
Introduction
Spiral Source Ayurveda ("I," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.
Please read this Privacy Policy carefully. By using our services or website, you agree to the collection and use of information in accordance with this policy.
Information We Collect
Personal Information
We may collect personal information that you voluntarily provide to us when you:
- Schedule an appointment or consultation
- Fill out forms on our website
- Subscribe to our newsletter or communications
- Contact us via email, phone, or contact forms
- Create an account on our website
This information may include:
- Name
- Email address
- Phone number
- Mailing address
- Date of birth
- Payment information
Health Information
As an Ayurvedic and wellness service provider, we collect sensitive health information necessary to provide our services, including:
- Medical history
- Current health conditions and symptoms
- Lifestyle habits and practices
- Dietary preferences and restrictions
- Medications and supplements
- Mental and emotional health information
- Family health history
- Information about past trauma (when voluntarily disclosed)
Automatically Collected Information
When you visit our website, we may automatically collect certain information about your device and usage, including:
- IP address
- Browser type and version
- Pages visited and time spent on pages
- Referring website addresses
- Device information (type, operating system)
- Cookies and similar tracking technologies
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our Ayurvedic and yoga services
- Develop personalized wellness protocols and recommendations
- Schedule and manage appointments
- Communicate with you about services, appointments, and updates
- Process payments and maintain financial records
- Send educational content, newsletters, and promotional materials (with your consent)
- Respond to your inquiries and provide customer support
- Comply with legal obligations and maintain records
- Analyze and improve our website and services
- Prevent fraud and ensure security
Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), our legal basis for collecting and using your personal information depends on the specific information and context:
- Consent: You have given clear consent for us to process your personal information for specific purposes
- Contract: Processing is necessary to perform our services under our agreement with you
- Legal Obligation: Processing is necessary to comply with the law
- Legitimate Interests: Processing is necessary for our legitimate interests, provided those interests do not override your rights
How We Share Your Information
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
Service Providers
We may share your information with trusted third-party service providers who assist us in operating our website and delivering our services, such as:
- Payment processors
- Scheduling and appointment software providers
- Email marketing platforms
- Website hosting services
- Cloud storage providers
These service providers are contractually obligated to protect your information and use it only for the purposes we specify.
Legal Requirements
We may disclose your information if required to do so by law or in response to:
- Valid legal processes (subpoenas, court orders)
- Government or regulatory requests
- Protection of our rights, property, or safety
- Prevention of fraud or illegal activity
- Compliance with applicable laws and regulations
Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. You will be notified of any such change.
With Your Consent
We may share your information with third parties when you have given us explicit consent to do so.
HIPAA Compliance Notice
While Ayurvedic practitioners are not typically covered entities under HIPAA (Health Insurance Portability and Accountability Act), we recognize the sensitive nature of health information and implement privacy practices that align with HIPAA principles to protect your health information.
Data Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Secure Socket Layer (SSL) encryption for data transmission
- Encrypted storage of sensitive information
- Restricted access to personal information on a need-to-know basis
- Regular security assessments and updates
- Secure password protocols
- Regular staff training on privacy and security practices
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Health and consultation records are typically retained for a minimum of seven years in accordance with industry best practices and legal requirements.
When we no longer need your information, we will securely delete or anonymize it.
Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
General Rights
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information (subject to legal obligations)
- Objection: Object to our processing of your personal information
- Restriction: Request restriction of processing of your information
- Data Portability: Request transfer of your information to another service provider
- Withdraw Consent: Withdraw consent for processing where consent is the legal basis
California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising your CCPA rights
European Residents (GDPR)
If you are located in the EEA, you have rights under the General Data Protection Regulation, including those listed above, plus:
- Right to lodge a complaint with a supervisory authority
- Right to object to processing based on legitimate interests
- Right to withdraw consent at any time
How to Exercise Your Rights
To exercise any of these rights, please contact us using the information provided in the "Contact Us" section below. We will respond to your request within 30 days (or as required by applicable law).
Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your experience. Cookies are small files stored on your device that help us:
- Remember your preferences and settings
- Understand how you use our website
- Improve website functionality and performance
- Provide personalized content
You can control cookie settings through your browser preferences. Note that disabling cookies may affect the functionality of our website.
Third-Party Links
Our website may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.
Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children without parental consent. If you are a parent or guardian and believe your child has provided us with personal information, please contact us, and we will delete such information.
Marketing Communications
With your consent, we may send you promotional emails, newsletters, and other communications about our services. You can opt out of marketing communications at any time by:
- Clicking the "unsubscribe" link in our emails
- Contacting us directly with your request
- Updating your communication preferences in your account settings
Please note that even if you opt out of marketing communications, we may still send you non-promotional messages related to your account or services.
International Data Transfers
If you are located outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located. By using our services, you consent to the transfer of your information to the United States.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:
- Posting the updated policy on our website
- Updating the "Last Updated" date at the top of this policy
- Sending you an email notification (for significant changes)
Your continued use of our services after any changes constitutes acceptance of the updated Privacy Policy.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Spiral Source Ayurveda
Email: [email protected]
Address: Tucson, AZ

View our Privacy Policy and Terms and Conditions here.
© 2026. All Rights Reserved.
photos: TT 🤍 JL 🤍 SD 🤍 KD




