Privacy policy
24 July 2026
Who we are
Wellsa Junyska (“Reshaped by Wellsa”) operates this website from Canggu, Bali, Indonesia. Contact for all privacy matters: hello@reshapedbywellsa.com.
What data we collect
- Reservation form: your name, email address, WhatsApp number, the class or session you pick, an optional note, and (only if you tick the separate checkbox) your consent to receive updates about new classes. This data is stored in a database operated for us on Cloudflare’s infrastructure (Cloudflare D1) so reservations can be managed, and a notification to Wellsa plus a confirmation email to you are sent via our email provider (Resend).
- Class-pass purchases: when you buy a class pass we store your name, email address, WhatsApp number, the tier you chose, and the pass itself (credits, status, validity, and which of Wellsa’s classes you book with it) in the same Cloudflare D1 database. We keep a payment reference so we can match your payment to your pass; we do not store your card or bank-account numbers (see Payments below). Your pass is accessed through a private, single link we email you (no password).
- Marketing updates: only sent if you explicitly opted in via the separate checkbox. Marketing consent is always separate from a reservation or a purchase and is never bundled with either. You can withdraw consent at any time by emailing us or replying to any message; we then stop using your address for updates.
- Contact form: name, email address, optional phone number and your message. Sent to us by email so we can answer your enquiry; not stored in a database.
- WhatsApp: reservations are confirmed personally via WhatsApp. If you contact us there (or receive a confirmation), Meta’s terms and privacy policy apply to that conversation.
- Email to us: mail sent to hello@reshapedbywellsa.com is forwarded to Wellsa’s own inbox by Cloudflare Email Routing, which passes the message on without storing a mailbox for it.
- Server logs: our hosting provider may log IP addresses for security and operations.
What we do NOT do
- No advertising or tracking cookies. This site sets no cookies that require a banner.
- No analytics that profile you across sites, follow you around the web, or feed advertising. See “Visitor statistics” below for the cookieless page counting we do use.
- No embedded video platforms (videos on this site are self-hosted).
- No sale or sharing of your data with third parties for marketing.
Payments
How it works today. Class-pass payments are arranged directly with Wellsa. When you request a pass we send you the amount and a reference number, and Wellsa sends you her bank transfer or QRIS details personally by email and WhatsApp. Your payment is then handled by your own bank or e-wallet under their terms. We never see or store your card or bank-account numbers. We keep only the payment reference, so we can match your payment to your pass.
If card and e-wallet checkout is switched on later, it will be provided by Xendit, a licensed payment processor acting as an independent data controller for the payment itself. You would be sent to Xendit’s own hosted checkout page to enter your details; those details would go directly to Xendit and would never be seen or stored by us or by this website. Xendit would return only a payment reference and a confirmation that the payment succeeded. We do not embed any Xendit script, tracker or payment form on this site. See Xendit’s privacy policy for how they process payment data.
Embedded content
This site embeds Google Maps for the studio locations. Loading a map transmits your IP address to Google. See Google’s privacy policy for details.
Visitor statistics
We use Cloudflare Web Analytics to see how many people visit the site and which pages they read. It is built to be privacy-first: it sets no cookies, stores nothing on your device, and does not fingerprint you or follow you onto other websites. It counts page views alongside general technical information such as the page that referred you, the country, and the browser and device type. No profile of you is built, and the measurement cannot be used to identify you. The small measurement script is loaded from Cloudflare. See Cloudflare’s privacy policy for details.
Spam protection
The contact and reservation forms use Cloudflare Turnstile to block automated spam. Turnstile processes technical browser signals to tell a person from a bot. It sets no tracking cookie and does not profile you across sites; see Cloudflare’s privacy policy.
Your rights
You may request access to, correction of, or deletion of the personal data you sent us (including reservation records, pass and purchase records, and the marketing list) at any time by emailing hello@reshapedbywellsa.com. Under Indonesia’s Personal Data Protection Law (UU PDP 27/2022) you have the right to access, correct and delete your personal data.
Retention
Enquiry emails are kept only as long as needed to handle your request, then deleted. Reservation records are kept as long as needed to run the classes and are deleted on request. Class-pass and purchase records (including the payment reference and your class-booking history for a pass) are kept while your pass is valid and afterwards for the period we need to meet tax and accounting obligations, then deleted or anonymised. We never hold payment-instrument data at all: your card, bank-account or e-wallet details stay with your own bank or e-wallet, and with Xendit if card checkout is switched on later.