top of page

Maya Laser Spa

PRIVACY POLICY

A LEGAL DISCLAIMER

This Privacy Policy outlines the data and privacy practices of  Maya Laser Spa,   “we,” “us,” or “our”) across our digital platforms—including MayaLaserSpa.com—and in our physical spa locations. It applies to all services, features, and experiences we offer that reference or link to this policy (collectively, the “Services”).

By accessing or using our Services, you agree to the terms of this Privacy Policy and our Terms and Conditions. Any consumer health data we collect is governed by our Consumer Health Data Notice, where applicable.

📑 Table of Contents

PRIVACY POLICY - THE BASICS

  1. Personal, Sensitive, and Non-Personal Data We Collect and How We Use and Disclose It

  2. Additional Details About Our Data Practices

  3. Third-Party Advertising, Analytics & Privacy Controls

  4. Loyalty & Referral Program Disclosures

  5. Your Choices

  6. Data Security

  7. Third-Party Content and Links

  8. Consent to International Data Transfer

  9. Services Intended for General Audiences

  10. Changes to This Privacy Policy

  11. How to Contact Us

  12. U.S. State-Specific Rights

WHAT TO INCLUDE IN THE PRIVACY POLICY

Personal, Sensitive, and Non-Personal Data We Collect and How We Use and Disclose It

We collect data in three primary ways:

  • Directly from you (e.g., appointment bookings, intake forms, consultations)

  • Automatically through your interaction with our website and digital platforms

  • From third-party sources (e.g., marketing partners, analytics providers)

We treat your data with the same care and discretion we bring to every treatment. Some of this data may be classified as “personal information,” “personal data,” or “sensitive data” under applicable laws. We treat IP addresses, device identifiers, and cookie data as personal data where required.

We may de-identify or pseudonymize personal data to make it non-personal—for example, by aggregating it or hashing identifiers. We do not attempt to re-identify de-identified data unless permitted by law. If non-personal data is combined with personal data, we treat the result as personal data.

📊 Data Categories Overview

 

Contact Information (e.g., name, email, phone)Appointment scheduling, client communication, 

Health & Treatment Data Service customization, safety, compliance Licensed professionals, EMR systems Not sold/shared

Payment Information Transaction processing Payment processors Not sold/shared

Device & Usage Data Site optimization, analytics Analytics providers May be shared for advertising

Loyalty Program Data Rewards tracking, promotions Program administrators Not sold/shared

Would you like me to continue with the rest of the sections using this pink-accented style? I can also help you apply it to your intake forms, service menus, or website copy for a cohesive brand experience.

2- Additional Details About Our Data Practices

We may use your data to:

  • Provide and personalize treatments

  • Improve our Services and client experience

  • Communicate promotions, updates, and appointment reminders

  • Comply with legal and regulatory obligations

We never use your data in ways that compromise your trust. We retain data only as long as necessary for the purposes described, or as required by law

3. Third-Party Advertising, Analytics & Privacy Controls

We may partner with third-party platforms to deliver relevant ads and measure performance. These partners may use cookies, device identifiers, and browsing data.

You can manage your preferences through:

  • Browser settings

  • “Do Not Track” signals

  • Opt-out links provided in our communications

Your privacy preferences are always respected

 

1. Personal, Sensitive, and Non Personal Data We Collect and How We Use and Disclose It

 

We collect data about users of the Services directly, automatically when you visit the Services, and sometimes from third parties. Some of this data may be considered “personal information” or “personal data”, and some of which may be considered “sensitive”, under various applicable laws. We will also treat other information, including IP addresses and cookie identifiers, as “personal data” where required by applicable law and we will treat certain personal data as “sensitive data” as required by applicable law.

Note that we may de-identify or pseudonymize personal data so that it is non-personal, such as aggregating (such as combining it with data about other individuals) and/or or converting it to a code, sometimes using a function commonly known as “hash”, or otherwise removing characteristics that make the data personally identifiable to you. We maintain and use de-identified data without attempting to re-identify it, except where permitted by applicable law, such as to determine whether
our de-identification processes satisfy legal requirements. We will treat de-identified or pseudonymized data as non-personal to the fullest extent allowed by applicable law. If we combine non-personal data with personal data, then we will treat the combined information as personal data under this Privacy Policy.

The following chart sets out by category the personal data collected (“Category”), the purposes for which the information is collected (“A. Purposes”), the categories of third parties to whom the information may be disclosed for a business purpose (“B. Disclosed To”), and the categories of third parties to whom the information may be sold for monetary value or other valuable consideration or shared for cross contextual behavioral advertising/targeted marketing (“C. Sold/Shared To”)

5. Your Choices

You have the right to:

  • Access or correct your personal data

  • Opt out of marketing communications

  • Request deletion of your data (subject to legal exceptions)

We honor your choices with grace and transparency.

6. Data Security

We implement industry-standard safeguards to protect your data, including:

  • Encryption

  • Secure servers

  • Access controls

While no system is flawless, we continuously monitor and improve our security practices.

 

7. Third-Party Content and Links

Our Services may include links to third-party websites or content. We are not responsible for their privacy practices. We recommend reviewing their policies before

8. Consent to International Data Transfer

If you access our Services from outside the U.S., your data may be transferred to and processed in the U.S. By using our Services, you consent to this transfer.

 

9. Services Intended for General Audiences

Our Services are not intended for children under 13. We do not knowingly collect personal data from minors without parental consent.

 

10. Changes to This Privacy Policy

We may update this policy from time to time. Changes will be posted with a revised effective date. We encourage you to review it periodically.

We’ll always keep you informed—because trust is timeless.

11. How to Contact Us

For questions or concerns about this Privacy Policy or your data, please contact:
Maya Laser Spa, LLC
📍 Irvine, CA
📧elayyannadia@gmail.com
📞 949-378-7634

 

12. U.S. State-Specific Rights

Depending on your state of residence, you may have additional rights under applicable privacy laws. We honor these rights and provide mechanisms for exercising them.

 

 

.

bottom of page