Effective Date: January 1, 2025
Massage & Wellness Collective

Welcome! This Privacy Policy (“Policy”) describes how Massage & Wellness Collective (“Massage & Wellness,” “we,” “our,” or “us”) collects, uses, and shares your personal information. It also outlines your rights and choices regarding your data. Please read this Policy carefully.

Who We Are

This Policy applies to Massage & Wellness Collective, located in Portsmouth, NH.
Contact us at:

Scope of This Policy

Applies to your use of:

Personal Data We Collect

We may collect:

  • Identity Data: Name, date of birth, gender

  • Contact Data: Email, phone, mailing address

  • Commercial Data: Appointment history, payments

  • Device/Network Data: IP address, browser type, cookies

  • User Content: Messages, reviews, form entries

How We Collect Data

  • You provide it directly, when booking appointments or contacting us

  • Collected automatically, via cookies and device data

  • From service providers, like payment & scheduling platforms

How We Use Your Data

We use data to:

  • Manage and confirm appointments

  • Respond to inquiries

  • Process payments & issue receipts

  • Send updates and promotional messages (with consent)

  • Improve website and service experience

Cookies & Analytics

  • We use cookies for traffic analysis, personalization, and functionality

  • You can manage cookies through your browser

  • We may use tools like Google Analytics

Data Sharing

We do not sell your personal data. We may share it with:

  • Service providers (e.g., payment processors, website hosts)

  • Legal authorities, as required by law

  • Business partners, only for services you’ve requested

Consumer Rights & Choices

Depending on your location, you have rights to:

  • Access, correct, delete, or obtain a copy of your data

  • Object to or withdraw consent

  • Opt out of marketing emails anytime

  • Exercise additional rights under state laws (see below)

Request details or opt-outmassageandwellnesscollective@gmail.com

New Hampshire (NH)

If we meet statutory thresholds for NH residents (35,000+ per year or 10,000+ with ≥25% revenue from selling data), we additionally:

  • Provide notice of targeted advertising and personal data sales

  • Require opt-in consent for sensitive data

  • Honor Global Privacy Control or similar opt-out signals

  • Respond to rights requests within 45 days (plus one 45-day extension)

  • Conduct Data Protection Impact Assessments for high-risk processing

Massachusetts (MA)

We comply with MA obligations by:

  • Maintaining a Written Information Security Program (WISP) per 201 CMR 17.00, including risk assessments, encryption, access controls, and security training

  • Following MA breach notification law (MGL c. 93H), notifying affected residents as required

Data Security

We implement administrative, technical, and physical safeguards to protect personal data. While no system is fully secure, we strive to protect your information.

Data Retention

We keep personal data only as long as necessary to:

  • Provide services

  • Comply with legal requirements

  • Resolve disputes or enforce agreements

Minors

Our services are not intended for individuals under 16 without parental or guardian authorization. If we learn of any unauthorized collection, we promptly delete that data.

Policy Updates

We may update this Policy occasionally. Changes will be posted on this page with the revised effective date. Continued use indicates acceptance.

Contact Us

For questions, requests, or concerns, please reach out: