Legal
Privacy
Policy.
What this website collects, why, who else sees it, how long we keep it, and what you can ask us to do about it. Hair loss is a private subject, and this page is written to be read rather than skimmed past.
The short version
- This policy covers the website. Anything created in the course of your care — your history, your imaging, your chart — is protected health information under HIPAA and is governed by the practice's Notice of Privacy Practices, not by this page.
- The site collects what you type into a form, and ordinary technical information about the visit. Nothing clinical is ever put in a web address.
- Google Analytics and a Meta advertising pixel run on these pages. The pixel is deliberately configured not to read the page's own text.
- We do not sell your information for money. Some advertising cookies may count as “sharing” or “targeted advertising” under state law, and Sections 09 and 12 tell you how to switch that off.
- You can ask us what we hold, ask for a copy, ask us to correct it, and ask us to delete it. Email hello@mohrhair.com.
This summary is a reading aid. It is not the policy, and if it differs from the numbered sections below, the numbered sections govern.
Scope, and the HIPAA line
This Privacy Policy explains how MOHR — Modern Optimal Hair Restoration (MOHR, we, us) handles information collected through mohrhair.com and through the booking, payment and enquiry tools linked from it (the Site).
MOHR is a health care provider. Information created or received in the course of your care — your medical history, your examination, your scalp imaging, your photographs, your treatment plan, your chart and your billing record — is Protected Health Information under the Health Insurance Portability and Accountability Act (HIPAA).
That information is governed by the practice's Notice of Privacy Practices and by HIPAA and New York health-privacy law — not by this policy. Where this policy and the Notice of Privacy Practices differ in relation to Protected Health Information, the Notice of Privacy Practices controls. A copy is provided at your first visit and is available on request.
In short: this page is about the website. The Notice of Privacy Practices is about your medical record. Both apply, each to its own subject.
This policy also does not apply to information handled by third parties under their own policies — the scheduling platform, the payment processor, or any site you reach by following a link from ours. Section 08 and Section 16 say more.
Information you give us
We collect what you choose to give us:
- Contact and booking details — your name, email address, telephone number, and the appointment time you select.
- Enquiry content — whatever you write in a message or a form field, and anything you tell us by email or telephone.
- Payment details — handled by our payment processor. We receive confirmation that a payment succeeded, the amount, the date and a transaction reference. We never receive or store your full card number.
- Marketing preferences — whether you have asked to hear from us, and any consent you have given or withdrawn.
- Correspondence — records of what you have asked us and how we answered, including a request made under Section 13.
Some fields are necessary to book: without a name, an email address and a payment, an appointment cannot be held. Everything else is optional, and you can leave it blank.
Please do not send us detailed medical information through a website form or ordinary email. Neither is a secure channel, and Section 05 explains what we do with clinical detail that arrives anyway.
Information collected automatically
Like almost every website, ours records technical information about the visit. This is collected by our hosting provider and by the analytics tools described in Section 06:
- Device and connection — IP address (from which an approximate city or region and a country code may be derived), browser type and version, operating system, screen size and language.
- Usage — pages viewed, the time and duration of the visit, links and buttons clicked, scroll depth, and the page you came from.
- Referral and campaign — the referring website, and campaign parameters in the web address such as
utm_source,utm_medium,utm_campaign,gclidandfbclid, which tell us which advertisement or link brought you here. - Identifiers — cookie and similar identifiers set by the tools in Section 06, and values your browser stores for the duration of a session.
- Security and operational logs — request logs kept to keep the Site running, to diagnose faults and to detect abuse.
Information from other sources
We may receive information about you from:
- Our scheduling platform, when you book — the name, email address, telephone number and answers you gave it, and the appointment details.
- Our payment processor — the outcome of a payment, and limited details such as the card brand and last four digits, for reconciliation.
- Advertising and analytics partners — aggregate reporting about how campaigns performed. This tells us that a campaign produced bookings; it does not tell us which individual did what.
- You, by another route — a telephone call, an email, a social media message, or a person you asked to contact us on your behalf.
Health information on this site
The Site is deliberately built to keep clinical detail out of the parts of the internet that are hardest to control. Specifically:
- No clinical information is ever placed in a web address. A page URL on this site never contains your name, your email address, an assessment result, a candidacy determination, or anything about a medication or treatment. This matters because the address of the page you are on is sent to analytics and advertising tools automatically.
