Privacy Policy
Last updated: November 25, 2025
This Privacy Policy describes how LRM Aesthetics, Inc., (the “Site”, “we”, “us”, or “our”) collects, uses, and discloses your personal data when you visit, use our services, or otherwise communicate with us (collectively, the “Services”). For purposes of this Privacy Policy, “you” and “your” means you as the user of the Services, whether you are a customer, consumer, healthcare professional, website visitor, or another individual whose information we have collected pursuant to this Privacy Policy.
Please read this Privacy Policy carefully. By using and accessing any of the Services, you agree to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree to this Privacy Policy, please do not use or access any of the Services.
This Privacy Policy does not address how we process “Consumer Health Data” or “Regulated Health Information” as that term is defined under applicable state law about consumers who reside in the states of Nevada, Washington, New York, and any other applicable U.S. jurisdiction. Please refer to our Health Data Privacy Policy for more details.
To the extent that we process deidentified data, we will maintain and use the data in deidentified form and will not attempt to reidentify the data unless explicitly permitted by applicable law. Deidentified data that remains deidentified is not personal data and we may use such data for any lawful purpose. Deidentified data that is reidentified and otherwise qualifies as personal data is subject to this Privacy Policy.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will post the revised Privacy Policy on our website, update the “Last updated” date, and take any other steps required by applicable law.
What personal data do we collect about you?
We collect the below categories of personal data from you when you access the Services:
- Contact and Account Information: Name, email address, postal address, and phone number. If you create an account with us, we also collect demographic information such as your age, date of birth, and gender, in addition to your account username and password.
- Website Activity: We collect information related to your access to and use of our Services, including the type of browser you use, access times, pages viewed, your IP address, and the page you viewed before and after visiting our Services. We may also collect this type of information in visual form when you visit our Services, including video snippets of your Services activity.
- Device Information: We collect information about the computer or mobile device you use to access our Services, including the hardware model, operating system and version, unique device identifiers, and mobile network information.
- Health Related Information: We collect information that may relate to your health in the context of our regulatory responsibilities under the Federal Food, Drug, & Cosmetic Act (such as adverse event and product complaint reporting), health-related data that you disclose to us offline and online, such as through our consumer-facing websites, communications channels, or otherwise through the Services.
- Transaction Data: Depending on your relationship with us, you may be allowed to order our products through the Services. If you do so, we (and our payment processors) collect information as necessary to facilitate your purchase and order, including payment or financial information.
- Employment and Professional Information: Place of employment, credentials, and occupation or professional membership.
- Geolocation Information: Approximate location of your device from your IP address.
- Commercial Information: Information about your product and service preferences and interests, including interests in our products and services.
- Social Media Information: Account names, handles, biographies, and other details that you make available on social media networks.
- Other information that you may provide to us or that we may infer based on the above.
How do we collect personal data?
We collect personal data directly from you in the below contexts. We also collect personal data from you using sources like advertising or marketing networks, data analytics providers, social networks, data brokers, and other service providers or third parties.
- If you register an account with us or otherwise access the Services
- In connection with your interactions, inquiries, or other requests
- If you upload or share a photo or other digital content through one of our Services, or share content linking to any of our social media accounts
- If you participate in a contest, promotion, or survey
- If you contact us via e-mail or through our customer service, including through the use of online chat tools that we may make available
- We and our third-party vendors may use tracking tools like browser cookies, flash cookies, pixels, and web beacons to collect information from you. Please see “How do we use cookies and other tracking technologies?” for more information.
How do we use your personal data?
We may use your personal data in the following ways:
- To provide, operate, maintain, and protect our Services, including fulfilling your orders and requests for our products;
- To analyze and improve our Services, including developing new products or services;
- To communicate with you, respond to your inquiries, and to send you information by email, postal mail, telephone, text message, notifications, or other means about our products and services;
- To promote and conduct educational or promotional events, including those that may be in person and to support our marketing and advertising activities, including delivering personalized advertising;
- To enhance and help us better understand your browsing experience, needs, and preferences and provide consistent, personalized services and experiences across our Services;
- To protect the security or integrity of the Services, including to perform security analyses to verify that the Services is working properly and have not been compromised based on our legitimate interests;
- To protect us, our users, and the public, and comply with applicable law, regulation, or legal process, including to validate user information for fraud and risk detection purposes, resolve disputes and protect the rights of users and third parties, respond to claims and legal process (such as subpoenas and court orders), fulfill our reporting obligations, monitor and enforce compliance with our contracts, including our Terms of Service, and otherwise detect, prevent, or stop any activity that may be illegal, unethical, or legally actionable; and
- To evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which personal data held by us about our customers is among the assets transferred.
How do we disclose your personal data?
We disclose your personal data to the following categories of third parties:
- Service providers: We engage vendors and consultants to assist with and perform certain functions on our behalf such as: auditing and accounting firms, professional services consultants, providers of data hosting, storage, and analytics services, and IT and security vendors.
