Privacy Policy

Last updated: July 2026

This Privacy Policy ("Policy") describes how Aesthatech LLC, a New Jersey limited liability company, and its affiliates ("Aesthatech", "Company", "we", "us", or "our") collect, use, disclose, retain, and protect personal information in connection with our business management platform for independent beauty and wellness professionals, including our website, dashboard, APIs, and related services (collectively, the "Service").

This Policy applies to our business customers ("Business Customers", "you") who register for and use the Service, and, where applicable, to the end-consumers of our Business Customers ("End-Consumers" or "Clients") whose data is processed by Business Customers through the Service. Section 18 explains this distinction in detail.

By accessing or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, you must not access or use the Service. This Policy is incorporated into and subject to our Terms of Service.

We do not sell personal information for monetary consideration.

1. Information We Collect

a. Account & identity information

Name, email address, phone number, business name, password/authentication credentials, and profile information collected via Clerk when you register, log in, or manage your account.

b. Business information

Business name, address, tax/EIN information (if provided), services offered, pricing, staff information, and other operational details you configure within the Service.

c. Client / End-Consumer data

Names, contact details (email, phone, address), service notes, appointment and visit history, preferences, and other information you enter or import about your own clients. This may include sensitive categories of information (e.g., health-adjacent notes such as allergies or skin conditions) that you choose to record.

d. Payment and billing information

Subscription plan, billing address, transaction history, and payment method details. Payment card data is collected and processed directly by our PCI DSS-compliant payment processor(s) (currently Stripe); we do not store full payment card numbers on our servers.

e. Third-party integration data

If you connect third-party services (such as Square or other point-of-sale, calendar, or payment systems) to your account, we collect the data made available to us through those integrations via OAuth or API connections, including catalog, booking, order, and customer data, as permitted by your authorization scopes and the applicable third party's terms.

f. Usage and technical data

Feature usage, log data, timestamps, generation/usage limits, referring URLs, and diagnostic information used to operate, secure, and improve the Service.

g. Device and connection information

IP address, browser type and version, operating system, device identifiers, and general geolocation inferred from IP address.

h. Cookies and similar technologies

Session and functional cookies, local storage, and similar technologies as described in Section 9.

i. Communications

Content of support requests, emails, and other communications you send to us.

2. How and Why We Use Information

  • Account management: creating, authenticating, and maintaining your account and preferences.
  • Service delivery: operating core features such as client management, scheduling, content planning, and Smart Features described in Section 3.
  • Payment processing: billing, invoicing, fraud prevention, and subscription management.
  • Analytics and improvement: understanding feature usage to maintain, troubleshoot, and improve the Service.
  • Security: detecting, preventing, and responding to fraud, abuse, unauthorized access, and security incidents.
  • Legal compliance: complying with applicable laws, regulations, legal process, and enforcing our agreements.
  • Communications: sending service-related notices, updates, security alerts, and, where permitted, marketing communications (with an opt-out available at all times).
  • Third-party integrations: syncing and reconciling data with services you connect, such as payment processors or point-of-sale systems.

3. Legal Basis for Processing

Where the GDPR, UK GDPR, or similar frameworks apply, we rely on the following legal bases:

  • Contractual necessity: processing necessary to perform our contract with you (e.g., providing the Service you subscribed to).
  • Legitimate interests: for security, fraud prevention, product improvement, and direct marketing to existing customers, balanced against your rights and interests.
  • Consent: for optional features such as Smart Features (AI processing) and non-essential cookies, which you may withdraw at any time.
  • Legal obligation: where processing is required to comply with tax, accounting, or other legal requirements.

Under the CCPA/CPRA, our collection and use of personal information is described throughout this Policy and does not constitute a "sale" or "sharing" as those terms are defined by California law, except as may occur through certain analytics or advertising cookies you may enable; see Section 9 and Section 12.

4. AI-Powered "Smart Features"

Aesthatech's Smart Actions, Smart Insights, and Content Planner features are powered by Anthropic's Claude API.

