Privacy
How we handle your information.
In plain words. Considered, warm, and honest about what we do with the details you trust us with.
Last updated · 20 August 2026
At a glance
Inner Gaia is a curated marketplace connecting people seeking holistic practice with practitioners who’ve been reviewed by a person. To run it we collect a small amount of information from each side, and we use it only to make the introduction, the booking, and the follow-up work.
- What we collect: your email and name; if you’re a practitioner, your professional profile; if you book, your booking and payment metadata.
- Why: to run the waitlist now, and to run the marketplace (matching, booking, paying, reviewing) once we open.
- Who else sees it: only the service providers we need to operate (database, email, payments, video). Never sold, never rented.
- How long we keep it: as long as your account is active, plus a short tail for legal and tax records.
- Your rights: access, correct, delete, port, restrict, object. One email to hello@innergaia.com starts the process.
1. Who we are
Inner Gaia is operated by a US-registered sole proprietorship (the “data controller”) under United States tax registration. Review — confirm entity name + mailing address before public launch
For privacy questions, including any request to access, correct, or delete your information, write to hello@innergaia.com. We respond within 30 days, usually much sooner. We do not currently have a designated Data Protection Officer; the founder is the accountable contact for all privacy matters. Review — DPO requirement triggers depend on processing volume; reassess at scale
2. What we collect
From everyone — the waitlist (today)
- Your name and email address.
- Whether you signed up as a seeker or a practitioner.
- The source URL (always
innergaia.comfor now) and a server timestamp of when you joined.
From people who sign in (once the marketplace opens)
Sign-in is by one-time email link (magic link). The link is generated by our own application and delivered by our email processor, Resend. We store your email address and the linkage to your profile row. We do not store passwords because there are no passwords.
From practitioners
- Full name, headline, short and long bio.
- Modalities you practice (from a controlled list of 25), languages you work in.
- City and country.
- Optional: an introduction video URL, a credentials URL, an avatar photo.
From seekers when you book
- The service you booked, the practitioner, and the session time.
- Booking status (pending, confirmed, completed, cancelled, refunded, no-show) and the price breakdown (service fee, platform commission, practitioner payout).
- Stripe identifiers for the payment (the actual card details never reach our systems — they sit with Stripe).
- The video room URL that we generate for the session.
Reviews
After a completed session you can leave a 1–5 rating and an optional written review. We link the review to the booking it came from so we can verify it’s genuine.
What we do not collect
- We do not run third-party analytics, ad pixels, or behavioural trackers.
- We do not buy data about you from data brokers.
- We do not collect special-category data (Article 9 GDPR) about you intentionally. See § Not medical advice for why this is worth saying out loud on a wellness platform.
3. How we collect it
- Directly from you — when you join the waitlist, apply as a practitioner, edit your profile, list a service, or book a session.
- Automatically — basic server logs (IP address, request path, timestamp) at our hosting layer (Cloudflare) for security and reliability, retained briefly. Review — confirm Cloudflare Workers log retention window and document it
- From processors — once payments and video sessions are live, Stripe will return payment status via signed webhooks and Daily.co will return a room URL. Authentication is handled inside our own application, not by a third party.
4. How we use it
We use the information for these specific purposes:
- To run the waitlist — to write to you once when the door opens. That email is the one and only marketing message we send from waitlist signup.
- To run the marketplace — to match seekers with practitioners, take bookings, charge payments, generate the session video room, and send transactional notifications (confirmation, reminder, cancellation, refund).
- To review practitioner applications by hand — a person reads each application before a practitioner profile is published.
- To support you — when you write to us we look at your account context so we can answer accurately.
- To prevent abuse — anti-fraud, anti-spam, refund disputes, account safety.
- To meet our legal obligations — tax records, payment records, lawful requests we’re required to honour.
We do not use your information to train AI models, sell your data, send unrelated marketing, or build behavioural profiles for advertising.
5. Legal basis for processing (EU/UK only)
If you’re in the EU, UK, or another jurisdiction that asks which legal basis we rely on, the answer is one of these:
- Performance of a contract — for everything required to actually deliver a booking (matching, payment, video room, confirmation email).
- Consent — for the waitlist email signup (you ticked the box by submitting the form), and for any future optional features that ask explicitly.
- Legitimate interest — for running the platform safely (anti-fraud, anti-spam, security logs) and for manually reviewing practitioner applications. We’ve balanced these interests against your privacy and believe they don’t override your rights; you can object at any time.
- Legal obligation — for tax records, payment records, and lawful requests.
6. Who else sees it
We share only what each provider needs to do its job. None of them are allowed to use your data for their own purposes.
Service providers (sub-processors)
- Cloudflare — hosts the website, runs our server-side code (Workers), and provides our database (D1). Sees request metadata, including IP address, for routing, execution, and security. Our database is located in the Western Europe region.
- Resend — sends sign-in, transactional and waitlist email, and maintains the audience lists.
- Stripe — not yet active. Will process payments, manage practitioner payouts, and hold card data once bookings open. (We never see or store your card.)
- Daily.co — not yet active. Will generate the video room URL for each session once sessions open. Sessions are not recorded.
Each of the above signs a data processing agreement (DPA) with us before any real customer data touches them. Review — confirm DPAs are executed and filed for Cloudflare and Resend before public launch, and for Stripe and Daily.co before those services go live
Practitioners and seekers
When you book a session, the practitioner sees your name and the booking details so they can show up prepared. When you publish a practitioner profile, your name, headline, bio, modalities, city, and reviews are public on the practitioner page.
