← Back to menu
Privacy Policy
Vitaliteit Massage
Overview
Version 3 — in force from 2 September 2026. We ask you to sign this policy alongside our Terms of Service, so your record shows you were given both. Signing acknowledges that you have read it; it is not consent to anything beyond what is described here.
This Privacy Policy describes what personal information Vitaliteit Massage collects, why we collect it, how we use it, and the choices you have. We collect only what is necessary to operate your Booking Account and deliver the services you request.
What We Collect
- Account info — full name, email address, phone number, any additional email addresses you add as aliases, the Client ID we assign to your account, and the year you were born. Utah requires us to record your birth year on your intake form, and we do not treat clients under 18. We may ask to see photo ID at the clinic to confirm your age — we look at it and hand it back, and never photograph, scan or keep a copy.
- Appointment records — session dates, times, services booked, treatment upgrades requested, attendance and check-in status, cancellation and no-show history, and therapist notes (SOAP notes: subjective, objective, assessment, plan, and a long-form narrative)
- Health information — collected through our annual and per-session intake forms: allergies, current medications, major medical history, recent surgeries or injuries and whether an injury is recent or still healing, pain and pressure levels, pregnancy, whether you are currently under a doctor’s care, whether you are coming to us for a specific health issue, draping preference, and any condition you tell us is relevant to your care. We collect this so your therapist can work safely. It is used for your treatment, is never used for marketing, and is never shared for advertising.
- Consent records and your signature — your signed intake consents and any separate breast-draping waiver, together with the date signed. Each intake form, each waiver, and every terms document you accept stores the handwritten signature image you draw on screen as a picture kept with that record. The draping waiver is stored with its own separate signature image.
- Payment metadata — PayPal order and capture IDs, the payer name and email address PayPal returns to us, the amount of each transaction, and Groupon redemption codes. We never store credit-card numbers; all card data is handled directly by PayPal.
- Credit balances — your account carries several separate balances, and for each we keep the running total, the lifetime purchased and used counts, and the pack-by-pack purchase history: Diamond Gift Certificates (DGCs), membership session cover charges, Treatment Upgrade credits, Holder Credits, gratuity credits, membership years, and any Groupon voucher you have redeemed.
- TOS acceptances — date, version, IP address, and the user-agent string of the device used at the time you accepted each terms document
- Account activity feed — account events (bookings confirmed, credits granted, transfers sent and received, gifts claimed) are stored as a per-account history and shown to you in the Notifications tab of your /account dashboard, most recent 50 first, with a badge for anything you have not read yet. The same history is stored against your account in our database and the clinic owner can read it. The feed is filed under your phone number; if you change your number we move it across, and if that move does not complete we are alerted and finish it by hand.
- Marketing preferences — whether you receive promotional emails, the date that preference was set and where it came from, and a random unsubscribe token tied to your account
- Information about other people that you give us — your intake form asks for an emergency contact, and we store that person’s name and phone number. We use it only if something goes wrong during a session; we never contact them otherwise and never market to them. Separately, when you buy a gift, book a session for someone else, or transfer credits, we store the name and email address of the person you name — and, for gifts and for sessions you book for someone else, their phone number too — even before that person is a client of ours. The same applies in reverse: if someone buys you a gift or books a session for you, their name and email are stored against that record.
- Technical data — your IP address and browser user-agent, used to rate-limit sign-in codes and block abuse. Rate-limit counters store only a one-way hash of the identifier, not the address itself.
How We Use Your Information
- To create, identify, and operate your Booking Account
- To send transactional emails (booking confirmations, OTP codes, cancellation receipts, no-show notices, balance updates)
- To deliver and improve massage services (e.g. SOAP notes help your therapist remember preferences across sessions)
- To process payments through PayPal
- To send occasional promotional emails — see How marketing email actually works below
- To comply with tax, accounting, and consumer-protection law
We do not sell your personal information to third parties. Ever.
