Privacy Notice

Last Modified: August 27, 2025

1. INTRODUCTION.

AI Glow Track, LLC ("AIGlowTrack", "we", "our", or "us") respects your privacy and is committed to protecting it through our compliance with this Privacy Notice ("Notice"). We are committed to being transparent in our handling and processing of Personal Information in accordance with applicable privacy and data protection laws. This Privacy Notice and our WMHMD Notice are incorporated into our Terms of Service, which are available at https://www.aiglowtrack.com/privacy.

This Notice applies to you ("you" or "your") and anyone who accesses or uses our Services through https://www.aiglowtrack.com (our "Website(s)"), software, platforms, and mobile application ("App") (collectively, the "Services"), whether as a guest or registered user ("User(s)"). Users include: (i) individual consumers who self-register on the Services, and (ii) individuals who use the Services in connection with seeking or receiving medical care from a licensed medical professional ("Healthcare Provider(s)").

Please read this Notice carefully to understand how we collect, use, maintain, protect, and disclose your Personal Information (as defined below). If you do not agree with our terms, your choice is not to use our Services. By accessing or using this Website, you agree to this Privacy Notice.

This Notice may change from time to time (see Changes to Our Privacy Notice). Your continued access of our Services after we make changes is deemed to be acceptance of those changes, so please check the Last Modified Date at the top of this Notice, to ensure that you are viewing the most current version of this Notice.

2. CHILDREN'S PRIVACY.

The Service is general audience and intended for users 18 and older. We do not knowingly collect Personal Information from anyone younger than age 18.

3. HIPAA AND PHI.

Certain demographic, health and/or health-related information that AIGlowTrack collects about Users on behalf of the licensed medical professions that we partner with ("Healthcare Provider(s)") as part of providing the Services may be protected health information ("Protected Health Information" or "PHI") governed by the Health Insurance Portability and Accountability Act ("HIPAA"). Specifically, this may be true when (i) AIGlowTrack is providing administrative, operational, or other services to a Healthcare Provider that is a "Covered Entity" (as defined by HIPAA); and (ii) in order to provide those services, AIGlowTrack receives identifiable information about a User on behalf of the Healthcare Provider, where AIGlowTrack is acting as a "Business Associate" (as defined by HIPAA); and (iii) this identifiable information is regulated as PHI.

When you use AIGlowTrack directly (for example, by uploading your own photos or tracking your treatments), your health information is not subject to HIPAA because AIGlowTrack is not a Covered Entity or Business Associate. Even though HIPAA doesn't apply, we still take strong steps to protect your privacy and keep your information secure, as outlined in this Privacy Notice.

If you are using AIGlowTrack through your Healthcare Provider, your information may be protected by HIPAA as PHI. For Healthcare Provider-directed use, we act as a Business Associate under a signed Business Associate Agreement (BAA), ensuring HIPAA compliance with data encryption (AES-256, TLS 1.3). With respect to any PHI in our possession, you have certain rights under HIPAA as described in the Notice of Privacy Practices provided to you by your Healthcare Provider. Please refer to the applicable Notice of Privacy Practices of your Healthcare Provider for more information, including rights to access, amend, or request restrictions on PHI.

4. INFORMATION WE COLLECT ABOUT YOU AND HOW WE COLLECT IT.

Personal information generally means information that identifies (whether directly or indirectly) a particular individual, such as the individual's name, postal address, email address, and telephone number ("Personal Information"). We collect several types of Personal Information, such as Contact Information when you sign up for an account ("Account") or Aesthetic Information when you log treatments.

Other types of information we collect is information related to how you use our platform, which helps us improve our Services. We generally use Personal Information that we collect about you or that you provide to us to provide you with our Services.

You expressly consent to receiving communications from AIGlowTrack through the information you provided to us. Please review our Terms of Service for more information about our user guidelines. For more information on how to access and control your communication preferences, please see YOUR RIGHTS and the YOUR CHOICES REGARDING YOUR INFORMATION sections below.

When you provide us with information in connection with a particular activity or otherwise sign up for or order our products and Services or provide your contact information to us, including your email address or telephone number in connection with that activity, product or service, you agree that such action constitutes a purchase or inquiry establishing a business relationship with us.

