Privacy Policy

Last updated 27 August 2026 · Effective 27 August 2026 · Version 3.0

We don’t sell your data

We collect only what we need to run your retreat, and share it only with processors who help deliver it.

You stay in control

Access, correct, delete or export your data any time by email.

No spam

Marketing only with consent. Unsubscribe in one click, always.

01  Introduction

This Privacy Policy explains how Evolve Escapes (“Evolve Escapes”, “we”, “us”, “our”) collects, uses and protects your personal data when you visit evolve-escapes.com, book a retreat, or interact with our services.

We are committed to handling your personal information transparently and in accordance with the UK General Data Protection Regulation (UK GDPR), the EU GDPR where applicable, and the Data Protection Act 2018.

By using our website or booking a retreat in Bali, Marbella or Ibiza, you acknowledge you have read this policy. If you do not agree, please do not use our services.

02  Who We Are

For data protection purposes, Evolve Escapes is the data controller. We determine how and why your personal data is processed.

Evolve Escapes is a trading name of Danny Robinson, sole trader, operating in the United Kingdom. Contact: support@evolve-escapes.com.

03  What We Collect

We collect personal data you provide, data we collect automatically, and data from third parties where you have consented.

Categories of personal data collected
CategoryExamplesSource
IdentityName, DOB, gender, profile photo, passport details for travelDirect
ContactEmail, phone, emergency contact, social handleDirect
FinancialGoCardless bank account details, payment amounts and dates, Stripe last 4 where used, billing email. We never store full card detailsDirect / GoCardless / Stripe
TransactionBooking history, retreat preferences, add-ons, referral codeDirect
Health & FitnessInjuries, allergies, dietary requirements, fitness level, goals (with explicit consent)Direct, health questionnaire
TechnicalIP address, browser, device ID, time zone, operating systemAutomatic
UsagePages viewed, scroll, clicks, referral URL, session durationAutomatic, via analytics
MarketingConsent status, email open and click, ad interaction, survey responsesDirect / Cookies

04  Payments

Direct Debit: GoCardless

We collect payments via Direct Debit through GoCardless. Deposits are non-refundable. The remaining balance is collected in fixed instalments on the dates shown at checkout.

05  How We Collect It

Directly from you

When you enquire, book, fill health forms, subscribe, message us on Intercom, or post reviews.

Automatically

Via cookies and similar technology (_ga, _fbp, _clck, ee_consent) when you browse our site.

Third parties

GoCardless and Stripe for payments, Shopify for merch, Klaviyo for email events, and Meta or TikTok ads if you consented.

06  Why We Use It & Lawful Bases

Purposes and lawful bases for processing
PurposeData usedLawful basis
To process and confirm your retreat bookingIdentity, Contact, Financial, TransactionContract
To personalise fitness, meals and safetyHealth, Identity, ContactConsent (explicit) + Vital Interests
Customer support and communityContact, Transaction, Technical, Intercom chatsContract + Legitimate Interest
To improve the site and retreatsUsage, Technical, survey responsesLegitimate Interest
Marketing (email, SMS, ads)Contact, Marketing, Transaction, UsageConsent or Legitimate Interest*
Fraud, legal and accounting complianceIdentity, Financial, Transaction, TechnicalLegal Obligation + Legitimate Interest

* For existing customers, we may rely on legitimate interest for similar retreats (soft opt-in). You can opt out any time. For prospective customers, we rely on consent.

07  Marketing

We love to keep our community inspired. With your consent, we will send you emails about new retreat dates in Bali, Marbella and Ibiza, early-bird offers, training plans and community stories.

We personalise content based on your retreat interests and engagement, via Klaviyo.

  • Email: via Klaviyo, with an unsubscribe link in every email
  • SMS and WhatsApp: only if you explicitly opt in
  • Personalised ads: via Meta, Google and TikTok custom audiences, only with consent via ee_consent

Your marketing choices

  • Opt out of email: click unsubscribe, or email support@evolve-escapes.com with the subject “UNSUBSCRIBE”
  • Opt out of ads: manage via the ee_consent banner or your ad platform settings
  • Object to legitimate interest: email us to object. We will stop unless compelling legitimate grounds override

08  Cookies

We use cookies and similar technologies to make our site work, remember preferences, measure performance and, with your consent, for advertising. Manage them any time via our cookie banner (ee_consent).

Cookies used on this site
CookieProviderPurposeDurationType
ee_consentEvolve EscapesStores your cookie preferences12 monthsNecessary
__evolvesession, _csrfEvolve Escapes / VercelSecurity, load balancing, sessionSession, 24hNecessary
_ga, _ga_*, _gidGoogle AnalyticsAnalytics: pageviews, events, conversions13 months / 24hAnalytics (consent)
_fbp, _fbc, frMeta PixelAd measurement, custom audiences3 monthsMarketing (consent)
_ttp, _tt_enable_cookieTikTokAd performance and targeting13 monthsMarketing (consent)
_clck, _clsk, CLIDMicrosoft ClarityHeatmaps and session replay for UX improvement12 monthsAnalytics (consent)
__kla_id, _klaKlaviyoOn-site tracking for personalised emails12 monthsMarketing (consent)
intercom-*, _audienceIntercomLive chat and help centre9 monthsFunctional

You can block cookies in browser settings, but some features (checkout, login, chat) may break. Revisit preferences any time via the “Cookie Settings” link in the footer.