- Social media platforms: Where you choose to interact with us through social media, your interaction with these platforms typically allows the social media company to collect some information about you through cookies and other digital tracking mechanisms that they place on your device. In some cases, the social media company may recognize you through these technologies even when you do not interact with their platform. Please visit the social media companies’ respective privacy policies to better understand their data collection practices and the controls they make available to you.
- Companies involved in advertising: We work with companies that assist us in advertising our Services to you and others who may be interested in the Services. These companies may use tracking technologies on our Services to collect or receive information over time and across different websites or platforms, including this website and the Services and elsewhere on the internet, and use that information to provide measurement services and provide you with targeted ads.
- Corporate affiliates: We share personal data with our subsidiary companies.
- Business partners: We may work with other companies to provide you with certain product or service offerings.
- Law enforcement, government agencies, or parties in a legal proceeding: We may share personal data with these entities to comply with the law or assist law enforcement. We may also provide your personal data to third parties in the context of a subpoena or similar legal process.
- Third parties in the context of a merger or similar business transaction.
How do we use cookies and other tracking technologies?
We and our third-party vendors use cookies, pixel tags, and other tracking technologies on the Services in a variety of ways to enhance or personalize your online browsing experience. These tracking technologies help us better understand your needs and preferences and tell us which parts of our website you have visited, facilitate and measure the effectiveness of our advertisements, and provide consistent and personalized services and experiences.
These tracking technologies gather information over time and across different websites about you, some of which may be personal data as identified above in “What personal data do we collect about you?” We also use these technologies to support our targeted advertising activities. Some jurisdictions may consider targeted advertising to be a “sale” of personal data, and some jurisdictions may consider data about your interactions with our consumer-facing, health-related online Services (i.e., not the online Services intended for healthcare professional audiences) to be considered “health information” or “sensitive” personal data. Thus, we may “sell” personal data, including “sensitive” personal data about you. Please see “Your Privacy Rights,” below, for more information about rights and choices that you may have with respect to this practice, including how to request to opt out.
You can set your browser not to accept cookies or to notify you when you are sent a cookie, giving you the opportunity to decide whether or not to accept it. If you do not accept cookies, however, you may not be able to access your account information or utilize certain functionalities on our Services. Please note that our Services do not currently recognize “Do Not Track” signals. However, our Services may recognize certain opt-out preference signals, such as the Global Privacy Control, and will process such signals in accordance with applicable law, potentially including “do not sell”, “do not share”, “limit the use or disclosure of sensitive personal information,” and opt out of targeted advertising requests. You may set such a signal through your browser or browser extension.
Third-Party Links
Third-party links on the Services may direct you to third-party websites that are not affiliated with us, including social media platforms. We are not responsible for the content or accuracy of third-party websites, or for any other materials, products, or services of third parties.
We are not liable for any harm or damages related to the purchase or use of goods, services, resources, content, or any other transactions made in connection with any third-party websites. Please review carefully the third party’s policies and practices and make sure you understand them before you access their website. Complaints, claims, concerns, or questions regarding third-party products should be directed to the third party.
How do you protect my personal data?
We take reasonable precautions, including implementing physical and electronic safeguards, to help protect the security and privacy of your personal data. However, please be aware that no means of transmitting data over the internet is 100% secure. Please take steps to protect your own personal data, such as by selecting a unique and complex password for your account.
Do we collect children’s information?
We will never knowingly request personal data from anyone under the age of 18. The Services are not targeted to or intended for use by children. However, if we learn that we have received personal data from a child under the age of 18 without appropriate parental consent, we will delete that information from our database.
How long do we keep your personal data?
We retain personal data for as long as needed or permitted in light of the purpose(s) for which it was obtained and consistent with applicable law. The criteria used to determine our retention periods include:
- The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us);
- Whether there is a legal obligation to which we are subject (for example, we are required to keep records of your transactions for a certain period of time); or
- Whether retention is advisable in light of our legal position (such as in regard to applicable statutes of limitations, litigation, or regulatory investigations).
What choices do I have about my personal data?
You can review and change certain personal data related to your use of the Services (such as your name and contact information) by signing into your account or by contacting us as described in the section entitled, “Contact” below.
If you prefer not to receive promotional communications from us, such as information about special offers, you can let us know by contacting our customer service as described in the section entitled, “Contact” below. You may also follow the instructions included with the message, such as by following unsubscribe or opt out links. Please note that we may still send you messages in response to your inquiries or about other non-promotional items, such as managing your account or relationship with us.
Your Privacy Rights
You may have the rights listed below (“Data Subject Rights”) with respect to the personal data that we collect or process about you, however, these rights differ depending on your place of residency, including California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, Nevada, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. Please note that we reserve the right to honor your Data Subject Rights to the extent required by applicable law.
