BOOKING OFFERS
Skip to main content

PRIVACY POLICY

Hairchitect Med Spa & Beauty Lounge San Francisco

Effective Date: 12/16/2025


At Hairchitect Med Spa & Beauty Lounge San Francisco ("Hairchitect," "we," "our," or "us"), we respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our website, book services, receive our emails or texts, interact with our social media or ads, or otherwise engage with us.

By using our website or services, you agree to this Privacy Policy.


1. INFORMATION WE COLLECT

1.1 Personal Information You Provide

We collect information you voluntarily provide when you:

  • Book appointments or consultations
  • Create an account or profile
  • Complete health questionnaires or consent forms
  • Contact us via phone, email, or contact forms
  • Subscribe to our newsletter or communications
  • Participate in promotions, surveys, or events
  • Provide feedback or reviews

This may include:

  • Contact information: name, email address, phone number, mailing address
  • Account information: username, password, preferences
  • Booking details: appointment dates, times, services requested, provider preferences
  • Communication content: messages, feedback, questions, survey responses
  • Marketing preferences: subscription choices, communication preferences

1.2 Medical and Health Information

As a medical spa providing physician-supervised treatments, we collect health information necessary to provide safe and effective care:

  • Health history: medical conditions, medications, allergies, previous treatments
  • Treatment information: services received, treatment notes, progress photos, outcomes
  • Consent forms: signed authorizations for specific treatments
  • Clinical assessments: skin condition, contraindications, recommendations

HIPAA Protections: Health information related to medical spa treatments is protected under the Health Insurance Portability and Accountability Act (HIPAA) and our separate Notice of Privacy Practices for Protected Health Information. This Privacy Policy primarily addresses information not covered by HIPAA, though some overlap may exist. For detailed information about how we handle Protected Health Information (PHI), please see our HIPAA Notice of Privacy Practices, available at our facility and upon request.

1.3 Payment Information

We collect payment information to process transactions:

  • Credit/debit card information
  • Billing address
  • Payment history and transaction records

Payment processing: Payment card information is processed by our secure third-party payment providers (e.g., Square, Stripe). We do not store full credit card numbers on our servers. Our payment processors maintain PCI-DSS compliance.

1.4 Automatically Collected Information

When you visit our website or use our services, we automatically collect certain technical information:

  • Device information: IP address, device type, operating system, browser type and version, unique device identifiers
  • Usage information: pages viewed, features used, clicks, time spent on pages, referring/exit pages, search terms
  • Location information: approximate geographic location based on IP address (not precise GPS location)
  • Cookies and tracking technologies: information collected through cookies, web beacons, pixels, and similar technologies (see Section 2)

1.5 Information from Third Parties

We may receive information about you from:

  • Booking platforms: Online scheduling services (e.g., Acuity, Booksy, Boulevard) that facilitate appointments
  • Analytics providers: Google Analytics, website performance tools
  • Advertising platforms: Google Ads, Meta (Facebook/Instagram), Microsoft Advertising
  • Social media platforms: When you interact with our social media pages or use social login features
  • Business partners: Joint marketing partners, event co-sponsors
  • Publicly available sources: Business directories, professional networks

This information is collected and shared consistent with your settings on those third-party services.


2. COOKIES AND ONLINE TRACKING

2.1 What Are Cookies?

Cookies are small text files stored on your device that help websites function and remember your preferences. We use cookies and similar technologies including web beacons, pixels, and SDKs.

