Privacy Policy
Effective date: July 23, 2026
1. Scope
Somavue is a product of Blue Chip Group LLC, a Texas limited liability company ("Blue Chip Group," "we," "us," or "our"). This Privacy Policy explains how Blue Chip Group collects, uses, protects, and retains information when shops, staff, customers, patients, and referral partners use Somavue.
Somavue is built for massage, bodywork, and adjacent wellness shops. When a person books, checks in, completes a form, or otherwise interacts with a shop through Somavue, Blue Chip Group processes that person's customer and patient information for and on behalf of that shop. The shop determines what information it collects and how it uses that information in its customer relationship, subject to applicable law and the shop's own privacy notices.
Making information available to the shop a person chose to interact with is part of providing Somavue; it is not a sale or disclosure to an unrelated third party for marketing. Blue Chip Group separately determines how it uses information for its own account administration, security, billing, support, product operations, legal compliance, and other purposes described in this Privacy Policy.
2. Information We Collect
We collect information needed to operate the service, including:
- Shop and account information: organization name, location details, staff names, phone numbers, roles, invitations, passkey enrollment state, and session records.
- Customer and patient information: names, contact details, dates of birth when provided or required, appointment details, service selections, check-in state, intake answers, consent evidence, pain-map drawings, notes, and related records.
- Scheduling and operations data: services, prices, add-ons, staff schedules, rooms, resources, booking settings, appointment history, readiness status, and provider assignments.
- Payment information: payment status, invoices, line items, Stripe PaymentIntent identifiers, Stripe connected-account status, payout summaries, application-fee records, refunds, and payment-related metadata. Full card numbers are processed by Stripe and are not stored by Somavue.
- Partner and business contact information: referral partner lead names, email addresses, evaluation notes, referral codes, partner status, and partner-attributed signup records.
- Communications data: SMS delivery records, opt-out status, message templates, account verification and security notices, staff invitations, shop-directed pre-visit form links, push-notification device tokens, and support messages.
- Device, security, and usage data: IP address, user agent, host, request metadata, audit logs, authentication challenges, kiosk identifiers, event logs, and error diagnostics.
- Marketing source data: referral codes, campaign parameters (such as UTM source, medium, campaign, term, and content), landing path, and referring URL captured when someone starts signup from a Somavue marketing page.
3. How We Use Information
We use information to:
- Provide booking, scheduling, check-in, intake, customer records, payments, reminders, reporting, and staff operations.
- Authenticate staff and customers, secure sessions, provision kiosks, and prevent unauthorized access.
- Process customer payments through Stripe Connect and support payout, invoice, refund, and reporting workflows.
- Evaluate referral partner requests, administer referral codes, and track partner-attributed shop signups.
- Share referral-attribution status and related signup information back to the referring partner when needed to administer referral credit, partner dashboards, eligibility, and compensation.
- Send transactional SMS for account access and security and for shop-directed pre-visit forms, and send operational push notifications to staff devices.
- Maintain audit logs, troubleshoot issues, prevent fraud, enforce policies, and comply with legal obligations.
- Improve Somavue's product, onboarding, support, and marketing funnels.
4. Third-Party Providers and Marketing
We use third-party providers to operate Somavue. Current or planned providers include:
- Vultr: application hosting and database infrastructure.
- Stripe: payment processing, Stripe Connect onboarding, Stripe Terminal, payouts, disputes, and payment compliance.
- Flowroute: transactional SMS delivery and SMS opt-out handling.
- Apple Push Notification service (APNs), Google Firebase Cloud Messaging (FCM), and browser push services: delivery of operational push notifications to staff devices. We send a device token or push subscription and the notification payload needed to deliver an alert; we do not use these services for advertising.
- Amazon SES: email delivery for internal Somavue support and operational alerts.
- Sentry: error and crash reporting for the backend, web apps, and native apps. Error reports are scrubbed of sensitive data such as credentials and authentication headers before sending.
- S3-compatible object storage: storage for uploaded files or generated documents when those features are enabled.
These providers process data only as needed to provide infrastructure, communications, payment, storage, support, security, or compliance services. Stripe's processing is also governed by Stripe's own privacy policy.
