Return to Self
Privacy Policy
Effective and last updated: July 14, 2026. This Privacy Policy explains how Return to Self, operated by Samina Mujtaba in Winter Garden, Florida, handles personal information through this website, inquiries, booking, payment, intake, and session-related communication.
1. Scope and who we are
This Policy applies to information Return to Self receives through MyReturnToSelf.com and in connection with its private, group, online, and in-person experiences. It does not govern a third party's own website, app, or service, even when linked here.
Return to Self provides personal-growth and well-being experiences. It is not a medical provider, mental health provider, health plan, or healthcare clearinghouse. Information you provide is therefore not necessarily protected by HIPAA. Please do not use email or a website form for emergencies or for information you do not want transmitted electronically.
2. Information we collect
Depending on how you interact with us, we may collect:
- Identity and contact details: name, email address, phone number, date of birth, and emergency-contact information.
- Booking and transaction details: selected experience, appointment information, amount paid, payment status, receipt and transaction identifiers, and limited payment details made available by the payment processor. Return to Self does not receive or store your full card number or card security code.
- Intake and suitability information: information you voluntarily provide about pregnancy, medical, neurological, psychiatric, cardiovascular, medication, treatment, accessibility, or other participation-related concerns.
- Communications: questions, feedback, preferences, and the contents of messages you send to us.
- Session administration: attendance, consent or waiver status, accommodations, scheduling history, and brief operational notes needed to provide the experience.
- Technical information: IP address, browser and device type, timestamps, referring pages, requested pages, error logs, and security or fraud signals generated by our hosting and payment providers.
We collect information from you, from a person booking on your behalf, and automatically from service providers that operate the website, scheduling, communications, and payment functions.
3. Why we use information
We use personal information only as reasonably necessary to:
- respond to inquiries and provide requested information;
- evaluate basic participation suitability and requested accommodations;
- schedule, confirm, deliver, reschedule, and follow up on experiences;
- process payments, refunds, receipts, and transaction disputes;
- maintain consent, waiver, financial, safety, and business records;
- protect participants, prevent fraud, secure the website, and enforce our terms;
- improve our offerings and understand website performance; and
- comply with law, respond to lawful process, and establish or defend legal claims.
Where applicable law requires a legal basis, we rely on your consent, steps requested before entering a contract, performance of our agreement, legitimate interests that do not override your rights, and compliance with legal obligations. You may withdraw consent for future processing, but doing so does not affect prior lawful use and may prevent us from providing a requested experience.
4. Sensitive information
Intake information may reveal health or other sensitive details. We ask only for information reasonably relevant to participation, safety, accessibility, or legal obligations. We do not use sensitive information for targeted advertising, sell it, or use it to make unrelated decisions. Please do not provide details we have not requested or do not need.
5. Payments and Stripe
Group payments are processed by Stripe. Payment information entered in embedded Checkout is submitted directly to Stripe and is handled under Stripe's own terms and privacy practices. Return to Self receives the transaction status and limited information needed to identify and manage the reservation. Stripe may process device, identity, payment, and fraud information as an independent service provider or controller under applicable law.
6. Cookies and similar technology
The website and its infrastructure may use essential cookies or similar technology for security, network operation, accessibility, and session continuity. Embedded Stripe Checkout may use cookies and device signals for payment, authentication, and fraud prevention. Return to Self does not currently use advertising cookies or sell browsing activity for cross-context behavioral advertising. If that changes, this Policy and any legally required consent controls will be updated first.
7. When information is disclosed
We may disclose relevant information to:
- website hosting, payment, scheduling, email, communications, storage, security, and professional-service providers acting for us;
- venues or contractors only when needed to administer an experience and subject to appropriate confidentiality expectations;
- accountants, insurers, attorneys, and other advisers;
- government, courts, or other parties when reasonably necessary to comply with law, protect safety, investigate misuse, or establish or defend legal rights; and
- a successor or prospective successor in a merger, financing, reorganization, sale, or transfer of the business, subject to appropriate safeguards.
Return to Self does not sell personal information, rent contact lists, or share personal information for cross-context behavioral advertising. We do not disclose sensitive intake information except to provide the requested experience, protect safety, comply with law, or act at your direction.
8. Retention
We keep information only as long as reasonably necessary for the purpose collected, participant safety, accounting, tax, insurance, dispute, and legal requirements. Retention varies by record: routine inquiries that do not become bookings are generally deleted or de-identified within 24 months; transaction and core business records may be kept for up to seven years; and intake, consent, waiver, and incident-related records may be kept for the period reasonably needed to address safety, insurance, and legal claims. We may retain de-identified information that cannot reasonably be linked back to you.
9. Security
We use reasonable administrative, technical, and organizational measures appropriate to a small business and the nature of the information. These include limiting access, using reputable providers, and using encrypted transport where supported. No storage system or internet transmission is completely secure, and we cannot promise absolute security. If you believe information has been compromised, contact us promptly.
10. Your privacy choices and rights
You may ask us to access, correct, or delete information about you; obtain a portable copy; withdraw consent; restrict or object to certain uses; or opt out of nonessential marketing. Applicable rights and exceptions depend on your location and our legal obligations. We may need to verify your identity and may retain information that law, safety, accounting, fraud prevention, or legal claims require us to keep.
You may use an authorized agent where law permits. We will not discriminate against you for making a valid privacy request. If we deny a request, you may ask us to reconsider by replying with “Privacy Appeal.” You may also contact the regulator or attorney general responsible for privacy in your jurisdiction.
11. Children
The website and experiences are intended for adults 18 and older. We do not knowingly collect personal information online from children under 13 or knowingly offer sessions to minors. If you believe a child has provided information, contact us so we can review and delete it as appropriate.
12. External services and international processing
Links to Instagram, scheduling tools, Stripe, or other services take you to systems we do not control. Review their policies before providing information. Providers may process information in the United States or other countries whose laws differ from those where you live, subject to protections required by applicable law.
13. Policy changes
We may update this Policy to reflect operational, legal, or technology changes. The “last updated” date will change when we do. Material changes will be communicated in a manner appropriate to the change and will apply prospectively unless law permits otherwise.
14. Contact and privacy requests
Email privacy questions or requests to Samina@MyReturnToSelf.com with the subject “Privacy Request.” Do not include unnecessary health, financial, or identity information in your first email. We may request limited information to verify and fulfill your request.