Hone Privacy Policy
Effective date: May 22, 2026·Last updated: August 24, 2026
1. Who we are
Hone is a software service for electrolysis and skincare practitioners to manage client records, appointments, treatment notes, and related practice operations.
Hone is operated by Sam Vemuri (an individual operating as Hone, pending incorporation), located in Ontario, Canada.
For privacy-related questions, contact us at privacy@hone.care.
A formal mailing address will be provided here once our registered business address is established. In the interim, written correspondence may be sent to privacy@hone.care and we will provide a mailing address for service of legal documents upon request.
2. Scope
This policy describes how we collect, use, store, share, and protect personal information when you use Hone at hone.care or any subdomain. It applies to:
- Practitioners who sign up to use Hone to run their practice (“Studio Owners” and “Practitioners”)
- Clients of those practitioners whose information is entered into Hone by the practitioner
- Prospective clients who give a studio their details through its public Hone booking page before becoming a client at all — in particular by joining a studio’s new-client waitlist. You are covered by this policy from the moment you submit that form, whether or not you ever book, and whether or not a practitioner has ever entered anything about you
We process data on behalf of practitioners. Practitioners are the data controllers of their clients’ and prospective clients’ information. Hone is the data processor.
3. Personal information we collect
From practitioners directly
- Name, email address, phone number
- Login credentials (passwords are hashed, never stored in plaintext)
- Studio name, business address, business contact info
- Billing information (processed by our payment processor, not stored by Hone)
From practitioners about their clients
- Client name, contact information (email, phone, address)
- Date of birth, gender, pronouns
- Skin type, Fitzpatrick classification, allergies, contraindications
- Treatment notes, session records, photos (if uploaded)
- Appointment history, treatment plans, treatment goals
- Emergency contact information
- Health intake responses
From prospective clients directly
When a studio is taking new clients by waitlist, its public booking page offers a short form instead of the booking flow. If you fill that form in, you give us the information — no practitioner enters it, and you do not need an account. We collect:
- Your name and email address
- Your phone number, if you choose to give one; it is optional
- Which studio’s waitlist you joined, and when
- Where the studio keeps its waitlist with us, whether you are still waiting, or have been removed from that waitlist by the studio
That is the whole list. The waitlist form does not ask for health information, and joining a waitlist does not create a client record, an appointment, or an intake form for you.
Automatically when you use Hone
- IP address, browser type, device information
- Pages visited, actions taken, timestamps
- Cookies and similar technologies for authentication and session management
From third parties
- Authentication providers (Google) if you sign in with them
- Payment processors for billing confirmation
Sensitive health information
Some of the information that practitioners enter about their clients is sensitive health information, including:
- Allergies and contraindications
- Skin conditions and Fitzpatrick skin type
- Treatment notes and clinical observations
- Health intake responses (medical history, medications, conditions)
- Photographs of skin or treatment areas
Sensitive health information receives enhanced protection under Canadian privacy law and our practices:
- Practitioners must obtain explicit, informed consent from clients before entering sensitive health information into Hone
- We apply strict access controls so this information is only visible to authorized practitioners within the client’s studio
- Practitioners are responsible for handling this information in accordance with applicable health information privacy laws in their jurisdiction
- Clients have the right to know what sensitive health information their practitioner has stored about them and to request access through their practitioner
If you are a client and have concerns about sensitive health information stored about you in Hone, contact your practitioner directly. If your practitioner does not respond, you may also contact us at privacy@hone.care.
4. How we use personal information
We use personal information to:
- Provide the Hone service to practitioners
- Authenticate users and secure accounts
- Send appointment reminders and confirmations on behalf of practitioners (only when the practitioner has enabled this)
- Run a studio’s new-client waitlist on its behalf, and let that studio contact you about availability if you joined it
- Process payments and billing
- Respond to support requests
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
- Improve the service through aggregate, anonymized analysis
We do not:
- Sell personal information to third parties
- Use client health information for advertising
- Train machine learning models on practitioner or client data
- Access practitioner data except as needed for support (with permission) or required by law
5. Where we store data
Personal information is stored on infrastructure provided by Supabase, hosted in AWS US-East-1 (Northern Virginia, United States).
This means data may be transferred to and stored outside of Canada. The United States has different privacy laws than Canada, and US authorities may have legal access to data stored in the US under US law.
We selected this provider because it offers strong security, reliability, and the technical features needed to operate Hone. We are evaluating Canadian data residency options for future deployments.
Practitioners and clients in Canada should be aware that by using Hone, their information is transferred to and processed in the United States.
