This Privacy Policy explains how SGN NAIL SERVICES, doing business as She Got Nails – Nail Studio (“She Got Nails,” “we,” “us,” or “our”), collects, uses, stores, and shares personal data when you visit shegotnails.ph, contact us, create an account, book an appointment, place an order, sign up for updates, or otherwise interact with our business online or in person.
This policy is written to help you understand what personal data we collect, why we collect it, how we use it, and what choices and rights you may have.
1. Who We Are
Business name: SGN NAIL SERVICES, doing business as She Got Nails – Nail Studio
Website: www.shegotnails.ph
Privacy contact: She Got Nails Admin
Privacy email: privacy-first@shegotnails.ph
General contact email: shecares@shegotnails.ph
Phone: +63 949 645 8940
Address: 1081 Concepcion Aguila St, Quiapo, Manila, 1001 Metro Manila
If you have a privacy question or want to make a request about your personal data, please contact us using the privacy details above.
2. Scope of This Policy
This Privacy Policy applies to personal data we collect through our website, booking pages, account or login features, shop or checkout features, inquiry forms, email or messaging communications, marketing sign-up forms, testimonials or reviews, and related business operations.
This policy does not automatically apply to third-party websites, apps, or platforms that we do not control, even if we link to them or use them as service providers. Those third parties may have their own privacy notices and terms.
3. What Personal Data We Collect
Depending on how you interact with us, we may collect the following categories of personal data.
A. Contact and identity information
This may include your name, email address, phone number, username, and similar contact details.
B. Booking and appointment information
This may include the services you select, preferred dates and times, booking history, reservation or deposit status, appointment notes, and related details needed to manage your booking.
C. Order and transaction information
If you buy products from us, this may include order details, billing and shipping details, purchase history, transaction references, and related customer-service records.
D. Payment-related information
If you pay online, your payment may be processed by PayMongo or its payment partners. We may receive payment confirmations and related transaction details needed to verify, manage, support, refund, or document your booking or order. We do not describe ourselves in this policy as receiving your full card details unless that is actually how your payment setup works.
E. Communications and inquiry data
This may include messages you send through forms, email, SMS, social media, or other channels, as well as our replies and related support records.
F. Account and login data
If you create an account, we may collect account credentials, account preferences, login activity, and related account data.
If you choose to sign in using a third-party login option, such as Google, we may receive profile or authentication-related details made available through that sign-in method, subject to that provider’s settings and policies.
G. Website, device, and technical data
This may include your IP address, browser type, device information, pages viewed, referral data, cookie identifiers, cart/session data, and similar technical information collected through our website, plugins, analytics tools, and security tools.
H. Security-related records
To help secure our website and services, we may collect or generate technical and security records such as login attempt data, access logs, IP-related records, and similar website-security events.
I. Reviews, testimonials, and user-submitted content
If you submit a review, testimonial, survey response, or similar content, we may collect and use that information in line with the purpose for which it was provided.
J. Client hand photos for portfolio, website, and social media
With your separate consent, we may take photos of your hands after your service and may use those photos on our website, social media pages, marketing materials, or other brand channels. This consent is optional and is not required to receive our services.
K. Limited service-safety information
As part of service suitability and safety, we may ask limited questions at the time of service about allergies, sensitivities, or contraindications. As a general rule, we do not intend to collect or retain detailed health information through our website as part of ordinary customer records unless you choose to provide it in writing or we need to document a safety concern, incident, complaint, or legal issue.
4. How We Collect Personal Data
We may collect personal data:
- directly from you, when you book, order, sign up, create an account, message us, submit a form, leave a review, or otherwise contact us;
- automatically, when you use our website through cookies, logs, analytics, security tools, and similar technologies;
- from third-party service providers that support our business, such as booking, payment, messaging, analytics, hosting, login, or security providers; and
- from public platforms when you choose to interact with us there, such as social media or public review channels.
