Thank you for visiting our website (“Site”). Sensei Wellness Holdings, Inc., on behalf of itself and its affiliates (“Sensei,” the “Company,” “we,” “us” or “our”) is providing this Privacy Policy to describe the Personal Information (as described herein) that Sensei collects, stores and uses through our interactions with you and through our resorts, retreats, products, services, events and programs – including our Sites, mobile applications and digital platforms (each a “Service,” and collectively, the “Services”). This Privacy Policy, together with our Terms of Use and other policies we refer to in this Privacy Policy, describes how Sensei collects and uses your Personal Information, and how you can exercise certain rights with respect to your Personal Information.
If you are a resident of a state that has adopted comprehensive privacy legislation, this Privacy Policy outlines additional information applicable to our collection and use of your Personal Information, and how you can exercise your rights under state law, which can be found in State Privacy Rights.
If you are a resident of the European Economic Area (“EEA”) or the United Kingdom (UK) this Privacy Policy also outlines additional provisions applicable to our collection and processing of your Personal Information, which can be found here. Non-EEA countries do not have the same data protection laws as the EEA. We will, however, take steps to ensure that any transfer of personal information will be secure and complies with applicable data protection laws.
By submitting your Personal Information to us, you agree to the processing set out in this Privacy Policy. If there are any additional uses of your Personal Information that are not described in this Privacy Policy, then we will provide you with the necessary information and consult you on such additional uses in accordance with applicable law.
2. Personal Information We Collect
3. Sensitive Information We Collect
4. Information from Business Partners
5. How We Use Personal Information
7. How We Share and Disclose Data
8. Cookies and Similar Technologies
10. Third Party Sites and Services
11. Notice Regarding Health Information
15. Additional Policies for Residents of EEA and UK
16. Changes to This Privacy Policy
This Privacy Policy describes how Sensei collects, uses, and shares Personal Information of our guests, visitors to our Site at www.sensei.com, and individuals who contact us to request information. The Site and our other programs and services are referred to in this Privacy Policy as the “Services.” This Policy describes how we collect and use Personal Information (information which can be used to identify a specific individual) and anonymous data (which cannot be used to identify a specific individual).
Region specific provisions. Certain provisions of this Policy, which are clearly labelled, apply only to users who are citizens or residents of particular regions (for example,, the European Economic Area or California). Otherwise, this Policy applies to all users of our Services, regardless of location.
Children. Our Services are not directed to children. See Protecting children’s privacy below.
For purposes of this Privacy Policy, “Personal Information” means information (whether stored electronically or in a paper based filing systems) relating to a living individual who can be identified from that data, or from that data and other information in our possession.
When you interact with us through the Services, we may collect Personal Information from you or from other sources. This data may be information that you directly provide to us, such as Personal Information you provide when you visit our retreats, or information we collect when you use the devices we offer, or from your browser or mobile device. When you use the wearable devices we offer as part of the Services, we collect a variety of medical information discussed below in “Sensitive Information We Collect.” We also collect Personal Information from our affiliates, partners, vendors, data brokers and public sources.
The table below describes the categories of Personal Information we may collect:
Category | Description |
Identifiers | Name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number or state identification card number, passport number, or other similar identifiers |
Protected Classes | Race, age, gender, religion, citizenship, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information |
Commercial Information | Records of personal property, purchasing or consuming histories or preferences |
Biometric Information | Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to obtain identifying information, such as fingerprints, face prints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data |
Internet Activity | Browsing history, search history, IP address, website interactions |
Geolocation Data | GPS coordinates, location history or movements |
Sensory Data | Audio, electronic, visual, thermal, olfactory, or similar information |
Professional Data | Current or past job history or performance evaluations |
Education Data | Educational background, grades, scores |
Other Data | Financial information, medical information, health insurance information |
Inferences | Profiles drawn from other Personal Information reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes. |
The examples given in this table are not meant to provide an exhaustive list, but are examples of the kinds of data included in each category. We do not collect all of this data, and we specify the categories of information we do collect below.
In addition to the Personal Information described above, we may collect Sensitive Information from or about you. In this Privacy Policy, “Sensitive Information” means Personal Information that is subject to heightened legal protection in certain jurisdictions. Sensitive Information may include:
We collect the Sensitive Information that you voluntarily provide to us directly or indirectly, including through the use of our Services, any Sensei Site or portal, an electronic tracking or monitoring device or use of an instrument or equipment, or any third-party website or software application connected to Sensei. We will only use your Sensitive Information with your explicit consent or as authorized by law.
