | Per applicable law (up to 7 years)依据适用法律(最长 7 年) |
| Studio Operator analytics & usage reporting工作室运营者分析与使用报告 | Legitimate interests合法利益 | 24 months rolling滚动 24 个月 |
4. Third-Party Integrations and Data Sharing 4. 第三方集成与数据共享
4.1 Mindbody, Inc. 4.1 Mindbody, Inc.
MiaoDesk integrates with the Mindbody platform via the Mindbody Public API. In order to provide appointment booking, modification, and cancellation services:
MiaoDesk 通过 Mindbody 公共 API 与 Mindbody 平台集成。为提供预约、修改和取消服务:
- We authenticate to Mindbody using API keys provided by the Studio Operator;
- We transmit caller-provided appointment data (name, service, date/time) to Mindbody to create or modify bookings;
- We read existing booking and client records from Mindbody to fulfill the caller's request; and
- We do not store Studio Clients' Mindbody client profile data on MiaoDesk servers beyond the duration of the call session.
- 我们使用工作室运营者提供的 API 密钥向 Mindbody 进行身份验证;
- 我们将来电者提供的预约数据(姓名、服务、日期/时间)传输至 Mindbody 以创建或修改预约;
- 我们从 Mindbody 读取现有预约和客户记录以满足来电者的请求;以及
- 我们不会在通话会话结束后将工作室客户的 Mindbody 客户资料数据存储在 MiaoDesk 服务器上。
Mindbody processes data pursuant to its own privacy policy and terms of service. Studio Operators are responsible for ensuring their use of Mindbody complies with applicable law and their own client-facing disclosures. MiaoDesk is not responsible for Mindbody's data practices.
Mindbody 依据其自身的隐私政策和服务条款处理数据。工作室运营者负责确保其对 Mindbody 的使用符合适用法律及其自身面向客户的披露要求。MiaoDesk 不对 Mindbody 的数据做法负责。
4.2 Twilio, Inc. 4.2 Twilio, Inc.
MiaoDesk uses Twilio's programmable voice infrastructure to route inbound calls and provision phone numbers. In connection with this:
MiaoDesk 使用 Twilio 的可编程语音基础设施路由来电并配置电话号码。与此相关:
- Caller telephone numbers, call metadata, and audio streams are processed by Twilio in real time;
- Twilio may store call logs and metadata per its own data retention policies;
- MiaoDesk and Studio Operators are Twilio customers and data controllers for calls placed to studio lines; and
- Twilio acts as a sub-processor under MiaoDesk's data processing arrangements.
- 来电电话号码、通话元数据和音频流由 Twilio 实时处理;
- Twilio 可能依据其自身的数据保留政策存储通话日志和元数据;
- MiaoDesk 和工作室运营者是 Twilio 客户,也是拨打至工作室线路的通话的数据控制者;以及
- Twilio 在 MiaoDesk 的数据处理安排下充当分处理者。
Twilio is certified under relevant security frameworks. MiaoDesk's agreement with Twilio includes data processing addenda consistent with applicable law. Callers who have concerns about Twilio's data handling should review Twilio's Privacy Policy at twilio.com/legal/privacy.
Twilio 已通过相关安全框架认证。MiaoDesk 与 Twilio 的协议包含符合适用法律的数据处理附录。对 Twilio 数据处理有疑虑的来电者应查阅 Twilio 隐私政策:twilio.com/legal/privacy。
4.3 ElevenLabs, Inc. (AI Voice and Agent Processing) 4.3 ElevenLabs, Inc.(AI 语音与助手处理)
MiaoDesk uses ElevenLabs to power the AI voice agent that handles inbound calls. ElevenLabs processes the call in real time and, in doing so, receives personal information provided by the caller, including:
MiaoDesk 使用 ElevenLabs 驱动处理来电的 AI 语音助手。ElevenLabs 实时处理通话,在此过程中接收来电者提供的个人信息,包括:
- Caller name, as provided during the call;
- Appointment-related input variables (e.g., requested service, preferred date and time) that the agent uses to make tool calls to Mindbody; and
- The audio stream of the conversation for purposes of speech recognition and response generation.
