Privacy Policy

Last updated: November 10, 2025

Introduction
Costa Yoga (“we,” “us,” or “our”) respects your privacy and is committed to protecting
your personal information. This Privacy Policy explains how we collect, use, disclose,
retain, and protect personal information when you interact with our studio, website,
mobile app, booking system, events, or other services (collectively, “Services”). This
policy applies to individuals who visit or register with Costa Yoga in Oviedo, Florida.

Summary of this Privacy Policy
We collect the personal information needed to provide classes, process payments,
manage bookings and memberships, and communicate with you. Costa Yoga does not
sell your personal data. You can access, correct, or request deletion of your data;
submit privacy requests by contacting us at the phone and postal address provided
below. The full policy below describes the categories of data we collect, how we use it,
who we share it with, and your privacy rights.

Information We Collect
We may collect the following categories of personal information:
• Identifiers: name, email, phone number, postal address, account username.
• Contact & account data: account credentials (securely hashed passwords), booking
history, membership status, class credits.
• Payment & billing: payment card details, billing address, transaction records
(processed through third party payment processors). Costa Yoga does not store full
card numbers or CVV codes.
• Health & wellness information: voluntary disclosures such as injuries, medical conditions, pregnancy, or other information you provide to help us ensure a safe class experience.
• Communications: customer service messages, support requests, feedback, and other
correspondence.
• Device & usage data: IP address, browser type, device identifiers, pages visited, app
usage, analytics data, and cookies.
• Location & attendance: class attendance, studio check ins, and location data if you
enable location services.
• Photos & media: images or video you upload or that include you (used for
promotional purposes).
• Sensitive data: sensitive health only if you voluntarily provide it; we treat such data
as sensitive and handle it in accordance with applicable laws.

How We Collect Information
We collect information in several ways:
• Directly from you when you register, sign up, purchase services, complete forms,
communicate with us, or provide health information or media.
• Automatically through cookies and tracking technologies when you use our website or
app.
• From service providers and partners (e.g., payment processors, email providers,
analytics vendors).
• From third parties you authorize (e.g., referral services) or publicly available sources.

Uses of Personal Information
We use personal information for the following purposes:
• To provide and manage classes, memberships, workshops, private sessions, and
purchases.
• To process payments, refunds, and billing.
• To send booking confirmations, reminders, updates, and responses to inquiries.
• To maintain safety and provide reasonable accommodations based on health
information you provide.
• To analyze and improve our Services, personalize communications, and provide
recommendations.
• To send marketing communications if you opt in, and to honor your opt out
preferences.
• To prevent fraud, enforce our terms, and protect the safety and rights of Costa Yoga,
our staff, and clients.
• To comply with legal obligations and cooperate with law enforcement or regulators
when required.

Sharing & Disclosure
We do not sell personal information. We may disclose personal information to:
• Service providers who perform functions on our behalf (e.g., booking platforms,
payment processors, email/SMS services, analytics vendors).
• Contractors and vendors assisting with studio operations (e.g., IT, marketing, and
legal advisors).
• Successors or buyers in connection with a sale, merger, or reorganization (with
appropriate protections).
• Governmental authorities, law enforcement, or regulators where required by law or to
protect legal rights, safety, or property.
• Other parties with your consent or as otherwise disclosed at the time of collection.
We share only the minimum data necessary for vendors to perform their services and
require contractual protections to safeguard your information.

Third Party Sites & Links
Our Services may link to third party websites or services. We are not responsible for
the content or privacy practices of those third parties. Please review their privacy
notices before providing personal information.

Cookies & Tracking Technologies
We use cookies, web beacons, pixels, and similar technologies to operate and improve
our site and app, provide analytics, remember preferences, and support advertising
where applicable. You may control cookie settings through your browser or app, but
disabling certain cookies may limit functionality.

Marketing & Communications
We will only send marketing communications (email, SMS, push notifications) if you opt
in where required by law. Each marketing message includes clear instructions to opt out
or unsubscribe. We maintain records of your contact preferences.

Your Privacy Rights
Subject to applicable law, you may have rights to:
• Access and receive a copy of personal information we hold about you.
• Correct inaccurate or incomplete personal information.
• Request deletion of your personal information, subject to legal and contractual
retention obligations.
• Object to or restrict certain processing activities.
• Withdraw consent where processing is based on consent.
• Opt out of targeted advertising and certain sharing/selling, where applicable.
To exercise these rights, contact us using the details below. We will verify requests as
necessary before responding and will respond within applicable statutory timeframes.

Data Retention
We retain personal information only as long as necessary to fulfill the purposes
described in this policy and to comply with legal obligations. As a baseline, Costa Yoga
retains most customer records, transaction records, membership and booking histories,
waivers, and incident reports for seven (7) years from the date of last activity, unless a
different retention period is required by law or justified by business need. CCTV footage
and temporary security recordings are typically retained for a shorter, documented
period (commonly 30 days) unless required for an ongoing investigation.

Security
We implement industry standard administrative, technical, and physical safeguards to
protect personal information. No security measure is absolute; we cannot guarantee
complete security. In the event of a data breach affecting personal information, we will
follow applicable notification laws and provide required notices.

Children
Our Services are not directed to children under 18. We do not knowingly collect
personal information from children under 18. If we learn that we have collected
information from a child under 18 without parental consent, we will take steps to delete
the information.

Sensitive Health Data & Consumer Health Data
If you provide sensitive health information (for example, in registration forms or
wellness intake), we will use this information only to provide, manage, and improve
services you request and as otherwise permitted by law. We limit access to such data to
staff who need it to provide services and apply enhanced safeguards.

Transfers
Your personal information may be processed or stored in the United States. By using
our Services, you consent to the transfer of information to the U.S. and to processing in
accordance with this policy.

Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, legal
requirements, or services. Material changes will be posted with an updated “Last
updated” date and, where appropriate, notified to you.

Contact & How to Exercise Your Rights
To ask questions, exercise privacy rights, or submit a request, contact:
Phone: 321 276 8188
Email: hello@costayogastudio.com
Address: 1976 Alafaya Trail #1220, Oviedo, FL 32765

When you submit a request, we may need to verify your identity before processing it.
We will not discriminate against you for exercising your privacy rights.

Additional Notices & Disclosures
• No Selling of Personal Data: Costa Yoga does not sell your personal information.
• Loyalty Programs: If we offer loyalty rewards that relate to your data, we will disclose
material terms and obtain any required consent.
• Legal Compliance: We will disclose personal information where necessary to comply
with laws, respond to legal process, or protect safety and property.

Your Journey Starts Here

Start your journey with Costa Yoga and experience the power of mindful movement.