Sensei collects Personal Information from its vendors and business partners. Sensei collects that information in the course of our business dealings:
When you or the company you work for interacts with Sensei (for example, when providing technical services to us), we may collect the following types of Personal Information:
We use the Personal Information we collect for the following purposes:
We may also use your data in any other manner as disclosed at the time of collection, or when we have otherwise obtained consent. Please also note that this Privacy Policy does not place any limits on what we do with aggregated, pseudonymized or anonymized data.
If you use a mobile device to access pages of the Site optimized for mobile viewing, opt in to receive SMS (text messages) from Sensei (as/when available), or use a mobile application, the following additional terms and conditions (“Mobile Terms”) also apply to you. Your access to the Site via your mobile device or use of a mobile application confirms your agreement to these Mobile Terms, as well as the rest of the Terms of Use. By opting in, you agree to receive promotional and personalized marketing text messages (e.g., SMS and MMS) on your mobile device from Sensei, including text messages that may be sent using an automatic telephone dialing system, to the phone number you provided when signing up or any other phone number that you designate. These messages may be recurring or one-time messages. Message frequency varies. Sensei reserves the right to alter the frequency of messages sent at any time, so as to increase or decrease the total number of sent messages. Sensei also reserves the right to change the short code or phone number from which messages are sent and we will notify you when we do so.
Your consent is not required as a condition of purchasing any goods or services from Sensei. You can opt out at any time and for any reason by following provided instructions or by texting “STOP” to the number associated with the SMS message. You will receive one further message confirming you are unsubscribed. You acknowledge that our text message platform may not recognize and respond to unsubscribe requests that do not include the STOP keyword command and agree that Sensei and its service providers will have no liability for failing to honor such requests. If you unsubscribe from one of our text message programs, you may continue to receive text messages from Sensei through any other programs you have joined until you separately unsubscribe from those programs. If you wish to join again, you can opt in at any time. If you have any questions or require further assistance, you may respond “HELP” to the number associated with the SMS message. For more information, please contact us by emailing privacyinfo@sensei.com (please reference “Questions about SMS”).
By agreeing to receive SMS messages from Sensei, you certify that you are over 18 years of age and (a) you are the mobile account holder or (b) you have the account holder’s permission to enroll the designated mobile phone number and understand that message and data rates may apply. You agree that you are solely responsible for all message and data charges that apply to use of your mobile device to access the Site or use of a mobile application. All such charges are billed by and payable to your mobile service provider. Not all mobile devices or handsets may be supported and our messages may not be deliverable in all areas. Please contact your participating mobile service provider for pricing plans, participation status and details. Sensei, its service providers, and the mobile carriers are not liable for delivered or undelivered content. You understand that wireless through Wi-Fi or a participating mobile service provider may not be available in all areas at all times and may be affected by product, software, coverage or other service changes made by your mobile service provider or otherwise. Additional terms and conditions may apply to your use of a mobile application, based on the location and nature of use and the type of mobile device on which you install and use the mobile Application.
There are times when we share Personal Information with other companies. We share Personal Information for the following purposes:
We may also share your Personal for others purpose that we disclose at the time we collect the Personal Information, or when at other times that you give us your consent.
We use cookies and similar technologies (collectively, “Tracking Technologies”) to provide the Services and to collect data. In addition, third parties may also use Tracking Technologies when you use the Services; for example, if we engaged a third party to operate the Services, or because the Services contain content delivered by third parties. These Tracking Technologies consist of:
We use Tracking Technologies for the following purposes:
Some browsers have incorporated “Do Not Track” features that send an automated signal to the websites that you visit using that browser. At this time, the Services do not recognize or respond to these signals. However, you can adjust your preferences regarding the data we collect using the tools and methods described above.
We take steps to protect your data from unauthorized access, use and disclosure. These steps take into account the sensitivity of the data we collect and use, as well as the current state of technology. This includes, for example, storing your data on systems that have limited access and are maintained in controlled facilities. We also use, and require our vendors to use, industry standard security protocols when processing any payments for your use of the Services.
It is important to remember that no system can be guaranteed to be completely secure. We recommend that you help us keep your data safe by taking reasonable steps such as keeping your passwords private and not disclosing sensitive Personal Information in places that can be accessed publicly.
We work with a number of third parties to operate the Services. When we engage third parties in connection with operating the Services, those third parties may only collect, use or access your data as needed for them to perform these functions. These third parties include: Cendyn, Oracle Opera, Alice, Book4Time, NetSuite, Asana, PayCom, Navia, Microsoft, OKTA, CARTA, Expensify, TeamPay.
These third parties are only authorized to use your Personal Information as permitted by this Privacy Policy, or as disclosed to you at the time your data is collected. Please note, however, that these third parties may supplement data collected or received in connection with the Services with data they collect or receive through other websites, platforms and services, in accordance with the policies and disclosures posted on those websites, platforms and services. Within the past twelve months, we have disclosed the following categories of Personal Information to third parties: personal identifiers, commercial information, Internet/other electronic network activity information, geolocation data, characteristics of protected classifications, and inferences drawn from this information.
