Privacy
Policy
Where adventure begins, privacy matters. We protect your data like we protect your journey.
We collect only what we need to run transformative retreats. Contact is via email.
Your data is never sold. We share only with processors who help deliver your retreat.
Access, correct, delete, or export your data anytime via email.
Marketing only with consent. Unsubscribe in one click, always.
Contents
Introduction
This Privacy Policy explains how Evolve Escapes (“Evolve Escapes”, “we”, “us”, “our”) collects, uses, and protects your personal data when you visit evolve-escapes.com, book a retreat, or interact with our services.
We are committed to handling your personal information transparently and in accordance with the UK General Data Protection Regulation (UK GDPR), the EU GDPR where applicable, and the Data Protection Act 2018.
By using our website or booking a retreat in Bali, Marbella, or Ibiza, you acknowledge you have read this policy. If you do not agree, please do not use our services.
Who We Are
For data protection purposes, Evolve Escapes is the data controller. We determine how and why your personal data is processed.
Evolve Escapes is a trading name of Danny Robinson — sole trader, operating in the United Kingdom. Contact: support@evolve-escapes.com
What We Collect
We collect personal data you provide, data we collect automatically, and data from third parties where you have consented.
| Category | Examples | Source |
|---|---|---|
| Identity | Name, DOB, gender, profile photo, passport details for travel | Direct |
| Contact | Email, phone, emergency contact, social handle | Direct |
| Financial | GoCardless bank account details, payment amounts/dates, Stripe last 4 where used, billing email (we never store full card) | Direct / GoCardless / Stripe |
| Transaction | Booking history, retreat preferences, add-ons, referral code | Direct |
| Health & Fitness | Injuries, allergies, dietary requirements, fitness level, goals (with explicit consent) | Direct — health questionnaire |
| Technical | IP address, browser, device ID, time zone, operating system | Automatic |
| Usage | Pages viewed, scroll, clicks, referral URL, session duration | Automatic via analytics |
| Marketing | Consent status, email open/click, ad interaction, survey responses | Direct / Cookies |
Payments
We collect payments via Direct Debit through GoCardless. Deposits are non-refundable. Remaining balance is collected in fixed installments on dates shown at checkout.
How We Collect It
Why We Use It & Lawful Bases
| Purpose | Data Used | Lawful Basis |
|---|---|---|
| To process & confirm your retreat booking | Identity, Contact, Financial, Transaction | Contract |
| To personalise fitness, meals, and safety | Health, Identity, Contact | Consent (explicit) + Vital Interests |
| Customer support & community | Contact, Transaction, Technical, Intercom chats | Contract + Legitimate Interest |
| To improve site & retreats | Usage, Technical, Survey responses | Legitimate Interest |
| Marketing — email, SMS, ads | Contact, Marketing, Transaction, Usage | Consent or Legitimate Interest* |
| Fraud, legal, accounting compliance | Identity, Financial, Transaction, Technical | Legal Obligation + Legitimate Interest |
* For existing customers, we may rely on legitimate interest for similar retreats (soft opt-in). You can opt out anytime. For prospective customers, we rely on consent.
Marketing
We love to keep our community inspired. With your consent, we will send you emails about new retreat dates in Bali, Marbella, Ibiza, early-bird offers, training plans, and community stories.
We personalise content based on your retreat interests and engagement via Klaviyo.
- Email: via Klaviyo — unsubscribe link in every email
- SMS/WhatsApp: only if you explicitly opt in
- Personalised ads: via Meta, Google, TikTok custom audiences — only with consent via ee_consent
Cookies
We use cookies and similar technologies to make our site work, remember preferences, measure performance, and — with your consent — for advertising. Manage anytime via our cookie banner (ee_consent).
| Cookie | Provider | Purpose | Duration | Type |
|---|---|---|---|---|
| ee_consent | Evolve Escapes | Stores your cookie preferences | 12 months | Necessary |
| __evolvesession, _csrf | Evolve Escapes / Vercel | Security, load balancing, session | Session – 24h | Necessary |
| _ga, _ga_*, _gid | Google Analytics | Analytics — pageviews, events, conversions | 13 months / 24h | Analytics (consent) |
| _fbp, _fbc, fr | Meta Pixel | Ad measurement, custom audiences | 3 months | Marketing (consent) |
| _ttp, _tt_enable_cookie | TikTok | Ad performance & targeting | 13 months | Marketing (consent) |
| _clck, _clsk, CLID | Microsoft Clarity | Heatmaps, session replay for UX improvement | 12 months | Analytics (consent) |
| __kla_id, _kla | Klaviyo | On-site tracking for personalised emails | 12 months | Marketing (consent) |
| intercom-*, _audience | Intercom | Live chat & help center | 9 months | Functional |
You can block cookies in browser settings, but some features (checkout, login, chat) may break. Revisit preferences anytime via footer “Cookie Settings”.
