Privacy Policy
Eco-Yoga Institute ACN 677 775 245 (“we,” “us,” “our”) Website: ecology.yoga Last updated: February 2026
This Privacy Policy explains what personal information we collect, how we use it, how we protect it, and your rights in relation to it. We handle your personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), as amended by the Privacy and Other Legislation Amendment Act 2024.
1. Information We Collect
We collect personal information when you interact with the Site in the following ways:
Account registration. When you create an account, we collect your name, email address, username, and password. Depending on your membership tier, we may also collect a profile photo, biographical information, and other details you choose to provide.
Membership and payments. When you sign up for a paid membership or purchase a product, your payment is processed by Stripe and/or PayPal. We do not collect or store your credit card numbers, bank account details, or other payment credentials. These are submitted directly to the payment processor and never pass through our servers. We receive only confirmation of payment, transaction identifiers, and billing address from these processors.
Community participation. When you post in forums, groups, or comments, or interact with other members, the content you post and your activity (such as posts, replies, and group memberships) are visible to other members in accordance with the Site’s community features.
Courses. When you enrol in or complete courses through the School, we collect enrolment records, progress data, and completion status.
Shop purchases. When you purchase products, we collect your name, email, shipping address, and order details. Payment processing is handled by Stripe and/or PayPal as described above.
Contact and correspondence. When you contact us by email or through the Site’s contact form, we collect the information you provide in your message.
Automatically collected information. When you visit the Site, our servers and analytics tools may automatically collect technical information such as your IP address, browser type, operating system, referring URL, pages visited, and time spent on the Site. This information is used to understand how the Site is used and to improve its performance and security.
Cookies. We use cookies to maintain your login session, remember your preferences, and support the functionality of the Site (including WooCommerce shopping cart and checkout). We do not use cookies for third-party advertising or behavioural tracking. You can configure your browser to refuse cookies, but some features of the Site may not function properly without them.
2. How We Use Your Information
We use the personal information we collect only for the following purposes:
- To create and manage your account and membership.
- To process payments and fulfil orders.
- To deliver courses and track your progress.
- To operate the community features of the Site (forums, groups, events, member profiles).
- To respond to your enquiries and provide support.
- To send you service-related communications (such as account confirmations, billing notices, and membership updates).
- To send you occasional newsletters or updates about the Site, where you have consented or where we are otherwise permitted to do so. You can unsubscribe from marketing emails at any time using the unsubscribe link in the email or by contacting us.
- To monitor and improve the Site’s performance, security, and functionality.
- To detect, prevent, and respond to security incidents, fraud, or misuse.
- To comply with legal obligations.
We do not use your personal information for purposes other than those described above without your consent.
3. What We Do Not Do
To be clear about our practices:
- We do not sell, rent, or trade your personal information to third parties.
- We do not serve third-party advertising on the Site.
- We do not use your personal information for behavioural advertising or profiling.
- We do not purchase or use third-party marketing lists.
- We do not use automated decision-making that significantly affects your rights or interests. If this changes in the future, we will update this policy and notify you in accordance with applicable law.
4. Third Parties and Data Sharing
We share personal information with third parties only as necessary to operate the Site and provide our services:
Payment processors. Stripe and PayPal process your payment transactions. Your payment credentials are submitted directly to these processors and are governed by their privacy policies (Stripe, PayPal). We do not have access to your full card or bank account details.
Hosting and infrastructure. The Site is hosted by third-party hosting providers who may have access to server data (including IP addresses and access logs) as part of providing hosting services. These providers are contractually required to handle data securely.
WordPress plugins and services. The Site runs on WordPress with BuddyBoss (community features), Tutor LMS (courses), and WooCommerce (shop and memberships). These platforms process data as part of delivering their functionality. Where these services transmit data to external servers, they operate under their own privacy policies.
Email services. We may use third-party email services to send newsletters and transactional emails. These services receive your email address and name for the purpose of delivering messages on our behalf.
Affiliate programmes. The Site participates in affiliate programmes, including the Amazon Services LLC Associates Program. When you click an affiliate link and make a purchase on a third-party site, that site may collect information about your visit and purchase through their own cookies and tracking. This is governed by the affiliate partner’s privacy policy, not ours. We do not receive any personal information about you from affiliate partners — only anonymised commission data.