2.2 Types of Cookies We Use

Essential Cookies (Required):

  • Enable core website functionality
  • Remember your login status
  • Maintain security and prevent fraud
  • Enable booking system features

Performance and Analytics Cookies:

  • Google Analytics - to understand traffic patterns and improve the site
  • Website performance monitoring tools
  • Help us identify technical issues

Functionality Cookies:

  • Remember your preferences and settings
  • Provide enhanced features and personalization
  • Remember your language or region

Advertising and Marketing Cookies:

  • Google Ads and Remarketing - to show ads based on past visits and measure conversions
  • Meta Pixel (Facebook and Instagram Ads) - to show relevant ads and measure performance across Meta platforms
  • Microsoft Advertising (Bing Ads) - to personalize ads across Microsoft's network
  • Custom audiences - to reach you with relevant offers on advertising platforms

2.3 Your Cookie Choices

You have several options to control cookies:

Browser Settings:

  • Most browsers allow you to block or delete cookies through settings
  • Note: Blocking essential cookies may limit website functionality

Platform-Specific Controls:

Industry Opt-Out Tools:

Cookie Preferences: [If available on your site, insert link to cookie consent management tool]

Important Notes:

  • Opt-out preferences may rely on cookies, so clearing cookies may require you to opt out again
  • Opt-outs are browser and device-specific
  • Privacy or ad-blocking tools may interfere with some website features

2.4 Do Not Track Signals

Some browsers have "Do Not Track" features. Our website does not currently respond to Do Not Track signals, but we honor legally recognized opt-out preference signals where applicable (see Section 8 for California residents).


3. HOW WE USE INFORMATION

We use collected information for the following purposes:

3.1 Provide and Improve Services

  • Schedule, confirm, and manage appointments
  • Provide medical spa treatments and beauty services
  • Deliver customer support and respond to inquiries
  • Process payments and maintain transaction records
  • Administer your account and preferences
  • Improve service quality and develop new offerings
  • Conduct research, analytics, and quality assessment

3.2 Communication

  • Send booking confirmations, appointment reminders, and follow-up communications
  • Provide important service notices and updates
  • Send transactional messages related to your appointments or purchases
  • Respond to your questions and requests
  • Collect feedback and conduct surveys

3.3 Marketing and Personalization

  • Send promotional emails, newsletters, and special offers (with your consent where required)
  • Send marketing text messages (with your express consent)
  • Display personalized content and recommendations
  • Show relevant advertisements on our site and third-party platforms
  • Conduct marketing campaigns and measure their effectiveness
  • Create custom audiences and lookalike audiences for advertising

3.4 Legal, Safety, and Security

  • Comply with legal obligations and respond to legal requests
  • Enforce our Terms and Conditions and other agreements
  • Prevent fraud, abuse, and security threats
  • Protect the rights, property, and safety of Hairchitect, our clients, and others
  • Resolve disputes and investigate complaints

3.5 Business Operations

  • Maintain and operate our website and booking systems
  • Conduct analytics and business intelligence
  • Manage business transactions (mergers, acquisitions, asset sales)
  • Maintain records in accordance with legal requirements

4. EMAIL AND SMS MARKETING

4.1 What We Send

Marketing Communications May Include:

  • Promotional offers and special discounts
  • New service announcements and product launches
  • Educational content about treatments and skincare
  • Seasonal promotions and event invitations
  • Client surveys and feedback requests
  • Referral program information

Transactional and Service Communications Include:

  • Appointment confirmations and reminders
  • Booking changes or cancellations
  • Payment receipts and invoices
  • Important service updates or policy changes
  • Post-treatment care instructions
  • Account security notifications

4.2 Legal Basis and Consent for Marketing

Marketing Emails:

United States:

  • We may send marketing emails without prior opt-in if we comply with CAN-SPAM Act requirements
  • You can unsubscribe at any time using the link in every email
  • We will honor unsubscribe requests within 10 business days

European Union/United Kingdom:

  • We send marketing emails only with your prior express consent OR
  • Under the limited "soft opt-in" exception for existing customers when marketing similar services
  • Every email includes an easy unsubscribe option
  • Our legal bases are consent and legitimate interests where permitted by law
  • You can withdraw consent at any time

Marketing Text Messages (SMS) and Automated Calls:

United States:

  • Sent ONLY with your prior express written consent
  • You must opt in by providing your phone number and agreeing to receive texts
  • Reply STOP to any text message to opt out immediately
  • Message and data rates may apply
  • Message frequency varies

