MENU

Privacy Policy

Effective: July 17, 2026

Our commitment: Relax & Renew RMT protects personal information and personal health information in accordance with Ontario's Personal Health Information Protection Act, 2004 (PHIPA), the federal Personal Information Protection and Electronic Documents Act (PIPEDA) where it applies, College of Massage Therapists of Ontario (CMTO) requirements, Canada's Anti-Spam Legislation (CASL), and other applicable law.

Accepting this Privacy Policy acknowledges our information practices. It does not by itself authorize marketing. Marketing consent is requested separately.

1. Who We Are and Our Accountability

Relax & Renew RMT is an Ontario mobile massage therapy practice and general partnership. Depending on the record and care arrangement, Relax & Renew RMT or the treating RMT may be the health information custodian, and authorized staff, contractors, and service providers may act as agents. Our Privacy Officer oversees our privacy program, responds to access and correction requests, and receives privacy complaints.

2. Information We Collect

We limit collection to information reasonably required for care, operations, legal obligations, and the purposes described below. Depending on how you interact with us, this may include:

  • Identity and contact information: name, pronouns where provided, date of birth, email, phone number, service address, emergency contact, account identifiers, and identity-verification information.
  • Clinical information: health history, symptoms, conditions, medications, treatment goals, assessments, treatment plans, consent records, contraindications, progress notes, referrals, and other information required for safe Massage Therapy care.
  • Insurance information: insurer, plan and member identifiers, coordination-of-benefits information, claim details, benefit assignments, and insurance-card images you choose to upload.
  • Booking information: appointment type and duration, individual or multi-attendee booking details, waitlist and simultaneous-service requests, practitioner preferences, service location, scheduling history, cancellations, and attendance.
  • Payment and membership information: invoices, receipts, payment status, transaction and refund records, gift-card activity, membership term and credits, billing address, and payment-provider identifiers. Full payment-card numbers and security codes are handled by Stripe and are not stored in our application systems.
  • Communications: emails, SMS, RCS and chat messages, voicemail, call metadata, call recordings and transcripts where disclosed, communication preferences, consent evidence, and unsubscribe or STOP requests.
  • Technical and usage information: IP address, browser and device information, authentication and security events, pages and features used, referral and conversion events, cookies, local browser storage, and similar technologies.
  • Location and safety information: service addresses and routing information needed to determine coverage and travel. Therapist safety systems may record a therapist's location and emergency events during mobile service; those records can indirectly identify the appointment location.

3. How We Collect and Use Information

  • To assess, plan, provide, document, coordinate, and improve Massage Therapy care.
  • To determine service coverage, calculate travel eligibility, schedule practitioners, manage waitlists, and coordinate individual, duo, group, back-to-back, and simultaneous appointments.
  • To communicate about appointments, intake requirements, care, receipts, payments, safety, service interruptions, and client support.
  • To process payments, maintain a card on file, administer memberships and gift cards, issue receipts, and submit or reconcile insurance claims where authorized.
  • To operate and secure our website, client portal, booking systems, telephone and messaging systems, prevent abuse, maintain audit records, and investigate incidents.
  • To analyze website and campaign performance using Google Analytics, Google Ads, Meta technologies, and similar tools where enabled, subject to applicable consent requirements and your browser or platform choices.
  • To meet PHIPA, PIPEDA where applicable, CASL, tax, insurance, professional, court, regulatory, and other legal obligations.

We normally collect information directly from you. With authority, we may also receive it from your substitute decision-maker, another attendee arranging a multi-person booking, an insurer or plan administrator, another healthcare provider, Cliniko, Stripe, or another service provider involved in the requested service.

4. Consent, Clinical Communications, and Marketing

  • Consent for treatment is obtained separately under the Health Care Consent Act, 1996 and CMTO requirements. A client may ask questions or withdraw treatment consent at any time.
  • Privacy consent may be express or implied where permitted by PHIPA, including when you voluntarily provide information for care. We seek express consent where required.
  • Appointment confirmations, care information, payment notices, receipts, security messages, and responses to your requests are service or clinical communications, not marketing subscriptions.
  • Marketing email or text consent is optional and collected separately. Refusing marketing does not affect care. You can unsubscribe through an email link, reply STOP where supported, update your preference, or contact us. We retain enough information to honour and prove your preference.
  • Withdrawing consent does not require destruction of records we must keep and does not affect prior lawful handling. It may limit services where the information is necessary for safe care, billing, or legal compliance.

