1. Introduction
This Privacy Policy explains how Mimoup (“Mimoup,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you visit mimoup.com, create an account, or use our products and services (collectively, the “Services”).
Our Services include Marketing OS, Social Hub, Website Builder, Server-Side Tracking, AI Agents, Lead Collector, billing, and related dashboards, APIs, embeds, and browser extensions.
By using the Services, you acknowledge this Privacy Policy. If you do not agree, please do not use the Services. Capitalized terms not defined here have the meaning given in our Terms of Service.
2. Who we are & roles
Controller. For account data, billing data, and platform analytics about how you use Mimoup, Mimoup acts as a data controller (or equivalent under applicable law).
Processor. For Customer Content you upload or connect into Mimoup—such as email lists, message threads, website content, tracking events, AI knowledge documents, and scraped lead exports—we generally act as a processor (or service provider) on your instructions. You are responsible for having a lawful basis to collect and process that data, including notices and consents required for your end users and recipients.
Contact for privacy requests: privacy@mimoup.com.
3. Information we collect
3.1 Information you provide
- Account & profile: name, email address, password (stored hashed), agency/workspace details, role, and preferences.
- Billing: plan selections, invoices, and payment-related identifiers. Card numbers and wallet credentials are handled by our payment partners (Stripe, PayPal, Paddle)—we do not store full payment card data on Mimoup servers.
- Support: messages, attachments, and diagnostics you send to support.
- Customer Content: data you submit to the Services, including campaign content, contact lists, templates, connected channel metadata, site documents, tracking configurations, AI prompts/knowledge, and lead-export files.
- Credentials you connect: OAuth tokens, API keys (including optional bring-your-own OpenAI keys), domain DNS verification data, and similar secrets needed to operate integrations. Secrets are encrypted at rest where implemented.
3.2 Information collected automatically
- Usage & device data: IP address, browser type, device identifiers, approximate location derived from IP, pages viewed, feature usage, timestamps, and referral URLs.
- Logs & security: authentication events, error logs, rate-limit and abuse-prevention signals.
- Cookies & similar technologies: session cookies for login, preference cookies, and analytics cookies where enabled. See Section 8.
3.3 Information from third parties
- Social platforms when you connect channels (e.g., Meta, Telegram, TikTok).
- Payment providers confirming checkout status and subscription state.
- Email and AI infrastructure providers processing sends or model completions.
- Public or customer-supplied sources you choose to import (e.g., CSV uploads).
4. How we use information
We use information to:
- Provide, operate, maintain, and improve the Services;
- Authenticate users, manage workspaces, and enforce permissions;
- Process subscriptions, invoices, refunds, and fraud prevention;
- Send transactional email (verification, password reset, billing notices, product alerts);
- Deliver customer-configured features: campaigns, messaging, hosted sites, tracking pipelines, AI chat, and lead tools;
- Monitor performance, debug issues, and secure the platform;
- Comply with law, respond to lawful requests, and enforce our Terms;
- Communicate product updates or marketing where permitted (you may opt out of non-essential marketing).
We do not sell personal information as “sale” is commonly defined under privacy laws such as the CCPA/CPRA. We do not use Customer Content to train public foundation models for unrelated third parties.
5. Service-specific processing
5.1 Marketing OS
We process contact emails, names, campaign and journey content, funnel and conversion events, delivery events (sends, opens, clicks, bounces, complaints where available), and sending-domain or provider configuration. You must only upload contacts you are authorized to message and honor unsubscribe requests.
5.2 Social Hub
When you connect channels, we process account identifiers, messages, media metadata, and scheduling data needed for inbox and publishing features. Platform policies of Meta, Telegram, TikTok, and others also apply to those connections.
5.3 Website Builder & commerce
Site content, custom domains, forms submissions, store/customer data on published sites, and related media are processed to host and operate your sites. Visitors to your published sites interact primarily with you as the site operator.
5.4 Server-Side Tracking
Event payloads, identifiers, and destination configurations you set up may include end-user data. You control what is collected and where it is forwarded (e.g., ads platforms). Configure tracking lawfully and transparently for your properties.
