Privacy Policy
How Constella AI Technologies, Inc. collects, uses, stores, shares, retains, and protects personal information across every product in our ecosystem.
A Virginia Corporation
- 1. Plain-Language Summary
- 2. Key Definitions
- 3. Information We Collect
- 4. Sources of Information
- 5. How We Use Information
- 6. AI, Automated Processing & Profiling
- 7. Visual, Biometric & Image Privacy
- 8. Consumer Health Data & MedSpa
- 9. How We Share Information
- 10. Cookies, Pixels & Tracking
- 11. Marketing Communications
- 12. SMS & Text Messaging
- 13. Reviews, Testimonials & Public Content
- 14. Legal Bases for Processing
- 15. Data Retention
- 16. Deletion & De-Identification
- 17. Data Security
- 18. Children & Minors
- 19. Your Privacy Rights
- 20. California Privacy Notice
- 21. Virginia Privacy Notice
- 22. Maryland Privacy Notice
- 23. Washington Consumer Health Data
- 24. Biometric Privacy Notice
- 25. International Users
- 26. Third-Party Links & Services
- 27. Provider Responsibilities
- 28. How to Exercise Your Rights
- 29. Appeals
- 30. Opt-Out Mechanisms
- 31. Financial Incentives
- 32. Changes to This Privacy Policy
- 33. Contact Information
This Privacy Policy describes how Constella AI Technologies, Inc., a Virginia Corporation, referred to in this Privacy Policy as “Constella,” “Constella AI,” “Company,” “we,” “us,” or “our,” collects, uses, stores, shares, discloses, protects, retains, and otherwise processes personal information.
This Privacy Policy applies to all websites, mobile applications, platforms, dashboards, software, tools, forms, communications, marketplaces, provider profiles, AI features, booking flows, image upload features, visual analysis tools, beauty matching features, marketing pages, and related services operated by Constella, including but not limited to: Constella AI, Constella Orbit, Beauty Passport, Constella Match AI, LashMatch AI, BrowMatch AI, WaxMatch AI, SkinMatch AI, GlowMatch AI, MedSpaMatch AI, BridalMatch AI, NailMatch AI, and any future Constella product, platform, feature, vertical, website, or service.
This Privacy Policy is incorporated into the Constella Terms of Service, Client Terms, Provider Terms, Biometric / Visual Analysis Consent Policy, Photo and Before/After Release, AI Matching Disclosure, Product Recommendation Disclosure, SMS Terms, Cookie Policy, and any other applicable agreement or notice.
By accessing or using the Services, creating an account, submitting information, uploading photos, creating a Beauty Passport, joining Constella Orbit, communicating with a Provider, signing up for beta access, requesting onboarding, booking services, submitting reviews, or otherwise interacting with Constella, you acknowledge that you have read and understood this Privacy Policy.
1. Plain-Language Summary
Constella AI is building a beauty and wellness discovery platform. We use information about clients, providers, services, preferences, portfolios, locations, availability, photos, reviews, and interactions to help clients find better-fit beauty professionals and to help providers grow their businesses.
We may collect information from:
- Clients, providers, beauty professionals, and business owners
- Website visitors, beta applicants, and people who submit forms or message us
- People who upload photos or join Beauty Passport or Constella Orbit
- People who interact with our emails, texts, ads, or social media
- Public business listings and publicly available professional information
- Third-party tools used to operate the platform
Some information may be sensitive, including photos, visual analysis data, skin/lash/brow preferences, beauty goals, medspa interests, and location information.
We use this information to operate Constella, create Beauty Passport profiles, build provider profiles, match clients with providers, recommend services and products, improve AI matching, support provider onboarding, process payments, send communications, maintain safety and security, prevent fraud, analyze platform performance, comply with law, and improve the platform.
We do not intend to sell biometric identifiers. We do not provide medical advice through general platform features. We are not responsible for independent providers’ privacy practices outside the Constella platform.
2. Key Definitions
“Services” means all Constella websites, apps, tools, dashboards, forms, profiles, AI features, visual analysis tools, booking flows, marketplace features, communications, and related offerings.
