Privacy Policy
At GlowClient, we are committed to protecting the privacy and security of your information, including Protected Health Information (PHI). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our medical spa management platform.
Introduction
GlowClient, Inc. ("GlowClient," "we," "us," or "our") provides a HIPAA-compliant medical spa and aesthetic practice management platform. This Privacy Policy applies to information we collect through our website, web application, mobile applications, and any related services (collectively, the "Services").
Effective Date: December 8, 2025
By using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree to this Privacy Policy, please do not use our Services.
Legal Compliance Notice
This Privacy Policy is designed to comply with applicable federal and state privacy laws, including HIPAA (Health Insurance Portability and Accountability Act), CCPA (California Consumer Privacy Act), and other applicable regulations.
Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, phone number, business name, and professional credentials when you register
- Patient Data: Medical histories, treatment records, photographs, consent forms, and other Protected Health Information (PHI) that you enter into the system
- Payment Information: Billing address and payment card details (processed securely through Stripe)
- Communications: Messages, support requests, and feedback you send to us
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, time spent, and navigation patterns
- Device Information: IP address, browser type, operating system, and device identifiers
- Log Data: Server logs including access times, error reports, and system activity
- Audit Logs: Records of all PHI access and modifications for HIPAA compliance
2.3 Protected Health Information (PHI)
We treat all patient-related data as Protected Health Information (PHI) under HIPAA. This includes:
- Patient names, addresses, and contact information
- Medical records and treatment histories
- Clinical photographs and documentation
- Appointment schedules and service records
- Insurance and billing information
- Any other individually identifiable health information
How We Use Your Information
We use the information we collect for the following purposes:
Service Delivery
To provide, maintain, and improve our platform features
Healthcare Operations
To facilitate patient care and practice management
Security & Compliance
To protect data, prevent fraud, and ensure HIPAA compliance
Communications
To send important updates, support responses, and notifications
Analytics
To analyze usage patterns and improve user experience
Legal Compliance
To comply with legal obligations and respond to lawful requests
Lawful Bases for Processing
We process your information based on the following legal bases:
- Contract Performance: Processing necessary to fulfill our service agreement with you
- Legal Obligation: Processing required to comply with HIPAA and other regulations
- Legitimate Interests: Processing for fraud prevention, security, and service improvement
- Consent: Processing based on your explicit consent where required
HIPAA Compliance
Business Associate Agreement
GlowClient acts as a Business Associate under HIPAA. We execute Business Associate Agreements (BAAs) with all covered entities who use our Services to process PHI.
Our HIPAA Commitments
- Implement administrative, physical, and technical safeguards
- Encrypt all PHI at rest and in transit using AES-256-GCM
- Maintain comprehensive audit logs of all PHI access
- Limit PHI access to authorized personnel only
- Report any security incidents or breaches promptly
- Train all employees on HIPAA requirements
- Conduct regular security risk assessments
Patient Rights Under HIPAA
Patients have specific rights regarding their PHI, including:
Information Sharing & Disclosure
We do not sell your personal information or PHI. We may share information only in the following circumstances:
5.1 Service Providers
We share information with carefully selected third-party service providers who assist us in operating our platform. All service providers handling PHI are required to sign Business Associate Agreements and maintain HIPAA compliance.
5.2 Legal Requirements
We may disclose information when required by law, including:
- Court orders or legal proceedings
- Public health activities
- Law enforcement requests with proper authorization
- Health oversight activities
- To prevent imminent serious harm
5.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will provide notice before your information is transferred and becomes subject to a different privacy policy.
We Never Sell Your Data
GlowClient will never sell, rent, or trade your personal information or Protected Health Information to third parties for marketing or any other purpose.
Data Security
We implement industry-leading security measures to protect your information:
Encryption
AES-256-GCM encryption for all PHI at rest; TLS 1.3 for data in transit
Access Controls
Role-based access control (RBAC) with multi-factor authentication
Audit Logging
Comprehensive logging of all PHI access and modifications
Infrastructure
SOC 2 compliant cloud hosting with geographic redundancy
For detailed information about our security practices, please visit our Security Page.
Data Retention
We retain your information for as long as necessary to provide our Services and comply with legal obligations:
| Data Type | Retention Period | Basis |
|---|---|---|
| Protected Health Information | 7 years minimum | HIPAA requirements |
| Audit Logs | 7 years | HIPAA compliance |
| Account Information | Duration of account + 3 years | Business necessity |
| Payment Records | 7 years | Tax/legal requirements |
| Usage Analytics | 2 years (anonymized) | Service improvement |
Your Rights
Depending on your location, you may have the following rights regarding your personal information:
Right to Access
Request a copy of the personal information we hold about you
Right to Correction
Request correction of inaccurate or incomplete information
Right to Deletion
Request deletion of your personal information (subject to legal retention requirements)
Right to Data Portability
Receive your data in a structured, machine-readable format
Right to Opt-Out
Opt-out of marketing communications and certain data processing
To exercise any of these rights, please contact us at privacy@glowclient.com. We will respond to your request within 30 days.
California Residents (CCPA)
California residents have additional rights under the California Consumer Privacy Act, including the right to know what personal information is collected and the right to non-discrimination for exercising privacy rights.
Third-Party Services
We use the following third-party services, all of which maintain appropriate security and privacy standards:
Each of these providers has their own privacy policy governing their use of your information. We encourage you to review their policies.
Children's Privacy
Our Services are not intended for children under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
For patients under 18, parental or guardian consent is required, and their information is handled with additional safeguards in accordance with applicable laws.
International Data Transfers
Our Services are primarily operated in the United States. If you access our Services from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States.
We implement appropriate safeguards for international data transfers, including:
- Standard Contractual Clauses (SCCs) where required
- Data processing agreements with international partners
- Technical measures to ensure equivalent levels of protection
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last Updated" date at the top
- Sending an email notification for significant changes
- Displaying a prominent notice within the application
We encourage you to review this Privacy Policy periodically. Your continued use of the Services after changes become effective constitutes acceptance of the revised policy.
Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Privacy Officer
Mailing Address
GlowClient, Inc.Attn: Privacy Officer
123 Market Street, Suite 500
San Francisco, CA 94105
For HIPAA-related concerns or to file a complaint, you may also contact the U.S. Department of Health and Human Services Office for Civil Rights.