5. Why We Use Personal Data
We may use personal data for these purposes:
- to operate and improve our website;
- to create and manage bookings and appointments;
- to process reservation fees, deposits, payments, orders, refunds, and related support;
- to provide the services or products you requested;
- to create and manage customer accounts;
- to respond to inquiries and communicate with you;
- to send booking confirmations, reminders, service notices, and other operational messages;
- to send newsletters, promotions, or updates where you have agreed to receive them or where otherwise allowed by law;
- to manage reviews, testimonials, and consented client photos;
- to maintain records for customer service, business administration, accounting, tax, dispute handling, fraud prevention, and compliance; and
- to protect our website, clients, staff, and business from misuse, unauthorized access, fraud, and security incidents.
Depending on the context, we may process personal data because it is necessary to respond to your request, enter into or perform a contract with you, comply with legal obligations, protect life and health, pursue our legitimate interests, or because you gave consent.
6. Booking and Appointment Information
If you book with us, we may use your personal data to:
- create, confirm, and manage your appointment;
- process your reservation fee or deposit;
- contact you about reminders, changes, delays, cancellations, and rescheduling;
- maintain booking history and service-related records;
- support customer service and dispute handling; and
- apply our studio policies where needed.
We currently use LatePoint as our booking provider. Booking-related personal data may be processed through that system to operate our appointment workflow.
7. Orders and Payments
If you buy products or pay for services online, we may use your personal data to:
- process and confirm the transaction;
- fulfill your order;
- provide shipping, delivery, support, return, or refund assistance;
- maintain invoice, accounting, and transaction records; and
- help detect or prevent fraud and unauthorized transactions.
We currently use PayMongo to help process deposits and payments. Payment providers may process payment credentials under their own privacy notices and terms.
8. SMS, Email, and Other Communications
We may contact you by email, SMS, phone, or similar channels for booking and service-related communications.
SMS reminders
We currently use Twilio for SMS reminders. This may involve processing personal data such as your full name, booked service, and appointment date and time.
Email newsletters and marketing
If you sign up for updates, launches, or promotions, we may send you marketing emails. Each marketing email should include an unsubscribe method or opt-out process.
Email newsletter provider: Mailchimp
You can opt out of marketing communications at any time using the unsubscribe method in the message or by contacting us.
9. Photos, Testimonials, and Reviews
With your separate consent, we may:
- take photos of your hands after your service;
- post approved client hand photos on our website, social media pages, or marketing materials;
- publish reviews or testimonials you submit or approve for publication; and
- keep a record of your consent for internal compliance purposes.
Giving this consent is optional. Refusing it will not affect your ability to receive our services.
If you later want us to stop using a photo, testimonial, or review that you previously approved, you may contact us. We will review your request and take reasonable steps for future use. Please note that this may not affect uses already made before your request, printed materials already produced, or copies reposted or shared by third parties outside our control.
10. Cookies, Analytics, and Similar Technologies
Our website may use cookies, pixels, local storage, cart/session tools, security tools, and similar technologies to:
- make the website function properly;
- support login, shopping cart, and account features;
- remember user sessions and site preferences;
- understand how visitors use the website;
- measure marketing or advertising performance; and
- improve website functionality, performance, and user experience.
We currently use or may use tools such as:
- Google Analytics
- Meta Pixel
- WordPress and WooCommerce cookies
- website security and session-related cookies
Google Analytics helps us understand website usage and site performance. Meta Pixel helps us measure actions taken on our website and improve advertising performance.
You can usually control cookies through your browser settings. Some website functions may not work properly if certain cookies are disabled.
11. Security and Fraud Prevention
We use reasonable and appropriate measures intended to help protect personal data and reduce unauthorized access, abuse, fraud, and website-security incidents.
These measures may include password protections, role-based access, website security tools, limited staff access, secure service providers, and internal administrative controls.
No website, platform, or transmission method can guarantee absolute security.
12. When We Share Personal Data
We do not sell personal data in the ordinary sense of selling customer data for money.