“Client” means a person using Constella to find, match with, book, review, message, or evaluate beauty, wellness, aesthetic, or personal care providers.
“Provider” means a beauty professional, lash artist, brow artist, wax specialist, esthetician, nail artist, salon, spa, medspa, bridal beauty provider, skincare provider, product brand, wellness provider, or other business using or appearing on Constella.
“Beauty Passport” means a client profile that may include preferences, service goals, beauty history, visual inputs, photos, provider preferences, style preferences, products, and personalization data.
“Constella Orbit” means the provider-facing dashboard and growth platform.
“Visual Data” means photos, videos, selfies, face images, eye images, lash images, brow images, skin images, nail images, treatment images, before-and-after images, provider portfolio images, and image metadata.
“Image-Derived Data” means information created from Visual Data, such as visual observations, labels, tags, match factors, style categories, feature maps, profile attributes, or AI-generated analysis.
“Sensitive Personal Information” means information considered sensitive under applicable law, which may include precise location, biometric-related data, certain health or wellness information, login credentials, government identification numbers, financial information, racial or ethnic origin, religious beliefs, sex life, sexual orientation, or other legally protected data.
“Consumer Health Data” means information that may identify a consumer’s past, present, or future physical or mental health status where regulated by applicable law.
“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to a person or household.
3. Information We Collect
A. Account and Identity Information
Name, business name, username, password or authentication information, email, phone number, mailing/billing address, profile photo, account ID, user type, provider type, client type, professional credentials, and business representative information.
B. Contact Information
Email, phone, social handles, website URL, booking link, business address, service area, communication preferences, and emergency or alternate contact information if voluntarily provided.
C. Provider Business Information
Business name, owner name, professional name, service categories, licenses and certifications, insurance information where requested, portfolio, bio, staff names, business description, services offered, pricing, availability, hours, location, booking/cancellation/refund policies, specialties, social media pages, reviews, ratings, website links, beta participation status, provider verification status, Constella vertical category, and Constella Orbit profile data.
D. Client Profile & Beauty Passport Information
Beauty goals; service, style, lash, brow, waxing, skincare, nail, medspa, bridal, and product preferences; service history; saved providers; favorite looks; budget and location preferences; appointment and rebooking preferences; review history; before-and-after preferences; Beauty Passport profile attributes; uploaded inspiration images; and user-submitted notes.
E. Visual Data
Photos, selfies, videos, face/eye/lash/brow/skin/nail/hair/treatment images, portfolio images, before-and-after and progress photos, product result images, review images, and image metadata (upload date/time, source, quality indicators).
F. Image-Derived and AI Analysis Data
Visual observations, style categories, AI-generated match factors and fit signals, AI-generated client preference signals, service/product suggestion inputs, portfolio classification, provider specialty insights, review authenticity indicators, content moderation signals, image quality scores, fraud detection signals, and Beauty Passport visual profile information.
Some image-derived information may be considered biometric information, biometric identifiers, sensitive personal information, or consumer health data under certain laws depending on how it is created, used, and stored. When required, we provide additional notices and consent flows.
G. Booking and Transaction Information
Appointment requests, booking confirmations, service and provider selected, appointment date/time, deposits, payments, refunds, cancellation history, no-show information, invoices, receipts, subscription information, payment processor tokens, transaction IDs, chargeback information, promotional credits, product purchases, and affiliate transaction information. We generally use third-party payment processors and do not intentionally store complete payment card numbers.
H. Communications
Emails, SMS, in-app messages, support messages, provider-client messages, feedback, survey and beta onboarding responses, call notes, voluntary DM responses, consent records, opt-out requests, and complaint records.
I. Reviews, Testimonials, and User Content
Reviews, ratings, testimonials, comments, before-and-after stories, provider/client feedback, portfolio captions, service descriptions, uploaded content, public profile content, social media references, and referral information. The FTC’s Consumer Reviews and Testimonials Rule addresses deceptive review and testimonial conduct, including fake or false reviews and misleading testimonials.
