YogaCandy

Privacy Policy

Last updated: 7 April 2026

1. Who We Are

YogaCandy (“we”, “our”) operates yogacandy.info. We are committed to protecting your personal data and complying with the EU General Data Protection Regulation (GDPR) and applicable data protection laws.

2. Data We Collect

  • Account data: name, email address, role (teacher/student), and hashed password when you register.
  • Location data: approximate city and country, stored only in your browser (localStorage). Never sent to our servers unless you submit a form.
  • Usage data: anonymous page views via server logs (IP addresses are anonymised after 24 h).
  • Communications: messages you send via contact forms or the AI chat widget.

3. Legal Basis (GDPR Art. 6)

  • Consent (Art. 6.1.a): location detection and marketing communications. You may withdraw at any time.
  • Contract (Art. 6.1.b): account registration and service delivery.
  • Legitimate interests (Art. 6.1.f): security, fraud prevention, and anonymous analytics.

4. On-Device AI

The style recommender runs entirely in your browser using Chrome’s built-in AI (Gemini Nano). Your questionnaire answers are never transmitted to YogaCandy or any third party.

5. Third-Party Services

  • Supabase — authentication and database (EU region). Data Processing Agreement in place.
  • Google Maps — map embeds when you allow location access. Governed by Google’s Privacy Policy.
  • Instagram / Behold — embedded feed from @yogacandyae. Governed by Meta’s Privacy Policy.

6. Advertising & Cookies (Google AdSense)

We use Google AdSense to display advertisements on this website. Google AdSense uses cookies and similar tracking technologies to serve ads based on your prior visits to this website and other sites across the web.

  • Third-party cookies: Google and its partners may use cookies to personalise ads, measure ad performance, and prevent ad fraud.
  • Interest-based ads: Google may use your browsing history across participating websites to show relevant ads. You can opt out via Google Ad Settings.
  • DoubleClick cookie: Google AdSense also uses the DoubleClick cookie to help deliver better, more relevant ads across the web.

You can learn more about how Google uses data at policies.google.com/technologies/partner-sites.

7. Your Rights (GDPR Art. 15–22)

You have the right to:

  • Access your personal data (Art. 15)
  • Correct inaccurate data (Art. 16)
  • Erase your data — “right to be forgotten” (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing (Art. 21)
  • Withdraw consent at any time without affecting prior processing (Art. 7.3)

To exercise any right, email us at privacy@yogacandy.info. We will respond within 30 days.

8. Data Retention

Account data is retained while your account is active and for 12 months after deletion, after which it is permanently erased. You may request immediate deletion at any time.

9. Contact & Complaints

Data Controller: YogaCandy · privacy@yogacandy.info
You have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, UAETRA in the UAE).