Updated December 23, 2025

Privacy Policy

Your trust matters. This policy explains how Eye Kiosk handles and protects the data you share with us.

1. Who We Are

Eye Kiosk, Inc., a Delaware corporation ("Eye Kiosk", "we", "our", or "us") provides AI-guided vision measurement kiosks, web applications, and related services for optometry practices and retail partners.

We act as the data controller for personal information collected directly from end users and website visitors. When we process information on behalf of a practice or optical partner, we do so as their processor under a written data processing agreement.

2. Information We Collect

Information you provide directly

  • Contact details such as name, email address, phone number, and shipping address.
  • Prescription data, pupillary distance measurements, and lens preferences supplied by you or your care provider.
  • Payment information (processed securely by our PCI-compliant payment providers).
  • Support communications, feedback, and marketing preferences.

Information collected automatically

  • Device telemetry from kiosks, including firmware version, sensor calibration status, and anonymized session identifiers.
  • Technical logs and analytics from our web and mobile applications (IP address, browser type, operating system, referring pages, usage timestamps).
  • AI capture artifacts such as anonymized facial landmark vectors used to improve measurement accuracy.
  • Location data (general geographic region inferred from IP address; precise location only with your consent).

Information from partners

  • Order fulfillment updates from optical labs and shipping carriers.
  • Identity verification and fraud-prevention signals from payment providers.
  • Practice account data (e.g., authorized optometrists, store locations) from our business partners.

3. Biometric Information

Our kiosks use camera technology to capture facial measurements for pupillary distance (PD) calculations. This processing is essential to provide accurate eyewear fitting.

  • Facial geometry data is processed in real-time to extract measurement coordinates; raw images are not stored after processing unless you explicitly consent to save a reference photo.
  • We do not use facial recognition for identification purposes. The geometric data extracted cannot be used to identify you.
  • If you are in Illinois, Texas, Washington, or another state with biometric privacy laws, we will obtain your informed consent before collecting biometric information and will comply with applicable retention and destruction requirements.
  • You may request deletion of any stored biometric data by contacting privacy@eyekiosk.online.

4. Cookies and Tracking Technologies

We use cookies and similar technologies to operate our services, remember your preferences, and analyze usage patterns.

Types of cookies we use

  • Essential cookies: Required for basic site functionality (authentication, shopping cart, security).
  • Functional cookies: Remember your preferences such as language and display settings.
  • Analytics cookies: Help us understand how visitors interact with our services so we can improve the user experience.

Your cookie choices

  • Most browsers allow you to block or delete cookies through settings. Note that blocking essential cookies may impair site functionality.
  • We honor Global Privacy Control (GPC) signals where required by law.
  • We do not respond to "Do Not Track" browser signals as there is no industry-standard interpretation, but we do not track users across third-party websites for advertising purposes.

5. How We Use Personal Information

We process personal information only when we have a legal basis under applicable law (such as consent, performance of a contract, compliance with legal obligations, protection of vital interests, or legitimate interests pursued by us or a third party).

  • Delivering core services: providing vision measurements, processing eyewear orders, and managing kiosk sessions.
  • Maintaining platform integrity: diagnosing issues, monitoring for abuse, auditing access, and ensuring hardware safety.
  • Improving experiences: training and validating AI models, calibrating kiosk sensors, and conducting user research with de-identified data.
  • Communicating with you: sending transactional updates, responding to support requests, and delivering marketing communications (where permitted).
  • Complying with legal obligations: responding to lawful requests, maintaining records as required, and protecting our legal rights.

6. How We Share Information

We do not sell personal information as defined by the California Consumer Privacy Act or other state privacy laws.

We do not share personal information for cross-context behavioral advertising.

We do not permit advertising networks to track individuals across our properties.

Service providers

  • Optical labs that manufacture your eyewear.
  • Payment processors (such as Stripe) that handle transactions securely.
  • Shipping carriers that deliver your orders.
  • Cloud infrastructure providers that host our platform.
  • Analytics services that help us improve our products.

Other disclosures

  • With professional advisors (lawyers, auditors) under confidentiality obligations when necessary to protect our business.
  • With government authorities or law enforcement when required to comply with applicable laws or lawful requests.
  • With corporate affiliates or in connection with a merger, acquisition, or sale of assets, subject to appropriate protections.

7. Data Retention

We retain personal information for as long as needed to provide services, maintain business records, comply with legal obligations, resolve disputes, and enforce agreements.

  • Account information: Retained while your account is active and for a reasonable period afterward to handle inquiries.
  • Prescription and order data: Retained for seven (7) years to support warranty claims, regulatory requirements, and potential disputes.
  • Log and analytics data: Retained for up to twenty-four (24) months unless extended for security or auditing purposes.
  • Marketing preferences: Retained until you unsubscribe or request deletion.
  • Biometric data: Deleted within 3 years of collection or upon your request, whichever is sooner, unless required for an ongoing transaction.