J. Device, Usage, and Technical Information
IP address, device ID, browser type, operating system, app version, device type, referring URL, pages viewed, buttons clicked, search queries, session activity, approximate IP-based location, timestamps, cookies, pixels, SDK data, crash and performance logs, security logs, fraud signals, and analytics identifiers.
K. Location Information
Approximate location, city, state, ZIP, service area, provider/client-selected locations, distance from provider, IP-derived location, and precise location only if voluntarily enabled or required for a feature. We do not need constant precise location tracking for most features.
L. Publicly Available and Third-Party Information
Public business and professional information, including business name, website, public phone/email, address, public social media, booking link, service menu, public reviews and portfolio, and public license or registration information where available. We may also receive information from vendors, analytics providers, payment processors, booking systems, advertising partners, social platforms, data enrichment providers, or other users.
4. Sources of Information
We collect information directly from you, your account, your Beauty Passport, your Provider profile, Constella Orbit onboarding, forms, uploaded photos, bookings, payments, messages, emails, SMS, reviews, social media interactions, cookies and tracking technologies, providers, clients, public business listings and websites, social platforms, booking platforms, payment processors, analytics vendors, advertising platforms, security vendors, customer support tools, data providers, and business partners.
5. How We Use Information
A. Operating the Platform
Create accounts; authenticate users; maintain profiles; display provider listings; operate Beauty Passport, Constella Orbit, and Constella Match AI; process bookings and payments; provide customer support; send service communications; maintain security; debug errors; manage beta onboarding; and provide requested services.
B. AI Matching and Personalization
Match clients with Providers; recommend services, beauty verticals, products, and rebooking timing; generate provider-fit scores and profile insights; personalize Beauty Passport; improve search, discovery, recommendations, categorization, and portfolio analysis.
C. Provider Growth and Constella Orbit
Create and optimize Provider profiles, categorize by vertical, display portfolios, highlight specialties, analyze service offerings, support discovery, generate business insights, support verification and lead routing, and power marketing, analytics, review management, and future AI business tools.
D. Visual Analysis
Analyze uploaded photos and support Beauty Passport personalization, LashMatch AI, BrowMatch AI, SkinMatch AI, GlowMatch AI, MedSpaMatch AI, BridalMatch AI, NailMatch AI, before-and-after review, portfolio presentation, detection of misleading or prohibited content, and ongoing image-processing quality improvements. Visual analysis is not medical advice, diagnosis, dermatology evaluation, or a replacement for licensed professional judgment.
E. Product Recommendations and Commerce
Recommend products, aftercare, skincare routines, lash/brow/waxing/bridal/medspa aftercare; support affiliate links and brand partnerships; process product transactions; measure product performance; and personalize commerce experiences. Constella may receive compensation from product recommendations, affiliate relationships, brand partnerships, sponsored placements, and commerce integrations.
F. Communications
Onboarding messages, transactional emails, booking confirmations and reminders, provider beta information, customer support replies, product updates, administrative and legal notices, marketing emails where permitted, SMS where permitted, responses to inquiries, and opt-out processing.
G. Marketing and Advertising
Promote Constella and participating Providers; measure campaigns; build lookalike or custom audiences where permitted; analyze user interest; improve outreach; send newsletters and beta campaigns; invite Providers and Clients; display ads; and measure conversions. Where required, we provide opt-out rights for targeted advertising, sale, or sharing of personal information.
H. Safety, Fraud Prevention, and Legal Compliance
Verify identity; detect fake accounts, spam, fraud, abuse, fake reviews, and unauthorized image use; investigate complaints; prevent scraping; protect users, Providers, and Constella; enforce agreements; respond to lawful requests; comply with law; maintain audit and consent records; and defend legal claims.
6. AI, Automated Processing, and Profiling
Constella uses AI and automated systems to provide matching, recommendations, personalization, search, provider categorization, profile optimization, image analysis, product recommendations, fraud detection, moderation, and analytics. AI outputs may be inaccurate, incomplete, biased, outdated, or unsuitable. AI matching is assistive only. It does not guarantee a Provider’s quality, availability, safety, licensure, suitability, professionalism, or result.
