Privacy Policy
Version 1.0 · Last updated: 15 September 2026
Contents
1. Who we are and how to contact us
Red Life Therapy Inc., carrying on business as Red Life Wellness ("Red Life," "we," "us" or "our"), operates a wellness studio at 1448 Dresden Row, Halifax, Nova Scotia, Canada. This policy explains how we handle personal information in our website, booking application, customer communications and studio services. It also covers information about emergency contacts. It does not govern another organization's independent services or our employment records.
Our Privacy Officer is responsible for this policy and privacy requests. Contact the Privacy Officer at hello@redlifewellness.ca or write to Privacy Officer, Red Life Therapy Inc., 1448 Dresden Row, Halifax, NS, Canada. Use "Privacy request" in the subject line if possible; no special wording is required. Please do not include detailed medical information, identity documents or payment credentials in an initial email. We will arrange an appropriate way to handle information needed for your request.
We handle customer information under applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA). Red Life provides non-medical wellness services. Collecting safety-screening information does not make our screening a medical diagnosis or treatment.
2. Privacy at a glance
- We collect information needed to manage accounts, assess session suitability, record consent, provide services, process payments and address support or safety concerns.
- Health information is sensitive. We seek express consent for routine health screening and restrict its use to the purposes explained when collected and in this policy, unless the law permits or requires otherwise.
- Marketing is optional. Accepting a waiver or acknowledging this policy does not sign you up for promotions, photographs or testimonials.
- Our application uses Base44 and payments use Stripe. Information may be processed outside Canada.
- You can ask about our practices, request access or correction, withdraw consent, or request account closure and deletion, subject to applicable legal limits.
3. Information we collect and why
We collect information from you, from your use of our services and, where relevant, from the providers and people described below. Required fields should be identified when collected. Optional information is not required to receive a session.
| Information | Examples | Main purposes |
|---|---|---|
| Account and contact details | Name, email, phone number, date of birth or age-eligibility information, account identifier and authentication information. | Create and secure an account, confirm service eligibility, identify bookings and communicate with you. |
| Health and suitability screening | Answers about pregnancy, sensitivity to light, relevant medication effects, implanted devices, recent surgery or wounds, relevant active treatment, eye conditions, seizures and other safety concerns; any necessary follow-up. | Identify matters requiring review, decide whether to offer or defer a session, apply appropriate precautions and respond to safety concerns. |
| Consent and service records | Screening status, waiver and consent text/version, acknowledgments, acceptance times, relevant device/browser information, bookings, attendance, cancellations, waitlist requests and session notes. | Document informed choices, administer sessions and resolve questions, incidents or disputes. |
| Purchases and membership | Products, amounts, currency, payment status, receipts, refunds, payment-provider references, subscriptions, sessions and usage. | Process and reconcile purchases, administer entitlements, prevent payment misuse and meet accounting obligations. |
| Emergency contacts | The contact's name and phone number. | Contact someone about an emergency or significant safety concern involving you. These details are not used for marketing. |
| Communications and preferences | Support messages, necessary staff notes, incident reports, communication choices, marketing choices and optional wellness interests or referral source. | Answer requests, manage service concerns and preferences, and send communications you have chosen or that are otherwise lawful. |
| Technical and security records | IP address and connection information handled by our site or providers, browser/device information, authentication and usage events, browser storage, error and administrative audit records. | Operate and secure the website and application, remember settings, troubleshoot and investigate misuse. |
Please provide accurate information, keep relevant details up to date and disclose only what is necessary. We do not ask for your social insurance number or health-card number for ordinary wellness services. Avoid sending full medical histories, card numbers or passwords through general contact forms. If a clinician's input is needed, we seek information relevant to suitability, rather than an unrestricted medical record.
Tell your emergency contact that you are providing their details to Red Life for the purposes above and obtain their permission. If you give information for someone else, ensure you have authority to do so. Staff may create relevant service, support or incident records. We seek permission before obtaining information directly from a clinician or another person unless the law allows an exception.
4. Consent, required information and your choices
We explain the important information, purposes and disclosures when requesting consent. Consent may be express or, for appropriate non-sensitive activities, reasonably implied by your request and the circumstances. We seek a separate affirmative choice before routine collection and use of health-screening information. We do not rely on continued browsing or a general privacy acknowledgment as consent to every use described here.
You can decline optional information or marketing without losing access to services. If you decline or withdraw consent for information reasonably needed to assess suitability, provide a session, maintain necessary records or process payment, we may be unable to provide the affected service. We will explain the consequence. This does not remove any cancellation, refund or other rights you have under law or your agreement.
You may withdraw consent by contacting our Privacy Officer, subject to legal or contractual restrictions and reasonable notice. Withdrawal applies to future processing based on that consent. It does not undo lawful earlier processing or require destruction of records that must still be retained for an identified lawful purpose. We will explain material restrictions and available options.
