Legal

Privacy Policy

Effective date: August 19, 2026 (also the date this version was last updated)

Who we are and how to contact us

T.A.P by Yasa Laser is an aesthetic treatment journal / passport product operated by 1001285246 Ontario Inc., an Ontario corporation. The product is meant to help people keep a personal log of aesthetic treatments that is often missing today — user-controlled, not a clinic chart. Yasa Laser Clinic is a healthcare / aesthetic provider that partners with us on product experience and guidance. It is not the App operator, and there is no sale of the App to that clinic and no revenue share from the App. This policy applies to information we process through the App and website. It does not cover a clinic’s or provider’s own practices outside our processing (for example, care they provide in clinic, or messages already in a clinic inbox).

Operator: 1001285246 Ontario Inc.
Mailing address: 2308 Sunningdale Rd W, London, Ontario N6H 5L2, Canada
Privacy officer: Jamie Sabino
Phone: 519-701-7570
Email: support@tapbyyasa.com

The App is currently distributed through the Apple App Store. Google sign-in is available on iOS. We do not currently offer Google Play distribution.

The Services are intended for users in the United States and Canada. The website is available in English and French (Canada). We do not geo-block Quebec or other Canadian provinces. 1001285246 Ontario Inc. is an Ontario corporation and treats the federal Personal Information Protection and Electronic Documents Act (PIPEDA) as the baseline private-sector privacy law for the Services.

Privacy questions, access or correction requests, consent withdrawal, and suspected incidents: contact Jamie Sabino (privacy officer) at support@tapbyyasa.com or 519-701-7570. Related pages: Terms of Use, Delete Account, and Support. If we cannot resolve a privacy concern, you may also contact the Office of the Privacy Commissioner of Canada or your provincial or territorial privacy commissioner, or (where you live in the United States) the privacy authority that applies to you. You may also write to 1001285246 Ontario Inc., 2308 Sunningdale Rd W, London, Ontario N6H 5L2, Canada.

Categories of information we collect

Depending on how you use the Services, we may process:

  • Account and identity — name, email address, authentication provider (email, Apple, or Google), profile photo or avatar, and account timestamps.
  • Health, treatment, wellness, and photographic information (user-entered) — journal fields you choose to enter (for example allergies, medications, and related profile details), treatment modalities, dates, notes, providers, appointments, skincare and areas-of-concern tracking when those features are on your plan, and photos (treatment photos, concern check-in photos, and avatars). This is information you store for personal organization. The App is not a substitute for medical advice, diagnosis, or treatment; it is not an electronic medical record system; and we do not claim that the Services are a HIPAA-covered clinical system.
  • Scheduling callback requests — preferred contact method, phone number, service interest, and free-text notes you submit so we can email a provider or clinic you designate (when the feature is enabled for your plan).
  • Push and device — push tokens and notification preference toggles (reminders versus clinic product or marketing messages).
  • Approximate location (optional) — if you grant location permission, the App uses it on your device to sort nearby providers in the directory. We do not store those coordinates on your account profile.
  • Product feedback — category, message, and app version / build / platform metadata. Feedback does not create a support SLA.
  • Support and email — messages you send to support@tapbyyasa.com.
  • Diagnostics and security — authentication logs, server logs, and abuse or rate-limit metadata as needed to operate and protect the Services. The iOS App does not include a third-party analytics, crash, or advertising SDK.
  • Subscriptions (T.A.P Plus) — App Store transaction and entitlement state synced through our subscription tooling (including RevenueCat webhooks) so we can apply plan tier and photo limits.
  • Website — standard hosting and request logs; information you submit through contact or support channels. This website does not use advertising cookies, pixels, session replay, a third-party analytics SDK, or embedded third-party font or form vendors. If that changes, we will update this policy.

Device permissions the current iOS App may request: photo library and camera (journal, avatars, and concern photos), notifications (for push delivery), and location when in use (nearby-provider sort only). The current App does not use calendars, contacts, HealthKit, or the microphone for a product feature.

Sources of information

  • You, when you create an account, enter journal content, upload media, adjust preferences, or contact support.
  • Your device or operating system (for example push permission state, optional location permission, and basic technical metadata).
  • Apple or Google when you use those sign-in options.
  • Apple App Store and RevenueCat entitlement signals for T.A.P Plus.
  • Clinics or operators only insofar as you redeem a clinic sponsorship code or submit a user-initiated callback request. A sponsoring clinic does not receive your identity from a redemption.

