How Essence by Shine collects, uses, and protects your personal information.
Plain-language summary: I collect what you voluntarily submit through forms (contact, coming-soon, review, referral) and what you provide when you create an optional account (name, email, password, plus authentication data like 2FA codes if you turn it on). I use this information to reply to you, run your account, run the referral program, and publish reviews you submit. Appointment booking happens on a separate platform with its own policy. I do not sell your data. I do not use advertising or tracking cookies. I currently do not send marketing email — and if I ever do, it will only go to clients who have opted in from their dashboard.
Essence by Shine is a California-based sole proprietorship operated by Shine, providing facial, skincare, and injectable treatments. This website is operated for clients located in the State of California.
This Privacy Policy applies to information collected through this website (essencebyshine.com) and any optional account you create on it. It works together with my Terms of Use and, if you participate in the referral program, my Referral Program Terms. Appointment booking is handled through a separate third-party platform with its own privacy policy (see Section 4).
Contact for privacy matters:
Use my contact form
California, USA (Bay Area — I'd love for you to come to me, travel available upon request)
My website includes several places where you can voluntarily submit information:
General inquiry contact form:
Coming-soon notification sign-up (for services not yet available):
Notification sign-up information is used solely to contact you when the requested service becomes available.
Account registration (only if you choose to create an account):
Account security data (created automatically when you use those features):
Review submission form:
Reviews are not published automatically. I review each submission and publish only those I approve. Approved reviews are displayed publicly on the Site under your first name and the service category, as described in the Terms of Use. Email addresses, last names, and phone numbers are not displayed publicly. You can request removal of any approved review at any time by contacting me.
Referral program data (if you receive a referral link or share yours):
I do not collect appointment details, health information, treatment notes, or payment data through this website. All appointment booking is handled through a third-party scheduling platform, which has its own privacy policy (see Section 4).
If you choose to sign in with Google or Apple, that provider authenticates you and shares a small profile with me — typically your name, email, and a stable identifier. Your password and any other information held by the provider stay with the provider. I do not receive your contacts, calendar, photos, or anything else outside of basic sign-in information. Use of those buttons is governed by the provider's own terms and privacy policy:
When you visit my website, the web server automatically logs standard technical information, including:
This server log data is used solely for security and site maintenance purposes. It is not linked to your personal identity and is not shared with third parties.
This website does not use advertising cookies, tracking pixels, or analytics services. A small number of cookies and browser storage items are used solely for essential functionality:
ebs_ref) — set when you follow a referral link shared by another client. Used only to attribute your visit so the person who referred you can receive credit if you complete a service. Expires after 90 days. Never used for advertising or behavioral tracking.ebs_signup_source) — set if you click a sign-up prompt the Site offers (for example, the referral-program prompt). Records which on-site prompt led to your sign-up so I can tell whether those prompts are useful. Stored for up to one year. Not shared with anyone and not used for advertising.No cookies are set for marketing, retargeting, or behavioral tracking purposes. If this changes in the future, this policy will be updated and you will be notified through an updated cookie notice before any new tracking begins.
I honor the Global Privacy Control browser signal as an opt-out preference under the CCPA/CPRA. Because I do not sell or share your personal information for cross-context behavioral advertising in the first place, no further action is required when GPC is detected — but I treat the signal as a clear instruction to keep things that way.
I use the information I collect only for these purposes:
I do not currently send marketing email. If I add an opt-in for promotional messages in the future, the opt-in toggle will appear on your dashboard and will default to off — you'll receive promotional email only after you actively turn it on. Every promotional email I do send will include a clear way to unsubscribe, and unsubscribing will not affect your ability to receive transactional or account-related email (password resets, verification, security alerts) or the services I provide.
I will not sell or rent your information. I will not use your information for cross-context behavioral advertising. I will not run automated decision-making against your information that produces legal or similarly significant effects. I will not use information you submit on this Site to train any third-party machine-learning model.
I retain contact-form submissions, coming-soon sign-ups, and referral leads only as long as necessary to follow up with you, and I retain account information for the life of your account (see Section 9). You can ask me to delete information sooner — see Section 6 for how.
Appointments are booked through a separate third-party scheduling platform. When you use that platform, you are subject to its own privacy policy, not this one. That platform collects your appointment details, service preferences, and any related information directly — my website does not receive or store that data.
I encourage you to review the privacy policy of the booking platform before submitting your appointment information. I select platforms that maintain appropriate security standards for the data they handle.
I do not sell, rent, or trade your personal information to any third party.
The only personal information collected through this website is what you voluntarily submit via my general inquiry form (name, email, message). I may share this only in these limited circumstances:
Under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), California residents have the following rights regarding their personal information held by me:
You have the right to request that I disclose what personal information I have collected about you, the categories of sources, the business purpose for collecting it, and any third parties with whom it was shared.
You have the right to request deletion of your personal information that I have collected, subject to certain exceptions (e.g., if needed to complete a transaction you requested or comply with a legal obligation).
You have the right to request that I correct inaccurate personal information I hold about you.
I do not sell or share your personal information with third parties for cross-context behavioral advertising. You do not need to take any action to opt out of a sale that does not occur.
I will not discriminate against you for exercising any of these rights. Exercising your privacy rights will not affect your ability to receive services from me.
To submit a privacy rights request, use my contact form. I will respond to verifiable requests within 45 days as required by California law. I may need to verify your identity before processing your request.
In compliance with the California Online Privacy Protection Act (CalOPPA), I commit to the following:
I take reasonable and appropriate technical measures to protect your personal information against unauthorized access, disclosure, alteration, or destruction. These include:
No method of transmission over the internet is 100% secure. While I strive to protect your information, I cannot guarantee absolute security.
I retain your personal information for as long as necessary to provide services to you and comply with my legal obligations. Specifically:
You may request deletion of your personal information at any time (subject to the exceptions described in Section 6), and I will honor those requests promptly.
Account-based features of the Site are intended for adults (see the Terms of Use, Section 2). My website and services are not directed to children under the age of 16, and I do not knowingly collect personal information from anyone under 16. If you believe I have inadvertently collected information from a minor, please contact me immediately and I will delete it promptly.
My website may contain links to third-party websites (for example, social media profiles or review platforms). These sites have their own privacy policies, and I am not responsible for their content or practices. I encourage you to review the privacy policy of any third-party site you visit.
I may update this Privacy Policy from time to time to reflect changes in my practices or applicable law. I will update the Effective Date at the top of this page and, for material changes, post a notice on my homepage.
Continued use of my website after any changes constitutes your acceptance of the updated policy.
If you have questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact me directly:
Essence by Shine
Bay Area, California, USA
Use my contact form
Availability: By appointment — flexible scheduling
This Privacy Policy was prepared for Essence by Shine, a California-based aesthetics studio. It is provided for informational purposes and does not constitute legal advice. For complex compliance questions, consult a California-licensed attorney.