Privacy Policy
This policy explains what Inside MedSpa collects about you, why, who we share it with, and the choices and rights you have. It covers insidemedspa.com and the emails we send.
Who we are
Inside MedSpa is published by Quill & Harbor LLC ("we", "us"). For visitors in the European Economic Area (EEA), the United Kingdom and Switzerland, Quill & Harbor LLC is the controller of the personal information described here. You can reach us about anything in this policy at contact@quillandharbor.com.
The short version
- If you sign up, we store your email address to send you what you asked for. We never sell it, and we don't give it to advertisers.
- We use Google Analytics to understand how the site is used.
- We show ads from Google AdSense. Google and its partners use cookies to choose ads, including ads based on your visits to other sites (personalized ads). You can turn that off: see Your Privacy Choices.
- In the EEA, the UK and Switzerland, we ask Google's tags not to use analytics or advertising cookies unless you consent.
- You can unsubscribe in one click, and ask us to access, correct or delete your data at any time.
What we collect
Information you give us
- Email address: when you sign up for the free brief or email alerts, sign in, redeem a gift, or join through a referral link. If you join through a referral link, we record who referred you so we can credit them.
- Comments: your name, email address, the comment and the IP address it was sent from. Your name and comment appear publicly once approved; your email address and IP address don't.
- Messages: your name, email address and message when you use our contact form or email us, including partnership and advertising enquiries.
- Browser notifications: if you allow them, your browser gives us a push address and encryption keys (linked to your email address if you're signed in) so we can send them.
- Payments: paid subscriptions, when offered, are processed by Stripe. Stripe collects your card and billing details under its own privacy policy; we receive only the subscription status and the email address linked to it. Paid checkout isn't open at the moment.
Information collected automatically
- Usage and device data, through Google Analytics: pages viewed, time on page, the site that referred you, device and browser type, and approximate location (derived from your IP address).
- Advertising data, through Google AdSense: cookie and device identifiers, IP address, the pages you visit here and your interactions with ads, used by Google and its partners to show, personalize and measure ads.
- Server and security data: our hosting provider, Cloudflare, processes standard request data (IP address, browser user agent, the page requested) to deliver and protect the site. If a request looks like an attack (for example, probing for admin files), we record its IP address, user agent and path so we can block it.
- Aggregate statistics: we count page views per page and per network operator (for example, a cloud provider) to spot automated traffic. These counts don't identify you.
Our emails don't contain tracking pixels or click tracking. Our email provider tells us whether a message was delivered, bounced or marked as spam.
Cookies and similar technologies
- Strictly necessary:
im_skeeps you signed in (up to one year);im_mcounts free articles when article metering is switched on (30 days); Cloudflare may set security cookies such as__cf_bm. - Analytics: Google Analytics cookies (
_ga,_ga_*), kept for up to two years. - Advertising: Google advertising cookies such as
__gads,__gpiand__eoion this site, and cookies on Google domains such as doubleclick.net, typically kept for up to 13 months. - Local storage: your browser may store your consent choices and small interface settings.
In the EEA, the UK and Switzerland, our pages tell Google's tags not to use analytics or advertising cookies unless you consent. You can also block or delete cookies in your browser. The site works without them, although signing in needs im_s.
How we use it, and our legal bases
Where the GDPR or the UK GDPR applies, we rely on these legal bases:
- Sending the brief and alerts you signed up for: your consent, which you can withdraw at any time by unsubscribing.
- Signing you in, and managing gifts, referrals and any paid subscription: performing our contract with you.
- Publishing and moderating comments, and answering your messages: our legitimate interest in running a publication and responding to readers.
- Keeping the site secure and working (blocking attacks, preventing spam and abuse, fixing faults): our legitimate interest in protecting the service and its readers.
- Analytics and advertising cookies: your consent. Outside the EEA, the UK and Switzerland we use them as local law allows, with the opt-outs described below.
- Keeping records the law requires (for example, tax records for payments): legal obligation.
We don't make decisions about you based solely on automated processing that have legal or similarly significant effects.
Advertising on Inside MedSpa
Inside MedSpa is supported by ads served by Google AdSense. Third-party vendors, including Google, use cookies to serve ads based on your previous visits to this website or other websites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visits to this site and/or other sites on the internet. Advertisers have no say in what we cover.
- You can opt out of personalized advertising in Google's Ads Settings.
- You can opt out of many third-party vendors' use of cookies for personalized advertising at www.aboutads.info, or in Europe at youronlinechoices.eu.