  • Client names, email addresses, and phone numbers are pseudonymized before transmission. Each client is replaced with an opaque token (e.g. a1b2c3d4) derived from their internal ID. Real contact details are restored server-side after processing and are never sent to Anthropic.
  • Service notes and visit history (which may contain health-adjacent context such as allergies or skin conditions) are sent in anonymized form and are not linked to any identifiable individual.
  • Anthropic does not train its models on API inputs submitted through the API. Per Anthropic's standard API terms, inputs and outputs are retained for a limited period (currently up to 30 days) for safety and operational purposes, then deleted.
  • You will be asked to provide explicit, informed consent before Smart Features are enabled on your account for the first time. You may withdraw this consent at any time by contacting us (Section 15), which will disable Smart Features for your account going forward.
  • AI-generated outputs are suggestions only and do not constitute professional, medical, legal, or financial advice. You are solely responsible for reviewing and validating any AI-generated content before relying on or distributing it.

5. How We Share Information

We disclose personal information only in the following circumstances:

RecipientPurposeData involved
SupabaseDatabase & storage infrastructureAll business and client data
ClerkAuthenticationName, email, login sessions
StripeBilling & payment processingSubscription and payment info
AnthropicSmart Features (Claude API)Pseudonymized/anonymized business context (no direct identifiers)
Square / other POS or scheduling integrationsData sync you authorizeCatalog, booking, order, and customer data per your authorized scopes
Hosting & infrastructure providersApplication hosting, CDN, email deliveryData necessary to operate the Service

We may also disclose information: (i) to comply with applicable law, regulation, legal process, or governmental request; (ii) to enforce our agreements, including investigation of potential violations; (iii) to protect the rights, property, or safety of Aesthatech, our users, or the public; (iv) in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, with notice to affected users where required by law; and (v) with your explicit consent.

We do not sell personal information to third parties for monetary consideration, and we do not share personal information for cross-context behavioral advertising.

6. International Data Transfers

Aesthatech is based in the United States, and our service providers may process data in the United States and other countries. If you access the Service from the European Economic Area (EEA), United Kingdom, or other regions with data transfer restrictions, your information may be transferred to, stored, and processed in a country that may not have the same data protection laws as your home jurisdiction.

Where required, we rely on appropriate safeguards for such transfers, including the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, adequacy decisions, or other legally recognized transfer mechanisms with our processors. You may contact us for more information about the safeguards we use for a specific transfer.

7. Data Retention

  • Account and business data: retained for as long as your account is active, and for a reasonable period thereafter to comply with legal obligations, resolve disputes, and enforce agreements.
  • Client/End-Consumer data: retained per your instructions as the Business Customer, until you delete it or delete your account.
  • Billing records: retained by Stripe and, where applicable, us, for the period required by applicable tax and financial recordkeeping laws (typically up to 7 years).
  • Smart Feature inputs/outputs: retained by Anthropic for up to 30 days per their standard API terms, then deleted.
  • Backups and logs: may persist in encrypted backups or security logs for a limited period after deletion, after which they are purged in the ordinary course of business.
  • On account deletion, we will delete or anonymize personal data within our systems within a commercially reasonable period, except where retention is required by law.

8. Your Privacy Rights

Depending on your jurisdiction (including under the GDPR, UK GDPR, CCPA/CPRA, and other applicable laws), you may have the following rights regarding your personal information:

Right to Access / Know

Request confirmation of, and access to, the personal information we hold about you, including a downloadable copy: Download my data.

Right to Rectification / Correction

Correct or update inaccurate or incomplete personal information directly within the Aesthatech dashboard, or by contacting us.

Right to Erasure / Deletion

Request permanent deletion of your account and associated personal data via your account settings or our API endpoint DELETE /api/gdpr/delete-account. Deletion is irreversible and subject to the retention exceptions described in Section 7.

Right to Data Portability

Receive your personal information in a structured, commonly used, machine-readable format, and transmit it to another controller where technically feasible.

Right to Object / Opt-Out

Object to processing based on legitimate interests, opt out of marketing communications, and opt out of the sale or sharing of personal information (though we do not currently sell or share personal information as defined by the CCPA/CPRA).

Right to Restriction of Processing

Request that we limit the way we use your personal information in certain circumstances.

Right to Withdraw Consent

Withdraw consent for Smart Feature processing or optional cookies at any time, without affecting the lawfulness of processing before withdrawal.

Right to Non-Discrimination

We will not discriminate against you (e.g., by denying services or charging different prices) for exercising any of these rights.

