SHAY SKINby Shay Esthétique
Privacy

Privacy policy

Last updated: August 5, 2026

In short

This site does not ask you to create an account. Since August 5, 2026, it includes an online shop whose checkout and payment are powered by Shopify, and a newsletter you can sign up for to receive a discount code. Since July 30, 2026, it also carries one advertising cookie — the Meta pixel — which only loads after you agree, and an advertising page lets you ask to be called back. Most of your information still does not come from here: it comes from your file at the clinic and from our booking software. This page states what we actually hold, not what would sound good.

Who we are

This policy applies to the website https://shayskin.ca, operated by SHAY SKIN, 111 Rue Chabanel Ouest #604, Montréal (QC) H2N 1C8. It also covers the information the clinic holds about you in its own systems.

  • Person in chargeChaimaa Rouki, fondatricePerson in charge of the protection of personal information
  • Emailinfo@shaymedico.ca
  • Phone+1 438 796-3111
  • Address111 Rue Chabanel Ouest #604, Montréal (QC) H2N 1C8

Write to that email address for any question about this policy, to see your file, have it corrected, withdraw a consent or file a complaint. It is a real inbox, read by the clinic.

What we collect, and when

We would rather tell you moment by moment than give you a vague list.

When you browse the site

Nothing is asked of you and there is no account to create. Our web server does keep a technical log of every page served: your IP address, the date and time, the page requested, the page you came from and your browser type. That log keeps the site running and helps us spot abuse. We also limit how many times a form can be submitted from one IP address: that counter lives for a few minutes in the server's memory, is never written to disk and disappears on every restart.

When you ask to be called back

Our advertising pages invite you to leave your contact details so we can call you back. Two items are required — your name and your phone — and two are optional: your email and a short message. You may also indicate the area you are interested in. We additionally keep the page your request came from and, where applicable, the identifier of the ad you clicked: this tells us which ads are worth their cost, never to profile you. This information is used solely to call you back and is kept for 90 days, then deleted. Do not write health information in the message: those questions belong in a consultation, on the secure form the clinic sends you through a personal link.

When you sign up for the referral program

The ambassador form collects your name and at least one way to reach you: email, phone, or both. From that we generate a referral code. Phone numbers are stored as 10 digits, without formatting. There is no account and no password: your tracking page opens with your code. So share it only with the people you invite.

The invitation form also asks for the name and contact details of the person you invite, so the $25 credit can be applied. This form works: what that person enters is recorded in our database. No invitation has been recorded to date. Those details are compared with the other invitations tied to the same code, solely to avoid duplicates.

When a referral link is opened, our server keeps a technical record of it, as for any page: the time, the link's code, the IP address and the browser. We do not attach your name to it.

When you sign a treatment consent

Before certain treatments, the clinic sends you a personal link to a form to sign. This form is the only place on the site where we collect health information, and that information is sensitive. Depending on the treatment, it may ask about: pregnancy or breastfeeding, current medication (including isotretinoin, photosensitizing drugs, blood thinners), cold sores, keloids, autoimmune disease, diabetes, epilepsy, cancer, metal implants, allergies, skin phototype, recent tanning, recent treatments and products, tattoos on the treated area.

When you sign, we also record three things you do not type yourself: your handwritten signature as you draw it on screen (kept as an image), your IP address and your browser type. Those three exist solely to prove that it was you who signed, and when. We are telling you here rather than letting you find out later.

The form separates two photo consents, and they are not the same. The first allows before/after photos to be kept in your file, for internal use: it is part of following your treatment. The second allows them to be published on our site, our social media or our ads: it is optional, it states whether your face may be recognizable, and you can withdraw it. Declining publication changes nothing about your treatment, its price, or how you are treated.

A signing link stops working 14 days after it is sent.

When you are already a client of the clinic

This is the point our previous policy stayed silent about, and it is the most important one. If you have already booked with us, your contact details and appointment history do not come from this site: they come from Fresha, the booking software the clinic uses. The clinic imported a copy into its own database to manage files, reminders and accounting. Depending on the case, that copy contains: name, email, phone, date of birth, appointment history and notes.

For clients followed at the clinic, the clinical file is added to that: treatment notes, photos and signed consents.

When you use the shop

Your cart stays in your browser until you check out: it is not sent to us and we cannot see it. When you click “Checkout”, your cart is sent to Shopify, which hosts the checkout, the payment and your order history. You enter your email, shipping address and payment directly with Shopify; we keep no card number, which Shopify processes on its own. You may also choose “Reserve for pickup”: the button then opens your email software with your cart details, and you pay on site at the clinic.

