0

Your Cart is Empty

Privacy policy

This Privacy Policy describes how Medical Spa Supply (the “Site” or “we”) collects, uses, and discloses your Personal Information when you visit or make a purchase from the Site.

Contact

After reviewing this policy, if you have additional questions, want more information about our privacy practices, or would like to make a complaint, please contact us by e-mail at info@medicalspasupply.com or by mail using the details provided below:

332 S Michigan Ave, Ste 121 #5444, Chicago, IL 60604

Collecting Personal Information

When you visit the Site, we collect certain information about your device, your interaction with the Site, and information necessary to process your purchases. We may also collect additional information if you contact us for customer support. In this Privacy Policy, we refer to any information about an identifiable individual (including the information below) as “Personal Information”. See the list below for more information about what Personal Information we collect and why.

  • Device information
    • Purpose of collection: to load the Site accurately for you, and to perform analytics on Site usage to optimize our Site.
    • Source of collection: Collected automatically when you access our Site using cookies, log files, web beacons, tags, or pixels.
    • Disclosure for a business purpose: shared with our processor Shopify.
    • Personal Information collected: version of web browser, IP address, time zone, cookie information, what sites or products you view, search terms, and how you interact with the Site.
  • Order information
    • Purpose of collection: to provide products or services to you to fulfill our contract, to process your payment information, arrange for shipping, and provide you with invoices and/or order confirmations, communicate with you, screen our orders for potential risk or fraud, and when in line with the preferences you have shared with us, provide you with information or advertising relating to our products or services.
    • Source of collection: collected from you.
    • Disclosure for a business purpose: shared with our processor Shopify.
    • Personal Information collected: name, billing address, shipping address, payment information (including credit card numbers), email address, and phone number.
  • Customer support information
    • Purpose of collection:To provide any customer support including solutions to your Site experience, selection, check-out, and tracking of orders.
    • Source of collection:Collected from you.
    • Disclosure for a business purpose:shared with our processor Shopify and our phone system Grasshopper.
    • Personal Information collected: Name, phone number, email, address (if applicable).

Mobile -

 If you provide your number for order confirmation or tracking purposes, we will use it when you make it your preference to communicate via that method. If you have provided the number to us and have opted in for marketing offers, we may use it to occasionally market further products, deals, and services to you. If you no longer wish to communicate via mobile / text, text STOP to our number, or please email info@medicalspasupply.com to indicate any of your preference changes. All texts sent or received are subject to charges with your mobile carrier service. We cannot be held liable for any charges incurred. International numbers are not supported at this time.

Minors

The Site is not intended for individuals under the age of18. We do not intentionally collect Personal Information from children. If you are the parent or guardian and believe your child has provided us with Personal Information, please contact us at the address above to request deletion.

Sharing Personal Information

We share your Personal Information with service providers to help us provide our services and fulfill our contracts with you, as described above. For example:

  • We use Shopify to power our online store. You can read more about how Shopify uses your Personal Information here:https://www.shopify.com/legal/privacy.
  • We may share your Personal Information to comply with applicable laws and regulations, to respond to a subpoena, search warrant or other lawful request for information we receive, or to otherwise protect our rights.
  • To Lessgistics LLC (Warehousing and fulfillment partner) for purposes of fulfillment and other physical vendor partners listed on the site.
  • Third party phone / customer support solutions for greater hourly service coverage beyond internal corporate hours and to reduce wait times.

Behavioral Advertising

As described above, we use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For example:

  • We use Google Analytics to help us understand how our customers use the Site. You can read more about how Google uses your Personal Information here:https://www.google.com/intl/en/policies/privacy/. You can also opt-out of Google Analytics here:https://tools.google.com/dlpage/gaoptout.
  • We share information about your use of the Site, your purchases, and your interaction with our ads on other websites with our advertising partners. We collect and share some of this information directly with our advertising partners, and in some cases through the use of cookies or other similar technologies (which you may consent to, depending on your location).
  • We use Shopify Audiences to help us show ads on other websites with our advertising partners to buyers who made purchases with other Shopify merchants and who may also be interested in what we have to offer. We also share information about your use of the Site, your purchases, and the email address associated with your purchases with Shopify Audiences, through which other Shopify merchants may make offers you may be interested in.
  • We use social media platforms such as Facebook, Instagram, Twitter to help us show ads relative to users interests and preferences. 

