PRIVACY POLICY
Last updated September 7, 2026 · Effective September 7, 2026.
This policy explains what Soulfull Gatherings LLC, a Texas limited liability company ("Soulfull Gatherings", "we", "us") collects when you use the Soulfull Gatherings iOS app, visit soulfullgatherings.com, or enquire about and attend one of our retreats — and what we do with it.
It is written to be read, not to be survived. If anything here is unclear, write to us at info@soulfullgatherings.com and we will explain it in plain words.
I. WHAT WE COLLECT
What you give us:
Your first name, at onboarding or account creation, so we can greet you by name and know who is coming on a retreat.
Your email address, at account creation, sign-in, or when you enquire, so we can identify your account, confirm your address, and reply to you.
Your password, at account creation. It is stored only as a salted hash by our authentication provider. We never see or store your actual password.
Your intentions, how your body feels, and how often you practise, through four short onboarding questions, to shape what the app suggests to you. These answers are self-described preferences: what you are hoping for, and how you would describe your energy. They are not medical or fitness measurements, and we do not treat them as health data. We do not read data from Apple Health, and the app never asks for it.
Retreat enquiries and messages, when you email or message us, so we can answer you and arrange your place.
Health and dietary information you choose to share before a retreat, only if you tell us, to keep you safe and fed. See section III.
What is created automatically:
A guest identifier. The app opens an anonymous session the first time you launch it, so that retreat listings and images load before you have an account. This creates a random identifier for your device's session. It contains no name, no email, and nothing that identifies you personally. If you later create an account with an email and password, that same identifier becomes your account.
Booking records: which retreat, the amount, the currency, whether payment succeeded, and a reference to the payment held by our payment processor.
Ordinary technical records kept by the services that host the app's data and our website: IP address, approximate region, device and browser type, timestamps, and error logs. We use these to keep things running and secure, not to build a profile of you.
Payment information:
When retreat payments are taken in the app, card details go directly to Stripe and are entered inside Stripe's own payment sheet. We never receive, see, or store your full card number. What reaches us is a payment reference, the last four digits, the amount, and whether the charge succeeded.
In the current version of the app, in-app reservations are switched off. Retreat places are arranged by email or message. The payment path described here applies once in-app reservations are turned on.
What we do not collect:
No advertising identifier (IDFA), and no App Tracking Transparency prompt, because there is nothing to track you with. No third-party analytics or advertising SDK inside the app. No location data; the app never asks for your location. No contacts, no photo library, no microphone. No camera access: the app declares a camera purpose string because our payment library contains a card-scanning feature, but that feature is unreachable and the app will never open your camera. No data from Apple Health or any fitness source.
II. WHAT STAYS ON YOUR PHONE
Some of the most personal things in the app are never uploaded to us at all. They are stored only in the app's own storage on your device, and they are removed when you delete the app:
Your journal reflections. Everything you write against a journal prompt stays on your phone. We cannot read it, and it is not backed up to our servers.
Your retreat to-do list and packing list, including which items you have ticked off.
Your 1:1 session choices made in the retreat experience.
Your onboarding answers, which are held on the device and are only copied to our servers if and when you create an account.
Because these live on the device, they do not move with you to a new phone, and we cannot recover them for you.
III. HEALTH INFORMATION BEFORE A RETREAT
Before a retreat we may ask about injuries, medical conditions, allergies, dietary requirements, and emergency contacts. You do not have to tell us anything. If you withhold something that affects your safety, however, we may not be able to take you.
This information is used only to run your retreat safely. We share it with the specific guides, practitioners, venue, or caterer who need it for your retreat, and with emergency services if there is a medical emergency. We do not use it for anything else, and we delete it within 12 months of the retreat ending.
IV. HOW WE USE WHAT WE COLLECT
We use your information to run the app: to sign you in, keep you signed in, remember your preferences, and show you the right content. To provide the practices, recipes, prompts, and retreat information you asked for. To arrange, confirm, and run your retreat, including logistics and safety. To take payment and keep the financial and tax records the law requires us to keep. To reply to you when you contact us.
We also use it to send you service messages: email confirmation, booking confirmations, and changes to a retreat. These are not marketing, and you cannot opt out of them while you have an account or a booking. We send occasional news about upcoming retreats only if you asked for it, and every one of those emails has an unsubscribe link.
Finally, we use it to keep the service secure, prevent abuse and fraud, fix things that break, and comply with the law.
We do not use your information to build advertising profiles. We do not sell it, and we do not share it for cross-context behavioural advertising.
V. WHO WE SHARE IT WITH
We share personal information only with the service providers below, only to the extent they need it to do their job for us, and only under contracts that require them to protect it.
Supabase provides our database, account authentication, and hosting for practice audio and video. It receives your account identifier, email, name, onboarding answers, booking records, and technical logs.
Stripe processes payments. It receives your card details (directly from you), your email, your name, and the amount charged.