- 通话中提供的来电者姓名;
- 预约相关输入变量(例如请求的服务、偏好的日期和时间),助手使用这些变量向 Mindbody 发起工具调用;以及
- 用于语音识别和响应生成的对话音频流。
ElevenLabs acts as a sub-processor of personal data under MiaoDesk's data processing arrangements. ElevenLabs' own data retention practices for audio streams and conversation data are governed by its Privacy Policy at elevenlabs.io/privacy. MiaoDesk does not independently control ElevenLabs' retention periods for data processed on its infrastructure; Studio Operators and Studio Clients should review ElevenLabs' Privacy Policy directly for information about how that data is stored and retained.
ElevenLabs 在 MiaoDesk 的数据处理安排下充当个人数据的分处理者。ElevenLabs 对音频流和对话数据的数据保留做法受其隐私政策约束:elevenlabs.io/privacy。MiaoDesk 不独立控制 ElevenLabs 对其基础设施上处理的数据的保留期限;工作室运营者和工作室客户应直接查阅 ElevenLabs 的隐私政策,以了解该数据如何存储和保留。
4.4 Stripe, Inc. 4.4 Stripe, Inc.
Billing for Studio Operator subscriptions is processed by Stripe. MiaoDesk does not store payment card numbers or banking information. Stripe is a PCI-DSS Level 1 certified payment processor. Subscription metadata (plan tier, quantity, billing status) is stored in MiaoDesk's systems for account management purposes.
工作室运营者的订阅账单由 Stripe 处理。MiaoDesk 不存储支付卡号或银行信息。Stripe 是 PCI-DSS 一级认证支付处理商。订阅元数据(计划层级、数量、账单状态)存储在 MiaoDesk 系统中用于账户管理目的。
4.5 Supabase (Database Infrastructure) 4.5 Supabase(数据库基础设施)
MiaoDesk's backend database is hosted on Supabase, which uses Amazon Web Services infrastructure. Data is encrypted at rest and in transit. Supabase acts as a sub-processor under our data processing arrangements.
MiaoDesk 的后端数据库托管在使用亚马逊网络服务基础设施的 Supabase 上。数据在静态和传输过程中均加密。Supabase 在我们的数据处理安排下充当分处理者。
4.6 n8n (Workflow Automation) 4.6 n8n(工作流自动化)
MiaoDesk uses n8n, a workflow automation platform, to process Stripe subscription lifecycle events (e.g., subscription activation, renewal, cancellation, and payment failure) and to trigger internal account state updates. In this capacity, n8n processes Studio Operator account data and Stripe subscription identifiers. n8n does not process Studio Client call data or personal information derived from calls. n8n acts as a sub-processor under our data processing arrangements.
MiaoDesk 使用工作流自动化平台 n8n 处理 Stripe 订阅生命周期事件(例如订阅激活、续订、取消和付款失败)并触发内部账户状态更新。在此过程中,n8n 处理工作室运营者账户数据和 Stripe 订阅标识符。n8n 不处理工作室客户通话数据或通话衍生的个人信息。n8n 在我们的数据处理安排下充当分处理者。
4.7 Replit, Inc. (Application Hosting) 4.7 Replit, Inc.(应用程序托管)
MiaoDesk's web application, dashboard, and backend API functions are hosted on Replit's cloud infrastructure. Replit acts as a hosting provider and infrastructure sub-processor. Personal data transmitted through MiaoDesk's web application (e.g., Studio Operator account management actions, Stripe checkout sessions) may transit Replit's servers. Data is encrypted in transit. Replit's data practices are governed by its own privacy policy at replit.com/privacy.
MiaoDesk 的 Web 应用程序、仪表板和后端 API 功能托管在 Replit 的云基础设施上。Replit 充当托管提供商和基础设施分处理者。通过 MiaoDesk Web 应用程序传输的个人数据(例如工作室运营者账户管理操作、Stripe 结账会话)可能经过 Replit 的服务器。数据在传输过程中加密。Replit 的数据做法受其自身隐私政策约束:replit.com/privacy。
4.8 Resend (Transactional Email) 4.8 Resend(事务性电子邮件)
MiaoDesk uses Resend to send transactional emails to Studio Operators, including account signup verifications, password resets, billing notifications, and other service communications. In this capacity, Resend processes Studio Operator email addresses and the content of those communications. Resend does not process Studio Client personal information. Resend acts as a sub-processor under our data processing arrangements. Resend's data practices are governed by its privacy policy at resend.com/legal/privacy-policy.
