Privacy Policy
Last updated 27 August 2026 · Effective 27 August 2026 · Version 3.0
We don’t sell your data
We collect only what we need to run your retreat, and share it only with processors who help deliver it.
You stay in control
Access, correct, delete or export your data any time by email.
No spam
Marketing only with consent. Unsubscribe in one click, always.
Contents
- 01 Introduction
- 02 Who We Are
- 03 What We Collect
- 04 Payments
- 05 How We Collect It
- 06 Why We Use It
- 07 Marketing
- 08 Cookies
- 09 Sharing & Processors
- 10 International Transfers
- 11 Retention
- 12 Your Rights
- 13 Security
- 14 Children
- 15 Automated Decisions
- 16 Third-Party Links
- 17 Changes
- 18 Contact Us
- 19 Complaints
- 20 Interpretation
01 Introduction
This Privacy Policy explains how Evolve Escapes (“Evolve Escapes”, “we”, “us”, “our”) collects, uses and protects your personal data when you visit evolve-escapes.com, book a retreat, or interact with our services.
We are committed to handling your personal information transparently and in accordance with the UK General Data Protection Regulation (UK GDPR), the EU GDPR where applicable, and the Data Protection Act 2018.
By using our website or booking a retreat in Bali, Marbella or Ibiza, you acknowledge you have read this policy. If you do not agree, please do not use our services.
02 Who We Are
For data protection purposes, Evolve Escapes is the data controller. We determine how and why your personal data is processed.
Evolve Escapes is a trading name of Danny Robinson, sole trader, operating in the United Kingdom. Contact: support@evolve-escapes.com.
03 What We Collect
We collect personal data you provide, data we collect automatically, and data from third parties where you have consented.
| Category | Examples | Source |
|---|---|---|
| Identity | Name, DOB, gender, profile photo, passport details for travel | Direct |
| Contact | Email, phone, emergency contact, social handle | Direct |
| Financial | GoCardless bank account details, payment amounts and dates, Stripe last 4 where used, billing email. We never store full card details | Direct / GoCardless / Stripe |
| Transaction | Booking history, retreat preferences, add-ons, referral code | Direct |
| Health & Fitness | Injuries, allergies, dietary requirements, fitness level, goals (with explicit consent) | Direct, health questionnaire |
| Technical | IP address, browser, device ID, time zone, operating system | Automatic |
| Usage | Pages viewed, scroll, clicks, referral URL, session duration | Automatic, via analytics |
| Marketing | Consent status, email open and click, ad interaction, survey responses | Direct / Cookies |
04 Payments
Direct Debit: GoCardless
We collect payments via Direct Debit through GoCardless. Deposits are non-refundable. The remaining balance is collected in fixed instalments on the dates shown at checkout.
05 How We Collect It
Directly from you
When you enquire, book, fill health forms, subscribe, message us on Intercom, or post reviews.
Automatically
Via cookies and similar technology (_ga, _fbp, _clck, ee_consent) when you browse our site.
Third parties
GoCardless and Stripe for payments, Shopify for merch, Klaviyo for email events, and Meta or TikTok ads if you consented.
06 Why We Use It & Lawful Bases
| Purpose | Data used | Lawful basis |
|---|---|---|
| To process and confirm your retreat booking | Identity, Contact, Financial, Transaction | Contract |
| To personalise fitness, meals and safety | Health, Identity, Contact | Consent (explicit) + Vital Interests |
| Customer support and community | Contact, Transaction, Technical, Intercom chats | Contract + Legitimate Interest |
| To improve the site and retreats | Usage, Technical, survey responses | Legitimate Interest |
| Marketing (email, SMS, ads) | Contact, Marketing, Transaction, Usage | Consent or Legitimate Interest* |
| Fraud, legal and accounting compliance | Identity, Financial, Transaction, Technical | Legal Obligation + Legitimate Interest |
* For existing customers, we may rely on legitimate interest for similar retreats (soft opt-in). You can opt out any time. For prospective customers, we rely on consent.
