Privacy Policy

Last updated: 2 July 2026

1. Who we are

YogaTimer ("we", "us", "our") is operated from the United Kingdom. For the purposes of the UK GDPR and the Data Protection Act 2018, we are the data controller of the personal information you provide when using our service at https://yogatimer.co.uk.

Contact for privacy matters: support@yogatimer.co.uk.

2. What data we collect

  • Account data: email address, display name, first name and surname (optional), password (hashed by Supabase; we never see the plain text).
  • Sequences you create: titles, descriptions, poses, timings, and any notes you add.
  • Live session data: timestamps of when you started, paused, or completed a class; move changes; audio-cue events; wake-lock and offline recovery events.
  • Bluetooth remote events: when a paired remote clicks, disconnects, or reconnects. We do not receive audio or video from the remote.
  • Billing data: Stripe stores your card details and billing address. We store only your Stripe customer ID, your subscription status, and renewal dates.
  • Technical data: IP address (for rate limiting and abuse prevention only, not stored long-term), browser type, timestamps of requests, and error diagnostics.

3. Why we process your data (lawful basis)

  • To provide the service (contract): account creation, sequence storage, live session playback, subscription billing.
  • To secure the service (legitimate interest): rate limiting, brute-force protection, error monitoring.
  • To comply with legal obligations: retaining financial records for HMRC as required by UK tax law.

We do not sell your data, and we do not use your data for advertising.

4. Who we share data with (sub-processors)

We use the following trusted third-party services to run YogaTimer. Each has its own GDPR-compliant Data Processing Agreement in place:

  • Supabase - authentication and database hosting (EU region).
  • Stripe - payment processing.
  • Vercel - frontend web hosting.
  • Railway - API server hosting.
  • Resend - transactional email (password resets, account confirmations).

5. How long we keep your data

  • Account and sequence data: for as long as your account is active. Deleted immediately when you delete your account.
  • Live session and Bluetooth event data: for as long as your account is active.
  • Billing records: 6 years after the last transaction, as required by UK tax law.
  • Server logs: 30 days maximum.

6. Your rights under UK GDPR

You have the right to:

  • Access - request a copy of your data. Available instantly from your account page (Download my data button).
  • Rectification - correct inaccurate data. Edit your profile in the app or contact us.
  • Erasure - delete your account and all associated data. Available from your account page (Delete my account button).
  • Portability - export your data in JSON format. Same button as Access above.
  • Object or restrict processing - contact us at support@yogatimer.co.uk.
  • Complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

7. Cookies

We use strictly necessary cookies to keep you signed in (Supabase authentication session). We do not use tracking cookies or third-party analytics cookies. A consent banner is not required for strictly necessary cookies under UK ePrivacy rules.

8. International transfers

Our data is hosted primarily in the EU (Supabase). Stripe may process payment data in the US under Standard Contractual Clauses. All transfers are governed by UK GDPR-compliant safeguards.

9. Data breaches

In the unlikely event of a personal data breach that risks your rights and freedoms, we will notify the ICO within 72 hours and, where required, notify you directly by email.

10. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email or via a banner in the app. The "Last updated" date at the top of this page reflects the latest revision.