Privacy policy

Effective date: August 15, 2026

This Privacy Policy explains how Moonbear Ventures LLC (“Moonbear”, “we”, “us”) processes personal data in connection with Remind, including the Remind application for Microsoft Teams, the Remind administration interface, teamsreminder.app, our documentation, billing and support services (together, the “Service”).

1. Who we are

Moonbear Ventures LLC is the provider of Remind.

  • Registered address: 1021 E LINCOLNWAY STE 6216, CHEYENNE, Wyoming 82001-4851
  • Country/state of establishment: Wyoming, United States of America
  • Privacy contact: privacy@teamsreminder.app

2. Our role

For reminder content and related Microsoft Teams information processed for an organization, the organization is generally the data controller and Moonbear acts as its data processor. We process that data to provide Remind under the organization’s instructions and our Data Processing Addendum.

Moonbear acts as a controller for information used to operate its own business, including account administration, subscriptions, billing, support, website security, fraud prevention and legal compliance.

If you use Remind through your employer or another organization, that organization’s privacy notice may also apply. Requests concerning organization-controlled data may need to be directed to the organization’s Microsoft 365 administrator.

3. Personal data we process

Depending on how Remind is used, we process the following categories.

Microsoft Teams and reminder data

  • Microsoft tenant, user, team, channel, chat and conversation identifiers needed to address and deliver reminders.
  • Display names of the person creating a reminder and, when applicable, the people mentioned in or associated with it.
  • Team and channel names where needed to display and manage a reminder.
  • Reminder text, schedule, time zone, recurrence, status and delivery history.
  • When a reminder is created from a Teams message, the sender’s display name and the portion of the message needed for the reminder preview.
  • Service and conversation routing information supplied by Microsoft that is needed to send the reminder back to Teams.
  • Subscription, plan, seat assignment and organization-administration information.
  • Administrative searches performed through optional organization-administration features.

Remind does not need users to include passwords, payment-card data, patient records, protected health information or other highly sensitive information in reminder text. Users should not include such information unless their organization has expressly authorized that use and entered any required written agreement with Moonbear.

Billing data

  • Name, business name, billing email, billing address, tax information, subscription and transaction details.
  • Stripe collects and processes payment-card information. Moonbear does not receive or store complete payment-card numbers or card security codes.
  • Customers may alternatively purchase Remind through Microsoft’s commercial marketplace using Microsoft Teams, AppSource or Azure Marketplace. For those purchases, Microsoft processes the purchase and billing and provides Moonbear with the purchaser or administrator identity, Microsoft tenant information, selected plan, license or seat quantity, subscription identifier and subscription or transaction status needed to provision and administer the subscription.

Website, security and technical data

  • IP address, request date and time, requested URL, browser/device information, authentication events and diagnostic information.
  • Application, queue and delivery events, error reports, audit information and security alerts.
  • Necessary cookie or local-storage identifiers used for authentication, security and user-requested functionality.

Support and communications data

  • Name, email address, message content and any optional screenshot or attachment submitted through the contact form or email.
  • Records of support conversations and privacy or security requests.
  • Cloudflare Turnstile challenge and device/network information used to prevent automated abuse of the contact form.

4. Where the data comes from

We receive personal data:

  • directly from users and customer administrators;
  • from Microsoft Teams, Microsoft Entra ID, Microsoft Graph and related Microsoft services when users or administrators interact with Remind;
  • from Microsoft’s commercial marketplace for subscriptions purchased through Teams, AppSource or Azure Marketplace;
  • from Stripe for directly purchased subscription and transaction administration; and
  • automatically from browsers, devices, servers and security systems when the Service is accessed.

Where Moonbear acts as a controller, we rely on the following legal bases where applicable:

PurposeTypical legal basis
Provide accounts, subscriptions, support and requested Service functionalityPerformance of a contract or steps requested before entering a contract
Process invoices, taxes and legally required recordsCompliance with a legal obligation
Secure, troubleshoot and prevent abuse of the ServiceLegitimate interests in operating a secure and reliable service
Measure service health and improve functionality using limited operational dataLegitimate interests in maintaining and improving the Service
Send optional marketing communicationsConsent, where consent is required
Establish, exercise or defend legal claimsLegitimate interests and applicable legal obligations

Where Moonbear acts as a processor, the customer determines the relevant purposes and legal bases. We process customer data only as necessary to provide the Service and on the customer’s documented instructions, unless applicable law requires otherwise.

We do not sell personal data or share it for cross-context behavioural advertising.

6. How we disclose personal data

We disclose personal data only as necessary to:

  • provide Remind through Microsoft Teams and related Microsoft services;
  • use approved service providers for cloud hosting, payment processing, Microsoft marketplace subscription fulfillment, contact-form protection, Google Workspace email/support delivery and other operational functions;
  • comply with law, court orders or valid governmental requests;
  • investigate fraud, abuse or threats to users, Moonbear or the public; or
  • complete a merger, financing, acquisition or sale of all or part of the business, subject to appropriate confidentiality and data-protection safeguards.

