Privacy Policy

United States

Effective date: August 9, 2026

This Privacy Policy explains how DoulaOne, operated by Aku Online Limited (“DoulaOne”, “we”, “us”, or “our”), collects, uses, discloses, and protects personal information when you visit doulaone.com or use our practice-management platform (the “Service”). It applies to residents of the United States. If you are in the United Kingdom, European Union, or European Economic Area, our UK/EU Privacy Policy applies instead.

1. Our role: business and service provider

Information about you (the account holder), site visitors, and leads. When you create an account, visit our website, or request a demo, we act as a business (a controller) that decides how and why your personal information is processed. This Policy describes that processing.

Information you enter about your clients. When you store client records, notes, contracts, birth preferences, intake forms, invoices, and documents in DoulaOne, you are the business/controller for that information and we act as your service provider (processor). We handle that information only to provide the Service to you, under our Data Processing Addendum. You are responsible for providing your clients with any required privacy notices and for having a lawful basis to collect their information. If you are a client of a birth worker who uses DoulaOne and want to exercise privacy rights over your information, please contact that birth worker directly; we will assist them as their service provider.

2. Categories of personal information we collect

In the last 12 months we have collected the following categories of personal information (using the categories defined in the California Consumer Privacy Act, as amended by the CPRA). Whether we collect a category from you depends on how you use the Service.

CategoryExamplesCollected
A. IdentifiersName, email address, account/workspace identifiers, IP address, and login credentials.Yes
B. Customer records (Cal. Civ. Code § 1798.80(e))Contact details, business/practice name, and payment or subscription records (we do not store full card numbers).Yes
C. Commercial informationPlan and subscription history, and records of the Service you use.Yes
D. Internet or network activityDevice and browser information, access logs, and (only where you opt in) product-analytics usage events.Yes
E. Geolocation dataApproximate location (country and region) derived from your IP address to show relevant pricing and defaults. We do not collect precise GPS location.Yes
F. Professional or employment informationJob title, team size, and how you plan to use DoulaOne (for example, from a demo request).Yes
G. Sensitive personal informationAccount log-in credentials. Any health-related information in your workspace belongs to your clients' records, for which you (not DoulaOne) are the business — see Section 1 and our Data Processing Addendum.Limited
H. InferencesWe do not build profiles or inferences about you for advertising or automated decision-making.No

We do not knowingly collect the following CCPA categories: biometric information, or characteristics of protected classifications for our own purposes. We do not use personal information to make automated decisions that produce legal or similarly significant effects about you.

3. Where we get your information

  • Directly from you — when you sign up, subscribe, request a demo, contact support, or use the Service.
  • Automatically — device, log, and approximate-location data when you use our website and app.
  • From integrations you connect — for example your email address from Google, Zoom, or Calendly if you choose to link them.
  • From our service providers — such as payment status from Stripe.

4. How and why we use personal information

We use personal information for these business purposes:

  • Create, secure, and manage your account and workspace
  • Provide, maintain, and improve the Service
  • Authenticate you and keep your session secure
  • Process subscription billing and, where you enable it, online client payments through Stripe
  • Detect your approximate region to show relevant pricing and defaults
  • Respond to demo requests, support enquiries, and other communications
  • Send transactional messages you request (for example, appointment reminders)
  • Send marketing or newsletter emails where you have opted in (you can unsubscribe at any time)
  • Detect, prevent, and address fraud, abuse, and security incidents
  • Comply with legal obligations and enforce our Terms of Service
  • Understand how birth workers use features so we can improve the product (feature-usage metadata only — never your clients' content or health information)

Product analytics.To improve DoulaOne, we collect privacy-conscious analytics about how you (the birth worker) use the app — for example, that an invoice was created or an appointment was scheduled. This is collected server-side, tied to a pseudonymous account identifier, and does notinclude your clients' names, contact details, notes, or any health information, and it does not set cookies on your device. You can turn it off under Settings → Privacy.

5. Sensitive personal information

The only sensitive personal information we collect about you as a business is your account log-in credentials, which we use solely to secure and provide the Service. We do not use or disclose sensitive personal information for purposes that, under the CPRA, would give you a right to limit its use, so we are not required to offer a “Limit the Use of My Sensitive Personal Information” link.

Health-related and other sensitive details entered into client records belong to your clients' information, for which you are the business and we are a service provider. We do not use that information for our own purposes. See our Data Processing Addendum.

6. How we disclose personal information

We disclose personal information to service providers and contractors that process it on our behalf for the business purposes above, under written contracts that limit their use of the information. Categories of recipients include:

  • Hosting and infrastructure — Supabase (database, authentication, and file storage) and Vercel (application hosting)
  • Payments— Stripe (subscription billing and optional online client payments)
  • Email delivery— Brevo (transactional and opt-in marketing email)
  • Maps— Mapbox (directory map display)
  • Region lookup— ipapi.co (approximate location from IP, only where hosting-provider location data is unavailable)
  • Optional integrations you connect — Google, Zoom, Calendly, and OpenAI (only if you enable them)
  • Analytics— Mixpanel (privacy-conscious analytics; on public pages only after you opt in, and in-app for feature-usage metadata only)

We may also disclose personal information to comply with law, respond to lawful requests and legal process, protect our rights and the safety of others, or in connection with a merger, acquisition, or sale of assets (with notice as required by law).

