Privacy Policy

Version 1.0 · Last updated: 15 September 2026

1. Who we are and how to contact us

Red Life Therapy Inc., carrying on business as Red Life Wellness ("Red Life," "we," "us" or "our"), operates a wellness studio at 1448 Dresden Row, Halifax, Nova Scotia, Canada. This policy explains how we handle personal information in our website, booking application, customer communications and studio services. It also covers information about emergency contacts. It does not govern another organization's independent services or our employment records.

Our Privacy Officer is responsible for this policy and privacy requests. Contact the Privacy Officer at hello@redlifewellness.ca or write to Privacy Officer, Red Life Therapy Inc., 1448 Dresden Row, Halifax, NS, Canada. Use "Privacy request" in the subject line if possible; no special wording is required. Please do not include detailed medical information, identity documents or payment credentials in an initial email. We will arrange an appropriate way to handle information needed for your request.

We handle customer information under applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA). Red Life provides non-medical wellness services. Collecting safety-screening information does not make our screening a medical diagnosis or treatment.

2. Privacy at a glance

  • We collect information needed to manage accounts, assess session suitability, record consent, provide services, process payments and address support or safety concerns.
  • Health information is sensitive. We seek express consent for routine health screening and restrict its use to the purposes explained when collected and in this policy, unless the law permits or requires otherwise.
  • Marketing is optional. Accepting a waiver or acknowledging this policy does not sign you up for promotions, photographs or testimonials.
  • Our application uses Base44 and payments use Stripe. Information may be processed outside Canada.
  • You can ask about our practices, request access or correction, withdraw consent, or request account closure and deletion, subject to applicable legal limits.

3. Information we collect and why

We collect information from you, from your use of our services and, where relevant, from the providers and people described below. Required fields should be identified when collected. Optional information is not required to receive a session.

InformationExamplesMain purposes
Account and contact detailsName, email, phone number, date of birth or age-eligibility information, account identifier and authentication information.Create and secure an account, confirm service eligibility, identify bookings and communicate with you.
Health and suitability screeningAnswers about pregnancy, sensitivity to light, relevant medication effects, implanted devices, recent surgery or wounds, relevant active treatment, eye conditions, seizures and other safety concerns; any necessary follow-up.Identify matters requiring review, decide whether to offer or defer a session, apply appropriate precautions and respond to safety concerns.
Consent and service recordsScreening status, waiver and consent text/version, acknowledgments, acceptance times, relevant device/browser information, bookings, attendance, cancellations, waitlist requests and session notes.Document informed choices, administer sessions and resolve questions, incidents or disputes.
Purchases and membershipProducts, amounts, currency, payment status, receipts, refunds, payment-provider references, subscriptions, sessions and usage.Process and reconcile purchases, administer entitlements, prevent payment misuse and meet accounting obligations.
Emergency contactsThe contact's name and phone number.Contact someone about an emergency or significant safety concern involving you. These details are not used for marketing.
Communications and preferencesSupport messages, necessary staff notes, incident reports, communication choices, marketing choices and optional wellness interests or referral source.Answer requests, manage service concerns and preferences, and send communications you have chosen or that are otherwise lawful.
Technical and security recordsIP address and connection information handled by our site or providers, browser/device information, authentication and usage events, browser storage, error and administrative audit records.Operate and secure the website and application, remember settings, troubleshoot and investigate misuse.

Please provide accurate information, keep relevant details up to date and disclose only what is necessary. We do not ask for your social insurance number or health-card number for ordinary wellness services. Avoid sending full medical histories, card numbers or passwords through general contact forms. If a clinician's input is needed, we seek information relevant to suitability, rather than an unrestricted medical record.

Tell your emergency contact that you are providing their details to Red Life for the purposes above and obtain their permission. If you give information for someone else, ensure you have authority to do so. Staff may create relevant service, support or incident records. We seek permission before obtaining information directly from a clinician or another person unless the law allows an exception.

5. Health screening and automated rules

The application applies rules to screening answers to identify whether a booking can proceed, requires staff review or should be deferred. These rules do not diagnose a condition, provide medical advice or establish that a session is safe for a particular person. Staff review may still require advice from your qualified healthcare professional.

Contact hello@redlifewellness.ca if an answer is wrong, circumstances change, or you want a staff explanation or review of a screening outcome. A review does not guarantee clearance. Where a consent, incident or decision record must be preserved, we can record a correction or updated information alongside the original rather than overwrite the history.

We do not authorize the use of identifiable customer information, including health screening, for targeted advertising, sale of customer lists or general-purpose AI model training by Red Life or our service providers. We select and configure providers on that basis and do not submit client health records to public AI tools. This policy does not authorize those activities. Any proposed additional technology use involving sensitive information requires a separate privacy assessment and any legally required notice and consent.

6. Payments, login and service providers

We use service providers to support the purposes above. We limit information provided to what the service requires and remain accountable for information processed on our behalf. We require appropriate contractual or other protections and assess provider practices in light of the information's sensitivity.

