Privacy Policy

PRIVACY POLICY

Effective Date: July 2026

  1. Scope

This Privacy Policy describes how Grin & Glow Studio (“Grin & Glow,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards personal information when you interact with our website, online booking tools, mobile experiences, communications, and related services (collectively, the “Services”).

This Privacy Policy applies to personal information collected through our Services. For information regarding how we use and protect Protected Health Information (“PHI”), please refer to our HIPAA Notice of Privacy Practices, available at our office and upon request.

  1. Our Commitment to Privacy & HIPAA Compliance

We take privacy, confidentiality, and data security seriously. Grin & Glow utilizes HIPAA-aligned systems, administrative safeguards, technical protections, and operational procedures designed to protect personal information and PHI.

Where applicable, we maintain Business Associate Agreements (“BAAs”) with third-party vendors that may access PHI in connection with the Services they provide to us. We implement reasonable safeguards including encryption in transit and at rest, role-based access controls, audit logging, secure backups, employee training, and multi-factor authentication where available.

While no system or transmission method can guarantee absolute security, we continuously work to maintain and improve the protection of your information in accordance with applicable laws and HIPAA Security Rule principles.

  1. Information We Collect

Depending on how you interact with our Services, we may collect the following categories of information:

• Contact & Identity Information: Name, phone number, email address, mailing address, date of birth, and related identifiers.

• Appointment & Service Information: Appointment requests, provider preferences, scheduling details, consultation information, and related notes.

• Payment Information: Card-on-file details are processed and securely tokenized by our PCI-compliant payment processor. We do not store full credit card numbers.

• Communication Preferences & Consents: Marketing preferences, SMS/email opt-ins, policy acknowledgements, and communication settings.

• Technical & Device Information: IP address, browser type, device identifiers, cookies, analytics data, and website usage information.

• Optional Health Information: Limited information you voluntarily provide for scheduling or consultation purposes. Please avoid submitting highly sensitive medical details through open-text fields unless specifically requested.

  1. How We Use Information

We may use your information to:

• Schedule, confirm, modify, and manage appointments

• Communicate regarding appointments, services, policies, and updates

• Maintain card-on-file functionality and process authorized payments or applicable cancellation/no-show fees

• Improve our website, systems, services, and patient experience

• Respond to inquiries and provide customer support

• Send marketing or promotional communications where permitted and consented to

• Maintain security, detect fraud, troubleshoot issues, and comply with legal obligations

  1. Cookies & Analytics

Our website may use cookies, analytics tools, and similar technologies to improve website functionality, enhance user experience, analyze traffic patterns, and support marketing efforts.

Where required by law, we will request consent for certain tracking technologies. You may modify your browser settings to disable cookies; however, some website functionality may become limited.

  1. Disclosures to Third Parties

We may share information with trusted third parties as necessary to operate our business and provide Services, including:

• Scheduling, EHR & Communication Platforms: Third-party systems used for appointment scheduling, patient communications, operational workflows, and related business functions.

• Payment Processors: PCI-compliant payment processors used for secure payment processing and tokenized card storage.

• Service Providers: Vendors providing IT support, cloud hosting, cybersecurity, analytics, email delivery, SMS communications, and related operational services, all subject to confidentiality obligations.

• Legal & Compliance Purposes: When required by law, regulation, subpoena, court order, legal process, or when necessary to protect the rights, safety, property, or security of Grin & Glow, our patients, staff, or others.

We do not sell personal information. We also do not use or disclose Protected Health Information (“PHI”) for marketing purposes without appropriate authorization where required by law.

  1. Card on File & Payments

To help streamline scheduling and billing, patients may be required to maintain a valid card on file. Payment information is securely processed and tokenized through our PCI-compliant payment processor.

Authorized charges may include treatment payments, cancellation fees, late-cancel fees, or no-show fees in accordance with our Scheduling & Cancellation Policy.

  1. Text Messaging (SMS) & Email Communications

By providing your contact information, you consent to receive transactional communications related to your appointments and services, including confirmations, reminders, scheduling updates, post-visit instructions, and operational notifications.

Marketing communications are only sent where you have opted in or where otherwise permitted by law. You may unsubscribe from marketing emails using the unsubscribe link included in communications or opt out of SMS marketing by replying STOP. Standard carrier message and data rates may apply.

Consent to receive marketing text messages is not a condition of purchasing services. Message frequency may vary.

  1. Children’s Privacy

Our Services are intended for individuals age 18 and older unless services are authorized by a parent or legal guardian and permitted under applicable law. We do not knowingly collect personal information from minors without appropriate authorization or consent.

  1. Data Retention

We retain personal information and appointment records for as long as reasonably necessary to provide Services, comply with legal, regulatory, accounting, operational, and HIPAA-related obligations, resolve disputes, and enforce our policies.

When information is no longer required, we securely delete, anonymize, or de-identify it in accordance with applicable standards.

  1. Security Measures

We maintain safeguards designed to protect personal information and PHI against unauthorized access, disclosure, alteration, or destruction. These measures may include encryption, secure servers, access restrictions, audit logging, employee confidentiality training, cybersecurity monitoring, backups, and related administrative, physical, and technical protections.

While no system can guarantee absolute security, we continuously work to maintain and improve the security of our systems and data.

In the event of a data breach involving personal information, we will provide notifications as required under applicable federal and New Jersey law.

  1. Your Privacy Rights

Depending on your state or country of residence, you may have rights regarding your personal information, including rights to request access, correction, deletion, restriction, or copies of certain data, as well as the right to opt out of marketing communications.

To exercise applicable rights or submit privacy-related questions, please contact us at [privacy email]. We may require identity verification before processing certain requests.

  1. Third-Party Websites

Our website may contain links to third-party websites, platforms, or services. These third parties maintain separate privacy practices and policies, and we are not responsible for their content, security, or privacy practices. We encourage you to review their privacy policies before submitting information.

  1. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect operational, legal, or regulatory changes. Updates will be posted on this page with a revised effective date. Continued use of our Services following any updates constitutes acceptance of the revised Privacy Policy.

  1. New Jersey Law

This Privacy Policy shall be governed by and construed in accordance with the laws of the State of New Jersey, without regard to conflict of law principles.