European Union/United Kingdom:

  • Sent ONLY with your prior consent or as otherwise permitted by law
  • Easy opt-out instructions provided in every message

4.3 Transactional vs. Marketing Messages

Transactional/Service Messages:

  • These are necessary to provide services or fulfill our contract with you
  • Examples: appointment confirmations, reminders, receipts, critical service notices
  • Do NOT require marketing consent
  • Free from promotional content
  • Cannot be opted out of (though you can choose not to use our services)

Mixed Content Rule:

  • If a message contains BOTH transactional information AND promotional content, we treat it as a marketing message
  • Stricter opt-in or opt-out rules apply based on your region

4.4 How to Opt Out

Email Marketing:

  • Click the "Unsubscribe" link at the bottom of any marketing email
  • Email us at [Insert Email] with subject line "Unsubscribe from Emails"
  • Adjust preferences in your account settings (if applicable)

SMS Marketing:

  • Reply STOP to any marketing text message
  • Email us at [Insert Email] with subject line "Unsubscribe from SMS"

Important Notes:

  • Opting out of marketing does NOT stop transactional communications (appointment confirmations, receipts, etc.)
  • We will process your opt-out request promptly
  • You may continue to receive messages briefly while we process your request

5. HOW WE SHARE INFORMATION

We do not sell your personal information for monetary consideration.

We may disclose your information in the following circumstances:

5.1 Service Providers and Processors

We share information with trusted third-party service providers who help us operate our business, under contracts that limit their use of information to our specific instructions:

  • Booking and scheduling platforms (e.g., Acuity, Booksy, Boulevard)
  • Payment processors (e.g., Square, Stripe)
  • Email marketing platforms (e.g., Mailchimp, Constant Contact)
  • SMS messaging services (e.g., Twilio)
  • Cloud storage and hosting providers (e.g., AWS, Google Cloud)
  • Analytics providers (e.g., Google Analytics)
  • Customer relationship management (CRM) systems
  • IT support and security services
  • Professional advisors (accountants, lawyers)

5.2 Advertising and Analytics Partners

To measure and improve advertising effectiveness and reach you with relevant marketing:

  • Google Ads - for ad delivery, remarketing, and conversion tracking
  • Meta (Facebook/Instagram) - for ad delivery and performance measurement
  • Microsoft Advertising - for ad personalization across Microsoft network
  • Analytics platforms - for website performance and user behavior analysis

These partners may receive information consistent with your privacy choices and their own privacy policies.

5.3 Business Partners

  • Co-marketing partners for joint promotions (with your consent)
  • Event sponsors or collaborators
  • Professional networks or associations (for industry purposes only)

5.4 Legal, Safety, and Compliance

We may disclose information when required or permitted by law:

  • To comply with legal obligations, court orders, or government requests
  • To enforce our Terms and Conditions or other agreements
  • To protect against fraud, security threats, or illegal activities
  • To protect the rights, property, or safety of Hairchitect, our clients, employees, or the public
  • In connection with litigation or dispute resolution

5.5 Business Transactions

If we are involved in a merger, acquisition, asset sale, bankruptcy, or other business transaction, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control.

5.6 With Your Consent

We may share information for other purposes with your explicit consent.

5.7 Aggregated or De-Identified Information

We may share aggregated, anonymized, or de-identified information that cannot reasonably identify you, for any purpose including research, analytics, and marketing.

5.8 Targeted Advertising and "Sharing"

California, Colorado, Connecticut, Virginia, and similar state laws define certain targeted advertising or cross-context behavioral advertising activities as a "share" or "sale" of personal information, even when no money is exchanged.

We may engage in activities that constitute "sharing" for targeted advertising purposes by allowing advertising platforms to use information about your website activity to show you relevant ads on other platforms.

Your opt-out rights: See Section 8 (California), Section 9 (New York), and Section 10 (Europe/UK) for information about your choices.


