Privacy Policy
Effective May 15, 2026
1. What we collect
- Account info: name, email, phone, date of birth.
- Health intake: medical conditions and contraindications you self-report. We use this only to determine eligibility for specific services and to flag risks to our staff. This information is not shared outside Chill N Out and its booking platform vendors.
- Payment info: card data is collected and stored by Stripe, our payment processor. We never see or store it.
- Usage data: pages visited, services viewed, bookings made.
- Communications: records of SMS/email we send you, and any replies.
2. How we use it
- Operate your account and bookings
- Send transactional messages (confirmations, reminders, cancellations)
- Improve services and content
- Comply with legal obligations
- With your separate opt-in, send marketing messages
3. Who we share with
We share data only with service providers necessary to operate our business:
- Stripe — payment processing
- Twilio — SMS delivery (when configured)
- Resend — transactional email (when configured)
- Our booking platform provider — for hosting, backup, and customer support
- Anthropic (if AI features are enabled) — for chatbot processing
We do NOT sell or rent your personal information to third parties for their marketing.
4. Health information
Wellness studios are not "covered entities" under HIPAA. However, we treat health-intake data as sensitive and apply the same access controls we use for payment data. Access is limited to (a) staff who need it to provide your service, and (b) authorized platform administrators for technical support.
5. Cookies & tracking
Our website uses essential cookies to maintain your session and analytics cookies to understand site usage. We do not use advertising tracking cookies. You can disable cookies via your browser settings, though some features may not work without them.
6. Your rights
You may at any time:
- Request a copy of the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account and associated data (subject to legal record-retention requirements for transaction data)
- Opt out of marketing communications
Contact support@lakelandchillnout.com to exercise these rights.
7. Data retention
- Account & booking history: retained 7 years
- Health intake: retained as long as you remain an active client + 4 years
- SMS/email logs: retained 2 years
- Card data: never retained by us (held only at Stripe per their schedule)
8. Security
We use TLS encryption for all data in transit. Card data is handled exclusively by PCI-DSS Level 1 certified processors. Health-intake data is encrypted at rest in our database. Access requires authenticated session.
9. Children
Our services are not intended for users under 18 without parent/guardian involvement. We do not knowingly collect personal information from children under 13.
10. Contact
Chill N Out Cryotherapy
6595 South Florida Avenue Suite 10
Lakeland, FL 33813
(863) 337-4847
support@lakelandchillnout.com