Workshop Spirit is operated by Workshop Spirit . Privacy questions: info@workshopspirit.com.
This policy explains how we handle personal data when you visit our website, create an account, book a workshop, or use organisation admin features on the platform.
For most platform operations (accounts, security, booking administration, and legal record-keeping), we act as a data controller. For workshop delivery, customer service about the workshop itself, and marketing to bookers who opt in, the hosting organisation is typically the controller and we process data on its instructions. Payment card and account details are handled by PayPal or Stripe under their own privacy notices when you pay. If you opt in to marketing at checkout, the hosting organisation is the controller for those communications; we sync your opt-in to the organisation’s Mailchimp audience as its processor.
- Account data: name, email, password hash, two-factor authentication settings, passkey (WebAuthn) credentials where you enable them, and email login code preferences where you enable that fallback.
- Booking data: workshop selections, attendee details you provide, dietary or access requirements, notes, terms acceptance records, and payment status.
- Payment metadata: transaction references, amounts, currency, and processor status — not full card numbers.
- Communications: transactional email delivery metadata and support correspondence.
- Technical and security data: IP address, browser type, server logs, and session identifiers needed to operate and secure the service.
- Marketing opt-in: whether you chose to receive updates from a hosting organisation (only when you affirmatively opt in).
- Contract: to create and administer bookings, accounts, and payments you request.
- Legal obligation: to keep records required by tax, accounting, or regulatory rules.
- Legitimate interests: fraud prevention, platform security, service reliability, and improving the product (balanced against your rights).
- Consent: marketing communications from a hosting organisation, only where you opt in at checkout.
We share personal data only where needed to provide the service:
- Hosting organisations receive booking and attendee data for workshops they host.
- PayPal and Stripe process payments when selected by an organisation or at checkout.
- Resend delivers transactional email on our behalf.
- Mailchimp receives name and email for bookers who opt in to an organisation’s marketing, synced on that organisation’s instructions.
- Infrastructure providers that host the application and database under appropriate safeguards.
Some subprocessors (including payment and email providers) may process data outside the UK. Where this occurs, we rely on appropriate safeguards such as UK adequacy regulations or standard contractual clauses, as applicable.
- Transactional: booking confirmations, payment receipts, balance and instalment reminders, account and security notices, organisation booking alerts, and practical updates from hosting organisations about sessions you have booked (for example schedule or venue changes).
- Marketing: only where you opted in at checkout; sent by the hosting organisation via Mailchimp. Unsubscribe using the organisation’s mailing list or Mailchimp controls.
We keep personal data for as long as needed to provide the service and meet legal and accounting obligations. Booking and financial records may be retained for statutory periods even after a booking ends. If you request account deletion, we mark your account for deletion and permanently remove it after a 30-day grace period, unless we must retain specific records by law.
- Access and export: download a JSON export from your account privacy page. The export currently includes basic account fields (name, email, and account creation date); it does not yet include full booking history.
- Deletion: request account deletion from your account privacy page. Deletion is completed after the grace period described above.
- Object, restrict, and rectify: contact us where UK GDPR gives you these rights.
- Complaint: you may complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk if you believe we have handled your data unlawfully.
We use encryption for organisation API credentials (payment and Mailchimp keys), access controls, and industry-standard practices to protect personal data. No online service can guarantee absolute security; please use a strong password and enable two-factor authentication or passkeys where available. Email login codes are offered only as a fallback where enabled.
The platform is not directed at children under 16. We do not knowingly collect personal data from children without appropriate parental authority.
We may update this policy from time to time. The “last updated” date below shows when it was last revised.
Last updated: 2026-06-25