6. YOUR CHOICES AND RIGHTS

You have various rights and choices regarding your personal information:

6.1 Access and Update Information

  • View or update: Contact us to access, review, or update your personal information
  • Account settings: Update preferences through your account (if applicable)
  • Correct inaccuracies: Request corrections to inaccurate information

6.2 Marketing and Communication Preferences

  • Email marketing: Unsubscribe using the link in any marketing email
  • SMS marketing: Reply STOP to any marketing text
  • Phone marketing: Request to be added to our Do Not Call list
  • Direct mail: Request removal from our mailing list
  • Advertising platforms: Adjust ad settings on Google, Meta, Microsoft, and other platforms

6.3 Cookie Management

  • Browser settings: Block or delete cookies through your browser
  • Cookie preferences: Use our cookie consent tool (if available)
  • Ad choices: Use DAA and NAI opt-out tools

6.4 Delete Your Information

  • Request deletion: Contact us to request deletion of your personal information
  • Limitations: Some information must be retained for legal, regulatory, or legitimate business purposes (e.g., transaction records, medical records)
  • Account closure: Request account deletion (if applicable)

6.5 Object or Restrict Processing

  • Marketing objection: Opt out of marketing communications
  • Processing objection: In some jurisdictions, you can object to certain processing activities
  • Restrict processing: Request that we limit how we use your information

6.6 Data Portability

In certain jurisdictions, you have the right to receive a copy of your personal information in a portable, structured format.

6.7 Withdraw Consent

Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.


7. DATA SECURITY

We take the security of your information seriously and implement reasonable technical, administrative, and physical safeguards to protect it:

7.1 Security Measures

  • Encryption: Data encrypted in transit using SSL/TLS protocols
  • Access controls: Restricted access to personal information on a need-to-know basis
  • Least privilege principle: Employees and contractors have minimum necessary access
  • Authentication: Password protection and multi-factor authentication where appropriate
  • Regular updates: Security patches and software updates applied promptly
  • Secure payment processing: PCI-DSS compliant payment processors
  • Medical record security: HIPAA-compliant protections for health information
  • Physical security: Controlled access to facilities and secure storage of paper records
  • Employee training: Regular security and privacy training for staff
  • Vendor management: Security requirements in contracts with service providers

7.2 Limitations

No method of transmission or storage is 100% secure. While we use reasonable measures to protect your information, we cannot guarantee absolute security. Risks include:

  • Unauthorized access by third parties
  • Hardware or software failures
  • Human error
  • Cyberattacks or security breaches

7.3 Your Responsibilities

  • Protect your credentials: Keep your account password secure
  • Report suspicious activity: Notify us immediately of any unauthorized access
  • Use secure connections: Avoid accessing your account on public or unsecured networks
  • Update contact information: Keep your contact details current so we can reach you about security matters

7.4 Data Breach Response

In the event of a data breach that affects your personal information and triggers legal notification obligations, we will:

  • Notify affected individuals as required by law
  • Provide information about the breach and steps you can take
  • Notify relevant regulatory authorities where required
  • Take steps to mitigate harm and prevent future incidents

8. CALIFORNIA PRIVACY RIGHTS

This section applies to California residents and reflects the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

8.1 Categories of Information Collected

In the past 12 months, we have collected the following categories of personal information:

  • Identifiers: name, email, phone number, address, IP address, device identifiers
  • Commercial information: booking history, services purchased, payment records
  • Internet or network activity: browsing history, website interactions, ad engagement
  • Geolocation data: approximate location based on IP address
  • Inferences: preferences, interests, characteristics derived from your activity
  • Sensitive personal information: health information (subject to HIPAA protections for medical treatments), account login credentials with password

We do not knowingly collect government identifiers (SSN), financial account information (full card numbers), or precise geolocation.

