Plainly, what we hold and why.
Effective 13 August 2026 · Applies worldwide — we hold everyone to the strictest standard we operate under. Looking for the membership agreement? Read the terms.
1. Who we are
The Weekly Root is a weekly wellness newsletter published by Thrive Wellness Network (“we”, “us”, “our”). We are the data controller for the personal information described in this policy.
You can reach us about anything in this policy at thrivewellnessnetwork1@gmail.com, and we aim to answer within five working days.
2. What we collect
We keep the smallest amount of information that lets us deliver the letter reliably and honour your choices.
- Email address — required to send you the newsletter.
- Name — only if you give it, used to personalise greetings.
- Consent record — the date and time you subscribed, the date and time you confirmed, and the page you subscribed from.
- Delivery preferences — your time zone (detected from your browser so the letter arrives at a sensible local hour) and which categories of email you have opted into.
- Membership details — if you become a paying member: your plan, status, renewal date and payment reference. Card numbers are handled entirely by Paystack and never reach our servers.
- Delivery and engagement events — whether an email was delivered, bounced, was marked as spam, or had a link clicked.
- Messages you send us — questions submitted through the Ask page or by email, and our replies.
- Basic technical data — IP address and user agent captured transiently by our hosting and security layers to keep the site available and to stop abuse.
3. How we use it
We use your information to send the newsletter you asked for, to confirm your address, to run and support your membership, to answer your questions, to measure whether the letter is being delivered and read in aggregate, and to keep the service secure.
We do not sell your data, we do not share it with advertising networks, and we do not use it to build individual behavioural profiles for third parties.
4. Consent and legal basis
Marketing emails are sent on the basis of your consent, given by confirmed opt-in: nothing is sent to you until you click the link in the confirmation email we send after you subscribe. We keep the record of that confirmation for as long as you remain subscribed, because it protects you as much as it protects us.
Where consent is not the right basis, we rely on contract (running a membership you have paid for), legitimate interests (security, fraud prevention, keeping the service working), or legal obligation (tax and accounting records).
You can withdraw consent at any time. Every email carries a one-click unsubscribe link, and withdrawal takes effect immediately.
5. Measurement
We record deliveries, bounces, spam complaints and link clicks so we know the letter is arriving and which topics readers find useful. These are reviewed in aggregate. We do not sell engagement data, and when you unsubscribe, measurement stops with the mail.
6. Who processes data for us
We use a small number of vetted providers, each under a data-processing agreement and each limited to what they need to do their job.
- Supabase — database, authentication and file storage.
- Resend — delivery of newsletter, confirmation and onboarding email.
- Paystack — payment processing for memberships.
- Netlify — website hosting and content delivery.
7. International transfers
Our providers operate infrastructure in several countries, so your data may be processed outside the country you live in. Where data leaves the UK or European Economic Area, transfers are covered by Standard Contractual Clauses or an equivalent approved safeguard in our agreements with those providers.
8. How long we keep it
Subscriber records are kept while you are subscribed. If you unsubscribe, we keep a minimal suppression record (your email address and the fact that you opted out) indefinitely, so that we never email you again by accident. If you ask for erasure, we delete everything except that suppression record and anything we must retain by law.
Delivery and engagement events are retained for up to 24 months. Payment and invoicing records are kept for as long as tax law requires, typically six to seven years.
9. Security
Data is encrypted in transit with TLS and at rest by our infrastructure providers. Access to subscriber data is restricted to the accounts that need it and enforced at the database level with row-level security. The site is served with a strict content security policy, and sensitive actions are protected against cross-site request forgery.
No system is perfect. If a breach affecting your personal data occurs, we will notify the relevant supervisory authority and, where the risk to you is high, notify you directly.
10. Your rights
Wherever you live, we extend the same rights to you: access, a portable copy, correction, erasure, restriction, objection, and the right to withdraw consent. Most of these are self-serve, and none of them will make us ask you twice.
If you are in the UK or EEA and think we have handled your data badly, you may complain to your local supervisory authority. We would rather you told us first.
11. Children
The Weekly Root is written for adults and is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has subscribed, contact us and we will remove the record.
12. Changes to this policy
If we change how we handle your data in a way that materially affects you, we will update the effective date below and tell you in the newsletter before the change takes effect.
13. Exercising your rights
Update your details or export your data from your account, change which emails you receive on the preferences page, or leave entirely in one click. For anything else, including erasure, email thrivewellnessnetwork1@gmail.com.