Legal

Privacy Policy

Last updated: June 23, 2026

This Privacy Policy explains how Pearl Beauty Head Spa ("we," "our," or "us") collects, uses, and protects your personal information when you book appointments through this website. This site is powered by AsparaOS, a third-party booking platform. BothPearl Beauty Head Spa and AsparaOS are committed to protecting your privacy.

1. Who Controls Your Data

Pearl Beauty Head Spa is the data controller of the personal information you provide when booking appointments. We determine how your data is used in connection with your appointments with us.

AsparaOS, Inc. is our data processor — it operates the booking platform on our behalf and processes your data only per our instructions. AsparaOS does not independently sell or use your personal information. For AsparaOS's own privacy practices, see asparaos.com/legal/privacy.

Contact us at: 3927 Walnut Grove #117, Rosemead, CA 91770 · 6267668998

2. Information We Collect

Information you provide:

  • Name — to identify your booking and address you by name
  • Email address — to send booking confirmations, reminders, and receipts
  • Phone number (optional) — for appointment reminders and contact if needed
  • Gift recipient name (optional) — if booking a service as a gift
  • Service notes (optional) — preferences or instructions for your technician

Payment information:

  • Deposit or payment card details are collected and processed securely by Stripe (PCI-DSS Level 1 certified). We never see or store your card number, expiration date, or CVV. We retain only a Stripe payment reference.
  • For gift bookings, the full service price is charged at the time of booking (see the Terms of Service for the gift refund policy). We retain a payment reference and the recipient name you provide so the salon can fulfill the appointment.
  • For gift cards, we collect the purchaser's name, email, and phone to issue the card, email the QR code, and record who redeems it and when. Gift card purchases are final sale — non-refundable (see the Terms of Service).

Automatically collected:

  • IP address, browser type, and device type (for security and fraud prevention)
  • Pages visited on this booking site (via server logs)
  • Session tokens (to maintain your booking session)

3. How We Use Your Information

  • To schedule, confirm, and manage your appointments
  • To send appointment confirmations, reminders, and follow-up communications
  • To process deposits and payments
  • To maintain business records as required by law
  • To contact you about your booking or appointment-related concerns
  • To improve our services and detect fraudulent bookings

We do not sell, rent, or share your personal information with third parties for marketing purposes. We do not use your data for advertising.

4. Third-Party Services

We use the following trusted services to operate our booking system:

  • Stripe — secure payment processing (PCI-DSS Level 1 compliant). Stripe's privacy policy applies to data it receives.
  • AsparaOS — booking platform and data storage. Data is stored in Supabase (AWS, USA) with encryption at rest and in transit.
  • Resend — transactional email delivery (booking confirmations, reminders). Email addresses are shared only to deliver emails relevant to your booking.

These processors are contractually bound to use your data only to provide services to us and are required to maintain appropriate security measures.

5. How Long We Keep Your Data

  • Appointment records — retained for 3 years for legitimate business records
  • Payment records & receipts — retained for 7 years as required by financial regulations
  • Service signatures & consent records — retained for 3 years for chargeback protection
  • Email address — retained while your appointment history is active; deleted on your request after the minimum retention period

You may request deletion of your personal data at any time (see Section 7). Deletion is subject to the minimum retention periods above, which are required by law.

6. Cookies

This booking website uses the following types of cookies:

  • Essential session cookies — to maintain your booking session while you complete a reservation. These expire when you close your browser or complete the booking.
  • Security cookies — to prevent fraud and abuse (e.g., rate limiting).

We do not use advertising cookies, behavioral tracking cookies, or share cookie data with ad networks. See our Cookie Policy for full details.

7. Your Privacy Rights

All users have the right to:

  • Request a copy of the personal information we hold about you
  • Request correction of inaccurate or outdated information
  • Request deletion of your personal information (subject to legal retention requirements)

EU & UK residents (GDPR) additionally have the right to:

  • Data portability (Art. 20) — receive your data in a machine-readable format
  • Restriction of processing (Art. 18) — limit how we process your data in certain circumstances
  • Object to processing (Art. 21) — object to processing based on legitimate interests
  • Lodge a complaint with your national data protection authority

California residents (CCPA/CPRA) additionally have the right to:

  • Know what personal information we collect and how it is used
  • Opt out of the sale of personal information (we do not sell your data)
  • Non-discrimination for exercising your privacy rights

Canadian residents (PIPEDA) additionally have the right to:

  • Withdraw consent to the collection, use, or disclosure of your information
  • Challenge the accuracy and completeness of your information and have it amended
  • File a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca)

Australian residents (Privacy Act 1988 & Australian Privacy Principles) additionally have the right to:

  • Request access to the personal information we hold about you
  • Request correction of personal information that is inaccurate or out of date
  • Complain to the Office of the Australian Information Commissioner (OAIC, oaic.gov.au) if you believe your privacy has been breached

To exercise any right, submit a Data Request or contact us directly. We will respond within 30 days.

8. Security

We implement industry-standard security measures: TLS encryption in transit, encrypted database storage via Supabase/AWS, row-level data isolation (your data is inaccessible to other salons using the platform), and role-based access controls for staff. No system is 100% secure, but we take data protection seriously and review our practices regularly.

9. Children’s Privacy

This booking service is not intended for individuals under 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, contact us immediately and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be indicated by an updated "Last updated" date. We encourage you to review this page before each booking. Continued use of this booking site after changes constitutes acceptance.

11. Contact & Data Requests

For privacy questions, data access requests, or deletion requests:

  • 3927 Walnut Grove #117, Rosemead, CA 91770 · 6267668998

Or submit a Data Request form.

Platform provider: AsparaOS, Inc. — privacy@asparaos.com

If you are unsatisfied with our response, you may also contact your local data protection authority — for example the ICO (UK), your EU national authority, the Office of the Privacy Commissioner of Canada, or the OAIC (Australia).

Terms of ServiceCookie PolicyAccessibilityData Request