What this site does not do

Saying this is as useful as saying what it does.

Payment via Shopify

Online payment is handled by Shopify, on its own pages. We keep no card number: Shopify processes it alone. You may also pay at pickup in the clinic.

No account

No sign-up, no password, no profile. The referral tracking page opens with a code, nothing else.

Optional newsletter

You may sign up for our newsletter to receive a discount code. Your email is then stored with Shopify, where the mailing list lives, with your consent. You can unsubscribe at any time. Without signing up, this site adds you to no list.

No profiling

We build no advertising profile, do not track you across sites, and sell your information to no one.

One honest clarification: if you are a client of the clinic, we may email or text you about your appointments, your follow-up or our offers. That does not go through this site. You may ask us to stop at any time, by replying STOP to a text or writing to info@shaymedico.ca.

Cookies, local storage and analytics

Today, this site sets no cookie in your browser during a normal visit. The only cookie the application sets is the clinic's admin session cookie: it concerns staff only, lasts 12 hours and is never sent to a client.

Two things are, however, saved in your browser's “local storage”. They are never sent to our servers:

  • shay_cart — your cart contents, as product name and quantity. No personal data.
  • shay-consent-v1 — your choice about analytics and advertising cookies, with the date of that choice.
  • shay_cart_id — the technical identifier of your Shopify cart, once you check out. It is used only to clear your cart after payment. No personal data. It is the only one of these items the site sends back to our server, and only to check whether the order was paid.
  • shay_news — a simple flag noting that the newsletter window has already been shown to you, so it is not repeated. No personal data.

Two measurement tools are planned. The Meta pixel is ACTIVE as of July 30, 2026: it measures callback requests and bookings coming from our Facebook and Instagram ads. Google Analytics is still not connected — no Google script is loaded on this site. The Meta pixel loads only AFTER you agree: as long as you have not accepted advertising in the choices panel, nothing is sent to Meta, and declining is as easy as accepting. Once accepted, it collects what you do not give us: IP address, cookie identifier (“_fbp”, “_fbc”), browser, page views, and the “callback request” event at the moment you submit the form. That information goes to the United States.

You can open the choices panel at any time: Manage cookies. The same link sits at the bottom of every page. Withdrawing your consent deletes the relevant cookies and reloads the page.

One point where we are not yet up to standard: the Google map shown on our home page and on the clinic page loads as soon as the page opens, without waiting for your consent. It sends Google your IP address, your browser and the page you are on. It is currently the only third party your browser contacts on this site, and it is something we need to fix.

Who receives your information

We sell nothing to anyone. Here is the complete list of the companies that handle your information today, named rather than summarized as “our partners”:

  • Hostinger — rents us the server that delivers this site's pages. The technical log described above (IP address, time, page requested, browser) sits on that machine, and it is located in the United States. No client file is stored on it.
  • Supabase — hosts our database. The project is dedicated to the clinic and its servers are in Montreal (ca-central-1 region). That is where your file, your consents and your appointments live.
  • Google — only through the map shown on two pages, described above.
  • Fresha — our booking software. This site sends it nothing: you go there yourself by clicking “Book”. From that point on, Fresha's own privacy policy applies to what you enter there.
  • Telnyx — our telecommunications provider. When the clinic sends you a reminder or follow-up text message, your first name and phone number pass through it so the message can be delivered. It receives nothing else, and nothing at all if we never text you.
  • Meta Platforms (Facebook, Instagram) — only if you accepted advertising in the choices panel. It then receives your IP address, a cookie identifier (“_fbp”, “_fbc”), the pages you view and the fact that you asked to be called back. It receives neither your name, nor your phone, nor your email, nor the message you write us. Its servers are in the United States. If you decline, no Meta script is loaded and nothing is sent to it.
  • Resend — the service that delivers the internal notice telling the clinic you asked to be called back. That notice contains your name, your phone, your email if you gave one, and the area you are interested in. It goes to the clinic, never to you. Its servers are in the United States.

And what is not yet connected

Since August 5, 2026, the online shop runs on Shopify. Shopify hosts the catalogue, the cart, the checkout, payment and order history, with its own subcontractors, outside Quebec. When you place an order or sign up for the newsletter, the information this involves — email, shipping address, order details and payment — is sent to Shopify and its subcontractors. That transfer is governed by Shopify's data processing agreement, in force simply because the account is open. Your clinical file, however — treatment notes, photos, consents, history — is NEVER sent to Shopify: it stays in Montreal. This separation is deliberate.

