Legal · Chrome Aesthetics Spa

Privacy Policy

Effective Date: January 1, 2025 · Last Updated: July 17, 2026 · Controller: Between You and Me dba Chrome Aesthetics

Summary:

Chrome Aesthetics collects only the information needed to provide your care and keep you informed. We never sell your personal information. Medical and health information is handled under HIPAA. You may opt out of marketing messages at any time. If you have questions about this policy, call or email us directly, we are always happy to talk through it.

1. Who We Are

Between You and Me dba Chrome Aesthetics ("Chrome Aesthetics," "we," "us," or "our") is a nurse practitioner-led medical spa located at 3613 NM-528 Suite H, Albuquerque, New Mexico 87114. We are responsible for the personal information collected through this website and through the delivery of our services.

This Privacy Policy applies to personal information we collect when you:

  • Visit our website at chromeaestheticsspa.com

  • Submit a contact, booking, or intake form

  • Schedule or attend an appointment

  • Receive treatments or wellness services

  • Purchase products or gift cards

  • Opt in to receive SMS, email, or other marketing communications

  • Interact with us via phone, email, or social media

Contact for Privacy Matters

If you have questions, concerns, or requests related to this policy, please contact our Privacy Manager directly:

  • Name: Barbara Franklin

  • Email: [email protected]

  • Phone: (505) 897-5065

  • Address: 3613 NM-528 Suite H, Albuquerque, NM 87114

2. Personal Data We Collect

"Personal data" means any information that can directly or indirectly identify you. We collect only the information necessary to provide our services, maintain accurate records, and communicate with you.

Category

Examples

Source

Identity Data

First and last name, date of birth, gender

You (intake forms, booking)

Contact Data

Email address, phone number, mailing or billing address

You (forms, booking, phone calls)

Appointment & Medical Intake Data

Medical history, treatment records, allergies, current medications, procedure-relevant health information

You (intake paperwork, consultations) collected only as medically necessary

Financial Data

Payment card details, billing information

You, processed securely through Square, Cherry, or CareCredit. We do not store raw card numbers.

Transaction Data

Purchases, treatments received, appointment history, gift card redemptions, Chrome Club membership status

Generated through your interactions with us

Technical Data

IP address, browser type and version, device type, operating system, referring URLs, session data

Automatically collected via cookies and analytics tools

Usage Data

Pages visited, time spent, links clicked, forms interacted with

Automatically collected via GoHighLevel, Google Analytics

Communications Data

Content of messages sent via our contact form, email, or SMS

You

Marketing Preferences

Whether you have opted in or out of SMS and email marketing, consent timestamps

You (form checkboxes, opt-out replies)

Sensitive Health Data

Protected Health Information (PHI) as defined under HIPAA see Section 13

You (intake forms, consultations) collected only with consent and solely for treatment purposes

We also collect and use aggregated or anonymized data (such as website traffic trends) that cannot be used to identify any individual. This data is not personal data and is not subject to this policy.

3. How We Collect Your Information

Direct Interactions

You provide information to us when you:

  • Submit a contact, booking, consultation, or intake form on our website

  • Call or email our office

  • Complete medical intake paperwork in person or digitally

  • Purchase a product, service, gift card, or Chrome Club membership

  • Check in for an appointment or sign consent forms

  • Opt in to receive SMS or email communications

Automated Technologies

When you visit our website, we automatically collect certain Technical and Usage Data through:

  • GoHighLevel (GHL) — our website and CRM platform, which tracks form submissions, session activity, and marketing automations

  • Google Analytics — aggregated website traffic and behavior analysis

  • Meta (Facebook) Pixel — conversion tracking for Facebook and Instagram advertising, if active

  • Cookies and session tracking — see Section 6 for full details

Third-Party Sources

We may receive information about you from:

  • Square — appointment booking records and payment processing

  • Zenoti — appointment booking records and payment processing

  • Cherry and CareCredit — payment plan applications (we receive confirmation of approval; we do not receive your full application or credit details)

  • GoHighLevel — form completions, email engagement, and SMS response data

  • Social media platforms — if you contact or interact with us via Instagram, Facebook, or TikTok

4. How We Use Your Information

We use your personal information only for lawful purposes, including where it is necessary to deliver our services, fulfill a legal obligation, or where you have given your consent.

