Privacy Policy
Under The Veil LLC
Effective Date:
Last Updated:
1. Scope and Acceptance
Under The Veil LLC (“Under The Veil,” “we,” “us,” or “our”) is a limited liability company organized under the laws of the State of Texas, United States. We operate private retreat experiences and the website at undertheveilretreats.com (the “Site”).
This Policy applies to information we collect through the Site, through our booking and scheduling tools, through direct correspondence, and in the course of delivering a retreat experience. It applies to prospective guests, confirmed guests, and general visitors.
This Policy does not apply to the practices of third parties we do not own or control.
Under The Veil LLC is the data controller responsible for the information described here. By using the Site, requesting a call, or submitting information to us, you acknowledge the practices described in this Policy.
2. Our Approach
Discretion is not a feature of what we offer. It is a precondition of it.
We collect the minimum information necessary to evaluate mutual fit, deliver the experience safely, and meet our legal obligations. We do not build advertising profiles, we do not sell information, and we do not treat guest data as an asset to be monetized.
Where this Policy grants us latitude, our practice is to use less of it than we are permitted.
3. Information We Collect
3.1 Information You Provide Directly
Depending on how you engage with us, we may collect:
Inquiry and scheduling information. Name, email address, telephone number, time zone, and any message or context you choose to include.
Application and evaluation information. Professional background, reasons for interest, referral source, and any other information you volunteer during an application or discovery conversation.
Retreat delivery information. Where you proceed to a confirmed retreat, information reasonably necessary to host you, which may include travel and arrival details, accommodation preferences, dietary requirements, emergency contact information, and any accessibility needs you disclose.
Correspondence. The contents of emails, messages, and other communications you send us, and our records of those exchanges.
Payment information. Where an engagement proceeds to payment, transactions are processed by third-party payment processors and financial institutions. We receive confirmation of payment and limited transaction records. We do not collect or store full payment card numbers or bank account credentials.
3.2 Information Collected Automatically
When you visit the Site, we and our service providers may collect:
IP address and approximate geographic region derived from it
Browser type and version, device type, operating system, and screen characteristics
Pages viewed, time on page, scroll behavior, and referring URL
Date, time, and duration of access
Information collected through cookies and similar technologies (Section 7)
3.3 Information From Third Parties
We may receive information about you from:
Scheduling and booking platforms used to arrange discovery calls, which collect your name, email address, selected time, and time zone under their own privacy policies
Communication and email service providers that process our correspondence with you
Referral sources. Where an existing guest, advisor, or partner introduces you to us, we may receive your name and contact information from them
Publicly available sources. Where relevant to evaluating fit for an experience of this nature
We identify our current service providers on request. We do not name specific vendors in this Policy because our tooling changes; naming them here would risk stating something inaccurate.
3.4 What We Do Not Collect
We do not knowingly collect, and do not request through the Site:
Government identification numbers, passport numbers, or immigration documentation, except where a specific retreat venue or carrier legally requires it for travel arrangements, in which case we will tell you why and limit collection accordingly
Full payment card or financial account numbers
Medical records, clinical documentation, diagnoses, or laboratory results
Biometric identifiers
Information about anyone under the age of 18
Under The Veil is not a healthcare provider. We are not a covered entity or business associate under HIPAA. Our experiences are not medical care, psychological treatment, psychotherapy, crisis intervention, or a substitute for any of them. Nothing we provide should be understood as clinical advice.
4. Sensitive Information
Our guests are, by definition, people for whom exposure carries consequence. We treat the following as sensitive and handle it accordingly:
Your identity as a prospective or confirmed guest
Anything you disclose about your personal circumstances, wellbeing, or professional situation
Dietary, accessibility, or emergency contact information provided for retreat delivery
We do not require you to disclose sensitive information. If you choose to share it, we use it only for the purpose for which you shared it, restrict internal access to those with a genuine operational need, and do not use it to infer characteristics about you or to make decisions beyond evaluating fit and hosting you safely.
We do not use or disclose sensitive personal information for purposes that would require the right to limit under applicable state law.
5. How We Use Information
We use information to:
Respond to inquiries and schedule conversations
Evaluate mutual fit for an experience
Arrange, deliver, and support a retreat, including coordination with venues and partners
Communicate about logistics, preparation, and follow-up
Process payments and maintain financial records
Operate, secure, monitor, and improve the Site
Detect and prevent fraud, abuse, and security incidents
Establish, exercise, or defend legal claims
Comply with applicable law, regulation, and legal process
We do not use your information for third-party advertising, sell it, share it for cross-context behavioral advertising, or subject you to automated decision-making that produces legal or similarly significant effects without human involvement.
