← Back to menu

Privacy Policy

Vitaliteit Massage

Overview

Version 3 — in force from 2 September 2026. We ask you to sign this policy alongside our Terms of Service, so your record shows you were given both. Signing acknowledges that you have read it; it is not consent to anything beyond what is described here.

This Privacy Policy describes what personal information Vitaliteit Massage collects, why we collect it, how we use it, and the choices you have. We collect only what is necessary to operate your Booking Account and deliver the services you request.

What We Collect

How We Use Your Information

We do not sell your personal information to third parties. Ever.

How marketing email actually works. We would rather describe this accurately than claim more than we do. The promotional-email box on the Booking Account sign-up screen is unticked by default — leave it alone and we will only email you about your own appointments and account. Some older accounts, and accounts we created for you (for example when someone bought you a gift), were set up before that and may still be marked as opted in; you can see and change your setting at any time at /account. A one-off complimentary offer sent by the owner by hand can reach you even if you have opted out, and if you are not a client of ours at all, sending you that offer creates a client record for you — your email address, whatever name the owner entered, and a marketing preference recorded as not opted in and labelled with where it came from, none of which you gave us. Every promotional email carries a working one-click unsubscribe link. Transactional emails — confirmations, one-time codes, receipts, account notices — are not affected by this preference, because they are needed to run your account.

Third Parties We Share With

We use these vendors to deliver the service:

Sharing is not limited to vendors — some features show one client something about another:

We have no next-of-kin or executor process for account access. There is no path in the system for a family member, executor, or legal representative to be given access to your account or your treatment records. We release records to you, or where the law requires us to. Money is handled separately and by hand: Section 9 of our Terms of Service lets an executor or authorised representative, on written request with documentation, have the unredeemed balance on the account transferred to a named person or refunded.

Data Retention

To be accurate about the mechanism: a nightly job removes only short-lived records — one-time codes, /account session tokens, trusted-device tokens, the one-tap sign-in links in our emails, emailed payment links, rate-limit counters, in-clinic intake tokens, the short-lived holds placed on a time slot while someone is part-way through booking, extending or rescheduling a session, and the older gift store described above. A slot hold records the IP address of the browser that placed it, and for some kinds the email address of the person booking; the hold itself lapses within half an hour and the record is deleted 24 hours after it was made. Nothing else is deleted automatically. No scheduled job erases appointment, payment, or treatment records when a retention period ends — that removal is done by hand on review, or when you ask us for it. You can request erasure at any time using the address below.

Your Rights

You may at any time:

Residents of states with extra privacy rights (California CCPA, Virginia VCDPA, Colorado CPA, etc.) may exercise those rights using the same email address.

Security

There are four ways into a Booking Account, and your account may have any or all of them:

One more link, which is not a way into your account. Every confirmation and reminder email also carries a link to a page for that one appointment. It shows that session's date, time and length and the name it was booked under, and it lets you cancel or reschedule that one appointment after you confirm the email address it was sent to. It cannot see your balances, your other appointments or your purchase history, and it cannot change anything else on your account. Unlike the one-tap sign-in link above it carries no expiry: it keeps working for as long as that appointment stands, and afterwards it can still show that appointment's details, though a session that has already taken place can no longer be cancelled through it. Anyone who can read that mailbox can open it, so what we said above about a shared email address applies here too.

