Legal · Chrome Aesthetics Spa
Effective Date: January 1, 2025 · Last Updated: July 17, 2026 · Controller: Between You and Me dba Chrome Aesthetics
Summary:
Chrome Aesthetics collects only the information needed to provide your care and keep you informed. We never sell your personal information. Medical and health information is handled under HIPAA. You may opt out of marketing messages at any time. If you have questions about this policy, call or email us directly, we are always happy to talk through it.
Between You and Me dba Chrome Aesthetics ("Chrome Aesthetics," "we," "us," or "our") is a nurse practitioner-led medical spa located at 3613 NM-528 Suite H, Albuquerque, New Mexico 87114. We are responsible for the personal information collected through this website and through the delivery of our services.
This Privacy Policy applies to personal information we collect when you:
Visit our website at chromeaestheticsspa.com
Submit a contact, booking, or intake form
Schedule or attend an appointment
Receive treatments or wellness services
Purchase products or gift cards
Opt in to receive SMS, email, or other marketing communications
Interact with us via phone, email, or social media
If you have questions, concerns, or requests related to this policy, please contact our Privacy Manager directly:
Name: Barbara Franklin
Email: [email protected]
Phone: (505) 897-5065
Address: 3613 NM-528 Suite H, Albuquerque, NM 87114
"Personal data" means any information that can directly or indirectly identify you. We collect only the information necessary to provide our services, maintain accurate records, and communicate with you.
Category
Examples
Source
First and last name, date of birth, gender
You (intake forms, booking)
Email address, phone number, mailing or billing address
You (forms, booking, phone calls)
Medical history, treatment records, allergies, current medications, procedure-relevant health information
You (intake paperwork, consultations) collected only as medically necessary
Payment card details, billing information
You, processed securely through Square, Cherry, or CareCredit. We do not store raw card numbers.
Purchases, treatments received, appointment history, gift card redemptions, Chrome Club membership status
Generated through your interactions with us
IP address, browser type and version, device type, operating system, referring URLs, session data
Automatically collected via cookies and analytics tools
Pages visited, time spent, links clicked, forms interacted with
Automatically collected via GoHighLevel, Google Analytics
Content of messages sent via our contact form, email, or SMS
You
Whether you have opted in or out of SMS and email marketing, consent timestamps
You (form checkboxes, opt-out replies)
Protected Health Information (PHI) as defined under HIPAA see Section 13
You (intake forms, consultations) collected only with consent and solely for treatment purposes
We also collect and use aggregated or anonymized data (such as website traffic trends) that cannot be used to identify any individual. This data is not personal data and is not subject to this policy.
You provide information to us when you:
Submit a contact, booking, consultation, or intake form on our website
Call or email our office
Complete medical intake paperwork in person or digitally
Purchase a product, service, gift card, or Chrome Club membership
Check in for an appointment or sign consent forms
Opt in to receive SMS or email communications
When you visit our website, we automatically collect certain Technical and Usage Data through:
GoHighLevel (GHL) — our website and CRM platform, which tracks form submissions, session activity, and marketing automations
Google Analytics — aggregated website traffic and behavior analysis
Meta (Facebook) Pixel — conversion tracking for Facebook and Instagram advertising, if active
Cookies and session tracking — see Section 6 for full details
We may receive information about you from:
Square — appointment booking records and payment processing
Zenoti — appointment booking records and payment processing
Cherry and CareCredit — payment plan applications (we receive confirmation of approval; we do not receive your full application or credit details)
GoHighLevel — form completions, email engagement, and SMS response data
Social media platforms — if you contact or interact with us via Instagram, Facebook, or TikTok
We use your personal information only for lawful purposes, including where it is necessary to deliver our services, fulfill a legal obligation, or where you have given your consent.