- Google explains its practices in How Google uses information from sites or apps that use our services.
If you opt out you'll still see ads, but they won't be personalized to you.
Who we share information with
We share personal information only with the service providers that run the publication for us, and only for that purpose:
- Cloudflare: hosting, content delivery, security, and the database that stores sign-ups, comments and notification subscriptions.
- Amazon Web Services: Amazon SES sends our emails, and AWS hosts the systems that manage our mailing lists, in the United States.
- Google: Google Analytics, and Google AdSense for ads. For advertising, Google also acts as an independent controller under the Google Privacy Policy.
- Stripe: payment processing, when paid subscriptions are offered.
- Browser push services (Google, Mozilla, Apple or Microsoft, depending on your browser): delivering notifications you've allowed.
We may also disclose information if the law requires it, to protect our rights or other people's safety, or as part of a merger, sale or reorganisation of our business, in which case this policy continues to apply. We don't sell your email address or other contact details, and we don't give them to advertisers.
Selling, sharing and targeted advertising (U.S. state privacy laws)
We don't sell personal information for money. But when Google shows personalized ads here, it collects identifiers (such as cookie IDs and your IP address), internet activity (the pages you view here) and approximate location through cookies. California law may treat that as "sharing" personal information for cross-context behavioral advertising, and some other states treat it as a "sale" or as "targeted advertising". You have the right to opt out: see Your Privacy Choices. We treat a Global Privacy Control (GPC) signal as a valid opt-out for the browser that sends it. We don't knowingly sell or share the personal information of anyone under 16.
In the last 12 months we have collected the categories of personal information described above: identifiers (such as email address, IP address and cookie IDs), internet or other electronic network activity, approximate geolocation, commercial information (subscription status), and the content of the comments and messages you send us. We collect them from you, from your browser or device, and from our service providers, for the purposes described in this policy. We don't collect sensitive personal information.
Your rights
Everyone can unsubscribe from our emails with the link in any message, and can ask us to access, correct or delete the personal information we hold about them.
In the EEA, the UK and Switzerland, you have the right to access your personal information, correct it, have it erased, restrict or object to how we use it (including an absolute right to object to direct marketing), receive it in a portable format, and withdraw your consent at any time without affecting processing that took place before. You can also complain to a data protection authority, such as your local EU supervisory authority, the UK Information Commissioner's Office or the Swiss Federal Data Protection and Information Commissioner.
In California and other U.S. states with privacy laws, you have the right to know what personal information we collect and how we use and disclose it, to access it, to correct it, to delete it, and to opt out of its sale, sharing or use for targeted advertising. You can use an authorized agent. We won't discriminate against you for exercising these rights. If we decline a request, you can appeal by replying to our decision; if we deny the appeal, you can contact your state attorney general.
How to make a request: email contact@quillandharbor.com with the subject "Privacy request" and the email address you use with Inside MedSpa. We'll verify the request by confirming it with that address, and respond within one month (EEA, UK, Switzerland) or 45 days (U.S. states). If a request is complex we may extend that as the law allows, and we'll tell you why. Opt-out requests are handled within 15 business days.
International transfers
We're based in the United States, and our service providers process information in the U.S. and other countries. When they receive personal information from the EEA, the UK or Switzerland, they rely on recognised safeguards such as the EU–U.S. Data Privacy Framework (with its UK and Swiss extensions) or the European Commission's Standard Contractual Clauses.
How long we keep it
- Email subscriptions: while you're subscribed. After you unsubscribe we keep your address on a suppression list so we don't email you again; ask us and we'll delete everything else.
- Accounts, gifts, referrals and access records: while they're active, and afterwards only as long as needed to resolve questions or disputes.
- Comments: for as long as they're published. Ask us and we'll remove yours.
- Messages: as long as needed to deal with your enquiry.
- Analytics: Google Analytics keeps user-level data for no more than 14 months.
- Security records: IP addresses linked to attack attempts are kept for as long as needed to protect the site.
- Payment records: as long as tax and accounting law requires.
Security
We use encrypted connections (HTTPS), access controls and established providers to protect your information. No system is perfectly secure, but we work to keep your data safe.
Children
Inside MedSpa is written for adults and isn't directed to children. We don't knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, contact us and we'll delete it.
Changes to this policy
When we change this policy we'll update the date at the top. If a change is significant, we'll highlight it on this page.
Contact
Quill & Harbor LLC · contact@quillandharbor.com · Your Privacy Choices