6. How we share personal information
We share personal information only as follows:
With service providers who help us operate Hone, under contract:
- Supabase (database and authentication)
- Vercel (web hosting)
- Resend (transactional email delivery)
- Twilio (SMS delivery, when enabled by practitioner)
- Stripe (payment processing, when enabled by practitioner)
- Anthropic (AI-assisted features, when enabled, with data minimization)
When required by law, such as in response to a valid court order, subpoena, or government request, after legal review.
With clients of practitioners, at the practitioner’s direction (e.g., appointment confirmation emails sent to a client).
With the studio whose waitlist you joined. A waitlist request belongs to that one studio: we handle it for that studio alone, it is visible only to that studio, and it is not shared with any other studio on Hone.
What happens to your request depends on the studio. A studio’s new-client waitlist is either kept with us as a stored record, or not kept by us at all. Which applies is a setting on the studio, not on you, and it can change. Ask the studio, or write to privacy@hone.care, and we can tell you how that studio’s waitlist is handled now. We do not record, for each request, which handling was in force when it was made — so for an earlier request we may not be able to establish afterwards which of the two applied.
Where the waitlist is kept with us, your entry is recorded when you submit it. We also try to notify that studio by email so it can act on your request sooner, and to send you an acknowledgement that you joined. Those emails are attempted, not guaranteed: a message can fail to send or fail to arrive, and a studio may have no email address set up to receive one. Your entry is stored either way. A notification that never arrives does not mean your request was not recorded.
Where it is not kept with us, we keep no waitlist entry for you at all. Instead we attempt to send your details to the studio by email, and that message is the request itself rather than a notification about a record on our side. What we can confirm is that our email service accepted the message for sending; that is not the same as the studio receiving it, and we cannot promise it arrives. Where it does arrive, the studio may keep it under its own practices — but we cannot tell you that such a copy exists.
What we tell you when that attempt does not clearly succeed depends on what we actually know. If we know the request was not sent — for example because there is no studio email address available, or because the send cannot be started or is refused — we tell you the request did not go through. If the outcome is uncertain instead, meaning we tried and could not establish what happened, we tell you we could not confirm your request, and ask you to contact the studio before trying again. We do not describe an uncertain outcome as a failure, and in neither case do we tell you that you joined.
Under either handling, joining a waitlist does not create an appointment, a client record, or an intake form for you.
In connection with a business transfer, such as a merger or sale of assets, with notice to affected users.
Hone does not sell your personal information and does not share it for Hone’s own marketing. A studio may enable optional marketing or analytics integrations for its own booking pages; where enabled and consented, limited non-clinical booking event data may be shared with that studio’s configured provider, as described in Section 7.
7. Cookies and tracking
We use cookies for:
- Authentication (keeping you signed in)
- Session management
- Security (preventing cross-site request forgery)
Hone does not enable advertising or behavioral tracking by default, and Hone itself does not use third-party advertising cookies to target you across the web.
7.1 Optional studio-enabled marketing and analytics integrations
A studio may choose to enable third-party marketing or analytics integrations for its own booking pages and ads, for example Meta, Google, TikTok, Pinterest, LinkedIn, Microsoft Ads, or similar providers. Where a studio enables such an integration and, where applicable, you consent, Hone may send limited booking or conversion event information to the studio’s configured provider, and may process these events on the studio’s behalf.
The pixel, tag, dataset, token, or ad account used belongs to the studio, not to Hone, unless we state otherwise. Hone does not mix one studio’s conversion data with another’s. You can still complete a booking even if you decline non-essential marketing tracking, subject to any separate cookie choices on the studio’s own website.
When such an integration is enabled and consented, Hone may send only minimal, non-clinical conversion data, which may include:
- the event name or type (for example, that a booking was confirmed)
- the event time and a booking-derived event identifier
- the booking page address (event source URL)
- hashed contact identifiers, such as a hashed email or phone number, where consent and configuration permit
- a generic service category only, such as consultation, electrolysis, laser, or other
- basic browser context such as IP address or user agent, only where legally permitted and collected as part of the booking request
Hone does not send sensitive clinical information to marketing or analytics providers. In particular, Hone does not send:
- intake answers or other health information
- treatment notes or appointment notes
- contraindications or allergies
- body areas or treatment photos
- cancellation reasons
- exact, sensitive service names
- raw access tokens or portal links
8. Your rights under PIPEDA
If you are in Canada, you have the following rights under the Personal Information Protection and Electronic Documents Act (PIPEDA):
- Right to access the personal information we hold about you
- Right to correct inaccurate or incomplete information
- Right to withdraw consent to certain uses (subject to legal or contractual restrictions)
- Right to file a complaint with the Office of the Privacy Commissioner of Canada
To exercise any of these rights, contact us at privacy@hone.care. We will respond within 30 days.