Outside Quebec

Your file is stored in Montreal. Our providers are nonetheless foreign companies: their technical staff may access the servers from outside Quebec for support and backups. Four transfers outside Quebec actually take place today: page hosting by Hostinger, the Meta pixel if you accepted advertising, the internal notice sent to the clinic through Resend when you ask to be called back, and — since August 5, 2026 — Shopify, when you order in the shop or sign up for the newsletter. Google Analytics remains disconnected. The law requires us to assess each transfer outside Quebec before it happens and to frame it in a written agreement; we did so for Shopify before opening the shop.

How long we keep it

Let us be frank rather than reassuring: our system deletes nothing on its own. As of today there is no automatic purge. Your information stays in our database until we erase it by hand — at your request, or on our own initiative when it no longer serves a purpose. That is a real limitation, and we would rather write it down than promise a deletion that would not happen.

  • Clinical file (notes, photos, consents): kept for the period required by our professional and legal obligations, and to keep your future treatments safe.
  • Contact details and appointment history: kept while you remain a client, then for the duration of our accounting obligations.
  • Referral: kept for the duration of the program and the crediting of rewards.
  • Server technical logs: they are not yet subject to a defined retention period. That is an open item on our side.
  • Signing link: it stops working after 14 days.

A signed consent form is a special case. Our database technically forbids deleting it, because it is a piece of evidence: it attests to what was explained to you before a treatment. If you withdraw your consent, the withdrawal is recorded with its date and the consent stops applying going forward — but the signed document itself remains. Erasing it completely requires a manual intervention in the database. We will do it if you ask and if the law allows us to; either way, we will answer you.

Something else you are entitled to know: when a note, a photo or a consent is changed or deleted, our database keeps a copy of it in an internal log, so that the history of a health file cannot be silently rewritten. A deletion request must therefore also cover that copy, and that is what we handle when a request reaches us.

Your rights, and how to use them

It all happens in one place: write to info@shaymedico.ca. Tell us what you want and give us enough to find you in our records (the name and phone number used at the clinic are enough). The law gives us 30 days to respond.

  • Access — obtain the list of what we hold about you and receive a copy of it.
  • Correction — have anything inaccurate, incomplete or outdated fixed.
  • Withdrawal of consent — withdraw a treatment consent, the permission to publish your photos, or your agreement to analytics and advertising cookies. Withdrawing one does not force you to withdraw the others.
  • Deletion — ask that your information be erased. We will tell you honestly what we can erase and what we must keep, with the reason: a health file and a signed consent are not erased like an email address.
  • Portability — receive, in a common computer format, the information you yourself provided to us. This right does not cover what the clinic wrote about you, such as treatment notes; those fall under the right of access.
  • Cessation of publication and de-indexing — require that we take down a photo or content about you that we published, and that we ask search engines to stop referencing it.

No decision about you is made by a computer alone. The health questionnaire may flag a contraindication based on your answers, but it does not decide for you: a practitioner reviews the file, discusses it with you, and makes the call.

How it is protected

Our database is never reachable from your browser: every read or write goes through our server, and a request made from outside is refused. Exchanges with the site are encrypted. The admin area is password-protected and the session ends automatically after 12 hours.

We will not tell you everything is perfect. Today, admin access is not tied to individual accounts: we are therefore unable to trace which person at the clinic viewed a file. That is an improvement to be made, and we write it here rather than let you believe otherwise.

If a confidentiality incident occurred — a loss, unauthorized access, an unintended disclosure — the law requires us to record it in a register, take steps to limit its consequences, and notify you as well as the Commission d'accès à l'information when the incident presents a risk of serious injury. That is what we would do.

Changes to this policy

Every time our practices change — an analytics tool switched on, a checkout opened, a provider added — this page is rewritten and the date at the top is changed. That date is the only promise we make here: if it has not moved, nothing has moved.

Questions, complaints and recourse

For any question about this policy, to exercise your rights, or to complain about how we handle your information, write to the person in charge at info@shaymedico.ca. We will answer you and tell you what we are doing with your request.

If our answer does not satisfy you, you may contact the Commission d'accès à l'information du Québec, which oversees the application of the law and receives complaints.

If you buy a product from us, our terms of sale apply in addition to this policy.

This policy applies the Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), known as “Law 25”. In case of any discrepancy, the statute prevails: https://www.legisquebec.gouv.qc.ca/fr/document/lc/P-39.1

Privacy policy | SHAY Esthétique