5. INFORMATION PROVIDED BY YOU OR ON YOUR BEHALF.

The following table describes the Personal Information we collect from you or on your behalf when you use our Services.

Categories of Personal Information

Account Information:

  • Full Name
  • Email Address
  • Phone Number
  • Account credentials and authentication information
  • Profile information and preferences

Aesthetic Information:

  • Treatment Information (product, units, injection sites, treatment date, provider name, documents, satisfaction rating, post op instructions, and lab results)
  • Face Data (including photographs and Kesty AI (patent-pending)-enabled analysis results and recommendations)
  • Any other Health Information you choose to share with us in the "notes" sections of the patient Treatment Logging Form

Payment Information:

  • Full Name
  • Banking Information (i.e., credit/debit card number)
  • Shipping/Billing address

Healthcare Provider Account Information:

  • Full Name
  • Email Address
  • Licensure Information
  • Professional Background

How / When Personal Information is Collected

You input your contact information when filling out a questionnaire or a webform on our Services.

You input this information when you create an Account.

Face Data may be collected either through the in-app camera or via your device's camera on our Services when you upload a photo during your interaction with our services.

  • For clarity, we only use Face Data for analysis of skin conditions. We do not use Face Data for purposes of recognizing or identifying an individual customer.
  • In some jurisdictions, Face Data may be considered "biometric information". Biometric information means any information, regardless of how it is captured, converted, stored, or shared, based on an individual's biometric identifier used to identify an individual. If and to the extent that we collect Biometric Information, we only collect such information with your consent. You acknowledge and agree to AIGlowTrack, its affiliates, and service providers collecting, processing, and storing your Biometric Information for the purposes outlined in this Privacy Notice.

You provide Payment Information to purchase a subscription for the Services.

Note that we do not store Payment Information. We use third-party payment processors to process your Payment Information. For more information, see the HOW WE DISCLOSE AND SHARE YOUR INFORMATION section.

Purpose for Personal Information Collection

  • To provide the Services requested by you
  • To provide you with an Account
  • To connect you with a Healthcare Provider
  • To communicate with you about the Services you have requested
  • To provide you with customer support
  • To send communications about similar products and services, where appropriate, with the option to opt out at any time
  • To comply with applicable legal or regulatory requirements and law

We collect and use Face Data to personalize your skincare programs and provide treatment recommendations based on the visual analysis of your facial skin conditions, such as pimples, wrinkles, pigmentation, and others.

When you upload photos to AIGlowTrack, we use them to give you results through our AI Skin Analysis Feature. We also use your photos to help improve our AI so it can get better over time.

6. AUTOMATICALLY COLLECTED INFORMATION.

As you navigate through and interact with our Services, we and our third-party service providers may automatically collect certain information from you whenever you access or interact with the Services. We may combine this automatically collected log information with other information we collect about you. We do this to improve Services we offer you, analytics, and site functionality.

Categories of Personal Information

Usage Information:

Details of your visits to our Website or App (e.g. links you've clicked on, content response times, location data, logs, and other similar communication data and statistics about your interactions), geolocation data (with user consent).

Device Information:

Information about your computer and internet connection, including your device type, operating system, and browser type.

Purpose for Personal Information Collection

  • To analyze your use of the Services
  • To improve and develop our Website and Services and to enable us to offer new features and material
  • To comply with applicable legal or regulatory requirements and law enforcement requests
  • To protect the Services, our company, our employees, and our users from malicious attacks, hacking, fraud, or other illegal or unauthorized activity
  • To investigate and take steps to prevent potential fraud or other wrongdoing
  • To comply with and enforce our Terms of Service

This information is automatically collected when you visit our Services.

7. TRACKING TECHNOLOGIES.

We, as well as third parties that provide content, advertising, or other functionality on the Services, may use cookies, pixel tags, local storage, and other technologies ("Tracking Technologies") to automatically collect information through our Services. Tracking Technologies are essentially small data files placed on your computer, tablet, mobile phone, or other devices that allow us to record certain pieces of information whenever you visit or interact with our Site and Services. Depending on the specific Tracking Technology, we, our online data partners, or vendors may use Tracking Technologies to associate these activities with other Personal Information they or others have about you, including by association with your email or online profiles. We (or service providers on our behalf) may then send communications and marketing to these emails or profiles.

