Privacy
Privacy Policy
Last Updated: August 2026
Who we are
Raksa Retreats ("we", "us", "our") is operated by Mt. Meru Natives LLC, a US limited liability company, and organises small-group wellness and adventure retreats. You can reach us at hello@raksaretreats.com for anything relating to your data.
Our registered office and principal place of business is:
Mt. Meru Natives LLC, 3729 E Farm Road 28, Fair Grove, MO 65648-8039, USA.
Mt. Meru Natives LLC is the data controller for the personal information described in this policy.
What we collect
- Newsletter form: your first name and email address.
- Booking form: your name, email address, phone number, chosen room or tier, and any notes you choose to share (such as dietary or medical information relevant to your stay).
- Payment information: we do not store your full card or bank details ourselves. Payments are processed directly through Wise and/or PayPal, who handle and secure your payment data under their own privacy policies.
- Technical data: basic, non-identifying information our hosting provider records to keep the site running securely.
Health and dietary information (including EU guests)
Where you voluntarily share dietary or medical information relevant to your stay, we treat this as sensitive information. We use it only to support your safety and comfort during the retreat, limit access to the hosts and staff who need it to do so, and do not share it beyond what's necessary to run the retreat safely (for example, informing on-site catering of a dietary restriction). You are never required to share more than you're comfortable with, though incomplete information may limit our ability to accommodate certain needs.
We collect this information through our booking and retreat intake forms — for example allergies, dietary requirements, injuries, medical conditions, medication, mobility limitations and emergency contact details. Under the EU/UK GDPR, health information is a special category of personal data (Article 9). For guests in the EU or UK we rely on your explicit consent (Article 9(2)(a)) to process it, and on vital interests (Article 9(2)(c)) where processing is necessary in a medical emergency during a retreat. You may withdraw that consent at any time by emailing us, and we will delete the information, subject to any records we must keep by law.
Intake responses are stored in our access-controlled booking database, are visible only to San, Cam and the specific staff or partner (such as catering or an activity provider) who needs a given detail to keep you safe, and are never used for marketing or profiling. Health, medical, dietary and accessibility information is retained only for as long as reasonably necessary to support the relevant retreat and to address related safety or legal requirements — in practice, deleted or anonymised within 12 months of the end of your retreat. It is held separately from, and is not kept for the same period as, the financial booking record we retain for accounting purposes.
Cookies
Our website may use a small number of essential cookies needed for the site to function correctly (for example, to keep your session working during booking). We do not use cookies for advertising or third-party tracking, and we do not run analytics tools that track visitors across the web.
Because we set no analytics, advertising or other non-essential cookies, no cookie-consent banner is required under the EU ePrivacy rules. If we ever introduce analytics or marketing cookies, we will add a consent banner that asks for your permission before those cookies are set, and update this page.
How we use it
- To send you retreat news and updates when you subscribe.
- To process, confirm and manage your booking and deposit.
- To contact you about practical details before and during a retreat.
- To keep our website secure and functioning correctly.
- To meet our legal and accounting obligations.
We do not sell your data, and we do not share it beyond the service providers we use to run the site, store bookings, process payments, and send email.
Who we share it with
We share limited personal data with trusted service providers who help us operate, including:
- Website hosting and infrastructure providers
- Email delivery providers (for newsletters and booking confirmations)
- Payment processors (Wise, PayPal)
- Accommodation and activity partners, where necessary to arrange your stay or an excursion (for example, providing your name for a hotel reservation)
These providers only receive the information necessary to perform their function and are not permitted to use your data for their own purposes.
Legal basis
We rely on:
- Consent, for newsletter emails and for sharing sensitive dietary or medical information. You can withdraw consent at any time.
- Performance of a contract, for booking-related information necessary to arrange and deliver your retreat.
- Legitimate interests, for basic technical and security data needed to keep the site running safely.
- Legal obligation, for records we're required to keep for accounting and tax purposes.
International data transfers
As a US-based company, your information may be processed and stored in the United States or other countries where our service providers operate. Where we transfer personal data from the EU/UK to a country without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses, and take reasonable steps to protect the privacy of guests located in the EU/UK in line with applicable data protection standards.
How long we keep it
- Newsletter details are kept until you unsubscribe.
- Booking and financial records may be retained for up to 7 years where necessary to meet accounting, tax, insurance or other legal obligations, after which they are deleted or anonymised.
- Health, medical, dietary and accessibility information is retained only for as long as reasonably necessary to support the relevant retreat and address related safety or legal requirements (normally deleted or anonymised within 12 months of the end of your retreat). It is not kept for the full 7-year accounting period simply because the booking record is retained.
- Technical data is retained only as long as needed for security and site operation purposes.
Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your data
- Restrict or object to certain processing
- Request a portable copy of your data
- Withdraw consent at any time, without affecting processing carried out before your withdrawal
To exercise any of these rights, email hello@raksaretreats.com and we will respond within 30 days. Every newsletter also includes an unsubscribe link.
If you are in the EU or UK and believe we have not handled your data properly, you also have the right to lodge a complaint with your local data protection supervisory authority.
Photography, video and testimonials
Photos and videos may be taken during Raksa retreats for legitimate documentation and operational purposes, subject to applicable law and reasonable expectations of privacy.
Where we intentionally use an identifiable guest's photograph, image, likeness or video for our website, social media, advertising or other promotional materials, we ask for that guest's affirmative consent first. Silence is not treated as consent, and giving consent is never a condition of attending a retreat. Consent may be withdrawn at any time by emailing us.
Testimonials are used for promotional purposes only with the guest's knowledge and consent. Guests may contact us to request removal or anonymisation of a testimonial.
Third-party links and content
Our website may contain links to third-party websites or embedded third-party content, including social media content. These third parties operate under their own privacy policies, and Raksa Retreats is not responsible for the privacy practices of external websites or services.
Automated decision-making
Raksa Retreats does not use personal data for automated decision-making or profiling that produces legal or similarly significant effects on you.
Data breaches
If Raksa Retreats becomes aware of a personal data breach affecting personal information, we will take reasonable steps to contain and investigate the breach and will notify affected individuals and relevant authorities where required by applicable law.
California privacy rights
Depending on whether applicable California privacy law applies to you and to our processing of your information, California residents may have additional rights regarding access to, correction of, deletion of, and certain uses or disclosures of their personal information.
To exercise applicable privacy rights, contact us at hello@raksaretreats.com.
Children's privacy
Our retreats and services are intended for adults, and participants must generally be at least 18 years old unless separately approved by Raksa Retreats.
We do not knowingly collect personal data from children under 16. If you believe a minor has provided personal data to us, please contact us at hello@raksaretreats.com and we will take appropriate steps to delete the information.
Security
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Changes
If this policy changes, the updated version will be posted on this page with a revised "Last Updated" date. Where changes are significant, we will take reasonable steps to notify newsletter subscribers by email.
Contact us
For any questions about this Privacy Policy or how we handle your data, contact us at hello@raksaretreats.com.
© 2026 Mt. Meru Natives LLC