We do not intend to use automated processing to make legally significant decisions about employment, credit, housing, insurance, education, government benefits, or healthcare eligibility. You may have rights under certain state laws concerning profiling, automated decision-making, targeted advertising, or sensitive data processing.
7. Visual, Biometric, and Image-Related Privacy
Constella may collect or process Visual Data and Image-Derived Data. Depending on the feature and jurisdiction, certain image-derived data may be considered biometric information or biometric identifiers. Illinois BIPA, for example, defines biometric identifiers to include a scan of hand or face geometry. Constella’s handling of visual and biometric-related data is further described in our Biometric / Visual Analysis Consent Policy.
As a general rule: we seek consent where required; we use visual data for disclosed purposes; we do not intend to sell biometric identifiers; we maintain retention and deletion procedures; we limit access to sensitive visual data; we use service providers for hosting, security, moderation, and AI processing; we may de-identify or aggregate data for improvement and analytics; and we do not use visual analysis to provide medical diagnosis through general platform features.
8. Consumer Health Data & MedSpa / Skincare Information
Some Constella features may involve skincare, medspa interests, treatment goals, allergies, sensitivities, cosmetic concerns, service preferences, wellness interests, or information that may be considered consumer health data under certain laws. Washington’s My Health My Data Act protects certain consumer health data outside traditional HIPAA coverage.
Constella is generally a technology platform and is not itself a medical provider through its general Services. However, some Providers may be healthcare providers, medspas, or regulated aesthetic businesses. Where required, we may provide additional consumer health data notices, separate consent flows, or a separate Consumer Health Data Privacy Policy. You should not upload medical records, prescriptions, lab results, diagnosis information, or protected health information unless specifically requested through an approved feature.
9. How We Share Information
A. Providers
We may share information with Providers when you match, book, message, request a consultation, share Beauty Passport information, authorize sharing of photos or visual analysis, submit a review, request services, or need support for a provider-related issue. This may include your name, contact information, appointment details, service goals, Beauty Passport preferences, relevant photos, visual analysis outputs, messages, and service-related notes. Providers are independent businesses; their use of information may be governed by their own privacy policies, professional rules, and client agreements.
B. Clients
We may display Provider information to Clients, including business name, provider name, services, portfolio, reviews, ratings, specialties, badges, availability, location, booking link, website, social media, and profile details.
C. Service Providers and Vendors
Cloud hosting, database, AI processing, image storage and moderation, payment processing, booking infrastructure, email, SMS, analytics, advertising technology, customer support, consent management, security, fraud prevention, legal advisors, auditors, accountants, insurance providers, and data storage vendors. These vendors process information only as needed to provide services to Constella and subject to appropriate obligations.
D. Payment Processors
Payment information may be processed by third-party payment processors. We may receive transaction confirmations, payment tokens, billing details, subscription information, chargeback information, and fraud signals.
E. Product Brands and Commerce Partners
If you interact with product recommendations, affiliate links, brand offers, product bundles, or commerce features, we may share limited information with product brands, merchants, affiliate networks, or fulfillment partners to complete transactions, track referrals, measure performance, or provide offers.
F. Advertising and Analytics Partners
We may share or make available certain identifiers, usage, device, cookie, or conversion data with advertising and analytics partners. This may be considered “sharing,” “targeted advertising,” or “sale” under certain privacy laws. We will provide opt-out mechanisms where required.
G. Legal and Safety Disclosures
To comply with law; respond to subpoenas, court orders, warrants, and lawful government requests; protect rights and safety; investigate fraud; enforce agreements; resolve disputes; protect users, Providers, and Constella; prevent abuse; and defend legal claims.
H. Business Transfers
Information may be disclosed or transferred in connection with a merger, acquisition, financing, investment, due diligence, reorganization, sale of assets, bankruptcy, change of control, corporate restructuring, or assignment to an affiliate or successor. Any successor will be expected to handle personal information consistent with applicable law.