8.2 Sources of Information

We collect information from:

  • You directly (forms, bookings, communications)
  • Your devices (automatically collected)
  • Our service providers and partners
  • Third-party platforms and data providers
  • Publicly available sources

8.3 Purposes for Collection and Use

See Section 3 for detailed purposes, including:

  • Providing services
  • Communication
  • Marketing and personalization
  • Analytics and improvement
  • Legal compliance and security

8.4 Disclosure of Information

In the past 12 months, we have disclosed personal information to:

  • Service providers and processors
  • Advertising and analytics partners
  • Business partners (with consent)
  • Legal and government entities (when required)

Categories disclosed: All categories listed in 8.1 may be disclosed for the purposes described.

8.5 Sale or Sharing of Personal Information

Sale for monetary consideration: We do NOT sell personal information for money.

Sharing for targeted advertising: We may "share" personal information with advertising partners for cross-context behavioral advertising, which California law treats as a sale. This includes sharing activity information with Google Ads, Meta, and Microsoft Advertising for ad targeting.

Categories shared: Identifiers, commercial information, internet activity, inferences.

Opt-out right: You have the right to opt out of the "sale" or "sharing" of your personal information at any time.

8.6 Sensitive Personal Information

We collect sensitive personal information (health information, account credentials) only as necessary to provide services. We do not use or disclose it for purposes other than those allowed under the CCPA (providing services, security, fraud prevention, legal compliance).

8.7 Your California Privacy Rights

Right to Know: Request information about personal information we've collected, including categories, sources, purposes, and categories of third parties with whom we share it.

Right to Access: Request a copy of the specific personal information we have about you.

Right to Correct: Request correction of inaccurate personal information.

Right to Delete: Request deletion of your personal information, subject to legal exceptions.

Right to Data Portability: Receive your information in a portable, structured format.

Right to Opt Out of Sale/Sharing: Opt out of the "sale" or "sharing" of your personal information for targeted advertising.

Right to Limit Use of Sensitive Information: Request limitation of use and disclosure of sensitive personal information (applies only if we use it for purposes beyond providing services).

Right to Non-Discrimination: You will not face discrimination for exercising your privacy rights. We will not:

  • Deny goods or services
  • Charge different prices
  • Provide different quality of service
  • Suggest you will receive different pricing or service quality

Note: We may offer financial incentives or different pricing for different levels of service that are reasonably related to the value of your information.

8.8 How to Exercise Your Rights

Submit a Request:

  • Email: This email address is being protected from spambots. You need JavaScript enabled to view it. with subject line "California Privacy Request"
  • Phone: Call +1 (415) 908-1966
  • In person: Visit us at 1530 Union St, San Francisco, CA 94123

Include in Your Request:

  • Your full name
  • Contact information (email and phone)
  • The specific right you wish to exercise (know, access, correct, delete, opt-out)
  • Enough detail for us to locate your information in our systems

Verification:

  • We may request additional information to verify your identity before fulfilling your request
  • Verification helps protect your privacy by ensuring we don't disclose information to the wrong person
  • We will only use verification information for this purpose

Authorized Agents:

  • You may designate an authorized agent to make requests on your behalf
  • We require proof of authorization (power of attorney or signed written authorization)
  • We may still require verification of your identity

Response Timeline:

  • We will acknowledge your request within 10 business days
  • We will respond substantively within 45 days
  • If we need more time, we will notify you and may extend up to an additional 45 days

8.9 Opt-Out Preference Signals

We will honor opt-out preference signals recognized by California law (e.g., Global Privacy Control) when detected from your browser.

8.10 Retention

See Section 11 for information about how long we retain personal information.

8.11 California Shine the Light Law

California Civil Code Section 1798.83 permits California residents to request information about disclosure of personal information to third parties for their direct marketing purposes. We do not share personal information with third parties for their own direct marketing purposes.


9. NEW YORK PRIVACY COMPLIANCE

This section applies to New York residents.

