Privacy Policy
Effective date: September 1, 2026
This Privacy Policy describes how the business operating this site collects and uses personal information through this website and related services.
Data we collect
We collect: (1) Account data — email, name, profile image; (2) Client and health-related information — contact details, date of birth, emergency contact, medical conditions, injuries, and other information you provide in intake and release forms (typically on a studio storefront); (3) Payment data — processed by Stripe for customer purchases and, for studio owners, Polar and/or Stripe for platform subscriptions (we do not store card numbers); (4) Bookings and usage — sessions, credits, cancellations; (5) Usage and analytics — when you consent, we use analytics (e.g. page views) to improve the service; (6) Error and reliability diagnostics — limited technical details when the site fails (see Error diagnostics).
Legal basis
We process data on the basis of: contract (account, bookings, payments, platform subscriptions); consent (analytics, marketing emails where applicable); and legitimate interest (security, fraud prevention, service reliability). Health-related data is processed with your explicit consent as part of intake and release forms.
Sale and sharing of personal information
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use third-party advertising, remarketing, or similar ad tags on this service. California residents may review or update related choices on our Cookie Policy page (Manage cookie preferences), which covers analytics consent.
Third parties and processors
We use the following processors under contract to operate the service: Convex (database), Netlify (hosting), Cloudflare R2 (public asset storage), WorkOS (authentication, including optional Sign in with Google), Google (Wallet pass issuance, Fonts CDN, and Maps embeds where used), Stripe (payments, including Google Pay where offered), Polar (platform subscription billing for studio owners, where used), Mux (video playback and related delivery analytics when video features are enabled), Resend (email), Twilio (optional SMS when a studio enables it), OpenRouter or similar AI providers (admin content tools only, when enabled), and PostHog (product analytics only if you consent; limited error diagnostics as described below). Each processes data only as necessary to provide the service.
Error diagnostics
To keep the service reliable and secure, we may send limited error reports (for example error message, stack identifiers, page path, and a hashed network identifier) to PostHog from our servers when a page or function fails. This diagnostics processing is separate from optional product analytics cookies and may occur without an analytics cookie opt-in. We do not use these reports for advertising.
Retention
We retain your data for as long as your account is active and as needed to provide the service, comply with law, or resolve disputes. You may request deletion of your account and data at any time (see Your rights).
Your rights
You have the right to: access and portability — download a copy of your data from My Account ("Download my data"); rectification — update your profile and preferences; erasure — delete your account from My Account ("Delete my account") or contact us; object or restrict certain processing; withdraw consent (for example analytics via Manage cookie preferences on the Cookie Policy page, marketing via Email preferences); and lodge a complaint with a supervisory authority.
When you delete your account in-app, we anonymize your profile and personal fields in our application database. Related booking or payment ledger rows may remain for the studio's records, accounting, or legal retention with your profile identifiers removed. Sign-in (WorkOS) and payment processors (Stripe; Polar for studio-owner platform billing) may retain records as required for security, fraud prevention, tax, or their own policies — contact us at the email below if you need help confirming a deletion request.
To exercise these rights, use the in-app options on the site where you have an account, or contact us (see Contact). You can opt out of marketing emails at any time via the link in any marketing email or in your account under Email preferences.
International transfers
Your data may be processed in the United States or other countries where our processors operate. We ensure appropriate safeguards (such as standard contractual clauses where required) for transfers outside your country.
Cookies
We use cookies and similar technologies in these categories: (1) Essential — required for authentication, security, and core site functionality; (2) Analytics — optional and only enabled with your consent (e.g. page views and feature usage); and (3) Marketing / sale-share controls — this service does not use third-party advertising tags for cross-context behavioral advertising. You can accept analytics, reject non-essential cookies, or update your choice at any time from the Cookie Policy page (Manage cookie preferences). Essential cookies remain active because they are necessary for the service to operate.
Google account data and Google services
This section describes how j.pilates studio accesses, uses, stores, and shares information received from Google when you use Google-related sign-in or services with this site.
Sign in with Google (when offered)
If you choose to sign in with Google, authentication is provided through our identity provider WorkOS AuthKit. Depending on the permissions you grant, we may receive from Google your email address, name, and profile photo (typically via OpenID Connect scopes such as openid, email, and profile).
- How we use it: to create and secure your account, identify you across sessions, and provide the service you requested.
- How we store it: email and name in our application database; session authentication via WorkOS (secure HTTP-only session cookie). We do not store Google OAuth refresh tokens or Google user IDs in our application database.
- How we share it: WorkOS processes sign-in on our behalf. We do not sell Google user data, use it for third-party advertising, or use it to train generalized AI/ML models.
- Retention and deletion: retained while your account is active and as needed to operate the service; you may delete your account in-app or contact us (see Contact).
- Your controls: sign out at any time; revoke this app's access in your Google Account permissions; delete your account to remove stored profile data subject to legal retention requirements.
Google Calendar
We do not access, read, or modify the contents of your Google Calendar through Google Calendar API scopes. If you choose "Add to Google Calendar" or subscribe to our booking calendar, you initiate that action: we provide event details via a browser link or a signed iCal feed URL that you add to Google Calendar. Google may fetch that feed; we do not receive your Google Calendar events back.
Google Wallet passes
If you choose to save a booking to Google Wallet, session details needed to display the pass (for example event title, time, and location) are sent to Google to create the pass. This uses Google's Wallet API under a server service account, not your personal Google OAuth tokens.
Other Google touchpoints
Google Pay (when offered at checkout) is processed by Stripe. Google Fonts and embedded Google Maps previews may load resources from Google's CDN; those requests do not provide us with your Google account data.
Limited Use
j.pilates studio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. For more information about Google's privacy practices, see the Google Privacy Policy.
Contact
For privacy requests, contact: [email protected]. Data controller: j.pilates studio.