Privacy Policy
Last updated: 30 June 2026
This Privacy Policy explains how Inner Bloom ("we", "us", "our") collects, uses and protects your personal data when you visit this website or interact with our services. We comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
Inner Bloom is the data controller for the personal data described in this policy. You can contact us at innerbloomadmin@gmail.com.
2. What data we collect
- Information you provide: name, email address and any message content you send us via email or our forms.
- Technical data: IP address, browser type, device information, pages viewed and approximate location.
- Cookies and similar technologies: see our Cookie Policy.
3. How we use your data and our lawful basis
| Purpose | Lawful basis |
|---|---|
| Responding to enquiries | Legitimate interests / consent |
| Sending marketing emails (when you opt in) | Consent |
| Site analytics and performance | Consent |
| Meeting legal and regulatory obligations | Legal obligation |
4. Sharing your data and third-party services
We share data only with trusted service providers acting as our processors. These providers are contractually bound to protect your data, and we do not sell your personal data. The main categories of third parties involved in running this site are:
- Hosting & site delivery — Lovable / Cloudflare (serves the website and may process IP addresses for security and delivery).
- Web fonts — Google Fonts loads typography files from
fonts.googleapis.comandfonts.gstatic.com. Your IP address is briefly shared with Google to render the page. - Checkout & membership — when you click "Join The Challenge" you are taken to ThriveCart and Inner Bloom Academy, who collect the data needed to process your purchase under their own privacy policies.
- Affiliate / referral tracking — referral links use a member identifier so that commissions can be attributed to the referring member.
- Email — if you contact us by email, our mailbox provider processes the message in order to deliver it.
5. International transfers
Some of our providers (including Google and our hosting provider) are based outside the UK and EEA. Where data is transferred internationally, we rely on appropriate safeguards such as the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or adequacy regulations.
6. How long we keep your data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting or reporting requirements. Marketing email data is kept until you unsubscribe.
7. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request erasure of your data
- Restrict or object to our processing
- Withdraw consent at any time (without affecting prior processing)
- Data portability
- Lodge a complaint with the Information Commissioner's Office (ico.org.uk)
To exercise any of these rights, email innerbloomadmin@gmail.com.
8. Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss or alteration. However, no method of transmission over the internet is 100% secure.
9. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision.