Privacy Policy
Before + After (“Before + After,” “we,” “us,” or “our”) operates a marketplace that helps people discover aesthetic-treatment providers, evaluate services and results, request and manage bookings, make payments, and communicate with providers. This Privacy Policy explains how we collect, use, disclose, and retain personal information through trybeforeandafter.com, customer and provider accounts, and related communications and services (the “Service”).
This policy does not govern a provider’s independent clinical or business records. Providers are separate businesses and may have their own privacy practices. Review the privacy notice of the provider you choose.
1. Personal information we collect
The information we collect depends on how you use the Service.
Information you provide
- Contact and account information: name, email address, phone number, account identifiers, authentication records, and communication preferences.
- Booking and service information: the provider and service selected, requested or confirmed appointment time, treatment or service interest, booking status and history, notes you choose to submit, and acknowledgments or consents.
- Payment and transaction information: transaction amount, currency, status, refunds, disputes, and payment or payout identifiers supplied by Stripe. We do not receive or store full payment-card numbers.
- Communications and support: messages with us or a provider through the Service, support requests, and records of email or text-message delivery and preferences.
- Provider information: business and professional contact information, location, services and prices, professional credentials, ownership or team role, onboarding and verification information, and payout-readiness status. Stripe separately collects identity, banking, tax, and verification information needed for connected-account services.
Customer reviews and transformation-media submissions are not currently enabled. We will provide additional notice and choices before collecting customer-submitted review text or before-and-after media through those features.
Information collected automatically
- Device and network information: IP address, browser and device type, operating system, user agent, approximate location derived from IP, and security or fraud signals.
- Usage information: pages and provider profiles viewed, searches and filters, referral source, links or buttons selected, booking-funnel events, timestamps, and errors.
- Cookies and similar technologies: session and authentication cookies, referral-attribution cookies, marketing-attribution cookies, security controls, preference cookies, and analytics technologies.
Information from other sources
We may receive information from providers and customers involved in a booking; payment, communications, analytics, hosting, security, and support providers; publicly available professional-license sources, provider websites, business directories, and Google Business information; and referral links or partners.
Treatment-related and other sensitive information
Booking selections, treatment interests, communications, acknowledgments, account credentials, and payment-related information may be sensitive under some laws. We use this information only as reasonably necessary to provide, secure, support, and comply with law for the Service unless we first provide any additional notice or choice required by law.
Before + After is a marketplace, not your healthcare provider. We do not claim that all information handled by the Service is protected health information under HIPAA or exempt from consumer-privacy laws. Any HIPAA, California Confidentiality of Medical Information Act, or similar exemption depends on the specific information, entity, and circumstances.
2. How we use personal information
We use personal information to:
- provide search, discovery, booking, account, payment, support, and communication features;
- send booking confirmations, reminders, updates, authentication links, and other requested communications;
- share necessary booking information with the provider selected by the customer;
- process and reconcile payments, platform fees, provider transfers, refunds, disputes, and related records;
- verify and administer provider listings, credentials, ownership, eligibility, and payouts;
- secure accounts and bookings, prevent fraud and abuse, debug errors, and protect the Service;
- understand aggregate Service usage and improve product performance;
- comply with legal obligations, enforce agreements, and resolve disputes; and
- carry out another purpose described when the information is collected or at your direction.
We do not use sensitive personal information to infer characteristics about you for unrelated purposes.
3. How we disclose personal information
We may disclose personal information to:
- The provider you select: contact, booking, service, scheduling, payment-status, and communication information needed to fulfill the booking.
- Operational service providers: companies that provide hosting and databases, payment processing and connected-account onboarding, email and SMS delivery, analytics, error monitoring, security, and support. These currently include Google Cloud, Stripe, Resend, Google Analytics, and Sentry; Twilio is used when SMS service is enabled.
- Public-data providers: services such as Google Business or professional-license sources used to evaluate and maintain provider listings.
- Professional advisers and authorities: lawyers, accountants, auditors, insurers, regulators, courts, or law enforcement when reasonably necessary to comply with law or protect rights and safety.
- Business-transaction participants: parties involved in a proposed or completed financing, merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable confidentiality obligations.
- Others at your direction or with your consent.
We may use or disclose aggregated or deidentified information that cannot reasonably be linked to you.
4. California disclosures and choices
California law describes categories of personal information. During the preceding twelve months, the Service may have collected the following categories for the purposes described above: identifiers; customer records; commercial information; internet or network activity; approximate geolocation; professional information; inferences about service or provider interests; and sensitive personal information such as account credentials, treatment-related selections, and limited payment-account information handled by Stripe.
We collect these categories from you, your device, providers involved in a booking, operational service providers, and public sources. We disclose them for the operational purposes described above to the provider you select and to the applicable categories of service providers and other recipients described in Section 3.
We do not sell personal information for money. We do not currently use personal information for cross-context behavioral advertising. Our California Privacy Choices page lets you disable optional analytics on the Service and explains how to submit a request without creating an account.
Depending on which California laws apply to Before + After and to the particular information, California residents may request access to or a portable copy of eligible information, deletion, correction, information about our practices, or restriction of a legally covered sale, sharing, or use of sensitive personal information. We will not discriminate against you for making a privacy request. An authorized agent may submit a request as permitted by law, subject to appropriate proof of authority and verification.
Submit a request through California Privacy Choices or email privacy@trybeforeandafter.com. You do not need to create an account. We will verify requests in a way proportionate to the information requested and use verification information only for that purpose. We may retain information or deny part of a request where an exception applies, including transaction completion, security, fraud prevention, disputes, legal obligations, or protecting others’ rights.
We intend to acknowledge covered requests within 10 business days and respond within 45 calendar days. If additional time is permitted and reasonably necessary, we will explain the extension.
5. Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this policy. Retention depends on the record and may include the period needed to provide an account or booking, complete and document transactions, protect account and payment security, resolve support matters, refunds, chargebacks, or legal disputes, comply with tax, accounting, payment, and other obligations, and enforce agreements.
Security and diagnostic records generally have a shorter operational lifecycle than transaction, dispute, consent, or legal records. When information is no longer needed, we delete it, deidentify it, or isolate it from ordinary use as appropriate. Backups may persist for a limited recovery cycle before deletion.
6. Cookies, analytics, and browser privacy signals
We use necessary first-party cookies for authentication, security, referrals, marketing campaign attribution, and privacy preferences. We also use Google Analytics to understand Service usage. We do not currently use advertising pixels or third-party advertising networks for cross-context behavioral advertising.
The Service does not respond separately to the legacy “Do Not Track” browser signal because there is no generally accepted response standard. Other parties, including analytics providers, may collect information about activity over time and across websites subject to their own technologies and privacy notices.
We recognize the Global Privacy Control signal as a request to disable optional analytics on the browser sending the signal. Necessary authentication, security, booking, and payment processing continue to operate.
7. Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, encryption in transit, secrets management, environment separation, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Communications choices
Marketing email includes an unsubscribe method. You may opt out of SMS by replying STOP and request help by replying HELP. We may still send non-promotional communications reasonably necessary for an active booking, account, security event, or transaction, subject to applicable law.
9. Children
The Service is intended for adults and is not directed to children under 18. We do not knowingly collect personal information from children. Contact us if you believe a child submitted personal information so we can investigate.
10. Changes to this policy
We may update this policy as the Service and law change. We will post the revised policy with an updated “Last updated” date and provide additional notice when required. We will not use previously collected personal information for a materially different, unrelated purpose without any notice or consent required by law.
11. Contact us
Questions or privacy requests may be sent to:
Before + After
privacy@trybeforeandafter.com