Legal
Privacy Policy
How we handle information in Milo, both your own account details and the client records your business keeps here.
Last updated September 16, 2026
1. Two different roles
Milo is operated by Yonatan Ibragimov, o/a Cwoted (“we”). For your account and billing details, we decide how the information is used. For the client records, appointments, and notes your business enters, you decide; we hold and process that information on your behalf and act on your instructions.
2. What we collect
- Account information — name, email address, password (stored only as a cryptographic hash), and your role.
- Business settings — business name, locations, hours, services, staff, and booking preferences.
- Client records you enter — the contact details, appointments, forms, notes, files, and payment records your business keeps about the people it serves.
- Billing information — subscription status, plan, and billing period. Card details go directly to Stripe; we receive only identifiers and payment status, never the full card number.
- Technical information — a session cookie to keep you signed in, and server logs used to operate and secure the service.
3. How we use information
- to run the workspace and its booking, calendar, and CRM features;
- to send transactional messages your business triggers, such as booking confirmations, reminders, reschedules, and receipts;
- to take subscription payments and handle billing questions;
- to secure the service, prevent abuse, and fix faults;
- to meet legal and accounting obligations.
We do not sell personal information, and we do not use your client records to advertise to anyone.
4. Service providers
We share information with a small set of providers, only as needed to deliver the service:
- Stripe — subscription payments and, where enabled, payments your business collects from its own clients.
- Resend — delivery of transactional email.
- Telnyx — delivery of text messages, where your business enables SMS.
- Google — calendar synchronisation, only for accounts that connect a Google Calendar.
- Hosting and database providers — to run the application and store its data.
5. Where information is stored
Milo’s data is stored and processed in Canada and the United States. Where information moves across borders, it stays subject to this policy and to contractual protections with our providers.
6. Retention and backups
We keep information for as long as your account is active. Encrypted backups are retained for a limited period so data can be restored after a fault. When an account closes, active data is deleted after a reasonable export window, and backup copies age out on their normal schedule. We keep billing records for as long as tax and accounting rules require.
7. Security
Access is protected by authenticated sessions and role-based permissions, each workspace’s data is scoped to that workspace, passwords are stored as hashes, backups are encrypted, and traffic is served over HTTPS. No system is perfectly secure, so we also ask you to use a strong, unique password and to grant team access carefully.
8. Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to withdraw consent. For account information, contact us at info@milo.cwoted.com.
If you are a client of a business that uses Milo, that business controls your record. Please contact them directly; we will support them in responding to you.
9. Children
Milo is intended for businesses, not for children. We do not knowingly collect information directly from children. A business may keep appointment records about a minor client where it is lawful for it to do so.
10. Changes to this policy
We will update this page when our practices change, and will revise the date shown above. Where a change is significant, we will give reasonable notice.
Contact
Questions about this document can go to info@milo.cwoted.com.