HIPAA Compliant
Last Updated: December 8, 2025

Privacy Policy

At GlowClient, we are committed to protecting the privacy and security of your information, including Protected Health Information (PHI). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our medical spa management platform.

Section 1

Introduction

GlowClient, Inc. ("GlowClient," "we," "us," or "our") provides a HIPAA-compliant medical spa and aesthetic practice management platform. This Privacy Policy applies to information we collect through our website, web application, mobile applications, and any related services (collectively, the "Services").

Effective Date: December 8, 2025

By using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree to this Privacy Policy, please do not use our Services.

Legal Compliance Notice

This Privacy Policy is designed to comply with applicable federal and state privacy laws, including HIPAA (Health Insurance Portability and Accountability Act), CCPA (California Consumer Privacy Act), and other applicable regulations.

Section 2

Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, phone number, business name, and professional credentials when you register
  • Patient Data: Medical histories, treatment records, photographs, consent forms, and other Protected Health Information (PHI) that you enter into the system
  • Payment Information: Billing address and payment card details (processed securely through Stripe)
  • Communications: Messages, support requests, and feedback you send to us

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, time spent, and navigation patterns
  • Device Information: IP address, browser type, operating system, and device identifiers
  • Log Data: Server logs including access times, error reports, and system activity
  • Audit Logs: Records of all PHI access and modifications for HIPAA compliance

2.3 Protected Health Information (PHI)

We treat all patient-related data as Protected Health Information (PHI) under HIPAA. This includes:

  • Patient names, addresses, and contact information
  • Medical records and treatment histories
  • Clinical photographs and documentation
  • Appointment schedules and service records
  • Insurance and billing information
  • Any other individually identifiable health information
Section 3

How We Use Your Information

We use the information we collect for the following purposes:

Service Delivery

To provide, maintain, and improve our platform features

Healthcare Operations

To facilitate patient care and practice management

Security & Compliance

To protect data, prevent fraud, and ensure HIPAA compliance

Communications

To send important updates, support responses, and notifications

Analytics

To analyze usage patterns and improve user experience

Legal Compliance

To comply with legal obligations and respond to lawful requests

Lawful Bases for Processing

We process your information based on the following legal bases:

  • Contract Performance: Processing necessary to fulfill our service agreement with you
  • Legal Obligation: Processing required to comply with HIPAA and other regulations
  • Legitimate Interests: Processing for fraud prevention, security, and service improvement
  • Consent: Processing based on your explicit consent where required
Section 4

HIPAA Compliance

Business Associate Agreement

GlowClient acts as a Business Associate under HIPAA. We execute Business Associate Agreements (BAAs) with all covered entities who use our Services to process PHI.

Our HIPAA Commitments

  • Implement administrative, physical, and technical safeguards
  • Encrypt all PHI at rest and in transit using AES-256-GCM
  • Maintain comprehensive audit logs of all PHI access
  • Limit PHI access to authorized personnel only
  • Report any security incidents or breaches promptly
  • Train all employees on HIPAA requirements
  • Conduct regular security risk assessments

Patient Rights Under HIPAA

Patients have specific rights regarding their PHI, including:

Right to access their PHI
Right to request amendments
Right to accounting of disclosures
Right to request restrictions
Right to confidential communications
Right to file complaints
Section 5

Information Sharing & Disclosure

We do not sell your personal information or PHI. We may share information only in the following circumstances:

5.1 Service Providers

We share information with carefully selected third-party service providers who assist us in operating our platform. All service providers handling PHI are required to sign Business Associate Agreements and maintain HIPAA compliance.

5.2 Legal Requirements

We may disclose information when required by law, including:

  • Court orders or legal proceedings
  • Public health activities
  • Law enforcement requests with proper authorization
  • Health oversight activities
  • To prevent imminent serious harm

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will provide notice before your information is transferred and becomes subject to a different privacy policy.

We Never Sell Your Data

GlowClient will never sell, rent, or trade your personal information or Protected Health Information to third parties for marketing or any other purpose.

Section 6

Data Security

We implement industry-leading security measures to protect your information:

Encryption

AES-256-GCM encryption for all PHI at rest; TLS 1.3 for data in transit

Access Controls

Role-based access control (RBAC) with multi-factor authentication

Audit Logging

Comprehensive logging of all PHI access and modifications

Infrastructure

SOC 2 compliant cloud hosting with geographic redundancy

For detailed information about our security practices, please visit our Security Page.

Section 7

Data Retention

We retain your information for as long as necessary to provide our Services and comply with legal obligations:

Data TypeRetention PeriodBasis
Protected Health Information7 years minimumHIPAA requirements
Audit Logs7 yearsHIPAA compliance
Account InformationDuration of account + 3 yearsBusiness necessity
Payment Records7 yearsTax/legal requirements
Usage Analytics2 years (anonymized)Service improvement
Section 8

Your Rights

Depending on your location, you may have the following rights regarding your personal information:

Right to Access

Request a copy of the personal information we hold about you

Right to Correction

Request correction of inaccurate or incomplete information

Right to Deletion

Request deletion of your personal information (subject to legal retention requirements)

Right to Data Portability

Receive your data in a structured, machine-readable format

Right to Opt-Out

Opt-out of marketing communications and certain data processing

To exercise any of these rights, please contact us at privacy@glowclient.com. We will respond to your request within 30 days.

California Residents (CCPA)

California residents have additional rights under the California Consumer Privacy Act, including the right to know what personal information is collected and the right to non-discrimination for exercising privacy rights.

Section 9

Cookies & Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience:

Types of Cookies We Use

Essential Cookies

Required for basic functionality, authentication, and security

Required

Functional Cookies

Remember your preferences and settings

Optional

Analytics Cookies

Help us understand how you use our Services

Optional

You can manage cookie preferences through your browser settings. Note that disabling essential cookies may affect the functionality of our Services.

Section 10

Third-Party Services

We use the following third-party services, all of which maintain appropriate security and privacy standards:

AWSCloud hosting & data storage
StripePayment processing
ClerkAuthentication services
TwilioSMS notifications
SendGridEmail delivery
VercelApplication hosting

Each of these providers has their own privacy policy governing their use of your information. We encourage you to review their policies.

Section 11

Children's Privacy

Our Services are not intended for children under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

For patients under 18, parental or guardian consent is required, and their information is handled with additional safeguards in accordance with applicable laws.

Section 12

International Data Transfers

Our Services are primarily operated in the United States. If you access our Services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States.

We implement appropriate safeguards for international data transfers, including:

  • Standard Contractual Clauses (SCCs) where required
  • Data processing agreements with international partners
  • Technical measures to ensure equivalent levels of protection
Section 13

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last Updated" date at the top
  • Sending an email notification for significant changes
  • Displaying a prominent notice within the application

We encourage you to review this Privacy Policy periodically. Your continued use of the Services after changes become effective constitutes acceptance of the revised policy.

Section 14

Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Mailing Address

GlowClient, Inc.
Attn: Privacy Officer
123 Market Street, Suite 500
San Francisco, CA 94105

For HIPAA-related concerns or to file a complaint, you may also contact the U.S. Department of Health and Human Services Office for Civil Rights.

Your Privacy Matters to Us

We are committed to protecting your information with the highest standards of security and compliance. If you have any questions, our Privacy team is here to help.