Salt Escapes
All TripsWhat to ExpectOur StoryAvailability
Contact UsFAQs
Book Now
All TripsWhat to ExpectOur StoryAvailabilityContact UsFAQsBook Now

Salt Escapes Ltd · Company Number 11086084

Privacy Policy

Last updated: 21 April 2026

Contents

  1. 1. Who we are
  2. 2. What this policy covers
  3. 3. What personal data we collect
  4. 4. Health and special category data
  5. 5. How we collect your data
  6. 6. Why we process your data and our lawful bases
  7. 7. Marketing and profiling
  8. 8. Cookies and tracking technologies
  9. 9. Server-side tracking
  10. 10. Who we share your data with
  11. 11. International data transfers
  12. 12. How long we keep your data
  13. 13. Your rights
  14. 14. Children's data
  15. 15. Data security
  16. 16. Data breaches
  17. 17. Changes to this policy
  18. 18. How to contact us
  19. 19. How to complain

1. Who we are

We are Salt Escapes Ltd, a company registered in England and Wales (Company Number 11086084).

Registered address: 24 Chelsfield Gardens, London, SE26 4DJ, United Kingdom

Website: www.salt-escapes.com

Booking platform: book.salt-escapes.com

Email: support@salt-escapes.com

We are the data controller for the personal data described in this policy. That means we decide how and why your personal data is processed.

We operate under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations (PECR). Our supervisory authority is the Information Commissioner's Office (ICO).

Note: Salt Escapes Ltd is registered with the ICO as required under the Data Protection Act 2018. If you wish to verify our registration, you can search the ICO's public register at ico.org.uk.

2. What this policy covers

This policy explains how we collect, use, store, share, and protect your personal data when you:

  • Visit our website or booking platform
  • Subscribe to our newsletter
  • Make an enquiry or pre-register interest in a retreat
  • Book and attend one of our retreats
  • Interact with us on social media or through our chat widget
  • Are photographed or filmed during a retreat

It applies to everyone who interacts with Salt Escapes, whether you are a website visitor, prospective guest, confirmed guest, or past guest.

3. What personal data we collect

We collect different types of data depending on how you interact with us.

Website visitors:

  • IP address and approximate location
  • Browser type and version, operating system, device type
  • Pages visited, time spent on pages, referral source
  • Mouse movements, clicks, and scroll behaviour (via session recording tools)
  • Cookie identifiers (see Section 8)

Newsletter subscribers:

  • Email address
  • Email engagement data (opens, clicks)
  • Purchase and browsing history linked to your email

Enquiries and pre-registration:

  • Full name
  • Email address
  • Phone number
  • Country of residence
  • Destination and date preferences
  • Room type preferences
  • Whether you are travelling with a companion

Booking customers (everything above, plus):

  • Passport details (name, number, nationality, expiry date)
  • Date of birth
  • Dietary requirements
  • Medical conditions, injuries, and physical limitations
  • Fitness level and exercise experience
  • Allergies
  • Emergency contact details (name, relationship, phone number)
  • Billing name and address
  • Payment card details (processed by Stripe — we do not store card numbers)

On-retreat guests:

  • Photographs and video footage taken during retreats
  • Social media content featuring you (with your consent)

Contractors and suppliers:

  • Name, contact details, bank details
  • Contract and payment records

4. Health and special category data

This section is particularly important. As a fitness retreat company, we need to collect data about your health and physical condition to run our retreats safely. This includes:

  • Medical conditions and injuries — so our trainers and retreat staff can adapt activities and respond to emergencies
  • Dietary requirements — which may reveal health conditions or religious beliefs
  • Allergies — to protect your safety during meals and activities
  • Fitness levels and physical capabilities — to design appropriate training programmes

Under UK GDPR, this information is classified as special category data (Article 9) because it relates to your health and may reveal religious or philosophical beliefs.

Our lawful basis for processing this data:

We process special category data on the basis of your explicit consent (Article 9(2)(a) UK GDPR).

  • We ask for your explicit consent during the booking process, before you provide this information.
  • You can withdraw your consent at any time by emailing support@salt-escapes.com.
  • If you withdraw consent, we may not be able to accommodate you safely on a retreat, and we will explain any implications before processing your withdrawal.
  • Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

We only share health data with retreat staff, fitness instructors, and catering providers who need it to deliver your retreat safely. We never use health data for marketing purposes.