Authorities
If we receive a lawful, narrow request from a court or regulator we will comply with the minimum required. If we can tell you about the request without violating the law, we will.
We do not sell, rent, or trade your information.
7. International data transfers
Inner Gaia is a US-registered business serving a global audience, and our processors run servers in different regions. When your data crosses a border, we rely on one of these transfer mechanisms:
- EU Standard Contractual Clauses (or the UK Addendum) with each processor that processes EU/UK personal data.
- Adequacy decisions where the European Commission has made one.
- EU–US Data Privacy Framework certification, where the processor participates.
8. How long we keep it
- Waitlist record — until we’ve written the launch email and you have either signed up or declined. Up to 24 months from your signup date if you do neither. Review — confirm retention window before launch
- Account profile — while your account is active. Delete your account and we delete the profile within 30 days.
- Booking and payment records — at least 7 years from the booking date, for US tax and audit obligations. Review — confirm the retention period required by US + applicable state tax law
- Practitioner application archive — applications we’ve rejected are kept for 12 months so we can recognise repeat applications and explain our prior decision if asked.
- Reviews — public reviews remain public for the life of the practitioner profile; if a review is removed for policy reasons, the row is kept internally for 12 months for dispute history.
- Server / security logs — short tail at our hosting and edge layers; Review — confirm exact retention window with Cloudflare.
9. Your rights
Depending on where you live, you have some or all of these rights:
- Access — get a copy of the personal data we hold about you.
- Correct — fix anything inaccurate or incomplete.
- Delete — ask us to erase your data. We will, except for the narrow records we’re required to retain by law (tax, payment, dispute).
- Restrict — pause certain processing while we sort out a dispute or correction.
- Object — to processing based on legitimate interest, including manual practitioner review.
- Portability — receive your data in a machine-readable format (we provide JSON).
- Withdraw consent — at any time, for processing based on consent. Withdrawing doesn’t affect anything we did before you withdrew.
- Lodge a complaint — with your local data-protection authority. In the EU, that’s the regulator in your country; in the UK, the ICO.
Write to hello@innergaia.com from the email address you signed up with. We respond within 30 days. We don’t charge a fee unless your request is plainly excessive (and even then we’d tell you first).
10. California rights (CCPA / CPRA)
If you live in California, in addition to the rights above you have:
- The right to know what personal information we collect, use, disclose, and (if we did) sell or share.
- The right to delete personal information we collected from you.
- The right to correct inaccurate personal information.
- The right to limit use of sensitive personal information.
- The right to opt out of sale or sharing of personal information.
- The right to non-discrimination for exercising any of the above.
We do not sell or share personal information. Even so, we’re required to say so explicitly. The Californian opt-out is a single email to hello@innergaia.com with “Do Not Sell or Share” in the subject line — even though there is nothing to opt out of.
11. Cookies
We use a small number of cookies that are strictly necessary to operate the site. We do not use analytics, advertising, or third-party tracking cookies.
- Authentication session cookie — set by our own application after you sign in so you stay signed in. Required.
- CSRF / form security cookie — protects form submissions from cross-site request forgery. Required.
Because we only use strictly-necessary cookies, we do not display a cookie banner. You can clear or block these cookies in your browser at any time; you will then need to sign in again.
Review — re-evaluate if we ever add a non-essential cookie, pixel, or analytics tool12. Security
- All traffic over HTTPS (TLS 1.2+).
- Data at rest is encrypted by our providers (Cloudflare, Stripe).
- Every query that reads or writes personal data runs on the server and is checked against the signed-in user before it executes, so one account cannot read another’s data.
- Payments are tokenised by Stripe; we never see or store your card.
- Magic-link sign-in means no passwords to leak.
- Database and API credentials are held server-side only, never shipped to the browser, and rotated periodically.
No system is perfectly secure. If you discover a vulnerability, write to hello@innergaia.com with “Security” in the subject — we take responsible disclosure seriously and respond quickly.
13. Not for children
Inner Gaia is for adults aged 18 or older. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with information, write to hello@innergaia.com and we will delete it.
14. Not medical advice
Inner Gaia is a marketplace for holistic practitioners. The practitioners listed are not necessarily licensed medical providers, and sessions booked through Inner Gaia are not medical advice, diagnosis, or treatment. Do not delay seeking medical attention from a qualified clinician because of anything you read here or anything a practitioner says in a session.
We intentionally do not collect health information about seekers. If a practitioner’s bio or credentials reference specific health conditions, that information is provided by the practitioner about their own practice, not about you.
15. Marketing email
From the waitlist, you will receive one email when we open the door. That’s it. No newsletter. No drip campaign.
Once you have an account, we send transactional emails — booking confirmations, reminders, cancellations, refunds, security alerts — and you cannot unsubscribe from those because they are necessary to operate your account. Any future optional marketing email would be clearly labelled and opt-in.
16. Changes to this policy
If we change this policy in a way that materially affects your rights, we will email you and post a notice on the homepage at least 30 days before the change takes effect. Small clarifications and typographic fixes will be reflected in the “last updated” date above without a separate announcement.
17. Contact
For any privacy question or request: hello@innergaia.com.
Postal address: Review — confirm mailing address before public launch.