MiaoDesk 使用 Resend 向工作室运营者发送事务性电子邮件,包括账户注册验证、密码重置、账单通知和其他服务通信。在此过程中,Resend 处理工作室运营者的电子邮件地址及这些通信的内容。Resend 不处理工作室客户的个人信息。Resend 在我们的数据处理安排下充当分处理者。Resend 的数据做法受其隐私政策约束:resend.com/legal/privacy-policy。
4.9 Additional Sub-Processors 4.9 其他分处理者
A current list of MiaoDesk's sub-processors is available upon written request at support@miaodesk.com. We will provide at least 30 days' prior notice to Studio Operators before adding a new sub-processor that processes Studio Client personal information.
MiaoDesk 分处理者的最新列表可通过发送书面请求至 support@miaodesk.com 获取。在添加处理工作室客户个人信息的新分处理者之前,我们将至少提前 30 天通知工作室运营者。
4.10 Disclosures Required by Law 4.10 法律要求的披露
We may disclose personal information to government authorities, law enforcement, or courts if required by valid legal process (e.g., subpoena, court order, or regulatory requirement). Where permitted by law, we will notify affected parties before complying. We will not voluntarily disclose personal information to law enforcement without valid legal compulsion.
如有效法律程序(例如传票、法院命令或监管要求)所要求,我们可能向政府机构、执法部门或法院披露个人信息。在法律允许的范围内,我们将在履行义务前通知受影响方。我们不会在没有有效法律强制要求的情况下自愿向执法部门披露个人信息。
4.11 Business Transfers 4.11 业务转让
If MiaoDesk is acquired, merges with another entity, or transfers substantially all of its assets, personal information held by MiaoDesk may be transferred as part of that transaction. We will provide notice on our website and, where required by law, obtain consent before personal information is subject to a materially different privacy policy.
如果 MiaoDesk 被收购、与其他实体合并或转让其绝大部分资产,MiaoDesk 持有的个人信息可能作为该交易的一部分被转让。我们将在网站上发布通知,并在法律要求时,在个人信息受到实质不同的隐私政策约束之前取得同意。
5. Sensitive Personal Information 5. 敏感个人信息
Certain information disclosed during calls may constitute "sensitive personal information" under applicable law, including:
通话期间披露的某些信息在适用法律下可能构成"敏感个人信息",包括:
- Health or medical information voluntarily disclosed during appointment booking (e.g., injuries, medical conditions, pregnancy);
- Biometric identifiers, if any voice biometric feature is enabled (currently not offered by MiaoDesk); and
- Information from minors (persons under 13 — see Section 6).
- 预约期间自愿披露的健康或医疗信息(例如伤病、疾病状况、怀孕);
- 如启用任何语音生物特征功能,则包括生物特征标识符(目前 MiaoDesk 不提供此功能);以及
- 来自未成年人(13 岁以下人员)的信息——见第 6 节。
MiaoDesk does not use health-related information disclosed during calls for any purpose other than fulfilling the specific appointment request. Such information is not shared with advertisers, data brokers, or any third party except as necessary to complete the Mindbody booking. Studio Operators must not configure MiaoDesk to solicit sensitive information beyond what is necessary for appointment booking.
MiaoDesk 不将通话期间披露的健康相关信息用于完成具体预约请求之外的任何目的。此类信息不会与广告商、数据经纪商或任何第三方共享,除非完成 Mindbody 预约所必需。工作室运营者不得将 MiaoDesk 配置为征集超出预约所需范围的敏感信息。
6. Children's Privacy 6. 儿童隐私
MiaoDesk's Service is not directed to children under 13 years of age, and we do not knowingly collect personal information from children under 13. If a caller under 13 contacts a studio phone line, their information will be processed solely to handle the call and will not be used for any secondary purpose. If a Studio Operator believes a minor's information has been inadvertently stored, they should contact support@miaodesk.com for deletion. MiaoDesk complies with the Children's Online Privacy Protection Act (COPPA) to the extent applicable.