9.1 Data Security and SHIELD Act Compliance

We maintain reasonable administrative, technical, and physical safeguards consistent with New York's Stop Hacks and Improve Electronic Data Security (SHIELD) Act, including:

  • Data encryption
  • Access controls
  • Security monitoring
  • Employee training
  • Incident response procedures

9.2 Data Breach Notification

If a data breach occurs that triggers New York's notification requirements, we will:

  • Notify affected individuals without unreasonable delay
  • Provide information about the breach, data types affected, and protective measures
  • Notify the New York Attorney General and consumer reporting agencies if required
  • Offer identity theft prevention services where appropriate

9.3 Biometric Information

We do not currently collect biometric identifiers or biometric information (fingerprints, facial recognition, retina scans, voiceprints, etc.).

If we collect biometric information in the future:

  • We will provide clear notice consistent with New York City and New York State biometric privacy laws
  • We will obtain informed consent before collection
  • We will not sell, lease, or trade biometric information
  • We will establish a retention schedule and destruction guidelines
  • We will implement reasonable security measures

9.4 Your New York Privacy Rights

New York residents have the right to:

  • Access: Request information about personal data we collect and how we use it
  • Correct: Request correction of inaccurate personal information
  • Delete: Request deletion of personal information, subject to legal exceptions
  • Opt out: Opt out of targeted advertising

How to Exercise Rights:

  • Email: [Insert Email] with subject line "New York Privacy Request"
  • Phone: (415) 634-0998
  • In person: 1530 Union St, San Francisco, CA 94123

9.5 New York City Automated Employment Decision Tools

If we ever use automated employment decision tools as defined by New York City law, we will comply with all notice, audit, and bias audit requirements.


10. EUROPE AND THE UNITED KINGDOM

This section applies to individuals in the European Economic Area (EEA), Switzerland, and the United Kingdom.

10.1 Data Controller

Hairchitect Med Spa & Beauty Lounge San Francisco is the controller of your personal data processed through our website and services.

10.2 Legal Bases for Processing

We process personal data based on the following legal grounds:

Contract Performance:

  • Processing necessary to provide services you've requested
  • Booking appointments and delivering treatments
  • Processing payments

Consent:

  • Marketing communications (where required)
  • Cookies (where required)
  • Processing of special category data (health information) with your explicit consent

Legitimate Interests:

  • Improving our services and website
  • Analytics and business intelligence
  • Direct marketing to existing customers (soft opt-in)
  • Fraud prevention and security
  • Operating and managing our business

We only rely on legitimate interests where they are not overridden by your rights and interests.

Legal Obligations:

  • Compliance with applicable laws and regulations
  • Responding to legal requests
  • Tax and accounting requirements

Vital Interests:

  • Protection of health or life in emergency situations

Public Interest:

  • Public health purposes where applicable

10.3 Your Rights Under GDPR/UK GDPR

You have the following rights:

Right to Access: Obtain confirmation of whether we process your data and access to that data

Right to Rectification: Correct inaccurate or incomplete personal data

Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data in certain circumstances

Right to Restriction: Request limitation of processing in certain situations

Right to Data Portability: Receive your data in a structured, commonly used format and transmit it to another controller

Right to Object:

  • Object to processing based on legitimate interests
  • Object to direct marketing (absolute right - we must stop)
  • Object to automated decision-making and profiling

Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting prior processing

Right Not to be Subject to Automated Decision-Making: Protection from decisions based solely on automated processing that significantly affects you

10.4 How to Exercise Your Rights

Contact Us:

  • Email: This email address is being protected from spambots. You need JavaScript enabled to view it. with subject line "GDPR/UK GDPR Request"
  • Phone: +1 (415) 908-1966
  • Mail: 1530 Union St, San Francisco, CA 94123

We will respond within one month. In complex cases, we may extend by two additional months and will notify you.

No Fee: Exercising your rights is generally free, though we may charge a reasonable fee for manifestly unfounded or excessive requests.