The Services may also contain links to, or integrations with, other websites, platforms or services that are not operated or controlled by Sensei (each a “Third Party Site,” and collectively, the “Third Party Sites”). Please note that this Privacy Policy does not apply to those Third Party Sites. For more information on how those Third Party Sites collect, use and share data, we suggest that you contact the operators of those Third Party Sites directly.
This additional notice applies to personal information relating to your health, including personal information defined as “consumer health data” and similar terms (collectively referred to as “Health Information”) under applicable laws, including but not limited to Washington State’s My Health My Data Act and Nevada’s similar statute (SB 370).
What Health Information do we collect?
We collect Health Information that you voluntarily provide to us and that is reasonably necessary for us to provide you with the products and services that you request. For example, when booking a spa service or stay, or if you otherwise share with us such data, we may collect certain, limited information about your preferences (including for an accessible room), health conditions, diagnosis, and treatments (including procedures and medications).
Will Health Information be provided to third parties?
We may share your Health Information, where permitted under applicable law with:
We take steps to require those parties to protect your Health Information in a manner consistent with the provisions of this Privacy Policy.
We may also disclose information as may be required by law or legal process, or if we reasonably believe such disclosure is necessary to comply with legal process or the reasonable requests of law enforcement or to exercise or protect the rights, property or personal safety of Four Seasons, our Guests or Owners, or others.
What are your rights with respect to your Health Information?
You may have the right to: (1) access your Health Information, including a list of all third parties and affiliates with whom we may share Health Information; (2) withdraw your consent to our processing of your Health Information; and (3) request the deletion of your Health Information. You may also have other rights under the laws of your jurisdiction of residence, or as further described in State Privacy Rights below. You can exercise your rights by submitting a request as described in State Privacy Rights.
Additional Appeal Rights Under Nevada and Washington Law
If your request to exercise a right with respect to your Health Information is denied, under Washington’s My Health My Data Act or Nevada’s SB 370, if you are a resident of either state or your request relates to the processing of Health Information within those states, you may appeal that decision by contacting us at privacy.officer@fourseasons.com. If your appeal is unsuccessful, you can raise a concern or lodge a complaint with, as appropriate, the Washington State Attorney General at www.atg.wa.gov/file-complaint or the Nevada State Attorney General at https://ag.nv.gov/Complaints/File_Complaint/.
The Services are not directed at children under the age of 16, and our policy is to not knowingly collect Personal Information from children under the age of 13, nor to sell Personal Information of individuals under the age of 16. We encourage parents and guardians to monitor their children’s online behavior, put parental control tools in place, and teach children not to provide their Personal Information through the Services without parental consent. For certain activities in which children are allowed to participate, any request for Personal Information (such as registration data) is intended for and directed to the parent or legal guardian.
If you have reason to believe that a child under the age of 13 has provided Personal Information to us without parental consent, please contact us using any of the methods described in the “How to Contact Us” section of this Privacy Policy, and we will endeavor to delete that data from our systems.
For children located in jurisdictions within the EU, we comply with the age limits applicable in each Member State. In these instances, the references above to the age of 13 will be deemed to be references to the age limits applicable in each Member State. Where this Privacy Policy refers to consent, this will require the consent of a parent or legal guardian in relation to any person under the age limits applicable in each Member State.
Personal Information collected by Sensei may be stored and processed in the region in which it is collected, in the United States, and in any other region where we maintain major operations. We maintain offices in Santa Monica, California, and Lanai, Hawaii. We take steps to ensure that the data we collect under this Privacy Policy is stored and processed in accordance with this Privacy Policy regardless of where the data is located. By providing Personal Information in connection with the Services, you acknowledge and agree that such Personal Information may be transferred from your current location to the offices and servers of Sensei and our authorized third party service providers located in the United States. Our practice when transferring Personal Information is to rely on standard data protection contract clauses or individual consent.
We retain Personal Information for as long as necessary to provide the Services and fulfill the transactions you have requested, or for other necessary purposes such as complying with our legal obligations, resolving disputes and enforcing our agreements. Because these factors vary for different types of Personal Information, actual retention periods may vary. The criteria we use to determine the appropriate retention periods include:
This section supplements our Privacy Policy with additional information for residents of states that have adopted privacy laws giving their residents certain rights with respect to the personal information we collect. Effective July 1, 2024, comprehensive privacy laws are in effect in California, Colorado, Connecticut, Oregon, Texas, Utah and Virginia. . As noted above, we collect data that you provide directly when you register for or use the Services, user credentials that you supply directly when you register for or update your login information to use the Services, demographic data, payment data, device data, usage data, location data, information about your interests and preferences, third party integrations, and other third party data. In accordance with the privacy laws adopted by these states, residents have the right to request that we disclose the following information about our collection and use of Personal Information over the twelve months prior to your request:
Oregon-specific Rights
In addition to the rights listed above, under the Oregon Consumer Privacy Act (“OCPA”), Oregon residents may request a list of specific third parties that have received from us either the resident’s specific personal data or the personal data.
