MedSpa Compass

Legal

Privacy Policy

Last updated July 26, 2026.

This Privacy Policy explains how MedSpa Compass (“we”, “us”, “our”) collects, uses and protects personal information when you visit https://medspacompass.com. MedSpa Compass is an independent directory of med spas and aesthetic clinics. We are not affiliated with, do not own and do not endorse the businesses listed on the site.

1. Who we are

The data controller responsible for your personal information is:

WebMoose

Privacy contact: hello@medspacompass.com

We have not appointed a Data Protection Officer. Please direct all privacy questions to the email address above.

2. Information we collect

2.1 Information you provide

  • Contact form: your name, email address and the content of your message.
  • Listing submission or claim: the business name and details, and your name, role and contact details when you add or claim a clinic.
  • Newsletter (optional): your email address, if you choose to subscribe.

2.2 Information collected automatically

  • Server logs: IP address, browser/user-agent, request time and URL path, kept for security and diagnostics (via Cloudflare).
  • Cookies: see section 8.
  • Analytics (only with your consent, if enabled): anonymized usage statistics such as pages viewed and approximate location.
  • Directory interaction metrics (only with your consent): clicks on phone, website, email and directions links. A salted IP hash is kept for no more than five minutes solely to prevent duplicate counts; persistent event records contain the listing, interaction type and time, not the IP address.

2.3 Business directory data

The clinic names, addresses, phone numbers, websites, opening hours, ratings and review counts shown in our directory are compiled from publicly available sources - including Google Business Profile data (through our data provider, DataForSEO) and the businesses’ own websites. This may include a publicly displayed business email address and the URL where it was found. This is business contact information about the listed clinics, not personal data about you as a visitor. Business owners can claim, correct or request removal of a listing (see section 5).

3. How we use your information & legal bases

Under the EU/UK General Data Protection Regulation (GDPR), we rely on the following legal bases:

  • Responding to your inquiries - legitimate interest, or steps taken at your request (Art. 6(1)(b)/(f)).
  • Publishing and managing listings - legitimate interest in operating a business directory, or performance of a contract where you submit/claim a listing (Art. 6(1)(b)/(f)).
  • One-to-one business profile notices - legitimate interest in telling a listed business about its profile, corrections and a private directory audit (Art. 6(1)(f)). Every promotional profile message provides an immediate opt-out, and opted-out or bounced addresses are suppressed from future outreach.
  • Security and abuse prevention - legitimate interest (Art. 6(1)(f)).
  • Newsletter and analytics - your consent (Art. 6(1)(a)), which you can withdraw at any time.

4. Sharing and service providers

We do not sell your personal information. We share data only with providers who help us run the service:

  • Cloudflare, Inc. (USA) - hosting, content delivery (CDN), web application firewall, and the D1 database and R2 storage.
  • Resend, Inc. (USA) - delivery and delivery-status tracking for transactional and one-to-one business profile emails.
  • Analytics provider (only if analytics is enabled and you consent) - aggregated, anonymized usage statistics.

International transfers: these providers may process data in the United States. Transfers outside the European Economic Area are covered by the EU Standard Contractual Clauses and appropriate safeguards.

5. Business listings and public data

If you own or represent a clinic listed on MedSpa Compass and want to claim, correct or remove your listing, email hello@medspacompass.com. After we verify your connection to the business, we will update or remove the listing promptly.

6. Your rights

If you are in the EEA or UK, you have the right to access, rectify, erase, restrict or port your data, to object to processing based on legitimate interest, and to withdraw consent at any time.

If you are a California resident, you have the right to know what personal information we collect, to request deletion or correction, and to opt out of the sale or sharing of personal information. We do not sell or share personal information, and we will not discriminate against you for exercising your rights. Optional analytics remains off unless you consent. You can change that choice under Your Privacy Choices in the footer; we also honor Global Privacy Control (GPC) signals automatically.

To exercise any of these rights, email hello@medspacompass.com. We respond within 30 days.

7. Data retention

  • Contact messages - up to 12 months after our last correspondence.
  • Listing submissions - while the listing is published, plus a reasonable period afterwards for record-keeping.
  • Server logs - about 30 days (Cloudflare).
  • Newsletter - until you unsubscribe.
  • Business profile outreach records - up to 24 months for delivery history and duplicate-send prevention. Suppression records may be retained longer so we can continue honoring opt-outs and complaints.

8. Cookies

MedSpa Compass uses essential browser storage for your privacy preference. Google Analytics 4 is optional and is not loaded until you explicitly allow analytics.

  • Essential (always active): session and your saved privacy choice. The site does not work properly without them.
  • Analytics (Google Analytics): aggregated usage statistics, disabled by default and enabled only after your affirmative choice. Advertising storage and personalization remain disabled.

Use Your Privacy Choices in the footer to allow or withdraw analytics consent at any time. A Global Privacy Control (GPC) signal overrides a stored permission and keeps analytics off. We save the choice in this browser and apply it through Google Consent Mode v2.

9. Security

We use technical and organizational measures to protect data, including HTTPS/TLS encryption, restricted administrative access, a web application firewall, and Standard Contractual Clauses for transfers outside the EEA. No method of transmission over the internet is completely secure, but we work to protect your information.

10. Children

MedSpa Compass is intended for adults and is not directed to children under 16. We do not knowingly collect personal information from children.

11. Complaints

If you believe we have mishandled your personal information, please contact us first at hello@medspacompass.com. You may also contact a regulator:

  • United States: your state Attorney General or consumer-protection office. California residents may contact the California Privacy Protection Agency (cppa.ca.gov) or the California Attorney General (oag.ca.gov).
  • EEA / UK: your local data protection authority.

12. Changes to this policy

We may update this Privacy Policy from time to time. The version date at the top of this page will always reflect the latest revision, and we will communicate material changes where required.