Purpose
Data Used
Register you as a new client and maintain your records
Identity Data, Contact Data
Schedule, confirm, and manage appointments
Identity Data, Contact Data, Appointment Data
Provide medical aesthetic, skincare, and wellness treatments
Appointment & Medical Intake Data, Identity Data
Process payments and manage billing
Financial Data, Transaction Data, Identity Data
Send appointment reminders, confirmations, and follow-up care instructions
Contact Data, Appointment Data, Marketing Preferences
Send marketing communications (promotions, offers, new services)
Contact Data, Marketing Preferences only with your consent or existing patient relationship
Respond to your questions, complaints, or information requests
Contact Data, Communications Data
Improve our website, services, and client experience
Technical Data, Usage Data (aggregated or anonymized where possible)
Comply with legal, regulatory, and healthcare obligations
All relevant categories as required by law
Maintain safety and prevent fraud
Identity Data, Technical Data, Transaction Data
You may receive marketing communications from us if you have:
Replying STOP to any text message we send
Clicking Unsubscribe in any marketing email
Contacting us directly at [email protected] or (505) 897-5065
Opting out of marketing communications will affect your ability to receive appointment reminders, care instructions, or other service-related messages that are not promotional in nature.
Explicitly opted in by checking a consent box on our forms
Previously received services from us and have not opted out
You may opt out of marketing communications at any time by:
Chrome Aesthetics may send the following types of text messages:
Transactional / Service Messages: Appointment reminders, booking confirmations, rescheduling notifications, post-treatment follow-up, and care instructions
Marketing Messages: Promotions, special offers, new service announcements, Chrome Club membership updates, and seasonal campaigns
We collect SMS consent through:
The opt-in checkbox on our website contact and booking forms
In-office sign-up at the time of service
Explicit verbal consent documented in our CRM
Our consent language clearly describes the types of messages you will receive, references this Privacy Policy, and states that message and data rates may apply.
You may opt out of SMS messages at any time by:
Replying STOP to any text message from us
Contacting us at (505) 897-5065 or [email protected]
After opting out, you will receive a single confirmation message. No further marketing texts will be sent. You may still receive non-marketing appointment-related messages unless you specifically request that all messages stop.
Message frequency varies based on your appointment schedule and marketing preferences. Typically 2–6 messages per month for active patients. Standard message and data rates may apply depending on your mobile carrier plan.
Our SMS program complies with the Telephone Consumer Protection Act (TCPA), FCC regulations, and CTIA guidelines. Consent records, including timestamps and the exact language presented at opt-in, are maintained in our CRM system.
Our website uses cookies and similar tracking technologies to operate correctly, analyze usage, and deliver relevant advertising.
Cookie Type
Purpose
Provider
Required for the website to function form sessions, security, navigation
GoHighLevel
Aggregate traffic analysis pages visited, session duration, referral sources
Google Analytics
Tracks actions taken after clicking our ads; used to measure ad performance and retarget visitors
Meta (Facebook) Pixel, Google Ads
Tracks form completions and website visits within our CRM to enable marketing automations
GoHighLevel
You can control cookies through your browser settings. Most browsers allow you to:
View what cookies are set
Block all cookies or cookies from specific sites
Delete cookies when you close your browser
We never sell your personal information to third parties. We share your data only as described below, with service providers who are contractually bound to protect it.
Recipient
Purpose
Data Shared
Website hosting, CRM, form processing, email and SMS automation, appointment management
Identity, Contact, Appointment, Communications, Marketing Preferences
Online booking platform and payment processing
Identity, Contact, Financial, Transaction Data
Online booking platform and payment processing
Identity, Contact, Financial, Transaction Data
Patient financing and payment plans
Identity, Contact Data (as required for financing application)
Patient financing and payment plans
Identity, Contact Data (as required for financing application)
Website analytics, advertising measurement
Technical Data, Usage Data (anonymized/aggregated)
Advertising performance tracking and audience building
Technical Data (via Pixel hashed where possible)
Coordination of care when referral or consultation is required
Medical Intake Data, PHI only with your written authorization
Compliance with applicable law, court orders, or government requests
As required by law
In the event of a business merger, acquisition, or sale of assets
All categories you will be notified in advance
Some of our service providers (including Google and GoHighLevel) may store or process data on servers located outside New Mexico or the United States. We ensure that appropriate data processing agreements and security standards are in place with all providers, regardless of location.