How marketing email actually works. We would rather describe this accurately than claim more than we do. The promotional-email box on the Booking Account sign-up screen is unticked by default — leave it alone and we will only email you about your own appointments and account. Some older accounts, and accounts we created for you (for example when someone bought you a gift), were set up before that and may still be marked as opted in; you can see and change your setting at any time at /account. A one-off complimentary offer sent by the owner by hand can reach you even if you have opted out, and if you are not a client of ours at all, sending you that offer creates a client record for you — your email address, whatever name the owner entered, and a marketing preference recorded as not opted in and labelled with where it came from, none of which you gave us. Every promotional email carries a working one-click unsubscribe link. Transactional emails — confirmations, one-time codes, receipts, account notices — are not affected by this preference, because they are needed to run your account.
Third Parties We Share With
We use these vendors to deliver the service:
- PayPal — payment processing. Receives your name, email, and the amount of each transaction. PayPal's own privacy policy governs how they handle that data.
- Google Firebase / Google Cloud — hosts our website, database, and backend. Stores your account record, appointment history, treatment records, signature images, and TOS acceptances. Located in Google's US data centers.
- SendGrid — delivers transactional and marketing emails. Receives your email address and the message contents. SendGrid keeps its own delivery records under SendGrid's retention policy, not ours.
- Google Calendar — the owner's working calendar, used for scheduling and availability. Every booking writes an event to it. Correcting an earlier version of this policy: the event does not carry only your first name. It carries the date, time and session length, whether the session is a membership session, and your full name. Depending on how the booking was made, the event description may also carry your email address, how the session was paid for (DGC, Groupon, member, waitlist, comped), the appointment or holder reference, and any private note the owner added when creating the appointment. The calendar belongs to the clinic owner's own Google account and is not published.
- Groupon — when you redeem a Groupon voucher we mark it redeemed in Groupon's merchant portal. Groupon does not receive your account data beyond what you originally gave Groupon at voucher purchase.
- Google Fonts — our pages load typefaces from Google's font servers, so your IP address and browser details are visible to Google when a page loads. No account data is sent.
- Google Maps — our contact page embeds a live map of the clinic, loaded from Google's map servers. Google sees your IP address and browser details when that page opens, and may set its own cookies. No account data is sent. Our other pages only link out to Google Maps, which sends Google nothing unless you click the link.
- jsDelivr — a public code CDN. The on-screen signature pad is a small JavaScript library your browser fetches from cdn.jsdelivr.net rather than from us, and it then runs on the page. It loads on the booking page (/book), the checkout page (/checkout), the gift-claim page (/claim), the membership sign-up page (/member-signup) and your account dashboard (/account and /account-app). jsDelivr sees your IP address and browser details when it serves that file, and receives no account data. It is pinned to a fixed version and checked against an integrity hash, so a file that had been altered would be refused by your browser. The confetti animation used to be fetched from this CDN too; since 17 September 2026 we serve it ourselves, so it reaches no third party.
Sharing is not limited to vendors — some features show one client something about another:
- Gifts. The buyer supplies the recipient's name and email address. When the gift is claimed, the buyer is emailed and told the name (or email address) of the person who claimed it. The person claiming a gift is told the buyer's name or email, and it appears on their credit history as “gift from …”. If a gift goes unclaimed, the buyer is reminded and the recipient is named in that reminder.
- Balance transfers. To send credits you enter the recipient's email address or Client ID. Your receipt names the recipient and shows their email address, and the recipient is emailed your name. If a transfer is refused, the message you see may reveal how many of that credit type the recipient already holds, or that their account is restricted. Both sides are emailed unless they have switched account emails off, and the transfer is recorded against both accounts.
- Booking for someone else. The booker supplies the attendee's name, email and phone number, and receives a receipt naming the attendee. The booker also chooses whether the attendee is emailed a confirmation.