Right to Lodge a Complaint

Lodge a complaint with your local data protection authority (e.g., your EU/UK supervisory authority) or the applicable regulator in your jurisdiction.

To exercise any of these rights, contact us at support@aesthatech.com. We will verify your identity before fulfilling requests and will respond within the timeframe required by applicable law (e.g., 30 days under GDPR, 45 days under CCPA, extendable as permitted).

9. Children's Privacy

The Service is intended for business use by individuals who are at least 18 years old. We do not knowingly collect personal information from children under the age of 16 (or the applicable age of digital consent in your jurisdiction). If we become aware that we have collected personal information from a child without verified parental consent, we will take steps to delete such information promptly. If you believe a child has provided us with personal information, please contact us at support@aesthatech.com.

10. Cookies and Tracking Technologies

We use the following categories of cookies and similar technologies:

  • Strictly necessary cookies: session cookies set by Clerk for authentication and to keep you securely logged in. These cannot be disabled without affecting core functionality.
  • Functional storage: browser-side local storage used to cache generated content and preferences between page loads.
  • Analytics cookies (if enabled): used to understand aggregate usage patterns and improve the Service. Where required by law, we will request your consent before enabling non-essential analytics or advertising technologies.

We do not currently use third-party advertising or cross-site tracking cookies. You can control cookies through your browser settings; disabling strictly necessary cookies may prevent you from using the Service.

11. Data Security

We implement administrative, technical, and physical safeguards designed to protect personal information, including:

  • Encryption of data in transit (TLS) and at rest where supported by our infrastructure providers.
  • Access controls limiting internal access to personal information on a need-to-know basis.
  • Authentication and session security managed through Clerk, including support for secure password and multi-factor authentication practices.
  • Payment data handled by PCI DSS-compliant processors; we do not store full payment card numbers.
  • Regular review of our security practices and vendor security posture.

No method of transmission or storage is 100% secure. While we strive to use commercially reasonable means to protect personal information, we cannot guarantee absolute security, and you use the Service at your own risk.

12. Data Breach Notification

In the event of a security incident involving unauthorized access to personal information that triggers a legal notification obligation, we will notify affected users and, where required, applicable regulators without undue delay and in accordance with applicable law (e.g., within 72 hours of becoming aware, where required under GDPR). Notifications will describe the nature of the incident, the categories of data involved, and the steps we are taking in response, to the extent known at the time.

13. California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), grants you the following additional rights:

  • Right to know the categories and specific pieces of personal information we have collected about you, and the sources, purposes, and third parties involved.
  • Right to delete personal information we have collected from you, subject to certain exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of the "sale" or "sharing" of personal information. Aesthatech does not sell or share personal information as those terms are defined by the CCPA/CPRA.
  • Right to limit use and disclosure of sensitive personal information (we do not use sensitive personal information for purposes beyond providing the Service).
  • Right to non-discrimination for exercising any CCPA/CPRA right.

To exercise these rights, contact us at the address in Section 15. We may need to verify your identity before processing your request. You may designate an authorized agent to submit a request on your behalf, subject to verification.

14. International Privacy Frameworks

We aim to comply with applicable privacy laws in the jurisdictions where our Business Customers operate, including:

  • EU General Data Protection Regulation (GDPR): for Business Customers and End-Consumers located in the European Economic Area, we act as either a controller (for our own business purposes, such as account administration and billing) or a processor (with respect to Client data you input, processed on your instructions).
  • UK GDPR and Data Protection Act 2018: equivalent protections apply to users in the United Kingdom.
  • Brazil's Lei Geral de Proteção de Dados (LGPD): we extend equivalent rights (access, correction, deletion, portability, and information about sharing) to users in Brazil.
  • Canada's PIPEDA and other applicable provincial privacy laws.
  • Other applicable state, provincial, or national privacy laws, which we monitor and aim to comply with as our user base grows.

Where you act as a Business Customer processing End-Consumer personal data through the Service, you are responsible for ensuring you have an appropriate legal basis to do so, and, where applicable, for entering into a Data Processing Addendum with us. Contact us to request our standard DPA.

15. Contact Us

For privacy-related requests, questions, or complaints, you may contact us through any of the following channels:

We aim to respond to all privacy inquiries within the timeframes required by applicable law.