Sharing & Processors
We do not sell your data. We share it only with trusted processors who help us run Evolve Escapes, under Data Processing Agreements.
| Processor | Service | Data Shared | Location |
|---|---|---|---|
| Vercel | Hosting, edge, logs | Technical, Usage | USA / EU (DPA) |
| Supabase | Database, auth, storage | All categories (encrypted at rest) | EU — Frankfurt |
| GoCardless | Direct Debit collection for retreat payments | Name, email, bank account details, payment amounts/dates | UK / EEA — FCA regulated |
| Stripe | Card payments & fraud checks (where used) | Financial, Contact, Transaction | USA (EU SCCs) |
| Shopify | Merch store, checkout | Identity, Contact, Transaction | Canada / USA |
| Klaviyo | Email & SMS marketing | Contact, Marketing, Transaction, Usage | USA (SCCs) |
| Google (Analytics, Ads) | Analytics, YouTube embeds, advertising | Technical, Usage, Marketing (consent) | USA (SCCs) |
| Meta | Facebook/Instagram ads, Pixel | Technical, Usage, Marketing (consent) | USA (SCCs) |
| TikTok | Advertising & measurement | Technical, Marketing (consent) | USA / Singapore |
| Microsoft Clarity | Session replay, heatmaps | Usage, Technical (anonymized IP) | USA (SCCs) |
| Intercom | Helpdesk, live chat, onboarding | Identity, Contact, Technical, Chat content | USA / EU |
International Transfers
Our processors are primarily in the EU and USA. Where data leaves the UK/EEA, we ensure an adequate level of protection via:
- EU Commission adequacy decisions (where applicable)
- Standard Contractual Clauses (SCCs) with supplementary measures
- International Data Transfer Agreement (IDTA) for UK transfers
Contact us at support@evolve-escapes.com for a copy of safeguards.
Retention
| Data Type | Retention | Reason |
|---|---|---|
| Booking & financial | 7 years after retreat | Tax & accounting law |
| Health questionnaire | 2 years after retreat or until withdrawn | Safety + limitation periods |
| Marketing consent & logs | 3 years after last engagement / consent | Proof of consent |
| Support tickets (Intercom) | 3 years | Service improvement |
| Analytics (anonymized) | 26 months | Product improvement |
| Cookies ee_consent | 12 months | Preference recall |
Your Rights
To exercise any right, email support@evolve-escapes.com with your name and request. We respond within one month (extendable by two months for complex requests). We may need to verify identity via booking email or ID.
Security
We use appropriate technical and organisational measures: encryption at rest (Supabase), TLS in transit, role-based access, 2FA, Vercel firewall, Stripe PCI-DSS Level 1 where used, GoCardless FCA-regulated Direct Debit, and regular access reviews.
No system is 100% secure. If you suspect a breach, email support@evolve-escapes.com immediately. We will notify you and the ICO where legally required.
Children
Our retreats are for persons 18+. We do not knowingly collect data from children under 18. If you believe a child has provided data, contact support@evolve-escapes.com and we will delete it promptly.
Automated Decisions
We may use automated personalisation (e.g., showing Bali vs Marbella retreats based on browsing) via Klaviyo and Meta. This does not produce legal or similarly significant effects. You can object via email or cookie preferences. No solely automated decision-making with legal effects is performed.
Third-Party Links
Our site may link to Instagram, TikTok, Spotify playlists, and hotel partners. Clicking those links means their privacy policies apply, not ours. We encourage you to read their policies.
Changes
We may update this policy to reflect new retreats, tech, or law. The “Last Updated” date at the top shows when it changed. For material changes, we will notify by email or banner. Continued use after changes means acceptance.
Contact Us
We aim to reply within 48 hours Monday–Friday. For fastest handling of data rights requests, include subject: “Data Request — [Your Right]”.
- Full name and booking email
- Right you wish to exercise
- Any context to help us locate data
Complaints
We hope to resolve any privacy concerns directly. Please email support@evolve-escapes.com first.
You also have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO):
Contact the ICO via their website or helpline for guidance on data protection concerns.
If you are in the EU, you may also contact your local supervisory authority.
Interpretation
“Personal data”, “processing”, “controller”, “processor”, “data subject” have meanings given in UK GDPR.
Headings are for convenience only. In case of conflict between this policy and our Terms, our Terms prevail for contractual matters, but this policy prevails for privacy.
Where adventure begins and evolution awaits — with privacy respected at every step.