PRIVACY POLICY

# Privacy Policy

Last Updated: September 1, 2026

This Privacy Policy explains how Brooke Neborsky LLC, a Hawaii limited liability company doing business as Daily Self Massage and Après Surf (“Company,” “we,” “us,” or “our”), collects, uses, shares, and protects personal information.

We are the controller of personal information described here. Our Daily Self Massage website is https://dailyselfmassage.com. Our Après Surf shop is https://www.apressurfmaui.com.

## 1. Scope

This Policy applies to:

1. https://dailyselfmassage.com, including course pages, checkout, login, and blog.
2. Daily Self Massage course accounts and course-progress records.
3. Notify-me, contact, and similar forms on the Daily Self Massage site (including WPForms and Contact Form 7).
4. Advertising and analytics technologies we place on the Daily Self Massage site, including the Meta (Facebook) Pixel described below.

The same company also operates Après Surf. If you shop at https://www.apressurfmaui.com, Shopify collects and processes shop information on our behalf. We may combine Après Surf shop information with Daily Self Massage information (for example, if you use the same email on both) so we can recognize you as a customer of the same business, fulfill orders, and, where allowed, send relevant updates. Shopify’s own privacy terms also apply to that shop.

This Policy does not apply to third-party websites we merely link to, except to the extent we receive information back from a vendor listed in Section 6.

## 2. Categories of information we collect

We collect the following categories, depending on how you use the Services.

### 2.1 Information you give us

1. Identity and contact: name, email address, and, if you provide it, phone number or mailing address.
2. Account credentials: username or email and a password (stored in hashed form by our site tools).
3. Commercial information: which course you buy (for example, Release Your Jaw at $247), discount codes, and purchase timestamps.
4. Communications: messages you send through forms or email, including any health-related details you choose to include (for example, a question about jaw pain). We do not ask you to complete a medical history in order to buy a course. If you volunteer health information, we use it only to respond and to keep a record of the conversation.
5. Notify-me signups: email address and which coming-soon course you asked to hear about.

We do not collect your full payment card number on our Site. Course payments are handled by PayPal. Après Surf shop payments are handled through Shopify’s checkout.

### 2.2 Information collected automatically

1. Device and log data: IP address, browser type, device type, operating system, referring URL, pages viewed, dates and times, and approximate location derived from IP address.
2. Course usage: lessons opened, progress, and similar interactions needed to deliver the course.
3. Cookies and similar technologies: see Section 12. This includes the Meta Pixel (Pixel ID 1317941479517067), which may collect identifiers, page views, and events such as viewing a course page or starting checkout.

### 2.3 Information from service providers

PayPal may tell us that a payment succeeded or failed, a PayPal transaction ID, the payer email associated with the payment, and similar confirmation data. Vimeo may provide video playback technical data. Hostinger provides hosting and server logs. Shopify may provide Après Surf order data to us as the shop owner.

### 2.4 Information we do not intentionally collect

We do not require sensitive government IDs. We do not sell courses to children. We do not use the Meta Pixel or forms to build a dossier of medical diagnoses. Course content is educational self-massage. It is not a clinical intake.

## 3. How we use information

We use personal information to:

1. Create and maintain your account and provide course access.
2. Process payments and keep records of what you bought.
3. Deliver digital content, including streaming video through Vimeo.
4. Send transactional messages (receipts, access instructions, password resets, material changes to terms or this Policy).
5. Respond to questions and support requests.
6. Send launch or marketing emails if you asked us to (for example, a notify-me form). You can unsubscribe using the link in those emails or by writing info@dailyselfmassage.com.
7. Operate, secure, debug, and improve the Site.
8. Measure ads and, where permitted, show or measure Daily Self Massage advertising on Meta properties. This uses the Meta Pixel described in Section 12.
9. Combine Daily Self Massage and Après Surf records as described in Section 1.
10. Detect fraud, abuse, or Terms violations.
11. Comply with law, tax, and accounting duties, and defend legal claims.

## 4. Legal bases (GDPR and UK GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, we process personal information on these bases:

1. Contract. We process account, purchase, payment-confirmation, and course-delivery data to perform our contract with you, including these Terms, checkout, and course access.
2. Legitimate interests. We process security logs, limited analytics needed to keep the Site working, fraud prevention, ordinary customer records, and combination of our two brand records where that is reasonably expected for one company. Our interest is running a small, lawful online course business and protecting it. You may object as described in Section 10.
3. Consent. We rely on consent for optional marketing emails and for non-essential cookies and similar technologies, including the Meta Pixel, where consent is required. You may withdraw consent without affecting the lawfulness of processing before withdrawal. Withdrawing consent for marketing cookies does not cancel your course.
4. Legal obligation. We keep transaction records as needed for tax, bookkeeping, and lawful requests.

