Legal

Privacy Policy

Last updated: May 14, 2026

AirCare (“we,” “us,” or “our”) operates a platform that connects patients with verified hair transplant clinics and clinics across multiple countries. This Privacy Policy explains how we collect, use, share, and protect your personal data when you use our website, applications, and services (collectively, the “Services”).

By using AirCare, you agree to the practices described in this policy. If you do not agree, please do not use our Services.

1. Our commitment to your privacy

At AirCare, keeping your information secure is a top priority. We believe you should understand exactly how your data is handled and have control over it. Here are the commitments we make to every user:

  • We do not sell your personal information. Your data is never sold to third parties for advertising, marketing, or any other purpose.
  • We only share what's needed to deliver your care. When you request an assessment or book a procedure, we share the minimum information necessary with your chosen clinic — nothing more.
  • We are transparent about data flows. Because our platform connects you with clinics in multiple countries, we clearly disclose when and where your data may be transferred internationally.
  • You can delete your data at any time. You can request deletion of your account and personal data, and we will honor that request subject to any legal obligations.

2. Information we collect

Information you provide directly

When you create an account, request assessments, or book a procedure through AirCare, you may provide:

  • Account information: name, email address, phone number, date of birth, and country of residence.
  • Health-related information: photos of your hair and scalp, hair loss history, medical history relevant to your procedure (e.g., medications, allergies, prior surgeries), and your treatment preferences (technique, budget, destination).
  • Booking and payment information: procedure dates, package selections, and payment details. Payment processing is handled by third-party payment processors — we do not store your full credit card number.
  • Communications: messages you send through the platform to clinics or our support team, and any reviews or feedback you submit. If you provide a mobile number and opt in, we may also send you text messages (see Section 7 below).

Information collected automatically

When you use our Services, we automatically collect certain information, including:

  • Device and browser data: IP address, browser type, operating system, device identifiers, and screen resolution.
  • Usage data: pages visited, search queries, clinics viewed, time spent on pages, and referral source.
  • Location data: approximate location derived from your IP address, used to show you relevant clinics and pricing in your local currency.

Information from third parties

We may receive information from partner clinics regarding the status of your booking or procedure, and from analytics providers that help us understand how our Services are used.

3. How we use your information

We use the information we collect to:

  • Provide, maintain, and improve our Services — including matching you with clinics, facilitating assessments, and processing bookings.
  • Send your assessment requests (including photos and health information) to the specific clinics you select.
  • Communicate with you about your account, bookings, and post-procedure follow-ups.
  • Personalize your experience, such as showing clinics relevant to your country and preferences.
  • Analyze aggregated, de-identified data to understand how our platform is used and improve our Services.
  • Detect, prevent, and address fraud, abuse, and security issues.
  • Comply with legal obligations and enforce our terms of service.

We will never use your health-related information for advertising or marketing purposes. We do not use your photos or medical details for anything other than facilitating the services you have requested.

4. How we share your information

AirCare does not sell your personal information. We share your data only in the following circumstances:

With clinics you select

When you request an assessment or book a procedure, we share the information necessary for the clinic to evaluate your case and deliver your care. This may include your name, contact details, photos, health information, and booking details. We only share this with the specific clinic(s) you choose — never with clinics you haven't engaged with.

With service providers

We work with trusted third-party service providers who help us operate our platform, including:

  • Cloud hosting and data storage (e.g., Supabase, Vercel)
  • Payment processing
  • Email delivery (e.g., Resend) and SMS messaging (e.g., Twilio) used to send you account notifications such as one-time photo-upload links
  • Analytics and performance monitoring
  • Customer support tools

These providers are contractually obligated to use your data only as necessary to perform services on our behalf and to maintain appropriate security measures.

For legal reasons

We may disclose your information if required by law, regulation, legal process, or governmental request, or if we believe disclosure is necessary to protect the rights, safety, or property of AirCare, our users, or the public.

In connection with a business transfer

If AirCare is involved in a merger, acquisition, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.

5. International data transfers

AirCare connects patients with clinics across multiple countries, including Turkey, Mexico, Colombia, and the United States. When you request an assessment or book a procedure with a clinic in another country, your personal data — including health-related information and photos — will be transferred to that clinic in the country where they operate.

Data protection laws vary by country. By submitting your information to a clinic abroad, you acknowledge that the clinic is subject to the data protection laws of its own jurisdiction, which may offer different levels of protection than your home country.

We take the following steps to protect your data in transit:

  • All data transmitted through AirCare is encrypted using TLS (Transport Layer Security).
  • We vet partner clinics for appropriate data handling practices as part of our onboarding process.
  • We share only the minimum information necessary for the clinic to deliver the service you requested.

