Privacy Policy
Last updated: 1 July 2025
Somafield ("we", "us", or "our") operates the website at somafield.co and related services (the "Platform"). This Privacy Policy explains what personal data we collect, how we use it, and the rights you have under the EU General Data Protection Regulation (GDPR) and the UK GDPR.
1. Who we are
Somafield is the data controller for personal data processed through the Platform. You can reach us at hello@somafield.co.
2. What data we collect
- Account and profile data: name, email address, location, professional biography, training and credentials, links to your website and social profiles.
- Booking data: session type, date and time, notes you choose to share with the practitioner, and communication tied to a booking.
- Payment data: when you pay for a session, payments are processed by Stripe. We receive only limited billing metadata (amount, currency, status, last four digits of card). We do not store full payment card details.
- Application data: if you apply to join Somafield as a practitioner, we collect the information you submit in the application form.
- Technical data: basic server logs (IP address, browser type, timestamps) needed to keep the Platform secure and running.
3. How we use your data
We use personal data to:
- Operate and secure the Platform.
- Publish practitioner profiles and enable bookings.
- Process payments and payouts.
- Send transactional emails (booking confirmations, reminders, account notifications).
- Review applications and communicate about them.
- Comply with legal obligations.
Our legal bases under the GDPR are: performance of a contract with you, our legitimate interest in running a trustworthy Platform, your consent (where required), and compliance with law.
4. Third parties who process data on our behalf
- Stripe — payment processing (privacy policy).
- Resend — transactional email delivery (privacy policy).
- Supabase — database, authentication, and file storage hosting (privacy policy).
Each of these providers has been chosen because it offers appropriate safeguards and data-processing agreements consistent with the GDPR. Where data is transferred outside the EEA, transfers rely on Standard Contractual Clauses or equivalent safeguards.
5. How long we keep data
We keep personal data only for as long as needed for the purposes above, or as required by law. Booking and payment records are retained for accounting purposes. Account data is deleted on request, subject to legal retention requirements.
6. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your data ("right to be forgotten").
- Restrict or object to certain processing.
- Receive a portable copy of your data.
- Withdraw consent at any time.
- Lodge a complaint with your local data-protection authority.
To exercise any of these rights, email hello@somafield.co.
7. Cookies
We use only the minimum cookies and browser storage needed to keep you signed in and to remember essential preferences. We do not use advertising or cross-site tracking cookies.
8. Security
Data is encrypted in transit (HTTPS). Access to production data is restricted to authorised personnel. We take reasonable steps to protect personal data, but no online service can guarantee absolute security.
9. Changes to this policy
We may update this policy from time to time. Material changes will be announced on the Platform or by email.
10. Contact
Questions or requests: hello@somafield.co.