5. How we collect your data

MethodExamples
Directly from youBooking forms, enquiry forms, email correspondence, phone calls, chat messages, retreat registration paperwork
AutomaticallyCookies, server logs, tracking pixels, session recording tools when you visit our website
From third partiesPayment confirmation from Stripe/Shopify, advertising platforms (Meta, Google, TikTok) matching your browsing to ad interactions

6. Why we process your data and our lawful bases

PurposeLawful basisDetails
Processing your booking and delivering your retreatContract (Art. 6(1)(b))Necessary to fulfil our contract with you
Processing health, dietary, and allergy dataExplicit consent (Art. 9(2)(a))Special category data — see Section 4
Sending you marketing emailsConsent (Art. 6(1)(a) + PECR Reg. 22)You can opt out at any time
Responding to your enquiriesLegitimate interest (Art. 6(1)(f))Our interest in responding to potential customers
Website analytics and performance monitoringLegitimate interest (Art. 6(1)(f))Understanding how our website is used to improve it
Advertising and conversion trackingConsent (Art. 6(1)(a))Via our cookie consent mechanism
Session recording (Microsoft Clarity)Consent (Art. 6(1)(a))Via our cookie consent mechanism
Fraud prevention and securityLegitimate interest (Art. 6(1)(f))Protecting our business and customers
Legal compliance (tax records, etc.)Legal obligation (Art. 6(1)(c))Required by law
Photographs and video on retreatsConsent (Art. 6(1)(a))You can opt out at any time
Emergency contact processingLegitimate interest (Art. 6(1)(f))Vital interest fallback in genuine emergencies
Contractor and supplier managementContract (Art. 6(1)(b))Necessary to fulfil our contract with them

Where we rely on legitimate interest, we have conducted a balancing test to ensure our interests do not override your rights. You can request details of these assessments by emailing us.

7. Marketing and profiling

Email marketing:

We use Klaviyo to send marketing emails. We only send marketing emails where you have given consent (e.g., subscribing to our newsletter or ticking a marketing consent box during booking). Every marketing email includes an unsubscribe link. You can also email support@salt-escapes.com to opt out.

Profiling and targeted advertising:

PlatformWhat happens
Meta (Facebook & Instagram)The Meta Pixel and Conversions API track pages you visit on our site. Meta uses this to show you ads and to build "lookalike" audiences of similar people.
Google AdsGoogle tracks conversions (e.g., completing a booking) and uses remarketing to show you ads on Google Search and partner sites.
TikTokThe TikTok Pixel tracks browsing behaviour for ad targeting and conversion measurement.
KlaviyoSegments subscribers based on engagement, purchase history, and browsing behaviour to personalise email content.

Your right to object:

You have the right to object to profiling at any time. You can:

  • Decline marketing cookies via our consent banner
  • Opt out of email profiling by unsubscribing
  • Use platform-specific opt-outs (e.g., Meta Ad Preferences, Google Ad Settings, TikTok privacy settings)
  • Email support@salt-escapes.com to object to profiling

We do not use automated decision-making that produces legal or similarly significant effects on you.

8. Cookies and tracking technologies

What are cookies?

Cookies are small text files stored on your device when you visit a website. They help websites work properly, remember your preferences, and understand how visitors use the site.

Our consent mechanism:

We use a cookie consent mechanism that operates using Google Consent Mode v2. When you first visit our site, a consent banner appears asking you to accept or decline non-essential cookies.

  • Essential cookies are set without consent (they are necessary for the site to function).
  • Analytics and marketing cookies are only set if you give consent.
  • Your consent preference is stored in the se_consent cookie for 1 year.
  • We detect whether you are visiting from a region with stricter consent requirements (e.g., UK/EEA) and adjust our consent mechanism accordingly, using the se_geo_eea cookie.

You can change your cookie preferences at any time by clearing your cookies or using the consent management option on our website.

Essential / Functional cookies:

CookieProviderPurposeDuration
se_consentSalt EscapesStores your cookie consent preferences1 year
se_geo_eeaSalt EscapesDetects whether regional consent rules apply30 days
intercom-id-*IntercomIdentifies your chat session9 months
intercom-device-id-*IntercomIdentifies your device for chat continuity9 months
intercom-session-*IntercomMaintains active chat session1 week

Analytics cookies:

CookieProviderPurposeDuration
_gaGoogle AnalyticsDistinguishes unique visitors2 years
_ga_* (x5 streams)Google AnalyticsMaintains session state per data stream2 years
FPLCGoogleCross-domain measurementSession
FPGSIDGoogleSession-level linkingSession
FPAUGoogleFirst-party attribution30 days
_clckMicrosoft ClarityIdentifies returning visitors for session recording1 year

