Birth Reimagined

Privacy Policy

We collect as little as we can get away with: an email address, a purchase record, and nothing else. No advertising trackers. No data selling. Your journaling never leaves your hands.

Last updated: 11 September 2026

1. Who is responsible for your data

Brandon Smith, doing business as Natural Birth Reimagined, of 3241 Parrish Road, Titusville, FL 32796, USA, is the data controller for personal data collected through naturalbirthreimagined.com and the Birth Reimagined course portal. For anything in this policy, contact info@naturalbirthreimagined.com.

2. What we collect

Your email address. Given when you claim free access, purchase the course, or sign in. It is your account identifier and how we send you your sign-in link.

Purchase records. When you buy, we store the Stripe checkout session and payment reference, the amount and currency paid, and the date. Stripe also collects your billing details and card information directly — we never see, receive, or store your card number.

Messages you send us. If you use the contact form, we receive the name, email address and message you type. That is delivered to our inbox by email; it is not stored in our database.

Technical data. Like any website, our servers and providers process your IP address, browser and device information, and request timestamps in order to serve pages, apply rate limits that block spam and abuse, and keep error logs. We also receive aggregate video playback data from our video provider (for example whether a module was played and whether it buffered) so we know the portal is working.

What we do not collect. We do not collect or store your journaling entries, your reflections, or anything you write while working through the modules — the course asks you to journal privately, and there is nowhere in our system for that to be sent. We do not collect health data, pregnancy details, due dates, or birth outcomes. We do not run advertising pixels, cross-site trackers, session recording, or heatmaps. We use Vercel’s Web Analytics on our marketing pages to see aggregate traffic like page views and referrers — it is cookieless, does not use a persistent identifier, and cannot track you individually or across other websites. We do not buy or enrich data about you from other sources.

3. Cookies

We use strictly necessary cookies only, which is why you don’t see a cookie banner on this site:

  • Supabase authentication cookies — keep you signed in to the course portal. Without them you would be signed out on every page.
  • nbr_access_tier — a short-lived cookie (one hour, server-side only) recording whether your account has free or paid access, so we don’t have to query the database on every page you open.

Our video and audio players may also use local browser storage to remember playback state. None of these are used for advertising or tracking you across other websites. You can clear or block cookies in your browser, but the portal will not be able to keep you signed in.

4. Why we use it, and our legal basis

  • To give you access to what you signed up for — creating your account, sending sign-in links, unlocking modules. Legal basis: performance of our contract with you.
  • To take payment and issue receipts — via Stripe. Legal basis: contract, and legal obligation for tax and accounting records.
  • To send transactional email — sign-in links, welcome email, purchase receipt, and important service notices. Legal basis: contract.
  • To answer your messages. Legal basis: legitimate interests in responding to inquiries.
  • To keep the service secure and working — rate limiting, abuse prevention, error logs, fraud and chargeback investigation, and enforcing our Refund Policy. Legal basis: legitimate interests in protecting our business and our members.
  • To send occasional emails about the course or new offerings — only if you have opted in. These are sent through ActiveCampaign and Resend. Legal basis: consent, which you can withdraw at any time using the unsubscribe link in any such email or by emailing us. Withdrawing it never affects your course access or the transactional emails you need.

We do not sell your personal data, rent it, or share it with advertisers or data brokers. We do not use it for automated decision-making or profiling.

5. Who processes data on our behalf

We keep the list of providers deliberately short. Each acts as our processor under contract, may only use the data to provide their service to us, and is bound by their own security and privacy obligations:

  • Stripe — payment processing. Receives your payment and billing details directly, and acts as its own controller for fraud prevention and regulatory purposes.
  • Supabase — authentication and database (your email address, access tier, and purchase records).
  • Mux — video hosting, streaming and playback quality monitoring.
  • Wasabi — storage and delivery of the audio and downloadable files, served through short-lived signed links.
  • Resend — sending transactional email, and, alongside ActiveCampaign during our transition between the two, marketing and newsletter email.
  • ActiveCampaign — marketing and newsletter email, if you have opted in to hear from us.
  • Circle — the community and session-booking platform used for our other offerings.
  • Xero — accounting and bookkeeping, which holds our transaction records.
  • Vercel — website and application hosting, including server request logs.