Apple distributes the app, and provides Sign in with Apple if you use it. It receives whatever Apple's own processes collect. If you sign in with Apple, you choose whether to share your real email or a private relay address. Either works, and we never see more than you chose to give.
Retreat partners are the venues, guides, practitioners, and caterers for a specific retreat. They receive your name and only the details that retreat requires, such as a dietary requirement or a relevant injury.
Each of these providers has its own privacy policy governing what it does with data as its own controller.
We also disclose information where the law requires it, to protect our rights or someone's safety, and, if we are ever acquired or merged, to the acquiring party, who would remain bound by this policy until it gives you notice of a change.
VI. THE WEBSITE
Our website is hosted on Squarespace, which sets the cookies it needs to serve pages, keep the site secure, and, where enabled, measure aggregate visits. Your browser sends Squarespace your IP address, browser type, and the pages you view, in the ordinary course of loading the site.
If you join a mailing list or waitlist on the site, we keep the email address you gave us until you unsubscribe.
The app itself sets no cookies and contains no web tracking. You can control cookies through your browser settings; blocking them may break parts of the site.
VII. HOW LONG WE KEEP IT
Account and profile: until you delete your account.
Guest session: until you delete the app, or the session expires.
Booking and payment records: 7 years after the transaction, because tax and accounting law requires it.
Pre-retreat health and dietary information: 12 months after the retreat.
Emails and messages you send us: 3 years.
Mailing list: until you unsubscribe.
Technical and security logs: as kept by our providers, typically weeks to months.
VIII. YOUR CHOICES
Deleting your account, from inside the app. Open the You tab and choose Delete account. This is immediate and permanent. It deletes your sign-in record, your profile, and your bookings, and it deletes your customer record with our payment processor along with any saved payment method. Completed charges remain in our accounting records, as the law requires. Anything held only on your phone, such as your journal and your checklists, goes when you delete the app.
See what we hold. Ask us and we will send you a copy.
Correct it. Your name and email are editable in the app; write to us for anything else.
Stop marketing email. Use the unsubscribe link, or ask us.
Ask a question or complain. Write to info@soulfullgatherings.com.
We answer requests within 45 days, and we will tell you if we need longer. We will never charge you for making a request or treat you differently for having made one.
IX. IF YOU LIVE IN CALIFORNIA
Under the California Consumer Privacy Act, as amended, you have the rights to know, delete, correct, and to opt out of sale or sharing. In the twelve months before this policy's date we collected these categories of personal information, all of it for the business purposes in section IV, from the sources and to the recipients described in sections I and V: identifiers (name, email address, account identifier, IP address); customer records (name and email tied to a booking); commercial information (retreats booked, amounts paid); internet activity (ordinary server and error logs); and other information you provide (your onboarding answers, and any health or dietary details you give us before a retreat).
We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the preceding twelve months. That includes the personal information of anyone under 16. Because we do not sell or share, we do not offer a "Do Not Sell or Share My Personal Information" link; there is nothing for it to do. We do not use or disclose sensitive personal information for any purpose beyond those permitted without a right to limit.
You may make a request yourself or through an authorised agent, at info@soulfullgatherings.com. We verify requests by matching the email address on the account.
X. IF YOU LIVE IN ANOTHER US STATE
Residents of states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as those laws take effect, have broadly the same rights to access, correct, delete, and obtain a copy of their personal information, and to opt out of targeted advertising, sale, and profiling with legal effects. We do none of those three things. Use the same address in section VIII. If we deny a request, you may appeal by replying to our decision, and you may contact your state Attorney General.
XI. IF YOU ARE IN THE UK OR THE EUROPEAN ECONOMIC AREA
We are based in the United States, so if you use the app or attend a retreat from the UK or the EEA your information is transferred to and processed in the US and in other countries where our providers operate. Where required, those transfers rely on the European Commission's Standard Contractual Clauses or the UK Addendum.
Where the UK GDPR or GDPR applies, our legal bases are: performance of a contract (running your account and your retreat), legitimate interests (keeping the service secure and working, and answering you), consent (marketing email, and any health information you volunteer), and legal obligation (tax and accounting records). You may withdraw consent at any time; doing so does not affect what came before.
You also have the rights to object, to restrict processing, to portability, and to lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office.
XII. SECURITY
Traffic between the app and our servers is encrypted in transit. Data is encrypted at rest by our hosting provider. Access to production data is restricted to the people who need it. Every user's records are isolated at the database level, so one account cannot read another's. Passwords are stored only as hashes.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant authorities as the law requires.
XIII. CHILDREN
The app and website are not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has given us information, write to info@soulfullgatherings.com and we will delete it. You must be at least 18 to book a retreat.
XIV. CHANGES
If we change this policy, we will update the date at the top. If the change is significant, such as a new category of data, a new recipient, or a new purpose, we will tell you in the app or by email before it takes effect. The current version always lives at this address.
XV. CONTACT
Write to us and a person will answer.
Soulfull Gatherings LLC
3001 Esperanza Crossing
78758 Austin, Texas
United States