< class="breadcumb-title">Privacy Policy

Privacy Policy

Eye Candy MedSpa and Lash Bar | Eyecandy Medspa MSO LLC
Last Updated: May 2026

Eyecandy Medspa MSO LLC (operating as Eye Candy MedSpa and Lash Bar, referred to as the Company, we, or us) is committed to protecting your privacy. This Privacy Policy describes how we collect, use, and disclose your personal information through our website, social media pages, email communications, and in-person interactions at our three Southern California locations. By using our Services, you agree to the collection and use of information in accordance with this Privacy Policy.

For questions or privacy-related requests, contact us at: medspaeyecandy@gmail.com


IMPORTANT NOTICE: MEDICAL SERVICES AND HIPAA

This Privacy Policy applies to your use of our website, booking systems, and marketing communications. It does not apply to health information collected in connection with actual medical treatments or procedures you receive from our affiliated medical provider, Jumaily Medical Corporation.

Jumaily Medical Corporation is an independent professional corporation whose licensed medical providers perform medical aesthetic procedures (including but not limited to Botox, PDO thread lifting, IV therapy, and other medical services) at Eye Candy MedSpa locations. Health information collected in the context of those medical services is governed separately by Jumaily Medical Corporation’s Notice of Privacy Practices under HIPAA and the California Confidentiality of Medical Information Act (CMIA).

If you have questions about how your medical treatment information is handled, please contact Jumaily Medical Corporation directly.


1. INFORMATION WE COLLECT

Personal Information: When you interact with us, we may collect:

  • Contact details: name, phone number, email address, mailing address
  • Appointment and booking information
  • Billing and payment information (processed securely by our payment processors)
  • Date of birth and gender (for treatment eligibility purposes)
  • IP address and device identifiers
  • Marketing preferences and communication consent

Health and Treatment Information: As a medical spa, we may collect limited health-related information necessary to facilitate aesthetic treatments, such as skin type, treatment history, allergies, and contraindications. This website-collected information is used solely to deliver safe and appropriate services to you. Note: detailed medical records related to actual procedures are handled by Jumaily Medical Corporation under HIPAA and CMIA, not this Privacy Policy.

Sensitive Personal Information: Consistent with the California Privacy Rights Act (CPRA), we identify the following as Sensitive Personal Information: health and medical information you voluntarily provide (such as allergies or contraindications for treatment purposes). We collect and use this information only to the extent necessary to provide you with our services. We do not use or disclose Sensitive Personal Information for purposes beyond what is reasonably necessary to provide the requested services.

Automatically Collected Information: When you visit our website, we automatically collect technical data including IP address, browser type, pages visited, time and date of visit, and device information, collected through cookies and similar tracking technologies.


2. HOW WE COLLECT YOUR INFORMATION

  • Directly from you when you book an appointment, fill out intake forms, or contact us
  • Through our website via cookies and tracking technologies
  • From social media platforms when you interact with our pages
  • From third-party providers such as booking software, payment processors, and marketing platforms

3. HOW WE USE YOUR INFORMATION

  • To schedule, manage, and confirm appointments
  • To facilitate aesthetic treatments and related services safely
  • To process payments and manage billing
  • To send appointment confirmations, reminders, and follow-up communications
  • To send marketing emails and SMS messages about promotions and new services (with your consent)
  • To respond to inquiries and customer service requests
  • To improve our website, services, and customer experience
  • To serve personalized advertisements on third-party platforms (see Section 6)
  • To comply with legal obligations and protect our legal rights
  • To detect and prevent fraud or unauthorized activity

4. MARKETING COMMUNICATIONS

Email Communications: When you provide your contact information or book an appointment, you may consent to receive marketing emails from Eye Candy MedSpa and Lash Bar. You can opt out at any time by clicking the unsubscribe link in any email we send.

SMS Text Messages: By consenting to receive SMS messages from Eye Candy MedSpa and Lash Bar, you agree to receive texts regarding promotions, appointment reminders, updates, and special offers. Message frequency varies. Message and data rates may apply. Reply STOP to opt out. Reply HELP for assistance. Carriers are not liable for delayed or undelivered messages. Consent is not a condition of purchase.

