Skip to main content

Privacy Policy

Last Updated: March 12, 2026

1. Introduction & Controller Identity

This Privacy Policy explains how MARKET-IN Yoga Studio (“we”, “us”, or “our”) collects, uses, and protects your personal data when you visit this website (the “Site”), contact us, or request information about classes, programs, and private sessions in Paris, France.

For the purposes of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the French Data Protection Act (Loi Informatique et Libertés), the data controller is:

  • Legal entity: MARKET-IN SAS
  • Studio name: MARKET-IN Yoga Studio
  • Registered address: 58 Rue de Monceau, 75008 Paris, France
  • Email: [email protected]
  • Telephone: +33 1 42 68 53 27

We do not appoint a Data Protection Officer (DPO) because we do not carry out large-scale monitoring of individuals or large-scale processing of special-category data. If that changes, we will update this policy and provide DPO contact details.

Effective date of this policy: March 12, 2026.

2. Personal Data We Collect

We collect personal data that you provide to us directly and data that is collected automatically when you use the Site. The categories below describe what we may process depending on how you interact with us.

  • Identity and contact details: name, email address, telephone number.
  • Form content: the message you send, preferred class type, scheduling preferences, and any details you choose to include so we can respond to your request.
  • Technical data: IP address, browser type and version, device type, operating system, language settings, and approximate location derived from IP (city-level).
  • Usage data: pages viewed, time spent, navigation paths, referrer information, and interactions such as clicks and form submissions.
  • Cookies and identifiers: first- and third-party cookie identifiers and similar technologies as described in Section 4.
  • Conversion events: signals that indicate a user completed an action (for example, a form submission or a request for schedule information), used for measurement and troubleshooting.

We do not intentionally collect special-category data (such as health data, religious beliefs, political opinions, genetic or biometric data) through this Site. We also do not request payment card numbers, bank account details, or government-issued identifiers through our contact forms. If you include sensitive information in a message, we will treat it carefully and use it only to respond, but we encourage you to keep messages practical and limited to what is necessary for scheduling and class recommendations.

3. Why We Process Personal Data & Legal Basis (GDPR Article 6)

We process personal data only where we have a lawful basis under GDPR. The table below describes the main purposes and legal bases that apply to our Site and studio operations.

  • Responding to contact and booking requests: to reply to enquiries, suggest appropriate class options, and coordinate scheduling by email or phone. Legal basis: GDPR Art. 6(1)(b) (steps prior to entering into a contract) and, where required, GDPR Art. 6(1)(a) (consent).
  • Providing and improving the Site: to maintain functionality, diagnose issues, and keep the Site secure. Legal basis: GDPR Art. 6(1)(f) (legitimate interests in operating a secure and reliable website).
  • Analytics: to understand aggregated usage patterns and improve content and performance. Legal basis: GDPR Art. 6(1)(a) (consent), where consent is required for analytics cookies.
  • Marketing and remarketing: to measure advertising performance and show relevant ads to people who have previously visited the Site. Legal basis: GDPR Art. 6(1)(a) (consent) for marketing cookies and pixels.
  • Legal and compliance obligations: to comply with applicable laws, respond to lawful requests, and enforce our Terms of Service. Legal basis: GDPR Art. 6(1)(c) (legal obligation).

Automated decision-making (GDPR Article 22): We do not engage in automated decision-making or profiling that produces legal or similarly significant effects. If we use audience segmentation for marketing measurement, it is used only for ad delivery optimization and does not create legal consequences for you.

4. Cookies & Tracking

Cookies are small text files stored on your device. We also use similar technologies such as pixel tags and server-side event forwarding in limited cases. Some cookies are necessary for the Site to work; others are optional and require your consent.

We group cookies into three categories that match our Cookie Policy:

Essential (always active)

Essential cookies are required for basic Site functionality, such as session continuity and storing your cookie consent preferences. These cookies do not require consent under applicable rules when they are strictly necessary to provide the service you request.

