Effective date: November 13, 2025
1) Who I am
I, Melanie Gobourne, operate Honest Courage at https://honestcourage.com/. I am the business that determines how and why your personal information is processed.
Address: District of Columbia, United States
Email: [email protected]
2) How my data processing works
To provide my website, bookings, messaging, and client management, I use HypnoPilot as my service platform. HypnoPilot acts as my service provider/processor and operates the system on my instructions.
3) What data I collect
a) Data you provide
Contact and booking details: name, email, phone number, preferred times, appointment history.
Messages and preferences: enquiries, support requests, consent choices, marketing preferences.
Session information: intake answers, goals, progress notes and other information shared during our work. These may include health-related details you choose to disclose.
Payments (if enabled): billing details and transaction confirmations. I do not store full card numbers. Payments are processed by the payment provider(s) I have enabled, such as Stripe or PayPal.
b) Data collected automatically
Technical data: IP address, device and browser type, pages viewed, timestamps.
Cookies and similar technologies: used for essential site functions, analytics, and marketing, managed via a cookie banner or settings tool.
c) Children and minors
My site is not directed to children under 13 and I do not knowingly collect personal information from children under 13. If a minor engages my services, I only process their data with verified parental or legal guardian consent and in line with applicable state law.
4) Why I process data
Provide services and manage bookings (to perform a contract or take steps at your request).
Client communication such as confirmations, reminders and follow-ups (contract or legitimate business purposes; SMS only with explicit consent).
Maintain records and session notes (legitimate business purposes; for sensitive or health-related information, I rely on your explicit consent).
Email marketing and updates like newsletters, tips or announcements (consent, with double opt-in for email).
Analytics and ads measurement to improve my website and measure campaigns (consent for non-essential cookies).
Legal and compliance purposes, including tax records and handling legal claims (legal obligations or legitimate business purposes).
You can withdraw consent at any time. This will not affect prior lawful processing.
5) Cookies and tracking
A cookie banner is used to request and record your choices.
Essential cookies are necessary for the site to function.
Analytics and marketing cookies such as Google Analytics, Meta Pixel and Google Ads may be used with your consent where required.
You can change or withdraw consent at any time in the cookie banner or settings tool.
6) Who processes data for me
I share personal information with service providers that help me run my services. They act on my instructions under written contracts. Depending on my configuration, I may use one or more of the following categories:
Platform operations: HypnoPilot as my service provider/processor.
CRM, automations, messaging infrastructure: a platform provider engaged by HypnoPilot as its sub-processor.
Email and messaging: internal email infrastructure within the platform, a professional email host and an SMS or voice provider.
Email marketing (if enabled): a newsletter provider with double opt-in.
Payments (if enabled): one or more payment providers such as Stripe or PayPal.
Analytics and ads (if enabled): analytics and advertising measurement tools with consent.
A current, detailed list of providers, with links to their privacy notices and data processing terms, is available at: https://hypnopilot.com/sub-processors. I do not sell personal information.
7) Communications and messaging compliance
I use my own account settings and sender IDs to send service messages and, if enabled, marketing messages. I review and approve message content before sending. I am responsible for obtaining and recording the consent required by applicable laws.
a) Types of messages
Service messages such as booking confirmations, reminders and follow-ups.
Marketing messages (if enabled) such as newsletters or offers, only with prior consent.
b) Consent
Email: marketing email uses double opt-in and includes an unsubscribe link.
SMS: I send SMS only with explicit opt-in consent collected at sign-up, for example on a form or during booking. At sign-up I explain who is messaging, what you will receive, that message and data rates may apply, that message frequency varies and how to opt out.
c) Opt-out and help
You can opt out of SMS at any time by replying STOP. For help, reply HELP or email [email protected]. Message frequency varies. Message and data rates may apply.
d) Responsibility and applicable rules
I follow applicable US rules, including the Telephone Consumer Protection Act (TCPA), CTIA messaging guidelines and the CAN-SPAM Act where applicable. HypnoPilot does not initiate or control messages on my behalf.
e) Mobile number use
I do not share mobile numbers or SMS opt-in data with third parties for their marketing. Mobile data is shared only with messaging providers as needed to deliver the service. See the current providers list at https://hypnopilot.com/sub-processors.
8) Sensitive information
Some information you share may be considered sensitive under certain state privacy laws, for example health-related details. I process such information only for the purposes you request and with your explicit consent. Access is limited to authorized personnel.
9) Your privacy rights (state-specific)
Depending on your state, you may have one or more of the following rights regarding your personal information:
Access and portability: request access to the personal information I hold about you and receive it in a portable format.
Correction: request that I correct inaccurate personal information.
Deletion: request that I delete personal information, subject to legal exceptions.
Opt out: opt out of the sale of personal information, the sharing of personal information for cross-context behavioral advertising, and targeted advertising.
Limit use and disclosure of sensitive personal information (where applicable).
Appeal: appeal my response to your request.
To exercise your rights, email [email protected] and describe your request. I will verify your identity before acting on a request and respond within the time period required by applicable law. You may authorize an agent to submit a request on your behalf as permitted by law. I will not discriminate against you for exercising your rights.
If I ever sell or share personal information for cross-context behavioral advertising or engage in targeted advertising, I will provide a clear opt-out link such as “Do Not Sell or Share My Personal Information” or “Your Privacy Choices.”
10) Notice at collection and retention
I collect the categories of information described in section 3 for the purposes listed in section 4. I keep personal information only as long as needed for those purposes or to meet legal obligations.
General enquiries and non-client messages: up to 24 months after the last contact.
Booking and service records: typically 6 to 10 years for tax and accounting or professional recordkeeping.
Session notes and health-related information: ordinarily 7 years from the last session, unless applicable rules require a different period.
Marketing data: until you withdraw consent or after 24 months of inactivity.
I delete or anonymize data earlier where I no longer need it, subject to legal retention duties.
11) Security
I apply appropriate technical and organizational measures to protect your information, including encryption in transit, access controls, least-privilege user permissions, multi-factor authentication where supported, regular access reviews and secure backups. I also require my service providers to implement suitable safeguards.
12) Third-party links and embedded content
My website may include links to third-party sites or embedded content. Those services operate under their own privacy policies.
13) International data transfers
If personal information is transferred, processed or stored outside your state or outside the United States, I use appropriate safeguards consistent with applicable law. You can contact me for details.
14) Financial incentives
I do not offer financial incentives for personal information. If I do in the future, I will provide a separate notice describing the material terms so you can decide whether to participate.
15) Accessibility
If you need this policy in an alternative format, contact me at [email protected].
16) Changes to this policy
If I update this policy, I will change the effective date above and, where appropriate, notify you.
17) Contact
Honest Courage
District of Columbia, United States
Email: [email protected]

©2025 Honest Courage. All Rights Reserved. Powered by HypnoPilot.