MiaoDesk 的服务不面向 13 岁以下儿童,我们不会故意收集 13 岁以下儿童的个人信息。如果 13 岁以下来电者联系工作室电话线路,其信息将仅用于处理该通话,不会用于任何次要目的。如果工作室运营者认为未成年人的信息被无意存储,应联系 support@miaodesk.com 请求删除。MiaoDesk 在适用范围内遵守《儿童在线隐私保护法》(COPPA)。
7. State-Specific Privacy Rights 7. 各州隐私权利
7.1 California — CCPA / CPRA 7.1 加利福尼亚州 — CCPA / CPRA
California residents have the following rights under the California Consumer Privacy Act (as amended by the California Privacy Rights Act):
根据《加利福尼亚州消费者隐私法》(经《加利福尼亚州隐私权法》修订),加利福尼亚州居民享有以下权利:
- Right to Know — You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, our purposes, and the categories of third parties to whom we disclose it.
- Right to Delete — You may request deletion of your personal information, subject to legal exceptions (e.g., legal hold, fraud prevention).
- Right to Correct — You may request correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing — MiaoDesk does not "sell" or "share" personal information as those terms are defined under CCPA/CPRA.
- Right to Limit Use of Sensitive Personal Information — You may request that we limit use of sensitive personal information to purposes necessary to provide the service.
- Right to Non-Discrimination — We will not discriminate against you for exercising any CCPA rights.
- 知情权 — 您可要求披露我们收集的有关您的个人信息的类别和具体内容、来源、我们的目的以及我们向其披露信息的第三方类别。
- 删除权 — 您可要求删除您的个人信息,但受法律例外情形限制(例如法律保留、欺诈预防)。
- 更正权 — 您可要求更正不准确的个人信息。
- 退出出售或共享的权利 — MiaoDesk 不按 CCPA/CPRA 定义的方式"出售"或"共享"个人信息。
- 限制敏感个人信息使用的权利 — 您可要求我们将敏感个人信息的使用限制在提供服务所必需的目的范围内。
- 不受歧视权 — 我们不会因您行使任何 CCPA 权利而对您进行歧视。
California residents may submit requests by emailing support@miaodesk.com. We will respond within 45 days (extendable by an additional 45 days with notice). We will verify your identity before processing requests.
加利福尼亚州居民可通过发送电子邮件至 support@miaodesk.com 提交请求。我们将在 45 天内响应(可在通知后延长额外 45 天)。我们将在处理请求前验证您的身份。
California — Shine the Light (Cal. Civ. Code § 1798.83): California residents may also request, once per calendar year, a list of categories of personal information disclosed to third parties for their direct marketing purposes. MiaoDesk does not disclose personal information for third-party direct marketing.
加利福尼亚州 — 阳光法(加州民法典第 1798.83 条):加利福尼亚州居民还可每日历年请求一次获取为第三方直接营销目的而向第三方披露的个人信息类别列表。MiaoDesk 不为第三方直接营销目的披露个人信息。
7.2 Texas — TDPSA 7.2 德克萨斯州 — TDPSA
Texas residents have rights under the Texas Data Privacy and Security Act (TDPSA) effective July 1, 2024, including rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of processing for targeted advertising or profiling. MiaoDesk does not engage in targeted advertising using personal data collected through the Service. Texas residents may submit requests to support@miaodesk.com.
