Consumer Health Data Privacy Policy
Last updated: July 2026
This policy explains how Linebook handles health-related intake data when a studio uses Linebook's intake tools to collect it. It supplements, and should be read together with, our Privacy Policy. We publish this page to provide transparency and to support compliance with potentially applicable consumer-health-data privacy laws, including where a studio's intake workflow may involve consumer health data.
Role note: in this workflow, the studio generally decides what health-related information to collect and why, and Linebook primarily processes that information on the studio's behalf as a processor or service provider. Nothing in this policy is intended to concede that Linebook is a directly regulated consumer-health-data entity under any specific state law unless that role is legally determined, or to limit any direct obligations Linebook may have where applicable law imposes them.
01Our role
When a studio uses Linebook's intake workflow to collect health screenings, waivers, date of birth, intake placement photos, or related consent records, the studio is generally the controller or business and Linebook acts as its processor or service provider for that data, following the studio's configuration and instructions. Linebook does not use that consumer health data for its own advertising, profiling, or machine-learning model-training purposes.
02What consumer health data we process
Depending on the studio's configuration, this may include health-screening answers, date of birth, signed waiver records, consent or acknowledgement records, intake placement photographs, and related metadata submitted in connection with the intake process. This policy does not imply that every image feature in Linebook is consumer health data or receives the same technical treatment. We do not collect precise location data, and we do not store government-ID images.
03How it is collected & the consent relied on
This data is collected directly from the client through the studio's intake flow, including through health-screening questions, waiver or release forms, date-of-birth fields, intake placement-photo prompts, and related consent or acknowledgement steps configured by the studio. The workflow is designed to support separate, unbundled acknowledgments for the health screening, the waiver, and photographs, but the studio remains responsible for deciding what to ask and for obtaining any consent, authorisation, or other lawful basis required in its jurisdiction.
04Who we disclose it to
We disclose this data only as needed to provide the service on the studio's behalf, including to the service providers listed on our Subprocessors page, and only for hosting, storage, security, support and related operational purposes. We do not sell consumer health data, use it for behavioural advertising, or use it to train machine-learning models. We do not disclose it in response to legal process except as required by applicable law and after appropriate review.
05Security
Sensitive intake content covered by this workflow is encrypted at rest using studio-specific keying and is intended to be accessible only through authenticated, studio-scoped product workflows. Linebook's ordinary admin and support interfaces are designed without a routine product path to open that encrypted intake content. To be clear, this is a statement about access controls and system design, not a claim that hosted infrastructure can never process encrypted data when the service needs to display it back to the authorised studio user.
06Retention & deletion
Consumer health data processed through the intake workflow is retained according to the studio's intake retention settings and configuration and applicable law; unless changed by the studio or required by law, sensitive intake defaults to about seven years from the client's last service. Other records outside the intake workflow may have different retention periods. Deletion may be subject to backup lifecycle, legal holds, disputes, security, tax/accounting, and legally required retention.
Where deletion is implemented through deletion of an associated encryption key or similar cryptographic control, encrypted sensitive intake content may be rendered unreadable in the ordinary service environment rather than deleted file-by-file.
07Your rights
Where applicable law grants rights regarding consumer health data, requests should ordinarily be directed first to the studio that collected the data where the studio controls that intake workflow. You may also contact us at hello@linebook.ink, and we will route the request to the studio, assist the studio with the request, or respond directly where required by applicable law, as appropriate to our role and legal obligations. We will not discriminate against a person for exercising rights granted by applicable consumer-health-data law.
This page is not legal advice and is intended to provide transparency and support potentially applicable consumer-health-data laws without determining whether Linebook or any studio is subject to a particular statute. Studios operating in Washington, Nevada or Connecticut, or handling other regulated health-related information, should review their own obligations. See also our Privacy Policy and Security Overview; information about our internal retention schedule may be available on request where appropriate.