Purposes and consent

We use personal information to:

  • Provide and maintain journal, account, and related App features (necessary to operate the account you request).
  • Enforce plan tiers, photo limits, and feature access.
  • Process and reflect T.A.P Plus subscription entitlements.
  • Send reminders and other operational notifications you enable (treatment and appointment reminders default on; you can turn them off in the App).
  • Send generic clinic-program or product notifications only where your preferences allow (those toggles default off). We send those messages; the sponsoring clinic is not told who enabled them and does not choose the recipient list. A preference toggle is a product control; it is not, by itself, a statement that a particular message satisfies anti-spam law.
  • Send callback emails you initiate to a designated provider or clinic.
  • Provide support, troubleshoot issues, and improve the product based on feedback you submit.
  • Maintain security, prevent abuse, and comply with law and app-store requirements.
  • Communicate about material service changes, including possible wind-down or discontinuation notices.

Required vs optional. Journal fields and photos exist because you choose to enter or upload them so your personal log works. That is not a separate clinic consent. If you do not want that data stored, do not enter it, delete it in the App, or delete your account.

Activity Required or optional If you refuse or withdraw
Account, journal, saved photos, plan/entitlements, security, service notices Required to provide the App you asked for You cannot use those features (or the account) without them
Treatment and appointment reminders Optional (default on) Turn off in Settings or OS notification permission; the journal still works
Clinic-program or product notifications Optional (default off) Leave off or turn off in Settings; the clinic is not told who opted in
Location to sort nearby providers Optional Deny OS permission; directory still works without proximity sort. Coordinates are not stored on your profile
Clinic sponsorship code Optional (plan benefits only) Do not redeem. Redeeming does not share your journal with the clinic
Request-callback to a clinic Optional; sending that message is consent for that email Do not tap send. After delivery we cannot recall it from the clinic’s inbox
Product feedback Optional Do not submit; no effect on the journal
Skin Analyzer / Face Map Not in the current App Store build We will ask again if we enable those features

How we record this today. Signup currently requires agreement to the Terms of Use. Notification choices are stored as on/off preferences with an updated timestamp — not a separate marketing-consent archive. We do not yet store a signed copy of the Privacy Policy version at signup; the policy on this website is the current one. Withdrawing optional consents (Settings → notifications, OS permission, stop uploading, delete account, or email support) does not recall a callback already delivered and does not cancel T.A.P Plus.

We do not use automated decision-making that produces legal or similarly significant effects about you. Plan limits and feature gates follow your Free, clinic-sponsored, or T.A.P Plus entitlement. They are not a credit, eligibility, or profiling engine.

Photos, hosting, and on-device features

Journal and avatar photos you save are uploaded to private cloud storage so they can be shown in your account. Access uses time-limited signed URLs, not public file links. Our hosting provider stores those files to operate the Service. We do not sell your photos. We do not currently use your photos to train machine-learning models (ours or a third party’s), and we do not run a product feature that sends your photos into a training or testing pipeline.

When you pick a photo, the App may read the capture date to help organize your journal. Upload processing resizes and compresses images and may drop some metadata, but we do not guarantee that all location metadata is removed. The original library file stays on your device under your operating system’s photo rules.

Skin Analyzer / Face Map are not enabled in the current App Store build. Those features, if enabled later, are designed to run analysis on your device as non-diagnostic organizational aids. We will update this policy if that changes. Photos you separately save to your journal are still stored as described above.

Clinic sponsorship and callbacks

Clinics that purchase a package of sponsorship redemptions (“seats”) are customers of 1001285246 Ontario Inc. for that package. Your journal stays yours. App account data and a clinic’s own clinical records are not combined.

If you redeem a clinic sponsorship code, we record that redemption in our systems and update your plan benefits (for example tier, photo limit, and which modules or notification options are available). The sponsoring clinic does not have access to our database and cannot see that it was you who redeemed, or your identity, usage, treatment entries, photos, profile fields, or notification preferences. Those remain under your control in the App. There is no clinic-staff dashboard for viewing user journals.

We may share with a seat-package clinic only aggregate figures (for example how many of its seats have been redeemed), not names, contact details, or journal content. Once you redeem a code, the clinic cannot revoke that redemption or cut your storage entitlement. Sponsored benefits last until the expiry configured for that code (and subject to other plan rules, such as T.A.P Plus).