- Membership companion. A member names their companion by email address, and that person must already have a Vitaliteit account of their own — the message the member sees can reveal whether that address has an account with us, whether that account is closed, and whether that person already holds a membership of their own. The invitation is emailed to the companion and names the member, unless they have switched account emails off. From then on each of you sees the other's email address in the Membership Companion section of your account page, and the account notices that open and accept the link name the other person. Gratuity Rewards earned on the companion's purchases are added to the member's rewards balance rather than the companion's, so the member's balance can rise because of something their companion bought. Either of you can end the link at any time, and when an accepted link ends the other person is told on their account.
We have no next-of-kin or executor process for account access. There is no path in the system for a family member, executor, or legal representative to be given access to your account or your treatment records. We release records to you, or where the law requires us to. Money is handled separately and by hand: Section 9 of our Terms of Service lets an executor or authorised representative, on written request with documentation, have the unredeemed balance on the account transferred to a named person or refunded.
Data Retention
- Active account info — retained while your account is open
- A closed account — closing your account does not delete it. Refundable balances are zeroed and paid out, and the account is flagged closed. Credits you did not pay for yourself — ones claimed from a gift, or transferred to you by someone else — and your gratuity and reward balances are cleared without payment, because they were never money you put in. Everything else — your client record, Client ID, appointment history, treatment records, consents and signatures — is retained, and the treatment records stay for the seven-year period below. There is no close button on the site today: you ask us by email, we work out any refund due on unused credits and pay it by hand, and the owner then marks the account closed. You can ask us to re-open a closed account at any time; your history and Client ID come back with it.
- Appointment + payment records — retained for 7 years to meet tax and consumer-protection record-keeping requirements, and removed after that on review
- Treatment records — intake forms, consents, the signature images captured on them, and SOAP notes are retained for seven years, as required for health-care records, and are removed after that on review. Closing your account deactivates it but does not erase these records.
- TOS acceptances — the record of each terms acceptance, and the signature captured with it, are retained indefinitely as legal evidence. Accepting a newer version preserves the previous signature alongside the new one.
- Sign-in material — one-time codes are deleted after 24 hours, /account session tokens after 2 days, and 30-day trusted-device tokens after 31 days. Rate-limit counters are deleted after 2 days and in-clinic intake tokens after 6 hours. The one-tap sign-in links in our emails stop working after 4 days, or when the appointment the email was about ends, whichever comes first; the link record itself is deleted 8 days after it was created.
- Gift purchase records — correcting an earlier version of this policy: these are not deleted 90 days after purchase. The nightly job clears only an older gift store that the gift checkout on the site no longer writes to, so a gift bought today is never deleted automatically: unclaimed, claimed or cancelled, the record is kept until we remove it by hand, and with it the buyer's and recipient's details, and those of whoever claimed the gift. Emailed payment links carry their own expiry: an offer link sent after a session expires in 14 days, a complimentary-offer link in 30 days, and a link for a session being held for you in 30 minutes. The link records themselves are deleted 30 days after they are created, so a complimentary-offer link expires and is cleared at about the same time
- Marketing email delivery records — we keep no log of our own marketing sends. Delivery data lives with SendGrid under SendGrid's retention policy. What we hold is your preference, the date it was set, and where it came from.
To be accurate about the mechanism: a nightly job removes only short-lived records — one-time codes, /account session tokens, trusted-device tokens, the one-tap sign-in links in our emails, emailed payment links, rate-limit counters, in-clinic intake tokens, the short-lived holds placed on a time slot while someone is part-way through booking, extending or rescheduling a session, and the older gift store described above. A slot hold records the IP address of the browser that placed it, and for some kinds the email address of the person booking; the hold itself lapses within half an hour and the record is deleted 24 hours after it was made. Nothing else is deleted automatically. No scheduled job erases appointment, payment, or treatment records when a retention period ends — that removal is done by hand on review, or when you ask us for it. You can request erasure at any time using the address below.
