Privacy policy
Last updated: July 29, 2026
In short
This site does not ask you to create an account, sells nothing online, has no newsletter and currently sets no advertising cookies. Most of your information does not come from here: it comes from your file at the clinic and from our booking software. This page states what we actually hold, not what would sound good.
Who we are
This policy applies to the website https://shayesthetique.ca, operated by SHAY Esthétique, 111 Rue Chabanel Ouest #604, Montréal (QC) H2N 1C8. It also covers the information the clinic holds about you in its own systems.
- Person in chargeThe management of SHAY Esthétique — Person in charge of the protection of personal information
- Emailinfo@shaymedico.ca
- Phone+1 438 796-3111
- Address111 Rue Chabanel Ouest #604, Montréal (QC) H2N 1C8
Write to that email address for any question about this policy, to see your file, have it corrected, withdraw a consent or file a complaint. It is a real inbox, read by the clinic.
What we collect, and when
We would rather tell you moment by moment than give you a vague list.
When you browse the site
Nothing is asked of you and there is no account to create. Our web server does keep a technical log of every page served: your IP address, the date and time, the page requested, the page you came from and your browser type. That log keeps the site running and helps us spot abuse. We also limit how many times a form can be submitted from one IP address: that counter lives for a few minutes in the server's memory, is never written to disk and disappears on every restart.
When you sign up for the referral program
The ambassador form collects your name and at least one way to reach you: email, phone, or both. From that we generate a referral code. Phone numbers are stored as 10 digits, without formatting. There is no account and no password: your tracking page opens with your code. So share it only with the people you invite.
The invitation form also asks for the name and contact details of the person you invite, so the $25 credit can be applied. This form works: what that person enters is recorded in our database. No invitation has been recorded to date. Those details are compared with the other invitations tied to the same code, solely to avoid duplicates.
When a referral link is opened, our server keeps a technical record of it, as for any page: the time, the link's code, the IP address and the browser. We do not attach your name to it.
When you sign a treatment consent
Before certain treatments, the clinic sends you a personal link to a form to sign. This form is the only place on the site where we collect health information, and that information is sensitive. Depending on the treatment, it may ask about: pregnancy or breastfeeding, current medication (including isotretinoin, photosensitizing drugs, blood thinners), cold sores, keloids, autoimmune disease, diabetes, epilepsy, cancer, metal implants, allergies, skin phototype, recent tanning, recent treatments and products, tattoos on the treated area.
When you sign, we also record three things you do not type yourself: your handwritten signature as you draw it on screen (kept as an image), your IP address and your browser type. Those three exist solely to prove that it was you who signed, and when. We are telling you here rather than letting you find out later.
The form separates two photo consents, and they are not the same. The first allows before/after photos to be kept in your file, for internal use: it is part of following your treatment. The second allows them to be published on our site, our social media or our ads: it is optional, it states whether your face may be recognizable, and you can withdraw it. Declining publication changes nothing about your treatment, its price, or how you are treated.
A signing link stops working 14 days after it is sent.
When you are already a client of the clinic
This is the point our previous policy stayed silent about, and it is the most important one. If you have already booked with us, your contact details and appointment history do not come from this site: they come from Fresha, the booking software the clinic uses. The clinic imported a copy into its own database to manage files, reminders and accounting. Depending on the case, that copy contains: name, email, phone, date of birth, appointment history and notes.
For clients followed at the clinic, the clinical file is added to that: treatment notes, photos and signed consents.
When you use the shop
Your cart stays in your browser. It is not sent to us and we cannot see it. There is no online payment on this site: the “Reserve for pickup” button opens your email software with your cart already written out, and you decide whether to send it. Your email provider therefore sees that message, like any other.
What this site does not do
Saying this is as useful as saying what it does.
You cannot pay online. We hold no card number, no shipping address and no online purchase history.
No sign-up, no password, no profile. The referral tracking page opens with a code, nothing else.
This site offers no mailing-list sign-up and sends no email today.
We build no advertising profile, do not track you across sites, and sell your information to no one.
One honest clarification: if you are a client of the clinic, we may email or text you about your appointments, your follow-up or our offers. That does not go through this site. You may ask us to stop at any time, by replying STOP to a text or writing to info@shaymedico.ca.
Cookies, local storage and analytics
Today, this site sets no cookie in your browser during a normal visit. The only cookie the application sets is the clinic's admin session cookie: it concerns staff only, lasts 12 hours and is never sent to a client.
Two things are, however, saved in your browser's “local storage”. They are never sent to our servers:
- shay_cart — your cart contents, as product name and quantity. No personal data.
- shay-consent-v1 — your choice about analytics and advertising cookies, with the date of that choice.
We plan to add two measurement tools: Google Analytics, to see which pages are visited, and the Meta pixel, to measure bookings and purchases coming from our Facebook and Instagram ads. Neither is active today: no Google or Meta script is loaded on this site. On the day they are, they will load only after your consent, given box by box, and declining will be as easy as accepting. Those tools would collect what you do not give us: IP address, cookie identifier, browser, page views and clicks — and that information would leave for the United States.
You can open the choices panel at any time: Manage cookies. The same link sits at the bottom of every page. Withdrawing your consent deletes the relevant cookies and reloads the page.
One point where we are not yet up to standard: the Google map shown on our home page and on the clinic page loads as soon as the page opens, without waiting for your consent. It sends Google your IP address, your browser and the page you are on. It is currently the only third party your browser contacts on this site, and it is something we need to fix.