Marketing cookies:

CookieProviderPurposeDuration
_fbpMeta (Facebook)Tracks visits for ad targeting3 months
_ttpTikTokTracks visits for ad targeting13 months
_gcl_auGoogle AdsAttributes conversions to ad clicks3 months
__kla_idKlaviyoIdentifies visitors for email marketing2 years
_dcidDoubleClick (Google)Ad conversion trackingSession

First-party tracking cookies:

CookieProviderPurposeDuration
se_visitor_idSalt EscapesIdentifies visitors across sessionsPersistent
se_ga_client_idSalt EscapesMirrors Google Analytics client ID for server-side usePersistent
se_fbpSalt EscapesMirrors Meta browser ID for server-side usePersistent

9. Server-side tracking

TechnologyWhat it does
Meta Conversions API (CAPI)Sends conversion events (e.g., page views, bookings) from our server to Meta. This supplements the Meta Pixel and may include hashed email addresses, IP addresses, and browsing data.
Server-side Google AnalyticsSends analytics data from our server to Google. This supplements the browser-based GA4 tag.

Server-side tracking is subject to the same consent rules as browser-based tracking. If you decline marketing or analytics cookies, we respect that choice for server-side data too.

10. Who we share your data with

ProcessorPurposeData sharedServer location
VercelWebsite hostingServer logs, IP addresses, browsing dataUS / Global CDN
SupabaseDatabase and backend servicesAll customer data (encrypted at rest)Australia (Sydney)
StripePayment processingPayment card data, billing informationUS
ShopifyE-commerce and order managementOrder details, customer dataCanada / US
KlaviyoEmail marketing and automationsEmail address, behaviour, purchase historyUS
GoogleAnalytics, advertising, tag orchestrationIP address, browsing data, conversionsUS
MetaAdvertisingBrowsing behaviour, conversions, hashed identifiersUS
TikTokAdvertisingBrowsing behaviour, conversionsSingapore / US
Microsoft ClaritySession recording and heatmapsMouse movements, clicks, scrolling behaviourUS
IntercomCustomer chat and supportChat transcripts, email address, browsing dataUS
TypeformForms and surveysForm responsesEU
PandaDocContract managementContractor personal dataUS

We may also share data:

  • With retreat venues, fitness instructors, and catering providers — limited to the information they need to deliver your retreat safely (including health data where you have given explicit consent)
  • With professional advisers (accountants, lawyers) — where necessary for legal or financial obligations
  • With law enforcement or regulators — where required by law
  • In the event of a business sale or restructure — any buyer would be required to continue protecting your data under this policy

We never sell your personal data.

11. International data transfers

CountryProcessorsTransfer mechanism
United StatesVercel, Stripe, Shopify, Google, Meta, TikTok, Klaviyo, Intercom, Microsoft, PandaDocUK-US Data Bridge / IDTA / Standard Contractual Clauses
AustraliaSupabaseInternational Data Transfer Agreement (IDTA)
CanadaShopifyUK adequacy decision
EUTypeformUK adequacy decision for EU/EEA
SingaporeTikTokIDTA / Standard Contractual Clauses

All international transfers are made in compliance with Chapter V of UK GDPR, using one or more of:

  • UK adequacy decisions — where the UK government has determined a country provides adequate data protection
  • International Data Transfer Agreements (IDTAs) — the UK-specific replacement for Standard Contractual Clauses
  • Standard Contractual Clauses (SCCs) — EU-approved contractual terms, supplemented where necessary by a Transfer Risk Assessment

You can request a copy of the relevant transfer safeguards by emailing support@salt-escapes.com.

12. How long we keep your data

Data typeRetention periodReason
Website analytics data (aggregated)26 monthsGA4 default retention; aggregated data kept for trend analysis
Cookie identifiersVaries (see Section 8)As per individual cookie durations
Newsletter subscriber dataUntil you unsubscribe + 30 daysNeeded to process your unsubscribe; then deleted
Enquiry and pre-registration data3 years from last contactTo follow up on interest and for business records
Booking and customer data7 years from retreat dateUK tax and accounting obligations (HMRC)
Health and special category data1 year after retreat completionRetained briefly for post-retreat follow-up and safety records; then securely deleted
Passport details6 months after retreat completionNo longer needed once travel is complete
Payment records7 years from transactionUK tax and accounting obligations (HMRC)
Emergency contact dataDeleted within 30 days of retreat completionNo longer needed
Photos and videoIndefinite (with consent)Used for marketing; deleted on withdrawal of consent
Chat transcripts (Intercom)2 years from conversationCustomer service records
Contractor data7 years from end of contractUK tax and accounting obligations
Session recordings (Clarity)30 daysAutomatically purged by Microsoft Clarity

When retention periods expire, data is securely deleted or irreversibly anonymised.