09  Sharing & Processors

We do not sell your data. We share it only with trusted processors who help us run Evolve Escapes, under Data Processing Agreements.

Data processors and what they receive
ProcessorServiceData sharedLocation
VercelHosting, edge, logsTechnical, UsageUSA / EU (DPA)
SupabaseDatabase, auth, storageAll categories, encrypted at restEU, Frankfurt
GoCardlessDirect Debit collection for retreat paymentsName, email, bank account details, payment amounts and datesUnited Kingdom / EEA, FCA regulated
StripeCard payments and fraud checks where usedFinancial, Contact, TransactionUSA / EU (SCCs)
ShopifyMerch store, checkoutIdentity, Contact, TransactionCanada / USA
KlaviyoEmail and SMS marketingContact, Marketing, Transaction, UsageUSA (SCCs)
Google (Analytics, Ads)Analytics, YouTube embeds, advertisingTechnical, Usage, Marketing (consent)USA (SCCs)
MetaFacebook and Instagram ads, PixelTechnical, Usage, Marketing (consent)USA (SCCs)
TikTokAdvertising and measurementTechnical, Marketing (consent)USA / Singapore
Microsoft ClaritySession replay, heatmapsUsage, Technical (anonymised IP)USA (SCCs)
IntercomHelpdesk, live chat, onboardingIdentity, Contact, Technical, chat contentUSA / EU

Retreat partners (controllers)

Hotels, trainers, nutritionists and local transport partners in Bali, Marbella and Ibiza receive only what is necessary (name, dietary and health notes, with consent) to deliver your retreat. They act as independent controllers under their own policies.

Legal and safety

We may disclose data if required by law, to protect safety, or in connection with a business transaction, under strict confidentiality.

10  International Transfers

Our processors are primarily in the EU and USA. Where data leaves the UK or EEA, we ensure an adequate level of protection via:

  • EU Commission adequacy decisions, where applicable
  • Standard Contractual Clauses (SCCs) with supplementary measures
  • The International Data Transfer Agreement (IDTA) for UK transfers

Contact us at support@evolve-escapes.com for a copy of safeguards.

11  Retention

Data retention periods
Data typeRetentionReason
Booking and financial7 years after the retreatTax and accounting law
Health questionnaire2 years after the retreat, or until withdrawnSafety and limitation periods
Marketing consent and logs3 years after last engagement or consentProof of consent
Support tickets (Intercom)3 yearsService improvement
Analytics (anonymised)26 monthsProduct improvement
Cookies (ee_consent)12 monthsPreference recall

12  Your Rights

  • Access: request a copy of your personal data.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: ask us to delete your data where it is no longer needed.
  • Restriction: ask us to pause processing in certain cases.
  • Portability: receive your data in a structured, machine-readable format.
  • Objection: object to processing based on legitimate interest or direct marketing.
  • Withdraw consent: withdraw consent at any time. This does not affect prior lawful processing.
  • No automated harm: not be subject to solely automated decisions with legal effects.

To exercise any right, email support@evolve-escapes.com with your name and request. We respond within one month, extendable by two months for complex requests. We may need to verify identity via your booking email or ID.

13  Security

We use appropriate technical and organisational measures: encryption at rest (Supabase), TLS in transit, role-based access, 2FA, Vercel firewall, Stripe PCI-DSS Level 1 where used, GoCardless FCA-regulated Direct Debit, and regular access reviews.

No system is 100% secure. If you suspect a breach, email support@evolve-escapes.com immediately. We will notify you and the ICO where legally required.

14  Children

Our retreats are for persons 18 and over. We do not knowingly collect data from children under 18. If you believe a child has provided data, contact support@evolve-escapes.com and we will delete it promptly.

15  Automated Decisions

We may use automated personalisation (for example showing Bali rather than Marbella retreats based on browsing) via Klaviyo and Meta. This does not produce legal or similarly significant effects. You can object via email or cookie preferences. No solely automated decision-making with legal effects is performed.

16  Third-Party Links

Our site may link to Instagram, TikTok, Spotify playlists and hotel partners. Clicking those links means their privacy policies apply, not ours. We encourage you to read their policies.

17  Changes

We may update this policy to reflect new retreats, technology or law. The “Last updated” date at the top shows when it changed. For material changes, we will notify you by email or banner. Continued use after changes means acceptance.

18  Contact Us

General and privacy enquiries: support@evolve-escapes.com

We aim to reply within 48 hours, Monday to Friday. For the fastest handling of data rights requests, use the subject line “Data Request” plus the right you wish to exercise.

What to include

  • Full name and booking email
  • The right you wish to exercise
  • Any context to help us locate your data

19  Complaints

We hope to resolve any privacy concerns directly. Please email support@evolve-escapes.com first.

You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner’s Office (ICO):

If you are in the EU, you may also contact your local supervisory authority.

20  Interpretation

“Personal data”, “processing”, “controller”, “processor” and “data subject” have the meanings given in UK GDPR.

Headings are for convenience only. In case of conflict between this policy and our Terms, our Terms prevail for contractual matters, but this policy prevails for privacy.