If you enable clinic-program or product notifications, 1001285246 Ontario Inc. may send you generic messages (push and/or email) about programs or products. We send those messages; the clinic does not know who opted in and does not pick recipients. They default off. Turn them off anytime in Settings → notifications, or disable OS push permission. We do not claim that a Settings toggle by itself satisfies every anti-spam statute. Sender for those App messages: 1001285246 Ontario Inc., support@tapbyyasa.com.

When you submit a request-callback, we email the details you provide (such as name, contact preferences, phone, service interest, and notes) to the designated provider or clinic so they can respond. That email is separate from sponsorship and from your in-App journal. Sending it does not turn your journal into a clinic chart. Once the message is delivered, it may become part of that clinic’s own records and is handled under the clinic’s privacy practices; we cannot recall it from their inbox. Clinics make their own care decisions.

Access, correction, deletion, support, and suspected privacy or security incidents for T.A.P account data are handled by 1001285246 Ontario Inc. (privacy officer: Jamie Sabino). A clinic does not respond to those requests for your App journal, except for information already in its own inbox or clinic systems.

Sharing and disclosures

We do not sell your personal information. We also do not share personal information for cross-context behavioral advertising as those terms are commonly used under US state privacy laws.

We may disclose information:

  • Service providers — vendors that help us operate the Services (hosting, authentication, storage, subscriptions, push delivery, email, and security). See the service-providers table below.
  • Clinics and providers — as described under clinic sponsorship and callbacks.
  • Legal and safety — when we believe disclosure is reasonably necessary to comply with law or legal process (such as a valid court order, warrant, or similar demand); to protect the safety of users or others; to investigate or prevent fraud, security incidents, or abuse; or to enforce our Terms of Use. We do not treat this as an unlimited right to share for any purpose we choose.
  • Corporate events — if we are involved in a merger, financing, reorganization, acquisition, or sale of assets, personal information may be transferred as part of that transaction, subject to this policy or a successor policy we will describe if the recipient’s practices differ in a material way.
  • De-identified or aggregated information — we may retain or use information that no longer reasonably identifies you (including after account deletion) for operations, security, or product improvement.

Service providers

We use service providers that process personal information on our behalf under their customer terms and, where they publish one, a data processing addendum. Those terms typically include confidentiality and security commitments. We do not sell personal information to them. We do not claim their practices are identical to this policy.

The current production stack includes:

Role Provider What they process
Auth, database, file storage, edge functions Supabase Account, journal, media, push tokens, and related backend data
Website hosting and auth-callback Cloudflare Website content delivery, request logs, and email-link forwarding into the App
Mobile build and push delivery Expo / EAS (and Apple APNs) App distribution tooling and push delivery
Subscriptions Apple App Store and RevenueCat Purchase and entitlement signals for T.A.P Plus
Social login Apple, Google Sign-in identity signals you authorize (Google sign-in is available on iOS)
Transactional email from the App Resend Account-deletion, scheduling-callback, and other operational emails sent by our backend
Support inbox routing Cloudflare Email Routing Delivery of messages sent to support@tapbyyasa.com

We will update this list when production vendors change in a material way.

International transfers

The Services are intended for users in the United States and Canada. Infrastructure providers may process or store information in the United States or other countries where they operate. Those countries may have different privacy laws, and foreign courts, regulators, or law-enforcement authorities may be able to access information under local law. Where required, we rely on contractual and organizational safeguards with those providers.

Retention

  • Account and journal data are retained while your account remains active.
  • If you delete in the App, you can choose immediate deletion after email confirmation, or a 30-day grace period you can cancel in Settings. The 30-day option is a cooling-off window before wipe, not a promise that every copy of every record disappears on a fixed 30-day clock.
  • If you request deletion by email instead, we typically acknowledge within 1–2 business days and aim to complete a verified wipe within 30 days, unless a legal hold or verification issue requires more time.
  • After a wipe runs, we delete or de-identify personal information associated with the account, subject to the exceptions below.
  • Support correspondence may be retained as needed to handle your request and maintain service records (the support mailbox is outside the in-app wipe).
  • Subscription and billing records held by Apple, RevenueCat, or us may be retained as required for accounting, tax, dispute, or legal purposes. Deleting the App account does not cancel T.A.P Plus.
  • Residual copies may remain in encrypted database backups for a limited window after deletion (typically up to about seven days, depending on our hosting provider’s backup settings). Backup copies are not used to restore a deleted account in ordinary operations.
  • If you used in-app export shortly before deletion, a copy of that export file may remain in private storage for a limited window (typically about seven days) until the download link expires.
  • Emails already delivered to a clinic or provider, and copies in our email vendor’s logs, are not recalled by account deletion.
  • User-created provider-directory entries may remain in an unattributed form (the link to your account is removed) so other operational records are not broken.
  • Security and server logs on our vendors’ platforms may be retained for a limited operational period unless a longer period is needed for investigations.

