PRIVACY

Privacy Policy

Last updated: May 2026

Placeholder. This page should be reviewed by a US healthcare attorney before going live. Below is a starting outline that covers the bases for a US medspa collecting consultation requests with limited PHI.

1. Who we are

Princess Treatment ("we", "us") operates the website at your-domain.com and an in-person medspa in Bellevue, WA. Questions: [email protected].

2. What we collect

  • Identity: name, email, phone — provided by you when booking a consultation or subscribing.
  • Health-related preferences: the area of concern and treatment interest you optionally share — collected only for clinical care planning.
  • Technical: IP address, device type, pages viewed (for analytics & abuse prevention).
  • Cookies: see Section 6.

3. How we use it

  • To respond to your consultation request and schedule your visit.
  • To deliver and personalise treatment plans.
  • To send the newsletter you opted into (and only that).
  • To prevent abuse and meet legal obligations.

We never sell your data. We never use your health-related details for advertising.

4. Sharing

We share data only with: (a) our regulated medical providers and staff under confidentiality agreements; (b) service providers strictly necessary to operate the service (email, hosting, payment) under written data-processing terms; (c) when required by law.

5. Retention

Booking records are retained for 7 years to comply with Washington medical record retention rules. Newsletter records are kept until you unsubscribe.

6. Cookies & tracking

We use first-party cookies for sessions and Google Analytics 4 for aggregate analytics. You can opt out via the cookie banner or your browser's Do Not Track setting.

7. Your rights

You may request access, correction, deletion, or export of your data, or withdraw consent. Email us at [email protected]. Washington residents have additional rights under the My Health My Data Act.

8. Security

We use industry-standard transport encryption, restricted access controls, and encrypted backups. No method is perfectly secure; we do not transmit medical details by email to clients.

9. Children

The service is not directed at children under 16. We do not knowingly collect their data.

10. Changes

We will post material changes here and update the "Last updated" date. Continued use after changes means you accept the updated policy.