We implement appropriate technical and administrative safeguards to protect your personal information from unauthorized access, disclosure, alteration, or destruction. These measures include:
Secure, encrypted connections (HTTPS/TLS) on our website
Role-based access controls only authorized staff with a legitimate need may access client records
Use of PCI-DSS compliant payment processors (Square, Cherry, CareCredit) we do not store raw payment card data on our systems
Password-protected CRM and practice management systems
Staff training on data privacy and confidentiality obligations
No system is 100% secure. In the event of a data breach affecting your information, we will notify you as required by applicable law see Section 14 for our breach notification policy.
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, comply with our legal obligations, and resolve any disputes.
Data Type
Retention Period
Medical and treatment records (PHI)
Minimum of 7 years from last treatment date, or longer as required by New Mexico healthcare regulations
Client contact and identity records
Duration of active patient relationship plus 5 years
Financial and transaction records
7 years, as required for tax and accounting purposes
Marketing consent records (SMS/email opt-in)
Duration of consent plus 4 years (required for TCPA compliance documentation)
Website analytics data
Up to 26 months (Google Analytics default); anonymized after 14 months
General correspondence and inquiry records
3 years from date of inquiry
When your data is no longer required, we will securely delete, destroy, or anonymize it.
Depending on your location and applicable law, you may have the following rights regarding your personal information. To exercise any of these rights, contact us using the information in Section 16. We may ask you to verify your identity before processing your request.
Right
What It Means
Right to Access
Request a copy of the personal information we hold about you
Right to Correction
Ask us to correct inaccurate or incomplete personal information
Right to Deletion
Request deletion of your personal information, subject to legal retention requirements (e.g., medical records must be retained under applicable law)
Right to Restrict Processing
Ask us to limit how we use your data in certain circumstances
Right to Data Portability
Request your data in a portable, machine-readable format where technically feasible
Right to Opt Out of Marketing
Withdraw marketing consent at any time, see Section 4 and Section 5
Right to Withdraw Consent
To exercise any of the rights above, please contact us by:
Email: [email protected] with subject line "Privacy Request"
Phone: (505) 897-5065
Mail: Chrome Aesthetics, 3613 NM-528 Suite H, Albuquerque, NM 87114, Attn: Privacy Manager
We will respond to verifiable requests within 30 days. In complex cases we may require up to 60 days and will notify you of the extension.
Your rights regarding Protected Health Information (PHI) are governed by HIPAA and are described in detail in Section 13 of this policy. HIPAA rights and general privacy rights operate in parallel you may exercise either or both.
Our website and services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18.
If a minor requires our services, a parent or legal guardian must provide consent on their behalf, be present during treatment, and may be required to sign medical intake and consent forms. In such cases, the parent or guardian's contact information is the primary record.
If we discover that we have inadvertently collected personal information from an individual under 18 without verified parental consent, we will promptly delete that information. If you believe we may have collected information from or about a minor without appropriate consent, please contact us immediately at [email protected].
Our website contains links to third-party websites, including our online shop partners (SkinMedica, Alastin, Colorescience, BioTE, Nutrafol), our booking platform (Square, Zenoti), and our financing partners (Cherry, CareCredit).
When you click a link to a third-party site, you leave our website and their privacy policies govern the collection and use of your information. We are not responsible for the privacy practices of any third-party sites and encourage you to review their privacy policies before providing any personal information.
Last Updated: July 17, 2026
This section describes how Chrome Aesthetics may use and disclose your Protected Health Information (PHI) and explains your rights under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and related federal regulations. This notice is required by law.
We are required by law to:
Maintain the privacy and security of your PHI
Provide you with this Notice of Privacy Practices
Follow the terms of this Notice as currently in effect
Notify you in the event of a breach of your unsecured PHI within 60 days of discovery
Treatment. We may use and disclose your PHI to provide, coordinate, or manage your care. This includes sharing relevant information with other healthcare professionals involved in your treatment, when appropriate and authorized.
Payment. We may use and disclose your PHI to bill for services and receive payment. This may involve disclosures to financing partners, payment processors, or health plans where applicable.
