Legal & privacy

Privacy Policy

What we collect, why we hold it, and the choices you have

Last updated: 5 September 2026

1. Who We Are

Find a Ski School ("FASS", "we", "us", "our") is a trading name of WPDesigns SARLU, a société à responsabilité limitée unipersonnelle registered in France (SIREN 939118303, VAT FR09939118303), with its registered office at 1 Rue de Luc, 64100 Bayonne, France. We operate the website findaskischool.com — a global ski school directory and booking platform connecting skiers and learners with ski schools and instructors worldwide.

We are the data controller for the personal data processed through our platform, except where ski schools or instructors process personal data independently (in which case they are separate data controllers).

Contact: [email protected]
Postal address: WPDesigns SARLU, 1 Rue de Luc, 64100 Bayonne, France
Supervisory authority: Commission Nationale de l'Informatique et des Libertés (CNIL), France. If you are in another EU or EEA country, or in the UK, you may also contact your local data protection authority.

2. Definitions

Throughout this policy:

  • "Skiers" or "learners" means individuals who use the platform to find, compare, and book ski lessons.
  • "Ski schools" means businesses listed on the platform that offer ski or snowboard instruction.
  • "Instructors" means individuals who teach skiing or snowboarding, whether employed by a school or working independently.
  • "Platform" means findaskischool.com, including the website, Progressive Web App, APIs, and embedded booking widgets.
  • "AI features" means the AI School Finder, AI Chatbot, AI Instructor Finder, AI Resort Finder, and any other features powered by artificial intelligence.
  • "Public data" means information visible to all platform visitors, such as school profiles, reviews, and instructor qualifications.
  • "Private data" means information accessible only to you, to us, or to parties you have a direct relationship with (e.g., your booked ski school).

3. Personal Data We Collect

3.1 Data you provide directly

When you create an account, book a lesson, use our AI features, or contact us, we may collect:

  • Account data: Name, email address, password (stored as a cryptographic hash — we never see your actual password), role (skier, school owner, instructor), profile photo.
  • Booking data: Lesson type, dates, experience level, number of participants, special requirements, goals and "anything else we should know" notes, equipment sizing preferences. Any of these free-text fields may contain health-related information (e.g., injuries, disabilities, physical limitations). Providing health information is always optional; if you include it, you consent to it being shared with the ski school for lesson planning purposes. We treat such data with the same protection as special category data under GDPR Article 9, and it is kept only as part of the booking record for the retention period in section 8 — it is never used for any other purpose.
  • Communication data: Messages you send to ski schools or instructors through our messaging system, and your conversations with our AI chatbot. Messages may contain personal or health-related information — we advise you to share medical details only when relevant to your lesson. Messages are stored securely and visible only to you and the school.
  • Read receipts: When you read a message, the sender is shown that you have read it, and you are shown the same for messages you send. This is on by default and you can turn it off at any time in your messaging settings — turning it off stops your read status being shared and stops you seeing anyone else's.
  • Review data: Star ratings, written reviews, and the school or instructor they relate to. Reviews are published publicly under your first name.
  • Gear profile data: Height, weight, ability level, gender, age group, and equipment preferences — used solely for gear recommendations. This data is not used to assess your health.
  • Support data: Information you provide in support tickets, including screenshots and descriptions of issues.
  • Payment data: We do not store your credit card details. All payments are processed directly by Stripe, who acts as an independent data controller for payment data. See Stripe's Privacy Policy.

3.2 Data collected automatically

When you visit our website, we automatically collect:

  • Device data: IP address, browser type and version, operating system, device type, screen resolution, language preference.
  • Usage data: Pages visited, time spent on pages, clicks, scroll depth, referring website or search terms. This data is collected using privacy-focused analytics and is not linked to advertising profiles.
  • Online status: While you are signed in, providers and instructors are shown in our directories as being online now, and visitors can filter for it. This is derived from when your account was last seen; nothing about your location or activity is collected. It is on by default and can be switched off in your settings.
  • Cookie data: See our Cookie Policy for full details.

3.3 GPS and location data

If you use our GPS Ski Tracking feature, we collect precise location data including GPS coordinates, speed, elevation, and route waypoints. This data is collected only with your explicit consent and only while you actively use the tracking feature. You can stop tracking at any time. GPS data is stored locally on your device when you're offline and synced to our servers when you reconnect.

You control who sees your GPS data and for how long through your privacy settings. You can delete your GPS data at any time from your dashboard.

