Privacy Policy

Last updated: October 17, 2025

The Prana Room (“TPR”, “we”, “us”, “our”) provides yoga and wellness services in Ontario. This policy explains how we handle personal information—especially personal health information (PHI)—under Ontario’s Personal Health Information Protection Act, 2004 (PHIPA).

This is general information, not legal advice.

1) Information we collect

  • Identity & contact: name, email, phone, address, emergency contact.

  • Bookings & transactions: class/program bookings, purchase history, billing details. (Payment card details are collected by our payment processor; we do not store full card numbers.)

  • Wellness intake / PHI (if provided): relevant health history, injuries, conditions, goals, and practitioner notes to help ensure safe participation.

  • Communications: emails, forms, direct messages, survey responses, preferences.

  • Website/usage data: cookies, IP address, device/browser type, pages viewed, and referring URLs.

2) How we use information

  • Deliver classes/programs and customer support.

  • Assess suitability and safety for participation (PHI used only as PHIPA permits).

  • Manage bookings, confirmations, reminders, receipts.

  • Improve our services and website (aggregate/usage insights).

  • Meet legal, tax, insurance, and risk-management requirements.

  • Send optional updates or promotions only with your consent (you may opt out at any time).

We do not sell your information.

3) Our role under PHIPA

If we collect PHI, we:

  • Limit collection to what is reasonably necessary for suitability and safety.

  • Apply heightened safeguards and restrict access to authorized personnel.

  • Use/disclose PHI only as permitted by PHIPA or with your consent.

If we collaborate with a health information custodian (e.g., a regulated health professional/clinic), we may act as their agent. Their PHIPA policies apply in addition to this policy, and we follow their directions for PHI handling.

4) Disclosures

We may disclose information:

  • To service providers acting on our behalf under confidentiality obligations (e.g., booking, payments, email, analytics, secure storage).

  • To professional advisors (legal, accounting, insurance) as needed.

  • As required by law or to protect safety/rights (e.g., serious risk of harm, lawful requests).

  • With your explicit consent (e.g., testimonials, referrals).

Website host: We use Squarespace to host our website. Squarespace may process limited technical/usage data to operate the site.
Location of services: Some service providers may store/process data outside Ontario/Canada. We use contractual and technical safeguards appropriate to the sensitivity of the data.

5) Your rights (PHIPA)

Subject to legal limits, you may:

  • Access and request correction of your PHI and other personal information we hold.

  • Withdraw consent for optional uses (like marketing) at any time.

  • Request restrictions on certain uses/disclosures where feasible.

We may verify your identity and retain information necessary to meet legal/insurance obligations.

6) Retention

We retain information only as long as reasonably necessary for the purposes above and to satisfy legal, regulatory, tax, and insurance requirements. We then securely delete or de-identify it.

7) Security

We use safeguards appropriate to sensitivity, including access controls, least-privilege practices, secure transmission where applicable, and confidentiality commitments with providers. No method is perfectly secure, but we strive to protect your information.

8) Cookies & analytics

We use cookies and similar technologies to run and improve our site. You can adjust your browser settings to limit cookies (some features may be affected).

9) Minors

Where minors participate, we require parent/guardian consent for collecting any information, including PHI.

10) Contact & complaints

Questions, access/correction requests, or complaints:
Email: thepranaroom.to@gmail.com

If unresolved, you may contact the Information and Privacy Commissioner of Ontario (IPC) at 1-800-387-0073.

11) Changes to this policy

We may update this policy. The “Last updated” date reflects the latest version. Material changes will be posted on our website.