- Right to Confirm Processing, Access, and/or Obtain a Copy: If you ask us, we will confirm whether we are processing your personal data. Additionally, upon request, we will provide you with a copy of all personal data you are lawfully entitled to receive, potentially including specific pieces of information, along with certain other details.
- Right to Amend: If you believe your personal data is inaccurate or incomplete, you may request that we correct it.
- Right to Delete: You may request that we delete personal data that we maintain about you.
- Right of Portability: You may request that we move, copy, or transfer the electronic personal data that we hold about you to another organization.
- Right to Revoke Consent and/or Opt Out of Certain Processing Activities: You may ask us to restrict or stop the processing of your personal data. This includes general requests and requests in specific contexts, such as if we process personal data that is considered “sensitive” under applicable U.S. state laws or engage in certain automated decision-making activities.
- Right to Limit Use and Disclosure of Sensitive Personal Data: You may ask us to limit the use and disclosure of sensitive personal data.
- Right to Opt Out of Targeted Advertising or “Sharing”: Targeted advertising is the practice of serving you tailored advertisements based on your personal data gathered over time and across other businesses, websites, applications, or services. Some jurisdictions may refer to this activity as “sharing.” You have the right to opt out of this practice.
- Right to Opt Out of Sales: Some jurisdictions may consider targeted advertising a “sale” of personal data. You may request that we not “sell” your personal data.
- Right to Non-Discrimination: We will not discriminate against you for exercising Data Subject Rights, but we may charge a reasonable fee as permitted by law in fulfilling these rights, such as if you request multiple copies of your personal data.
- Right to Appeal: If we deny your request to exercise a Data Subject Right, you may have the right to appeal the decision with us. If you would like to appeal a prior decision, please be sure to include information about your prior request so that we may locate our earlier determination.
- Right to Lodge a Complaint: You may submit a complaint to the competent supervisory authority in the country or state in which you live if you have any concerns about our processing of your personal data or if we deny your appeal to review a prior decision about your Data Subject Rights.
If you or your authorized agent would like to exercise a Data Subject Right, you may do so by following the instructions in “How do I contact you?” below. Please note that you may also login to your account to access and correct your account information at any time.
In order to process your request to exercise a Data Subject Right, we will ask you to verify your identity by confirming your name, e-mail address, phone number, or other identifiable information that we have in our records, such as most recent interaction with us, if applicable.
Additional Disclosures for California Residents
If you reside in California, please read this section for additional disclosures about how we collect, use, and disclose information about you under the California Consumer Privacy Act (or “CCPA”) (California Civil Code Section 1798.100 et seq.).
- Categories of Personal Information Collected: In the previous 12 months, we have collected the personal information listed in the section “What personal data do we collect about you?” above. This information falls into the following categories under the CCPA: identifiers; categories of personal information described in Cal. Civ. Code 1798.80(e); commercial information; geolocation information; audio, electronic, or visual information; internet or electronic network activity information; inferences drawn from the above categories. Additionally, we collect the following “sensitive” personal information: account credentials and health information (interactions with our health-related online Services).
- Sensitive Personal Information Uses or Disclosures: The data that we capture about your interactions with some of our health-related online Services that are intended for consumer audiences (i.e., not healthcare professionals) may be considered “sensitive” personal information. We use this interaction data to support cross-context behavioral advertising. You may request that we limit this use of our “sensitive” personal information by following the instructions in “Your Privacy Rights.”
- Business or Commercial Purpose for Collecting and Selling Information: We collect personal information for the business and commercial purposes described in “What personal data do we collect about you?” and “How do we use your personal data?” above.
- Categories of Sources of Personal Information: We collect personal information from and about you as described in “How do we collect personal data about you?” above.
- Categories of Third Parties with Whom We Disclose Information: We may disclose your personal information with third parties as described in “How do we disclose your personal data?” above.
- Categories of Personal Information Disclosed: In the preceding 12 months, we have disclosed the categories of personal information listed in “What personal data do we collect about you?” for the reasons described in “How do we disclose your personal data?” above.
- Sale or Share of Personal Information: Because we engage in the practice of cross context behavioral advertising, also known as online targeted advertising, we may “sell” and/or “share” your personal information as those terms are defined by the CCPA. In the preceding 12 months, we may have “sold” or “shared” identifiers, commercial information, employment or professional information, health information (usage and interaction data with certain health-related webpages in our Services), and internet or electronic network activity information with data analytics, advertising networks, and/or social media networks. We do not have any actual knowledge that we sell or share the personal information of users under the age of 16.
International Users
Please note that we may transfer, store, and process your personal data outside the country you live in, including the United States. Your personal data is also processed by staff and third-party service providers and partners in these countries.
Contact
Should you have any questions about our privacy practices or this Privacy Policy, or if you would like to exercise any of the rights available to you, please email us at business@lrmaesthetics.com; call 888.LRM.PDGF (888.576.7343); or contact us at LRM Aesthetics, Inc., 302 Innovation Drive, Suite 500,
Franklin, TN 37067, United States.