For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page athttps://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.

You can opt out of targeted advertising by:

  • FACEBOOK -https://www.facebook.com/settings/?tab=ads
  • GOOGLE -https://www.google.com/settings/ads/anonymous
  • BING -https://advertise.bingads.microsoft.com/en-us/resources/policies/personalized-ads
  • Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at:https://optout.aboutads.info/.

    Using Personal Information

    We use your personal Information to provide our services to you, which includes: offering products for sale, processing payments more efficiently and securely, shipping and fulfillment of your order, and keeping you up to date on new products, services, and offers.

    Retention

    When you place an order through the Site, we will retain your Personal Information for our records unless and until you ask us to erase this information. For more information on your right of erasure, please see the ‘Your rights’ section below.

    Automatic decision-making

    If you are a resident of the EEA, you have the right to object to processing based solely on automated decision-making (which includes profiling), when that decision-making has a legal effect on you or otherwise significantly affects you.

    We do engage in fully automated decision-making that has a legal or otherwise significant effect using customer data.

    Our processor Shopify uses limited automated decision-making to prevent fraud that does not have a legal or otherwise significant effect on you.

    Services that include elements of automated decision-making include:

    • Temporary blacklist of IP addresses associated with repeated failed transactions. This blacklist persists for a small number of hours.
    • Temporary blacklist of credit cards associated with blacklisted IP addresses. This blacklist persists for a small number of days.

    Selling Personal Information

    Our Site may sell Personal Information, as defined by the California Consumer Privacy Act of 2018 (“CCPA”).

    • We do not currently accept any financial incentive to sell data to any other party. 
    • We currently do not purchase any data from any other party.

    Your rights

    GDPR

    If you are a resident of the EEA, you have the right to access the Personal Information we hold about you, to port it to a new service, and to ask that your Personal Information be corrected, updated, or erased. If you would like to exercise these rights, please contact us through the contact information above. 

    Your Personal Information will be initially processed in Ireland and then will be transferred outside of Europe for storage and further processing, including to Canada and the United States. For more information on how data transfers comply with the GDPR, see Shopify’s GDPR Whitepaper:https://help.shopify.com/en/manual/your-account/privacy/GDPR.

    CCPA

    If you are a resident of California, you have the right to access the Personal Information we hold about you (also known as the ‘Right to Know’), to port it to a new service, and to ask that your Personal Information be corrected, updated, or erased. If you would like to exercise these rights, please contact us in writing through mail address contact information above. 

    If you would like to designate an authorized agent to submit these requests on your behalf, please contact us at the mail address above.

    Cookies

    A cookie is a small amount of information that’s downloaded to your computer or device when you visit our Site. We use a number of different cookies, including functional, performance, advertising, and social media or content cookies. Cookies make your browsing experience better by allowing the website to remember your actions and preferences (such as login and region selection). This means you don’t have to re-enter this information each time you return to the site or browse from one page to another. Cookies also provide information on how people use the website, for instance whether it’s their first time visiting or if they are a frequent visitor.

    We use the following cookies to optimize your experience on our Site and to provide our services.

    Cookies Necessary for the Functioning of the Store


    Name

    Function

    Duration

    _ab

    Used in connection with access to admin.

    2y

    _secure_session_id

    Used to track a user's session through the multi-step checkout process and keep their order, payment and shipping details connected.

    24h

    _shopify_country

    For shops where pricing currency/country set from GeoIP, that cookie stores the country we've detected. This cookie helps avoid doing GeoIP lookups after the first request.

    session

    _shopify_m

    Used for managing customer privacy settings.

    1y

    _shopify_tm

    Used for managing customer privacy settings.

    30min

    _shopify_tw

    Used for managing customer privacy settings.

    2w

    _storefront_u

    Used to facilitate updating customer account information.

    1min

    _tracking_consent

    Used to store a user's preferences if a merchant has set up privacy rules in the visitor's region.

    1y

    _cmp_a

    Used for managing customer privacy settings.

    1d

    c

    Used in connection with checkout.

    1y

    cart

    Used in connection with shopping cart.

    2w

    cart_currency

    Set after a checkout is completed to ensure that new carts are in the same currency as the last checkout.

