PranaRoot

Privacy Policy

Last updated: August 2026

PranaRoot (“we”, “us”, “our”) is a booking and studio management platform for yoga, Pilates, dance, martial arts, meditation, and wellness/beauty teachers. This Privacy Policy explains what data we collect, how we use it, and what rights you have over it.

1. Data we collect

For teachers (studio owners):

  • Name, email address, and password (for your account)
  • Studio name and public booking URL slug
  • Timezone and plan details
  • Your Stripe restricted API key and a webhook signing secret, if you connect Stripe to accept student payments — these are encrypted at rest (via Supabase Vault) and are used only to create charges, refunds, and subscriptions on your own Stripe account on your behalf. We never see or log the key in plain text after you save it, and it is never sent to your browser or any third party other than Stripe itself.

For students (people who book classes):

  • Name, email address, and phone number (provided when booking)
  • WhatsApp number (if provided, used only for class reminders)
  • Health and injury notes — entered by the teacher and visible only to that teacher. This is considered sensitive health data and is never shared with third parties.
  • Booking history and payment status

2. How we use your data

  • To provide the PranaRoot service — bookings, class management, student rosters
  • To send booking confirmation emails and class reminders
  • To process payments via Stripe, using each teacher's own connected Stripe account
  • To send WhatsApp reminders once that feature launches, if you have provided a WhatsApp number and the teacher has enabled reminders
  • We do not sell your data to any third party, ever

3. Health and injury notes

Teachers can record health notes (e.g. injuries, physical limitations) against a student profile. This information is:

  • Visible only to the teacher who entered it
  • Never shared with other users, third parties, or displayed publicly
  • Stored encrypted at rest by our database provider (Supabase / PostgreSQL)
  • Deletable at any time by the teacher or by contacting us

4. Third-party services

We use the following services to operate PranaRoot:

  • Supabase — database and authentication hosting. Your data is stored on Supabase's servers. A teacher's Stripe key is stored in Supabase Vault, an encryption layer separate from our regular database tables.
  • Stripe — payment processing. Each teacher connects their own Stripe account; card details are handled entirely by Stripe and never pass through our servers.
  • Paddle — billing for teacher subscription plans (Studio / Premium). Paddle acts as merchant of record and handles all card details for these subscriptions.
  • Resend — transactional email delivery (booking confirmations, alerts).
  • Vercel — application hosting and infrastructure.
  • PostHog — product analytics, so we can see which parts of PranaRoot are used and improve them. PostHog receives page addresses and product events (for example “a class was booked”) together with an anonymous identifier. It does not receive student names, email addresses, health notes, or payment details.
  • Sentry — error reporting, so we find out when something breaks. Sentry receives technical error details and is configured not to collect personal data.

5. Data retention

We retain your data for as long as your account is active. If you delete your account, your data is permanently deleted within 30 days, except where we are legally required to retain financial records (typically 7 years for payment records).

6. Your rights

You have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Withdraw consent for WhatsApp communications at any time
  • Export your data — teachers can download a complete machine-readable archive of their whole studio from Settings → Your data, and per-page CSVs of students and payments from those pages

To exercise any of these rights, email us at privacy@pranaroot.com.

If you are a student rather than a teacher: your booking, attendance, and pass records belong to the studio you booked with — they are the data controller and we process that data on their behalf. Ask your studio directly for a copy or for deletion, and they can action it from their dashboard. If they don't respond, write to us at the address above and we will help you reach them.

7. Cookies

Essential cookies. Authentication session cookies (set by Supabase) keep you signed in. When a teacher opens the subscription checkout, Paddle may set cookies required to process the payment. These are necessary for the service to work and are always active.

Analytics. We use PostHog to understand how PranaRoot is used. Until you accept analytics cookies, PostHog runs in a memory-only mode that stores nothing at all on your device and cannot recognise you on a later visit. If you accept, it stores a single identifier so we can tell a returning visitor from a new one. You can decline without losing any functionality, and you can change your mind at any time by clearing this site's cookies and site data in your browser.

We do not use advertising cookies or third-party tracking cookies, and we never sell your data.

8. Contact

For any privacy questions or requests, contact us at privacy@pranaroot.com. We aim to respond within 48 hours.