Privacy policy
How we collect, use, and protect personal information when you use Balance & Bliss in United Kingdom and beyond.
Last updated: September 2026.
Who we are
Balance & Bliss operates the marketplace that connects guests with retreat hosts. The controller of your personal data is identified in Company details.
This policy explains what we collect, why we collect it, who we share it with, and the rights you can exercise. It applies to our website, our booking flow, and the guest, host, and organiser dashboards.
Data we process
We collect information you give us directly, information generated as you use the service, and a limited amount of information from the payment and analytics providers we rely on.
- Account and contact details you provide — name, email address, phone number, and password credentials stored only as a hash
- Booking details — the retreat, dates, room type, guest count, dietary or accessibility notes you choose to share, and deposit and balance status
- Payment metadata — the outcome of a transaction, the last four digits and card brand, and billing address. Full card numbers are handled by our payment provider and never stored on our servers
- Host and organiser details — listing content, payout details, and any verification documents you submit
- Messaging and support history between guests, hosts, and our support team
- Device and usage data — IP address, browser type, timezone, pages viewed, and referring links, used to secure accounts, prevent fraud, and improve the product
Purposes and legal bases
We process data to perform our contract with you, comply with law, protect vital interests, and pursue legitimate interests such as fraud prevention and analytics, where balanced against your rights.
- Performance of a contract — creating your account, taking payment, confirming and administering a booking, and passing the details a host needs to receive you
- Legal obligation — tax and accounting records, and responding to lawful requests from authorities
- Legitimate interests — securing accounts, screening for fraud and payment risk, measuring how the site performs, and improving our listings and search
- Consent — marketing email, and any non-essential cookies or similar technologies. You can withdraw consent at any time without affecting processing already carried out
Sharing with hosts and service providers
When you book, we share the details a host needs to host you — your name, contact details, arrival dates, and any dietary or accessibility notes you provided. Hosts are independent controllers of the information they receive and are bound by their own obligations under data protection law.
We also use carefully selected processors who act on our instructions: payment processing, transactional email and messaging, cloud hosting and backup, error monitoring, and privacy-friendly site analytics. We do not sell personal data, and we do not share your phone number with third parties for their own marketing.
We may disclose information where we are legally required to, or where it is necessary to establish, exercise, or defend legal claims, or to protect the safety of guests, hosts, or the public.
International transfers
Retreats are hosted worldwide, so booking data may be transferred to a host outside the United Kingdom or the European Economic Area. Where a provider or host is located in a country without a UK adequacy decision, we rely on appropriate safeguards such as the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
How long we keep it
We keep account data while your account is open, and booking, payment, and tax records for as long as required by law after a booking completes — typically six years. Support correspondence is retained while a matter is open and for a reasonable period afterwards. Marketing preferences are kept until you withdraw consent. When data is no longer needed we delete it or irreversibly anonymise it.
Security
Traffic to and from the site is encrypted in transit. Session tokens are held in httpOnly cookies that scripts on the page cannot read, passwords are stored only as salted hashes, and access to production data is restricted to staff who need it. No system can be guaranteed perfectly secure, so please use a unique password and tell us promptly if you believe your account has been accessed without your permission.
Your rights
Depending on applicable law, you may have rights to access, rectification, erasure, restriction, portability, and objection. You may lodge a complaint with a supervisory authority.
You can update most account and contact details yourself in your dashboard, and unsubscribe from marketing email using the link in any such message. To exercise any other right, contact us via the Contact page. We respond within one month and may ask for information to verify your identity first.
If you are in the United Kingdom, your supervisory authority is the Information Commissioner's Office. If you are in the European Economic Area, it is the authority in your country of residence.
Children
The service is not directed at children, and accounts may only be created by adults. Guests under 18 may attend a retreat where the host permits it, as part of a booking made and supervised by a parent or guardian. If you believe a child has given us personal data directly, contact us and we will delete it.
Changes to this policy
We may update this policy as the service develops or the law changes. The date above shows when it was last revised, and material changes will be notified on the site or by email before they take effect.