Last updated: May 2, 2026
This Privacy Policy describes how GlowEngine, LLC (“GlowEngine,” “we,” “us,” or “our”) collects, uses, and shares information about you when you use the GlowEngine platform, including our web application, iOS app, Android app, and public booking pages (collectively, the “Service”).
GlowEngine is a practice management and booking platform for licensed medical spa and aesthetic practices. If you have questions about this policy, contact us at support@glowengine.ai.
GlowEngine serves two distinct groups:
Practitioners (our customers) are licensed practices and their staff who subscribe to GlowEngine to manage appointments, patients, billing, and communications. Practitioners control the data stored in their GlowEngine account.
Patients are the clients of those practices who may interact with GlowEngine through a practice’s public booking page, appointment reminders, or the practice’s use of the GlowEngine app. Patients are the customers of the practicing business, not of GlowEngine directly.
Under GDPR and similar frameworks, GlowEngine acts as a data processor (and the practice acts as the data controller) with respect to patient personal data that practices upload or collect through the Service. Practitioners are responsible for having a lawful basis to collect and process their patients’ data and for providing their patients with any required disclosures.
When a practice or provider creates a GlowEngine account, we collect:
Practitioners enter or import patient data into GlowEngine on behalf of their practice. This data may include:
When you use the Service, we collect:
When a patient books an appointment through a practice’s public booking page, we collect the information the patient submits: name, phone number, email address, and the selected service and time slot. This information is associated with the practice’s GlowEngine account.
We use the information we collect to:
We do not sell personal data. We do not use patient health or treatment data for advertising.
We share data with the following service providers as necessary to operate the Service:
| Sub-processor | Purpose | Data shared |
|---|---|---|
| Stripe, Inc. | Payment processing (practice subscriptions and patient payments via Stripe Connect) | Billing information, payment transaction data |
| Twilio Inc. | SMS appointment reminders and patient messaging | Patient phone number, message content |
| Amazon Web Services (AWS) | Cloud hosting (App Runner, RDS PostgreSQL), file storage (S3), and email delivery (SES) | All data stored or transmitted through the Service |
| Google LLC | Authentication via Google Sign-In | Practitioner Google account identifier and email |
| Apple Inc. | Authentication via Sign in with Apple | Practitioner Apple account identifier |
| Meta Platforms, Inc. (Facebook) | Authentication via Facebook Login | Practitioner Facebook account identifier |
We do not use Apollo Client Cloud or any third-party GraphQL analytics service; the Apollo SDK is used only for client-side network transport.
We may share information if required by law, legal process, or to protect the rights and safety of GlowEngine, our customers, or the public.
We retain practitioner account data for the life of the subscription plus a reasonable wind-down period (currently 90 days after account cancellation) to allow data export.
Patient appointment records, treatment notes, consent forms, and visit photographs are subject to medical records retention requirements that vary by state (typically 7 to 10 years for adults and longer for minors). Practices are responsible for ensuring their data retention and deletion practices comply with applicable law. GlowEngine will retain this data for at least the duration of the practice’s active subscription; practices may export their data at any time.
After the retention period, we delete or anonymize personal data.
GlowEngine may operate as a HIPAA Business Associate when the Service is used by a HIPAA-covered entity (such as a medical practice) to process protected health information. In that case, a Business Associate Agreement (BAA) is available upon request. Practices that are HIPAA-covered entities should request a BAA before uploading PHI to the Service.
GlowEngine implements administrative, technical, and physical safeguards consistent with HIPAA Security Rule requirements, including encrypted data storage (AES-256), encrypted data in transit (TLS 1.2+), access controls, and audit logging.
Depending on your location, you may have the following rights regarding your personal data:
Patients who wish to exercise these rights should contact the practice that holds their records. Practices can contact us at support@glowengine.ai for assistance.
The public booking page and web application use a session cookie to maintain login state. We do not use third-party advertising cookies or cross-site tracking on any GlowEngine page. We do not participate in cross-context behavioral advertising.
The Service is not directed at individuals under the age of 13 (or 16 for users in the EEA). We do not knowingly collect personal information from children. Practices that treat minor patients are responsible for obtaining any required parental consent for data processing.
We may update this Privacy Policy from time to time. If we make material changes, we will notify practitioners via email or a prominent notice in the app at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
For questions about this Privacy Policy or to exercise your rights, contact us:
GlowEngine
Email: support@glowengine.ai