• Home
  • About
  • Services
    • Massages
    • Facials >
      • Hydrafacial
      • Glacial
    • Bridal
  • Gift Cards
  • Reviews
  • Contact
  • Blog
  • Terms & Conditions
  • Privacy Policy
  • Home
  • About
  • Services
    • Massages
    • Facials >
      • Hydrafacial
      • Glacial
    • Bridal
  • Gift Cards
  • Reviews
  • Contact
  • Blog
  • Terms & Conditions
  • Privacy Policy
Search by typing & pressing enter

YOUR CART

Privacy Policy
Effective Date: 8/4/25
Last Updated: 8/4/25

1. Introduction
At Lash and Beauty Bar (“we,” “us,” “LABB”), located in Half Moon Bay, California, we respect your privacy and are committed to protecting your personal information. This Privacy Policy describes how we collect, use, disclose, retain, and safeguard your information in compliance with California state privacy laws (CalOPPA, CCPA/CPRA, Shine‑the‑Light) and applicable federal laws.


2. Information We Collect
Personal Information we collect includes: Identifiers such as name, postal address, email, phone number, date of birth

Health-related information such as skin concerns, allergies, treatment history (medical details)

Photographs taken pre/post services for documentation or marketing (with consent)

Communications data: email open/click behavior, SMS messages, appointment confirmations

Online tracking: cookies, website analytics, IP addresses, device/browser data

Source of Collection: Directly from you (through forms, scheduling, consultations), online tracking tools, third-party service providers (e.g. booking, payment, email/SMS platforms).


3. Why We Collect & How We Use Your Information To provide and customize beauty services (eyelash extensions, facials, waxing, massage)

To process payments and manage appointments To communicate via email and SMS (confirmations, reminders, after‑care, promotional updates) — you may opt out at any time

To comply with legal obligations and ensure safety

With explicit consent, to take and use photographs for treatment records and promotional purposes


4. Legal Bases & Consent for Marketing
Email/SMS Marketing: We follow CAN‑SPAM Act and TCPA regulations—every message includes opt‑out instructions. Under CCPA/CPRA, email addresses and phone numbers are personal information subject to user rights. California minors aged 13–16 require affirmative opt‑in; under‑13 minors require parental consent.

Photo & Medical Consent: Prior to any treatment involving photographs or collection of health data, clients will sign an informed consent form. Use and retention of medical or health data adhere to HIPAA‑style safeguards (even if not formally HIPAA‑covered); such data will not be disclosed without your express authorization.


5. Sharing & Disclosure of Information
We do not sell personal information. If LABB ever engages in sharing or selling, California residents will have access to a “Do Not Sell or Share My Personal Information” link.

We may share information with service providers (e.g., booking, payment, email/SMS delivery, analytics) under contracts that require them to safeguard the data in compliance with CCPA/CPRA standards. California’s Shine‑the‑Light law disclosures: If we share personal data with third parties for their marketing, California residents may request a statement disclosing what categories of information were shared and with whom.

6. Your Rights as a California Resident

Under the CCPA and CPRA, California residents have the rights to:

Know what categories of personal and sensitive personal information we collect, sell, or share

Access the specific pieces of personal information collected

Delete personal information we hold (with exceptions)

Correct inaccurate information

Opt out of sale or sharing of personal information

Limit use of sensitive personal information (e.g. detailed health or biometric data)

Non‑discrimination if you exercise your rights
To exercise your rights, please contact us via:

Phone: 650-397-7829

Email: [email protected]  
We will respond to verifiable requests within the legally allowed timeframe (typically 45 days or less) and no more than twice per 12‑month period.


7. Retention & Security
We retain personal and health‑related information only as long as necessary to fulfill service delivery and legal obligations. Retention periods are based on operational needs and regulatory requirements.

We implement reasonable physical, technical, and administrative safeguards to protect your information.

8. CalOPPA Web Privacy Requirements
Our privacy policy is linked prominently on our website footer, booking pages, and at points of data collection. 

This policy includes the effective date and date of last revision.

Users can access and request changes to their stored personal information.

9. Specific Consent Forms
Photo Consent: Clients must sign a standalone consent form granting permission to use images for medical documentation, internal review, or marketing (with option to restrict usage).

Medical/Health Consent: Clients will acknowledge collection of health information and authorize treatment, and indicate how data may be used. Opt‑outs or restrictions must be documented.
10. Children & Minors

We do not knowingly collect data from children under 13. For minors aged 13–16, parental or guardian consent is required before receiving marketing communications. All medical and image consents for minors must be signed by a parent or legal guardian.

11. Changes to This Policy

We reserve the right to update this Privacy Policy. Any material changes will be posted here with a new effective date. Continued use of our services implies acceptance of those changes.


12. Contact Information

If you have privacy-related inquiries or wish to exercise your consumer rights, please contact us:
Email: [email protected]
Mail: Privacy Compliance Team, Lash and Beauty Bar, 270 Capistrano Way, Suite #4 Half Moon Bay, CA
Phone (toll‑free): 650-397-7829


Contact Us

270 Capistrano Rd Ste #4, Half Moon Bay, CA 94019

Phone: 650-518-6937