Who receives your information
We sell nothing to anyone. Here is the complete list of the companies that handle your information today, named rather than summarized as “our partners”:
- Supabase — hosts our database. The project is dedicated to the clinic and its servers are in Montreal (ca-central-1 region). That is where your file, your consents and your appointments live.
- Google — only through the map shown on two pages, described above.
- Fresha — our booking software. This site sends it nothing: you go there yourself by clicking “Book”. From that point on, Fresha's own privacy policy applies to what you enter there.
- Telnyx — our telecommunications provider. When the clinic sends you a reminder or follow-up text message, your first name and phone number pass through it so the message can be delivered. It receives nothing else, and nothing at all if we never text you.
And what is not yet connected
Three things are being considered and do not work today. We write them down anyway, so you know what is coming: a payment provider, if the shop truly opens; an email delivery service, for order confirmations; and Shopify, if the shop were moved there. Shopify would then host the catalogue, the cart, payment and order history, with its own subcontractors, outside Quebec. None of these three is in service: nothing is sent to them as of this date. This page will be updated, and the date at the top will change, before any of them receives anything.
Outside Quebec
Your file is stored in Montreal. Our providers are nonetheless foreign companies: their technical staff may access the servers from outside Quebec for support and backups. And the tools described above — analytics, advertising, payment, email delivery, Shopify — would involve a transfer to the United States. The law requires us to assess that transfer before it happens, and to frame it in a written agreement. Until that is done, those tools stay disconnected.
How long we keep it
Let us be frank rather than reassuring: our system deletes nothing on its own. As of today there is no automatic purge. Your information stays in our database until we erase it by hand — at your request, or on our own initiative when it no longer serves a purpose. That is a real limitation, and we would rather write it down than promise a deletion that would not happen.
- Clinical file (notes, photos, consents): kept for the period required by our professional and legal obligations, and to keep your future treatments safe.
- Contact details and appointment history: kept while you remain a client, then for the duration of our accounting obligations.
- Referral: kept for the duration of the program and the crediting of rewards.
- Server technical logs: they are not yet subject to a defined retention period. That is an open item on our side.
- Signing link: it stops working after 14 days.
A signed consent form is a special case. Our database technically forbids deleting it, because it is a piece of evidence: it attests to what was explained to you before a treatment. If you withdraw your consent, the withdrawal is recorded with its date and the consent stops applying going forward — but the signed document itself remains. Erasing it completely requires a manual intervention in the database. We will do it if you ask and if the law allows us to; either way, we will answer you.
Something else you are entitled to know: when a note, a photo or a consent is changed or deleted, our database keeps a copy of it in an internal log, so that the history of a health file cannot be silently rewritten. A deletion request must therefore also cover that copy, and that is what we handle when a request reaches us.
Your rights, and how to use them
It all happens in one place: write to info@shaymedico.ca. Tell us what you want and give us enough to find you in our records (the name and phone number used at the clinic are enough). The law gives us 30 days to respond.
- Access — obtain the list of what we hold about you and receive a copy of it.
- Correction — have anything inaccurate, incomplete or outdated fixed.
- Withdrawal of consent — withdraw a treatment consent, the permission to publish your photos, or your agreement to analytics and advertising cookies. Withdrawing one does not force you to withdraw the others.
- Deletion — ask that your information be erased. We will tell you honestly what we can erase and what we must keep, with the reason: a health file and a signed consent are not erased like an email address.
- Portability — receive, in a common computer format, the information you yourself provided to us. This right does not cover what the clinic wrote about you, such as treatment notes; those fall under the right of access.
- Cessation of publication and de-indexing — require that we take down a photo or content about you that we published, and that we ask search engines to stop referencing it.
No decision about you is made by a computer alone. The health questionnaire may flag a contraindication based on your answers, but it does not decide for you: a practitioner reviews the file, discusses it with you, and makes the call.
How it is protected
Our database is never reachable from your browser: every read or write goes through our server, and a request made from outside is refused. Exchanges with the site are encrypted. The admin area is password-protected and the session ends automatically after 12 hours.
We will not tell you everything is perfect. Today, admin access is not tied to individual accounts: we are therefore unable to trace which person at the clinic viewed a file. That is an improvement to be made, and we write it here rather than let you believe otherwise.
If a confidentiality incident occurred — a loss, unauthorized access, an unintended disclosure — the law requires us to record it in a register, take steps to limit its consequences, and notify you as well as the Commission d'accès à l'information when the incident presents a risk of serious injury. That is what we would do.
Changes to this policy
Every time our practices change — an analytics tool switched on, a checkout opened, a provider added — this page is rewritten and the date at the top is changed. That date is the only promise we make here: if it has not moved, nothing has moved.
Questions, complaints and recourse
For any question about this policy, to exercise your rights, or to complain about how we handle your information, write to the person in charge at info@shaymedico.ca. We will answer you and tell you what we are doing with your request.
If our answer does not satisfy you, you may contact the Commission d'accès à l'information du Québec, which oversees the application of the law and receives complaints.
If you buy a product from us, our terms of sale apply in addition to this policy.
This policy applies the Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), known as “Law 25”. In case of any discrepancy, the statute prevails: https://www.legisquebec.gouv.qc.ca/fr/document/lc/P-39.1