Transactional Messages: Regardless of marketing preferences, you will continue to receive appointment confirmations, reminders, and important service-related notifications.


5. SHARING YOUR INFORMATION

We do not sell your personal information for monetary consideration. We may share your information only in these circumstances:

  • Service Providers: Vendors who help operate our business (booking platforms, payment processors, email marketing, analytics). These providers are contractually required to protect your data and use it only for the services they provide to us.
  • Advertising Partners: We use third-party advertising platforms including Meta (Facebook/Instagram) and Google to deliver targeted advertisements. These platforms may receive certain identifiers (such as hashed email addresses, pixel data, or device identifiers) to enable ad targeting and measurement. This may constitute sharing of personal information under California law. See Section 6 for opt-out options.
  • Legal Requirements: When required by law, court order, or government authority, or to protect rights, safety, or property.
  • Business Transfers: In the event of a merger or acquisition, your information may transfer to the acquiring entity under the same privacy protections.

6. COOKIES, TRACKING TECHNOLOGIES, AND ADVERTISING

We use cookies and tracking technologies on our website, including advertising pixels from Meta (Facebook/Instagram) and Google. These technologies allow us to:

  • Analyze website traffic and usage (Google Analytics)
  • Deliver and measure the effectiveness of our advertisements
  • Retarget visitors with relevant ads on third-party platforms
  • Build custom and lookalike audiences for advertising purposes

Under the California Privacy Rights Act (CPRA), the use of your personal information for cross-context behavioral advertising may be considered sharing of personal information, even without monetary exchange. You have the right to opt out of this sharing.

HOW TO OPT OUT OF SHARING FOR ADVERTISING:

Cookie Types We Use:

  • Essential Cookies: Required for website functionality
  • Analytics Cookies: Used to understand site traffic
  • Advertising/Targeting Cookies: Used to deliver and measure ads (Meta Pixel, Google Ads tags)

You can instruct your browser to refuse all cookies, though this may affect some site functionality. Our website does not currently respond to browser Do Not Track signals.


7. DATA RETENTION

We retain your personal information for as long as necessary to provide services, maintain business records, and comply with legal obligations. When no longer needed, we securely delete or anonymize it.

General retention guidelines: customer contact and booking records are retained for as long as you are an active client and for a reasonable period thereafter; financial transaction records are retained as required by applicable tax and accounting laws; marketing preferences and opt-out records are retained indefinitely to honor your choices.


8. DATA SECURITY AND BREACH NOTIFICATION

We implement reasonable organizational, technical, and administrative safeguards to protect your personal information from unauthorized access, disclosure, alteration, or destruction. However, no method of electronic transmission or storage is 100% secure.

In the event of a data breach involving your personal information, we will notify affected California residents as required by California Civil Code Sections 1798.29 and 1798.82, which require notification in the most expedient time possible and without unreasonable delay. Breach notifications will be sent to the email address or mailing address we have on file for you.

If you believe your interaction with us is no longer secure, please contact us immediately at medspaeyecandy@gmail.com.


9. YOUR CHOICES

  • Opt out of marketing emails: Use the unsubscribe link in any email
  • Opt out of SMS: Reply STOP to any text message
  • Opt out of advertising data sharing: Email medspaeyecandy@gmail.com with subject Do Not Share My Personal Information
  • Access or correct your information: Contact us at medspaeyecandy@gmail.com
  • Request deletion of your information: Contact us at medspaeyecandy@gmail.com (subject to legal retention requirements)

10. INFORMATION FOR CALIFORNIA RESIDENTS (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with specific rights regarding your personal information.

Categories of Personal Information Collected in the Last 12 Months:

  • Identifiers: name, email, phone, IP address, device identifiers
  • Customer records information: name, address, payment information
  • Sensitive Personal Information: health-related information voluntarily provided for treatment purposes
  • Commercial information: purchase and service history
  • Internet and network activity: browsing behavior on our site
  • Geolocation data: approximate location derived from IP address
  • Inferences: preferences drawn from your service history and interactions

Selling and Sharing of Personal Information: We do not sell personal information for monetary consideration, including the personal information of minors under 16. We do share certain identifiers and browsing data with advertising platforms (Meta, Google) for cross-context behavioral advertising purposes, which may constitute sharing under the CPRA. You have the right to opt out of this sharing (see Section 6).