德克萨斯州居民根据 2024 年 7 月 1 日生效的《德克萨斯州数据隐私与安全法》(TDPSA)享有相应权利,包括访问、更正、删除和获取其个人数据的可携带副本的权利,以及退出定向广告或画像处理的权利。MiaoDesk 不使用通过服务收集的个人数据进行定向广告。德克萨斯州居民可向 support@miaodesk.com 提交请求。
7.3 Illinois — BIPA and IPA 7.3 伊利诺伊州 — BIPA 与 IPA
Illinois residents are protected by the Illinois Biometric Information Privacy Act (BIPA) and the Illinois Personal Information Protection Act (PIPA). MiaoDesk does not currently collect, store, or use voice prints or other biometric identifiers. If MiaoDesk introduces any voice biometric feature in the future, we will:
伊利诺伊州居民受《伊利诺伊州生物特征信息隐私法》(BIPA)和《伊利诺伊州个人信息保护法》(PIPA)保护。MiaoDesk 目前不收集、存储或使用声纹或其他生物特征标识符。如果 MiaoDesk 将来引入任何语音生物特征功能,我们将:
- Provide prior written notice and obtain informed written consent from Illinois residents before collection;
- Publish a publicly available retention schedule; and
- Not sell, lease, trade, or profit from biometric data.
- 在收集前向伊利诺伊州居民提供事先书面通知并取得知情书面同意;
- 发布公开的保留时间表;以及
- 不出售、租赁、交易生物特征数据或从中牟利。
Illinois residents who believe their rights under BIPA have been violated may contact support@miaodesk.com. The Illinois Personal Information Protection Act also requires us to notify affected Illinois residents of security breaches involving personal information in the most expedient time possible and without unreasonable delay.
认为其 BIPA 权利受到侵犯的伊利诺伊州居民可联系 support@miaodesk.com。《伊利诺伊州个人信息保护法》还要求我们尽快且不无故拖延地通知受影响的伊利诺伊州居民涉及个人信息的安全漏洞。
7.4 Washington State — My Health DATA Act (MYHDA) 7.4 华盛顿州 — 《我的健康数据法》(MYHDA)
The Washington My Health DATA Act imposes additional obligations on entities that collect consumer health data. Information relating to a caller's health conditions disclosed during a call may constitute "consumer health data" under MYHDA. MiaoDesk's practices with respect to such data are:
《华盛顿州我的健康数据法》对收集消费者健康数据的实体施加了额外义务。通话期间披露的与来电者健康状况相关的信息在 MYHDA 下可能构成"消费者健康数据"。MiaoDesk 对此类数据的做法为:
- We collect health data only to fulfill the specific appointment request;
- We do not sell, license, or share consumer health data with third parties for advertising;
- We implement reasonable security measures as required by MYHDA; and
- Washington consumers may submit a request to access, delete, or withdraw consent for processing of consumer health data at support@miaodesk.com.
- 我们仅收集健康数据以完成具体的预约请求;
- 我们不向第三方出售、许可或共享消费者健康数据用于广告目的;
- 我们按 MYHDA 要求实施合理的安全措施;以及
- 华盛顿州消费者可通过 support@miaodesk.com 提交请求,以访问、删除消费者健康数据或撤回对其处理的同意。
7.5 Other U.S. State Laws 7.5 其他美国州法律
MiaoDesk monitors evolving state privacy legislation and will update this Policy as required. Studio Operators using MiaoDesk in states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Nevada, Montana, Iowa, Indiana, Tennessee, Oregon, Delaware, New Hampshire, New Jersey, Nebraska, and Minnesota) should review those laws to understand their obligations as data controllers with respect to their Studio Clients. MiaoDesk is prepared to provide data processing addenda tailored to specific state law requirements upon request.
MiaoDesk 持续关注不断演变的州隐私立法,并将根据需要更新本政策。在具有综合隐私法的州(包括科罗拉多州、康涅狄格州、弗吉尼亚州、犹他州、内华达州、蒙大拿州、爱荷华州、印第安纳州、田纳西州、俄勒冈州、特拉华州、新罕布什尔州、新泽西州、内布拉斯加州和明尼苏达州)使用 MiaoDesk 的工作室运营者应查阅相关法律,以了解其作为工作室客户数据控制者的义务。MiaoDesk 可根据请求提供针对特定州法律要求定制的数据处理附录。
8. Data Security 8. 数据安全
MiaoDesk implements technical and organizational measures appropriate to the risk of processing personal information, including:
MiaoDesk 实施与处理个人信息风险相适应的技术和组织措施,包括:
- Encryption of data in transit using TLS 1.2 or higher;
- Encryption of data at rest in Supabase using AES-256;
- Access controls limiting MiaoDesk employee access to personal data on a need-to-know basis;
- API credentials (Mindbody, Stripe, Twilio) stored encrypted and never exposed to client-side code;
- Regular review of third-party sub-processors' security postures; and
- Incident response procedures with target notification timelines aligned with applicable legal requirements (typically 72 hours for GDPR-equivalent frameworks and without unreasonable delay under U.S. state laws).
