Privacy
Privacy Policy
How Lash Her by Nataliea collects, uses, discloses, safeguards, retains, and provides choices concerning personal information, including Google Account and Calendar information.
Last updated July 29, 2026
This Privacy Policy explains how **Lash Her by Nataliea** (“Lash Her,” “we,” “us,” or “our”) handles personal information through `lashher.com`, our booking and checkout services, communications, training services, and the private Lash Her staff application.
Personal information means information about an identifiable individual. It does not include information that has been aggregated or de-identified so that it cannot reasonably be associated with an individual.
Information we collect
Website, device, and security information:
When you visit or use the website, our hosting and security systems may process:
- the page or route requested, date and time, referring page, and request status;
- IP address, browser, device type, operating system, and approximate location derived from a request;
- security, fraud-prevention, rate-limit, firewall, and diagnostic information; and
- performance measurements such as page-load and Core Web Vitals data.
If you choose analytics, Vercel Web Analytics also processes page views, routes, referrers, approximate location, browser, operating system, and device category for aggregated website reporting.
Inquiries and marketing
Depending on the form you use, we may collect your name, email address, phone number, Instagram account, location, selected training program, message, source page, marketing choice, the wording presented with that choice, and consent or unsubscribe timestamps.
The contact subscription popup is a marketing subscription. Submitting it records an affirmative marketing choice. Other inquiry and booking forms let you make a separate marketing choice.
Service bookings
For a booking, we may collect:
- name, email address, and phone number;
- selected service, add-ons, requested appointment time, and time zone;
- answers to booking and service-intake questions;
- booking, hold, confirmation, cancellation, failure, and customer-support information;
- marketing choice; and
- payment, policy-acceptance, and Calendar synchronization information.
Booking intake answers may contain information about sensitivities, allergies, prior services, or other matters relevant to providing the requested service. Do not provide information that is not relevant to the service.
Product orders and training
For product orders and training enrollment, we may collect:
- purchaser name, email address, and other contact details;
- cart contents, selected product or program, quantity, price, discount or promotion code, tax, and payment status;
- a product delivery address;
- training scheduling information and the status or expiry of a scheduling link; and
- confirmation, fulfillment, notification, refund, failure, and support information.
Payments and saved payment methods
Payment entry is handled through Square or Helcim. Lash Her does not intentionally receive or store a complete card number or card security code in its application database.
We do store payment-provider references and transaction information needed to reconcile payments, address disputes, issue permitted refunds, and maintain records. For service bookings where the customer expressly authorizes card storage for a potential no-show or late-cancellation charge, we may store the Square customer and card references, card brand, last four digits, expiry information, billing postal code, maximum authorized amount, accepted policy version and text hash, acceptance time, and hashed network or device evidence.
Staff and administrative information
For approved employees and contractors, we may collect staff contact information, role, access status, resource and calendar assignments, sign-in and connection history, administrative actions, audit reasons and metadata, and hashed IP-address or user-agent evidence where used for security and accountability.
Google Account and Calendar information
The private contractor booking management application uses two separate Google authorization functions.
For Google Sign-In, Lash Her requests `openid`, `profile`, and `email`. We receive a stable Google Account identifier, primary email address, email-verification status, name, and profile image where available. We use that information to authenticate the staff member, associate the Google Account with an approved Lash Her staff account, enforce staff access, and display account information.
An authorized contractor member may separately connect Google Calendar. That connection requests `openid`, `email`, `calendar.calendarlist.readonly`, and `calendar.events`. Through these permissions, Lash Her may process:
- the connected Google Account identifier and email address;
- OAuth access and refresh credentials and the scopes granted;
- calendar identifiers, names or labels, descriptions, time zones, access roles, primary-calendar status, and other CalendarList metadata returned by Google;
- the calendar selected or assigned for Lash Her bookings;
- event identifiers, titles, descriptions, locations, status, visibility, start and end times, recurrence, organizers, attendees, conferencing and attachment information, reminders, and extended properties returned during availability and conflict checks;
- private identifiers used to find Lash Her-created booking events; and- identifiers and contents of appointment events created by Lash Her.
Lash Her-created appointment events may contain the customer’s name, email address, phone number, service and appointment details, booking intake questions and answers, add-on or payment-status wording, internal booking and order references, and the customer as an attendee.
The selected staff calendar can contain both Lash Her and non-Lash-Her events. The current integration does not limit Google’s responses with partial-response field masks. The application uses calendar identifiers, labels, access roles and primary status for selection, and event identifiers, titles, start times and end times for availability and duplicate detection. It does not intentionally retain other returned fields as booking records.
The current integration creates appointment events. It does not automatically update or delete an existing Google Calendar event when an appointment is later changed or cancelled.