Your CPRA Rights:

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected, used, shared, or sold about you in the past 12 months
  • Right to Delete: Request deletion of personal information we have collected, subject to certain legal exceptions
  • Right to Correct: Request correction of inaccurate personal information we hold about you
  • Right to Opt-Out of Sharing: Direct us not to share your personal information for cross-context behavioral advertising
  • Right to Limit Use of Sensitive Personal Information: Request that we limit our use of your Sensitive Personal Information to what is necessary to provide the requested services
  • Right to Non-Discrimination: We will not deny services, charge different prices, or provide a different quality of service because you exercised any of your CPRA rights

To exercise any of these rights, contact us at medspaeyecandy@gmail.com. We will verify your identity and respond within 45 days (extendable by an additional 45 days with prior notice). All disclosures are provided free of charge.

Authorized Agents: You may designate an authorized agent to make a request on your behalf. We may require proof of your authorization and will verify your identity directly with you before processing the request.

California Shine the Light (Cal. Civil Code Sec. 1798.83): California residents with an established business relationship with us may request information once per year about personal information shared with third parties for their direct marketing purposes. To make such a request, contact us at medspaeyecandy@gmail.com or write to us at any of our locations listed in Section 14.

California Minor Users (Cal. Bus. and Prof. Code Sec. 22581): California residents under 18 who are registered users of our online services may request removal of publicly posted content. Contact us at medspaeyecandy@gmail.com to make such a request.

Do Not Track: Our website does not currently respond to browser Do Not Track signals, consistent with the lack of a uniform industry standard.


11. THIRD-PARTY LINKS AND PAYMENT SERVICES

Our website may contain links to third-party websites (including social media platforms). We are not responsible for the privacy practices of those third parties and encourage you to review their privacy policies before providing any personal information.

Payment Processing: Payments are processed by third-party payment processors who are PCI-DSS compliant. We do not store your full credit card or financial account details. Payment information is subject to the privacy policies of those processors.


12. CHILDREN’S PRIVACY

Our Services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at medspaeyecandy@gmail.com and we will promptly remove that information from our records.


13. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the Last Updated date at the top of this policy and post the revised policy on our website. For significant changes, we will provide notice by email or a prominent notice on our website at least 30 days before the change takes effect where practicable. Your continued use of our Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.


14. CONTACT US AND PRIVACY REQUESTS

For all privacy-related questions, requests, or concerns — including requests to access, delete, correct, or opt out of sharing of your personal information — please contact us:

Eye Candy MedSpa and Lash Bar | Eyecandy Medspa MSO LLC
Privacy Contact Email: medspaeyecandy@gmail.com
Subject line for privacy requests: Privacy Request – [Your Name]

Buena Park: 5801 Lincoln Avenue, Suite B, Buena Park, CA 90620 | (714) 723-0770
Newport Beach: 1829 Westcliff Dr, Newport Beach, CA 92660 | (949) 877-0256
Lakewood: 11134 Del Amo Blvd, Lakewood, CA 90715 | (562) 402-1888


Effective Date: May 2026
This Privacy Policy was prepared for Eyecandy Medspa MSO LLC doing business as Eye Candy MedSpa and Lash Bar, a California limited liability company.

ABOUT US

1,700+ Reviews Across 3 Locations

Rated 4.8 out of 5

At Eye Candy Medspa and Lash Bar, we enhance your natural beauty with expert skin and aesthetic treatments.

CONTACT US

LOCATIONS

5801 Lincoln Avenue, Suite B, Buena Park, CA 90620

1829 Westcliff Dr, Newport Beach, CA 92660

11134 Del Amo Blvd, Lakewood, CA 90715

Copyright 2026 Eye Candy – All rights reserved.