Pixel Tags/Web Beacons

A pixel tag (also known as a web beacon) is a piece of code embedded on the Website that collects information about users' engagement on that web page. The use of a pixel allows us to record, for example, that a user has visited a particular web page or clicked on a particular advertisement.

Cookies

A cookie is a small text file that can be stored on and accessed from your device when you visit and use our Website. We use cookies to analyze trends, administer the Website, and track users' movements around the site.

Please review your web browser settings to modify your cookie settings, to disable the use of cookies, or to delete cookies. Please note that third parties such as advertisers or analytics providers may also use cookies and similar technologies while you are browsing or using the Website. We unfortunately have no control over such third parties' use of these technologies.

Cookies can be categorized as first-party or third-party cookies. As the name implies, first-party cookies are put on your device by AIGlowTrack. Third-party cookies are placed on your device not by AIGlowTrack, but by a third-party. Third-party cookies may include the Tracking Technologies described below.

Analytics

We may use Tracking Technologies and other third-party tools to process analytics information about our Services. These Tracking Technologies are used by us and our third-party service providers to analyze how the Website is used and how the Website is performing. Tracking Technologies may collect information about your activities to provide you targeted advertising and to measure the effectiveness of our marketing campaigns. The third-party service providers that generate these Tracking Technologies, including, for example, Facebook, LinkedIn, and Google, have their own privacy policies, and may use their technologies to target advertising to you on other websites, based on your visit to our Website.

Tracking Technologies we use include:

  • Google Analytics: Google Analytics collects information such as how often users visit this Website, what pages they visit when they do so, and what other sites they used prior to coming to this Website. We use the information we get from Google Analytics only to improve our Services. Google Analytics collects only the IP address assigned to you on the date you visit this Website, rather than your name or other identifying information. We do not combine the information collected through the use of Google Analytics with personally identifiable information. Although Google Analytics plants a permanent cookie on your web browser to identify you as a unique user the next time you visit this Website, the cookie cannot be used by anyone but Google. Google's ability to use and share information collected by Google Analytics about your visits to this Website is governed by Google's Privacy Policy. You can prevent Google Analytics from recognizing you on return visits to this Website by disabling cookies on your browser.
  • Meta Pixel: We use Meta Pixel to customize our advertising and to serve you ads on your social media based on your browsing behavior. This allows your behavior to be tracked after you have been redirected to our Website by clicking on the Meta ad. The Meta Pixel stores a cookie on your device to enable us to measure the effectiveness of Meta ads for statistical and market research purposes. We do not have access to the information collected through the Meta Pixel. However, the information collected via the Meta Pixel is also stored and processed by Meta. Meta may link this information to your Meta account and also use it for its own promotional purposes in accordance with Meta's Privacy Policy. The Meta Pixel also allows Meta and its partners to show you advertisements on and outside of Meta. You can opt-out of displaying Meta ads by visiting your Meta Ad Settings, and you can clear and control the information third parties share with Meta in your Off-Meta Activity page. If you do not have a Meta account, you can opt-out of Meta ads through the Digital Advertising Alliance as describe below.

You can generally opt-out of receiving personalized ads from third-party advertisers and ad networks who are members of the Network Advertising Initiative (NAI) or who follow the Digital Advertising Alliance's Self-Regulatory Principles for Online Behavioral Advertising (DAA) by visiting the opt-out pages on the NAI website (http://optout.networkadvertising.org) and DAA website (http://www.aboutads.info/choices/).

8. DO NOT TRACK SIGNALS.

To the extent that we receive any Do-Not-Track signals, we will not comply with them as we do not track users' online activities over time and across third-party websites or online services.

9. PERSONAL INFORMATION PROVIDED BY THIRD PARTIES.

Third-Party Services

When you connect with us through a third-party platform we may, depending on your privacy settings, receive some information from your third-party account, and what we collect depends on your privacy settings with that service.

You may register to join the Services directly via the Website or by logging into your account with a third-party service ("TPS") via our Service (e.g., Facebook, Google, Apple, and other third-party services that let you sign in using your existing credentials with those services). If you choose to register via a TPS, or to later link your account with the Services to your account with an TPS, we will use the Personal Information you have provided to the TPS (such as your name, email address, and other information you make available via the TPS) to create your account. Note that the information we collect from and through a TPS may depend on the privacy settings you have set with the TPS and the permissions you grant to us in connection with linking your account with the Services to your account with an TPS. Other than what we may share with the TPS as described below, the Personal Information a TPS has about you is obtained by the TPS independent of our Services, and AIGlowTrack is not responsible for it.

