OGGYoga · Movement · Meditation

Draft for owner review · 5 August 2026

Privacy notice

OGG Yoga, Movement & Meditation uses personal information only where it is needed to answer enquiries, manage bookings, provide sessions safely, take payment and meet legal obligations.

Information we collect

For bookings we collect your name, email address and telephone number. For private sessions we also ask for relevant experience, goals, injuries or movement limitations and an optional emergency contact. We do not ask for a detailed medical history and do not store card details.

Why and how we use it

Booking and contact details are used to fulfil our agreement with you. Safety information is used to plan an appropriate session. Financial records may be kept where legally required. Marketing and photography information is used only with separate, optional consent, which you may withdraw.

Service providers and international processing

Supabase hosts booking and administrator-authentication data in the approved London, UK region. Stripe processes card payments. Vercel will host the website when launch is approved.

Cloudflare Email Routing receives messages sent to the public OGG address and forwards their sender details, message content and attachments to the owner’s verified existing mailbox. Cloudflare therefore processes information contained in customer emails for routing and security purposes.

Resend processes names, email addresses, message content and delivery information to send transactional confirmations, cancellations, private-session approvals and waiting-list invitations. OGG selects Resend’s Ireland region (eu-west-1) so messages are dispatched from Ireland. This does not provide EU-only data storage: Resend states that account information, email metadata, logs and API records are stored in the United States. This therefore involves international processing. Resend’s Data Processing Addendum includes contractual safeguards for transfers covered by UK and EU data-protection law. OGG will avoid including unnecessary private-session safety information in email messages.

Retention and security

Booking and payment records will normally be retained for up to seven years where needed for tax or legal records. Private-session safety notes will be reviewed and deleted when no longer needed. Resend processes customer data while the service agreement is active and states that customer data is deleted within 90 days after account termination, subject to applicable legal requirements. Access is restricted to authorised administrators, protected with authentication and database access controls.

Your rights

You may ask for access, correction, deletion, restriction or a portable copy of your information, or object to its use. Some records may need to be retained by law. Email bookings@oggyoga.co.uk. You may also complain to the UK Information Commissioner’s Office.

Return to the website