10. Cookies, Pixels, Tracking & Similar Technologies
We may use cookies, pixels, SDKs, tags, local storage, web beacons, and similar technologies to keep users signed in, remember preferences, measure traffic, analyze usage, improve performance, personalize content, measure ads, detect fraud, secure the platform, and support analytics, remarketing, and conversion measurement.
Categories may include strictly necessary, preference, analytics, advertising, security, and performance cookies. You may control cookies through browser settings, cookie banners, preference centers, or opt-out tools where available. Blocking cookies may affect certain features.
11. Marketing Communications
We may send marketing emails, newsletters, provider beta invitations, product updates, platform announcements, and promotional communications. You may unsubscribe from marketing emails using the unsubscribe link or by contacting us. We may still send transactional, administrative, legal, security, billing, support, and account-related messages. Commercial email must follow CAN-SPAM requirements, including truthful header information, a valid postal address, and opt-out mechanisms.
12. SMS and Text Messaging
If you provide a phone number and consent to receive SMS messages, we may send texts about onboarding, account activity, bookings, reminders, provider beta participation, support, and marketing where permitted. Message and data rates may apply. Consent to marketing texts is not required to purchase goods or services. You may opt out by replying STOP where supported. Business marketing texts may require prior express written consent under applicable telecommunications rules.
13. Reviews, Testimonials, and Public Content
If you submit reviews, ratings, testimonials, photos, comments, profile content, portfolio content, or before-and-after images, we may display them publicly or to relevant users depending on the feature and permissions. You should not include private information in public content. Reviews and testimonials must be truthful and based on genuine experiences. We may remove or restrict content that appears fake, deceptive, misleading, defamatory, unlawful, abusive, or non-compliant. The FTC’s review rule addresses deceptive and unfair conduct involving consumer reviews and testimonials.
14. Legal Bases for Processing
Where required by law, our legal bases may include your consent, performance of a contract, legitimate business interests, compliance with legal obligations, protection of vital interests, and public interest where applicable. Examples: account data to provide Services; payment data to complete transactions; visual data with consent where required; analytics data to improve the platform; security logs to prevent fraud and protect users; legal records to comply with obligations and defend claims.
15. Data Retention
We retain personal information only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Retention depends on account status, type of data, user/provider relationship, legal obligations, payment records, tax requirements, dispute history, fraud-prevention and security needs, consent records, backup cycles, regulatory obligations, and contractual requirements.
- Account information: retained while account is active and for a reasonable period afterward.
- Provider profiles: retained while provider participates and for a reasonable period afterward.
- Booking and transaction records: retained as needed for tax, accounting, legal, and dispute purposes.
- Beauty Passport data: retained while account is active or until deletion is requested, subject to exceptions.
- Visual data: retained according to this Policy and the Biometric / Visual Analysis Consent Policy.
- Consent records: retained as needed to prove consent and comply with law.
- Marketing records: retained until opt-out and as needed to maintain suppression lists.
- Security logs: retained as needed for fraud prevention, security, and legal purposes.
- De-identified or aggregated data: may be retained indefinitely where it no longer identifies a person.
16. Deletion & De-Identification
We may delete data by removing it from active systems, deleting source files, removing account associations, de-identifying or aggregating records, anonymizing data, allowing backups to expire, suppressing contact information from marketing systems, and disabling public display. Deletion may not immediately remove data from backups, legal-hold systems, fraud-prevention/accounting/transaction records, consent logs, provider records, third-party systems outside our control, content already distributed under a valid release, or archived or cached pages. We will honor deletion requests as required by applicable law.
17. Data Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest where appropriate, access controls, role-based permissions, authentication controls, secure cloud infrastructure, logging and monitoring, security reviews, vendor due diligence, employee access restrictions, incident response procedures, data minimization, consent management, secure deletion practices, and backup and recovery controls. No system is perfectly secure. We cannot guarantee absolute security. You are responsible for keeping your login credentials confidential.