If we propose a materially different purpose requiring consent, we will explain it and obtain the necessary consent before that use. Where a legal exception permits collection, use or disclosure without consent, we limit it to that exception.
5. Health screening and automated rules
The application applies rules to screening answers to identify whether a booking can proceed, requires staff review or should be deferred. These rules do not diagnose a condition, provide medical advice or establish that a session is safe for a particular person. Staff review may still require advice from your qualified healthcare professional.
Contact hello@redlifewellness.ca if an answer is wrong, circumstances change, or you want a staff explanation or review of a screening outcome. A review does not guarantee clearance. Where a consent, incident or decision record must be preserved, we can record a correction or updated information alongside the original rather than overwrite the history.
We do not authorize the use of identifiable customer information, including health screening, for targeted advertising, sale of customer lists or general-purpose AI model training by Red Life or our service providers. We select and configure providers on that basis and do not submit client health records to public AI tools. This policy does not authorize those activities. Any proposed additional technology use involving sensitive information requires a separate privacy assessment and any legally required notice and consent.
6. Payments, login and service providers
We use service providers to support the purposes above. We limit information provided to what the service requires and remain accountable for information processed on our behalf. We require appropriate contractual or other protections and assess provider practices in light of the information's sensitivity.
- Base44 provides our application platform, database, authentication and related hosting functions. It processes account, booking, screening, consent and other application records needed to operate those functions. Its privacy information is available at base44.com/privacy-policy.
- Stripe handles payment checkout and associated payment processing. We provide account/customer identifiers, contact details and purchase information. Payment details you enter in Stripe checkout are handled by Stripe; our application keeps transaction details, receipts and payment references. We do not send health-screening answers as payment metadata. Stripe may also process information for its own lawful payment, security and regulatory purposes: stripe.com/privacy.
- If you choose Google or Apple sign-in, the selected provider authenticates you and supplies the account information authorized through that process. Its own privacy terms apply to its independent services. We do not provide health-screening answers to it for sign-in.
- Hosting, authentication and communications services may process technical information and the contact details or message content needed to deliver their functions. We limit sensitive information in ordinary messages and notifications.
Provider privacy notices explain their practices but do not replace our responsibilities or authorize unrelated sharing by Red Life. Contact our Privacy Officer for information about the providers handling your information and applicable processing arrangements.
8. Processing outside Canada
Red Life and its service providers may store or access information outside Nova Scotia and Canada. Depending on the service, processing may occur in the United States and other countries. Information in another country may be subject to that country's laws and lawful access by its courts, regulators or government authorities.
We remain responsible for assessing these arrangements and using appropriate protections for information transferred for processing. A transfer does not waive your rights or shift our privacy responsibilities to you. Contact our Privacy Officer to ask about countries, providers and safeguards relevant to your information.
10. Marketing and service messages
Promotional email or text messages are optional and require the consent or other authorization required by Canada's anti-spam law. We request marketing choices separately from health consent and the waiver. A preference for SMS appointment reminders is not consent to promotional texts.
You can unsubscribe using the mechanism in a promotional message or by contacting us. We action unsubscribe requests without delay and no later than 10 business days. We may keep the minimum record needed to respect that choice and demonstrate consent or withdrawal.
We may continue to send lawful non-promotional messages needed for your account, requested bookings, receipts, service changes or safety. We keep promotional content separate from those messages. You can ask to change optional reminders or your contact channel; we will explain any essential communications that remain necessary.
11. Safeguards and security incidents
We are responsible for physical, organizational and technical safeguards appropriate to the sensitivity, amount and uses of the information. Our safeguards include limiting authorized access, confidentiality requirements, account-security controls, suitable provider arrangements and procedures for secure handling and disposal. We review safeguards as services and risks change. No system is completely secure; this statement does not limit our legal obligations or your remedies.
Use a strong, unique password, protect your sign-in credentials and sign out of shared devices. Tell us promptly if you suspect unauthorized access or receive a suspicious message appearing to come from Red Life. Please use our Privacy Officer contact and do not send passwords or detailed health records to report a concern.
We investigate suspected privacy incidents, take appropriate containment and corrective steps, and assess the risk to individuals. Where a breach creates a real risk of significant harm, we report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible after determining that it occurred, as required by law. We also make other legally required notifications and maintain required breach records.
12. Retention, account closure and disposal
We keep personal information only as long as reasonably necessary for the identified purposes and applicable legal requirements. Retention depends on the record, including whether it relates to an active account, an uncompleted service or refund, evidence of consent, an incident, a legal claim, an access request or an accounting obligation. We do not keep all information indefinitely merely because it was collected.