5.5 AI Agents
Agent configuration, knowledge documents, conversation transcripts, and usage metrics are processed to run chat embeds and APIs. Model inference may be performed via OpenAI (or your bring-your-own key). Prompts and relevant knowledge snippets are sent to the model provider to generate responses. Do not place highly sensitive personal data in knowledge bases unless you have a lawful basis and appropriate safeguards.
5.6 Lead Collector (Chrome extension)
The Mimoup Lead Collector browser extension is part of the Mimoup platform. Collecting, syncing, and exporting leads requires a Mimoup account and an active Lead Collector plan purchased on Mimoup.
Data the extension processes:
- Account credentials: Email and password are sent only to the Mimoup API for authentication. The extension stores the returned session token locally in Chrome storage.
- Collected leads: Business contact fields you choose to collect (name, phone, email, website, address, social links, etc.) are stored locally in the extension until you export or clear them. Optional sync sends a snapshot to Mimoup when you click sync. Lead data you scrape or export is Customer Content under your control and responsibility.
- Usage telemetry: Tool name and lead counts may be sent to Mimoup usage endpoints to validate your plan and enforce package limits.
We do not sell your collected leads to third parties.
Chrome permissions used by the extension:
- storage — session token and collected leads
- tabs / activeTab / scripting — run collectors on pages you open
- sidePanel — main Lead Collector UI
- downloads — export files to your device
- Host access — Mimoup API/app, and sites you open for collection (e.g. Maps, Search, directories, social profiles, and business websites)
Last updated for this extension disclosure: August 18, 2026.
6. Legal bases (EEA/UK)
Where GDPR/UK GDPR applies, we rely on:
- Contract: to provide the Services you request;
- Legitimate interests: to secure, improve, and market the Services in a balanced way;
- Consent: where required (e.g., certain cookies or marketing);
- Legal obligation: for tax, accounting, and compliance duties.
9. Data retention
We retain account and billing records for as long as your account is active and as needed for legal, tax, and dispute-resolution purposes. Customer Content is retained until you delete it or close your account, subject to backup cycles and legal holds. Logs and security data are kept for shorter operational windows unless a longer period is required.
After account deletion, we take steps to delete or de-identify personal data within a commercially reasonable period, except where retention is required by law.
10. Security
We implement administrative, technical, and organizational measures designed to protect information, including encrypted transport (HTTPS), access controls, hashed passwords, and encryption of certain secrets at rest. No method of transmission or storage is 100% secure. You are responsible for safeguarding credentials, rotating API/agent secrets, and configuring workspace permissions carefully.
11. International transfers
Mimoup and its providers may process data in countries other than your own. Where required, we use appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) for cross-border transfers.
12. Your privacy rights
Depending on your location, you may have rights to access, correct, delete, port, restrict, or object to certain processing, and to withdraw consent. You may also have the right to lodge a complaint with a supervisory authority.
To exercise rights regarding your Mimoup account data, email privacy@mimoup.com from your registered address. We may verify your identity before responding. For Customer Content about your end users, contact the Mimoup customer who controls that workspace—we will assist them as processor where appropriate.
California residents: You may request to know, delete, or correct certain personal information, and you will not be discriminated against for exercising CCPA/CPRA rights. We do not “sell” or “share” personal information for cross-context behavioral advertising as those terms are defined under the CPRA, except insofar as limited analytics tools may constitute “sharing” if enabled—contact us for current details.
13. Children’s privacy
The Services are not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.
14. Third-party sites & services
The Services may link to or integrate third-party websites, APIs, and platforms. Their privacy practices are governed by their own policies. We are not responsible for third-party content or practices outside Mimoup’s control.
15. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version with an updated effective date and, where material changes require it, provide additional notice (such as email or in-product notice). Continued use after the effective date constitutes acceptance of the updated policy where permitted by law.
16. Contact us
Mimoup
Website: mimoup.com
Privacy: privacy@mimoup.com
Support: support@mimoup.com
Legal: legal@mimoup.com