5. Sharing and Service Providers

We do not sell or rent personal information or personal health information. We disclose only what is reasonably necessary, with consent or other legal authority, including to:

  • Treating RMTs, authorized practice personnel, substitute decision-makers, and healthcare providers within an authorized circle of care.
  • Cliniko for practice management and clinical records; Stripe for payments, cards, subscriptions, and gift cards; and Auth0 for account authentication.
  • Telnyx and authorized email providers for calls, recordings, transcripts, SMS/RCS, voicemail, operational messages, and consent-based campaigns.
  • TELUS Health, insurers, plan administrators, and their processors when you request or authorize direct billing.
  • Cloud hosting, database, object-storage, Google Drive, encrypted backup, document-generation, mapping, routing, analytics, advertising, security, and support providers needed to operate the practice.
  • Regulators, law enforcement, courts, emergency services, insurers, professional advisers, or others where permitted or required by law, including to address safety, fraud, a privacy breach, or legal claims.

Some providers process information outside Ontario or Canada, where it may be subject to the laws of that jurisdiction. We use contractual, access, and technical safeguards appropriate to the information and remain accountable as required by Canadian law.

6. Safeguards

We use administrative, technical, and physical safeguards proportionate to the sensitivity of the information. These include role-based access, authentication, secure provider connections, encryption where appropriate, audit and delivery records, restricted administrative tools, backups, retention controls, staff and agent obligations, and incident-response procedures. No internet or storage system can be guaranteed completely secure. Clients should avoid sending personal health information through unsecured channels unless instructed.

7. Retention and Disposal

  • Adult clinical records: retained for at least 10 years after the client's last visit.
  • Minor clinical records: retained for at least 10 years after the day the client turns 18.
  • Telephone recordings: ordinarily retained for up to 30 days for quality, safety, and follow-up unless a longer period is required for an incident, complaint, legal obligation, or authorized clinical purpose.
  • Other records: booking, communication, consent, insurance, payment, membership, tax, security, and operational records are retained only as long as reasonably necessary for their purpose and applicable legal, professional, limitation, audit, and dispute requirements.

When retention is no longer required, information is securely deleted, destroyed, or anonymized. Backup copies may remain until their protected rotation period ends.

8. Cookies, Analytics, and Browser Storage

Our website and portals use essential cookies or local storage for authentication, security, saved preferences, address convenience, availability caching, and session continuity. Where enabled, Google and Meta technologies may measure visits, booking activity, referrals, and advertising performance. You can restrict cookies or local storage through your browser and manage advertising choices through the relevant provider. Blocking essential storage may prevent login, booking, or saved preferences from working correctly.

9. Access, Correction, and Privacy Choices

  • You may request access to or correction of personal information and personal health information, subject to limited legal exceptions.
  • We may require a written request and reasonable identity verification. Formal PHIPA access requests are handled within the time required by law.
  • You may withdraw consent or provide a consent directive, subject to legal and professional restrictions. We will explain material service consequences where applicable.
  • If we deny a formal request, we will explain the reason and available complaint rights where required.

10. Minors and Substitute Decision-Makers

Consent depends on capacity, not only age. A capable client may make their own treatment and privacy decisions. Where a client is incapable, an authorized substitute decision-maker may act in accordance with Ontario law. We may verify authority and involve the client to the extent appropriate.

11. Privacy Breaches and Complaints

We investigate suspected privacy incidents, contain and remediate them, and notify affected individuals and the Information and Privacy Commissioner of Ontario where PHIPA requires. Please contact our Privacy Officer first so we can investigate. You may also complain directly to the Information and Privacy Commissioner of Ontario at ipc.on.ca.

12. Contact and Policy Changes

Questions, access or correction requests, consent changes, and complaints may be directed to:

Privacy Officer — Relax & Renew RMT

1-226-337-9064
info@relaxandrenew.ca

We may update this Policy as our practices or legal obligations change. The effective date will be revised, and material changes will be communicated through an appropriate channel. A new purpose requiring consent will not be applied retroactively without the consent required by law.