18. Children and Minors
Constella is not intended for children under 13. We do not knowingly collect personal information from children under 13 without verifiable parental consent. Our visual analysis, Beauty Passport, provider matching, and biometric-related features are intended for adults. Users should not upload images of minors unless expressly permitted, legally authorized, and accompanied by required parent or guardian consent. If you believe a child’s information was submitted improperly, contact us at privacy@constellamatch.com.
19. Your Privacy Rights
Depending on where you live, you may have rights to access personal information; confirm whether we process your data; correct inaccurate information; delete personal information; receive a portable copy; opt out of sale of personal information; opt out of sharing for cross-context behavioral advertising; opt out of targeted advertising; limit use of sensitive personal information; withdraw consent; appeal a privacy rights decision; object to or restrict certain processing; request information about disclosures; and request deletion of visual or biometric-related data where applicable.
California, Virginia, Maryland, and other states provide consumer privacy rights that may apply depending on business thresholds, residency, data type, and processing activity. To exercise rights, contact privacy@constellamatch.com. We may need to verify your identity before responding.
20. California Privacy Notice
This section applies to California residents where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies. California residents may have rights to know, access, delete, correct, opt out of sale or sharing, limit use and disclosure of sensitive personal information, and not be discriminated against for exercising privacy rights.
Categories of Personal Information Collected
Identifiers; contact information; commercial information; internet activity; geolocation; professional or employment-related information; audio, electronic, visual, or similar information; sensitive personal information; inferences; user-generated content; payment-related information; biometric-related information where applicable.
Categories of Sources
You, Providers, Clients, public sources, service providers, advertising and analytics partners, payment processors, social media platforms, booking tools, and data vendors.
Business or Commercial Purposes
Operating Services; providing AI matching; creating profiles; processing bookings and payments; communicating; marketing; improving products; preventing fraud; maintaining security; complying with law; supporting provider onboarding; supporting product recommendations.
Categories of Recipients
Service providers, Providers, Clients, payment processors, analytics and advertising partners, product partners, legal advisors, government authorities where required, and business-transfer parties.
Sale or Sharing
Certain analytics, advertising, retargeting, or affiliate activities may be considered a “sale” or “sharing” under California law. Where required, we will provide a Do Not Sell or Share My Personal Information mechanism.
Sensitive Personal Information
We may collect sensitive personal information, such as account login credentials, precise location where enabled, certain visual/biometric-related information, payment-related data, or sensitive beauty/health-related preferences. We use sensitive personal information only as permitted by law, with consent where required, and for disclosed purposes.
21. Virginia Privacy Notice
Virginia residents may have rights under the Virginia Consumer Data Protection Act where applicable. Virginia law requires consent before processing sensitive data and provides consumer rights such as access, correction, deletion, portability, and opt-out of targeted advertising, sale of personal data, or certain profiling. To exercise Virginia rights, contact privacy@constellamatch.com. You may appeal a decision by replying to our response and stating that you are appealing the privacy decision.
22. Maryland Privacy Notice
This section applies to Maryland residents where the Maryland Online Data Privacy Act applies. Maryland adopted comprehensive privacy legislation regulating controllers and processors of consumer personal data. Maryland residents may have rights to access, correct, delete, obtain a copy of personal data, and opt out of certain processing, subject to legal requirements and exemptions. Because Constella is Maryland-focused in early provider outreach, we treat Maryland privacy compliance as a core operating requirement. To exercise rights, contact privacy@constellamatch.com.
23. Washington Consumer Health Data Notice
If Washington’s My Health My Data Act applies to any information we collect, use, or share, additional consumer health data protections may apply. Washington’s law was designed to protect consumer health data outside the scope of HIPAA in certain circumstances. If applicable, we may provide a separate Consumer Health Data Privacy Policy and separate consent mechanisms for collecting, using, or sharing consumer health data.