Our current subprocessors are listed at https://teamsreminder.app/subprocessors.

Microsoft Teams and Microsoft 365 are services selected and administered by the customer. Microsoft’s processing of data within those services is governed by the customer’s agreement with Microsoft.

7. International transfers and processing locations

The production application services, operational and security logs, and backups are hosted in Microsoft Azure’s West Europe region in the Netherlands.

Support, privacy and security email, including message content and attachments sent by email or forwarded from the contact form, is handled using Google Workspace (Gmail). Google may process this information in any of their service regions according to Moonbear’s Google Workspace configuration, its agreement with Google and applicable transfer safeguards.

Personal data may be processed in countries outside the country where a user is located. When the GDPR, UK GDPR or similar law requires safeguards for an international transfer, we use an applicable lawful transfer mechanism, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another legally recognized safeguard.

For transfers of personal data protected by the EEA GDPR from a customer in the EEA to Moonbear in the United States, Moonbear relies on the European Commission’s Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914. Module 2, covering controller-to-processor transfers, is incorporated into the Remind Data Processing Addendum.

For restricted transfers governed by the UK GDPR, Moonbear uses the UK International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses.

Moonbear requires service providers that process personal data on its behalf to enter into appropriate data-processing terms. Where those providers process personal data outside the EEA or UK, transfers are protected by applicable Standard Contractual Clauses, the UK Addendum, an applicable adequacy decision or another legally recognized transfer mechanism.

Moonbear evaluates relevant international transfers and implements supplementary safeguards where appropriate, including encryption in transit and at rest, access restrictions, logging and monitoring, data minimization and procedures for responding to legally binding government requests.

Information about the applicable safeguards may be requested by contacting privacy@teamsreminder.app.

8. Retention and deletion

The following is the proposed schedule. Publish it only after the production systems and written retention procedure enforce it.

DataProposed retention
Active reminder content and routing dataUntil the reminder is delivered, deleted, expires or the customer account is terminated, as applicable
Delivered, cancelled or expired reminder contentDeleted or de-identified within 30 days
Tenant, user and subscription configurationFor the subscription/account term and deleted or de-identified within 30 days after verified termination or deletion request, unless legally required longer
Operational application logs30 days
Security and audit logs90 days, unless needed longer for an active investigation or legal obligation
Contact-form attachments30 days after the support request is resolved
Support communications24 months after the request is closed
Billing, tax and transaction records10 years or the period required by applicable law
BackupsRotated and deleted within 90 days; deleted data may remain inaccessible in encrypted backups until rotation completes

When a customer is the controller, we follow the customer’s documented deletion instructions, subject to legal obligations. More information is available at https://teamsreminder.app/data-deletion.

9. Security

We use technical and organizational measures designed to protect personal data, including encrypted network connections, encryption at rest for production data stores and backups, access controls, multifactor authentication for administrative access, secrets management, logging and monitoring, vulnerability and dependency management, backups and restore testing, and incident-response procedures.

No service can guarantee absolute security. More information about our current controls is available at https://teamsreminder.app/security.

10. Your data-protection rights

Depending on applicable law, individuals may have rights to:

  • receive information about processing;
  • access personal data;
  • correct inaccurate or incomplete data;
  • request deletion;
  • restrict or object to processing;
  • receive portable data where applicable;
  • withdraw consent without affecting earlier lawful processing; and
  • lodge a complaint with a competent data-protection authority.

Remind does not make decisions that produce legal or similarly significant effects based solely on automated processing.

To exercise a right, contact privacy@teamsreminder.app. We may request information needed to verify identity and authority. We respond without undue delay and within the period required by applicable law, normally one month under the GDPR.

If an organization controls the relevant reminder data, we may forward the request to that organization or ask the individual to contact its Microsoft 365 administrator. We assist customers with verified requests as required by our Data Processing Addendum.

11. Cookies and similar technologies

The public marketing site does not currently use advertising or audience-analytics cookies. We use technologies that are necessary for security, authentication and requested functionality, including Cloudflare Turnstile on the contact form. The authenticated administration interface uses necessary session and security storage.

See https://teamsreminder.app/cookies for current details. If we introduce non-essential analytics or advertising technologies, we will request consent where required before activating them.

12. Children

Remind is a workplace productivity service and is not directed to children acting independently as consumers. Organizations using Microsoft 365 Education or otherwise permitting minors to use Remind are responsible for providing notices, obtaining permissions and establishing a lawful basis where required. Contact us before enabling uses involving children’s data if additional contractual safeguards are required.

13. Changes to this Policy

We may update this Policy to reflect changes in the Service, law or our processing practices. We will change the effective date and provide additional notice when a change materially affects users’ rights or our use of personal data.

14. Contact

Questions, complaints and rights requests may be sent to:

Moonbear Ventures LLC
1021 E LINCOLNWAY STE 6216 CHEYENNE, Wyoming 82001-4851 privacy@teamsreminder.app

Individuals in the EEA or UK may also lodge a complaint with the data-protection authority in the country where they live or work. We encourage contacting us first so that we can try to resolve the concern.