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on appropriate legal mechanisms for cross-border data transfers, including standard contractual clauses where applicable.

6. Cookies and tracking technologies

We use cookies and similar technologies to operate our Services, remember your preferences, and understand how our platform is used. These include:

  • Essential cookies: Required for core functionality such as authentication, country selection, and security. These cannot be disabled.
  • Analytics cookies: Help us understand how visitors use our Services, which pages are most popular, and where users encounter issues. We use this data in aggregate to improve the platform.
  • Preference cookies: Remember your settings, such as your selected country and language.

We do not use advertising or behavioral tracking cookies. We do not build advertising profiles based on your browsing activity.

You can manage cookie preferences through your browser settings. Note that disabling essential cookies may affect the functionality of our Services.

7. SMS text messages

If you provide a mobile phone number during your intake and consent to receive text messages, AirCare may send you SMS messages strictly to support your care journey on our platform. We send SMS through our messaging provider, Twilio, who acts as a service provider on our behalf and is contractually required to keep your number confidential.

What we send. SMS messages are transactional and account-related — for example, a one-time secure link to upload your hair photos from your phone, or status updates tied to an action you took in your AirCare account. We do not send marketing or promotional SMS.

How often we send.Message frequency depends on your activity. Most messages are sent only after you explicitly request them (for example, by tapping “Send link to my phone”). We do not send recurring marketing blasts.

Carrier charges. Standard message and data rates from your mobile carrier may apply. AirCare does not charge you for receiving SMS.

Opting out. You can stop receiving SMS at any time by replying STOP to any message we send. Reply HELP for assistance, or contact us at support@tryaircare.com. Opting out of SMS will not affect your AirCare account or your ability to use the rest of the Services — we will still be able to reach you by email.

Mobile phone numbers and SMS opt-in data are never shared with third parties or affiliates for marketing or promotional purposes.

8. Data security

We implement industry-standard security measures to protect your personal data, including:

  • Encryption of data in transit using TLS/HTTPS connections.
  • Encryption of data at rest in our cloud infrastructure.
  • Strict access controls limiting employee access to personal data on a need-to-know basis.
  • Secure cloud infrastructure provided by established providers with SOC 2 certifications.
  • Regular security reviews and monitoring for vulnerabilities.

While we take reasonable measures to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any security incidents.

9. Data retention

We retain your personal data for as long as your account is active or as needed to provide you with our Services. We may retain certain information for longer periods as necessary to:

  • Comply with legal or regulatory obligations.
  • Resolve disputes or enforce our agreements.
  • Maintain records required for financial, tax, or audit purposes.

Health-related information submitted for assessments is retained only as long as needed to facilitate your care. If you delete your account, we will delete or de-identify your personal data within 30 days, except where retention is required by law.

10. Your rights and choices

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request that we correct inaccurate or incomplete personal data.
  • Deletion: Request that we delete your personal data, subject to certain exceptions.
  • Portability: Request a copy of your data in a structured, machine-readable format.
  • Withdraw consent: Where we rely on your consent to process data, you may withdraw that consent at any time.
  • Opt out of communications: Unsubscribe from marketing emails at any time using the link in any email we send.

To exercise any of these rights, contact us at privacy@aircare.com. We will respond to your request within 30 days.

For residents of the European Economic Area (EEA)

If you are in the EEA, you have additional rights under the General Data Protection Regulation (GDPR), including the right to lodge a complaint with your local data protection authority. Our legal basis for processing your data includes: performance of a contract (providing our Services), your consent (for health-related data), and our legitimate interests (improving our platform and preventing fraud).

For residents of California

Under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), California residents have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. AirCare does not sell personal information as defined under these laws.

For residents of other US states

Residents of states with consumer health data privacy laws (such as Washington, Connecticut, Nevada, and Virginia) may have additional rights regarding their health-related data, including the right to consent prior to collection and the right to withdraw consent. Contact us to exercise these rights.

11. Children's privacy

AirCare is not intended for individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected data from a minor, we will take steps to delete that information promptly. If you believe a minor has provided us with personal data, please contact us at privacy@aircare.com.

12. Third-party links and services

Our Services may contain links to third-party websites, including clinic websites, payment processors, and social media platforms. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party service you interact with.

13. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Services. When we make material changes, we will notify you by updating the “Last updated” date at the top of this page and, where appropriate, providing additional notice (such as email notification or an in-app banner).

We encourage you to review this policy periodically to stay informed about how we protect your data.

14. Contact us

If you have questions about this Privacy Policy, your personal data, or how AirCare handles your information, contact us:

We aim to respond to all privacy-related inquiries within 30 days.