13. Your rights

Under UK GDPR, you have the following rights over your personal data. These rights are free to exercise — we will not charge a fee unless a request is manifestly unfounded or excessive.

  1. 1
    Right of access (Subject Access Request): You can ask for a copy of all the personal data we hold about you. We will respond within one calendar month. If your request is complex, we may extend this by a further two months, but we will tell you within the first month.
  2. 2
    Right to rectification: If any of your personal data is inaccurate or incomplete, you can ask us to correct or complete it.
  3. 3
    Right to erasure ("right to be forgotten"): You can ask us to delete your personal data. We will do so unless we have a lawful reason to keep it (for example, tax records we are legally required to retain).
  4. 4
    Right to restrict processing: You can ask us to limit how we use your data while a concern is being resolved — for example, if you dispute its accuracy.
  5. 5
    Right to data portability: You can ask for your personal data in a structured, commonly used, machine-readable format (e.g., CSV or JSON) so you can transfer it to another provider. This applies to data you provided to us, processed by automated means, on the basis of consent or contract.
  6. 6
    Right to object: You can object to processing based on legitimate interest or for direct marketing purposes. If you object to direct marketing, we will stop immediately.
  7. 7
    Rights related to automated decision-making and profiling: You have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal or similarly significant effects. We do not currently make any such decisions. Our advertising profiling (see Section 7) does not produce legal or similarly significant effects.
  8. 8
    Right to withdraw consent: Where we process your data based on consent (e.g., marketing emails, health data, cookies), you can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before you withdrew.

How to exercise your rights:

Email: support@salt-escapes.com

Please include enough information for us to verify your identity (your name and the email address you used with us). We will respond within one calendar month.

If we cannot fulfil your request (for example, if a legal obligation requires us to keep certain data), we will explain why.

14. Children's data

Our retreats and services are designed for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18.

If we discover that we have collected data from a child, we will delete it promptly. If you believe we hold data about someone under 18, please contact us at info@salt-escapes.com.

15. Data security

We take the security of your personal data seriously. Our measures include:

  • Encryption in transit — all data transmitted to and from our website uses HTTPS/TLS encryption
  • Encryption at rest — customer data stored in our database (Supabase) is encrypted at rest
  • Access controls — only authorised staff and contractors can access personal data, on a need-to-know basis
  • Payment security — card payments are handled by Stripe, which is PCI DSS Level 1 certified. We never see or store your full card number.
  • Regular reviews — we periodically review our security practices and the security posture of our processors

No system is completely secure. If you have concerns about the security of your data, please contact us.

16. Data breaches

If we become aware of a personal data breach that poses a risk to your rights and freedoms:

  • We will notify the ICO within 72 hours of becoming aware of the breach, as required by Article 33 UK GDPR.
  • If the breach poses a high risk to you, we will notify you without undue delay, as required by Article 34 UK GDPR.
  • We will explain what happened, what data was affected, what we are doing about it, and what you can do to protect yourself.

17. Changes to this policy

We may update this policy from time to time. When we make significant changes, we will:

  • Update the “Last updated” date at the top of this document
  • Where appropriate, notify you by email or through a notice on our website

We encourage you to review this policy periodically.

18. How to contact us

If you have any questions about this policy or how we handle your personal data:

Email: support@salt-escapes.com

Post: Salt Escapes Ltd, 24 Chelsfield Gardens, London, SE26 4DJ, United Kingdom

19. How to complain

If you are unhappy with how we have handled your personal data, we would like the chance to put things right. Please contact us first at support@salt-escapes.com.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Website: ico.org.uk

Phone: 0303 123 1113

Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Salt Escapes Ltd · Company Number 11086084 · Registered in England and Wales · support@salt-escapes.com

Salt Escapes

Fitness retreats with an adventurous side.

support@salt-escapes.com

Destinations

  • Zakynthos
  • Ibiza
  • Menorca
  • Costa Rica
  • Portugal
  • Caribbean

Learn More

  • What to Expect
  • Availability
  • Pre-Register

Company

  • Our Story
  • Careers
  • Contact Us
  • FAQs

Legal

  • Privacy Policy
  • Booking Terms

© 2018-2026 Salt Escapes. All rights reserved.