10.5 Right to Lodge a Complaint

You have the right to lodge a complaint with your local supervisory authority if you believe we've violated data protection law:

EU/EEA: Contact your national Data Protection Authority
UK: Information Commissioner's Office (ICO) - https://ico.org.uk
Switzerland: Federal Data Protection and Information Commissioner (FDPIC)

10.6 International Transfers

We are based in the United States. When we transfer your personal data outside the EEA, Switzerland, or UK, we use appropriate safeguards such as:

  • Standard Contractual Clauses approved by the European Commission or UK equivalents
  • Adequacy decisions where the destination country is deemed adequate
  • Appropriate safeguards under Article 46 GDPR/UK GDPR
  • Derogations for specific situations under Article 49 GDPR/UK GDPR (e.g., explicit consent, contract performance)

Transfers to the US: Following the invalidation of Privacy Shield, we rely on Standard Contractual Clauses and supplementary measures to ensure adequate protection.

You may request a copy of the safeguards we use by contacting us.

10.7 Retention

See Section 11 for our general retention practices. For EEA/UK individuals, we retain data only as long as necessary for the purposes described, taking into account legal requirements and limitation periods.

10.8 Special Category Data

Health information is "special category data" under GDPR requiring additional protections. We process health data only:

  • With your explicit consent
  • For medical treatment purposes (with appropriate safeguards)
  • As permitted by law

11. DATA RETENTION

We retain personal information only as long as necessary for the purposes described in this Privacy Policy, including to:

  • Provide and maintain services
  • Comply with legal obligations
  • Resolve disputes
  • Enforce agreements
  • Maintain business records

11.1 Retention Criteria

We determine retention periods based on:

  • Nature of the information: Sensitive data (health information) may have specific retention requirements
  • Purpose of processing: Marketing data retained only while actively used
  • Legal requirements: Tax records, medical records, employment records must be kept for specified periods
  • Limitation periods: Retained for periods during which claims could be brought
  • Your preferences: Honored where legally permissible
  • Technical constraints: Backup systems may retain data longer

11.2 Specific Retention Periods

Account and Contact Information:

  • Active accounts: Retained while account is active and for reasonable period after closure
  • Marketing lists: Retained until you opt out or for reasonable inactive period (typically 2-3 years)

Transaction and Booking Records:

  • Retained for 7 years minimum for tax and accounting purposes
  • Payment records: As required by financial regulations

Medical Records and Health Information:

  • Retained for minimum period required by California law (typically 7 years from last treatment)
  • May be retained longer for continuity of care or legal requirements
  • Subject to HIPAA retention rules

Communications:

  • Customer service interactions: Typically 2-3 years
  • Marketing consents: While valid and for reasonable period after revocation

Website and Analytics Data:

  • Typically 26 months for Google Analytics
  • Other analytics as needed for business purposes

Security and Fraud Prevention:

  • Retained as long as necessary to protect against fraud and security threats

11.3 Deletion

When retention periods expire and we no longer have a legitimate reason to keep information, we:

  • Securely delete or destroy the information
  • Anonymize the information so it no longer identifies you
  • Aggregate it with other information

Backup and Archive Systems: Information in backups and archives may persist until those systems are overwritten in the normal course of operations.


12. THIRD-PARTY LINKS AND SERVICES

12.1 External Websites

Our website may contain links to third-party websites, social media platforms, or services (e.g., Instagram, Facebook, booking platforms, payment processors). We are not responsible for:

  • Privacy practices of third parties
  • Content on external sites
  • Security of information you provide to third parties

We encourage you to review the privacy policies of any third-party sites you visit.

12.2 Third-Party Features

We may integrate third-party features such as:

  • Social media sharing buttons
  • Embedded videos (YouTube, Vimeo)
  • Maps (Google Maps)
  • Chat widgets

These features may collect information about you according to their own privacy policies.

12.3 Third-Party Responsibility

Third parties are responsible for their own privacy practices. Our Privacy Policy does not apply to their activities.


13. CHILDREN'S PRIVACY

13.1 Age Restrictions

Our services are not directed to children under 13 years of age, and we do not knowingly collect personal information from children under 13.

Medical Spa Services: Require clients to be 18 years or older.

