This Privacy Policy explains how Breathe With Sandy LLC ("Breathe With Sandy," "we," "us," or "our") collects, uses, shares, retains, and protects personal information when you use our websites, mobile applications, member dashboard, subscriptions, media library, community features, live event pages, email lists, and related services (collectively, the "Services").
By using the Services, you acknowledge this Privacy Policy. If you do not agree, do not use the Services.
1. Personal Information We Collect
Information you provide
- Account information: name, email address, login credentials, authentication identifiers, profile photo, preferences, settings, plan selection, and account status.
- Billing information: purchase status, subscription plan, trial status, renewal status, cancellation status, receipts, transaction identifiers, Stripe customer or subscription identifiers, RevenueCat identifiers, and app store purchase metadata. We do not store full payment card numbers.
- Community and profile content: posts, replies, messages, display name, avatar, reactions, reports, moderation records, and other content you submit to community features.
- Practice and app data: playlists, favorites, watch or listen history, scheduled practices, reminder preferences, downloads metadata, notes or reflections you choose to save, content filters, and app settings.
- Communications: support requests, feedback, survey responses, event inquiries, waitlist forms, newsletter signups, and email preferences.
- Event information: event registrations, ticketing or waitlist details, venue-related communications, and attendance-related support messages.
Information collected automatically
- Usage information: pages viewed, sessions played, features used, playback events, search and filter activity, clicks, referring pages, and approximate session duration.
- Device and technical information: IP address, browser type, operating system, device type, app version, language, time zone, crash logs, diagnostics, and unique device or installation identifiers.
- Approximate location: general location inferred from IP address, such as country or region. We do not request precise GPS location for the core Services.
- Cookies and similar technologies: cookies, local storage, pixels, SDKs, and similar tools used for sign-in, preferences, security, analytics, embedded media, email forms, and service operation.
Sensitive information
The Services are for wellness and breathwork, but they are not designed to collect medical records or detailed health information. You may choose to submit notes, community messages, support requests, or preferences that reveal information about your wellness, emotions, or health. Please do not submit medical records or sensitive information that you do not want processed by the Services.
2. How We Use Personal Information
We use personal information to:
- Provide, operate, personalize, and secure the Services.
- Create and manage accounts, authentication, profiles, subscriptions, entitlements, and customer support.
- Deliver breathwork, music, video, audio, downloads, playlists, reminders, community features, and event-related features.
- Process payments, verify purchases, manage trials, reconcile subscriptions, prevent billing abuse, and handle refunds or disputes.
- Send transactional messages, account notices, service updates, support replies, security alerts, push notifications, and marketing communications where permitted.
- Analyze usage, troubleshoot bugs, measure reliability, improve content, build new features, and understand which parts of the Services are useful.
- Moderate community content, enforce our Terms, protect users, prevent fraud, and maintain service integrity.
- Comply with law, tax, accounting, app store, payment processor, security, and legal obligations.
3. Legal Bases for EEA and UK Users
If you are in the European Economic Area or United Kingdom, we process personal information under the following legal bases:
- Contract: to provide the Services you request, including accounts, subscriptions, purchases, content access, downloads, and support.
- Consent: for optional marketing emails, certain cookies or similar technologies where required, and push notifications where required by platform rules.
- Legitimate interests: to secure, improve, troubleshoot, analyze, and protect the Services and our community, provided those interests are not overridden by your rights.
- Legal obligations: to comply with tax, accounting, consumer protection, law enforcement, and regulatory requirements.
4. How We Share Personal Information
We do not sell your personal information. We share personal information only as described in this policy or with your direction.
Service providers and processors
We may share information with vendors that help us operate the Services, including:
- Hosting, storage, and delivery: providers such as Cloudflare, Cloudflare Pages, Cloudflare R2, Google Cloud, Firebase, and related infrastructure providers.
- Authentication and messaging: providers such as Firebase Authentication, Firebase Cloud Messaging, Apple, Google, and email delivery providers.
- Payments and subscriptions: providers such as Stripe, RevenueCat, Apple App Store, and Google Play.