- The advertising pixel is configured not to read the page. Its automatic-configuration feature, which would otherwise scrape button text, link text and form field values and send what it found, is switched off before the pixel starts. It sends only the events we have explicitly written.
- No assessment result, imaging output, candidacy, diagnosis, medication or treatment detail is ever sent to an advertising platform — not as an event, not as a parameter, and not as advanced matching.
- The booking confirmation page reads your first name from your own browser's session storage rather than from the address bar, so a confirmation link that gets pasted into a message or captured in a log carries nothing about you.
If you volunteer clinical detail in a website form or an email, we treat it as confidential, move it into the clinical record where appropriate, and handle it under HIPAA and the Notice of Privacy Practices from that point. We do not use it for advertising, we do not disclose it to an advertising platform, and we do not use it to build an audience or a lookalike audience.
Cookies, pixels and analytics
Cookies are small files a website asks your browser to store. We and our providers use them, together with pixels, tags and browser storage, for the purposes below.
| Tool | What it does | Category |
|---|---|---|
| Hosting & delivery | Serves the pages, balances load, blocks abuse, and keeps request logs. The Site cannot function without it. | Strictly necessary |
| Browser session storage | Remembers, for the length of one visit, the campaign parameters you arrived with and the first name shown on a confirmation page. Stored in your browser; cleared when you close the tab. | Strictly necessary |
| Google Analytics 4 | Measures how the Site is used — visits, pages, referrers, and whether a booking link was clicked. Set to measure the Site, not to identify you by name. | Analytics |
| Meta Pixel | Measures whether an advertisement produced a visit or a booking click, and may be used to show you MOHR advertisements on Meta's services. Automatic page-scraping is switched off — see Section 05. | Advertising |
| Scheduling & payment | Third-party booking and checkout pages set their own cookies under their own policies when you use them. | Third-party |
You can control cookies through your browser: block them, delete them, or be warned before one is set. Blocking strictly-necessary cookies will break parts of the Site. Section 12 lists the specific opt-outs for analytics and advertising.
Global Privacy Control. Where you send a Global Privacy Control signal from your browser, we treat it as a valid request to opt out of the sharing of your personal information for cross-context behavioural advertising, for that browser and device. Because the signal is stored in the browser, you will need to send it from each browser and device you use.
How we use information
We use the information described above to:
- Provide the Services — schedule, confirm, remind, reschedule, take payment, issue receipts, and deliver the care you booked.
- Communicate with you — answer an enquiry, follow up on an appointment, and send service messages about your booking or your account.
- Run and improve the Site — diagnose faults, measure which pages and messages work, and make the booking path clearer.
- Advertise responsibly — measure whether a campaign produced enquiries, and reach people who may be interested in the practice. Subject always to Section 05: never using clinical information, and never disclosing that you are or may become a patient.
- Protect the practice — detect and prevent fraud, abuse, security incidents and non-payment, and enforce our Terms & Conditions.
- Meet legal obligations — comply with law, respond to lawful requests, keep records we are required to keep, and establish, exercise or defend legal claims.
We may create de-identified and aggregated information that cannot reasonably be used to identify you — for example, how many visitors booked in a month, or how a campaign performed. We may keep and use that information for any lawful business purpose without restriction, and we maintain it in de-identified form and do not attempt to re-identify it, except as permitted by law to test the de-identification.
How we disclose information
We do not sell your personal information for money. We disclose it in these circumstances, and no others:
- Service providers who work for us and process information on our instructions — hosting and content delivery, scheduling, payment processing, email delivery, customer-relationship management, analytics, advertising measurement, and professional IT support. They are permitted to use the information only to perform the service for us. Where a provider handles Protected Health Information, we put a HIPAA business associate agreement in place first.
- Advertising partners — limited technical and activity information as described in Section 09.
- Licensed providers and clinical staff involved in your care, and, with your authorization or as HIPAA permits, other clinicians.
- Professional advisers — our lawyers, accountants, insurers and auditors, under a duty of confidence.
- Legal and safety — where we reasonably believe disclosure is required by law, subpoena, court order or regulator; necessary to investigate suspected fraud, a security incident or a breach of our Terms; or necessary to protect the rights, property or safety of any person. Protected Health Information is disclosed only as HIPAA permits or requires.
- Business transfer — in connection with a merger, acquisition, financing, reorganization, sale of assets, or insolvency, information may be transferred as a business asset, subject to the acquirer honouring this policy and, for Protected Health Information, applicable health-privacy law.
- With your direction — anywhere else you ask us to send it, or consent to us sending it.
Advertising, “sale” and “sharing”
We want to be straightforward about this, because the legal words do not mean what they sound like.
We do not sell your personal information for money. We have never done so, and we do not do so now.
However: several state privacy laws define “sale” broadly enough to include disclosing an identifier to an advertising partner for valuable consideration, and define “sharing” or “targeted advertising” to include using such an identifier to show you advertisements across other websites and apps. The Meta Pixel described in Section 06 works that way. So, to be accurate rather than clever: our use of that pixel may be treated as “sharing” for cross-context behavioural advertising, and possibly as a “sale”, under the laws of some states.
What is disclosed to that partner is limited to online identifiers, the page address, the referring page and the event that occurred. It never includes an assessment result, an imaging output, a candidacy determination, a diagnosis, a medication, a treatment, or any statement that you are a patient of the practice.
You can stop it. Send a Global Privacy Control signal from your browser, use the browser and platform controls in Section 12, or email hello@mohrhair.com with “Do not share my information” and we will action it. We will not treat you differently for asking — not in price, not in scheduling, not in care.
We do not knowingly sell or share the personal information of anyone under 16.
How long we keep information
We keep personal information for as long as we need it for the purpose it was collected, and then for as long as we are required or reasonably need to keep it to comply with law, resolve disputes, and enforce our agreements. In practice:
| What | How long |
|---|---|
| Enquiries that did not become bookings | Up to 24 months from the last contact, then deleted or de-identified. |
| Booking and payment records | As long as required for tax, accounting and audit purposes — generally at least 7 years. |
| Clinical records | As required by New York law and professional obligations, which is longer than the periods above. Governed by the Notice of Privacy Practices. |
| Website and security logs | Short-term, typically measured in weeks to months, in line with our providers' defaults. |
| Analytics and advertising identifiers | Retained by those platforms under their own retention settings and policies. |
| De-identified and aggregated data | Indefinitely, as described in Section 07. |
Where a deletion request is made under Section 13, we honour it for the information we are not required to keep, and we tell you what we are keeping and why.
How we protect information
We maintain administrative, technical and physical safeguards designed to protect personal information against unauthorized access, use, alteration and destruction, appropriate to its sensitivity and consistent with our obligations under HIPAA and New York's data-security law. Those include encryption of the Site in transit, access limited to people who need it to do their job, reputable providers under written agreements, card data handled entirely by a PCI-compliant processor, and clinical information kept separate from marketing systems.
No method of transmission over the internet, and no method of electronic storage, is completely secure. We cannot and do not guarantee absolute security, and we cannot guarantee that email you send us will not be intercepted. Please do not send sensitive medical detail by ordinary email or through a web form — call the practice, or raise it at your visit.
Your choices
Whatever state you live in, you can:
- Stop marketing email — use the unsubscribe link in any marketing message, or email us. You will still receive appointment and account messages, which are part of the service.
- Stop marketing texts and calls — reply STOP to a text, or tell us. Reply HELP for help. Message and data rates may apply.
- Control cookies — through your browser's settings, and by using private browsing.
- Opt out of Google Analytics — install Google's browser add-on at tools.google.com/dlpage/gaoptout.
- Control Meta advertising — through the ad preferences in your Facebook or Instagram account settings.
- Use industry opt-outs — optout.aboutads.info and optout.networkadvertising.org. These are cookie-based, so they apply per browser.
- Send a Global Privacy Control signal — see Section 06.
- Ask us directly — email hello@mohrhair.com and describe what you want. We would rather do it than argue about whether a statute requires it.
State privacy rights
Several states give residents rights over personal information held by businesses subject to those laws — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and others, with more taking effect over time. Depending on where you live and whether the relevant law applies to us, those rights may include:
- To know what personal information we collect, the categories of source, the purposes, and the categories of third party we disclose it to.
- To access a copy of the personal information we hold about you, in a portable form where required.
- To correct inaccurate personal information.
- To delete personal information, subject to the exceptions the law allows — including information we must keep for legal, accounting, security or clinical-record reasons.
- To opt out of targeted advertising, of any “sale” or “sharing”, and of profiling that produces legal or similarly significant effects. We do not carry out that kind of profiling.
- To limit the use of sensitive personal information, where the law provides it. We do not use sensitive personal information for any purpose other than providing the Services and complying with law.
- Not to be discriminated against for exercising any of these rights. We will not deny you service, charge you a different price, or give you a lesser standard of care.