Purpose

Data Used

Register you as a new client and maintain your records

Identity Data, Contact Data

Schedule, confirm, and manage appointments

Identity Data, Contact Data, Appointment Data

Provide medical aesthetic, skincare, and wellness treatments

Appointment & Medical Intake Data, Identity Data

Process payments and manage billing

Financial Data, Transaction Data, Identity Data

Send appointment reminders, confirmations, and follow-up care instructions

Contact Data, Appointment Data, Marketing Preferences

Send marketing communications (promotions, offers, new services)

Contact Data, Marketing Preferences only with your consent or existing patient relationship

Respond to your questions, complaints, or information requests

Contact Data, Communications Data

Improve our website, services, and client experience

Technical Data, Usage Data (aggregated or anonymized where possible)

Comply with legal, regulatory, and healthcare obligations

All relevant categories as required by law

Maintain safety and prevent fraud

Identity Data, Technical Data, Transaction Data

Marketing Communications

You may receive marketing communications from us if you have:

  • Replying STOP to any text message we send

  • Clicking Unsubscribe in any marketing email

  • Contacting us directly at [email protected] or (505) 897-5065

Opting out of marketing communications will affect your ability to receive appointment reminders, care instructions, or other service-related messages that are not promotional in nature.

  • Explicitly opted in by checking a consent box on our forms

  • Previously received services from us and have not opted out

You may opt out of marketing communications at any time by:

5. SMS and Text Message Communications

Types of SMS Messages We Send

Chrome Aesthetics may send the following types of text messages:

  • Transactional / Service Messages: Appointment reminders, booking confirmations, rescheduling notifications, post-treatment follow-up, and care instructions

  • Marketing Messages: Promotions, special offers, new service announcements, Chrome Club membership updates, and seasonal campaigns

Opting In

We collect SMS consent through:

  • The opt-in checkbox on our website contact and booking forms

  • In-office sign-up at the time of service

  • Explicit verbal consent documented in our CRM

Our consent language clearly describes the types of messages you will receive, references this Privacy Policy, and states that message and data rates may apply.

Opting Out

You may opt out of SMS messages at any time by:

  • Replying STOP to any text message from us

  • Contacting us at (505) 897-5065 or [email protected]

After opting out, you will receive a single confirmation message. No further marketing texts will be sent. You may still receive non-marketing appointment-related messages unless you specifically request that all messages stop.

Message Frequency and Rates

Message frequency varies based on your appointment schedule and marketing preferences. Typically 2–6 messages per month for active patients. Standard message and data rates may apply depending on your mobile carrier plan.

Compliance

Our SMS program complies with the Telephone Consumer Protection Act (TCPA), FCC regulations, and CTIA guidelines. Consent records, including timestamps and the exact language presented at opt-in, are maintained in our CRM system.

6. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to operate correctly, analyze usage, and deliver relevant advertising.

Types of Cookies We Use

Cookie Type

Purpose

Provider

Essential

Required for the website to function form sessions, security, navigation

GoHighLevel

Analytics

Aggregate traffic analysis pages visited, session duration, referral sources

Google Analytics

Marketing / Advertising

Tracks actions taken after clicking our ads; used to measure ad performance and retarget visitors

Meta (Facebook) Pixel, Google Ads

Session / CRM

Tracks form completions and website visits within our CRM to enable marketing automations

GoHighLevel

Managing Cookies

You can control cookies through your browser settings. Most browsers allow you to:

  • View what cookies are set

  • Block all cookies or cookies from specific sites

  • Delete cookies when you close your browser

7. Who We Share Your Information With

We never sell your personal information to third parties. We share your data only as described below, with service providers who are contractually bound to protect it.

Recipient

Purpose

Data Shared

GoHighLevel (GHL)

Website hosting, CRM, form processing, email and SMS automation, appointment management

Identity, Contact, Appointment, Communications, Marketing Preferences

Square

Online booking platform and payment processing

Identity, Contact, Financial, Transaction Data

Zenoti

Online booking platform and payment processing

Identity, Contact, Financial, Transaction Data

Cherry

Patient financing and payment plans

Identity, Contact Data (as required for financing application)

CareCredit

Patient financing and payment plans

Identity, Contact Data (as required for financing application)

Google (Analytics & Ads)

Website analytics, advertising measurement

Technical Data, Usage Data (anonymized/aggregated)

Meta (Facebook / Instagram)

Advertising performance tracking and audience building

Technical Data (via Pixel hashed where possible)

Medical professionals

Coordination of care when referral or consultation is required

Medical Intake Data, PHI only with your written authorization

Legal or regulatory authorities

Compliance with applicable law, court orders, or government requests

As required by law

Successors in interest

In the event of a business merger, acquisition, or sale of assets

All categories you will be notified in advance

International Data Transfers

Some of our service providers (including Google and GoHighLevel) may store or process data on servers located outside New Mexico or the United States. We ensure that appropriate data processing agreements and security standards are in place with all providers, regardless of location.