- 使用 TLS 1.2 或更高版本加密传输中的数据;
- 在 Supabase 中使用 AES-256 加密静态数据;
- 基于最小权限原则限制 MiaoDesk 员工对个人数据的访问;
- API 凭据(Mindbody、Stripe、Twilio)加密存储,从不暴露于客户端代码;
- 定期审查第三方分处理者的安全状况;以及
- 事件响应程序,其目标通知时间表与适用法律要求一致(通常为 GDPR 等效框架下的 72 小时,以及美国州法律下的无故拖延)。
No security system is impenetrable. MiaoDesk cannot guarantee the absolute security of data transmitted over the internet. In the event of a security incident affecting personal information, we will notify affected Studio Operators and, where required by law, affected Studio Clients, in accordance with applicable breach notification laws.
没有任何安全系统是无懈可击的。MiaoDesk 无法保证通过互联网传输的数据的绝对安全。如发生影响个人信息的安全事件,我们将依据适用的违规通知法律通知受影响的工作室运营者,以及在法律要求时通知受影响的工作室客户。
9. Data Retention and Deletion 9. 数据保留与删除
MiaoDesk retains personal information for the periods described in the table in Section 3. Key retention rules are:
MiaoDesk 按第 3 节表格中描述的期限保留个人信息。主要保留规则如下:
- Call recordings captured by Twilio are retained for 90 days by default and then permanently deleted, unless a Studio Operator has configured a shorter period or extended retention is required by law. Audio stream data processed by ElevenLabs is subject to ElevenLabs' own retention policy (see Section 4.3); MiaoDesk does not control that retention period.
- Appointment transaction records are retained for 24 months in MiaoDesk's systems for audit and support purposes. The authoritative record of appointments resides in the studio's Mindbody account.
- Studio Operator account data is retained for the duration of the subscription plus 90 days post-cancellation, after which it is deleted or anonymized.
- Billing records are retained for 7 years as required by tax and financial regulations.
- Twilio 捕获的通话录音默认保留 90 天,之后永久删除,除非工作室运营者配置了更短的期限或法律要求延长保留。ElevenLabs 处理的音频流数据受 ElevenLabs 自身保留政策的约束(见第 4.3 节);MiaoDesk 不控制该保留期限。
- 预约交易记录在 MiaoDesk 系统中保留 24 个月用于审计和支持目的。预约的权威记录存储在工作室的 Mindbody 账户中。
- 工作室运营者账户数据在订阅期间加上取消后 90 天内保留,之后予以删除或匿名化。
- 账单记录按税务和财务法规要求保留 7 年。
Studio Operators may configure shorter call recording retention periods through the MiaoDesk dashboard. Studio Clients may request deletion of their personal information by contacting the studio directly or by emailing support@miaodesk.com with sufficient information to identify the call record(s) at issue.
工作室运营者可通过 MiaoDesk 仪表板配置更短的通话录音保留期限。工作室客户可通过直接联系工作室或发送电子邮件至 support@miaodesk.com(并提供足以识别相关通话记录的信息)来请求删除其个人信息。
10. Exercising Your Rights 10. 行使您的权利
To submit any privacy request (access, deletion, correction, portability, or opt-out), please contact us:
如需提交任何隐私请求(访问、删除、更正、可携带性或退出),请联系我们:
- Email: support@miaodesk.com (preferred — responses within 45 days)
- Mail: MiaoDesk, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr Suite 305, Newark, DE 19713
- 电子邮件:support@miaodesk.com(首选——45 天内响应)
- 邮寄:MiaoDesk, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr Suite 305, Newark, DE 19713
We will verify your identity before processing requests. Verification may require you to provide the telephone number used to call the studio and an approximate date of the call. We will not require unnecessary personal information for verification. We will not charge a fee for requests unless they are manifestly unfounded or excessive.