- Email and marketing forms: providers such as MailerLite and email delivery tools used for waitlists, newsletters, and service messages.
- Analytics, diagnostics, and support: tools used to understand usage, diagnose errors, prevent abuse, and respond to support requests.
Other sharing
- Community features: information you post in community areas may be visible to other users according to the feature design.
- Legal and safety: we may disclose information if required by law, legal process, or a valid government request, or if we believe disclosure is necessary to protect rights, safety, users, or the Services.
- Business transfers: information may be transferred as part of a merger, acquisition, financing, reorganization, or sale of assets.
- With your direction: we may share information when you ask us to, connect a third-party service, or intentionally interact with external links such as YouTube, Spotify, Instagram, ticketing providers, or app stores.
5. Cookies, Local Storage, and Analytics
We use cookies, local storage, SDKs, and similar technologies to keep you signed in, remember preferences, protect against abuse, support embedded forms and media, measure usage, and improve the Services. You can control cookies through your browser settings, but disabling some technologies may cause parts of the Services to stop working.
The Services may also use local browser or device storage for app functionality such as offline downloads, playback state, preferences, and cached media metadata.
6. Communications and Push Notifications
We may send service-related emails or in-app messages about your account, purchases, security, support, subscriptions, events, and important changes. You cannot opt out of essential service messages.
We send marketing emails only where permitted and you can unsubscribe using the link in those emails. Push notifications, where available, are controlled by your device, browser, and in-app preferences.
7. Data Retention
We retain personal information for as long as reasonably necessary for the purposes described in this policy, including to provide the Services, maintain accounts, comply with law, resolve disputes, enforce agreements, prevent fraud, and maintain security.
- Account data: retained while your account is active and for a reasonable period after deletion where needed for backups, legal compliance, security, or dispute resolution.
- Billing records: retained as needed for tax, accounting, audit, chargeback, processor, and legal obligations.
- Community and support records: retained as needed to operate the community, investigate reports, enforce rules, and provide support.
- Analytics and diagnostics: may be retained in aggregated or de-identified form for service improvement.
- Offline downloads: media cached on your device remains under your control and can usually be removed through app settings, browser storage settings, or device storage controls.
8. Your Privacy Rights and Choices
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal information. You may also have the right to withdraw consent where processing is based on consent.
You can update some information in your account settings. To make a privacy request, contact [email protected]. We may need to verify your identity before fulfilling a request.
United States state privacy rights
If you live in a U.S. state with a consumer privacy law, you may have additional rights, including the right to know or access categories of personal information, request deletion or correction, receive a portable copy, opt out of certain targeted advertising or sale/share of personal information if applicable, and appeal a denied request.
We do not sell personal information. If our practices change in a way that requires an opt-out, we will update this policy and provide the required mechanism.
EEA, UK, and Swiss rights
If you are in the EEA, UK, or Switzerland, you may have the right to lodge a complaint with your local data protection authority. We encourage you to contact us first so we can try to resolve your concern.
9. International Transfers
We are based in the United States and use service providers that may process information in the United States and other countries. These countries may have data protection laws different from those where you live. Where required, we use appropriate safeguards for international transfers, such as contractual protections.
10. Security
We use reasonable technical, organizational, and administrative measures designed to protect personal information, including encryption in transit, access controls, authentication safeguards, provider security controls, and monitoring for reliability and abuse.
No system is completely secure. You are responsible for using a strong password, keeping your credentials private, and maintaining the security of your devices.
11. Children's Privacy
The Services are not intended for children under 18, and we do not knowingly collect personal information from children under 18. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
12. Third-Party Links and Platforms
The Services may link to third-party websites, platforms, app stores, social networks, payment pages, ticketing pages, YouTube, Spotify, Instagram, and other external services. Their privacy practices are governed by their own policies, not this Privacy Policy.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date and, where required, provide additional notice. Your continued use of the Services after an updated policy takes effect means you acknowledge the updated policy.
14. Contact
Questions or privacy requests can be sent to:
Breathe With Sandy LLC
Email: [email protected]
Website: https://breathewithsandy.com