How we use personal information
We use personal information to:
- provide, administer, and secure the website and staff application;
- respond to inquiries and customer-support requests;
- create and manage booking holds, appointments, customer communications, and Calendar events;
- process and reconcile product, service, and training payments;
- store a payment method and apply an authorized no-show or late-cancellation charge where the customer expressly accepted the applicable policy;
- prepare and communicate about product fulfillment;
- administer training enrollment and scheduling;
- authenticate staff and enforce role-based access;
- send transactional messages and, with the required consent, marketing messages;
- remember cart, consent, and interface choices;
- measure website usage and performance;
- detect, prevent, and investigate fraud, abuse, security incidents, and technical failures;
- maintain accounting, tax, consent, audit, and dispute records; and
- comply with legal obligations and enforce applicable agreements.
We may use de-identified or aggregated information for reporting, capacity planning, troubleshooting, and service improvement where the information cannot reasonably identify an individual.
Google API data: use and Limited Use
Lash Her uses Google Account and Calendar information only to:
- authenticate authorized staff and associate the correct Google Account with a staff record;
- display basic staff identity information;
- let authorized staff select an available booking calendar;
- assess availability and identify potential scheduling conflicts from events returned by Google;
- find existing Lash Her booking events and avoid duplicates;
- create confirmed Lash Her appointment events; and
- secure, troubleshoot, and maintain these functions.
Lash Her does not sell Google user data or disclose it to advertising platforms, data brokers, or information resellers. We do not use Google user data for targeted, personalized, retargeted, or interest-based advertising, credit or lending decisions, surveillance, or training or improving generalized artificial-intelligence or machine-learning models.
We disclose Google user data only to service providers acting on our instructions where necessary to host, secure, maintain, and provide the staff booking and Calendar functions; where necessary to investigate security or abuse; where required by law; or in another circumstance expressly permitted by the Google API Services User Data Policy. Providers receiving this information are limited to the access and purposes needed to perform their services.
Lash Her personnel do not read unrelated Calendar event data except where the staff member expressly authorizes access to specific data for a support request, where necessary for security or abuse investigation, or where required by law. Google user data is not transferred as part of a sale, merger, acquisition, or other change of control without the explicit prior consent required by Google’s policies.
Lash Her’s use of information received from Google APIs will adhere to the [Google API Services User Data Policy], including the Limited Use requirements.
More detail is available on the [Lash Her Google Integration].
Cookies, local storage, analytics, and performance
The website uses browser storage and similar technologies for functions such as:
- keeping a shopping cart, generally for up to 30 days;- maintaining booking and checkout state;
- remembering the cookie and analytics choice;
- maintaining authenticated staff sessions and security controls; and
- remembering that a marketing popup was dismissed, generally for 30 days.
The saved cookie preference records that required storage is enabled, whether analytics was accepted, when the choice was made, and the preference format version. It remains in local storage until the browser or user removes it.
Vercel Web Analytics loads only after an affirmative analytics choice. It is configured for aggregated reporting and does not use third-party advertising cookies. If analytics permission is withdrawn during a visit, the application removes the injected analytics script, although information already sent cannot be recalled.
Vercel Speed Insights is currently used independently of the analytics choice to collect real-user performance measurements such as Core Web Vitals. Hosting, security, and request logs also operate regardless of the analytics choice because they support delivery and protection of the service.
The current website does not provide a permanent on-page preference centre after a choice is saved. You can remove the saved choice, cart, and similar local information through your browser’s controls for site data. On a later visit, the website may ask for the choice again.
When we disclose information
We do not sell or rent personal information.
We may disclose information to:
- Google, for approved staff identity and Calendar functionality;
- Square, for service payments, customer and saved-card references, invoices, authorized no-show charges, and certain training payment options;
- Helcim, for product, training, and other configured payment sessions and transaction processing;
- Resend, for transactional email and consented marketing contact management;
- Vercel, for website hosting, delivery, security, Web Analytics, and Speed Insights;
- Sanity, for public content management and controlled handling of any historical form records that remain during migration or retention;
- database, cache, storage, observability, and security providers that support the application;
- professional advisers, insurers, auditors, or payment and fraud specialists where reasonably necessary; and
- courts, regulators, law enforcement, or other parties where required or permitted by law.
If the business is reorganized, financed, sold, or transferred, relevant non-Google information may be disclosed under appropriate confidentiality and legal controls as part of evaluating or completing that transaction. Google user data remains subject to the stricter transfer restrictions stated in the Google API data section.
Payment providers, Google, and other third parties may also process information under their own terms and privacy notices when they act independently rather than solely on Lash Her’s instructions.
