TRIBECA MEDSPA MY HEALTH MY DATA PRIVACY NOTICE
Dated: August 5th, 2025
This My Health My Data Privacy Notice (“Health Data Notice”) is intended to supplement the Tribeca MedSpa Website Privacy Notice (“Privacy Notice”) <<PRIVACY NOTICE>> and applies to personal data defined as “Consumer Health Data” subject to the Washington State My Health My Data Act, and any other U.S. state law with a similar law in effect and applicable to you, including but not limited to Nevada’s Consumer Health Data Privacy Law (or “U.S. Health Data Laws”). This Health Data Notice does not supersede our Privacy Notice or Terms of Use, and instead, it is incorporated into our Privacy Notice by reference.
Consumer Health Data We Collect
The data that MedSpas of Manhattan, doing business as Tribeca MedSpa, SkinLab by Tribeca MedSpa (“MedSpa of Manhattan,” the “Company,” “we,” “our”) collects depends on the context of your interactions with us. Because Consumer Health Data is defined very broadly, many of the categories of data we collect could also be considered Consumer Health Data. As described in the <<PERSONAL INFORMATION WE MAY COLLECT>> and <<HOW WE MAY USE YOUR PERSONAL INFORMATION>> sections of our Privacy Notice, the data we collect can come from information you choose to submit to us, your user privacy settings, your location, how you interact with our websites, https://tribecamedspa.com or https://skinlab-nyc.com (or the “Website”), use our mobile application (the “App”), and more generally, your use any of our services (the “Services,” which include the Website and App).
“Consumer Health Data,” as used herein, means any Personal Information that is linked or reasonably linkable to a consumer and identifies their past, present, or future physical or mental health status, including details like health conditions, treatments, diagnoses, medication usage, reproductive health information, biometric data, and location data that could indicate a person seeking healthcare services.
Examples of Consumer Health Data may include:
- MedSpas of Manhattan may maintain notes associated with your account and/or user profile that, when combined with other information MedSpas of Manhattan collects such as your name, address, email address, and phone number, may constitute Consumer Health Data.
- Your searches on our Website or App for services or products that relate to a health condition, symptom, status, diagnosis, or treatment may constitute Consumer Health Data.
- Information that could identify your searches for services that allow you to assess, measure, improve, or learn about your or another person’s health. For example, we may collect information about information you viewed, which may indicate your attempt to learn more about certain services related to conditions that you or another person may have, or based on product descriptions you clicked on to explore whether certain products may be right for you.
- Other information that may be used to infer or derive data related to the above or other Consumer Health Data.
Terms that are capitalized herein are defined in the <<PRIVACY NOTICE>>.
Sources of Consumer Health Data
As described further in the Privacy Notice and in this Health Data Notice, we collect personal data (which may include Consumer Health Data) directly from you and from your interactions with our Website or App. We may use cookies, pixels, and other tracking mechanisms to collect certain information, including Consumer Health Data, with your consent or to provide you with the services or products you have requested.
Why We Collect and Use Consumer Health Data
We collect and use Consumer Health Data for the purposes described in the <<HOW WE USE YOUR PERSONAL INFORMATION AND SENSITIVE PERSONAL INFORMATION (INCLUDING CONSUMER HEALTH DATA)>> section of the Privacy Notice, and we collect Personal Information (which may include Consumer Health Data) directly from you and from your interactions with our Website.
We may use Consumer Health Data for other purposes for which we give you choices and/or obtain your consent as required by law – for example, to respond to an inquiry through our Contact Us form. See the <<YOUR PERSONAL INFORMATION / YOUR CHOICES>> and <<EXERCISING YOUR RIGHTS>>sections of the Privacy Notice and the <<HOW TO EXERCISE YOUR RIGHTS>> section below for more details on the controls and choices you may have.
How We Share Consumer Health Data
We may share each of the categories of Consumer Health Data described above in <<SOURCES OF CONSUMER HEALTH DATA>> for the purposes described in the <<SHARING OR SELLING YOUR PERSONAL INFORMATION AND TARGETED ADVERTISING>> section of the Privacy Notice. In particular, we may share Personal Information, including Consumer Health Data, with your consent, when you tell us to do so, as reasonably necessary to provide the services and products you request, or to respond to an inquiry. We may disclose Personal Information and/or Consumer Health Data when we believe that doing so is necessary to comply with applicable law or respond to valid legal process.
With Whom We Share Consumer Health Data
We provide certain of our business partners with your Consumer Health Data so that we can provide you with the services and products you requested. We may share Consumer Health Data with the following categories of third parties:
-
- Service providers. Vendors or agents (“processors”) working on our behalf may access Consumer Health Data. For example, our service providers may include companies we’ve hired to protect and secure data, or provide products or services in which you are interested.
- Parties to a corporate transaction. We may disclose Consumer Health Data as part of a corporate transaction or proceeding such as a merger, financing, acquisition, bankruptcy, dissolution, or a transfer, divestiture, or sale of all or a portion of our business or assets.
- Government agencies. As described in our Privacy Notice, we may be required to disclose data to law enforcement or other government agencies when we believe doing so is necessary to comply with applicable law or respond to valid legal process.
- Other third parties. In certain circumstances, it may be necessary to provide certain data to other third parties, for example, to comply with the law or to protect our rights or those of our customers.
- Affiliates. We enable access to data across our subsidiaries, affiliates, and related companies, for example, where we share common data systems or where access helps us to provide our services and operate our business.
How to Exercise Your Rights
The Company requires you to provide affirmative consent to (i) collection and (ii) sharing of your Consumer Health Data as described in this Notice and the <<PRIVACY NOTICE>> when you first access our Website. We do not sell your Consumer Health Data for monetary gain or other gain that can be monetized.
U.S. Health Data Laws provide consumers with certain rights regarding their Consumer Health Data, including rights to access, delete, or withdraw consent relating to Consumer Health Data, subject to certain exceptions. You can email us at info@TribecaMedSpa.com to request access, correction, or deletion of your Consumer Health Data, or to withdraw consent from future collection or sharing of Consumer Health Data. You may also opt out of Google Analytics services using the Opt-Out feature provided by Google or by installing the Google Analytics Opt-out Browser tool: https://tools.google.com/dlpage/gaoptout. See also our <<PRIVACY NOTICE>> to exercise your rights and choices.
If you submit a rights request to info@TribecaMedSpa.com, we will respond to that request within the period of time required under U.S. Health Data Laws.
If your request to exercise a right under U.S. Health Data Laws is denied, you may appeal that decision by emailing info@TribecaMedSpa.com. If your appeal is unsuccessful, you can raise a concern or lodge a complaint with the Washington State Attorney General at www.atg.wa.gov/file-complaint, or the Nevada State Attorney General, at https://forms.office.com/g/nv63bfqDLe, depending on your state of residence, or such other comparable agency that may exist under any other applicable U.S. Health Data Law.