Legal Bases (EEA, UK, and Switzerland)
Purpose | Legal Basis |
|---|---|
Responding to inquiries; scheduling | Consent; steps prior to entering a contract |
Evaluating fit; delivering a retreat | Performance of a contract |
Site security; fraud prevention; service improvement | Legitimate interests |
Financial records; regulatory compliance | Legal obligation |
Sensitive information you volunteer | Explicit consent |
Legal claims | Legitimate interests; establishment or defense of legal claims |
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out beforehand. Where we rely on legitimate interests, you may object, and we will stop unless we can demonstrate compelling grounds that override your rights.
6. Confidentiality and Discretion
Information shared with us in the course of an inquiry, application, discovery call, or retreat is held in confidence.
We do not:
Disclose or confirm the identity of prospective or confirmed guests to any third party
Confirm or deny an individual’s participation, including to family members, employers, journalists, or other guests, absent that individual’s written authorization
Publish testimonials, photographs, case studies, or quotations attributable to an individual without that individual’s prior written permission
Share the guest list among guests without consent
Disclose the substance of what is discussed during a retreat
Limits. This commitment is bounded only by:
Compliance with valid legal process, subpoena, court order, or applicable law
Circumstances involving a credible and imminent risk of serious harm to you or another person
Disclosure to venue and travel partners strictly to the extent necessary to host you, under confidentiality obligations
Disclosure to our professional advisors, who are bound by duties of confidentiality
Establishment, exercise, or defense of legal claims
Where we are legally compelled to disclose information about you, we will notify you in advance unless prohibited from doing so.
7. Cookies, Analytics, and Tracking
The Site uses cookies and similar technologies that are necessary for it to function, and may use analytics technologies to understand how visitors use the Site.
You may refuse or delete cookies through your browser settings. Some functionality may not operate as intended if you do.
We honor Global Privacy Control (GPC) signals. Where your browser transmits a GPC signal, we treat it as a valid request to opt out of sale and sharing under applicable state law. Because we do not sell or share personal information, this changes nothing about how we handle your data, but the signal is respected regardless.
We do not respond to Do Not Track (DNT) browser signals, as no common industry standard for DNT has been adopted. Our GPC handling above is the operative control.
We do not permit third parties to collect personal information about your online activities over time and across different websites when you use the Site.
8. How We Disclose Information
We do not sell your personal information. We have not sold personal information in the preceding twelve months. We do not share personal information for cross-context behavioral advertising.
We disclose information only as follows:
Recipient | Purpose | Safeguard |
|---|---|---|
Service providers | Hosting, scheduling, email delivery, analytics, payment processing | Contractually bound to use information solely to provide services to us, and prohibited from retaining, using, or disclosing it for any other purpose |
Venue and retreat partners | Arranging accommodation, travel, and on-site delivery at a confirmed retreat | Minimum necessary information only; confidentiality obligations |
Professional advisors | Legal, accounting, and insurance matters | Professional duties of confidentiality |
Legal authorities | Compliance with law, subpoena, or valid legal process | Advance notice to you where permitted |
Successor entity | Merger, acquisition, financing, or sale of assets | Successor bound by this Policy or notice given |
At your direction | Any disclosure you specifically authorize | Your written instruction |
We do not disclose personal information to any party for that party’s own independent marketing purposes.
9. Retention
We retain information only as long as necessary for the purpose for which it was collected, and thereafter only where a legitimate business or legal reason requires it.
We determine retention by reference to:
Whether an active or prospective relationship exists
Whether retention is necessary to deliver or support an experience
Applicable tax, accounting, and corporate recordkeeping requirements
Applicable statutes of limitation for potential legal claims
Any legal hold or preservation obligation
In practice, inquiries that do not progress are deleted within a short period. Records relating to completed engagements are retained for the period required by tax and limitation law, and then deleted or de-identified.
You may request deletion at any time under Section 10. Where a legal obligation prevents us from deleting particular records, we will tell you which records and why, and delete the remainder.
10. Your Rights
10.1 Rights Available to Everyone
Regardless of where you live, you may ask us to:
Access the personal information we hold about you
Correct information that is inaccurate or incomplete
Delete information we hold about you
Stop contacting you for any or all purposes
Explain how we obtained your information, if you did not provide it directly
We extend these rights to all individuals as a matter of practice, not only where law compels it.