Where we rely on legitimate interests, we do not use that basis to override your rights in a way the GDPR does not allow. We do not use special-category health data to target ads.

## 5. Recipients (who we share with)

We disclose personal information to the following categories of recipients. We do not sell personal information for money. Sharing for ads is described in Section 8.

1. PayPal. Course payment processing and fraud checks. PayPal receives the payment details you enter on PayPal’s flow, plus the amount and our account information needed to complete the charge.
2. Hostinger. Website hosting, storage, and related infrastructure for https://dailyselfmassage.com.
3. Vimeo. Hosting and playback of course videos. Vimeo may receive technical data when you play a video.
4. Meta Platforms, Inc. and its affiliates. If marketing cookies are active, the Meta Pixel may transmit identifiers (such as cookie IDs and IP address), site events, and hashed or other matching data Meta uses for ads and measurement. Pixel ID: 1317941479517067. This is “sharing” for cross-context behavioral advertising under California law. See Section 8.
5. Shopify. Après Surf shop operations at https://www.apressurfmaui.com. Shopify is not the processor of Daily Self Massage course payments. If you are a shop customer, Shopify processes that shop order. We may receive order and customer records from Shopify as the merchant.
6. WordPress, Elementor, WPForms, and Contact Form 7 tools, and our email and hosting stack. These run the Site, forms, and message delivery.
7. Professional advisers and authorities. Accountants, attorneys, or government bodies when reasonably necessary for tax, legal claims, or a binding request.

Each recipient processes information under its own terms as well as, where we have a contract, our instructions. We do not authorize these parties to use Daily Self Massage customer lists to sell their own unrelated products, except as inherent in a platform (for example, Meta using event data to provide the ad service we asked for).

## 6. International transfers

We are based in the United States. Hostinger, PayPal, Vimeo, Meta, Shopify, and other vendors listed above may process information in the United States and other countries.

If you are in the EEA, UK, or Switzerland, this means your information is transferred to a country that may not have an adequacy decision covering every recipient. We use appropriate safeguards available to a small business, including vendor contracts and the security measures in Section 9. We do not currently claim certification under the EU-US Data Privacy Framework in this Policy. By using the Site or buying a course, you understand that US law applies to our handling as described here, in addition to any non-waivable rights you have at home.

You may contact us for more detail about a particular vendor transfer.

## 7. Retention

We keep information only as long as needed for the purposes above, including:

1. Account and course-progress data: for as long as your account is active and you have course access, then for a reasonable period after closure so we can restore access if you write to us, resolve disputes, and maintain security.
2. Purchase and payment-confirmation records: generally up to seven years, or longer if a tax, accounting, or legal hold requires it.
3. Support emails and form messages: generally up to three years after the last message, unless a dispute requires longer.
4. Notify-me and marketing email lists: until you unsubscribe or we delete an inactive list, plus a suppression record so we do not email you again by mistake.
5. Server logs: a shorter operational period unless needed for security investigation.
6. Cookie and pixel data: according to Section 12 and the third party’s retention.

When we no longer need information, we delete or de-identify it. Backup copies may persist for a limited time until they cycle out.

## 8. California and US state privacy (including CPRA “sharing”)

### 8.1 We do not sell for money. We may share for ads.

We do not sell personal information for money.

We may share identifiers and internet activity (such as cookie identifiers, IP address, and site events) with Meta for cross-context behavioral advertising through the Meta Pixel (Pixel ID 1317941479517067). Under the California Consumer Privacy Act as amended by the CPRA, that is “sharing,” even though no money changes hands.

We do not claim that we “do not sell or share” personal information. The accurate statement is: we do not sell personal information for money, and we may share identifiers with Meta for ads.

### 8.2 How to opt out of sharing for ads

You can opt out of this sharing in any of these ways:

1. Cookie banner. Choose “Reject non-essential” or turn off marketing cookies under “Manage.”
2. Email. Write to info@dailyselfmassage.com with the subject line “Your Privacy Choices” and tell us you want to opt out of sharing for advertising. Use the email associated with your account if you have one.
3. Your Privacy Choices. Use the “Your Privacy Choices” link in the Site footer. That control opens cookie preferences so you can switch off marketing cookies, including the Meta Pixel.

Opting out of sharing does not delete your course account and does not stop strictly necessary cookies needed to log in, check out, or play content you requested.

If we detect a legally recognized opt-out preference signal that we are required to honor (including Global Privacy Control, where we have implemented support), we will treat it as a request to opt out of sharing for advertising for that browser.