10. HOW WE DISCLOSE AND SHARE YOUR INFORMATION.

We may share information we receive about you as follows or as otherwise described in this Privacy Notice. When we disclose Personal Information, the recipient is required to keep that Personal Information confidential, secure and process the Personal Information only for the specific purpose for which they are engaged:

  • With Healthcare Providers: We will share your Personal Information, including your Aesthetic Information and Face Data, with Healthcare Providers for the purposes of facilitating treatment and providing you with the Services you have requested. PHI disclosure with Healthcare Providers is governed by a BAA.
  • With Patients: If you are a Healthcare Provider with a registered account on the Services, we will share your Personal Information with Users who are patients to facilitate the patient provider relationship.
  • Service Providers: We employ the following third-party companies to provide Services on our behalf, to perform Services-related operations such as website maintenance, database management, web analytics, payment processing, or fraud detection:
  • Our Advertising Partners: As described above (see "Tracking Technologies") we partner with third party advertisers to display advertising on the Website. Our ad network partners use cookies and web beacons to collect user information about your activities on the Website and other websites to provide you targeted advertising based upon your interests.
  • Corporate Transactions: We may sell, transfer, or otherwise share some or all of our assets, including your Personal Information, in connection with a merger, acquisition, reorganization or sale of assets (including, in each case, as part of the due-diligence process with any potential acquiring entity) or in the event of bankruptcy.
  • If Required by Law: We will share Personal Information with government agencies as required by law in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. We may disclose any information about you to government or law enforcement officials or private parties as we, in our sole discretion, believe necessary or appropriate: (i) to enforce our Terms of Service; (ii) to respond to claims, legal process (including subpoenas); (iii) to protect our property, rights, and safety and the property, rights, and safety of a third-party, our users, or the public in general; (iv) to stop any activity that we consider illegal, unethical or legally actionable activity; and (v) as required in accordance with applicable local, state, or federal laws.
  • With your Consent: You may submit Personal Information to us through a form on the Services and consent to receive communication from us or our business affiliates and non-affiliates based on the information in the form. You may also choose to leave us a review via the Website, or through our business affiliates and non-affiliates based on your use of the Services.

11. YOUR CHOICES REGARDING YOUR INFORMATION.

You have several ways to exercise control over your information:

  • Account Settings: Registered Users may access, update, and delete their Personal Information by accessing their Account settings. Registered Users may also update their choices regarding the types of communications they receive from us through the online Account settings.
  • Device Settings: Registered users may also manage the privacy and visibility of their Personal Information through their device's system settings on Apple (iOS) or Android.
  • E-Mail: You may opt-out of receiving marketing emails from us by following the opt-out instructions provided in those emails. Please note that we reserve the right to send you certain communications relating to your Account or use of the Services (for example, administrative and service announcements) via email and other means and these transactional account messages may be unaffected if you opt-out from receiving marketing communications.
  • Providing Consent: You may choose whether to receive from us offers and promotions for our products and services, the products or services of third parties, or products and services that we think may be of interest to you, by providing your consent (for example, by clicking an unticked checkbox).
  • Contact Us: You may contact us to access, update or delete your personal information by contacting us at: privacy@aiglowtrack.com.

Please be aware that if you do not allow us to collect Personal Information from you, we may not be able to deliver certain experiences, products, or services to you, and some of our Services may not be able to take account of your interests and preferences.

12. SMS AND NOTIFICATION CONSENT.

By providing your phone number and opting in to receive notifications, you represent and warrant that you are the owner of, or otherwise authorized to provide, the phone number you provide, and that you consent to receive:

  • Account verification codes and security alerts
  • Treatment reminders (Botox, filler, laser maintenance, etc)
  • Appointment notifications and scheduling updates
  • Important account and service updates

Message and data rates may apply. You can opt out at any time by texting STOP to our messages or updating your notification preferences in your account settings.