8. Data Security

We implement appropriate technical and administrative safeguards to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These measures include:

  • Secure, encrypted connections (HTTPS/TLS) on our website

  • Role-based access controls only authorized staff with a legitimate need may access client records

  • Use of PCI-DSS compliant payment processors (Square, Cherry, CareCredit) we do not store raw payment card data on our systems

  • Password-protected CRM and practice management systems

  • Staff training on data privacy and confidentiality obligations

No system is 100% secure. In the event of a data breach affecting your information, we will notify you as required by applicable law see Section 14 for our breach notification policy.

9. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, comply with our legal obligations, and resolve any disputes.

Data Type

Retention Period

Medical and treatment records (PHI)

Minimum of 7 years from last treatment date, or longer as required by New Mexico healthcare regulations

Client contact and identity records

Duration of active patient relationship plus 5 years

Financial and transaction records

7 years, as required for tax and accounting purposes

Marketing consent records (SMS/email opt-in)

Duration of consent plus 4 years (required for TCPA compliance documentation)

Website analytics data

Up to 26 months (Google Analytics default); anonymized after 14 months

General correspondence and inquiry records

3 years from date of inquiry

When your data is no longer required, we will securely delete, destroy, or anonymize it.

10. Your Privacy Rights

Depending on your location and applicable law, you may have the following rights regarding your personal information. To exercise any of these rights, contact us using the information in Section 16. We may ask you to verify your identity before processing your request.

Right

What It Means

Right to Access

Request a copy of the personal information we hold about you

Right to Correction

Ask us to correct inaccurate or incomplete personal information

Right to Deletion

Request deletion of your personal information, subject to legal retention requirements (e.g., medical records must be retained under applicable law)

Right to Restrict Processing

Ask us to limit how we use your data in certain circumstances

Right to Data Portability

Request your data in a portable, machine-readable format where technically feasible

Right to Opt Out of Marketing

Withdraw marketing consent at any time, see Section 4 and Section 5

Right to Withdraw Consent

Where processing is based on consent, you may withdraw it at any time. This does not affect the lawfulness of processing prior to withdrawal.

How to Submit a Privacy Request

To exercise any of the rights above, please contact us by:

  • Email: [email protected] with subject line "Privacy Request"

  • Phone: (505) 897-5065

  • Mail: Chrome Aesthetics, 3613 NM-528 Suite H, Albuquerque, NM 87114, Attn: Privacy Manager

We will respond to verifiable requests within 30 days. In complex cases we may require up to 60 days and will notify you of the extension.

Note on Medical Records (HIPAA Rights)

Your rights regarding Protected Health Information (PHI) are governed by HIPAA and are described in detail in Section 13 of this policy. HIPAA rights and general privacy rights operate in parallel you may exercise either or both.

11. Children's Privacy

Our website and services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18.

If a minor requires our services, a parent or legal guardian must provide consent on their behalf, be present during treatment, and may be required to sign medical intake and consent forms. In such cases, the parent or guardian's contact information is the primary record.

If we discover that we have inadvertently collected personal information from an individual under 18 without verified parental consent, we will promptly delete that information. If you believe we may have collected information from or about a minor without appropriate consent, please contact us immediately at [email protected].

12. Third-Party Links

Our website contains links to third-party websites, including our online shop partners (SkinMedica, Alastin, Colorescience, BioTE, Nutrafol), our booking platform (Square, Zenoti), and our financing partners (Cherry, CareCredit).

When you click a link to a third-party site, you leave our website and their privacy policies govern the collection and use of your information. We are not responsible for the privacy practices of any third-party sites and encourage you to review their privacy policies before providing any personal information.

13. HIPAA Notice of Privacy Practices

Last Updated: July 17, 2026

This section describes how Chrome Aesthetics may use and disclose your Protected Health Information (PHI) and explains your rights under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and related federal regulations. This notice is required by law.

Our Duties Under HIPAA

We are required by law to:

  • Maintain the privacy and security of your PHI

  • Provide you with this Notice of Privacy Practices

  • Follow the terms of this Notice as currently in effect

  • Notify you in the event of a breach of your unsecured PHI within 60 days of discovery

Permitted Uses and Disclosures of PHI

Treatment. We may use and disclose your PHI to provide, coordinate, or manage your care. This includes sharing relevant information with other healthcare professionals involved in your treatment, when appropriate and authorized.

Payment. We may use and disclose your PHI to bill for services and receive payment. This may involve disclosures to financing partners, payment processors, or health plans where applicable.

Healthcare Operations. We may use and disclose your PHI for internal operations including quality assessment, staff training, compliance audits, and business planning solely to improve your care and our services.

Uses and Disclosures Without Your Authorization

In limited circumstances, we may use or disclose your PHI without your written authorization as required or permitted by law, including:

  • Public health activities (e.g., reporting certain diseases or adverse events to health authorities)

  • Health oversight activities (e.g., audits, investigations, inspections)

  • Legal proceedings or law enforcement, when required by law or court order

  • Workers' compensation compliance

  • Prevention of a serious threat to health or safety

  • Business associates who perform services on our behalf under a signed Business Associate Agreement (BAA)

Uses Requiring Your Written Authorization

We will obtain your written authorization before using or disclosing your PHI for any purpose not described in this Notice, including:

  • Most marketing communications where PHI is involved

  • Sale of PHI (we do not sell PHI)

  • Psychotherapy notes (where applicable)

You may revoke a written authorization at any time by submitting a written request to us, except to the extent that action has already been taken based on that authorization.

Special Protections: Substance Use Disorder Records (42 C.F.R. Part 2)

If any records we maintain relate to the treatment of Substance Use Disorders (SUD), those records are subject to enhanced federal confidentiality protections under 42 C.F.R. Part 2. Such records may not generally be used or disclosed without the patient's written consent, except as expressly permitted by law. Federal law prohibits the use of SUD treatment records in civil, criminal, or administrative proceedings against the patient without a specific court order.

Your HIPAA Rights

You have the right to:

  • Inspect and copy your medical records and other PHI we maintain, as permitted by law (a reasonable fee may apply for copies)

  • Request an amendment to your PHI if you believe it is inaccurate or incomplete

  • Request restrictions on how we use or disclose your PHI (note: we are not always required to agree, except where required by law)

  • Request confidential communications for example, asking us to contact you at an alternate phone number or address

  • Receive an accounting of disclosures of your PHI that were not for treatment, payment, or operations purposes

  • Obtain a paper copy of this Notice at any time, even if you agreed to receive it electronically

  • Be notified within 60 days of discovery of a breach of your unsecured PHI

To exercise any HIPAA right, submit your request in writing to Barbara Franklin at the contact information listed in Section 16. Some requests may be denied as permitted by law; you will be informed if this occurs and given the opportunity to appeal.

How to File a HIPAA Complaint

If you believe your privacy rights under HIPAA have been violated, you may file a complaint with us or directly with the federal government:

  • With us: Contact Barbara Franklin at [email protected] or (505) 897-5065

  • With HHS: U.S. Department of Health and Human Services, Office for Civil Rights

  • With the FTC: Federal Trade Commission

14. Data Breach Notification

In the event of a security breach that may have compromised your personal information or Protected Health Information, Chrome Aesthetics will:

  • HIPAA Breach: Notify affected individuals within 60 days of discovering the breach, as required by the HIPAA Breach Notification Rule (45 C.F.R. Part 164, Subpart D). If 500 or more New Mexico residents are affected, we will also notify the Secretary of HHS and prominent local media.

  • New Mexico Data Breach Notification Act: Notify affected individuals whose personal identifying information (PII) may have been accessed without authorization, in the most expedient time possible and without unreasonable delay, as required by the New Mexico Data Breach Notification Act (NMSA § 57-12C-4). If the breach affects 1,000 or more individuals, we will also notify the Office of the New Mexico Attorney General.

Breach notifications will be provided by email, mail, or phone (depending on the contact information we have on file) and will describe the nature of the breach, the types of information involved, steps we have taken to address it, and recommended actions for you to protect yourself.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this policy

  • Post the revised policy on this page

  • Notify you by email or SMS if the changes materially affect how we use your personal or health information

We encourage you to review this policy periodically. Your continued use of our services after changes are posted constitutes your acceptance of the updated policy.

16. Contact Us

For any questions, concerns, or requests related to this Privacy Policy or your personal information, please reach out to our Privacy Manager:

  • Privacy Manager: Barbara Franklin

  • Email: [email protected]

  • Phone: (505) 897-5065

  • Mail: Chrome Aesthetics, Attn: Privacy Manager, 3613 NM-528 Suite H, Albuquerque, NM 87114

  • Office Hours: Monday – Friday 9:00 AM – 6:00 PM, Saturday 9:00 AM – 2:00 PM (MT)

We take all privacy inquiries seriously and will respond within 5 business days for general questions, and within 30 days for formal rights requests.

Northwest, 3613 NM-528 suite h, Albuquerque, NM 87114, USA

Contact Us

(505) 897-5065

Albuquerque, NM 87114

Chrome Aesthetics logo

© 2026 All Rights Reserved. Terms of Use and Privacy Policy