Privacy Policy
How Nalu Wellness collects, uses, and protects your information — including your consumer health data rights under Washington State law.
Washington Residents: This policy includes a separate Consumer Health Data Privacy Policy as required by the Washington My Health My Data Act (RCW 19.373). See the section below titled "Consumer Health Data — Washington State."
Who We Are
Nalu Wellness is a sole-proprietor massage therapy practice owned and operated by Brooke Barak, Licensed Massage Therapist (LMT), located at 13317 NE 12th Ave, Suite 115, Vancouver, WA 98685. We can be reached at brookebarak.lmt@gmail.com or (360) 553-1153.
Information We Collect
Information you provide directly
- Name, email address, and phone number when booking an appointment or contacting us
- Health intake information you provide before or during your session (handled as protected health information — see our HIPAA Notice of Privacy Practices)
- Insurance information when billing through your health plan
- Payment information processed by Jane App or your insurance carrier — we do not store payment card data directly
Information collected automatically
- Standard web server logs (IP address, browser type, pages visited, referring URL, timestamps)
- Cookie and session data through our booking platform, Jane App
- Google Maps embed on our contact page may collect location and usage data per Google's Privacy Policy
How We Use Your Information
- To schedule, confirm, and manage your appointments
- To provide massage therapy services and maintain treatment records
- To process insurance billing and communicate with your health plan
- To send appointment reminders and follow-up communications
- To respond to your inquiries
- To comply with legal and regulatory obligations
We do not sell your personal information. We do not use your information for behavioral advertising.
Third-Party Services
We use the following third-party services that may process your data:
- Jane App — Online booking, scheduling, and client records platform. Jane App maintains HIPAA-compliant infrastructure and a Business Associate Agreement is in place. See Jane App's Privacy Policy.
- Google Maps — Embedded map on our contact page. See Google's Privacy Policy.
- Vercel — Website hosting. Server logs may be retained per Vercel's data retention policies.
- Thorne — If you click the Thorne supplement link from our site, Thorne's privacy policy governs data collected on their platform.
Consumer Health Data — Washington State
This section serves as our Consumer Health Data Privacy Policy as required by the Washington My Health My Data Act (MHMDA), RCW Chapter 19.373, effective June 30, 2024.
What is consumer health data?
Under Washington law, "consumer health data" includes personal information that identifies your past, present, or future physical or mental health status. This includes information you share when seeking or receiving massage therapy services, health intake forms, and records of your sessions.
What consumer health data we collect
- Health history and intake information you provide before sessions
- Session notes and treatment records
- Insurance and billing information related to health services
- The fact that you visited our website or sought information about health and wellness services
How we use consumer health data
We use consumer health data solely to:
- Provide massage therapy services to you
- Maintain treatment records as required by Washington State law
- Process insurance claims on your behalf with your consent
- Comply with applicable laws and regulations
We do not sell consumer health data. We do not use consumer health data for advertising. We do not share consumer health data with third parties except as necessary to provide your care (Jane App, your insurance carrier) or as required by law.
Your rights under the MHMDA
Washington residents have the following rights regarding their consumer health data:
- Right to access — You may request a copy of the consumer health data we hold about you
- Right to deletion — You may request deletion of your consumer health data, subject to our legal retention obligations
- Right to withdraw consent — You may withdraw consent for collection or sharing of your consumer health data at any time
- Right to know — You have the right to know what consumer health data we have collected, how it is used, and with whom it is shared
To exercise any of these rights, contact us at brookebarak.lmt@gmail.com. We will respond within 45 days as required by law.
Geofencing
We do not use geofencing technology to collect consumer health data from individuals near our practice location or any other healthcare facility.
Data Retention
We retain client records and treatment notes for a minimum of seven (7) years as required by Washington State law (WAC 246-830-460). Booking and contact information is retained as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required by law.
Data Security
We use industry-standard safeguards to protect your information, including secure booking systems through Jane App. However, no data transmission or storage system is 100% secure. If you have concerns about the security of your information, please contact us.
Children's Privacy
Our services are not directed to individuals under 18. We do not knowingly collect personal information from minors. Minors receiving services must be accompanied by a parent or legal guardian who provides consent.
Changes to This Policy
We may update this policy from time to time. Material changes will be posted on this page with an updated date. Continued use of our services after changes constitutes acceptance of the updated policy.
Contact Us
For questions about this privacy policy, to exercise your data rights, or to make a privacy-related complaint:
- Email: brookebarak.lmt@gmail.com
- Phone: (360) 553-1153
- Mail: Nalu Wellness, 13317 NE 12th Ave, Suite 115, Vancouver, WA 98685