  • Base44 provides our application platform, database, authentication and related hosting functions. It processes account, booking, screening, consent and other application records needed to operate those functions. Its privacy information is available at base44.com/privacy-policy.
  • Stripe handles payment checkout and associated payment processing. We provide account/customer identifiers, contact details and purchase information. Payment details you enter in Stripe checkout are handled by Stripe; our application keeps transaction details, receipts and payment references. We do not send health-screening answers as payment metadata. Stripe may also process information for its own lawful payment, security and regulatory purposes: stripe.com/privacy.
  • If you choose Google or Apple sign-in, the selected provider authenticates you and supplies the account information authorized through that process. Its own privacy terms apply to its independent services. We do not provide health-screening answers to it for sign-in.
  • Hosting, authentication and communications services may process technical information and the contact details or message content needed to deliver their functions. We limit sensitive information in ordinary messages and notifications.

Provider privacy notices explain their practices but do not replace our responsibilities or authorize unrelated sharing by Red Life. Contact our Privacy Officer for information about the providers handling your information and applicable processing arrangements.

7. Other circumstances in which we share information

We allow access within Red Life only to people who need the information for their responsibilities, with confidentiality obligations. Access to health answers and incident details should be limited more closely than access to ordinary booking information.

We may also disclose necessary information:

  • At your direction or with your consent, including a specifically authorized communication with a healthcare professional.
  • To emergency responders or an emergency contact where needed and lawfully permitted to address an emergency or serious safety concern.
  • To professional advisers, insurers or claims administrators where reasonably needed for a specific incident, legal matter or claim and supported by consent or a lawful exception. This is not unrestricted access to all customer health records.
  • Where a law, valid legal process or a permitted investigation requires or authorizes disclosure. We assess the request and limit the information disclosed as appropriate.
  • In a proposed or completed business transaction where the law permits, subject to necessary-use limits, confidentiality and protection commitments, and any required notice. Information from an abandoned transaction must be returned or destroyed as required by law. A transaction does not authorize unrelated use of your information.

We do not sell personal information or provide customer lists to other organizations for their own marketing. We do not publish identifiable client photographs, recordings, stories or testimonials without separate, specific permission. An emergency contact is not automatically authorized to see your account or health records.

8. Processing outside Canada

Red Life and its service providers may store or access information outside Nova Scotia and Canada. Depending on the service, processing may occur in the United States and other countries. Information in another country may be subject to that country's laws and lawful access by its courts, regulators or government authorities.

We remain responsible for assessing these arrangements and using appropriate protections for information transferred for processing. A transfer does not waive your rights or shift our privacy responsibilities to you. Contact our Privacy Officer to ask about countries, providers and safeguards relevant to your information.

9. Cookies, browser storage and external content

Our application and its providers use browser storage and similar technologies for functions such as authentication, session security, application settings and remembering preferences. Technical request information may also be processed to operate and protect the service. Blocking required storage can interfere with sign-in or booking. You can manage browser storage through your browser settings.

The website self-hosts its font files; no font request is sent to an external provider. Links to maps, social platforms or other websites take you to services governed by their own policies. We do not include health-screening answers in those requests.

We require an affirmative choice before activating optional analytics or advertising trackers. Where offered, you can decline them or later change that choice as easily as accepting. Health information, screening and waiver content, private account pages and identifiable session details must not be sent to advertising pixels or session-replay services. If we introduce optional tracking, the choice notice will identify its provider, purpose and relevant duration before activation. This policy alone is not consent to optional tracking.

10. Marketing and service messages

Promotional email or text messages are optional and require the consent or other authorization required by Canada's anti-spam law. We request marketing choices separately from health consent and the waiver. A preference for SMS appointment reminders is not consent to promotional texts.

You can unsubscribe using the mechanism in a promotional message or by contacting us. We action unsubscribe requests without delay and no later than 10 business days. We may keep the minimum record needed to respect that choice and demonstrate consent or withdrawal.

We may continue to send lawful non-promotional messages needed for your account, requested bookings, receipts, service changes or safety. We keep promotional content separate from those messages. You can ask to change optional reminders or your contact channel; we will explain any essential communications that remain necessary.

11. Safeguards and security incidents

We are responsible for physical, organizational and technical safeguards appropriate to the sensitivity, amount and uses of the information. Our safeguards include limiting authorized access, confidentiality requirements, account-security controls, suitable provider arrangements and procedures for secure handling and disposal. We review safeguards as services and risks change. No system is completely secure; this statement does not limit our legal obligations or your remedies.

Use a strong, unique password, protect your sign-in credentials and sign out of shared devices. Tell us promptly if you suspect unauthorized access or receive a suspicious message appearing to come from Red Life. Please use our Privacy Officer contact and do not send passwords or detailed health records to report a concern.

We investigate suspected privacy incidents, take appropriate containment and corrective steps, and assess the risk to individuals. Where a breach creates a real risk of significant harm, we report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible after determining that it occurred, as required by law. We also make other legally required notifications and maintain required breach records.