Your Rights
You may at any time:
- View and update your account info from /account
- Turn promotional emails off (or back on) from /account, or by clicking “unsubscribe” in any marketing email
- Request a copy of all data we hold about you by emailing frontdesk@vitaliteitinfo.com
- Ask us to close your account by emailing frontdesk@vitaliteitinfo.com — there is no self-serve close button on the site today. We quote what is owed on your unused credits and the owner pays it out by hand; closing deactivates the account rather than deleting it, and the retention rules above still apply
- Ask us to erase your data by emailing frontdesk@vitaliteitinfo.com (appointment, payment and treatment records may be retained as required by law)
- Correct any inaccurate information we hold
Residents of states with extra privacy rights (California CCPA, Virginia VCDPA, Colorado CPA, etc.) may exercise those rights using the same email address.
Security
There are four ways into a Booking Account, and your account may have any or all of them:
- A one-time code emailed to you — the default. Codes are six digits, single-use, and short-lived: they expire in ten minutes and the record is deleted within 24 hours. We store only a hash of the code, never the digits themselves. Guesses are capped per code, per email address, and per IP address.
- A password — only if you chose to set one. Setting a password switches your account to password sign-in in the same step, so from that moment it is a second working way into your account; removing it switches you back. The emailed one-time code keeps working either way — it is never gated on your sign-in method, so setting a password can never lock you out. Passwords are stored only as a bcrypt hash and never in readable form.
- A trusted device — only if you ticked “trust this device.” That browser then holds a random token that signs you in for up to 30 days without a code. The server keeps only a hash of it. Signing out, or changing your sign-in credentials, revokes it.
- A one-tap link in one of our emails — appointment reminders and “something needs you” notices carry a personal sign-in link so you do not have to fetch a code to act on them. It works once, and expires when the appointment it was sent about ends, or after four days, whichever comes first; a notice that is not about a particular appointment takes the four days. The server keeps only a hash of it, and changing your sign-in credentials revokes any outstanding links along with your other sessions. It is deliberately weaker than signing in: it opens your account and lets you confirm, reschedule or cancel a session, but it cannot move credits to another person, change your password or email address, or close your account — those still ask you to sign in properly. Please understand what this means: while the link is live, anyone who can read that mailbox can open your account and see your name, phone number, balances, purchase history and appointments. If your email is shared, or you would rather not have these links sent at all, switch off account emails altogether using the master switch in the notification settings on your account page — turning off only the appointment-reminder category still leaves a link in our “something needs you” notices.
One more link, which is not a way into your account. Every confirmation and reminder email also carries a link to a page for that one appointment. It shows that session's date, time and length and the name it was booked under, and it lets you cancel or reschedule that one appointment after you confirm the email address it was sent to. It cannot see your balances, your other appointments or your purchase history, and it cannot change anything else on your account. Unlike the one-tap sign-in link above it carries no expiry: it keeps working for as long as that appointment stands, and afterwards it can still show that appointment's details, though a session that has already taken place can no longer be cancelled through it. Anyone who can read that mailbox can open it, so what we said above about a shared email address applies here too.
One more link, which is not a way into your account. Booking confirmations, reschedule confirmations and reminders all carry a link to a page for that one appointment, and reminders additionally carry one-click Confirm and Cancel links built on the same token. Opening that page shows the session's date, time and length, the name it was booked under, how it is being paid for — a membership Cover Charge, Diamond Gift Certificates, a Groupon, or at the appointment — and the credits held against it. The one-click Confirm and Cancel links ask for nothing further at all: two clicks from the mailbox confirm or cancel the appointment. Cancelling or rescheduling from the page itself first asks you to confirm the email address it was sent to. Either route can move credits: cancelling or moving a session within 72 hours of its start can forfeit a Cover Charge or a certificate, and moving one into that window needs a Holder Credit, which the page will spend once you agree. In the course of that the page may tell you how many Holder Credits you hold, or that a certificate or Cover Charge balance has run out. It does not show your other appointments or your purchase history, and it cannot transfer credits to anyone else, change your password or email address, or close your account. Unlike the one-tap sign-in link above it carries no expiry: it keeps working for as long as that appointment stands, and afterwards it can still show that appointment's details, though a session that has already taken place can no longer be cancelled through it. Anyone who can read that mailbox can do all of this, so what we said above about a shared email address applies here too.
