← Back to menu
Privacy Policy
Vitaliteit Massage
Overview
This Privacy Policy describes what personal information Vitaliteit Massage collects, why we collect it, how we use it, and the choices you have. We collect only what is necessary to operate your Booking Account and deliver the services you request.
What We Collect
- Account info — full name, email address, phone number (optional)
- Appointment records — session dates, times, services booked, attendance status, therapist notes (SOAP notes)
- Payment metadata — PayPal capture IDs, Groupon redemption codes, Diamond Gift Certificate / Membership balances. We never store credit-card numbers; all card data is handled directly by PayPal.
- TOS acceptances — date, version, IP address, and the user-agent string of the device used at the time you accepted each terms document
- Marketing preferences — whether you have opted in to promotional emails
How We Use Your Information
- To create, identify, and operate your Booking Account
- To send transactional emails (booking confirmations, OTP codes, cancellation receipts, no-show notices, balance updates)
- To deliver and improve massage services (e.g. SOAP notes help your therapist remember preferences across sessions)
- To process payments through PayPal
- To send marketing emails — only if you have opted in
- To comply with tax, accounting, and consumer-protection law
We do not sell your personal information to third parties. Ever.
Third Parties We Share With
We share information only with vendors that are essential to delivering the service:
- PayPal — payment processing. Receives your name, email, and the amount of each transaction. PayPal's own privacy policy governs how they handle that data.
- Google Firebase — hosts our website and database. Stores your account record, appointment history, and TOS acceptances. Located in Google's US data centers.
- SendGrid — delivers transactional and marketing emails. Receives your email address and the message contents.
- Google Calendar — synced for scheduling availability. Receives appointment date, time, service length, and your first name.
- Groupon — when you redeem a Groupon voucher we mark it redeemed in Groupon's merchant portal. Groupon does not receive your account data beyond what you originally gave Groupon at voucher purchase.
Data Retention
- Active account info — retained while your account is active
- Appointment + payment records — retained for 7 years to meet tax and consumer-protection record-keeping requirements
- TOS acceptances — retained indefinitely as legal evidence
- SOAP notes — retained for as long as you have an active account; deleted on account deletion unless required by law
- Marketing email logs — retained for 2 years
Your Rights
You may at any time:
- View and update your account info from /account
- Opt out of marketing emails by unchecking the preference in /account or clicking "unsubscribe" in any marketing email
- Request a copy of all data we hold about you by emailing frontdesk@vitaliteitinfo.com
- Delete your account by emailing frontdesk@vitaliteitinfo.com (appointment/payment records may be retained as required by law)
- Correct any inaccurate information we hold
Residents of states with extra privacy rights (California CCPA, Virginia VCDPA, Colorado CPA, etc.) may exercise those rights using the same email address.
Security
Your account is protected by one-time email codes (OTP) — we never store passwords by default. Connections to our website use HTTPS. Database access is restricted to Vitaliteit Massage staff and is logged. PayPal handles all payment-card data and is PCI-DSS compliant.
No system is perfectly secure. If we detect a breach affecting your account we will notify you by email within 72 hours and report it to relevant regulators as required.
Cookies & Local Storage
Our website uses local storage (not cookies) to keep you signed in to /account after a successful OTP. We do not use third-party tracking cookies, pixels, or advertising trackers. PayPal's checkout iframe may set its own cookies when you complete a payment — those are governed by PayPal's privacy policy.
Children
Vitaliteit Booking Accounts are for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, email frontdesk@vitaliteitinfo.com and we will delete the account.
Changes to This Policy
We may update this Privacy Policy. Material changes will be surfaced at your next booking — you'll be asked to review and re-accept the updated version. Past acceptances are preserved with their version number and date.
Last updated: 2026-05-23 (v1 — initial release)