We may share personal data only when reasonably necessary, including with:
- LatePoint for booking and appointment management;
- PayMongo and related payment partners for payment processing and transaction support;
- Twilio for SMS reminders and related service communications;
- Google Analytics and Meta Pixel, where enabled, for website analytics and advertising measurement;
- website hosting, maintenance, technical support, and security providers;
- email or newsletter providers;
- delivery, logistics, or fulfillment providers, if relevant to your order;
- professional advisers such as accountants, auditors, insurers, or lawyers;
- regulators, courts, law enforcement, or government authorities where required or permitted by law; and
- buyers, successors, or transaction counterparties if the business is reorganized, merged, sold, or transferred, subject to applicable protections.
13. International Processing and Transfers
Some of the service providers we use may process or store personal data outside the Philippines or may use infrastructure located outside the Philippines.
Where that happens, we aim to use service providers that apply appropriate safeguards and security measures and to limit sharing to what is reasonably necessary for the relevant purpose.
Because website, booking, payment, messaging, analytics, and advertising providers may operate across multiple countries, this section should not be deleted unless you have completed a vendor-by-vendor check and confirmed that no cross-border processing occurs.
14. How Long We Keep Personal Data
We keep personal data only for as long as reasonably necessary for the purposes described in this policy, unless a longer period is required or allowed by law, needed for legitimate business purposes, needed for legal claims, or needed for tax, accounting, security, or dispute-resolution reasons.
Unless a different period is required by law or a specific situation, we currently intend to apply the following retention periods:
- Inquiry and contact-form records: up to 2 years from the last interaction
- Booking, appointment, and service records: up to 5 years from the last completed, cancelled, or missed appointment
- Customer account records: while the account remains active, and up to 2 years after closure or last activity
- Order, invoice, and payment-related records: up to 10 years from the transaction date
- SMS and service-message records: up to 2 years from the message date
- Marketing subscription records: until you unsubscribe or up to 2 years from your last meaningful interaction, whichever comes first
- Opt-out or suppression records: as long as reasonably needed to honor your unsubscribe or do-not-contact request
- Security logs: up to 12 months, unless longer retention is needed for a security investigation or legal issue
- Analytics and cookie-related data: according to the settings and retention periods of the relevant tool, browser, cookie, or platform
- Photo/testimonial consent records and approved content: for as long as needed for the purpose you agreed to, unless you withdraw consent earlier or we decide the content is no longer needed
When retention is no longer necessary, we will delete, anonymize, block, archive, or securely dispose of the relevant data as appropriate.
15. Your Privacy Rights
Subject to applicable law and lawful limitations, you may have the right to:
- be informed about how your personal data is processed;
- request access to personal data we hold about you;
- request correction of inaccurate or incomplete personal data;
- object to certain processing in some cases;
- request deletion, blocking, or restriction where applicable;
- withdraw consent where we rely on consent;
- request data portability where applicable; and
- lodge a complaint with the National Privacy Commission.
We may ask for reasonable verification information before acting on a request.
16. How To Exercise Your Rights
For privacy requests, questions, or complaints, please contact:
She Got Nails Admin
Email: privacy-first@shegotnails.ph
Please describe your request clearly so we can review and respond more accurately.
If you believe your data privacy rights have been violated, you may also contact the National Privacy Commission of the Philippines.
17. Minors
Our services are not intended for minors, and we do not knowingly accept bookings from minors or intentionally collect their personal data for bookings or services.
If we learn that we collected personal data from a minor in a way that should not have occurred, we will take appropriate steps to review and address the situation.
18. CCTV
We do not currently use CCTV in the studio.
19. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our website, tools, service providers, operations, legal obligations, or privacy practices.
When we make material changes, we will update the “Last updated” date and, where appropriate, provide additional notice through the website or another suitable channel.
20. Contact Us
For general questions about our business, please contact us using the contact details listed on our website.
For privacy-specific concerns, please contact:
She Got Nails Admin
privacy-first@shegotnails.ph
