Privacy policy
Last updated: August 2026
This page explains what personal data this site collects, why, and what you can do about it. The short version: only what is needed to run your account and your courses.
1.What is collected
- Account: email address, password (stored only as a cryptographic hash, never in readable form), name if you provide one, preferred language.
- Onboarding: the name you want to be called, your age, your dance background and what you are here for. It is used to recommend where to start and to know who is in the class.
- Training: which courses you have access to, which lessons are unlocked, which you marked as done and where you stopped in a video.
- Orders: order number, amount, currency, payment status, and the identifier of the Stripe session. Card numbers never reach this site.
- Messages: whatever you write in the contact form.
2.Why, and on what legal basis
- To give you the courses you paid for and to run your account: performance of a contract.
- To issue and keep records of orders: legal obligation.
- To answer your messages: legitimate interest.
- To send news about new courses, only if you ticked that box: consent, which you can withdraw at any time.
3.Who else sees it
- Stripe, for processing payments.
- The hosting provider that runs the server and the database.
- Nobody else. Data is not sold, rented, or handed over for advertising.
4.How long it is kept
Account and training data for as long as the account exists. Order records for as long as accounting law requires. Contact messages for up to two years.
5.Your rights
You can ask for a copy of your data, a correction, deletion, restriction of processing, or portability, and you can object to processing based on legitimate interest. Write to the address at the bottom of this page and you get an answer within 30 days.
If you believe your data is handled badly, you can complain to the Romanian data protection authority (ANSPDCP) or to the authority in your own country.
6.Security
Passwords are stored hashed with bcrypt. Sessions live in the database and can be revoked. Traffic is served over HTTPS. No system is perfect, but nothing here is stored in a way that would make a leak trivial to exploit.
