Privacy Policy
Last updated: March 2026
This policy explains what data I collect when you use this site and your sessions with me, why I use it, and how you can exercise your rights. I take your privacy seriously and hold your information in strict confidence.
Who is responsible for your data
Mark Spall operates this website and the booking, session, and referral services described below. For the purposes of UK and EU data protection law, I am the data controller. If you have questions, you can reach me via the contact details in your booking confirmation or on this site.
What data I collect and why
Bookings and sessions
When you book or pay for a session, I collect: your name, email address, and (if you provide it) phone number for WhatsApp. I use this to confirm your booking, send you the Zoom link and preparation materials, and communicate with you about your session. Payment is processed by Stripe; I do not store your card number. Stripe’s privacy policy applies to payment data.
Session recordings and any notes are held securely and used only to support the quality of our work together (as described in the Terms of Service). They are never shared with third parties.
Waitlist
If you join the waitlist, I collect your email address to notify you when new slots become available. You can ask to be removed at any time.
Referrals
If you use the “Get my referral link” feature, I collect the contact method you choose (email or phone number) to send you your personal referral link and to attribute any referral reward if someone books via your link. Referral tracking on this site uses local storage in your browser (not cookies) to remember that you arrived via a referral link; that data is kept for 30 days and is used only to apply the correct reward when a booking is made.
General site use
The site is hosted on Cloudflare. Like most websites, it may receive and log technical data such as your IP address and browser type for security and operation. I do not use this for marketing or profiling.
Cookies and local storage
I use only what is necessary to run the service:
- Stripe — When you use the booking or payment forms, Stripe may set a cookie (for example
__stripe_mid) for fraud prevention. This is essential for secure payments. - Referral tracking — If you arrive via a referral link, the site stores a small amount of data in your browser’s local storage (
mas_ref,mas_ref_ts,mas_ref_landing) for up to 30 days so that your referral can be recognised if you book. This supports the referral feature you or the person who shared the link chose to use.
I do not use advertising or analytics cookies. No cookies or local storage are used for tracking you across other websites.
Who I share data with
I do not sell or rent your data. I share it only where necessary:
- Stripe — For payment processing (card details stay with Stripe).
- Zoom — To create and manage your session meeting.
- Email delivery — Emails are sent via Amazon SES (or similar) so you receive confirmations and messages.
These providers are bound by their own privacy and data processing terms. I do not share session content, recordings, or notes with anyone unless required by law or with your explicit permission.
How long I keep data
Booking and session data (including recordings and notes) are retained for as long as needed to support our work together and to meet legal and accounting requirements. Waitlist and referral data are kept only as long as needed for those features. You can ask for your data to be deleted at any time (see Your rights below).
Your rights
Under UK and EU data protection law you have the right to:
- Access the personal data I hold about you.
- Have incorrect data corrected.
- Request deletion of your data.
- Object to or restrict certain processing.
- Receive a portable copy of your data.
If you have a booking, you can manage your booking from the link in your confirmation email. From there you can download your data (PDF or JSON) and request deletion of your data.
For any other request or question about your data, contact me using the details in your confirmation email or on this site. I will respond within 30 days. You also have the right to complain to the Information Commissioner’s Office (ICO) in the UK.
Changes to this policy
I may update this policy from time to time. The “Last updated” date at the top will change when I do. Continued use of the site or services after an update means you accept the revised policy.