Privacy Policy

Effective date: 23 July 2026
Last updated: 23 July 2026
Version: 1.0

1. Who we are

Evolve Within is a sole-trader business based in England & Wales. We provide evidence-based digital wellbeing content, assessments, programmes, and membership services to help people recover from burnout, rebuild identity, and develop sustainable confidence.

This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have over it under the UK GDPR and UK data protection law.

2. What personal data we collect and why

We collect personal data only when you choose to share it with us, or when our systems automatically collect it to make our website work.

2.1 Information you give us directly:

  • Assessment responses — when you complete the “Come Back to Yourself” assessment or any other self-assessment on our site. Legal basis: consent. We use this to score your assessment, show you your result, and segment you into a relevant support pathway.
  • Email address — if you choose to receive your assessment result or join our email list via MailerLite. Legal basis: consent. We keep your email address to send you the content you requested and, if you consent, future messages about resources that may help you.
  • Order and payment data — name, email address, and purchase history when you buy a product or join a membership. Legal basis: contract (to fulfil your order). We keep this data for as long as required by UK tax law (typically 6 years for financial records).
  • Membership account data — when you join our membership (Your Place). This includes name, email, password (encrypted), payment details (processed securely by our payment processor, never stored by us), account preferences, and membership history. Legal basis: contract. This data is kept for the duration of your membership and 12 months after cancellation for billing records.

2.2 Information collected automatically:

  • Analytics data — we use Google Analytics 4 (via Site Kit by Google) and Meta Pixel to understand how visitors use our site: which pages they visit, how long they stay, where they come from. Legal basis: legitimate interest (to improve our service and understand demand). This data does not identify you personally.
  • Technical data — IP address, browser type, device type, pages visited, timestamp. This helps us detect and fix problems. Legal basis: legitimate interest.
  • Cookies — essential cookies (to keep you logged in) and analytics cookies (with your consent, via Complianz). See our Cookies Policy for full details.

3. Who we share your data with

We only share your personal data with service providers who help us run our business. We do not sell your data to any third party, for any reason.

  • Hostinger — web hosting and infrastructure. They may store data on servers located in different countries; they follow UK GDPR safeguards.
  • WooCommerce and WooPayments — order processing and payments. We do not store your payment card details; these are handled securely by our payment processors and never stored on our servers.
  • PayPal — secondary payment processor, if you choose PayPal at checkout. PayPal’s own privacy policy applies to their processing.
  • MailerLite — email marketing platform. We send your email address to MailerLite only if you consent to receive emails. MailerLite stores your email and engagement data (opens, clicks) and uses it to send you requested messages and segmented content based on your assessment result. MailerLite’s privacy policy applies to their processing.
  • MemberPress — membership management platform. If you join our membership, your account data (email, name, password hash, membership status, payment history) is stored in MemberPress. MemberPress follows UK GDPR safeguards.
  • Complianz — consent management platform (Consent Mode v2). We use Complianz to record your cookie and consent preferences and ensure analytics only run when you’ve consented.
  • Google Analytics 4 — analytics data is processed by Google to show us how visitors use our site. Google’s privacy policy applies; your data may be transferred outside the UK with appropriate safeguards in place.
  • Meta Pixel — Meta’s conversion tracking pixel. We use this to understand which visitors take actions on our site (like purchase or assessment completion). Meta’s privacy policy applies to their processing.

4. International data transfers

Some of our service providers (Google, Meta, PayPal, Hostinger) may store or process data outside the UK or EEA, commonly in the United States. Where this happens, we rely on their Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs), which are recognised under UK GDPR as providing adequate protection. You can ask us for a copy of these safeguards.

5. How long we keep your data

  • Assessment responses — kept for as long as your MailerLite subscription is active, to inform your segmentation and recommended content. Deleted when you unsubscribe.
  • Email address and engagement data — kept until you unsubscribe from our email list or request deletion. If you are a member, kept until you cancel your membership.
  • Order and payment data — kept for 6 years (for tax and accounting purposes under UK law), then permanently deleted.
  • Membership data — kept while you are a member, then for 12 months after cancellation (for billing and dispute resolution), then deleted.
  • Analytics data — Google Analytics retains data for 14 months by default, then deletes it. Meta Pixel data follows Meta’s retention policy.
  • Technical/server logs — kept for 30 days, then deleted.

6. Your rights under UK GDPR

You have the right to:

  • Access your data — ask what personal data we hold about you.
  • Correct your data — if any information is wrong, ask us to fix it.
  • Delete your data — in most cases, ask us to delete your personal data (the “right to be forgotten”). Exception: we may keep financial records for 6 years if required by UK law.
  • Restrict processing — ask us to stop processing your data in certain ways while you consider whether to request deletion.
  • Data portability — ask for your data in a machine-readable format so you can transfer it to another service.
  • Withdraw consent — if we’re relying on your consent to process data (e.g., email marketing), you can withdraw that consent at any time. You can unsubscribe from emails using the link in every email we send.
  • Object to processing — in some cases, you can ask us to stop processing your data on the basis of legitimate interest.

To exercise any of these rights, email connect@evolvewithin.co.uk with details of your request. We will respond within one month. If you’re not happy with how we handle your data, you can also contact the Information Commissioner’s Office (ICO) at www.ico.org.uk.

7. Cookies and similar technologies

Our website uses cookies to function and, with your consent, to understand how you use it. See our Cookies Policy (link in footer) for full details about which cookies we use and how to manage your preferences. We use Complianz to manage your consent preferences and ensure analytics only run when you’ve opted in.

8. Children’s data

Our services are not intended for anyone under 18. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us immediately at connect@evolvewithin.co.uk and we will delete it.

9. Data security

We protect your personal data using industry-standard security measures, including encryption in transit (HTTPS) and at rest where appropriate. Our hosting provider (Hostinger) uses firewalls and regular security monitoring. Payment data is processed securely by our payment processors and is never stored on our servers.

However, no security system is 100% secure. If you believe your data has been compromised, please contact us immediately.

10. Changes to this policy

We may update this Privacy Policy as our business grows or our tools change. If we make material changes, we will notify you by email (if you’re subscribed) or by updating this page. The version date at the top of this page shows when it was last updated.

11. Contact us

Evolve Within
A UK sole-trader business
England & Wales
Email: connect@evolvewithin.co.uk

If you have questions about this Privacy Policy or how we handle your data, please email us above. For data protection concerns, you can contact the ICO at www.ico.org.uk or call 0303 123 1113.


This Privacy Policy was prepared in accordance with UK GDPR and the Data Protection Act 2018. Last reviewed and updated: 23 July 2026.