Potential consumer health data in the Constella context may include skin concern information, medspa treatment interests, allergy or sensitivity information, wellness goals, cosmetic treatment goals, treatment-related visual data, and service history involving wellness or aesthetic care. Constella does not provide medical diagnosis or treatment through general platform features.
24. Biometric Privacy Notice
If we collect or process biometric identifiers or biometric information as defined by applicable law, we will do so according to our Biometric / Visual Analysis Consent Policy. This may include notice before collection, consent where required, purpose disclosure, retention and destruction rules, security safeguards, restrictions on sale or disclosure, withdrawal procedures, and deletion mechanisms where required. Illinois BIPA treats a scan of face geometry as a biometric identifier and requires informed written release and retention/destruction rules for biometric data.
25. International Users
Constella is operated from the United States. If you access the Services from outside the United States, your information may be processed in the United States and other countries where our service providers operate. Your jurisdiction may have data protection laws different from U.S. law. We may restrict or disable certain features in jurisdictions where additional privacy, biometric, health data, AI, or marketing requirements apply.
26. Third-Party Links and Services
The Services may link to third-party websites, booking platforms, payment processors, social media pages, provider websites, product merchants, analytics tools, or advertising partners. We are not responsible for third-party privacy practices. You should review third-party privacy policies before providing information to them.
27. Provider Responsibilities
Providers using Constella are independent businesses. Providers are responsible for obtaining client consent; maintaining their own privacy policies where required; protecting Client Data; using Client Data only for authorized purposes; complying with applicable privacy, biometric, consumer health data, and SMS/email marketing laws; complying with professional confidentiality obligations; deleting or returning Client Data where required; avoiding unauthorized use of photos or before-and-after images; and avoiding upload of protected health information unless authorized. Constella may suspend Providers who misuse Client Data.
28. How to Exercise Your Rights
To submit a privacy request, email privacy@constellamatch.com. Please include your full name; email; phone if relevant; state or country of residence; type of request; account information; information needed to verify identity; and whether you are a Client, Provider, or website visitor. We may verify your identity by matching information you provide with information we maintain. Authorized agents may submit requests where permitted by law, subject to verification. We will respond within the time required by applicable law.
29. Appeals
If we deny your privacy request and applicable law gives you appeal rights, you may appeal by replying to our decision or emailing privacy@constellamatch.com with the subject line Privacy Rights Appeal. We will review and respond as required by law.
30. Opt-Out Mechanisms
Depending on applicable law and technical implementation, you may opt out of marketing emails, marketing texts, targeted advertising, sale or sharing of personal information, certain cookies, certain analytics, certain product recommendation tracking, certain profiling activities, and certain sensitive data uses. Opt-out methods may include email unsubscribe links; replying STOP to SMS; cookie preference centers; browser settings; the privacy request form; emailing privacy@constellamatch.com; and the “Do Not Sell or Share” mechanism where required.
31. Financial Incentives and Promotions
Constella may offer referral programs, beta incentives, provider promotions, discounts, rewards, credits, featured placement, or other benefits. If a program is considered a financial incentive under applicable privacy law, we will provide required disclosures and obtain opt-in consent where required. You may opt out of a financial incentive program as described in the program terms.
32. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If changes are material, we may provide notice by email, website notice, in-app notice, dashboard notice, or other reasonable means. The updated Privacy Policy will be effective as of the date posted unless stated otherwise. Your continued use of the Services after an updated Privacy Policy becomes effective means you acknowledge the updated policy. Where required by law, we will obtain consent for materially different uses of previously collected information.
33. Contact Information
Constella AI Technologies, Inc. (a Virginia Corporation)
Attn: Privacy Department
Privacy: privacy@constellamatch.com
Legal: legal@constellamatch.com
Support: support@constellamatch.com
Website: www.constellamatch.com
Traceable acceptance
Acknowledge & Accept the Constella AI Privacy Policy
By checking the box and submitting, you create a permanent, timestamped record of your agreement to Constella AI Privacy Policy version 2.0 (effective 2026-06-06). We log your name, email, the page URL, your browser, and the time of acceptance for audit purposes.