07 Marketing
We love to keep our community inspired. With your consent, we will send you emails about new retreat dates in Bali, Marbella and Ibiza, early-bird offers, training plans and community stories.
We personalise content based on your retreat interests and engagement, via Klaviyo.
- Email: via Klaviyo, with an unsubscribe link in every email
- SMS and WhatsApp: only if you explicitly opt in
- Personalised ads: via Meta, Google and TikTok custom audiences, only with consent via ee_consent
Your marketing choices
- Opt out of email: click unsubscribe, or email support@evolve-escapes.com with the subject “UNSUBSCRIBE”
- Opt out of ads: manage via the ee_consent banner or your ad platform settings
- Object to legitimate interest: email us to object. We will stop unless compelling legitimate grounds override
10 International Transfers
Our processors are primarily in the EU and USA. Where data leaves the UK or EEA, we ensure an adequate level of protection via:
- EU Commission adequacy decisions, where applicable
- Standard Contractual Clauses (SCCs) with supplementary measures
- The International Data Transfer Agreement (IDTA) for UK transfers
Contact us at support@evolve-escapes.com for a copy of safeguards.
11 Retention
| Data type | Retention | Reason |
|---|---|---|
| Booking and financial | 7 years after the retreat | Tax and accounting law |
| Health questionnaire | 2 years after the retreat, or until withdrawn | Safety and limitation periods |
| Marketing consent and logs | 3 years after last engagement or consent | Proof of consent |
| Support tickets (Intercom) | 3 years | Service improvement |
| Analytics (anonymised) | 26 months | Product improvement |
| Cookies (ee_consent) | 12 months | Preference recall |
12 Your Rights
- Access: request a copy of your personal data.
- Rectification: correct inaccurate or incomplete data.
- Erasure: ask us to delete your data where it is no longer needed.
- Restriction: ask us to pause processing in certain cases.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interest or direct marketing.
- Withdraw consent: withdraw consent at any time. This does not affect prior lawful processing.
- No automated harm: not be subject to solely automated decisions with legal effects.
To exercise any right, email support@evolve-escapes.com with your name and request. We respond within one month, extendable by two months for complex requests. We may need to verify identity via your booking email or ID.
13 Security
We use appropriate technical and organisational measures: encryption at rest (Supabase), TLS in transit, role-based access, 2FA, Vercel firewall, Stripe PCI-DSS Level 1 where used, GoCardless FCA-regulated Direct Debit, and regular access reviews.
No system is 100% secure. If you suspect a breach, email support@evolve-escapes.com immediately. We will notify you and the ICO where legally required.
14 Children
Our retreats are for persons 18 and over. We do not knowingly collect data from children under 18. If you believe a child has provided data, contact support@evolve-escapes.com and we will delete it promptly.
15 Automated Decisions
We may use automated personalisation (for example showing Bali rather than Marbella retreats based on browsing) via Klaviyo and Meta. This does not produce legal or similarly significant effects. You can object via email or cookie preferences. No solely automated decision-making with legal effects is performed.
16 Third-Party Links
Our site may link to Instagram, TikTok, Spotify playlists and hotel partners. Clicking those links means their privacy policies apply, not ours. We encourage you to read their policies.
17 Changes
We may update this policy to reflect new retreats, technology or law. The “Last updated” date at the top shows when it changed. For material changes, we will notify you by email or banner. Continued use after changes means acceptance.
18 Contact Us
General and privacy enquiries: support@evolve-escapes.com
We aim to reply within 48 hours, Monday to Friday. For the fastest handling of data rights requests, use the subject line “Data Request” plus the right you wish to exercise.
What to include
- Full name and booking email
- The right you wish to exercise
- Any context to help us locate your data
19 Complaints
We hope to resolve any privacy concerns directly. Please email support@evolve-escapes.com first.
You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner’s Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
If you are in the EU, you may also contact your local supervisory authority.
20 Interpretation
“Personal data”, “processing”, “controller”, “processor” and “data subject” have the meanings given in UK GDPR.
Headings are for convenience only. In case of conflict between this policy and our Terms, our Terms prevail for contractual matters, but this policy prevails for privacy.