Privacy Policy
Last updated: September 2026
At Casa Om, we are committed to respecting your privacy and protecting your personal data. This Privacy Policy explains how we collect, use, store, and safeguard your personal information when you visit our studio, use our website, book classes through our booking system, or interact with us.
1. Who We Are (Data Controller)
For the purposes of the UK General Data Protection Regulation (UK GDPR), Casa Om is the data controller responsible for your personal data.
- Studio Name: Casa Om
- Location: Casa Om, 19 South Street, Chesterfield, S40 1QX
- Data Contact Email: hello@casaom.co.uk
2. What Personal Data We Collect
We only collect information that is necessary to provide you with a safe, seamless, and personalised experience, whether that's a class, a private treatment, or just joining our pre-launch waitlist:
- Identity & Contact Data: Your full name, date of birth, email address, phone number, and postal address.
- Emergency Contact Data: The name and phone number of a person we can contact in case of a medical emergency during class.
- Health, Waiver & Consultation Data: Information you provide about injuries, surgeries, medical conditions, or pregnancy on our Health Waiver, plus your typed full name and a hand-drawn signature confirming it. If you book a Skin and Bodhi beauty treatment, this also includes anything you share on your consultation/intake form and any treatment notes, product recommendations, or aftercare documents your beautician keeps against your account.
- Profile Photo: If you choose to add one, a profile photo you upload.
- Financial & Payment Data: Payment details, handled entirely by Stripe's own secure checkout. Casa Om never sees or stores your full card number. Studio payments (classes, memberships, gift cards) go through Casa Om's own Stripe account; Skin and Bodhi beauty payments go through the beautician's own, entirely separate Stripe account, since she runs that as an independent business renting space from us.
- Transaction History: Records of classes and beauty appointments booked/attended, passes and memberships purchased, and communications with us.
- Account Security Data: If you set an in-app PIN or turn on Face ID/fingerprint unlock, that lives entirely on your own device (as a locally-hashed PIN and your phone's own biometric system); we never receive, see, or store your fingerprint, face scan, or PIN ourselves.
- Notification Data: If you allow notifications, our push notification provider (OneSignal) links your device to your account so we can send you booking reminders and updates, see "How We Share Your Data" below.
- Calendar Sync Link: If you choose to "Sync with your calendar," we generate a personal link you can add to Google, Apple, or Outlook calendar as a "subscribe by URL" feed. Anyone with that exact link could see the class or appointment names and times it lists, so treat it like a password and don't share it. It never includes health, payment, or contact information, just what's booked and when.
- Apple Health Data (iOS only): If you grant permission, attending a class logs it as a completed workout in your iPhone's own Health app, so it appears in your own fitness history. This is one-way and stays on your device: we write a workout entry (activity type, start and end time) into Apple's HealthKit, we never read anything back out of your Health app, and this data is never sent to or stored on Casa Om's own servers. You can turn this off at any time in your iPhone's Settings.
- Apple Watch Companion (iOS only): If you use a paired Apple Watch, a short summary of your upcoming bookings and loyalty status is relayed to it directly from your iPhone using Apple's WatchConnectivity technology. This stays between your own paired devices; it isn't sent to Casa Om or stored anywhere beyond what's already described above.
- Waitlist Signups: If you join our pre-launch queue, we collect your name, email address, and (optionally) who referred you.
- Technical Data: Standard web request data (like IP address and browser type) that any website server sees. We don't run advertising or analytics trackers on our site or in our app; see "Cookies & Similar Technologies" below for exactly what we do store locally in your browser or device.
3. How We Use Your Personal Data
We use your information under the following legal bases under UK GDPR:
- To Perform Our Contract With You: To process bookings, manage memberships, send class confirmation emails, handle cancellations, and notify you of waitlist updates.
- To Ensure Your Safety (Legitimate Interest/Vital Interest): To allow instructors to adapt movements safely according to your health history, and to contact emergency services or your emergency contact if needed.
- For Marketing Communications: When you sign up, we'll send you occasional newsletters, details about upcoming workshops, retreats, and special offers, unless you tick the box at signup to say you don't want them. Booking confirmations, class reminders, and other transactional emails aren't affected by this either way. You can opt out at any time, either from the box at signup or via the unsubscribe link at the bottom of any marketing email.
- For Legal & Accounting Obligations: To maintain accurate financial records for UK tax (HMRC) reporting.
4. How We Share Your Data
We will never sell, rent, or trade your personal information to third parties. We only share data with trusted service providers who help us run the studio and app:
- Supabase: Hosts our database, sign-in system, and any files you upload (like a profile photo or waiver signature). This is where your account and booking data actually lives.
- Stripe: Processes payments on our behalf. As above, studio payments go through Casa Om's own Stripe account; beauty treatment payments go through the beautician's own, separate Stripe account.
- Resend: Sends our transactional and marketing emails (booking confirmations, receipts, newsletters).
- OneSignal: Delivers push notifications to the app if you've allowed them, linked to your account by an internal ID only, not your name or email.
- Behold.so: Powers the live Instagram feed shown on some pages. Loading that feed makes your browser request images directly from Behold's servers, which sees your IP address the same way any website you visit does.
- Google Fonts: Our typefaces load from Google's font servers, which likewise sees your IP address when a page loads.
All third-party service providers are contractually required to safeguard your data and handle it strictly in accordance with UK GDPR laws.
5. How Long We Keep Your Data
We retain your personal data only for as long as necessary to fulfil the purposes we collected it for:
- Active Student Accounts: Kept while your account remains active with us.
- Health Waivers & Liability Records: Retained for 7 years following your last visit, in accordance with UK legal and insurance claims guidelines.
- Financial & Transaction Records: Retained for 6 years following the end of the relevant UK tax year, as required by HMRC.
- Waitlist Signups: Kept until you join as a full member, or ask us to remove you sooner.
6. Your Legal Rights (Under UK GDPR)
As an individual in the UK, you have clear rights regarding your personal data:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct inaccurate or incomplete information.
- Right to Erasure ("Right to be Forgotten"): You can delete your account and data yourself at any time from the app's side menu, or ask us to do it for you (subject to legal or insurance retention obligations, such as health waivers and financial records, and to first cancelling any active membership, which needs 30 days' notice like any cancellation).
- Right to Withdraw Consent: You can unsubscribe from marketing emails or withdraw health consent at any time.
To exercise any of these rights, please contact us at hello@casaom.co.uk.
7. Cookies & Similar Technologies
We don't run any advertising or analytics trackers on our website or in our app. What we do store, locally in your own browser or device (not on our servers), is limited to what's needed for the site and app to actually work:
- Keeping you signed in between visits.
- Remembering your place in the pre-launch queue and any referral code, if you've joined it, so the page recognises you on your next visit.
- Security preferences you've set yourself in the app, like whether App Lock is on (the PIN itself is stored only as a hash, never in plain text, and never leaves your device).
Some pages also embed third-party content (our Instagram feed, our web fonts) that causes your browser to make requests directly to those services, as described in "How We Share Your Data" above. You can adjust your browser settings to block cookies and local storage at any time, though our sign-in and booking features won't work properly without them.
8. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements or studio practices. Any updates will be posted here with a revised "Last Updated" date.
9. How to Contact Us or Lodge a Complaint
If you have any questions about this Privacy Policy or wish to make a complaint regarding how your data has been handled, please contact us first so we can resolve it:
If you are not satisfied with our response, you have the right to lodge a complaint with the UK's data protection regulator: the Information Commissioner's Office (ICO), ico.org.uk, Helpline: 0303 123 1113.