Healthcare Operations. We may use and disclose your PHI for internal operations including quality assessment, staff training, compliance audits, and business planning solely to improve your care and our services.
In limited circumstances, we may use or disclose your PHI without your written authorization as required or permitted by law, including:
Public health activities (e.g., reporting certain diseases or adverse events to health authorities)
Health oversight activities (e.g., audits, investigations, inspections)
Legal proceedings or law enforcement, when required by law or court order
Workers' compensation compliance
Prevention of a serious threat to health or safety
Business associates who perform services on our behalf under a signed Business Associate Agreement (BAA)
We will obtain your written authorization before using or disclosing your PHI for any purpose not described in this Notice, including:
Most marketing communications where PHI is involved
Sale of PHI (we do not sell PHI)
Psychotherapy notes (where applicable)
You may revoke a written authorization at any time by submitting a written request to us, except to the extent that action has already been taken based on that authorization.
If any records we maintain relate to the treatment of Substance Use Disorders (SUD), those records are subject to enhanced federal confidentiality protections under 42 C.F.R. Part 2. Such records may not generally be used or disclosed without the patient's written consent, except as expressly permitted by law. Federal law prohibits the use of SUD treatment records in civil, criminal, or administrative proceedings against the patient without a specific court order.
You have the right to:
Inspect and copy your medical records and other PHI we maintain, as permitted by law (a reasonable fee may apply for copies)
Request an amendment to your PHI if you believe it is inaccurate or incomplete
Request restrictions on how we use or disclose your PHI (note: we are not always required to agree, except where required by law)
Request confidential communications for example, asking us to contact you at an alternate phone number or address
Receive an accounting of disclosures of your PHI that were not for treatment, payment, or operations purposes
Obtain a paper copy of this Notice at any time, even if you agreed to receive it electronically
Be notified within 60 days of discovery of a breach of your unsecured PHI
To exercise any HIPAA right, submit your request in writing to Barbara Franklin at the contact information listed in Section 16. Some requests may be denied as permitted by law; you will be informed if this occurs and given the opportunity to appeal.
If you believe your privacy rights under HIPAA have been violated, you may file a complaint with us or directly with the federal government:
With us: Contact Barbara Franklin at [email protected] or (505) 897-5065
With HHS: U.S. Department of Health and Human Services, Office for Civil Rights
With the FTC: Federal Trade Commission
In the event of a security breach that may have compromised your personal information or Protected Health Information, Chrome Aesthetics will:
HIPAA Breach: Notify affected individuals within 60 days of discovering the breach, as required by the HIPAA Breach Notification Rule (45 C.F.R. Part 164, Subpart D). If 500 or more New Mexico residents are affected, we will also notify the Secretary of HHS and prominent local media.
New Mexico Data Breach Notification Act: Notify affected individuals whose personal identifying information (PII) may have been accessed without authorization, in the most expedient time possible and without unreasonable delay, as required by the New Mexico Data Breach Notification Act (NMSA § 57-12C-4). If the breach affects 1,000 or more individuals, we will also notify the Office of the New Mexico Attorney General.
Breach notifications will be provided by email, mail, or phone (depending on the contact information we have on file) and will describe the nature of the breach, the types of information involved, steps we have taken to address it, and recommended actions for you to protect yourself.
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. When we make material changes, we will:
Update the "Last Updated" date at the top of this policy
Post the revised policy on this page
Notify you by email or SMS if the changes materially affect how we use your personal or health information
We encourage you to review this policy periodically. Your continued use of our services after changes are posted constitutes your acceptance of the updated policy.
For any questions, concerns, or requests related to this Privacy Policy or your personal information, please reach out to our Privacy Manager:
Privacy Manager: Barbara Franklin
Email: [email protected]
Phone: (505) 897-5065
Mail: Chrome Aesthetics, Attn: Privacy Manager, 3613 NM-528 Suite H, Albuquerque, NM 87114
Office Hours: Monday – Friday 9:00 AM – 6:00 PM, Saturday 9:00 AM – 2:00 PM (MT)
We take all privacy inquiries seriously and will respond within 5 business days for general questions, and within 30 days for formal rights requests.
Helpful Links: