$99 a month, forever — for the first 270 customers.  See pricing
Home
Features
Use Cases
Start a Business
Pricing
Resources
About
Contact
First 270: $99/mo Forever
Legal

Privacy Policy

How LashBooked collects, uses, and safeguards information across our marketing website and SaaS platform.

Effective August 13, 2026. Questions? Contact us at clients@illuminationlab.io. This Privacy Policy will be updated as our business evolves; we will revise the effective date and, where changes are material, provide additional notice.

1. Introduction

This Privacy Policy ("Policy") describes how Illumination Lab LLC, a Florida limited liability company doing business as "LashBooked" ("LashBooked," "we," "us," or "our"), collects, uses, discloses, and protects information in connection with (a) the marketing website located at https://lashbooked.com and any related web properties (the "Site"), and (b) the LashBooked software-as-a-service platform, including our CRM, messaging, scheduling, automation, marketing, and analytics tools built for lash & brow artists (collectively, the "Platform," and together with the Site, the "Services").

LashBooked is a business software and marketing service for beauty professionals. We are not a medical or healthcare provider, and the Services are not designed to collect or store medical records. For purposes of the GDPR and similar laws, Illumination Lab LLC acts as the controller of the personal information described in this Policy that we collect for our own purposes, and as a business under the California Consumer Privacy Act.

This Policy applies to prospective customers and website visitors, current customers of the Platform and their authorized users, job applicants, and other individuals who interact with us. When one of our customers (a lash & brow artist or studio) uploads or manages information about their own clients through the Platform, that customer is the controller of their client information and we act as a processor or service provider acting on their instructions. If you are a client of a studio that uses the Platform, please review that studio's own privacy notice, and direct requests about your information to the studio first.

2. Information We Collect

2.1 Account and Business Information You Provide

We collect information you submit to us when you:

  • Fill out a form on the Site, request a demo, subscribe to emails, or download a resource (e.g., name, email, phone number, business name, role, business size, and any message content you include).
  • Register for or administer a Platform account (e.g., account credentials, billing contact, business and tax identifiers, staff/team directory data, studio locations, and integration credentials).
  • Contact customer support or communicate with us by email, chat, phone, or social media (we may retain the content of those communications and any related attachments).
  • Submit billing information through our payment processor (we do not store full payment card numbers; see Section 4).
  • Participate in surveys, webinars, user research, or promotional events.

2.2 Client Contact Data You Import

The Platform is a CRM and marketing tool, so our customers import and manage information about their own clients and leads. This "Client Data" typically includes names, phone numbers, email addresses, appointment history, service preferences, notes the artist records, and message threads between the studio and its clients. Customers decide what Client Data to load into the Platform and are responsible for having the right to do so. We process Client Data only to provide the Services to the customer and as described in our agreement with them; we do not use Client Data for our own marketing.

2.3 Information Collected Automatically

When you visit the Site or use the Platform, we and our service providers may automatically collect:

  • Device and browser information such as IP address, device identifiers, operating system, browser type and version, language preferences, and referral URLs.
  • Usage and log data such as pages viewed, links clicked, features used, time spent, searches within the Platform, session identifiers, timestamps, crash reports, and diagnostic information.
  • Cookies, pixels, local storage, and similar technologies (see Section 6).
  • Approximate location derived from IP address.

2.4 Information From Third Parties

We may receive information about you from:

  • Integration partners you connect to your Platform account (e.g., Google, Meta, calendar and booking providers, review platforms, and other authorized integrations) — limited to the scopes you grant.
  • Analytics and marketing providers that help us measure campaign performance and improve the Site.
  • Our payment processor, which provides transaction metadata, authorization status, and fraud signals.
  • Messaging and email delivery vendors that return delivery, engagement, and error signals.
  • Publicly available sources and data enrichment vendors used for sales, marketing, and fraud-prevention purposes.

3. How We Use Information

We use the information we collect for the following purposes:

  • Service delivery. To provide, operate, maintain, secure, and improve the Services, including hosting customer content, routing messages, running automations, and reporting analytics.
  • Account management. To authenticate users, administer billing, enforce usage limits, and provide customer support.
  • Communications. To send transactional messages (receipts, security alerts, service notices) and, where permitted, marketing communications about new features, events, and resources. You can opt out of marketing messages at any time.
  • Product analytics and development. To understand how users interact with the Services, diagnose problems, and build new features. We may create aggregated or de-identified data that no longer identifies an individual; we may use and disclose such data for any lawful purpose.
  • Marketing and advertising. To measure the performance of our marketing, reach past visitors, and deliver relevant content.
  • Security and fraud prevention. To detect, investigate, and prevent abuse, security incidents, and unlawful activity, and to enforce our Terms of Service.
  • Legal and compliance. To comply with applicable laws, respond to lawful requests, and exercise or defend legal claims.

Where the GDPR or similar laws apply, we rely on one of the following lawful bases for processing: performance of a contract (to provide the Services you request), our legitimate interests (such as securing and improving the Services and marketing to businesses, balanced against your rights), your consent (for example, for certain cookies and marketing messages, which you may withdraw at any time), or compliance with a legal obligation.

4. How We Share Information

We do not sell personal information for monetary consideration, and we do not "share" personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act, except where you have opted in or where otherwise described in Section 6. We disclose information only as described below.

4.1 Service Providers, Processors, and Sub-Processors

We share information with vendors that perform services on our behalf under written contracts that restrict their use of the information. Categories include:

  • Hosting and infrastructure providers that store and serve the Services.
  • Payment processing providers that process card and bank transactions on our behalf (see Section 4.2).
  • Messaging and telephony providers that deliver SMS, MMS, and email on behalf of our customers.
  • Email delivery and marketing automation providers.
  • Analytics, product telemetry, and error-monitoring providers.
  • Customer support, CRM, and ticketing tools we use to help you.
  • Professional services firms (legal, accounting, auditors).

A current list of key sub-processors is available on request at clients@illuminationlab.io.

4.2 Payment Processing

Payments are handled by a third-party payment processor. When you provide payment details, that information is transmitted to and processed by the payment processor under its own terms and privacy policy. We receive limited transaction data (such as the last four digits of a card, authorization results, and billing metadata) and do not store full payment card numbers on our systems.

4.3 Business Transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of our assets, personal information may be transferred as part of the transaction, subject to customary confidentiality protections. We will notify affected users where required by law.

4.4 Legal Requirements and Protection of Rights

We may disclose information when we believe in good faith that disclosure is necessary to (a) comply with applicable law, subpoena, court order, or other legal process; (b) enforce our agreements or investigate potential violations; (c) protect the rights, property, safety, or security of LashBooked, our users, or the public; or (d) respond to an emergency.

4.5 With Your Consent or At Your Direction

We may share information with third parties when you authorize us to do so, including when you enable an integration or request that we transfer information to another service.

4.6 Aggregated or De-Identified Data

We may share aggregated or de-identified information that cannot reasonably be used to identify you.

5. Cookies and Similar Technologies

We use cookies and similar technologies to operate, analyze, secure, and market the Services. This section serves as our cookie policy. The categories we use include:

  • Strictly necessary. Required for core functionality such as authentication, session management, and load balancing. These cannot be disabled.
  • Functional. Remember your preferences and settings.
  • Analytics and performance. Help us understand how the Services are used so we can improve them.
  • Advertising and measurement. Measure the effectiveness of our marketing campaigns and, where permitted, deliver relevant ads on other sites.

You can control cookies through your browser settings, device controls, and our cookie preference tool (where available). You can also opt out of certain interest-based advertising through industry tools such as the Network Advertising Initiative (thenai.org/opt-out) and the Digital Advertising Alliance (optout.aboutads.info). We honor Global Privacy Control ("GPC") signals as an opt-out of sale/sharing for browsers that transmit them, consistent with applicable law. Disabling certain cookies may affect Site functionality.

6. Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law. Specifically:

  • Customer account data is retained for the duration of the subscription and for a reasonable period afterward to support wind-down, dispute resolution, and legal obligations. Retention of the Client Data our customers import is further governed by the Terms of Service and our agreement with the customer.
  • Marketing inquiry data (e.g., demo requests, newsletter signups) is retained for a reasonable period unless you ask us to delete it or unsubscribe.
  • Website logs and security data are retained for a limited period sufficient to support troubleshooting, analytics, and incident response.
  • Billing and tax records are retained for the periods required under applicable tax, accounting, and commercial laws.