16. Dispute Resolution

If you have a concern about our handling of your personal information, please contact us first so we can attempt to resolve it directly. Any dispute, claim, or controversy arising out of or relating to this Policy that cannot be resolved informally shall be governed by, and resolved in accordance with, the dispute resolution, arbitration, and governing law provisions set forth in our Terms of Service, including any applicable arbitration agreement and class action waiver, to the fullest extent permitted by applicable law. Nothing in this section limits any non-waivable right you may have to lodge a complaint with a supervisory or regulatory authority.

17. Third-Party Integrations (Square and Others)

Aesthatech may offer optional integrations with third-party platforms, including point-of-sale, payment, scheduling, and booking providers such as Square. If you choose to connect a third-party integration:

  • You authorize Aesthatech to access and process data made available through that integration's API (e.g., catalog items, bookings, orders, and customer records) strictly to provide the connected functionality (such as syncing your catalog or bookings).
  • Your use of the third-party service remains subject to that provider's own terms of service and privacy policy, which we encourage you to review.
  • We implement industry-standard authentication (OAuth) and, where applicable, webhook signature verification to secure data exchanged with these integrations.
  • You may disconnect a third-party integration at any time from your account settings, which will revoke our access to that provider's data going forward.
  • We are not responsible for the privacy or security practices of third-party platforms, which operate independently of Aesthatech.

18. Business Customer Data vs. End-Consumer Data

This Policy distinguishes between two categories of individuals whose data may be processed through the Service:

  • Business Customers: the beauty and wellness professionals and businesses who register for and directly use the Service. With respect to Business Customer account, billing, and usage data, Aesthatech acts as a data controller and processes such data as described throughout this Policy.
  • End-Consumers/Clients: the individuals who are clients of our Business Customers, whose personal information (e.g., contact details, service notes, appointment history) is entered into the Service by the Business Customer. With respect to this data, Aesthatech acts solely as a data processor / service provider on behalf of the Business Customer, who acts as the data controller and is responsible for ensuring a valid legal basis for collecting and providing such data to us.

End-Consumers seeking to exercise privacy rights with respect to data held by a Business Customer through the Service should contact that Business Customer directly. Aesthatech will provide reasonable assistance to Business Customers in responding to such requests, consistent with our Data Processing Addendum.

19. Disclaimer and Limitation of Liability

The Service and any information provided through it (including AI-generated Smart Feature outputs) are provided on an "AS IS" and "AS AVAILABLE" basis without warranties of any kind, whether express, implied, or statutory, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement.

To the maximum extent permitted by applicable law, Aesthatech and its officers, directors, employees, and agents shall not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or any loss of data, profits, revenue, or business opportunities, arising out of or related to this Policy or our processing of personal information, even if advised of the possibility of such damages. Our aggregate liability arising out of or related to this Policy shall not exceed the amount described in the Limitation of Liability section of our Terms of Service.

20. Indemnification

You agree to indemnify, defend, and hold harmless Aesthatech and its officers, directors, employees, and agents from and against any claims, damages, liabilities, losses, and expenses (including reasonable attorneys' fees) arising out of or related to: (a) your breach of this Policy; (b) your collection, use, or disclosure of End-Consumer/Client personal information through the Service without a valid legal basis; or (c) your violation of any applicable privacy or data protection law in connection with your use of the Service.

21. Force Majeure

Aesthatech shall not be liable for any failure or delay in performing its obligations under this Policy resulting from causes beyond its reasonable control, including acts of God, natural disasters, war, terrorism, labor disputes, internet or telecommunications failures, third-party service outages, or governmental action.

22. Updates to This Policy

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will post the updated Policy on this page and revise the "Last updated" date above. For material changes that significantly affect your rights, we will provide additional notice, such as by email or an in-app notification, at least 30 days in advance where practicable. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Policy.

23. Severability and Governing Law

If any provision of this Policy is held to be invalid, illegal, or unenforceable by a court or authority of competent jurisdiction, that provision shall be limited or eliminated to the minimum extent necessary, and the remaining provisions shall continue in full force and effect.

Except as otherwise required by mandatory local data protection law, this Policy and any dispute arising under it shall be governed by the laws of the State of New Jersey, United States, consistent with the governing law provisions in our Terms of Service.