Last updated: July 2026
This Privacy Policy ("Policy") describes how Aesthatech LLC, a New Jersey limited liability company, and its affiliates ("Aesthatech", "Company", "we", "us", or "our") collect, use, disclose, retain, and protect personal information in connection with our business management platform for independent beauty and wellness professionals, including our website, dashboard, APIs, and related services (collectively, the "Service").
This Policy applies to our business customers ("Business Customers", "you") who register for and use the Service, and, where applicable, to the end-consumers of our Business Customers ("End-Consumers" or "Clients") whose data is processed by Business Customers through the Service. Section 18 explains this distinction in detail.
By accessing or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, you must not access or use the Service. This Policy is incorporated into and subject to our Terms of Service.
We do not sell personal information for monetary consideration.
a. Account & identity information
Name, email address, phone number, business name, password/authentication credentials, and profile information collected via Clerk when you register, log in, or manage your account.
b. Business information
Business name, address, tax/EIN information (if provided), services offered, pricing, staff information, and other operational details you configure within the Service.
c. Client / End-Consumer data
Names, contact details (email, phone, address), service notes, appointment and visit history, preferences, and other information you enter or import about your own clients. This may include sensitive categories of information (e.g., health-adjacent notes such as allergies or skin conditions) that you choose to record.
d. Payment and billing information
Subscription plan, billing address, transaction history, and payment method details. Payment card data is collected and processed directly by our PCI DSS-compliant payment processor(s) (currently Stripe); we do not store full payment card numbers on our servers.
e. Third-party integration data
If you connect third-party services (such as Square or other point-of-sale, calendar, or payment systems) to your account, we collect the data made available to us through those integrations via OAuth or API connections, including catalog, booking, order, and customer data, as permitted by your authorization scopes and the applicable third party's terms.
f. Usage and technical data
Feature usage, log data, timestamps, generation/usage limits, referring URLs, and diagnostic information used to operate, secure, and improve the Service.
g. Device and connection information
IP address, browser type and version, operating system, device identifiers, and general geolocation inferred from IP address.
h. Cookies and similar technologies
Session and functional cookies, local storage, and similar technologies as described in Section 9.
i. Communications
Content of support requests, emails, and other communications you send to us.
Where the GDPR, UK GDPR, or similar frameworks apply, we rely on the following legal bases:
Under the CCPA/CPRA, our collection and use of personal information is described throughout this Policy and does not constitute a "sale" or "sharing" as those terms are defined by California law, except as may occur through certain analytics or advertising cookies you may enable; see Section 9 and Section 12.
Aesthatech's Smart Actions, Smart Insights, and Content Planner features are powered by Anthropic's Claude API.
a1b2c3d4) derived from their internal ID. Real contact details are restored server-side after processing and are never sent to Anthropic.We disclose personal information only in the following circumstances:
| Recipient | Purpose | Data involved |
|---|---|---|
| Supabase | Database & storage infrastructure | All business and client data |
| Clerk | Authentication | Name, email, login sessions |
| Stripe | Billing & payment processing | Subscription and payment info |
| Anthropic | Smart Features (Claude API) | Pseudonymized/anonymized business context (no direct identifiers) |
| Square / other POS or scheduling integrations | Data sync you authorize | Catalog, booking, order, and customer data per your authorized scopes |
| Hosting & infrastructure providers | Application hosting, CDN, email delivery | Data necessary to operate the Service |
We may also disclose information: (i) to comply with applicable law, regulation, legal process, or governmental request; (ii) to enforce our agreements, including investigation of potential violations; (iii) to protect the rights, property, or safety of Aesthatech, our users, or the public; (iv) in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, with notice to affected users where required by law; and (v) with your explicit consent.
We do not sell personal information to third parties for monetary consideration, and we do not share personal information for cross-context behavioral advertising.
Aesthatech is based in the United States, and our service providers may process data in the United States and other countries. If you access the Service from the European Economic Area (EEA), United Kingdom, or other regions with data transfer restrictions, your information may be transferred to, stored, and processed in a country that may not have the same data protection laws as your home jurisdiction.
Where required, we rely on appropriate safeguards for such transfers, including the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, adequacy decisions, or other legally recognized transfer mechanisms with our processors. You may contact us for more information about the safeguards we use for a specific transfer.
Depending on your jurisdiction (including under the GDPR, UK GDPR, CCPA/CPRA, and other applicable laws), you may have the following rights regarding your personal information:
Right to Access / Know
Request confirmation of, and access to, the personal information we hold about you, including a downloadable copy: Download my data.
Right to Rectification / Correction
Correct or update inaccurate or incomplete personal information directly within the Aesthatech dashboard, or by contacting us.
Right to Erasure / Deletion
Request permanent deletion of your account and associated personal data via your account settings or our API endpoint DELETE /api/gdpr/delete-account. Deletion is irreversible and subject to the retention exceptions described in Section 7.
Right to Data Portability
Receive your personal information in a structured, commonly used, machine-readable format, and transmit it to another controller where technically feasible.
Right to Object / Opt-Out
Object to processing based on legitimate interests, opt out of marketing communications, and opt out of the sale or sharing of personal information (though we do not currently sell or share personal information as defined by the CCPA/CPRA).