Processing outside Ontario or Canada
Some service providers may process or store information in Canada, the United States, or other countries where they or their subprocessors operate. Information processed outside your province or country may be subject to the laws and lawful access processes of that jurisdiction. We use contractual, access, and security controls appropriate to the service and information, but laws and protections can differ between jurisdictions.
Retention and deletion
We retain personal information only for as long as reasonably needed for the purposes described in this Policy, including providing services, maintaining security, resolving disputes, enforcing agreements, and meeting tax, accounting, consent, and other legal obligations. We then delete, redact, or de-identify it where feasible. A legal hold, active dispute, security investigation, failed processing state, or provider limitation may extend a period.
The application is configured with the following principal retention targets. These schedules depend on successful operation of the automated retention process and do not describe provider-side backups. A failed or unresolved processing state may delay a scheduled action:
- abandoned booking holds without an order are deleted after 30 days;- terminal booking holds are redacted after 180 days and deleted after 730 days;
- identity, intake, and operational free text in terminal appointment records are redacted after 395 days;
- stored payment-event payload fields are scrubbed after 90 days and payment-event rows are deleted after 730 days;
- terminal checkout orders are redacted after 395 days, soft-deleted after 2,555 days, and purged after a further 30-day grace period;
- terminal training enrollment records are redacted after 395 days and deleted after 2,555 days;
- non-consenting marketing-form submissions are deleted after 180 days and consenting submissions are redacted after 395 days;
- inactive marketing contact profile fields are redacted after 730 days;
- unsubscribed marketing contacts, marketing consent events, and terminal marketing synchronization records are deleted after 2,555 days, with synchronization payloads redacted earlier; and
- unused training scheduling links expire at the expiry time assigned to the link.
Other records, including staff access and audit records, Calendar connection metadata, appointment-to-Calendar mappings, payment attempts, provider customer or saved-card references, and policy-acceptance evidence, do not all use one automatic deletion period. We retain those records based on the active account or appointment, security and audit requirements, payment disputes and chargebacks, consent evidence, and applicable legal obligations, and delete or de-identify them when they are no longer reasonably required.
For the current employee Calendar connection, the credential is normally retained while the connection remains active. When an authorized user disconnects it, Lash Her removes the locally stored credential and attempts revocation with Google. Account identifiers, scope and assignment history, audit information, and identifiers of appointment events already created may remain for the purposes described above. Disconnecting does not remove existing events from Google Calendar or delete separate booking, payment, tax, or customer records.
Retention in provider systems and backups may continue for a limited period according to provider backup, security, fraud-prevention, and legal processes.
Safeguards
We use administrative, technical, and physical safeguards appropriate to the nature of the information. These include access controls, staff authorization checks, secure network transport, restricted server-side secrets, encryption for credentials stored through the current employee Calendar connection, hashed network or device evidence for certain audit records, provider tokenization for payment cards, logging controls, and redaction or deletion processes.
No system or transmission method is completely secure. If you believe information has been accessed or used improperly, contact us promptly.
Your choices and privacy rights
Subject to identity verification and applicable legal exceptions, you may ask us to:
- explain whether we hold personal information about you;- provide access to that information;
- correct inaccurate or incomplete information;
- withdraw consent for future processing that depends on consent;
- delete information that is no longer required; or
- provide information about our service providers and privacy practices.
Withdrawing consent does not invalidate earlier permitted processing and may prevent us from providing a feature that requires the information.
You may unsubscribe from marketing through the unsubscribe control in a message or by contacting us. We process valid electronic-message unsubscribe requests without charge and within the period required by applicable law. Transactional messages about an order, appointment, payment, security issue, or requested service may still be sent.
Authorized staff may disconnect an eligible Calendar connection through the staff account or remove Lash Her from [Google Account connections]. Removing access stops future use of that authorization but does not itself delete information previously received by Lash Her or events already created in Google Calendar. A separate deletion request may therefore be necessary.
If you are under the age of majority where you live, use booking, checkout, or training features with the involvement of a parent or legal guardian where required. A parent or guardian who believes a minor’s information was provided improperly may contact us.
Changes to this Policy
We may update this Policy when our services, providers, practices, or legal obligations change. We will post the revised version at this URL and update the effective date. If a change materially affects how we use information already collected, we will provide additional notice or request consent where required.
Contact and complaints
For a privacy request, question, or complaint, contact:
Lash Her by Nataliea
Attention: Privacy Lead
Email: lashher@lashher.com
Ontario, Canada
Please describe the request and the information or interaction involved. We may ask for information needed to verify your identity and protect against unauthorized disclosure.
If a concern is not resolved, you may contact the [Office of the Privacy Commissioner of Canada].