### 8.3 Categories, sources, purposes, and disclosure

In the last 12 months we have collected, and we expect to collect, the categories in Section 2. Sources are: you, your device, PayPal (payment confirmation), Shopify (Après Surf shop, if you shop there), and advertising/analytics partners if marketing cookies are on.

We use them for the purposes in Section 3. We disclose them to the recipients in Section 5. We share identifiers and internet activity with Meta for advertising as described in this Section 8. We do not sell personal information for money. We do not use or disclose sensitive personal information for purposes that require a separate “limit the use” right beyond ordinary service and compliance, and we do not use health details you volunteer in a support email for advertising.

We do not have actual knowledge that we sell or share the personal information of consumers under 16.

### 8.4 Your US state privacy rights

If you are a resident of California, Colorado, Connecticut, Virginia, Utah, or another US state that gives you consumer privacy rights, you may have the right to:

1. Know and access the personal information we hold about you.
2. Correct inaccurate personal information.
3. Delete personal information, subject to legal exceptions (for example, records of a purchase we must keep).
4. Obtain a portable copy of certain information.
5. Opt out of sharing for cross-context behavioral advertising, as in Section 8.2.
6. Opt out of targeted advertising or profiling in furtherance of decisions that produce legal or similarly significant effects, to the extent we do that. We do not use automated profiling to deny you housing, credit, or employment. Course access is based on payment and the Terms, not on a secret score.
7. Not receive discriminatory treatment for exercising these rights.

Submit a request by emailing info@dailyselfmassage.com. We will verify your identity (for example, by confirming control of the email on the account). An authorized agent may submit a California request as allowed by law. We will respond within the time those laws require, generally 45 days, with an extension if needed and permitted.

If we deny a request, you may appeal by replying to our decision email with the word “Appeal.”

California’s Shine the Light law: we do not disclose personal information to unaffiliated third parties for their own direct mail marketing in a way that requires a separate Shine the Light list. For questions, email us.

## 9. Security

We use reasonable administrative, technical, and physical safeguards appropriate to a small online course business. These include hashed passwords, HTTPS, restricted admin access, and reputable vendors for payments, hosting, and video.

No method of transmission or storage is completely secure. We cannot guarantee that unauthorized third parties will never defeat our measures. You can help by using a unique password and by not sharing your login.

If we become aware of a breach that requires notice, we will notify you and regulators as the law requires, using the email on your account where that is an appropriate channel.

## 10. GDPR and UK rights

If the GDPR or UK GDPR applies to our processing of your information, you also have the right to:

1. Access your data.
2. Rectify inaccurate data.
3. Erase data in certain cases.
4. Restrict processing in certain cases.
5. Data portability for information you provided and that we process by contract or consent.
6. Object to processing based on legitimate interests, including objecting to direct marketing at any time.
7. Withdraw consent where processing is based on consent.
8. Lodge a complaint with your supervisory authority (in the UK, the ICO; in the EEA, your local authority). We would appreciate the chance to address your concern first at info@dailyselfmassage.com.

These rights are not absolute. We will explain if an exception applies.

## 11. Children

The Services are for people 18 and older. We do not knowingly collect personal information from anyone under 18. We do not direct the Site or ads to children. If you believe a minor has given us information, email info@dailyselfmassage.com and we will delete it.

<a id=”cookies”></a>

## 12. Cookies and the Meta Pixel

This Section 12 is our cookie notice. The cookie banner and the “Your Privacy Choices” footer control point here (`https://dailyselfmassage.com/privacy-policy/#cookies`). Après Surf at https://www.apressurfmaui.com is a separate Shopify storefront and may set its own cookies under Shopify’s tools.

### 12.1 What cookies are

Cookies are small text files stored on your device when you visit a site. Similar tools include pixels, tags, and local storage. Some are set by us (first-party). Some are set by vendors (third-party).

We use them to run the Site, keep you logged in, remember your cookie choice, and, if you allow marketing cookies, measure and improve ads.

### 12.2 Necessary cookies

These cookies are needed for the Site to work. They typically:

1. Keep you logged in to your course account.
2. Support checkout and remember that you accepted the required legal checkboxes in that browser session.
3. Store your cookie-banner choice so we do not ask on every page load.
4. Provide security, load balancing, and basic fraud prevention on our host.

You cannot reject necessary cookies on the banner and still use login, checkout, or course playback as designed. You can block all cookies in your browser. If you do, account features may break.

We treat WordPress and Elementor session cookies, account cookies, and the cookie that records your banner choice as necessary.