    2w

    cart_sig

    A hash of the contents of a cart. This is used to verify the integrity of the cart and to ensure performance of some cart operations.

    2w

    cart_ts

    Used in connection with checkout.

    2w

    cart_ver

    Used in connection with shopping cart.

    2w

    checkout

    Used in connection with checkout.

    4w

    checkout_token

    Used in connection with checkout.

    1y

    dynamic_checkout_shown_on_cart

    Used in connection with checkout.

    30min

    hide_shopify_pay_for_checkout

    Used in connection with checkout.

    session

    keep_alive

    Used in connection with buyer localization.

    2w

    master_device_id

    Used in connection with merchant login.

    2y

    previous_step

    Used in connection with checkout.

    1y

    remember_me

    Used in connection with checkout.

    1y

    secure_customer_sig

    Used to identify a user after they sign into a shop as a customer so they do not need to log in again.

    1y

    shopify_pay

    Used in connection with checkout.

    1y

    shopify_pay_redirect

    Used in connection with checkout.

    1 hour, 3w or 1y depending on value

    source_name

    Used in combination with mobile apps to provide custom checkout behavior, when viewing a store from within a compatible mobile app.

    session

    storefront_digest

    Stores a digest of the storefront password, allowing merchants to preview their storefront while it's password protected.

    2y

    tracked_start_checkout

    Used in connection with checkout.

    1y

    checkout_session_lookup

    Used in connection with checkout.

    3w

    checkout_session_token_<<token>>

    Used in connection with checkout.

    3w

    identity-state

    Used in connection with customer authentication

    24h

    identity-state-<<token>>

    Used in connection with customer authentication

    24h

    identity_customer_account_number

    Used in connection with customer authentication

    12w

    Reporting and Analytics

    Name

    Function

    Duration

    _landing_page

    Track landing pages.

    2w

    _orig_referrer

    Track landing pages.

    2w

    _s

    Shopify analytics.

    30min

    _shopify_d

    Shopify analytics.

    session

    _shopify_fs

    Shopify analytics.

    30min

    _shopify_s

    Shopify analytics.

    30min

    _shopify_sa_p

    Shopify analytics relating to marketing & referrals.

    30min

    _shopify_sa_t

    Shopify analytics relating to marketing & referrals.

    30min

    _shopify_y

    Shopify analytics.

    1y

    _y

    Shopify analytics.

    1y

    _shopify_evids

    Shopify analytics.

    session

    _shopify_ga

    Shopify and Google Analytics.

    session

    customer_auth_provider

    Shopify analytics.

    session

    customer_auth_session_created_at

    Shopify analytics.

    session

    The length of time that a cookie remains on your computer or mobile device depends on whether it is a “persistent” or “session” cookie. Session cookies last until you stop browsing and persistent cookies last until they expire or are deleted. Most of the cookies we use are persistent and will expire between 30 minutes and two years from the date they are downloaded to your device.

    You can control and manage cookies in various ways. Please keep in mind that removing or blocking cookies can negatively impact your user experience and parts of our website may no longer be fully accessible.

    Most browsers automatically accept cookies, but you can choose whether or not to accept cookies through your browser controls, often found in your browser’s “Tools” or “Preferences” menu. For more information on how to modify your browser settings or how to block, manage or filter cookies can be found in your browser’s help file or through such sites as:www.allaboutcookies.org.

    Additionally, please note that blocking cookies may not completely prevent how we share information with third parties such as our advertising partners. To exercise your rights or opt-out of certain uses of your information by these parties, please follow the instructions in the “Behavioural Advertising” section above.

    Do Not Track

    Please note that because there is no consistent industry understanding of how to respond to “Do Not Track” signals, we do not alter our data collection and usage practices when we detect such a signal from your browser.

    Changes

    We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons.

    Complaints

    As noted above, if you would like to make a complaint, please contact us first by e-mail or by mail using the details provided under “Contact” above.

    If you are not satisfied with our response to your complaint, you have the right to lodge your complaint with the relevant data protection authority. You can contact your local data protection authority, or our supervisory authority here: For the U.S. visithttps://reportfraud.ftc.gov/#/faq, read through the FAQ, and if applicable, file a report.

    Last updated:1/2/2023