Connections to our website use HTTPS and are pinned to HTTPS by a strict-transport header. Database access is closed by default: the clinic owner's account is the only one that can read the database as a whole. The rules do also let a browser signed in to Firebase with a verified email address matching yours read its own appointment, client, credit-ledger and transfer records, and correct its own name, phone and account identifier — and nothing else. In practice signing in to your Booking Account creates no Firebase login at all; every client action runs through our server. Sensitive owner actions — credit adjustments, manual bookings, transfer reversals, gift resends — are written to an audit log; we do not log every read of the database, so we cannot claim a complete access trail. PayPal handles all payment-card data and is PCI-DSS compliant.
No system is perfectly secure, and we do not run automated breach-detection software. If we become aware of a breach affecting your account we will notify you by email within 72 hours of discovering it and report it to the relevant regulators as required.
Cookies & Local Storage
We set exactly one cookie of our own: a first-party “__session” cookie carrying the random 30-day “trust this device” token. It is set only if you tick that box, and it is HttpOnly (scripts cannot read it), Secure (HTTPS only) and SameSite=Lax (not sent to other sites). If you never tick that box, we set no cookie at all.
We also use your browser's own storage. An earlier version of this policy said these hold “only a random token” and are “set only after you sign in.” Neither was true, so here is the full list for a client's browser (the clinic owner's own browser additionally stores an admin device-trust token, its expiry date, and a marker for which system notifications she has already read; none of those hold anything about you):
- Local storage — 30-day sign-in token. The same random trust-this-device token and its expiry date, kept alongside the cookie. Set only if you tick that box; removed when you sign out.
- Session storage — /account session. A random token that keeps you signed in for the current browser tab. Set when you sign in; gone when the tab closes.
- Session storage — booking pre-fill. Set when you click through from /account to the booking page. This one is not only a random token: it holds your name, email address, phone number, Client ID, session token, and your DGC balance, cover-charge balance and membership status, so the booking form can fill itself in. It stays inside that browser tab and is cleared when the tab closes.
- Local storage — banner dismissal. A single flag recording that you dismissed the launch banner. It is set for any visitor who dismisses it, signed in or not, and holds nothing personal.
We run no analytics, no advertising trackers and no pixels of our own, and we set no tracking cookies of our own. We do load a few things from other companies' servers, and each of those companies can see your IP address and browser details as the page loads and may set its own cookies, governed by its own privacy policy rather than ours: PayPal's checkout script and payment window load from paypal.com; our pages load fonts from Google's font servers; the signature pad on our booking, checkout, gift-claim, membership sign-up and account pages loads from jsDelivr; and our contact page embeds a live map from Google Maps. All four are listed under Third Parties We Share With above. Beyond what PayPal needs in order to take a payment, none of them receives account data from us.
Children
Vitaliteit Booking Accounts are for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, email frontdesk@vitaliteitinfo.com and we will close the account and delete it by hand — no part of the system deletes an account on its own. If a session has already taken place, the treatment record for that session is subject to the seven-year retention rule above.
Changes to This Policy
We may update this Privacy Policy. Material changes will be surfaced at your next booking — you'll be asked to review and re-accept the updated version. Past acceptances are preserved with their version number and date.
Last updated: 2026-09-06 (v3 — fourth sign-in path disclosed: the one-tap link in reminder emails, and what it means for a shared mailbox; one-time code storage described precisely; the client-side self-cancellation database permission was removed, so this policy no longer claims it; the executor position now points at Section 9 of the Terms; the per-appointment link in confirmation and reminder emails is now described — that it carries no expiry, that the one-click Confirm and Cancel links in reminders need no further check, and that cancelling or rescheduling through it can forfeit or spend credits; two third-party services that load on our pages are now disclosed — jsDelivr, which serves the on-screen signature pad, and the Google Maps embed on the contact page)