12. Retention, account closure and disposal

We keep personal information only as long as reasonably necessary for the identified purposes and applicable legal requirements. Retention depends on the record, including whether it relates to an active account, an uncompleted service or refund, evidence of consent, an incident, a legal claim, an access request or an accounting obligation. We do not keep all information indefinitely merely because it was collected.

Our retention decisions distinguish active profile and contact information; screening, consent and session records; payment and accounting records; support and incident files; and technical, marketing-consent and security records. Relevant legal requirements and claim periods may require some records to outlast account closure. A specific legal hold may pause normal disposal, but does not authorize unrelated use or indefinite retention of everything in an account.

Information categoryPurposeRetention periodLegal basis
Account and contact detailsAccount management, bookings, communication, eligibilityDuration of active account + 30 days after closureService agreement, consent
Health and suitability screening answersSession suitability assessment, safetyActive account + 90 days after last session; superseded by new screening when health changesConsent, safety and liability protection
Consent and waiver recordsEvidence of informed consent and assumption of risk6 years after last session or account closureLimitation Act (NS), contract evidence, liability protection
Booking and session recordsSession administration, attendance, cancellation history6 years after last sessionLimitation Act (NS), service administration
Payment and accounting recordsPayment processing, refunds, tax and accounting obligations6 years from end of fiscal year (CRA requirement)Income Tax Act, CRA record-keeping rules
Incident reportsSafety investigation, liability, regulatory notification6 years after incident resolutionLimitation Act (NS), PIPEDA breach recording
Support messages and staff notesResolving customer inquiries and service concerns2 years after resolutionCustomer service, dispute resolution
Marketing consent recordsDemonstrating consent or withdrawal for promotional messagesWhile consent is active + 30 days after withdrawalCASL consent requirements
Administrative audit logsSecurity, access tracking, misuse investigation12 monthsSecurity, PIPEDA accountability
Emergency contact detailsContacting someone in an emergency or safety concernWhile account is active; deleted with account closureSafety, consent

When a retention purpose ends, we securely delete, destroy or genuinely anonymize the information and address copies held by providers on our behalf. Anonymization must mean that there is no serious possibility of identifying you from the information, alone or with other available information. Backups may take longer to expire through controlled replacement cycles; retained copies remain protected and must not be reused for unrelated purposes. Deletion requirements must also be addressed if a backup is restored.

You can request account closure, deletion or an explanation of the retention criteria for your records. We will assess what can be removed and explain any lawful reason for keeping information, together with the applicable period or criteria where possible. If you have an active membership or booking, we will explain and help resolve the related cancellation, payment and refund consequences. Where your request clearly asks us to end those services, we will treat it accordingly. Account closure does not extinguish accrued lawful obligations or reduce your statutory rights.

13. Access, correction and privacy requests

Contact our Privacy Officer to ask whether we hold information about you, request access to it, ask how it has been used or disclosed, correct an inaccuracy, withdraw consent, or request deletion. You can ask about the source of information and applicable providers or retention practices. An authorized representative may act for you if we can reasonably verify their authority.

We use identity checks proportionate to the request and sensitivity of the records. We seek no more verification information than reasonably necessary and do not require government identification as a routine condition of every request. Let us know if you need help making a request or require an accessible response format.

For access requests, we respond within 30 days after receipt, subject to extensions permitted by law. If an extension is needed, we provide notice within the initial period explaining the reason, new deadline and your right to complain. Access is provided at minimal or no cost. For any legally permitted fee, we explain the approximate amount and proceed with a charge only after you confirm that you still want the request processed.

Legal exceptions may limit access, for example to protect another person's information or legally privileged material. Where possible, we separate information that can be released. We explain a refusal and available complaint options unless the law prevents us from doing so. We do not refuse a request merely because you have stopped using our services.

Where a correction is justified, we update the information and, where appropriate, communicate it to relevant recipients. Where the original must be kept, we add a correction or record your unresolved disagreement. Exercising privacy rights does not require you to release claims or sign a new waiver.

14. Individuals under 19

Our client accounts and wellness services are intended for people aged 19 and over. Please do not create a client account or submit a minor's health screening for a session. If we learn that a client account belongs to someone under 19, we will restrict the account, assess the circumstances and remove information that we have no lawful reason to retain. Contact our Privacy Officer if you believe a minor's information has been submitted. This service-age rule does not remove privacy rights of minors whose information we hold.

15. Questions, complaints and policy changes

We will investigate privacy complaints and address substantiated concerns. You may contact our Privacy Officer at hello@redlifewellness.ca or the postal address in section 1. You can also contact the Office of the Privacy Commissioner of Canada through priv.gc.ca/en/report-a-concern. You do not have to give up a legal remedy or exhaust an internal process before contacting the regulator.

We update this policy when our practices or legal requirements change. The current version and update date appear on the website and downloadable copy. We provide additional notice of material changes where appropriate and obtain new consent where required before a new use. Updating this policy does not retroactively authorize processing or reduce rights protected by law. This policy is a privacy notice, not a liability waiver.