One more link, which is not a way into your account. Booking confirmations, reschedule confirmations and reminders all carry a link to a page for that one appointment, and reminders additionally carry one-click Confirm and Cancel links built on the same token. Opening that page shows the session's date, time and length, the name it was booked under, how it is being paid for — a membership Cover Charge, Diamond Gift Certificates, a Groupon, or at the appointment — and the credits held against it. The one-click Confirm and Cancel links ask for nothing further at all: two clicks from the mailbox confirm or cancel the appointment. Cancelling or rescheduling from the page itself first asks you to confirm the email address it was sent to. Either route can move credits: cancelling or moving a session within 72 hours of its start can forfeit a Cover Charge or a certificate, and moving one into that window needs a Holder Credit, which the page will spend once you agree. In the course of that the page may tell you how many Holder Credits you hold, or that a certificate or Cover Charge balance has run out. It does not show your other appointments or your purchase history, and it cannot transfer credits to anyone else, change your password or email address, or close your account. Unlike the one-tap sign-in link above it carries no expiry: it keeps working for as long as that appointment stands, and afterwards it can still show that appointment's details, though a session that has already taken place can no longer be cancelled through it. Anyone who can read that mailbox can do all of this, so what we said above about a shared email address applies here too.

Connections to our website use HTTPS and are pinned to HTTPS by a strict-transport header. Database access is closed by default: the clinic owner's account is the only one that can read the database as a whole. The rules do also let a browser signed in to Firebase with a verified email address matching yours read its own appointment, client, credit-ledger and transfer records, and correct its own name, phone and account identifier — and nothing else. In practice signing in to your Booking Account creates no Firebase login at all; every client action runs through our server. Sensitive owner actions — credit adjustments, manual bookings, transfer reversals, gift resends — are written to an audit log; we do not log every read of the database, so we cannot claim a complete access trail. PayPal handles all payment-card data and is PCI-DSS compliant.

No system is perfectly secure, and we do not run automated breach-detection software. If we become aware of a breach affecting your account we will notify you by email within 72 hours of discovering it and report it to the relevant regulators as required.

Cookies & Local Storage

We set exactly one cookie of our own: a first-party “__session” cookie carrying the random 30-day “trust this device” token. It is set only if you tick that box, and it is HttpOnly (scripts cannot read it), Secure (HTTPS only) and SameSite=Lax (not sent to other sites). If you never tick that box, we set no cookie at all.

We also use your browser's own storage. An earlier version of this policy said these hold “only a random token” and are “set only after you sign in.” Neither was true, so here is the full list for a client's browser (the clinic owner's own browser additionally stores an admin device-trust token, its expiry date, and a marker for which system notifications she has already read; none of those hold anything about you):

We run no analytics, no advertising trackers and no pixels of our own, and we set no tracking cookies of our own. We do load a few things from other companies' servers, and each of those companies can see your IP address and browser details as the page loads and may set its own cookies, governed by its own privacy policy rather than ours: PayPal's checkout script and payment window load from paypal.com; our pages load fonts from Google's font servers; the signature pad on our booking, checkout, gift-claim, membership sign-up and account pages loads from jsDelivr; and our contact page embeds a live map from Google Maps. All four are listed under Third Parties We Share With above. Beyond what PayPal needs in order to take a payment, none of them receives account data from us.

Children

Vitaliteit Booking Accounts are for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, email frontdesk@vitaliteitinfo.com and we will close the account and delete it by hand — no part of the system deletes an account on its own. If a session has already taken place, the treatment record for that session is subject to the seven-year retention rule above.

Changes to This Policy

We may update this Privacy Policy. Material changes will be surfaced at your next booking — you'll be asked to review and re-accept the updated version. Past acceptances are preserved with their version number and date.

Contact

Questions about privacy? Write to frontdesk@vitaliteitinfo.com.

Last updated: 2026-09-06 (v3 — fourth sign-in path disclosed: the one-tap link in reminder emails, and what it means for a shared mailbox; one-time code storage described precisely; the client-side self-cancellation database permission was removed, so this policy no longer claims it; the executor position now points at Section 9 of the Terms; the per-appointment link in confirmation and reminder emails is now described — that it carries no expiry, that the one-click Confirm and Cancel links in reminders need no further check, and that cancelling or rescheduling through it can forfeit or spend credits; two third-party services that load on our pages are now disclosed — jsDelivr, which serves the on-screen signature pad, and the Google Maps embed on the contact page)