我们将在处理请求前验证您的身份。验证可能要求您提供用于拨打工作室的电话号码及通话的大概日期。我们不会要求提供不必要的个人信息进行验证。除非请求明显无根据或过度,否则我们不会收取费用。
If you are a Studio Client seeking to exercise rights with respect to your appointment data in Mindbody, you should contact the studio directly, as MiaoDesk acts as a processor for that data and the Studio Operator is the data controller.
如果您是工作室客户,希望行使与 Mindbody 中预约数据相关的权利,应直接联系工作室,因为 MiaoDesk 对该数据充当处理者,工作室运营者是数据控制者。
11. International Data Transfers 11. 国际数据传输
MiaoDesk's services are directed at users in the United States. We do not currently target users in the European Economic Area (EEA), United Kingdom, or other jurisdictions subject to GDPR-equivalent laws. MiaoDesk's infrastructure and sub-processors are located in the United States. If in the future we offer services to individuals outside the United States, we will update this Policy to address cross-border transfer mechanisms.
MiaoDesk 的服务面向美国用户。我们目前不以欧洲经济区(EEA)、英国或其他受 GDPR 等效法律约束的司法管辖区的用户为目标。MiaoDesk 的基础设施和分处理者位于美国。如果我们将来向美国境外的个人提供服务,我们将更新本政策以说明跨境传输机制。
Studio Operators operating studios serving non-U.S. nationals should consider whether additional legal obligations apply to their use of MiaoDesk and should not use the Service to process personal data subject to GDPR without first contacting MiaoDesk to enter into a Data Processing Agreement.
运营服务非美国公民的工作室的工作室运营者应考虑其使用 MiaoDesk 是否适用额外的法律义务,并且在未事先联系 MiaoDesk 签订数据处理协议的情况下,不应使用本服务处理受 GDPR 约束的个人数据。
12. Studio Operator Obligations 12. 工作室运营者的义务
Studio Operators are data controllers with respect to their Studio Clients' personal information. By using MiaoDesk, Studio Operators represent and warrant that:
工作室运营者是其工作室客户个人信息的数据控制者。通过使用 MiaoDesk,工作室运营者声明并保证:
- They have a lawful basis for processing Studio Client personal information using MiaoDesk;
- They have provided, or will provide, adequate privacy disclosures to their Studio Clients, including notice of call recording;
- They will not configure MiaoDesk to collect personal information that is unnecessary for appointment management;
- They will respond to Studio Client rights requests that are directed to the studio; and
- They will notify MiaoDesk promptly if they become aware of any data security incident involving information processed by MiaoDesk.
- 他们具有使用 MiaoDesk 处理工作室客户个人信息的合法依据;
- 他们已向或将向其工作室客户提供充分的隐私披露,包括通话录音通知;
- 他们不会将 MiaoDesk 配置为收集对预约管理不必要的个人信息;
- 他们将响应向工作室提出的工作室客户权利请求;以及
- 如果他们发现任何涉及 MiaoDesk 处理信息的数据安全事件,将及时通知 MiaoDesk。
MiaoDesk provides a standard Data Processing Agreement (DPA) to Studio Operators upon request. Execution of the DPA is required for Studio Operators subject to state laws that mandate such agreements with service providers.
MiaoDesk 可根据请求向工作室运营者提供标准数据处理协议(DPA)。对于受要求与服务提供商签订此类协议的州法律约束的工作室运营者,需签署 DPA。
13. Limitation of Liability 13. 责任限制
The foregoing limitation does not apply to: (a) MiaoDesk's gross negligence or willful misconduct; (b) liability that cannot be limited under applicable law; or (c) death or bodily injury caused by MiaoDesk's negligence. Nothing in this Policy limits MiaoDesk's obligations under applicable data protection law.