7. We do not sell or share your personal information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California and other state privacy laws. We have not done so in the preceding 12 months, including for consumers we know to be under 16. We do not use third-party advertising trackers.

Because we do not sell or share personal information, there is nothing to opt out of for sale or sharing. We still honor recognized opt-out preference signals such as Global Privacy Control (GPC): when we detect a GPC signal, we treat it as a rejection of non-essential cookies (including analytics) and do not enable them. You can review or change cookie preferences later via Manage cookies.

8. How long we keep information

We keep your account and workspace information for as long as your account is active and as needed to provide the Service. When you close your account, we delete or de-identify your information within a reasonable period, except where we must retain it to comply with law, resolve disputes, prevent fraud, or enforce our agreements. Demo and sales-lead records are kept only as long as needed to follow up and are then deleted. We retain each category of information for no longer than reasonably necessary for the purpose it was collected.

9. Your California privacy rights

If you are a California resident, you have the following rights under the CCPA/CPRA, subject to certain exceptions:

  • Right to know / access — the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients.
  • Right to delete personal information we have collected from you.
  • Right to correct inaccurate personal information.
  • Right to data portability — a copy of your information in a portable format.
  • Right to opt out of sale/sharing and to limit the use of sensitive personal information — not applicable here because we do neither (see Sections 5 and 7).
  • Right to non-discrimination — we will not deny you service, charge different prices, or provide a different quality of service because you exercised your rights.

Shine the Light.We do not disclose personal information to third parties for their own direct-marketing purposes, so California's “Shine the Light” law (Cal. Civ. Code § 1798.83) does not apply to us.

10. Privacy rights in other US states

If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive consumer privacy law, you may have the right to: confirm whether we process your personal information and access it; correct inaccuracies; delete it; obtain a portable copy; and opt out of the sale of personal information, targeted advertising, and certain profiling. As explained in Section 7, we do not sell personal information, engage in targeted advertising, or profile you in ways that produce legal or similarly significant effects, so those opt-outs do not apply.

Right to appeal. If we decline to act on your request, you may appeal by replying to our decision or emailing contact@doulaone.com with “Privacy Appeal” in the subject line. We will respond within the time your state's law allows and, if we deny the appeal, tell you how to contact your state attorney general.

11. How to exercise your rights

To submit a request, email contact@doulaone.com from the address associated with your account, or use the export and deletion tools in your account settings where available.

  • Verification. To protect your information, we will verify your identity before responding, usually by confirming control of the email on your account. We may ask for additional information if we cannot otherwise verify you.
  • Authorized agents. You may use an authorized agent to submit a request. We may ask the agent for proof of authorization and may still verify your identity directly.
  • Timing. We will confirm receipt within 10 business days and respond within 45 days (with a permitted extension where allowed by law). Making a request is free unless it is excessive or repetitive.

If you are a client of a birth worker who uses DoulaOne, contact that birth worker to exercise rights over information they control. We will help them respond as their service provider.

12. Health information and HIPAA

DoulaOne is administrative software for birth workers. Most US birth workers are not HIPAA-covered entities, and DoulaOne is not currently offered as a HIPAA-compliant service and does not sign Business Associate Agreements (BAAs). If your practice is subject to HIPAA or you otherwise require BAA-covered handling of protected health information, contact us before storing regulated health information in the Service.

13. How we protect information

We use technical and organizational measures designed to protect personal information, including:

  • Row-level security isolating each workspace's data
  • Private, access-controlled file storage with signed URLs
  • Encryption in transit (HTTPS/TLS)
  • Server-side authentication and access controls
  • Restricted access to production systems and secrets

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Our systems are hosted in the European Union (Supabase, Paris region); if you use the Service from the United States, your information will be transferred to and stored on those systems.

14. Children's privacy

The Service is intended for professional use by adults and is not directed to children under 13. We do not knowingly collect personal information from children under 13 in violation of the Children's Online Privacy Protection Act (COPPA). If you believe a child under 13 has provided us personal information, contact us and we will delete it.

15. Cookies and tracking technologies

We use essential cookies and local storage required for authentication, session management, security, and remembering your preferences. These are strictly necessary for the Service to function.

With your opt-in through our cookie banner, we also use Mixpanel for privacy-conscious analytics on our public pages. We do not use third-party advertising cookies. A Global Privacy Control signal is treated as a rejection of analytics cookies.

Inside the app, our product analytics are collected server-side and do notuse cookies. They never include your clients' data or any health information, and you can turn them off under Settings → Privacy.

16. Third-party links

The Service may link to third-party websites and services we do not control. This Policy does not apply to those third parties, and we encourage you to review their privacy notices.

17. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the effective date. For material changes, we will provide notice through the Service or by email where appropriate.

18. Contact us

For privacy questions or to exercise your rights, contact our privacy team:

contact@doulaone.com

Aku Online Limited, 167-169 Great Portland Street, London, W1W 5PF, United Kingdom

See also our Terms of Service and Data Processing Addendum.