1. Who We Are and Our Accountability
Relax & Refresh provides mobile esthetician and wellness services in Ontario. Its Privacy Officer oversees privacy practices, access and correction requests, consent changes, complaints, and incident response.
Ontario's Personal Health Information Protection Act, 2004 (PHIPA) may apply where information is handled by or for a health information custodian. The federal Personal Information Protection and Electronic Documents Act (PIPEDA) may apply to commercial personal-information practices. We also follow CASL and other applicable privacy, consumer, tax, and legal requirements. This Policy does not claim that every Refresh record is a PHIPA record.
2. Information We Collect
Depending on how you interact with us, we may collect:
- Identity and contact information: name, pronouns where provided, date of birth where needed, email, phone, service address, emergency contact, account identifiers, and identity-verification information.
- Service and consent information: treatment goals, relevant health or safety information, contraindications, allergies, intake answers, practitioner notes where applicable, service-specific consent, and consent withdrawal.
- Booking information: treatment, duration, practitioner preference, attendee details, availability searches, temporary holds, waitlist and Request Booking preferences, service address, access notes, appointment status, cancellations, and attendance.
- Payment information: invoices, receipt details, payment and refund status, billing address, transaction references, and saved-card references. Card payments are securely handled by Stripe; Relax & Refresh does not receive or store your full card number or security code.
- Communications: emails, texts, voicemail, call metadata, support requests, service notices, marketing preferences, consent evidence, and unsubscribe or STOP requests.
- Website and security information: IP address, browser and device details, sign-in attempts, pages and features used, cookies, and information needed to protect the website from fraud or misuse.
- Location and safety information: service addresses, routing information, travel eligibility, parking and access details, and practitioner safety or emergency events that may indirectly identify an appointment location.
3. How We Collect and Use Information
- To answer inquiries and manage launch-interest preferences.
- To validate service coverage, calculate travel, show appropriate Refresh treatments and practitioners, and coordinate individual, group, back-to-back, or simultaneous appointments.
- To assess service suitability, prepare and provide a requested treatment, document consent, and support client and practitioner safety.
- To manage accounts, profiles, appointment history, cancellations, waitlist, Request Booking, invoices, receipts, payments, refunds, and saved cards.
- To send appointment, intake, payment, safety, security, and support communications and, only with separate consent, marketing communications.
- To operate, protect, troubleshoot, and improve the website and client portal; prevent fraud and abuse; and respond to privacy or security concerns.
- To meet applicable privacy, consumer, tax, court, safety, and other legal obligations.
We normally collect information directly from you. When appropriate, we may receive it from another attendee arranging a multi-person booking, someone you have authorized, or a company that helps us provide the requested service.
4. Consent, Service Communications, and Marketing
- Service-specific treatment consent is separate from accepting this Privacy Policy. You may ask questions and withdraw treatment consent at any time.
- Privacy consent may be express or implied where permitted by law. We seek express consent where the law or sensitivity of the purpose requires it.
- Appointment confirmations, intake reminders, payment notices, receipts, security alerts, and replies to your requests are essential service messages, not marketing subscriptions.
- Marketing email or text consent is optional and recorded separately. Refusing marketing does not affect service eligibility. You may use an unsubscribe link, reply STOP where supported, change your preference in the client portal, or contact us.
- Withdrawing consent does not invalidate prior lawful handling and does not require deletion of records we must retain. It may limit a service where the information is reasonably necessary for suitability, safety, payment, or legal compliance.
6. Safeguards and Business Separation
We use safeguards appropriate to the sensitivity of the information, including limited staff access, secure sign-in, encryption where appropriate, activity records, backups, retention rules, and plans for responding to privacy or security concerns.
Refresh appointments, invoices, consent, and service records are labelled and kept separate. If a Refresh service is unavailable, we do not substitute another business's records or services.
No website or storage method can be guaranteed completely secure. Please avoid sending sensitive information through an unsecured channel unless we ask you to do so.
7. Retention and Disposal
- Booking, service, consent, invoice, payment, tax, communication, security, and audit records are kept only as long as reasonably necessary for the purpose and applicable legal, limitation, tax, safety, dispute, and accountability requirements.
- Launch-interest information is kept until the launch is complete, consent is withdrawn, or we no longer reasonably need it. We may keep a record of an unsubscribe request so we continue to honour it.
- Records subject to PHIPA or another specific retention duty are kept for the period required by that law or the responsible custodian.
- When retention is no longer required, information is securely deleted, destroyed, or anonymized. Protected backups may remain until their normal rotation ends.
9. Access, Correction, Consent, and Complaints
- You may request access to or correction of your personal information, subject to limited legal exceptions.
- We may require a written request and reasonable identity verification before releasing or changing information.
- You may withdraw consent or change communication preferences, subject to legal or service requirements. We will explain any important effect on your service.
- If PHIPA applies to a record or request, applicable PHIPA access, correction, breach, and complaint rights continue to apply.
- We investigate suspected privacy incidents, contain and remediate them, and provide notices required by applicable law.
10. Contact and Policy Changes
Questions, access or correction requests, consent changes, and privacy complaints may be directed to the Relax & Refresh Privacy Officer:
We may update this Policy as practices or legal obligations change. The effective date and version will be revised, and material changes will be communicated through an appropriate channel. A new purpose requiring consent will not be applied retroactively without the consent or authority required by law.