1. Data Controller
The data controller responsible for your personal data is AI Digital Services LLC, registered at 254 Chapman Rd, Ste 208 #17213, Newark, DE 19702, United States. You can contact us at info@yuhuwellness.com for any privacy-related question.
2. Scope of this Policy
This Policy applies to personal data we process when you visit yuhuwellness.com, book a wellness session, apply to join our network of independent specialists, or otherwise interact with our services.
3. Information We Collect
3.1 Information you provide
- Identity and contact data: name, email address, phone number.
- Booking data: service requested, date and time, delivery address (hotel or home), special requests, allergies or medical notes you choose to share.
- Account data: password (hashed), authentication tokens, language preference.
- Communications: messages you send through email, WhatsApp, or our support channels.
3.2 Information collected automatically
- Technical data: IP address, browser type and version, device, operating system.
- Usage data: pages visited, time spent, referring URL, interactions with the booking flow.
- Cookie data: as detailed in our Cookie Policy.
3.3 Information from third parties
We receive limited information from Stripe (payment confirmations, fraud signals) and from hotel concierge partners when they book on your behalf.
4. Information from Independent Specialists
If you apply to join YuHu as an independent wellness specialist, we additionally collect: professional certifications, identification documents, photos, service catalogue, pricing, availability, payout details (processed by Stripe Connect), and the locations you serve. This data is required to verify your eligibility, publish your profile, and pay you for completed sessions.
5. Payment Processing
All payments are processed by Stripe, Inc. and Stripe Payments Europe Ltd. We do not see or store your full card number, CVV, or bank credentials. Stripe acts as an independent data controller for fraud prevention and as a processor on our behalf for transaction execution. See https://stripe.com/privacy for details.
6. How We Use Your Information
- To create and manage your booking and your account.
- To share necessary information (your name, address, phone, requested service, notes) with the independent specialist assigned to your session — this is essential to deliver the service.
- To process payments, refunds, and payouts.
- To communicate with you about appointments, changes, reminders, and customer support.
- To verify specialist applications and maintain platform safety.
- To comply with legal obligations including tax and accounting.
- To improve our website, services and security, and to detect fraud or abuse.
- To send marketing communications only where you have given consent, and to measure the performance of our marketing.
7. Legal Basis (GDPR)
- Performance of a contract — to deliver the booking you requested (Article 6(1)(b) GDPR).
- Legal obligation — for tax, accounting, and consumer protection (Article 6(1)(c)).
- Legitimate interest — to operate, secure and improve the platform, prevent fraud, and ensure quality (Article 6(1)(f)).
- Consent — for analytics, marketing cookies, and direct marketing (Article 6(1)(a)). You can withdraw consent at any time.
10. International Data Transfers
Some of our processors (Stripe, Supabase) may store or process personal data outside the European Economic Area, including in the United States. Where this happens, we rely on the European Commission's Standard Contractual Clauses and additional safeguards as required by Articles 44–49 GDPR.
11. Data Retention
- Booking and billing records: retained for up to 10 years to comply with tax and accounting law.
- Account data: retained while your account is active and for 24 months after closure for dispute resolution.
- Marketing data: retained only while your consent is active.
- Support communications: retained for up to 36 months.
- Cookies: as described in our Cookie Policy.
12. Security
We apply industry-standard technical and organisational measures: TLS encryption in transit, encryption at rest, hashed passwords, scoped database access via Row-Level Security policies, least-privilege admin access, and continuous security scanning. No system is ever 100% secure, but we work to minimise risk and respond promptly to incidents.
13. Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten") where the law allows.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent at any time, without affecting prior lawful processing.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email info@yuhuwellness.com. We will respond within one month.
14. Minors
Our services are intended for adults aged 18 or over. We do not knowingly collect personal data from children. If you believe a minor has provided us data, contact us and we will delete it.
15. Changes to this Policy
We may update this Policy from time to time. Material changes will be highlighted on this page with a revised "Last updated" date.
16. Contact
AI Digital Services LLC · 254 Chapman Rd, Ste 208 #17213, Newark, DE 19702, United States · info@yuhuwellness.com · www.yuhuwellness.com
Questions about this document?
Contact our team at info@yuhuwellness.com.