Privacy Policy
Private Wellness (“we,” “us”) respects your privacy. This Policy explains what information we collect, why we collect it, and how you can exercise your rights. We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's federal privacy law.
1. What we collect
Customer accounts: If you choose to create an account, we verify your email with a one-time code and use that verified address to display your associated reservation, booking and membership records. Account records are shared between privatewellness.co and privatewellness.co, but each domain requires its own sign-in. We store a hashed version of sign-in codes and session tokens, authentication timestamps and hashed rate-limit identifiers to help prevent abuse. Codes expire after 10 minutes; sign-in sessions expire after seven days or when revoked. These necessary account emails do not subscribe you to marketing. You may sign out on all devices from your dashboard or contact us about account deletion.
Bradford and Newmarket are proposed locations and standard session booking is not currently available. If a Studio opens and standard booking is activated, we may collect:
- Identifiers: your name, email, and phone number;
- Booking data: the slot you selected, your membership tier (if any), and your booking history;
- Waiver responses: your answers to contraindication questions, your typed signature, the IP address and browser you used to sign, and the time of signing;
- Payment data: handled directly by Stripe. We never see or store full card numbers. We would retain only the Stripe customer and payment identifiers needed for reconciliation.
When you use a founding-validation page, we may also collect:
- Founding reservation data: selected city, paid amount, reservation status, refund status, and the Stripe identifiers needed for reconciliation;
- Email-offer and opening-interest data: email, selected city, consent evidence, signup time, priority booking eligibility and the 50% first visit offer attached to your signup. We also record whether a confirmation email was accepted by our email provider, its message identifier, when you explicitly confirm your email, and any unsubscribe request. Provider acceptance does not prove inbox delivery. Historical paid offers may also retain optional phone numbers, discount codes and their redemption or refund status;
- Campaign attribution: permitted UTM values, campaign/ad identifiers, selected page hook, and an anonymous landing-session identifier. Advertising click identifiers are not persisted by the Newmarket founding page; and
- Optional survey answers: preferences about attendance, timing, expected frequency, pricing fit, and comments. We do not ask for medical information in this survey.
2. Why we collect it
We use your information to:
- administer any future service you separately book after a Studio opens, such as confirmations, access instructions, and follow-up emails;
- verify that future safety and contraindication policies are followed and maintain required records;
- process authorized payments, including the one-time refundable $49 Founding session deposit;
- measure paid demand for a proposed city, administer refundable founding reservations, manage the verified city cap, and conduct optional opening research;
- record your Newmarket priority booking and 50% first visit offer, send the booking invitation and opening updates you consented to receive, and administer historical discount codes and reservations;
- investigate security incidents and prevent abuse; and
- comply with our legal obligations.
3. Who we share it with
We share the minimum necessary information with trusted service providers:
- Stripe (Canada and United States) — one-time Founding Reservation payment processing and refund reconciliation; any future service would require separate authorization.
- Twilio (United States) — future SMS confirmations and access delivery if a Studio opens and this service is configured.
- Resend (United States) — transactional email delivery.
- Seam.so (United States) — future creation and revocation of time-bound door access if a Studio opens and this service is configured.
- Cloudflare (Canada and United States) — website hosting, DNS, and database.
- Google Analytics and Meta (United States) — optional campaign measurement only after the applicable consent choice and only when these services are configured.
Some of these providers store data in the United States. By using our service you consent to your information being transferred to and processed in those jurisdictions. U.S. law-enforcement authorities may be able to access information held in the United States.
We do not sell your personal information. Consent-gated campaign measurement may be used to understand ad and landing-page performance; it is not enabled for visitors who choose necessary-only processing.
4. How long we keep it
- Future waivers and booking history, if a Studio opens: seven (7) years, subject to applicable legal requirements.
- Payment records: retained by Stripe per its terms and by us for a minimum of six years, to satisfy CRA record-keeping rules.
- Email-offer and marketing consent records: retained while the offer or consent remains active, and as needed afterward to honour opt-outs and document consent. Marketing contact stops when you unsubscribe or withdraw consent.
- Founding reservation and refund records: retained for at least six years where required for payment and tax reconciliation.
- Optional founding survey responses: retained for the duration of location planning, then aggregated or deleted when no longer required.
- Aggregated, de-identified analytics: retained indefinitely.
5. Security
All traffic to our site is encrypted via HTTPS. Our database is hosted on Cloudflare D1 with access restricted to our application code. Secrets (API keys and webhook signing keys) are stored as encrypted Cloudflare Pages secrets and are not included in public source code. If future door access is introduced, access credentials will be time-bound and revoked after the applicable session window.
6. Your rights under PIPEDA
You have the right to:
- access the personal information we hold about you;
- correct information that is inaccurate or out of date;
- withdraw consent at any time, subject to legal or contractual restrictions;
- delete your account and associated personal information, except where we are required to retain it by law (e.g. tax and liability records); and
- complain to the Office of the Privacy Commissioner of Canada if you believe we have mishandled your data.
To exercise these rights or withdraw email consent, email [email protected]. Signup confirmation emails include an unsubscribe link that does not require a login. Confirming an email address does not create an account, charge your card or authorize a booking.
7. Children
Our service is not intended for anyone under 18. We do not knowingly collect personal information from minors.
8. Cookies and analytics
The Newmarket email signup page uses necessary browser storage for signup security and attribution limited to standard campaign parameters. Email and offer records are saved securely on our server, not only in your browser. Historical reservation pages may retain necessary checkout and receipt state. Optional Google Analytics and Meta advertising scripts are disabled on the signup campaign. Advertising click identifiers are not persisted by the signup page.
Verified payment and refund records remain in Stripe and our production database as required to provide the reservation, process refunds, prevent duplicate claims, maintain the 50-reservation cap, and meet legal or accounting obligations. No browser advertising Purchase event is sent for new reservations made under this necessary-only configuration.
9. Changes
If we materially change how we handle your data, we will update this page and, where possible, notify you by email.
10. Contact
Privacy inquiries: [email protected]
Instagram: @privatewellnes.ca