SMS consent and phone numbers will never be shared with third parties or affiliates for marketing purposes. SMS opt-in data and phone numbers are used only to deliver transactional messages in connection with our platform.

13. YOUR RIGHTS REGARDING YOUR INFORMATION.

Depending on where you are located, you may have certain rights regarding your Personal Information (also known as "personal data" under applicable data protection laws). Residents of certain jurisdictions may access, correct, update or delete your Personal Information; object to our processing of this information, ask us to restrict our processing of your Personal Information, or request portability of your Personal Information. Please see YOUR RIGHTS REGARDING YOUR INFORMATION and the YOUR CHOICES REGARDING YOUR INFORMATION sections of this Notice to learn more about exercising your rights.

Upon request AIGlowTrack will provide you with information about whether we hold any of your Personal Information. You are responsible for maintaining the accuracy of the information you submit to us, such as your Contact Information. You may access, correct, or request deletion of your Personal Information by making updates to that information in your Account settings or by contacting AIGlowTrack. If you request to access all Personal Information you've submitted, we will respond to your request to access within the time period required by applicable law.

We will use commercially reasonable efforts to honor your requests for deletion; however, certain residual information may actively persist on the Services even if you close your account. In addition, the rights described above may be limited, for example, if fulfilling your request would reveal Personal Information about another person, or if you ask us to delete information, we are required by law to keep or have compelling legitimate interests in keeping (such as for fraud prevention purposes). Your Personal Information may remain in our archives and information you update or delete, or information within a closed account, may persist internally for our administrative purposes, to the extent permitted by law.

Please note that our Services require a minimum amount of Personal Information in order to function. Individuals who do not provide Personal Information (e.g., by not filling out a profile) may not be able to access the full functionality of features found on the Services.

14. California Residents – Your California Privacy Rights

If you are a California resident, the California Consumer Privacy Act ("CCPA") and California Consumer Privacy Rights Act, amending the CCPA ("CPRA") (collectively the CCPA and CPRA are the "California Privacy Laws") provide you with additional privacy rights with respect to our collection, use and disclosure of your Personal Information, including:

  • The right to know what Personal information we have collected and how we have used and disclosed that Personal Information in the 12-month period preceding your request.
    • We collected the following categories of Personal Information in the last 12 months: identifiers/contact information, customer records information, characteristics of protected classifications under California or federal law, payment card information associated with you, commercial information, customer records information, Internet or other electronic network activity information, geolocation data, audio, electronic, visual or similar information, and inferences drawn from the above.
  • The sources of Personal Information from whom we collected are directly from users, analytics tools, social networks, and third-party services that update or supplement information we hold about you.
    • Please see the above section within this Notice titled INFORMATION WE COLLECT ABOUT YOU AND HOW WE COLLECT IT to see the full list of categories of Personal Information we have collected about you.
    • Please see the above sections YOUR RIGHTS and the YOUR CHOICES REGARDING YOUR INFORMATION sections of this Notice to see applicable business or commercial uses and disclosures of your Personal Information.
  • The right to request deletion of your Personal Information.
  • The right to be free from discrimination related to the exercise of any of your privacy rights.
  • The right to opt out of the sale of your Personal Information, and to request information about whether we have sold your Personal Information in the past 12 months.
    • Pursuant to the definitions of "sale", under California Privacy Laws, we do not "sell" and have not "sold" Personal Information in the previous 12 months.
  • The right to correct inaccurate Personal Information.
  • The right to limit the use and disclosure of Sensitive Personal Information.
  • The right to access information related to and opt-out of the use of automated decision-making technology.

For more information on how to exercise any applicable rights you may have under California Privacy Laws, please contact us at privacy@aiglowtrack.com. Please note that we may require you to verify your credentials, by matching your e-mail address, or other account information to the information in our systems, before you can submit a request to exercise any of these rights. If you authorize another person to act as your agent to submit requests on your behalf, then unless you provide the agent with power of attorney under the California Probate Code, we will ask the agent to provide us the written and signed authorization that you provided to the agent, we will confirm with you that you did provide the authorization, and we will verify your identity.

