Privacy Policy
Last updated: August 2026
1. Who We Are
The Breathing Organization ("TBO", "we", "us", "our") is operated by THE BREATHING ORGANIZATION (TBO) PTE. LTD., registered in Singapore. We provide a platform connecting breathwork practitioners ("Breathers") with certified Facilitated Breath Repatterning facilitators ("Facilitators"). This Privacy Policy explains how we collect, use, store, and protect your personal data in accordance with the Singapore Personal Data Protection Act (PDPA), the EU General Data Protection Regulation (GDPR) where applicable, and other relevant data protection laws.
Our data protection contact: privacy@thebreathing.org
2. Information We Collect
We collect the following categories of personal data:
2.1 Account Information
- Full name, email address, and phone number
- Date of birth (to verify minimum age requirements)
- Profile photo (optional)
- Account credentials (managed through Supabase Auth)
2.2 Booking & Payment Data
- Session bookings, history, and preferences
- Payment information (processed exclusively by Stripe; we do not store card details)
- Cancellation and refund records
- Package and bundle purchase history
2.3 Health & Wellbeing Data (Special Category Data)
To ensure participant safety, we collect sensitive health information through:
- Participation Agreement & Health Declaration (Waiver) — Physical and psychological health conditions, contraindications (e.g. heart conditions, epilepsy, pregnancy, psychiatric history), medications, and relevant personal circumstances. This is required before your first session.
- Pre-Session Check-ins — Current physical and emotional state, intentions, energy levels, and any acute health updates before each session.
- Post-Session Reflections — Self-reported experience outcomes, emotional state after the session, physical sensations, and subjective wellbeing indicators.
- Health Updates — Ongoing changes to your health status that you voluntarily report between sessions.
This health data is collected with your explicit consent and is necessary for the facilitator to hold a safe space and adapt sessions to your needs.
2.4 Facilitator-Specific Data
- Professional biography, specialties, and qualifications
- Availability schedules and location information
- Session observations and facilitator debriefs (for professional development)
- Revenue, payout, and commission data
- Gallery images and public profile content
2.5 Technical & Usage Data
- IP address, browser type, and device information
- Pages visited, interaction patterns, and session duration
- Cookies for authentication and session management
3. Legal Basis for Processing
We process your data on the following bases:
- Contract performance — Processing necessary to provide our platform services, process bookings, and manage payments.
- Explicit consent — Health and wellbeing data is processed based on your explicit consent, which you provide when completing the Participation Agreement.
- Legitimate interest — Platform security, fraud prevention, service improvement, and analytics.
- Legal obligation — Financial record-keeping, tax compliance, and responding to lawful requests.
4. How We Use Your Information
- Provide and improve our platform services
- Process bookings, payments, and refunds
- Send booking confirmations, session reminders, and waiver requests
- Enable facilitators to review health declarations and check-in data to ensure participant safety
- Generate anonymized insights to help facilitators track progress and improve their practice
- Match you with relevant facilitators and sessions based on preferences
- Maintain platform security and prevent misuse
- Comply with legal and financial obligations
5. Data Sharing & Third Parties
We share data with the following parties, only to the extent necessary:
- Your Facilitator(s) — Name, booking details, health declaration, pre-session check-in data, and post-session reflections. Facilitators are bound by confidentiality obligations.
- Hub/Organization Administrators — Booking activity and aggregate participation data for events organized through their hub.
- Stripe — Payment processing. Stripe acts as an independent controller for payment data. See Stripe's Privacy Policy.
- Supabase — Infrastructure provider for data storage and authentication (data processor).
- Vercel — Website and application hosting (data processor).
- Email service providers — For transactional emails (booking confirmations, reminders).
We do not sell your personal data to third parties. We do not use your data for advertising purposes.
6. Health Data: Special Protections
Your health and wellbeing data receives enhanced protection:
- Access is restricted to your assigned facilitator(s) and platform administrators where necessary for safety.
- Health data is encrypted at rest and in transit.
- Row-level security policies ensure only authorized users can access specific records.
- You can update your health declaration at any time if your circumstances change.
- You can request deletion of health data at any time (subject to safety considerations for upcoming bookings).
- Pre/post session check-in responses are linked to specific bookings and accessible only to the booking's facilitator.
7. Data Storage & Security
- Data is stored on secure cloud infrastructure with industry-standard certifications.
- Data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
- We implement row-level security (RLS) to ensure strict access control at the database level.
- Payment card details are never stored on our servers — they are handled exclusively by Stripe (PCI DSS Level 1 certified).
- Access to production systems is restricted to authorized personnel with multi-factor authentication.
8. Your Rights
You have the following rights regarding your personal data:
- Access — Request a copy of all data we hold about you.
- Correction — Correct inaccurate or incomplete data.
- Erasure — Request deletion of your account and personal data.
- Data portability — Receive your data in a structured, machine-readable format.
- Withdraw consent — Withdraw consent for health data processing at any time (this does not affect the lawfulness of prior processing).
- Complaint — Lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore, or your local data protection authority.
To exercise your rights, contact us at privacy@thebreathing.org. We will respond within 30 days.
9. Data Retention
- Active accounts — Data is retained for as long as your account is active.
- After account deletion — Personal data is deleted within 30 days. Anonymized aggregate data may be retained for analytics.
- Health declarations — Retained while you have an active account or active bookings. Deleted upon account deletion or withdrawal of consent.
- Session check-ins & reflections — Retained for the duration of your account. Available for deletion upon request.
- Financial records — Booking and payment records are retained for 5 years as required by applicable financial regulations.
- Facilitator debrief notes — Retained for professional development purposes while the facilitator's account is active. Client-identifiable information is deleted upon client request.
10. Cookies & Tracking
We use only essential cookies for:
- Authentication and session management
- Preventing cross-site request forgery (CSRF)
- Remembering user preferences
We do not use tracking cookies, third-party advertising cookies, or analytics cookies that profile individual users.
11. International Data Transfers
As a global platform, your data may be processed in jurisdictions outside of your country of residence. Where data is transferred internationally, we ensure appropriate safeguards are in place, including contractual protections with our service providers. By using our platform, you consent to such transfers as necessary to provide our services.
12. Children's Privacy
Our services are not intended for persons under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us immediately at privacy@thebreathing.org.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notice at least 14 days before the changes take effect. The "Last updated" date at the top indicates when this policy was last revised.
14. Contact
For privacy-related inquiries, data access requests, or complaints:
- Email: privacy@thebreathing.org
- Entity: THE BREATHING ORGANIZATION (TBO) PTE. LTD., Singapore