Smart in the Outdoors
Privacy Policy — Smart in the Outdoors
Last updated: 14th September 2026
Smart in the Outdoors ("we", "us", "our") is committed to protecting your privacy. This policy explains what personal information we collect through our website, why we collect it, how we use it, and your rights regarding it, in line with UK GDPR and the Data Protection Act 2018.
1. Who We Are
Smart in the Outdoors runs outdoor events including yoga, guided hikes, foraging walks, and retreats.
Contact: Helena Smart Email: info@smartintheoutdoors.com
2. Information We Collect
Depending on how you interact with our site, we may collect:
When you book a session:
-
Name, email address, phone number
-
Payment details (processed securely by our payment provider — we do not store your card details ourselves)
-
Booking history (sessions attended, dates, amounts paid)
When you create a member account:
-
The account details above, stored so you can log in, view your booking history, and rebook more easily
Health, fitness and dietary information:
-
Details you provide in our medical questionnaire (e.g. medical conditions, medication, allergies, dietary requirements)
-
This is "special category data" under UK GDPR. We only collect it with your explicit consent, and only to keep you safe during physical activity and to plan food/refreshments appropriately
Emergency contact details:
-
Name, relationship, and phone number of your emergency contact
General website use:
-
Standard technical data such as IP address and browsing activity, via cookies (see Section 7)
3. Why We Collect It and Our Legal Basis
What we use it for
Legal basis
Processing and managing your booking
Performance of a contract
Keeping you safe during sessions (health/fitness info)
Explicit consent
Planning food/refreshments (dietary info)
Explicit consent
Contacting your emergency contact if needed
Vital interests / explicit consent
Sending you booking confirmations and essential updates
Performance of a contract
Sending marketing updates (e.g. new sessions, offers)
Consent (you can opt out at any time)
Improving our website
Legitimate interests
4. Keeping Your Information Up to Date
Your health and dietary information remains on file and does not need to be resubmitted for each booking. It is your responsibility to keep it accurate — you can review and update it at any time via your member account. We will also prompt you periodically to reconfirm your details are still correct.
5. Who We Share Your Information With
We do not sell your personal information. We may share it with:
-
Wix, our website and booking platform provider, who host and process data on our behalf
-
Our payment processor, to handle transactions securely
-
Our yoga instructor or other session leaders, limited to what they need to run a session safely (e.g. relevant health/dietary information, not your full record)
-
Emergency services, if needed for your safety during a session
-
Authorities, where we are legally required to do so
6. How Long We Keep Your Information
-
Booking and account information is kept for as long as you hold a member account, and for a reasonable period afterwards for accounting and legal purposes
-
Health and dietary information is kept for as long as it remains current and you continue to book with us, and is removed on request or after a period of inactivity [insert period, e.g. 2 years]
7. Cookies
Our website uses cookies to help it function and to understand how visitors use it. You can manage cookie preferences through the cookie banner on our site or your browser settings.
8. Your Rights
Under UK GDPR, you have the right to:
-
Access the personal information we hold about you
-
Correct inaccurate information
-
Request deletion of your information (subject to legal/contractual limits)
-
Withdraw consent at any time (e.g. for marketing, or for storing health data — though this may limit your ability to book certain sessions)
-
Request a copy of your data in a portable format
-
Complain to the Information Commissioner's Office (ICO) if you believe your data has been mishandled
To exercise any of these rights, contact us at [your business email address].
9. Children
Our sessions and services are intended for adults. [Adjust this section if you accept under-18 bookings, e.g. with parental consent.]
10. Changes to This Policy
We may update this policy from time to time. The "last updated" date at the top will reflect the most recent version.
11. Contact Us
If you have any questions about this policy or how we handle your information, contact us at:
[your business email address]
Notes for you (not part of the published policy)
-
Fill in the bracketed placeholders (contact email, address, retention period, children's policy).
-
This is a solid starting template, but because you handle special category (health) data, it's worth having a solicitor or a service like an ICO-registered DPO template review it — particularly Sections 3, 5, and 6.
-
You'll also need to register with the ICO as a data controller if you haven't already (there's a small annual fee) — worth checking if you're already registered via your business setup.
-
Once it's live, link to this policy from your booking form and your medical questionnaire consent line.