15. WASHINGTON MY HEALTH MY DATA ACT.

To the extent that the Washington My Health My Data Act ("MHMD") applies to the Services, AIGlowTrack provides a My Health My Data Act Notice ("MHMD Notice"), hereby incorporated into this Privacy Notice by reference, for residents of the State of Washington in accordance with the My Health My Data Act of 2023 and sets out how AIGlowTrack collects, uses and discloses Consumer Health Data (as defined in the MHMD) that we collect from you when you use our Services. The MHMD Notice is available at: http://aiglowtrack.com/MHMD

16. FOR ANDROID USERS - GOOGLE PLAY DECLARATION FOR HEALTH APPS.

Our mobile apps interact with your camera roll only if you add a profile image to a profile in our mobile apps. Our mobile apps access, collect, use, and share your information (images and uploaded health files,) as stated above in the section titled, "WHAT INFORMATION IS COLLECTED AND HOW THAT INFORMATION IS COLLECTED AND USED." We also prominently highlight these uses, describe the type of data being accessed, and obtain your permission for these purposes as you use our mobile apps.

Our mobile apps only provide a technical mechanism for you to share Personal Information, including PHI, with your Healthcare Providers as a function of the patient and healthcare provider relationship.

17. INTERNATIONAL JURISDICTIONS.

Our Services are hosted and offered in the United States of America (US), and are subject to US federal, state, and local law. If you are accessing the Services from another country, please be advised that you may be transferring your personal information to us in the US, and you consent to that transfer, processing, and storage of your personal information in accordance with this Privacy Notice. You also agree to abide by the applicable laws of US federal, state, and local laws concerning your use of the Services and your agreements with us. Any persons accessing our Services from any jurisdiction with laws or regulations governing the use of the Internet, including the collection, use, or disclosure of Personal Information, different from those of the jurisdictions mentioned above may only use the Services in a manner lawful in their jurisdiction. If your use of the Services would be unlawful in your jurisdiction, you may not use our Services.

18. SECURITY

We use physical, technical, and organizational measures designed to protect your information against unauthorized access, theft, and loss. We restrict access to your personal information to those employees who need to know that information to service your account or perform their job functions. The following list describes the specific industry-standard security measures we utilize to protect your information:

  • AES-256 encryption for data at rest
  • TLS 1.3 encryption for data in transit
  • HIPAA-compliant cloud infrastructure
  • Regular security audits and monitoring
  • Access controls and authentication protocols
  • Secure photo storage with automatic backup

Although we take precautions intended to help protect information that we process, no system or electronic data transmission is completely secure. Any transmission of your personal data is at your own risk, and we expect that you will use appropriate security measures to protect your personal information.

You are responsible for maintaining the security of your account and the information in your account. We may suspend your use of all or part of the Services without notice if we suspect or detect any breach of security.

19. DATA RETENTION

Unless you request that we delete certain information (see YOUR RIGHTS REGARDING YOUR INFORMATION and the YOUR CHOICES REGARDING YOUR INFORMATION), we will retain your Personal Information for the period necessary to fulfill the purposes outlined in this Privacy Notice unless a longer retention period is required or permitted by law. The criteria used to determine our retention periods include:

  1. The length of time we have an ongoing relationship with you and provide services to you (for example, for as long as you have an account with us or keep using the Website);
  2. Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)
  3. Whether retention is advisable; and considering our legal position (such as, for statutes of limitations, litigation or regulatory investigations). For example, under HIPAA we may be required to retain certain PHI for six years unless we receive a request to delete the data.

20. THIRD-PARTY LINKS AND SERVICES.

The Services may contain links to third-party websites or services. When you click these links, you will be directed away from our Services. A link to a third-party website or service does not mean that we endorse it or the quality or accuracy of information presented on it. If you decide to visit a third-party website or service, you are subject to its privacy practices and policies, not ours. This Privacy Notice does not apply to any personal information that you provide to these other websites and services.

21. CHANGES TO THIS NOTICE.

AIGlowTrack may update this Privacy Notice at any time, and any changes will be effective upon posting. In the event that there are material changes to the way we treat your Personal Information, we will update the Last Modified date at the top of this Notice upon becoming effective. We may also notify you by email, in our discretion.

22. HOW TO CONTACT AIGLOWTRACK.

If you have any questions about this Privacy Notice, please contact us at:

AIGlowTrack Privacy Team

Email: privacy@aiglowtrack.com

Phone: 1-800-AIGLOW-1