8. Your Privacy Rights

Depending on your jurisdiction, you may have certain rights regarding your personal information. We do not discriminate against you for exercising these rights.

Rights that may be available to you

  • Right to know: Request information about what personal data we collect, use, and disclose.
  • Right to access: Obtain a copy of your personal information.
  • Right to correction: Request correction of inaccurate personal data.
  • Right to deletion: Request deletion of your personal information, subject to legal exceptions.
  • Right to portability: Receive your data in a structured, machine-readable format.
  • Right to opt out: Opt out of the sale or sharing of personal information (we do not sell your data).
  • Right to limit use of sensitive data: Restrict processing of sensitive personal information.
  • Right to non-discrimination: Exercise your rights without facing discriminatory treatment.

How to exercise your rights

  • Submit a request by emailing privacy@eyekiosk.online with sufficient details to identify you.
  • We will verify your identity (or the identity of your authorized agent) before fulfilling any request.
  • We will respond within the timeframe required by applicable law (typically 45 days) and explain any denial or limitation placed on your request.
  • You may designate an authorized agent to submit requests on your behalf with proper verification.

9. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

  • We do not sell personal information as defined by the CCPA.
  • We do not share personal information for cross-context behavioral advertising.
  • You may request disclosure of the categories and specific pieces of personal information we have collected about you.
  • You may request deletion of personal information we have collected from you.
  • You may request correction of inaccurate personal information.
  • We will not discriminate against you for exercising your CCPA rights.
  • California residents under 16 years of age may use our services only with parental consent.

10. Other State Privacy Rights

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive privacy laws may have similar rights to access, delete, correct, and port their data. Contact us to exercise these rights.

  • Nevada residents: We do not sell your personal information. If you have questions, contact us at privacy@eyekiosk.online.
  • We honor opt-out preference signals such as Global Privacy Control (GPC) where required by applicable law.
  • If we deny your privacy request, you may appeal by contacting us. We will respond to appeals within the timeframes required by your state's law.

11. International Data Transfers

We store information in the United States. When we transfer personal information outside of the country where it was collected, we implement safeguards such as Standard Contractual Clauses or other lawful transfer mechanisms.

Individuals located in the European Economic Area, United Kingdom, or Switzerland may contact us to request a copy of the transfer safeguards applicable to their data.

12. SMS Notifications & Consent

When you opt in to EyeKiosk SMS alerts—by checking the consent box on our web form, tapping "Agree & Subscribe" on a kiosk, or replying "YES" to an invite text—we store your phone number, consent timestamp, and preference so we can honor your choices.

  • SMS data is used only for transactional messages such as MFA codes, account notices, and order updates. Message frequency varies and standard message/data rates may apply.
  • Reply STOP to opt out or HELP for assistance at any time, or contact support to revoke consent. SMS consent is not required to complete a purchase, and you will continue to receive email updates even if you opt out of texts.
  • We do not share your phone number with third parties for their marketing purposes.

13. Children's Privacy

Eye Kiosk services are intended for use by individuals 13 years of age or older. Minors between 13 and 18 should use our services under the supervision of a parent, guardian, or licensed eye-care professional.

We do not knowingly collect personal information from children under 13 without verifiable parental consent. If you believe we have collected information from a child under 13 without consent, please contact us immediately so we can delete it.

California residents under 16 may not use our services without parental consent.

14. Third-Party Links and Services

Our services may contain links to third-party websites, applications, or services that are not operated by us. This Privacy Policy does not apply to those third-party services.

We encourage you to review the privacy policies of any third-party services before providing them with your information. We are not responsible for the privacy practices of third parties.

15. Security Practices

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.

While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

  • Encryption of data in transit (TLS 1.2+) and at rest using industry-standard algorithms.
  • Role-based access controls, multi-factor authentication, and least-privilege policies for employees and partners.
  • Secure kiosk hardware design, regular firmware validation, and tamper-resistant enclosures.
  • Continuous vulnerability monitoring, third-party penetration testing, and incident response playbooks.
  • Regular security training for all employees with access to personal data.
  • Data breach notification procedures in compliance with applicable laws.

16. Updates to This Policy

We may revise this Privacy Policy to reflect changes in our services, legal requirements, or privacy practices. We will post any changes on this page with an updated effective date.

For material changes that significantly affect how we use your personal information, we will provide more prominent notice (such as email notification or in-app alerts) before the new policy takes effect.

Your continued use of our services after the effective date constitutes acceptance of the updated Privacy Policy.

17. Contact Us

If you have questions about this Privacy Policy, want to exercise your privacy rights, or have concerns about how we handle your information, please contact us:

Email: privacy@eyekiosk.online

8 The Green Suite A Dover, DE 19901 United States