If you are a client of a practitioner using Hone, please contact your practitioner first for access or correction requests, as they are the data controller of your information. We will assist your practitioner in fulfilling your request.
If you joined a studio’s new-client waitlist and no longer want to be on it, or want to know what that studio holds about you, contact the studio — it is the controller of your request and can remove you. You may also write to privacy@hone.care, and we will assist. Where we hold a waitlist entry for you we can find it and act on it. Where we kept none, there is nothing on our side to look up, and we may not be able to tell you afterwards which handling applied or whether the message reached the studio. You do not need an account with us to make either request.
9. Data retention
We retain personal information for as long as:
- The practitioner’s account is active
- Necessary to provide the service
- Required by legal or regulatory obligations (typically up to 7 years for billing records)
When a practitioner closes their account, their data is retained so the account can be recovered and so we can meet our legal and record-keeping obligations. Practitioners may request deletion in writing at privacy@hone.care. We review permanent-deletion requests and respond based on what can be deleted, subject to applicable legal and professional record-retention requirements.
When a client is deleted by their practitioner in Hone, the record is archived, marked as deleted and hidden from everyday use, but retained for audit and clinical-record purposes. Archiving is not the same as permanent erasure: the record remains in our systems, and in backups, unless and until it is permanently deleted following a request we have reviewed and actioned.
We do not currently operate an automatic timed purge that permanently erases archived records or expires backup copies on a fixed schedule. Requests for permanent deletion are handled case by case through the process above, or through your practitioner where they are the controller of the record.
A stored new-client waitlist entry — one held for a studio whose waitlist is kept with us, as section 6 describes — is kept for as long as the studio keeps it. When a studio removes someone from its waitlist, the entry is marked as removed and retained as a record that the request was made and acted on, rather than erased — the same archiving distinction described above. We do not currently run an automatic timed purge of waitlist entries, and we do not claim any fixed retention period for them. Permanent deletion is handled case by case through the process above.
Where a studio’s waitlist is not kept with us, we keep no waitlist entry for you, so there is nothing on our side to retain and nothing for us to delete. We attempt to send your request to the studio by email. If that message arrives, copies of it may remain in the studio’s systems and in the email systems that carried it, under their retention practices rather than ours. We cannot promise it arrived, and we cannot tell you that any such copy exists. Ask the studio to remove you — and we will not claim to delete a record we never held.
Deletion can also be constrained by law and by professional record-retention obligations. Electrolysis and laser treatment records are clinical records, and practitioners are frequently required to retain them for a minimum period. Where such an obligation applies, we will retain the data for as long as it requires and delete it afterwards.
10. Security
We protect personal information with:
- TLS encryption for data in transit
- Row-level security so practitioners only access their own studio’s data
- Authentication via Supabase Auth using Google OAuth and email magic links. Hone does not collect or store account passwords directly.
- We review security-sensitive changes before deployment
No system is completely secure. If we become aware of a security breach affecting your personal information, we will notify you and applicable regulators as required by law.
11. Children’s privacy
Hone is intended for use by adult practitioners. Practitioners may store information about minor clients, but only as authorized by the minor’s parent or guardian as part of their professional services.
We do not knowingly collect personal information directly from children under 16. If you believe we have, contact privacy@hone.care.
12. International users
Hone is operated from Canada with infrastructure in the United States. If you access Hone from outside Canada or the US, you consent to the transfer of your information to these jurisdictions.
We do not currently target users in the European Economic Area, United Kingdom, or other jurisdictions with specific data residency requirements. If you are in one of these regions and have concerns, contact us before signing up.
13. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email to account holders at least 30 days before taking effect. The current version is always available at hone.care/privacy.
The two dates at the top of this page mean different things. Effective date is when this policy took effect. Last updated is when its text was last revised. Where a revision is a material change, it takes effect for account holders only after the 30-day notice described above; where it is not, the revised text is simply the current policy from the day it is published here. We do not apply a revision retroactively to information already collected under an earlier version.
14. Contact
Privacy questions: privacy@hone.care
Operator: Sam Vemuri (operating as Hone, pending incorporation), Ontario, Canada
Filing a complaint: Office of the Privacy Commissioner of Canada, 30 Victoria Street, Gatineau QC K1A 1H3, https://www.priv.gc.ca