Right to Restriction of Processing
Request that we limit the way we use your personal information in certain circumstances.
Right to Withdraw Consent
Withdraw consent for Smart Feature processing or optional cookies at any time, without affecting the lawfulness of processing before withdrawal.
Right to Non-Discrimination
We will not discriminate against you (e.g., by denying services or charging different prices) for exercising any of these rights.
Right to Lodge a Complaint
Lodge a complaint with your local data protection authority (e.g., your EU/UK supervisory authority) or the applicable regulator in your jurisdiction.
To exercise any of these rights, contact us at support@aesthatech.com. We will verify your identity before fulfilling requests and will respond within the timeframe required by applicable law (e.g., 30 days under GDPR, 45 days under CCPA, extendable as permitted).
The Service is intended for business use by individuals who are at least 18 years old. We do not knowingly collect personal information from children under the age of 16 (or the applicable age of digital consent in your jurisdiction). If we become aware that we have collected personal information from a child without verified parental consent, we will take steps to delete such information promptly. If you believe a child has provided us with personal information, please contact us at support@aesthatech.com.
We use the following categories of cookies and similar technologies:
We do not currently use third-party advertising or cross-site tracking cookies. You can control cookies through your browser settings; disabling strictly necessary cookies may prevent you from using the Service.
We implement administrative, technical, and physical safeguards designed to protect personal information, including:
No method of transmission or storage is 100% secure. While we strive to use commercially reasonable means to protect personal information, we cannot guarantee absolute security, and you use the Service at your own risk.
In the event of a security incident involving unauthorized access to personal information that triggers a legal notification obligation, we will notify affected users and, where required, applicable regulators without undue delay and in accordance with applicable law (e.g., within 72 hours of becoming aware, where required under GDPR). Notifications will describe the nature of the incident, the categories of data involved, and the steps we are taking in response, to the extent known at the time.
13. California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), grants you the following additional rights:
To exercise these rights, contact us at the address in Section 15. We may need to verify your identity before processing your request. You may designate an authorized agent to submit a request on your behalf, subject to verification.
We aim to comply with applicable privacy laws in the jurisdictions where our Business Customers operate, including:
Where you act as a Business Customer processing End-Consumer personal data through the Service, you are responsible for ensuring you have an appropriate legal basis to do so, and, where applicable, for entering into a Data Processing Addendum with us. Contact us to request our standard DPA.
For privacy-related requests, questions, or complaints, you may contact us through any of the following channels:
We aim to respond to all privacy inquiries within the timeframes required by applicable law.
If you have a concern about our handling of your personal information, please contact us first so we can attempt to resolve it directly. Any dispute, claim, or controversy arising out of or relating to this Policy that cannot be resolved informally shall be governed by, and resolved in accordance with, the dispute resolution, arbitration, and governing law provisions set forth in our Terms of Service, including any applicable arbitration agreement and class action waiver, to the fullest extent permitted by applicable law. Nothing in this section limits any non-waivable right you may have to lodge a complaint with a supervisory or regulatory authority.
Aesthatech may offer optional integrations with third-party platforms, including point-of-sale, payment, scheduling, and booking providers such as Square. If you choose to connect a third-party integration:
This Policy distinguishes between two categories of individuals whose data may be processed through the Service:
End-Consumers seeking to exercise privacy rights with respect to data held by a Business Customer through the Service should contact that Business Customer directly. Aesthatech will provide reasonable assistance to Business Customers in responding to such requests, consistent with our Data Processing Addendum.
The Service and any information provided through it (including AI-generated Smart Feature outputs) are provided on an "AS IS" and "AS AVAILABLE" basis without warranties of any kind, whether express, implied, or statutory, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement.
To the maximum extent permitted by applicable law, Aesthatech and its officers, directors, employees, and agents shall not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or any loss of data, profits, revenue, or business opportunities, arising out of or related to this Policy or our processing of personal information, even if advised of the possibility of such damages. Our aggregate liability arising out of or related to this Policy shall not exceed the amount described in the Limitation of Liability section of our Terms of Service.
You agree to indemnify, defend, and hold harmless Aesthatech and its officers, directors, employees, and agents from and against any claims, damages, liabilities, losses, and expenses (including reasonable attorneys' fees) arising out of or related to: (a) your breach of this Policy; (b) your collection, use, or disclosure of End-Consumer/Client personal information through the Service without a valid legal basis; or (c) your violation of any applicable privacy or data protection law in connection with your use of the Service.
Aesthatech shall not be liable for any failure or delay in performing its obligations under this Policy resulting from causes beyond its reasonable control, including acts of God, natural disasters, war, terrorism, labor disputes, internet or telecommunications failures, third-party service outages, or governmental action.
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will post the updated Policy on this page and revise the "Last updated" date above. For material changes that significantly affect your rights, we will provide additional notice, such as by email or an in-app notification, at least 30 days in advance where practicable. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Policy.
If any provision of this Policy is held to be invalid, illegal, or unenforceable by a court or authority of competent jurisdiction, that provision shall be limited or eliminated to the minimum extent necessary, and the remaining provisions shall continue in full force and effect.
Except as otherwise required by mandatory local data protection law, this Policy and any dispute arising under it shall be governed by the laws of the State of New Jersey, United States, consistent with the governing law provisions in our Terms of Service.