上述限制不适用于:(a) MiaoDesk 的重大过失或故意不当行为;(b) 适用法律下不能限制的责任;或 (c) 由 MiaoDesk 的过失造成的死亡或人身伤害。本政策中的任何内容均不限制 MiaoDesk 在适用数据保护法下的义务。
STUDIO OPERATORS ARE SOLELY RESPONSIBLE FOR ENSURING THEIR OWN COMPLIANCE WITH APPLICABLE PRIVACY LAWS. MIAODESK MAKES NO REPRESENTATION THAT USE OF THE SERVICE WILL RENDER ANY STUDIO OPERATOR COMPLIANT WITH APPLICABLE LAW. STUDIO OPERATORS ARE ENCOURAGED TO SEEK INDEPENDENT LEGAL COUNSEL.
工作室运营者独自负责确保其遵守适用的隐私法律。MIAODESK 不声明使用本服务将使任何工作室运营者符合适用法律。建议工作室运营者寻求独立法律顾问。
MiaoDesk is not responsible for the data practices of Mindbody, Twilio, ElevenLabs, Stripe, Supabase, n8n, Replit, Resend, or any other third party. Claims arising from third-party data practices should be directed to those entities.
MiaoDesk 不对 Mindbody、Twilio、ElevenLabs、Stripe、Supabase、n8n、Replit、Resend 或任何其他第三方的数据做法负责。因第三方数据做法产生的索赔应向相关实体提出。
14. Changes to This Policy 14. 本政策的变更
We may update this Policy from time to time to reflect changes in our practices, legal requirements, or the Service. When we make material changes, we will:
我们可能会不时更新本政策,以反映我们的做法、法律要求或服务的变化。当我们进行实质性变更时,我们将:
- Update the "Effective Date" at the top of this Policy;
- Post the revised Policy at miaodesk.com/privacy;
- Send email notice to Studio Operators at least 30 days before material changes take effect; and
- For changes that materially affect rights of Studio Clients, require Studio Operators to provide updated disclosures to their callers.
- 更新本政策顶部的"生效日期";
- 在 miaodesk.com/privacy 发布修订后的政策;
- 在实质性变更生效前至少 30 天向工作室运营者发送电子邮件通知;以及
- 对于实质性影响工作室客户权利的变更,要求工作室运营者向其来电者提供更新的披露。
Your continued use of MiaoDesk after the effective date of a revised Policy constitutes your acceptance of the changes, to the extent permitted by applicable law.
在修订后政策生效日期后继续使用 MiaoDesk,即构成您对变更的接受,在适用法律允许的范围内。
15. Contact Information 15. 联系信息
MiaoDesk, Inc. — Privacy Inquiries
MiaoDesk, Inc. — 隐私咨询
- Email: support@miaodesk.com
- Website: miaodesk.com/privacy
- Mail: MiaoDesk, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr Suite 305, Newark, DE 19713
- 电子邮件:support@miaodesk.com
- 网站:miaodesk.com/privacy
- 邮寄:MiaoDesk, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr Suite 305, Newark, DE 19713
MiaoDesk does not currently have a designated Data Protection Officer (DPO), as this obligation does not arise under applicable U.S. law. If required by future legal obligations or expansion into GDPR-covered jurisdictions, MiaoDesk will designate a DPO and update this Policy accordingly.
MiaoDesk 目前没有指定的数据保护官(DPO),因为这一义务在适用的美国法律下不存在。如果未来法律义务或扩展至受 GDPR 覆盖的司法管辖区有此要求,MiaoDesk 将指定 DPO 并相应更新本政策。
California residents may also contact the California Privacy Protection Agency (CPPA) at cppa.ca.gov. Other state residents may contact the attorney general of their state with privacy complaints.
加利福尼亚州居民还可联系加利福尼亚州隐私保护局(CPPA):cppa.ca.gov。其他州居民可向其所在州的总检察长提出隐私投诉。
This Privacy Policy was prepared for business planning purposes and does not constitute legal advice. Please consult qualified legal counsel before publishing.
本隐私政策仅为商业规划目的而准备,不构成法律建议。发布前请咨询合格的法律顾问。