  • _site_session: helps keep a session consistent while you navigate the Site.
  • cookie_consent: stores your cookie category choices so we can respect them on future visits.

Typical retention: session to 12 months (depending on the cookie’s function and your browser settings).

Analytics (consent)

If you opt in, we may use analytics tools (for example, Google Analytics 4) to understand how visitors use the Site. Where available, IP anonymization is used. Analytics data is used in aggregated form to improve content, identify performance issues, and understand which pages are most useful.

  • Examples: _ga (2 years), _ga_XXXXXXXXXX (2 years).
  • Analytics retention setting (typical): 14 months.

Marketing (consent)

If you opt in, we may use marketing cookies and pixels (for example, Google Ads and Meta technologies) to measure conversions, perform remarketing, and build audience groups such as custom or lookalike audiences. These tools can use cookie identifiers and events such as page views or form submissions to attribute advertising results.

  • Examples: _gcl_au (90 days), _fbp (90 days), _fbc (90 days when click ID is present).

Beyond cookies, some measurement setups can involve pixel tags (loaded in the browser) or server-side event forwarding. When we use server-side measurement, we use it to improve reliability and reduce duplicated events. If identifiers are transmitted, they may be hashed where appropriate. We do not use this to collect sensitive personal data.

5. Consent (EEA/UK)

Users in the European Economic Area (EEA) and the UK receive a consent notice under GDPR/UK GDPR. Analytics and marketing cookies activate only after explicit, informed, freely given consent (GDPR Art. 6(1)(a)). Your choice is recorded in the cookie_consent browser cookie and typically retained for 12 months.

You can withdraw consent at any time by using the “Manage cookie preferences” link in the footer. You can also clear cookies in your browser settings. Withdrawing consent does not affect the lawfulness of processing based on consent before it was withdrawn.

6. Sharing With Advertising & Service Partners

We use a small number of service providers to operate the Site, keep it secure, and (if you consent) measure and improve marketing effectiveness. We do not sell personal data.

  • Google LLC (Google Analytics 4, Google Ads, Google Tag Manager, remarketing): may receive cookie IDs, usage data, and conversion events. Privacy information: https://policies.google.com/privacy.
  • Meta Platforms (Meta Pixel, Custom/Lookalike Audiences, Conversion API where configured): may receive page events, conversion events, and audience membership signals. Privacy information: https://www.facebook.com/privacy/policy.
  • Cloudflare (CDN and security): may process IP addresses and technical data for threat detection, DDoS protection, and performance. Privacy information: https://www.cloudflare.com/privacypolicy/.

These providers act as service providers/processors or independent controllers depending on the product and configuration. Where applicable, we use contractual safeguards and settings intended to limit data use to providing the services requested. We do not permit these providers to use Site data for their own independent commercial purposes beyond what is described in their documentation and configured by us.

7. International Transfers

Some of our partners may process data outside the EEA/UK, including in the United States. When personal data is transferred internationally, we use appropriate safeguards such as:

  • EU-US Data Privacy Framework (DPF) (where applicable, since July 2023)
  • UK Extension to the EU-US DPF (where applicable)
  • Swiss-US DPF (where applicable)
  • Standard Contractual Clauses (EU 2021/914) as a fallback safeguard
  • UK International Data Transfer Addendum/IDTA as a fallback safeguard

We also apply practical measures such as limiting which events are sent, minimizing fields, and using consent-based activation for optional technologies.

8. Data Retention

We retain personal data only for as long as necessary for the purposes described in this policy, unless a longer period is required by law. Retention typically follows these guidelines:

  • Contact submissions: up to 2 years from the last interaction, to manage follow-ups and scheduling history.
  • Analytics data: typically 14 months (as configured in the analytics platform), subject to your consent.
  • Marketing cookies: retained according to cookie lifetimes (commonly 90 days) and only with consent.
  • Email correspondence: for the duration of the relationship, plus up to 1 year for continuity and dispute handling.
  • Server logs: typically up to 90 days for security monitoring and troubleshooting.
  • Cookie consent record: up to 3 years for auditability and compliance evidence.
  • Legal and tax records: as required by French law (often 6 to 10 years depending on the record type).