Beauty Lounge Services: Minors may receive services with parental consent, but we do not collect personal information from children under 13 through our website.

13.2 Parental Rights

If you believe we have collected information from a child under 13, please contact us immediately at [Insert Email]. We will:

  • Verify the claim
  • Delete the information promptly
  • Terminate any associated account

Parents/guardians have the right to:

  • Review information collected from their child
  • Request deletion of that information
  • Refuse further collection or use

13.3 COPPA Compliance

We comply with the Children's Online Privacy Protection Act (COPPA) and do not knowingly collect personal information from children under 13 without verified parental consent.


14. CHANGES TO THIS PRIVACY POLICY

14.1 Right to Modify

We reserve the right to update, modify, or replace this Privacy Policy at any time at our sole discretion to reflect:

  • Changes in our practices
  • New legal requirements
  • Technological developments
  • Business changes

14.2 Notice of Changes

We will notify you of material changes by:

  • Posting the updated Privacy Policy on this page with a new "Effective Date"
  • Sending email notification if you have an account with us (for significant changes)
  • Displaying a prominent notice on our website

Non-material changes (clarifications, formatting, contact information updates) may be made without additional notice beyond updating the Effective Date.

14.3 Your Responsibility

It is your responsibility to review this Privacy Policy periodically. Continued use of our website or services after changes constitutes your acceptance of the updated Privacy Policy.

If you do not agree with the updated Privacy Policy, you must stop using our services.

14.4 Previous Versions

We may maintain archived versions of previous Privacy Policies. Contact us if you would like to review a previous version.


15. CONTACT US

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Hairchitect Med Spa & Beauty Lounge San Francisco

Address:
1530 Union St
San Francisco, CA 94123

Phone:

+1 (415) 908-1966

Email: 

This email address is being protected from spambots. You need JavaScript enabled to view it.

Hours:

Monday - Sunday
9:00 - 20:00

Response Times

  • General inquiries: We strive to respond within 2-3 business days
  • Privacy rights requests: Responded to within timelines required by applicable law (typically 30-45 days)
  • Data breach concerns: Addressed immediately

16. HIPAA NOTICE OF PRIVACY PRACTICES

Protected Health Information (PHI) related to medical spa treatments is subject to additional protections under the Health Insurance Portability and Accountability Act (HIPAA).

For detailed information about how we handle PHI, please see our separate HIPAA Notice of Privacy Practices, which is:

  • Available at our facility
  • Provided to you at your first visit
  • Available upon request at any time
  • Posted on our website [if applicable - insert link]

Our HIPAA Notice describes:

  • How we use and disclose your health information
  • Your rights regarding your health information
  • Our legal duties regarding health information
  • How to file a complaint if you believe your privacy rights have been violated

This Privacy Policy and our HIPAA Notice work together to protect your privacy and health information.


17. ADDITIONAL DISCLOSURES

17.1 Medical Disclaimer

Information on our website about treatments and services is for informational purposes only and does not constitute medical advice. Always consult with qualified healthcare providers regarding medical decisions.

17.2 Treatment Photography

  • Photographs for medical records are taken with your consent and stored securely
  • Use of photos for marketing purposes (before/after galleries, social media, advertising) requires separate written authorization
  • You may revoke marketing consent at any time, though previously published materials may remain in circulation

17.3 Testimonials and Reviews

With your permission, we may use your testimonials or reviews in our marketing materials. You can request removal at any time.

17.4 Research and Aggregated Data

We may use de-identified or aggregated information for research, quality improvement, or business purposes without restriction.


ACKNOWLEDGMENT

By using our website, booking services, or providing us with personal information, you acknowledge that:

  • You have read and understood this Privacy Policy
  • You consent to the collection, use, and disclosure of your information as described
  • You understand your rights and how to exercise them
  • You have had the opportunity to ask questions about our privacy practices

Effective Date: 12/16/2025

Last Updated: 12/16/2025

Version: 1.0


This Privacy Policy is subject to change. Please review periodically for updates.