Last updated 2026-08-14

Privacy Policy

MogoMogo, Inc., a Delaware corporation, doing business as Mogomed (“Mogomed,” “we,” “us”) describes how we handle information when you use mogomed.com and app.mogomed.com.

1. Who we are

MogoMogo, Inc., a Delaware corporation, doing business as Mogomed (“Mogomed,” “we,” “us”) operates mogomed.com and app.mogomed.com. We are a medical-travel marketplace, not a HIPAA covered entity and not your hospital. If that changes we will update this policy.

2. Data we collect

We collect account information; booking details; payment metadata (Stripe processes cards — we do not store full card numbers); support communications; clinic-uploaded files; HSA receipts you upload; clinic staff names and PIN hashes; and security logs.

3. How we use it

We use this information to operate bookings, the vault, optional translations if you opt in, security, and legal compliance.

4. How we share

We share name, contact, requested care, and dates with the named hospital for your booking; with processors listed on our subprocessors page; and as required by law. We never sell personal data.

5. Health information

Booking details and requested procedures can be health data under state law. Vault files are stored encrypted at rest (AES-256), transmitted with TLS, kept in a private bucket, and downloaded via short-lived signed URLs. Staff access is role-based and logged. We do not claim HIPAA covered-entity compliance.

6. FTC Health Breach Notification

If a breach of PHR-type data occurs, we will notify as required. Contact privacy@mogomed.com.

7. AI processors

If you opt in, text excerpts may go to OpenAI under zero data retention when that vendor setting is enabled. Text is not used to train models under that configuration. Output is not certified translation.

8. International transfers

Partner hospitals operate in Mexico, Costa Rica, Panama, Colombia, Brazil, and Chile. Booking information is transferred to the hospital you select.

9. Cookies

We use essential session cookies. Analytics cookies will only be used if later disclosed with a banner.

10. Retention

Account data is kept while your account is active. Financial records are retained as required by law. Vault files remain until you delete them or a legal hold applies. Clinic access logs are retained for security.

11. Your rights

You may request access or deletion via privacy@mogomed.com and in-app account delete, including CPRA-style requests.

12. Children

Mogomed is for people 18 years of age or older.

13. Subprocessors

Current processors are listed at /privacy/subprocessors and currently include Supabase, Vercel, Stripe, Resend, Twilio (if WhatsApp is enabled), OpenAI (if translation is enabled), and Mapbox.

14. Contact

privacy@mogomed.com

Subprocessors · Questions: privacy@mogomed.com