California-specific Rights
In addition to the rights listed above, California has adopted the California Consumer Privacy Act (“CPPA”), which gives California consumers have the right to not be discriminated against because the consumer exercised any of the consumer’s rights under the CCPA. That means that a company may not deny goods or services to the consumer, charge different rates for goods or services, or provide a different level or quality of goods or services if the consumer chooses to exercise their rights under the CCPA (unless the different rate or different level or quality is reasonably related to the value to the business of the consumer’s data). We will not deny you any Services or charge you a different price, level or quality of Services because you exercise any of your rights under the CCPA; however, we may not be able to provide the Services if you refuse to provide us the Personal Information that is necessary for us to provide the Services, or if you ask us to delete your Personal Information.
Additionally, CCPA regulations require us to disclose metrics for the previous calendar year regarding the requests we receive. Those metrics are available at privacyinfo@sensei.com.
Health Information
You may have additional rights with respect to Health Information under Washington’s My Health My Data Act or Nevada’s SB 370. See Notice Regarding Health Information above.
We do not sell your Personal Information.
In addition to the other policies described in this Privacy Policy, residents of the EEA and UK are afforded the following additional rights and protections as required by the EU’s General Data Privacy Regulation (“GDPR”) and the UK’s Data Protection Act. The additional rights and protections set forth in this section of this Privacy Policy apply only to residents of the European Union or the EEA. For ease of reference, when we refer to GDPR in this section, we are referring to the UK Data Protection Act, as well as the GDPR. For the purposes of the GDPR, Sensei is a “Controller” which means Sensei determines the purposes for which, and the manner in which, any Personal Information is Processed and used in its business.
The following additional definitions apply to this Section of the Privacy Policy:
“Processor” means any Person Processing Personal Information.
“Person” means a natural person, corporation, association, organization, partnership, or other legal entity.
“Processing” is any activity that involves use of the Personal Information. It includes, without limitation, obtaining, recording or holding the Personal Information, or carrying out any operation or set of operations on the Personal Information including organizing, amending, retrieving, using, disclosing, erasing or destroying it. Processing also includes transferring Personal Information to third parties.
In order to comply with the GDPR, we are required to set out the legal basis for the processing of your Personal Information. In accordance with the purposes for which we collect and use your Personal Information, as set out above, the legal basis for processing your Personal Information will typically be one of the following:
The data that we collect from you is stored on our servers or on servers provided by cloud service providers. If you are a resident of the EEA, your Personal Information may be transferred within or outside the EEA to areas where privacy laws may be less strict than in the EEA. By submitting your Personal Information, you agree to this transfer, storing, and processing. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy.
The transmission of information via the Internet is not completely secure. Although we take reasonable efforts to protect your Personal Information, we cannot guarantee the security of your data transmitted to our Site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorized access.
In some cases, there is a legal requirement to keep Personal Information for a minimum period of time. Except in those circumstances, we do not keep your Personal Information for any longer than is necessary for the purposes for which the Personal Information was collected or for which it is to be further processed.
Subject to certain exceptions, you have the following rights with respect to your Personal Information:
All of these rights are subject to certain conditions and exemptions. For example, we are not obligated to erase your Personal Information if we need to retain it to protect ourselves in the event of a legal claim.
To exercise any of these rights, please submit a written request to us using the contact information set forth below. The Company reserves the right to charge a fee in dealing with such a request as permitted by applicable law and regulations. You may also opt out of receiving additional marketing information by using the unsubscribe feature in any marketing email we send you.
We may change this Privacy Policy from time to time to reflect changes in our business, the Services, or our practices and procedures. If we do make changes, we will post any changes on this page and indicate the date on which the Privacy Policy was last revised. We encourage you to review this Privacy Policy periodically, especially before you provide Personal Information directly to us through the Services. Your continued use of the Services after any changes to this Privacy Policy are in effect constitutes your acceptance of the revised Privacy Policy.
Although we strive to make this Privacy Policy as comprehensive as possible, we know you may still have questions or concerns about how we collect, use and share data. If you have a question, concern or complaint regarding our data privacy practices, you may contact us by any of the following methods:
By writing to us at 1119 Colorado Ave, Suite 18, Santa Monica, CA 90401, attention Tim P. Chun.
By sending an email to privacyinfo@sensei.com; or
By calling us at 866-588-3080.
Last Updated: September 26, 2024