We may also disclose data where we are legally required to — for example in response to a valid legal request or to establish or defend a legal claim — and to professional advisers such as our accountant and bookkeeper, bound by confidentiality. If the business is ever sold or reorganized, member data may transfer as part of it, and this policy would continue to apply to it.

6. International transfers

Our providers are largely based in, or operate infrastructure in, the United States and other countries outside the UK/EEA, which means your data may be processed there. Where data leaves the UK/EEA we rely on the transfer mechanisms our providers have in place — typically Standard Contractual Clauses (with the UK Addendum where relevant) or an applicable adequacy decision — together with the data processing terms in their agreements with us.

7. How long we keep it

  • Account data (email address, access tier) — for as long as your account is open, since access is for life. Deleted on request, subject to the record below.
  • Purchase and refund records — retained for up to seven years after purchase, because tax and accounting law requires it. These survive account deletion, and are kept to the minimum needed (the transaction, not your activity).
  • Contact form emails — kept in our inbox for up to 24 months, then deleted.
  • Server and error logs — short-term only, per our providers’ retention settings, typically 30 days or less. Rate-limiting records are held in memory and are not written to disk.

8. Your rights

Depending on where you live, you have some or all of the following rights over your personal data:

  • access — a copy of what we hold;
  • rectification — correcting anything inaccurate;
  • erasure — deleting it, where we don’t have an overriding legal obligation to keep it;
  • portability — receiving it in a machine-readable format;
  • restriction and objection — asking us to pause or stop a particular use;
  • withdrawal of consent — for marketing email, at any time;
  • the right not to be discriminated against for exercising any of these rights.

Email info@naturalbirthreimagined.com from the address on your account and we will respond within 30 days. We may need to confirm your identity first — usually by verifying you control the account email — so that we don’t hand your data to someone else. Requests are free; we may charge a reasonable fee only for repetitive or excessive requests.

Deleting your account also ends your access to the course, including your lifetime access. We will say so clearly before acting on the request.

If you are in the UK or EEA and think we have handled your data badly, you can complain to your national data protection authority (in the UK, the Information Commissioner’s Office). We would appreciate the chance to put it right first.

9. If you are in California

Under the CCPA/CPRA, the categories of personal information we collect are identifiers (your email address), commercial information (your purchase record), and internet or network activity (technical and playback data described above). We collect them for the business purposes set out in section 4.

In the last 12 months we have not sold personal information, and we have not shared it for cross-context behavioral advertising. We do not use or disclose sensitive personal information beyond what is needed to provide the service. We do not knowingly collect information from minors. You may exercise your rights to know, delete, correct, and opt out using the contact details above, and you may use an authorized agent — we will ask for proof of their authority. We do not offer financial incentives for your data.

10. Children

This service is for adults. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, email us and we will delete it.

11. Security

We take security seriously and keep the attack surface small. All traffic is served over HTTPS with strict transport security; the site sets a content security policy and related protective headers; database access is protected by row-level security so an account can only read its own record; privileged keys are held server-side only and never exposed to the browser; audio and video are served through short-lived signed links rather than public URLs; and we never store card data.

No system is perfectly secure. If a breach affects your personal data and creates a risk to you, we will notify you and the relevant regulator as required by law. If you spot a security problem, please report it to info@naturalbirthreimagined.com — we welcome it.

12. Do Not Track and Global Privacy Control

We don’t track you across websites and we don’t serve behavioral advertising, so there is nothing for a Do Not Track or Global Privacy Control signal to switch off. We honor them by default.

13. Changes to this policy

We may update this policy as the service changes. The current version always lives at this URL with the date it was last updated. If a change materially affects how we use your data, we will email members before it takes effect.

14. Contact

Brandon Smith, doing business as Natural Birth Reimagined
3241 Parrish Road, Titusville, FL 32796, USA
info@naturalbirthreimagined.com
Or use our contact form.