Legal requirements. We may disclose personal information if required to do so by law, court order, or government request, or where we have a good-faith belief that disclosure is necessary to protect our rights, your safety, or the safety of others, or to respond to a data breach or security incident.
We do not share personal information with any third parties beyond those described above.
5. Overseas Data Transfers
Some of the third-party services we use (such as Stripe, PayPal, and email providers) may store or process data on servers located outside Australia, including in the United States. Where personal information is transferred overseas, we take reasonable steps to ensure that the overseas recipient handles the information in accordance with the Australian Privacy Principles. By using the Site and providing your personal information, you consent to such transfers where they are necessary to provide our services.
6. Data Security
We take reasonable technical and organisational measures to protect your personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. These measures include:
- Use of SSL/TLS encryption for data transmitted between your browser and the Site.
- Secure password storage (hashed, not stored in plain text).
- Access controls limiting who can access personal information to those who need it to perform their role.
- Regular software updates and security patches for WordPress and its plugins.
- Use of reputable, secure hosting providers.
No method of electronic storage or transmission is completely secure. We cannot guarantee absolute security, but we are committed to maintaining and improving our security practices in line with current standards and our obligations under the Privacy Act.
7. Data Retention
We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Specifically:
- Account data is retained for as long as your account is active. If you delete your account, we will delete or de-identify your personal information within 30 days, except where retention is required for legal, accounting, or dispute resolution purposes.
- Transaction and order records are retained for 7 years in accordance with Australian tax and accounting obligations.
- Server logs containing IP addresses and technical data are retained for up to 12 months, after which they are deleted or anonymised.
- Forum posts and community content remain on the Site unless you request their removal (see Section 8 and Section 9).
8. User-Posted Content
Content you post on the Site — including forum posts, group discussions, comments, and profile information — is visible to other users. Do not post personal information that you do not wish to make public.
We will remove your posted content at your request where practicable. However, we cannot guarantee that content already copied, cached, or indexed by third parties (such as search engines) will be removed from their systems.
9. Your Rights
Under the Australian Privacy Principles, you have the right to:
- Access your personal information that we hold. You can view and update most of your information through your account settings.
- Correct any personal information that is inaccurate, incomplete, or out of date.
- Request deletion of your personal information, subject to certain exceptions (for example, where we are required to retain information for legal or accounting purposes, or where the information is part of forum threads in which others have participated).
- Withdraw consent for marketing communications at any time by using the unsubscribe link in any email or by contacting us.
- Request information about how your personal information has been used or disclosed.
To exercise any of these rights, contact us at admin@ecology.yoga with the subject line “Privacy Request.” We will acknowledge your request within 7 days and respond substantively within 30 days.
If you are located in a jurisdiction with additional data protection rights (such as the EU/UK under the GDPR), we will make reasonable efforts to honour those rights. Contact us to discuss your specific circumstances.
10. Data Breaches
In the event of a data breach involving your personal information that is likely to result in serious harm, we will:
- Take immediate steps to contain the breach and mitigate any harm.
- Assess the breach in accordance with our obligations under the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act).
- Notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as required by law.
We maintain a data breach response plan and will act promptly to address any incident.
11. Children
The Site is not directed at children under 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected such information, we will take steps to delete it promptly. If you believe a child under 16 has provided us with personal information, please contact us at admin@ecology.yoga.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Updated versions will be posted on this page with a revised “Last updated” date. If we make material changes — particularly changes to how we use or share your personal information — we will notify registered users by email before the changes take effect. Your continued use of the Site after changes are posted constitutes your acceptance of the updated policy.
13. Complaints
If you believe we have breached the Australian Privacy Principles or otherwise mishandled your personal information, you may lodge a complaint with us at admin@ecology.yoga. We will acknowledge your complaint within 7 days and investigate and respond within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the external organisation.
14. Contact
Eco-Yoga Institute ACN 677 775 245 Email: admin@ecology.yoga Website: ecology.yoga