Privacy Policy
What we collect, why, and what you can do about it.
Last updated: May 23, 2026
1. Who we are
lab818 Studios is operated at 4605 Lankershim Blvd #180, North Hollywood, CA 91602. For any privacy-related questions or requests, contact us at [email protected].
2. What we collect
| What | When | Why |
|---|---|---|
| Name, email, phone | When you book a session or use the contact form | To confirm your booking, send delivery emails, and answer questions |
| Booking details (date, service tier, add-ons) | During the booking flow | To reserve studio time and bill correctly |
| Payment information | At checkout | Processed by SBPay using Stripe. We never see or store your full card number — only the last 4 digits and brand. |
| Recorded session files | During your session | Stored on Dropbox and shared with you via download link. Auto-deleted after 30 days unless you request a longer retention. |
| Email engagement data | When we send you transactional emails (delivery, reminders, magic links) | To know when an email was opened or a link was clicked — helps us confirm delivery and follow up if something didn't reach you. |
| Site analytics (aggregated) | While browsing lab818studios.com | Page views and Core Web Vitals via Google Search Console. Anonymous — no individual tracking. |
3. How we use it
- Service delivery: Take your booking, send confirmations, deliver your recorded files, follow up on requests.
- Payments: Process payments through SBPay/Stripe and issue refunds when applicable.
- Operations: Internal reporting on bookings, occupancy, and revenue. No customer-identifying data is shared externally.
- Communication: Send transactional messages tied to your booking. We do not send marketing emails without your explicit opt-in.
- Legal compliance: Respond to lawful requests, enforce our Terms of Service, or protect our rights.
4. Third-party services we rely on
The booking app passes specific slices of your data to third-party services so we can operate. Each has its own privacy policy:
| Service | What they receive | Their policy |
|---|---|---|
| SimplyBook.me | Name, email, phone, booking details, invoice records | simplybook.me/privacy |
| SBPay (payment processor) | Booking amount, invoice id, customer name + email; card data handled by Stripe | sbpay.me |
| Stripe | Card data, billing details, transaction history | stripe.com/privacy |
| Dropbox | Recorded session files (audio + video) and the share link sent to you | dropbox.com/privacy |
| Resend (email delivery) | Email address and the body of transactional emails we send you | resend.com/privacy |
| Railway (hosting) | Server logs and operational data; no direct user-visible footprint | railway.app/privacy |
| Google (Business Profile + Search) | Booking metadata when customers come through Reserve with Google | policies.google.com/privacy |
5. Data retention
- Recorded files (Dropbox): 30 days by default. Longer retention available on request before expiration. After expiration, files are deleted and cannot be recovered.
- Booking records (SimplyBook + our database): Retained for at least 7 years for tax and accounting purposes, in line with IRS and California recordkeeping requirements.
- Customer email + contact info: Retained for as long as you have an active relationship with us, plus 7 years from your last booking for our records.
- Transactional email logs (Resend): Standard Resend retention (typically 30 days).
- Magic-link tokens: 24-hour TTL with a 2-hour sliding window; expired tokens are auto-deleted.
6. Cookies & local storage
We use minimal browser storage to operate the booking flow:
- sessionStorage (cleared when you close your tab): preserves your booking progress so you don't lose your place if you navigate away or hit back from the payment page.
- Admin session tokens (admin users only): 14-day cookies for staying logged into the admin board.
- No third-party tracking cookies. No Facebook Pixel, no advertising trackers, no cross-site profiles.
7. Your rights
You have the right to:
- Access the personal information we hold about you.
- Correct any inaccurate or out-of-date information.
- Delete your personal information (subject to legal recordkeeping requirements for past transactions).
- Export your data in a portable format.
- Object to specific uses of your data.
To exercise any of these rights, email [email protected]. We'll respond within 30 days. We may verify your identity before processing the request.
8. California residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
- The right to know what categories of personal information we collect, where it comes from, and who we share it with (covered above).
- The right to delete personal information (subject to exceptions).
- The right to correct inaccurate information.
- The right to opt out of "sale" or "sharing" of personal information. We do not sell your data to any third party.
- The right to non-discrimination for exercising any of these rights.
9. Security
We take reasonable measures to protect your information:
- HTTPS/TLS everywhere on lab818studios.com.
- Card data is never seen by our servers — it goes directly from your browser to Stripe via SBPay's hosted checkout.
- Administrative accounts use bcrypt-hashed passwords and short-lived session tokens.
- Backup access to file delivery and admin tools is restricted to studio staff.
No system is perfectly secure. If we ever experience a breach affecting your data, we'll notify you and the appropriate authorities as required by California law (Civil Code § 1798.82).
10. Children's privacy
Our services are not directed to children under 13. We do not knowingly collect personal information from anyone under 13. If you believe we have collected information from a child under 13, please contact us so we can delete it.
11. International users
We operate in the United States. If you're booking from outside the U.S., your information will be transferred to and processed in the U.S. and by our U.S.-based service providers. By using our services you consent to this transfer.
12. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the current version. Material changes will be communicated by updating that date. We will not retroactively reduce the protections that applied at the time your data was collected.
13. Contact us
Privacy questions, requests, or concerns:
- Email: [email protected]
- Phone: 818-669-7590
- Mail: lab818 Studios, 4605 Lankershim Blvd #180, North Hollywood, CA 91602
Not legal advice. This Privacy Policy is provided in good faith as a reasonable baseline for a small studio business in California, but it has not been reviewed by a licensed attorney for your specific operations or jurisdictions you serve. We recommend having a California privacy attorney review it before you rely on any specific compliance protection (CCPA/CPRA, COPPA, GDPR if you have EU customers, etc.).