Policies

Privacy Policy

How we collect, use, and protect your personal information. Compliant with Canada’s PIPEDA and Ontario’s privacy laws.

Last updated: May 2026

2. What we collect

  • Booking info: name, email, phone, address (when applicable), service requested, date/time, notes you choose to share.
  • Deposit info: payer name, payer email, transfer reference or screenshot — used only to match your payment to your booking.
  • Reviews: the name and comment you publicly post on a service page.
  • Technical data: standard server logs (IP, browser, time) kept short-term by our hosting provider for security.

3. Why we collect it

  • Confirm your appointment and prepare for your visit.
  • Contact you about your booking, deposit, or schedule changes.
  • Process and verify your deposit.
  • Display reviews you choose to publish.
  • Comply with legal and accounting obligations.

We collect only the information needed for these purposes — nothing more.

4. How we store it

Booking and review data are stored in Supabase (Postgres) with row-level security enabled. Photos and screenshots you upload are stored in a Supabase storage bucket. Only the owner, signed in with a unique account, can read your booking details. Reviews you post are public by design.

5. Who we share it with

We do not sell or trade your personal information. We share data only with service providers needed to run the site:

  • Supabase — database and storage hosting.
  • EmailJS — sends the booking notification email to the owner.
  • Cloudflare — serves the website and provides security.

We may disclose information if legally required by Canadian or Ontario authorities.

6. How long we keep it

  • Bookings: kept for up to 24 months for follow-up and tax records, then deleted.
  • Deposit screenshots: kept up to 12 months for payment dispute resolution.
  • Reviews: kept indefinitely unless you ask us to remove yours.

7. Your rights

Under PIPEDA you have the right to:

  • Access the personal information we hold about you.
  • Correct information that is inaccurate.
  • Withdraw consent and request deletion of your data.
  • Request that a review you posted be removed.

To exercise any of these rights, email lollylifestylehub@gmail.com with the subject line “Privacy Request”. We will respond within 30 days.

8. Children

Our services are intended for adults (18+). We do not knowingly collect information from children. If a parent or guardian books a service for a minor, only the booking adult’s contact information is collected.

9. Cookies & tracking

The website uses minimal browser storage to remember your booking-form choices and to keep the owner signed in to the admin area. We do not use third-party advertising trackers. Cloudflare may set basic security cookies.

10. Security

All traffic is encrypted with HTTPS. Database access is protected by row-level security. The owner’s admin password is stored only as a hashed value — never in plain text. We do our best to protect your data, but no online service can guarantee 100% security.

11. Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top will reflect the latest revision. Continued use of the site after a change means you accept the new policy.