9. Your Rights (GDPR & UK GDPR)

If you are in the EEA or the UK, you may have the following rights under GDPR/UK GDPR, subject to conditions and exemptions:

  • Right of access (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure (Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object (Art. 21)
  • Right to withdraw consent at any time (Art. 7(3))
  • Right to lodge a complaint with a supervisory authority (Art. 77)

To exercise your rights, email us at [email protected]. We may ask for additional information to verify identity before completing a request. We aim to respond within 30 days; this can be extended by up to 60 additional days for complex requests.

If you are in France, the supervisory authority is the Commission Nationale de l’Informatique et des Libertés (CNIL): https://www.cnil.fr. EU guidance is also available via the European Data Protection Board (EDPB): https://edpb.europa.eu. UK residents may contact the ICO: https://ico.org.uk.

10. Children

This Site is not directed at individuals under 16. We do not knowingly collect personal data from minors. If we learn that we have collected personal data from a child under 16 without verifiable parental consent, we will delete it promptly.

11. Do Not Track

This website does not respond to Do Not Track (DNT) browser signals. Third-party providers may have their own approaches to DNT and similar signals, as described in their privacy documentation.

12. Data Deletion Requests

If you would like us to delete personal data that we hold about you, email [email protected] with the subject line “Data Deletion Request”. We will confirm receipt and may ask for verification to prevent unauthorized deletion. We aim to complete deletion within 30 days, except where limited retention is required by law or for the establishment, exercise, or defense of legal claims.

13. Business Transfers

In the event of a merger, acquisition, asset sale, financing, reorganization, or insolvency, personal data may be transferred to a successor entity as part of the transaction. If such a transfer materially changes how personal data is used, we will provide notice on the Site.

14. California (CCPA/CPRA)

This section applies only to California residents when we process their personal information in a way that is subject to the California Consumer Privacy Act as amended by the CPRA (“CCPA/CPRA”). In the past 12 months, we may have collected the following categories:

  • Identifiers: name, email, IP address, cookie identifiers.
  • Internet/network activity: pages visited, interaction events, referrer information.
  • Inferences: general preferences derived from browsing behavior (used only for advertising relevance when you opt in).

We do not sell personal information as defined by CCPA. We may share information for cross-context behavioral advertising if marketing cookies are enabled. California residents may opt out of such sharing via our cookie preferences panel (accessible through the footer “Manage cookie preferences” link).

You may have rights to know, delete, correct, and opt out of sale/sharing, and the right to non-discrimination. To submit a request, email [email protected] with the subject “California Privacy Request”. We may need to verify your identity. Authorized agents must provide proof of authorization.

15. Virginia (VCDPA)

If the Virginia Consumer Data Protection Act (“VCDPA”) applies, Virginia residents may have rights to access, correct, delete, obtain a copy of their data, and opt out of targeted advertising. We do not sell personal data and we do not engage in profiling that produces legal or similarly significant effects.

To submit a request, email [email protected] with the subject “Virginia Privacy Request”. If we refuse to act on a request, you may appeal by emailing with the subject “Appeal of Refusal — Privacy Request”. We respond to appeals within 60 days. If the appeal is denied, you may contact the Virginia Attorney General.

16. Nevada

Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject “Nevada Do Not Sell Request”. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.

17. Changes to This Policy

We may update this Privacy Policy to reflect changes in legal requirements, technology, or how we operate the Site and studio services. Material changes will be announced on the Site at least 14 days before taking effect where appropriate. The “Last Updated” date at the top will be revised with each update.

18. Contact

For questions about privacy, data protection, or this Privacy Policy, contact:

Questions about privacy?

Email us and we will route your message to the right person. For booking-related requests, please use the Contact page.