Security and incidents

We use reasonable administrative, technical, and organizational safeguards intended to protect personal information, including encryption in transit and access controls appropriate to the App (including row-level access controls in our backend where applicable). No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

If you suspect a privacy or security incident involving the Services, email support@tapbyyasa.com. We maintain internal processes for reviewing and responding to incidents, including where law requires records or notices.

Your choices and rights

  • Access, correction, export, and deletion — use in-app export (Settings → Export my data) and in-app deletion (Settings → Account → Delete account), or email support@tapbyyasa.com from the address on your account. Export is the portable copy we provide. 1001285246 Ontario Inc. (privacy officer: Jamie Sabino) handles these requests for T.A.P account data, not a sponsoring clinic. Details are on the Delete Account page.
  • Withdraw optional consents — Settings → notifications, OS permission, stop uploading, or delete your account, as described under purposes and consent. Withdrawal does not recall a callback already delivered and does not cancel T.A.P Plus.
  • Complaints — contact the privacy officer first (see “Who we are and how to contact us”). If we cannot resolve a privacy concern, you may contact the Office of the Privacy Commissioner of Canada, your provincial or territorial privacy commissioner, or (where you live in the United States) the privacy authority that applies to you.
  • Notification preferences — manage reminder and clinic marketing toggles in the App, and OS push permissions on your device.
  • T.A.P Plus cancellation — cancel in Apple ID → Subscriptions. Deleting your App account does not by itself cancel an Apple subscription.
  • US state privacy rights — depending on where you live, you may have rights to know, access, correct, delete, or obtain a portable copy of certain personal information, and to appeal a denied request. We do not sell personal information or share it for cross-context behavioral advertising. To exercise rights or appeal, contact support.
  • Canada — as an Ontario business, we handle Canadian personal information under PIPEDA as the baseline. You may request access to or correction of personal information we hold about you, including where Quebec’s private-sector privacy law, Alberta’s Personal Information Protection Act, or British Columbia’s Personal Information Protection Act applies to you, subject to limited exceptions under applicable law. Contact support to make a request. If we cannot resolve it, use the complaints path above.

Operational messages (for example account security, or appointment and treatment reminders you enable) differ from clinic-program or product notifications, which depend on plan context and toggles that default off. OS-level permission is required for push delivery. Appointment reminder text uses visit date and status; it does not include treatment type, notes, or photos. Clinic-program or product broadcasts, when you enable them, are optional commercial messages we send; the clinic is not given a list of who opted in. Unsubscribe in Settings as described above.

Account deletion and export

See Delete Account for the current in-app path, email fallback, timelines, and what is deleted versus retained. You can export a JSON copy of account data in the App before deletion. Support can also assist with export if you cannot use the App. Emails already delivered to a clinic or provider may remain in that recipient’s systems outside our control.

Service discontinuation

We may modify, suspend, limit, or discontinue the Services. If we wind down the Service, we will provide reasonable notice where commercially and operationally practical, offer an opportunity to export or retrieve data you wish to keep when feasible (including in-app export while the App remains available), and may place accounts in a read-only state before retirement. After wind-down deadlines, remaining personal information is deleted or de-identified according to our retention practices, subject to legal and backup exceptions. We do not promise perpetual free access, lifetime storage, or permanent hosting of your content.

Children

T.A.P by Yasa Laser is not intended for anyone under 18, or under the age of majority where they live if that age is higher. We do not knowingly collect personal information from those users. If you believe we have collected personal information from someone who does not meet this requirement, contact us so we can review and delete the account.

Changes

We may update this policy as the App and website evolve. If we make material changes, we will update the effective date above and provide additional notice in the App, by email, or on the website where appropriate. Where we require a new in-app acceptance of this policy, we will ask for it in the App. We intend to record the version and date you accept; that record is still being completed (see “How we record this today”).