10.2 California Residents (CCPA/CPRA)
You have the right to know, delete, correct, opt out of sale and sharing, limit the use of sensitive personal information, obtain portability, and be free from retaliation for exercising any of these rights. We do not sell or share personal information, and we do not use sensitive personal information for purposes requiring a right to limit.
California residents may also request information about disclosures to third parties for direct marketing purposes under California’s “Shine the Light” law. We make no such disclosures.
You may use an authorized agent to submit a request. We will require proof of authorization and may verify your identity directly.
10.3 Other United States Residents
Residents of states with comprehensive privacy laws, including Texas, Virginia, Colorado, Connecticut, Utah, Oregon, Montana, Delaware, Nebraska, New Hampshire, New Jersey, and others as they take effect, have rights to confirm processing, access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling.
We do not engage in targeted advertising, sale of personal data, or profiling in furtherance of decisions producing legal or similarly significant effects.
Appeals. If we decline your request, you may appeal by replying to our decision or writing to the address in Section 14 with the word “Appeal” in the subject line. We will respond to appeals within 45 days with a written explanation of our reasoning. If we deny your appeal, we will provide a method to contact your state Attorney General to submit a complaint.
10.4 EEA, UK, and Swiss Residents (GDPR/UK GDPR)
You have rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing, including objection to direct marketing at any time. Where processing is based on consent, you may withdraw it at any time.
You may lodge a complaint with your local supervisory authority. In the UK, this is the Information Commissioner’s Office.
10.5 How to Exercise Your Rights
Send requests to the address in Section 14. Please describe what you are asking for with enough specificity that we can act on it.
We will verify your identity before disclosing or deleting information, using information already in our possession. We will not require you to create an account to make a request. We do not charge a fee for the first request in any twelve-month period, and we do not discriminate against anyone for exercising these rights.
We respond within 45 days, extendable once by a further 45 days where reasonably necessary, and sooner where law requires it. Where we cannot fully comply, we will explain why.
11. International Transfers
Under The Veil LLC operates from the United States. Our retreats may take place outside your country of residence. Information you provide will be transferred to and processed in the United States, and where relevant to a confirmed retreat, in the jurisdiction hosting that retreat.
Privacy laws in those jurisdictions may differ from those of your home country and may afford less protection.
Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses approved by the European Commission (with the UK Addendum where applicable) or another lawful transfer mechanism, together with supplementary measures where appropriate. A copy of the relevant safeguards is available on request.
12. Security and Incident Response
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information we hold, including:
Encryption of data in transit (TLS) and at rest where supported by our providers
Access limited to personnel and partners with a demonstrable need to know
Multi-factor authentication on accounts holding guest information
Confidentiality obligations binding everyone who handles guest information
Diligence on service providers before engagement
No system is perfectly secure, and we cannot guarantee absolute security.
In the event of a data breach affecting your personal information, we will notify you and the relevant regulators without undue delay and within the timeframes required by applicable law, describing what occurred, what information was involved, and what steps we are taking.
13. Additional Provisions
Children. The Site and our experiences are intended solely for adults aged 18 and over. We do not knowingly collect personal information from minors. If we learn we have, we will delete it promptly. If you believe a minor has provided us information, contact us at the address below.
Third-Party Links. The Site may link to third-party websites and platforms, including scheduling and payment tools. Those parties operate under their own privacy policies. We are not responsible for their practices, and we encourage you to review them.
Governing Law. This Policy is governed by the laws of the State of Texas, without regard to conflict-of-law principles, except where the mandatory law of your jurisdiction of residence applies to the processing of your personal information.
Severability. If any provision of this Policy is found unenforceable, the remaining provisions remain in full force.
Changes to This Policy. We may update this Policy. The “Last Updated” date reflects the most recent revision. Where changes are material, we will provide notice through the Site and, for individuals with whom we have an ongoing relationship, by direct communication. Your continued use of the Site after a change takes effect constitutes acceptance of the revised Policy.
14. Contact
Questions, requests, appeals, or concerns regarding this Policy may be directed to:
Under The Veil LLC privacy@undertheveilretreats.com c/o Northwest Registered Agent, LLC 5900 Balcones Drive, STE 100 Austin, TX 78731 United States
We acknowledge all privacy requests on receipt and respond substantively within 45 days, or sooner where required by law.
Under The Veil LLC. Private Experiences for Those Who Are Ready.

