Privacy Policy

Legal — Evolve Escapes Where adventure begins and evolution awaits.

Privacy
Policy

Where adventure begins, privacy matters. We protect your data like we protect your journey.

Last Updated
27 August 2026
Effective Date
27 August 2026
Version
V3.0 — Final
TL;DR — The Essentials

We collect only what we need to run transformative retreats. Contact is via email.

We Don't Sell

Your data is never sold. We share only with processors who help deliver your retreat.

Your Control

Access, correct, delete, or export your data anytime via email.

No Spam

Marketing only with consent. Unsubscribe in one click, always.

Contents
01

Introduction

This Privacy Policy explains how Evolve Escapes (“Evolve Escapes”, “we”, “us”, “our”) collects, uses, and protects your personal data when you visit evolve-escapes.com, book a retreat, or interact with our services.

We are committed to handling your personal information transparently and in accordance with the UK General Data Protection Regulation (UK GDPR), the EU GDPR where applicable, and the Data Protection Act 2018.

By using our website or booking a retreat in Bali, Marbella, or Ibiza, you acknowledge you have read this policy. If you do not agree, please do not use our services.

02

Who We Are

For data protection purposes, Evolve Escapes is the data controller. We determine how and why your personal data is processed.

Evolve Escapes is a trading name of Danny Robinson — sole trader, operating in the United Kingdom. Contact: support@evolve-escapes.com

03

What We Collect

We collect personal data you provide, data we collect automatically, and data from third parties where you have consented.

Category Examples Source
Identity Name, DOB, gender, profile photo, passport details for travel Direct
Contact Email, phone, emergency contact, social handle Direct
Financial GoCardless bank account details, payment amounts/dates, Stripe last 4 where used, billing email (we never store full card) Direct / GoCardless / Stripe
Transaction Booking history, retreat preferences, add-ons, referral code Direct
Health & Fitness Injuries, allergies, dietary requirements, fitness level, goals (with explicit consent) Direct — health questionnaire
Technical IP address, browser, device ID, time zone, operating system Automatic
Usage Pages viewed, scroll, clicks, referral URL, session duration Automatic via analytics
Marketing Consent status, email open/click, ad interaction, survey responses Direct / Cookies
Swipe to see more →
04

Payments

Direct Debit — GoCardless

We collect payments via Direct Debit through GoCardless. Deposits are non-refundable. Remaining balance is collected in fixed installments on dates shown at checkout.

05

How We Collect It

Directly From You
When you enquire, book, fill health forms, subscribe, message us on Intercom, or post reviews.
Automatically
Via cookies and similar tech — _ga, _fbp, _clck, ee_consent — when you browse our site.
Third Parties
GoCardless and Stripe for payments, Shopify for merch, Klaviyo for email events, Meta/TikTok ads if you consented.
06

Why We Use It & Lawful Bases

Purpose Data Used Lawful Basis
To process & confirm your retreat booking Identity, Contact, Financial, Transaction Contract
To personalise fitness, meals, and safety Health, Identity, Contact Consent (explicit) + Vital Interests
Customer support & community Contact, Transaction, Technical, Intercom chats Contract + Legitimate Interest
To improve site & retreats Usage, Technical, Survey responses Legitimate Interest
Marketing — email, SMS, ads Contact, Marketing, Transaction, Usage Consent or Legitimate Interest*
Fraud, legal, accounting compliance Identity, Financial, Transaction, Technical Legal Obligation + Legitimate Interest

* For existing customers, we may rely on legitimate interest for similar retreats (soft opt-in). You can opt out anytime. For prospective customers, we rely on consent.

07

Marketing

We love to keep our community inspired. With your consent, we will send you emails about new retreat dates in Bali, Marbella, Ibiza, early-bird offers, training plans, and community stories.

We personalise content based on your retreat interests and engagement via Klaviyo.

  • Email: via Klaviyo — unsubscribe link in every email
  • SMS/WhatsApp: only if you explicitly opt in
  • Personalised ads: via Meta, Google, TikTok custom audiences — only with consent via ee_consent
Your Marketing Choices
Opt Out Email — Click unsubscribe or email support@evolve-escapes.com with subject 'UNSUBSCRIBE'
Opt Out Ads — Manage via ee_consent banner or your ad platform settings
Object to Legitimate Interest — Email us to object — we will stop unless compelling legitimate grounds override
08

Cookies

We use cookies and similar technologies to make our site work, remember preferences, measure performance, and — with your consent — for advertising. Manage anytime via our cookie banner (ee_consent).

Cookie Provider Purpose Duration Type
ee_consent Evolve Escapes Stores your cookie preferences 12 months Necessary
__evolvesession, _csrf Evolve Escapes / Vercel Security, load balancing, session Session – 24h Necessary
_ga, _ga_*, _gid Google Analytics Analytics — pageviews, events, conversions 13 months / 24h Analytics (consent)
_fbp, _fbc, fr Meta Pixel Ad measurement, custom audiences 3 months Marketing (consent)
_ttp, _tt_enable_cookie TikTok Ad performance & targeting 13 months Marketing (consent)
_clck, _clsk, CLID Microsoft Clarity Heatmaps, session replay for UX improvement 12 months Analytics (consent)
__kla_id, _kla Klaviyo On-site tracking for personalised emails 12 months Marketing (consent)
intercom-*, _audience Intercom Live chat & help center 9 months Functional
Swipe to see more →

You can block cookies in browser settings, but some features (checkout, login, chat) may break. Revisit preferences anytime via footer “Cookie Settings”.

