Privacy Policy

Last updated: September 2026. This policy explains how Mi Eyecare collects, uses, and protects your personal data when you use this website or our practice.

1. Who we are

Mi Eyecare is an independent optical practice operated by MI OPTICS LTD (company number 13445858), registered in England and Wales at 485 Herringthorpe Valley Road, Rotherham, S65 3AD.

For any privacy question, you can reach us at info@mieyecare.co.uk or by phone on 01709 838833. We are the data controller for the personal data described in this policy.

2. What personal data we collect

We only collect data you give us directly, through:

  • Contact form: your name, email address, phone number, subject, and message, when you get in touch with us.
  • Account registration: your first and last name, email address, a securely hashed password, and an optional phone number, if you create an account.
  • Signing in with Google: your name and email address from your Google account, and a unique Google account identifier used to keep your sign-in secure. Google does not share your phone number with us through this method.
  • Booking an appointment: the service and date or time you choose, together with the name, email, and phone number already held on your account.
  • Booking by phone: if you call us to book, our staff record your first name and phone number, and, if you choose to give them, your last name, date of birth, and email address, together with the service and appointment time. We keep these details so we can find your record when you call again. If you give us an email address, we use it to send your booking confirmation and any changes to your appointment.
  • Cookies and website usage: we use strictly necessary cookies to keep you signed in securely. Only if you agree, we also use Google Analytics cookies to understand how our website is used — for example, which pages are visited and how visitors found us. We never use advertising cookies. See Cookies below for details.

3. How we use your data

We use your personal data to:

  • Create and manage your account and appointment bookings, including appointments you book with us by phone;
  • Respond to enquiries you send us through the contact form;
  • Send booking confirmations and account-related emails, such as email verification and password resets;
  • Keep our systems secure and prevent misuse of our booking system;
  • Understand how our website is used so we can improve it, only if you accept analytics cookies.

We rely on the following legal bases under UK GDPR: performance of a contract (managing your account and bookings, whether made online or by phone), our legitimate interest in responding to enquiries and keeping our services secure, and your consent where you choose to sign in with Google or accept analytics cookies. We do not use your data for marketing without your consent, and we never sell your personal data.

4. Who we share it with

We only share personal data with the third-party services that help us run the practice and this website:

  • Resend — sends transactional emails, such as appointment confirmations, contact-form notifications, and account emails.
  • Google — processes your name and email if you choose to sign in with a Google account.
  • Neon — hosts our secure database.
  • Upstash — provides rate-limiting to protect our booking system from abuse, and queues outgoing emails for reliable delivery.
  • Google Analytics (Google Ireland Limited and Google LLC) — only if you accept analytics cookies, measures how our website is used. It receives information such as the pages you visit, your approximate location, and your device and browser type. It never receives your name, email address, phone number, or appointment details.

We do not sell your personal data, and we do not use any advertising networks. Google Analytics is configured with advertising features and Google Signals turned off, so your data is not used for advertising or ad personalisation.

5. Cookies

Cookies are small files stored on your device. When you first visit our website, we ask whether you are happy for us to use analytics cookies. Google Analytics is not loaded at all, and no analytics cookies are set, unless you choose “Accept”.

Strictly necessary (always on, no consent needed):

  • Sign-in cookies (names beginning next-auth) — keep you signed in securely, protect forms against misuse, and return you to the right page after signing in. They last until you sign out or for up to 30 days.
  • Your cookie choice (mi_consent, stored in your browser) — remembers whether you accepted or rejected analytics, for 12 months, so we don't ask you on every visit.

Analytics (only with your consent):

  • _ga and _ga_<ID> — set by Google Analytics to tell visits apart and measure how the website is used. They last for up to 2 years. Google Analytics does not store IP addresses.

You can change your mind at any time by selecting “Cookie Settings” at the bottom of any page. If you turn analytics off, we stop Google Analytics and delete its cookies from your browser. You can also block or delete cookies in your browser settings.

6. International transfers

Some of the providers listed above may process data outside the UK. Where this happens, we rely on appropriate safeguards, such as Standard Contractual Clauses, to ensure your data continues to be protected to UK GDPR standards.

7. How long we keep your data

We keep your personal data only for as long as necessary for the purpose it was collected for — for example, to manage your account and appointment history, or to respond to and keep a record of an enquiry. You can ask us to delete your data at any time, as set out below.

8. Your rights under UK GDPR

You have the right to:

  • Access the personal data we hold about you;
  • Ask us to correct inaccurate data;
  • Ask us to delete your data;
  • Ask us to restrict how we use your data;
  • Receive your data in a portable format;
  • Object to how we process your data;
  • Withdraw consent at any time, where we rely on consent.

To exercise any of these rights, contact us at info@mieyecare.co.uk. If you are unhappy with how we have handled your data, you also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.

9. Security

Passwords are securely hashed and are never stored or visible in plain text. Appointment and account data is only ever accessible to you when signed in to your own account.

10. Children's data

Appointments for children are booked and managed through a parent or guardian's account. We do not knowingly collect personal data directly from children.

11. Changes to this policy

We may update this policy from time to time to reflect changes to our practice or the law. The “last updated” date at the top of this page shows when it was last revised.

12. Contact us

If you have any questions about this policy or how we handle your data, please get in touch or email info@mieyecare.co.uk.