Privacy Policy

Last Updated: January 27, 2026

🔒 Your Privacy is Sacred
🔐 AES-256-GCM Encryption 🚫 No Ad or Behavioral Tracking 🍪 No Tracking Cookies 📊 No Advertising Analytics 🛡️ HTTPS Secured

1. Our Commitment to Your Privacy

Given the deeply personal and sacred nature of the services offered, we take your privacy with the utmost seriousness. This is not a standard website-it is a sanctuary, and your information deserves sanctuary-level protection.

We operate on the principle of data minimization: we collect only what is essential to provide you with sacred healing services, and nothing more.

2. Information We Collect

2.1 Information You Provide

When you submit a booking request, we collect:

  • Contact Information: Name, email address, phone number
  • Session Preferences: Service selection, availability, intentions for the session
  • Health Information: Any relevant health notes, sensitivities, or concerns you choose to share (optional)
  • Consent Acknowledgment: Your digital signature confirming you've read and agreed to session boundaries

2.2 Information We Do NOT Collect

  • 🍪 We use a single strictly-necessary security cookie (CSRF protection for form submissions) — no tracking, advertising, or analytics cookies
  • ❌ We do not use Google Analytics or any tracking pixels
  • ❌ We do not collect IP addresses beyond standard server logs and the consent record attached to your booking (kept as evidence of your age and boundary agreement)
  • ❌ We do not use any third-party analytics services
  • ❌ We do not track your browsing behavior
  • ❌ We do not sell or share your data with advertisers
  • ❌ We do not use social media tracking

3. How We Protect Your Information

🛡️ Military-Grade Security

3.1 Technical Security Measures

  • Encryption at Rest: All stored data is encrypted with AES-256-GCM with unique initialization vectors
  • Encryption in Transit: All communications use HTTPS with TLS 1.3
  • Password Protection: Site access requires a password, adding an additional layer of privacy
  • Secure Authentication: Admin access uses bcrypt-hashed passwords and opaque server-side session tokens
  • Rate Limiting: Protection against brute force attacks
  • No External Dependencies: Your data never leaves our secure server

3.2 Operational Security

  • Only Ravi has access to booking information
  • Data is stored on secure, private servers
  • Regular security reviews and updates
  • No cloud storage services that could access your data

4. How We Use Your Information

Your information is used exclusively for:

  1. Scheduling: To arrange and confirm your healing sessions
  2. Communication: To contact you about your appointments (only if you've opted in)
  3. Session Preparation: To prepare appropriately for your unique needs and intentions
  4. Service Improvement: To provide better care in future sessions

We will never:

  • Sell your information to third parties
  • Share your information with marketing companies
  • Use your information for advertising
  • Contact you for any purpose other than your requested services

5. Data Retention

We retain your information only as long as necessary to provide services and maintain our professional relationship:

  • Active Clients: Information is retained while you remain an active client
  • Inactive Clients: Information may be retained for up to 2 years for clients who may wish to return
  • Deletion Requests: You may request complete deletion of your data at any time

6. Your Rights

You have complete control over your personal information:

  • Right to Access: Request a copy of all information we hold about you
  • Right to Correction: Request corrections to any inaccurate information
  • Right to Deletion: Request complete and permanent deletion of all your data
  • Right to Withdraw Consent: Withdraw your consent for us to process your data at any time

To exercise any of these rights, simply contact Ravi directly.

7. Third-Party Services

This website uses minimal external services:

  • Self-Hosted Fonts: Fonts are served from this website itself — no external font service is contacted
  • Email Service: For sending confirmations (if configured)-emails are sent directly, not through marketing platforms
  • Hosting (Render): The application and its encrypted data files run on Render; data at rest is AES-256-GCM encrypted and Render holds no decryption key
  • Error Monitoring (when enabled): Server errors may be reported to Sentry for reliability monitoring; personal fields are scrubbed before any report is sent
  • Calendar Sync (when connected): Booking date/time and service name may sync to the practitioner's Google Calendar

The full list of sub-processors, the data each receives, and how to request erasure from each is maintained in our sub-processor register.

8. Children's Privacy

This website and its services are intended for adults only (18 years or older). We do not knowingly collect information from anyone under 18 years of age.

9. Changes to This Policy

If we make changes to this privacy policy, we will update the "Last Updated" date at the top. Significant changes will be communicated directly to active clients.

10. Contact

Questions About Your Privacy?

If you have any questions, concerns, or requests regarding your privacy or personal data, please contact Ravi directly:

Email: RavishingRavi77@gmail.com

🙏 A Personal Note from Ravi
← Return to Sacred Space