Privacy Policy
This policy explains what personal data we collect when you message us on Facebook Messenger or Instagram, use our online booking form, or visit one of our branches, and how you can ask us to delete it. It covers our automated assistant, Bea, which runs through our Meta app Browcode Bea, and the booking pages at our online booking form and this website.
Who we are
The Browcode Corp. (SEC Company Reg. No. 2023040095654-02), doing business as Browcode Beauty Lounge, 2nd Floor Red Dot Collective Bldg., General Luna Street cor. Lagasca Street, Brgy. No. 10, San Jose, Laoag City, Ilocos Norte 2900, Philippines. We operate branches in Laoag, Vigan, Tuguegarao, Isabela, La Union, and Pampanga.
What we collect
- Messenger and Instagram data: your display name, profile picture, the account or conversation identifier Meta provides, and the messages, photos, and quick-reply taps you send to our Facebook Page or Instagram account.
- Booking details: name, mobile number, optional email address, chosen branch, service, artist, appointment date and time, and how you heard about us.
- Health and treatment screening: for services such as semi-permanent makeup, answers about peeling skincare, insulin or blood thinners, active skin irritation, and existing brow tattoos. We may also receive health information you choose to share in a conversation. This is sensitive personal information used for staff assessment and treatment planning; a booking or automated reply is not medical clearance.
- Payment proof: screenshots of deposit transfers you send to confirm a booking. We do not receive card or bank credentials.
- Walk-in check-in: name, mobile number, and branch when you scan a branch QR code in-store.
- Technical data: timestamps, browser type, and basic device information needed to serve the booking page.
Why we use it
- To answer your enquiries about services, prices, artists, and branch hours.
- To book, confirm, reschedule, or cancel your appointment and to verify deposits.
- To send appointment reminders and follow-ups about a booking you made.
- To keep a customer record so our front desk knows your booking history.
- To record screening answers and refer suitability questions to the branch team. If you prefer not to submit health information online, contact the branch to discuss an assessment.
- To keep the assistant working safely, including detecting abuse and fixing errors.
We do not sell your data and we do not use it for third-party advertising.
Automated assistant
Bea runs through our Meta app "Browcode Bea", connected to our Facebook Page with Meta permissions that let it list the Pages a Page administrator chooses to connect, receive new-message notifications for those Pages, and read and reply to messages sent to them. It uses an AI language model to answer enquiries and assist with booking details on supported Pages. Messages and relevant conversation context are processed to generate replies. Staff handle deposit verification, suitability assessments and requests that need a person. You can request staff assistance in the conversation or contact your branch directly; staff availability depends on branch hours. Bea cannot charge you or give medical clearance.
Who we share it with
- Meta Platforms: delivers Messenger and Instagram messages and applies its own privacy policy.
- Cloudflare and Supabase: host the booking tools and store operational records, conversation history and payment-proof files.
- BlackBug: builds and operates our booking tools and Bea on our behalf, including the booking pages at booking.blackbughq.com.
- ManyChat: routes some Page messages and staff handoffs alongside Bea.
- Anthropic: processes messages and relevant conversation context to generate Bea's AI replies.
- Authorised staff, management and technical support: access records needed to provide services, handle requests and maintain the booking system. Staff notifications and booking workflows may use Slack and connected automation tools.
- Google Fonts: supplies the typefaces on our booking pages and receives technical request information, such as your IP address and browser information, when fonts are loaded.
These providers may process data outside the Philippines. We may also disclose data when required by Philippine law or a lawful order.
How long we keep it
- Conversations and screening answers: kept for 12 months after your last message to us, then deleted.
- Booking, payment-proof and customer records: kept for 5 years after your last appointment, to meet accounting and tax record-keeping requirements and to handle legal claims, then deleted.
You can ask us to delete your data sooner at any time using the steps below. Records we must keep by law are retained only for that purpose and only for as long as the law requires.
Your rights
Under the Data Privacy Act of 2012 (Republic Act No. 10173) you may ask to access, correct, or delete your personal data, object to processing, or file a complaint with the National Privacy Commission. Contact us using the details below to exercise these rights or withdraw consent where processing relies on consent. We may need to verify your identity before disclosing or changing a record.
How to delete your data
Option 1: Email. Send a message to cs.browcode@gmail.com with the subject Data deletion request. Include any details that help us find your records, such as the Facebook or Instagram account you messaged us from and the approximate date, or the name and mobile number used for a booking. You can request deletion even if you never booked or gave a mobile number.
Option 2: Message us. Send "delete my data" to our Facebook Page to request staff assistance. For Instagram conversations, use Option 1 and include the account name you used. This message starts a request; it does not automatically erase records. You can also email customer service directly.
What happens next. We acknowledge your request within 3 business days and complete it within 30 days, then confirm by the same channel you used. Staff may ask for information needed to locate your records and verify your identity. The request can cover conversation history, screening answers, booking/customer records and deposit screenshots. We will explain the outcome and any records that must be retained for a legal obligation or legitimate legal claim. Removing an app or conversation from Meta does not itself delete records already held in our booking system.
If you are a Page administrator who authorised our app, you can revoke that authorisation in your Facebook Business Integrations settings. To delete data linked to that authorisation, use Option 1 and name the Facebook account and Page you connected. Customers who only messaged us should use the steps above. Disconnecting an integration does not delete records we already hold.
Security
Data is stored with cloud providers that use encryption in transit and at rest, and access is limited to staff who need it for their role. No system is perfectly secure, so please avoid sending sensitive information such as government IDs or full card numbers through chat.
Services for younger clients
Our menu includes selected children's nail services. This does not mean every treatment is suitable for a minor. For anyone under 18, please contact the branch before booking so staff can confirm service eligibility and any parent or guardian consent requirements. If you believe a child's personal data was provided inappropriately, contact customer service to request review and deletion where applicable.
Changes
We may update this policy. The effective date at the top changes when we do, and the current version always lives at this address.
Contact
Browcode Beauty Lounge Customer Service
Phone: +63 995 057 2634
Email: cs.browcode@gmail.com
Address: 2nd Floor Red Dot Collective Bldg., General Luna Street cor. Lagasca Street, Brgy. No. 10, San Jose, Laoag City, Ilocos Norte 2900, Philippines
