This Website Policy explains how Rhythm Wellness Club (“Rhythm,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you visit rhythmwellnessclub.com or use our related app and services (together, the “Site”). It applies to visitors and members located in the United States, the United Kingdom, and the European Union, and is written to reflect the requirements of the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and other applicable U.S. state privacy laws.
We collect information in a few different ways:
Like most websites, we use cookies and similar technologies (such as pixels and local storage) to run the Site, remember your preferences, and understand how visitors use our pages. These generally fall into three categories:
You can control or disable most cookies through your browser settings. Visitors in the UK and EU are shown a cookie notice on first visit and can adjust their preferences at any time; disabling non-essential cookies will not affect your ability to browse the Site, though some features may not work as intended.
We use the information we collect to: provide and personalise the Rhythm membership experience; process payments and manage your account; communicate with you about your membership, including service updates and, where you’ve agreed to receive them, marketing messages; maintain the security and proper functioning of the Site; and understand and improve how our Site and services are used.
If you are located in the UK or EU, we rely on the following legal bases to process your personal data: performance of a contract (to provide the membership you’ve signed up for); your consent (for example, for marketing communications or non-essential cookies, which you can withdraw at any time); our legitimate interests (such as keeping the Site secure and improving our services); and compliance with a legal obligation, where applicable.
We do not sell your personal information. We may share information with trusted service providers who help us operate the Site and deliver your membership — such as payment processors, our app and hosting providers, email and communications platforms, and lab or practitioner partners directly involved in your care. These providers are only permitted to use your information to perform services on our behalf. We may also disclose information if required to do so by law, or to protect the rights, safety, or property of Rhythm, our members, or others.
Rhythm is based in the United States, and information we collect — including from visitors and members in the UK and EU — may be transferred to, stored, and processed in the United States or other countries. Where required, we use appropriate safeguards, such as Standard Contractual Clauses, to protect information transferred internationally.
We keep personal information for as long as needed to provide our services, maintain your membership records, and comply with our legal and accounting obligations. When information is no longer needed for these purposes, we take steps to delete or anonymise it.
If you are located in the UK or EU, under GDPR you have the right to: access the personal data we hold about you; request correction of inaccurate data; request erasure of your data; restrict or object to certain processing; request a portable copy of your data; and withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with your local data protection authority — in the UK, this is the Information Commissioner’s Office (ICO).
If you are a California resident, under the CCPA/CPRA you have the right to: know what personal information we collect, use, and disclose; request deletion of your personal information; correct inaccurate personal information; opt out of the sale or sharing of personal information (we do not sell or share personal information as those terms are defined by the CCPA/CPRA); limit the use of sensitive personal information; and not be discriminated against for exercising these rights.
To exercise any of these rights, email us at hello@rhythmwellnessclub.com. We may need to verify your identity before fulfilling your request.
The Site is intended for adults and is not directed to children. We do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us with personal information, please contact us so we can remove it.
We use reasonable administrative, technical, and physical safeguards designed to protect your information from unauthorised access, loss, misuse, or alteration. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Our Site may contain links to third-party websites or services we do not control. This Website Policy does not apply to those third parties, and we encourage you to review their own privacy policies.
We may update this Website Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will update the “Last updated” date above when we do, and encourage you to review this page periodically.
If you have questions about this Website Policy or how we handle your information, please reach out to us at hello@rhythmwellnessclub.com.