When personal information is no longer needed, we will delete, anonymize, or de-identify it in accordance with our data retention and disposal procedures.

7. Data Security

We maintain administrative, technical, and physical safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These safeguards include encryption of data in transit and, where applicable, at rest; role-based access controls and least-privilege principles; secure software development practices; logging and monitoring; vendor security assessments; and employee training. Despite these efforts, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.

8. GDPR Rights (EU, UK, and Switzerland)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have rights under the GDPR and UK GDPR, including the rights of access, rectification, erasure, restriction of processing, data portability, and objection, as well as the right to withdraw consent at any time and the right to lodge a complaint with your local supervisory authority.

Legal bases. As described in Section 3, we identify a lawful basis for each processing activity — typically performance of a contract, our legitimate interests, your consent, or compliance with a legal obligation.

International transfers. LashBooked is operated from the United States, and your information will be transferred to and processed in the United States and in other countries where our service providers operate. Where we transfer personal data outside the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. A copy of the relevant safeguards is available on request.

To exercise any of these rights, contact us at clients@illuminationlab.io. If your personal information was provided to a studio that uses the Platform, we will refer your request to that studio as the controller and assist them as their processor.

9. CCPA/CPRA Rights (California)

If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the CPRA, subject to verification and applicable exceptions:

  • Right to know the categories and specific pieces of personal information we have collected, the sources, the business or commercial purposes for collecting it, and the categories of third parties with whom we share it.
  • Right to delete personal information we have collected from you.
  • Right to correct inaccurate personal information.
  • Right to opt out of the "sale" or "sharing" of personal information. As stated above, we do not sell personal information and do not share it for cross-context behavioral advertising, except as disclosed in Section 5 regarding advertising cookies where applicable; you may opt out at any time using our cookie preference tool or by sending a GPC signal.
  • Right to limit use of sensitive personal information to the purposes necessary to provide the Services.
  • Right to non-discrimination for exercising your rights — we will not deny you services, charge different prices, or provide a different level of service because you exercised your CCPA rights.

Categories of personal information. In the preceding 12 months we may have collected the following categories: identifiers (such as name, email, and phone number); commercial information (such as subscription and billing records); internet or network activity (such as usage and log data); geolocation data (approximate, from IP address); and professional or business information. The sources and purposes for each are described in Sections 2 and 3.

To exercise these rights, email clients@illuminationlab.io or submit a request through our contact page. We will verify your identity before responding. You may designate an authorized agent to make requests on your behalf; we will require written authorization and verification. If we deny your request, you may appeal by emailing clients@illuminationlab.io with the subject line "Privacy Appeal."

9.1 Residents of Other U.S. States

Residents of other U.S. states that have enacted comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others — may have similar rights to access, correct, delete, obtain a portable copy of, and opt out of certain processing (including targeted advertising, "sale" of personal data, and profiling that produces legal or similarly significant effects). To exercise these rights, contact us at clients@illuminationlab.io. Where applicable state law provides an appeal mechanism, you may appeal a denial by replying to our response.

10. Children's Privacy

The Services are intended for business use by lash & brow professionals and are not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact clients@illuminationlab.io and we will take appropriate steps to delete it.

11. Third-Party Links and Services

The Services may contain links to third-party websites, products, or services that we do not own or control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy notices of any third-party services you access.

12. Changes to This Policy

We may update this Policy from time to time. When we do, we will revise the effective date above. If the changes are material, we will provide additional notice (for example, through the Platform, by email, or through a prominent Site banner). Your continued use of the Services after the revised Policy becomes effective constitutes acceptance of the changes.

13. Contact Us

If you have questions, concerns, or complaints about this Policy or our privacy practices, contact us at:

  • Email: clients@illuminationlab.io
  • Entity: Illumination Lab LLC (Florida)

For data protection inquiries from residents of the EU, UK, or Switzerland, please use the email address above and include "Data Protection Inquiry" in the subject line.

See also: Terms of Service.