### 12.3 Marketing cookies (Meta Pixel)

We use the Meta (Facebook) Pixel, Pixel ID 1317941479517067, for advertising and measurement. When this pixel runs, Meta may set or read cookies and receive identifiers (such as cookie IDs and IP address), the pages you view on our Site, and events such as viewing a course page or starting checkout.

We use that information to understand whether ads are working and to show or measure Daily Self Massage ads on Meta properties (including Facebook and Instagram).

Under California law, this is “sharing” of personal information for cross-context behavioral advertising. We do not sell personal information for money. We may share identifiers with Meta for ads. You can opt out as described in Section 8.2 and in Sections 12.5 through 12.7.

Marketing cookies are not required to watch a course you already bought.

### 12.4 Other third-party tools you may encounter

1. PayPal. When you pay for a course, PayPal may set cookies on PayPal’s payment flow. Those cookies are governed by PayPal. They are needed to complete a payment you requested.
2. Vimeo. When you play a course video, Vimeo may set cookies or similar tools needed to deliver the player. Vimeo’s privacy documentation applies to Vimeo’s processing.
3. Hostinger. Our host may set technical cookies related to performance and security.
4. Forms. WPForms and Contact Form 7 may use a cookie or similar storage to submit a form and, where used, to support spam protection.

Turning off marketing cookies does not disable PayPal or Vimeo when you choose to pay or to play a video.

### 12.5 How to control cookies

**Our banner.** When the cookie banner is shown, you can:

1. Accept: allow necessary and marketing cookies, including the Meta Pixel.
2. Reject non-essential: allow necessary cookies only. The Meta Pixel will not run.
3. Manage: turn marketing cookies on or off, then save.

You can reopen those choices later with the “Your Privacy Choices” link in the footer.

**Browser controls.** Most browsers let you block or delete cookies. Instructions are in your browser’s help menu. Blocking all cookies may log you out or prevent checkout.

**Meta’s own controls.** You can also use Meta’s ad settings on Facebook or Instagram, and industry tools such as YourOnlineChoices or the Digital Advertising Alliance opt-out pages. Those tools do not log you out of Daily Self Massage.

### 12.6 EU, UK, and EEA: consent before marketing cookies

If you visit from the European Union, the United Kingdom, or the EEA:

1. We will not set marketing cookies, and we will not fire the Meta Pixel, until you choose Accept or you turn marketing cookies on under Manage.
2. Rejecting non-essential cookies will not block you from reading the Site or, after purchase, from accessing a course.
3. You may withdraw consent at any time by using Reject non-essential, Manage, or Your Privacy Choices.

Necessary cookies may still be set so the Site and your choice can function.

### 12.7 United States: disclosure and opt-out

If you visit from the United States:

1. We disclose that we use necessary cookies and, unless you opt out, marketing cookies including Meta Pixel 1317941479517067.
2. We do not sell personal information for money. Running the Meta Pixel is sharing identifiers with Meta for ads.
3. To opt out of that sharing, use Reject non-essential or Manage on the banner, use Your Privacy Choices in the footer, or email info@dailyselfmassage.com with the subject “Your Privacy Choices.”
4. If we detect a legally recognized opt-out signal we are required to honor (including Global Privacy Control, where implemented), we will treat it as an opt-out of marketing cookies and of sharing for advertising for that browser.

Opting out of marketing cookies does not opt you out of emails you already requested, such as a notify-me list. Use the unsubscribe link in those emails, or write to us.

### 12.8 How long cookies last

Session cookies expire when you close the browser. Persistent cookies last until they expire or you delete them. Meta and other vendors set their own durations. Our cookie that remembers your banner choice is kept long enough so we are not asking on every visit, and you can change it at any time.


## 13. Automated decision-making

We do not use solely automated decision-making that produces legal or similarly significant effects about you. PayPal may run its own fraud checks under PayPal’s policies.

## 14. Changes to this Policy

We may update this Policy. We will revise the “Last Updated” date at the top. If we make a material change, including a new type of sale or sharing of personal information, we will give notice by email to the address on your account (or the address you used to buy or to subscribe) and by posting the updated Policy.

The updated Policy applies from the effective date stated in the notice or, if none, from the posting date. If you need a copy of an older version, email us.

## 15. Contact

Privacy questions, access or deletion requests, and “Your Privacy Choices” opt-out requests:

Brooke Neborsky LLC
doing business as Daily Self Massage and Après Surf
106 Kawehi Pl
Kula, HI 96790
United States

Email: info@dailyselfmassage.com
Phone: (808) 727-9244

Please use the subject line “Privacy Request” or “Your Privacy Choices” so we can route it quickly.