We do not share, sell, or rent personal information to unrelated third parties for their marketing or promotional purposes. We disclose personal information only as described in this Privacy Policy, including to the shop a person chose to interact with, to operate Somavue, provide requested services, administer referral attribution and compensation, protect the service, or comply with law.
5. SMS Privacy
Somavue uses SMS for transactional messages: signup and sign-in verification codes, staff invitations, account-security notices such as a newly paired device, and shop-directed links for customers to complete a pre-visit intake form. Somavue does not send marketing or promotional SMS. Message frequency varies based on account activity and shop settings. Message and data rates may apply.
No mobile information will be shared with third parties or affiliates for marketing purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
We do not sell, share, or rent SMS opt-in data or consent to any third party for any reason other than to deliver the specific messaging services associated with the program. Messaging platform providers, mobile carriers, and other vendors involved in delivering messages or honoring opt-outs may process phone numbers and SMS consent status solely to perform those services on our behalf.
Reply STOP to opt out of messages from the sending number and program. Reply UNSTOP to enroll again and HELP for assistance, or contact support@somavue.com. See the SMS Program Terms for additional details.
6. Cookies and Similar Technologies
Somavue uses cookies and local browser storage for authentication, session continuity, security, selected location, theme, locale, and small interface preferences.
When someone starts signup from a Somavue marketing page, we store a first-party signup-attribution cookie and local-storage entry that remembers referral and campaign parameters (such as a referral code or UTM tags) so the resulting shop signup can be credited to the correct marketing source. We do not use this attribution data to track you across other sites or build a browsing profile, and we do not use third-party advertising cookies in the product.
7. Data Retention
We retain information as long as needed to provide Somavue, maintain shop records, comply with legal obligations, resolve disputes, enforce agreements, and preserve security evidence.
Intake, check-in, consent, pain-map, payment, audit, and legal records may be retained beyond ordinary account activity because shops may need them for legal, operational, accounting, or care-readiness reasons. Backups may retain deleted data for a limited period before aging out.
8. Security
Somavue uses security controls appropriate for a platform serving many shops, including TLS in transit, shop-scoped access checks, passkey-based staff authentication, hashed session tokens, audit logging, database constraints, and restricted operational access.
No system is perfectly secure. You are responsible for keeping your staff devices, kiosk devices, sessions, and authorized users secure.
9. Health-Adjacent and Sensitive Information
Somavue may store health-adjacent information such as intake answers, pain maps, service notes, pregnancy status, injury history, medications, consent evidence, and guardian-consent confirmations. Shops are responsible for deciding what they collect and for complying with laws that apply to their business and customer population.
Somavue is not expected to be a HIPAA covered entity in ordinary massage/bodywork shop workflows. If a shop is a covered entity or uses Somavue for protected health information, additional terms or compliance arrangements may be required.
10. Children's and Minor Information
Somavue is not directed to children under 13 as account holders. Shops may use Somavue to book or check in minors as patients when handled by a parent, legal guardian, or authorized adult. When Somavue knows a client is under 17, kiosk check-in may require a guardian confirmation before the visit proceeds.
11. Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, export, or restrict certain personal information. To exercise privacy rights, contact the shop that controls your record or contact us at privacy@somavue.com.
Some records cannot be deleted immediately if retention is required for legal, security, audit, payment, dispute, accounting, backup, or shop-record obligations.
12. US State Privacy Notices
We do not sell personal information and do not share personal information for cross-context behavioral advertising. We do not use sensitive personal information for purposes other than providing, securing, supporting, and improving the service.
California, Texas, and other US state residents may exercise applicable privacy rights by contacting privacy@somavue.com. We will not discriminate against you for exercising those rights.
13. International Access
Somavue is operated from the United States. If you access Somavue from outside the United States, your information may be processed in the United States, where privacy laws may differ from those in your location.
14. Changes to This Policy
We may update this Privacy Policy from time to time. The updated policy will show a new effective date. Continued use of Somavue after an update means the updated policy applies.
15. Contact
Questions about this Privacy Policy may be sent to privacy@somavue.com.