Our retention decisions distinguish active profile and contact information; screening, consent and session records; payment and accounting records; support and incident files; and technical, marketing-consent and security records. Relevant legal requirements and claim periods may require some records to outlast account closure. A specific legal hold may pause normal disposal, but does not authorize unrelated use or indefinite retention of everything in an account.
| Information category | Purpose | Retention period | Legal basis |
|---|---|---|---|
| Account and contact details | Account management, bookings, communication, eligibility | Duration of active account + 30 days after closure | Service agreement, consent |
| Health and suitability screening answers | Session suitability assessment, safety | Active account + 90 days after last session; superseded by new screening when health changes | Consent, safety and liability protection |
| Consent and waiver records | Evidence of informed consent and assumption of risk | 6 years after last session or account closure | Limitation Act (NS), contract evidence, liability protection |
| Booking and session records | Session administration, attendance, cancellation history | 6 years after last session | Limitation Act (NS), service administration |
| Payment and accounting records | Payment processing, refunds, tax and accounting obligations | 6 years from end of fiscal year (CRA requirement) | Income Tax Act, CRA record-keeping rules |
| Incident reports | Safety investigation, liability, regulatory notification | 6 years after incident resolution | Limitation Act (NS), PIPEDA breach recording |
| Support messages and staff notes | Resolving customer inquiries and service concerns | 2 years after resolution | Customer service, dispute resolution |
| Marketing consent records | Demonstrating consent or withdrawal for promotional messages | While consent is active + 30 days after withdrawal | CASL consent requirements |
| Administrative audit logs | Security, access tracking, misuse investigation | 12 months | Security, PIPEDA accountability |
| Emergency contact details | Contacting someone in an emergency or safety concern | While account is active; deleted with account closure | Safety, consent |
When a retention purpose ends, we securely delete, destroy or genuinely anonymize the information and address copies held by providers on our behalf. Anonymization must mean that there is no serious possibility of identifying you from the information, alone or with other available information. Backups may take longer to expire through controlled replacement cycles; retained copies remain protected and must not be reused for unrelated purposes. Deletion requirements must also be addressed if a backup is restored.
You can request account closure, deletion or an explanation of the retention criteria for your records. We will assess what can be removed and explain any lawful reason for keeping information, together with the applicable period or criteria where possible. If you have an active membership or booking, we will explain and help resolve the related cancellation, payment and refund consequences. Where your request clearly asks us to end those services, we will treat it accordingly. Account closure does not extinguish accrued lawful obligations or reduce your statutory rights.
13. Access, correction and privacy requests
Contact our Privacy Officer to ask whether we hold information about you, request access to it, ask how it has been used or disclosed, correct an inaccuracy, withdraw consent, or request deletion. You can ask about the source of information and applicable providers or retention practices. An authorized representative may act for you if we can reasonably verify their authority.
We use identity checks proportionate to the request and sensitivity of the records. We seek no more verification information than reasonably necessary and do not require government identification as a routine condition of every request. Let us know if you need help making a request or require an accessible response format.
For access requests, we respond within 30 days after receipt, subject to extensions permitted by law. If an extension is needed, we provide notice within the initial period explaining the reason, new deadline and your right to complain. Access is provided at minimal or no cost. For any legally permitted fee, we explain the approximate amount and proceed with a charge only after you confirm that you still want the request processed.
Legal exceptions may limit access, for example to protect another person's information or legally privileged material. Where possible, we separate information that can be released. We explain a refusal and available complaint options unless the law prevents us from doing so. We do not refuse a request merely because you have stopped using our services.
Where a correction is justified, we update the information and, where appropriate, communicate it to relevant recipients. Where the original must be kept, we add a correction or record your unresolved disagreement. Exercising privacy rights does not require you to release claims or sign a new waiver.
14. Individuals under 19
Our client accounts and wellness services are intended for people aged 19 and over. Please do not create a client account or submit a minor's health screening for a session. If we learn that a client account belongs to someone under 19, we will restrict the account, assess the circumstances and remove information that we have no lawful reason to retain. Contact our Privacy Officer if you believe a minor's information has been submitted. This service-age rule does not remove privacy rights of minors whose information we hold.
15. Questions, complaints and policy changes
We will investigate privacy complaints and address substantiated concerns. You may contact our Privacy Officer at hello@redlifewellness.ca or the postal address in section 1. You can also contact the Office of the Privacy Commissioner of Canada through priv.gc.ca/en/report-a-concern. You do not have to give up a legal remedy or exhaust an internal process before contacting the regulator.
We update this policy when our practices or legal requirements change. The current version and update date appear on the website and downloadable copy. We provide additional notice of material changes where appropriate and obtain new consent where required before a new use. Updating this policy does not retroactively authorize processing or reduce rights protected by law. This policy is a privacy notice, not a liability waiver.