How to make a request
Email hello@mohrhair.com with the subject line “Privacy request”, tell us which right you are exercising, and tell us the state you live in. We will acknowledge promptly and respond within the period the applicable law allows — generally 45 days, extendable once where the law permits and we tell you why.
Verification. To protect you, we must be able to verify that the request is really yours before we act on it. We will ask you to confirm information we already hold — typically the email address or telephone number on the record. For a request about health information we may ask for more, because the consequence of getting it wrong is greater. We cannot act on a request we are unable to verify, and we will tell you if that happens.
Authorized agents. An agent may make a request for you with written, signed permission, and we may still contact you to confirm it and to verify your identity directly.
Appeals. If we decline a request, we will tell you why. Where your state's law gives you a right of appeal, you may appeal by replying to our decision with the word “Appeal”; we will review it and respond within the statutory period, and if we decline again we will tell you how to complain to your state Attorney General.
One limit worth knowing. Protected Health Information is generally exempt from these state statutes, because HIPAA already governs it. That is not a way of saying no: your HIPAA rights — to access your record, to request an amendment, to an accounting of disclosures, and to request restrictions — are set out in the Notice of Privacy Practices, and they are how you exercise control over your clinical information.
California disclosures
If you are a California resident, this Section supplements the rest of the policy.
| Category (CCPA) | Collected | Disclosed for a business purpose to |
|---|---|---|
| Identifiers | Name, email, telephone, IP address, cookie identifiers | Hosting, scheduling, payment, CRM, analytics and advertising providers |
| Customer records | Name, telephone, payment confirmation details | Scheduling, payment and accounting providers |
| Commercial information | Services enquired about or purchased | Payment, accounting and CRM providers |
| Internet activity | Pages viewed, clicks, referrer, campaign parameters | Analytics and advertising providers |
| Geolocation | Approximate location derived from IP address, at country or region level | Hosting and analytics providers |
| Inferences | Limited inferences about interest in the Services, for measurement | Analytics and advertising providers |
| Medical information | Only where you volunteer it, or in the course of care | Not disclosed for advertising. Handled under HIPAA and mostly exempt from the CCPA on that basis. |
We collect these categories from the sources in Sections 02 to 04, for the purposes in Section 07. We do not sell personal information for money; our use of an advertising pixel may constitute “sharing”, and Section 09 tells you how to stop it. We retain each category for the periods in Section 10.
Shine the Light. California Civil Code § 1798.83 lets California residents ask once a year about personal information disclosed to third parties for their own direct-marketing purposes. We do not make such disclosures. You may confirm that by emailing hello@mohrhair.com.
Children
The Site and the Services are intended for adults. We do not knowingly collect personal information from anyone under 18, and the Services are not offered to children. If you believe a child has given us personal information, email hello@mohrhair.com and we will delete it.
Other websites
The Site links to services we do not control — a scheduling platform, a payment processor, mapping and social media. Following such a link takes you to a site governed by that operator's privacy policy, not ours. We are not responsible for their content or their practices, and we encourage you to read their policies before giving them information.
Visitors outside the United States
MOHR operates in New York and the Services are offered in the United States. Information we collect is processed and stored in the United States, where privacy laws may differ from those where you live. If you access the Site from outside the United States, you do so on your own initiative and you are responsible for compliance with local law. By using the Site you consent to the transfer of your information to, and its processing in, the United States.
If something goes wrong
If a security incident affects your personal information, we will investigate, take steps to contain it, and notify you and any regulator where the law requires — within the timeframes New York and, where applicable, HIPAA require. Telling you promptly is the point of that obligation, and we treat it that way.
Changes to this policy
We may update this policy as the Site, the law or our providers change. The revised version takes effect when posted and the “Last updated” date changes. For a material change we will take reasonable steps to bring it to your attention — a notice on the Site, or an email to the address we hold for you. Continuing to use the Site after a change takes effect means you accept the revised policy. Changes to the handling of Protected Health Information are made through the Notice of Privacy Practices, under the procedure HIPAA sets out.
How to reach us
Questions about this policy, a privacy request under Section 13, or a concern about how your information has been handled:
Attn: Privacy
910 Park Avenue, New York, NY
hello@mohrhair.com
We would rather hear from you than have you complain elsewhere, and we answer every privacy email. You also have the right to complain to your state Attorney General, and — for Protected Health Information — to the U.S. Department of Health and Human Services, Office for Civil Rights. We will not retaliate against you for making a complaint.