09

Sharing & Processors

We do not sell your data. We share it only with trusted processors who help us run Evolve Escapes, under Data Processing Agreements.

Processor Service Data Shared Location
Vercel Hosting, edge, logs Technical, Usage USA / EU (DPA)
Supabase Database, auth, storage All categories (encrypted at rest) EU — Frankfurt
GoCardless Direct Debit collection for retreat payments Name, email, bank account details, payment amounts/dates UK / EEA — FCA regulated
Stripe Card payments & fraud checks (where used) Financial, Contact, Transaction USA (EU SCCs)
Shopify Merch store, checkout Identity, Contact, Transaction Canada / USA
Klaviyo Email & SMS marketing Contact, Marketing, Transaction, Usage USA (SCCs)
Google (Analytics, Ads) Analytics, YouTube embeds, advertising Technical, Usage, Marketing (consent) USA (SCCs)
Meta Facebook/Instagram ads, Pixel Technical, Usage, Marketing (consent) USA (SCCs)
TikTok Advertising & measurement Technical, Marketing (consent) USA / Singapore
Microsoft Clarity Session replay, heatmaps Usage, Technical (anonymized IP) USA (SCCs)
Intercom Helpdesk, live chat, onboarding Identity, Contact, Technical, Chat content USA / EU
Swipe to see more →
Retreat Partners (Controllers)
Hotels, trainers, nutritionists, and local transport partners in Bali, Marbella, and Ibiza receive only what is necessary (name, dietary, health notes with consent) to deliver your retreat. They act as independent controllers under their own policies.
Legal & Safety
We may disclose data if required by law, to protect safety, or in connection with a business transaction, under strict confidentiality.
10

International Transfers

Our processors are primarily in the EU and USA. Where data leaves the UK/EEA, we ensure an adequate level of protection via:

  • EU Commission adequacy decisions (where applicable)
  • Standard Contractual Clauses (SCCs) with supplementary measures
  • International Data Transfer Agreement (IDTA) for UK transfers

Contact us at support@evolve-escapes.com for a copy of safeguards.

11

Retention

Data Type Retention Reason
Booking & financial 7 years after retreat Tax & accounting law
Health questionnaire 2 years after retreat or until withdrawn Safety + limitation periods
Marketing consent & logs 3 years after last engagement / consent Proof of consent
Support tickets (Intercom) 3 years Service improvement
Analytics (anonymized) 26 months Product improvement
Cookies ee_consent 12 months Preference recall
12

Your Rights

Access
Request a copy of your personal data.
Rectification
Correct inaccurate or incomplete data.
Erasure
Ask us to delete your data where no longer needed.
Restriction
Ask us to pause processing in certain cases.
Portability
Receive your data in a structured, machine-readable format.
Objection
Object to processing based on legitimate interest or direct marketing.
Withdraw Consent
Withdraw consent at any time — does not affect prior lawful processing.
No Automated Harm
Not be subject to solely automated decisions with legal effects.

To exercise any right, email support@evolve-escapes.com with your name and request. We respond within one month (extendable by two months for complex requests). We may need to verify identity via booking email or ID.

13

Security

We use appropriate technical and organisational measures: encryption at rest (Supabase), TLS in transit, role-based access, 2FA, Vercel firewall, Stripe PCI-DSS Level 1 where used, GoCardless FCA-regulated Direct Debit, and regular access reviews.

No system is 100% secure. If you suspect a breach, email support@evolve-escapes.com immediately. We will notify you and the ICO where legally required.

14

Children

Our retreats are for persons 18+. We do not knowingly collect data from children under 18. If you believe a child has provided data, contact support@evolve-escapes.com and we will delete it promptly.

15

Automated Decisions

We may use automated personalisation (e.g., showing Bali vs Marbella retreats based on browsing) via Klaviyo and Meta. This does not produce legal or similarly significant effects. You can object via email or cookie preferences. No solely automated decision-making with legal effects is performed.

16

Third-Party Links

Our site may link to Instagram, TikTok, Spotify playlists, and hotel partners. Clicking those links means their privacy policies apply, not ours. We encourage you to read their policies.

17

Changes

We may update this policy to reflect new retreats, tech, or law. The “Last Updated” date at the top shows when it changed. For material changes, we will notify by email or banner. Continued use after changes means acceptance.

18

Contact Us

General & Privacy Enquiries
support@evolve-escapes.com

We aim to reply within 48 hours Monday–Friday. For fastest handling of data rights requests, include subject: “Data Request — [Your Right]”.

What To Include
  • Full name and booking email
  • Right you wish to exercise
  • Any context to help us locate data
19

Complaints

We hope to resolve any privacy concerns directly. Please email support@evolve-escapes.com first.

You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO):

Website
ico.org.uk
Helpline
0303 123 1113

Contact the ICO via their website or helpline for guidance on data protection concerns.

If you are in the EU, you may also contact your local supervisory authority.

20

Interpretation

“Personal data”, “processing”, “controller”, “processor”, “data subject” have meanings given in UK GDPR.

Headings are for convenience only. In case of conflict between this policy and our Terms, our Terms prevail for contractual matters, but this policy prevails for privacy.

Where adventure begins and evolution awaits — with privacy respected at every step.

UK GDPR Compliant