Privacy Policy
Last updated: April 5, 2026
1. Who We Are
PSRx Body & Skin (“PSRx,” “we,” “us,” or “our”) operates the website psrxbodyandskin.com, the PSRx Skin Intelligence Member Portal, our online shop, and all associated booking and membership services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information across all of these platforms.
2. Information We Collect
Depending on which services you use, we may collect the following categories of information:
Personal Identifiers
- Full name, email address, phone number, date of birth
- Billing and shipping address (for shop orders)
- Profile photo (if provided via social login)
Health & Wellness Information (Member Portal)
- Skin concerns, skin type, treatment goals
- Health history and lifestyle assessment responses
- AI-generated skincare protocols and recommendations
- Check-in responses and progress tracking data
- Booking history and appointment notes
- Tattoo and skin images submitted for AI analysis
Account & Subscription Information
- Membership tier (Founding or Standard), subscription status, and billing dates
- Recharge subscription ID and customer ID
- Consent records (Terms of Service, AI disclosure, health acknowledgment, communication consent)
- Login method (email OTP, Google, or Facebook)
- Social login provider ID and access tokens (used only to maintain your session)
- Google Calendar integration status
Payment Information
- Transactions are processed securely by Shopify, Recharge, and Cherry Financing
- We do not store credit card numbers, CVV codes, or bank account details
- Order totals, items purchased, and fulfillment status are retained for service delivery
Usage & Technical Data
- Pages visited, time on site, clicks, and session duration
- Browser type, device type, operating system, IP address
- Referral source and UTM parameters
- Feature usage within the Member Portal
Marketing & Communication Data
- Email engagement (opens, clicks) via Klaviyo and Brevo
- SMS opt-in status and preferences
- Referral codes and gift card redemptions
- Lead form submissions (consultations, skin assessments, contact forms)
3. How We Use Your Information
- Service delivery: process bookings, manage subscriptions, fulfill shop orders, and grant access to the Member Portal
- AI-assisted care: generate personalized skincare protocols, analyze skin images, and provide clinical team recommendations using Anthropic's Claude AI
- Communications: send appointment confirmations, OTP login codes, protocol updates, booking reminders, and membership notifications via email
- Marketing: send promotional emails and SMS messages to opted-in contacts; create custom and lookalike audiences on Meta for advertising
- Analytics: understand how visitors use our website and portal to improve features and content
- Conversion tracking: report purchase and membership events to Meta via the Conversions API to measure ad effectiveness (data is hashed before transmission)
- Calendar integration: push booking appointments to your Google Calendar if you enable this feature
- Financing: facilitate Cherry patient financing applications for eligible services
- Compliance: maintain consent logs, fulfill legal obligations, and prevent fraud
4. Social Login (Google & Facebook)
You may choose to sign in to the Member Portal using your Google or Facebook account. When you do:
- We receive your name, email address, and profile photo from the selected provider
- We store a provider ID and access token to maintain your session — we do not receive your social media password
- If you use Facebook Login, we may match your account with Meta's advertising platform to improve ad targeting (your data is hashed with SHA-256 before any transmission)
- If you use Google Login, you may optionally enable Google Calendar sync for appointment reminders
You can revoke access to PSRx from your Google or Facebook account settings at any time. Revoking access will not automatically delete your PSRx account — contact us to request full data deletion.
5. Third-Party Services
We share data with the following third-party service providers as necessary to operate our business. Each provider has its own privacy policy.
- Google — social login (OAuth), Google Calendar API, Google Analytics
- Meta (Facebook/Instagram) — social login (OAuth), Meta Conversions API, Meta Ads Manager, Instagram content integration
- Shopify — e-commerce platform, product and order management
- Recharge — recurring subscription billing and management
- Cherry — patient financing for aesthetic services
- Brevo — transactional email delivery (OTP codes, booking confirmations)
- Klaviyo — email and SMS marketing automation
- Supabase — secure cloud database hosting (PostgreSQL)
- PostHog — product and website analytics (self-hosted proxy)
- Anthropic (Claude AI) — AI-assisted skincare protocol generation and tattoo/skin image analysis
- Vercel — website and portal hosting infrastructure
We do not sell your personal information to third parties.
6. Meta Conversions API & Advertising
We use the Meta Conversions API to share certain events (such as new memberships and cancellations) with Meta to measure the effectiveness of our advertising campaigns. Before any data is sent to Meta:
- Personal identifiers such as email address and phone number are hashed using SHA-256 encryption
- No raw personal data is transmitted to Meta
- This data may be used by Meta to match events to Meta users for ad attribution and lookalike audience creation
You can opt out of Meta's use of your data for advertising by visiting your Facebook Ad Preferences.
7. Cookies & Tracking Technologies
We use the following types of cookies and tracking tools:
- Session cookies: required for Member Portal login and navigation — cannot be disabled without losing portal access
- Analytics cookies: PostHog collects anonymous usage data routed through our own server (no direct third-party cookie)
- Marketing pixels: Meta Pixel may be active on public pages to track conversions from ad campaigns
You can manage cookie preferences through your browser settings. Blocking all cookies will prevent access to the Member Portal.
8. Data Retention
- Active accounts: retained for the life of your membership
- Health & assessment data: minimum 3 years to support continuity of care
- Consent records: retained permanently for legal compliance
- Cancelled accounts: anonymized after 24 months unless a deletion request is submitted
- Marketing data: removed within 30 days of unsubscribe request
9. Your Rights
You have the following rights regarding your personal information:
- Access: request a copy of the data we hold about you
- Correction: update inaccurate or incomplete information
- Deletion: request removal of your data (see Section 10)
- Portability: receive your data in a machine-readable format
- Opt-out: unsubscribe from marketing emails or SMS at any time via the link in any message
- Restrict processing: object to certain uses of your data
To exercise any of these rights, contact us at info@psrxbodyandskin.com.
10. Data Deletion
You have the right to request deletion of your personal data at any time. To submit a deletion request:
- Email info@psrxbodyandskin.com with the subject line “Data Deletion Request”
- Include the email address associated with your PSRx account
- We will confirm receipt within 2 business days and complete deletion within 30 days
Upon deletion we will remove your profile, assessment data, portal session, and marketing records. The following may be retained where required by law: transaction records, consent logs, and anonymized usage statistics.
Cancellation note: Deleting your data will immediately terminate access to the Member Portal and forfeit any remaining subscription period. We recommend cancelling your subscription through Recharge first.
Facebook / Meta users: If you signed in with Facebook and wish to have your data removed from our systems, you may also submit a request directly through Facebook at facebook.com/help/contact/540977946302970.
11. Data Security
We implement industry-standard security measures to protect your information:
- All data is transmitted over HTTPS/TLS encryption
- The Member Portal uses httpOnly session cookies to prevent client-side access
- Database access is restricted to server-side service role keys — never exposed to the browser
- Health and assessment data is stored in a private Supabase database with row-level security
- OTP login codes expire within 10 minutes and are single-use
- Social login tokens are encrypted at rest
No method of electronic transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately.
12. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has submitted information through our services, contact us immediately and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, technology, or legal requirements. We will notify members of material changes by email and by updating the “Last updated” date at the top of this page. Continued use of our services after changes constitutes acceptance of the revised policy.
14. Contact Us
For questions, data requests, or concerns about this Privacy Policy:
PSRx Body & Skin
Email: info@psrxbodyandskin.com
Website: psrxbodyandskin.com