SpaSeen

Privacy Policy

Effective August 17, 2026 · Last updated August 17, 2026

This policy explains what SpaSeen (“SpaSeen,” “we,” “us”) collects, why we collect it, who else sees it, and how to have it removed. SpaSeen is a business-to-business service and collects very little personal information. There is no advertising network, no tracking pixel, and nothing is sold.

01Who this policy covers

This policy applies to three groups of people, who are treated differently:

  • Customers — people with a SpaSeen account.
  • Visitors to this website — anyone reading these pages.
  • Businesses we analyse — clinics examined using publicly available information, including businesses that are not customers. Section 6 covers this directly, because it is the part most policies leave out.

02What we collect

Account information

An email address and a password, handled by our authentication provider. Passwords are stored by that provider in hashed form; we never see or store your password in readable form.

Business profile information you enter

The details needed to run checks on a clinic: business name, address, city, phone number, website address, the treatments offered, and competitors you want tracked.

You may also enter details about individual practitioners — name, credentials and a short biography. This is the only routinely personal information in the service, and it is information a clinic normally publishes about its own staff. Do not enter anything about a person that you would not publish on the clinic’s own website.

Billing information

Subscriptions are billed through Stripe. Stripe collects and stores your payment details directly. We receive confirmation of a subscription’s status and the limited billing details Stripe passes back — never your full card number.

Information the service produces

The questions asked of AI assistants, the answers those assistants returned, whether a business was named in each answer, the other businesses named alongside it, and the findings produced by examining a website and its public listings.

Technical information

Our hosting provider records standard server logs — IP address, browser type, page requested, timestamp — for security and reliability. We use one category of cookie: an essential cookie that keeps you signed in. There are no analytics cookies, no advertising cookies, and no third-party trackers on this site.

03Why we use it

  • To run the checks you asked for and produce your reports.
  • To keep your account working, and to sign you in.
  • To bill your subscription and keep records of payment.
  • To answer your support emails.
  • To keep the service secure, and to detect and prevent abuse.
  • To improve how accurately the checks work — in aggregate, and in a form that does not identify you.
  • To comply with the law, and to establish or defend legal claims.

We do not use your information to train our own AI models, and we do not use it to advertise to you or to anyone else.

04Who else sees it

We do not sell personal information, and we do not share it for advertising. We share information only with the companies that make the service work, each of which is contractually limited to processing it on our instructions:

  • Supabase Database hosting and account authentication.
  • Vercel Application hosting and delivery.
  • Stripe Subscription billing and payment processing.
  • Anthropic, OpenAI, Perplexity and Google The AI assistants SpaSeen queries on your behalf, and the models used to read those answers back.
  • Google Maps Platform Looking up publicly listed business information, such as a Google Business Profile.

What actually reaches the AI providers is narrow and worth being specific about: the text of a patient-style question, and the answer that came back so it can be read for mentions. Your account email, your billing details and your login are not sent to them. The questions themselves are generic — “best med spa in Phoenix” — and deliberately do not contain the client’s name.

We may also disclose information if legally required, or in connection with a merger, acquisition or sale of assets — in which case this policy continues to apply until you are given notice of a new one.

05How long we keep it

Account and clinic information is kept while your account is open. The history of checks is kept while your account is open, because visibility over time is the point of the product — a record with the history deleted is not useful.

When you close your account, we delete or anonymise your information within 90 days, except where we must keep records longer for tax, accounting or legal reasons. Billing records are kept as long as the law requires.

06Businesses we analyse who are not customers

The diagnostic checks work on any clinic’s public footprint, and we use them to prepare example analyses for businesses that have not signed up. Being straightforward about this matters more than being quiet about it.

What this involves, and what it does not:

  • We read publicly available information only — a website exactly as any visitor or search engine crawler sees it, and publicly listed business details such as a Google Business Profile.
  • We request no credential, no login, and no permission-based access of any kind, and we could not obtain one if we wanted to.
  • We identify ourselves honestly to web servers and respect a site's stated crawling preferences.
  • The information involved is business information — a clinic's name, address, phone number, opening hours, published pages. We do not seek out personal information about individuals.
  • We do not store the underlying third-party content itself. What is kept is our own assessment of it.

If you operate a business we have analysed and you want it removed, or you want to know what we hold, email matthew@spaseen.com. Say which business, and we will delete it. We do not require a reason and will not argue about it.

07Your rights and choices

Whoever you are and wherever you live, you can ask us to show you what we hold about you, correct it, delete it, or send you a copy. Email matthew@spaseen.com and we will respond within 30 days. We may need to confirm your identity before acting, to be sure we are not disclosing your information to someone else.

If you are in a place with specific privacy laws — California, or the European Economic Area and the United Kingdom among others — you may have additional rights, such as the right to object to certain processing or to complain to a supervisory authority. We extend the practical rights above to everyone rather than making them depend on where you live. We do not sell or share personal information as those terms are defined under California law.

08Security

Traffic to the service is encrypted in transit. The database enforces access rules at the row level, so an account can only read the clinics it owns, and that restriction is applied by the database itself rather than by application code alone. Access to production systems is limited.

No service can promise perfect security, and we will not claim otherwise. If a breach affects your information, we will notify you and any regulator that must be told, as the law requires.

09Where information is processed

SpaSeen is operated from the United States, and information is processed there and in other countries where our providers operate. If you use the service from elsewhere, you understand your information will be processed in the United States, where privacy laws may differ from those in your country.

10Children

The service is for businesses and is not directed to anyone under 18. We do not knowingly collect information from children. If you believe a child has provided us information, email us and we will delete it.

11Changes to this policy

We may update this policy. The date at the top always reflects the current version, and material changes will be notified by email or in the service before they take effect.

12Contact

Questions, requests, or a deletion request: matthew@spaseen.com. See also our Terms of Service.