3.4 Lesson notes, pre-arrival questionnaires, and progress data

When an instructor uses Quick Notes after a lesson, the recording is uploaded to private storage and sent to a configured speech-to-text processor. The raw transcript, together with any student name, activity and level supplied by the instructor, is then sent to the configured text-model provider to clean the note, generate a title and extract action items. The audio, raw transcript and generated outputs are saved with the note. Authorised instructors, relevant school staff and administrators can access it; the learner or parent can access it when the instructor shares it. Lesson notes may contain health, injury or fitness information and therefore require additional care.

Pre-arrival questionnaires: Some schools send a questionnaire before your lesson that explicitly asks about medical conditions, physical requirements, and equipment sizing. This data is shared with your instructor and school to ensure your safety. The medical fields are disabled by default — you must provide explicit consent before entering medical information. This data is retained for the duration of your booking plus 12 months, then deleted.

Quick Notes itself does not collect a learner consent record and does not offer a manual-only mode. Before recording, the school or instructor must inform the learner or parent and establish consent or another applicable lawful basis, including explicit consent where special-category data is involved. If you decline, ask the provider not to use Quick Notes and request a manually written recap through another agreed channel. Existing notes can be removed through a data privacy request or by contacting us. Removing the storage reference ends in-app access to the private audio; the underlying object is then handled under our private-storage lifecycle or an accelerated deletion request.

3.5 AI chatbot and AI feature data

When you use our AI-powered features (AI School Finder, AI Chatbot, AI Instructor Finder, AI Resort Finder), your queries are sent to third-party AI providers for processing. We currently use Anthropic (Claude) and Google (Gemini). What happens to a conversation afterwards depends on which feature you used. The AI Concierge and the AI finders are not stored on our servers: that history is held in your own browser and clears itself 24 hours after your last message, and all we retain is anonymous request metadata containing none of your messages. A school's own chatbot is different — those conversations are stored for up to 12 months so the school can review them, which is the retention period published in the table in section 8. You must agree to our chatbot privacy terms before starting a conversation. You are interacting with an AI, not a human.

Find a Ski School does not train AI models on your data — we do not run our own foundation models or fine-tune third-party ones. What the providers do with the inputs we send them is governed by their own Data Processing Addenda — public documents that they update independently of this notice (Anthropic: anthropic.com/legal/dpa; Google: cloud.google.com/terms/data-processing-addendum). At the paid API tiers we use, those documents say today that the providers do not use our inputs or outputs to train their foundation models. The linked DPAs are the authoritative position at any given moment. See Section 7 for international data transfers and our AI Transparency page for the plain-language breakdown plus opt-out toggles.

3.6 Data from third parties

We may receive personal data from:

  • Ski schools: When a school adds instructor profiles or imports student booking data.
  • Stripe: Payment confirmation and transaction references (not card details).
  • Public sources: Resort data, altitude data, and weather data from publicly available sources.

4. Why We Process Your Data and Our Legal Basis

Under GDPR Article 6, we process personal data on the following bases:

PurposeLegal basisData used
Provide your account and the platformContract (Art. 6(1)(b))Account data
Process bookings and connect you with ski schoolsContractBooking data, contact details
Process payments via StripeContractPayment references (Stripe holds card data)
Deliver AI-powered search and recommendationsLegitimate interest (improving user experience)Search queries, preferences
Store AI chatbot conversationsConsent (given before first chat)Chat messages, optional email/phone
Record, transcribe and AI-format lesson notes and track progressConsent or another applicable lawful basis; explicit consent where special-category data is includedAudio, raw transcript, student name, activity, level, cleaned note, generated title and action items
GPS ski trackingExplicit consentLocation, speed, elevation, routes
Gear recommendationsLegitimate interestHeight, weight, ability level, preferences
Publish your reviewsLegitimate interest (trust & transparency)Name, rating, review text
Send booking confirmations and remindersContractEmail, booking details
Send marketing emailsConsent (explicit opt-in)Email, name, preferences
Analyse platform usageLegitimate interestAnonymised usage data
Prevent fraud and protect securityLegitimate interestIP address, device data, audit logs
Comply with legal obligationsLegal obligation (Art. 6(1)(c))Financial records, audit logs

Where we rely on legitimate interest, we have conducted balancing tests to ensure your rights are not overridden. You can request details of these assessments by contacting us.

5. AI-Powered Features and Automated Processing

Our platform uses artificial intelligence to power several features. We are transparent about how AI is used:

  • AI School Finder / AI Chatbot: Your questions are processed by the third-party AI provider configured for that feature. Supported providers include Anthropic, OpenAI, Google, Groq, Together AI, Mistral, DeepSeek, OpenRouter and xAI. Responses are informational and may not always be accurate. No automated decisions with legal or similarly significant effects are made solely by AI.
  • School-specific chatbots: Each ski school may have its own AI chatbot trained on their lesson data, pricing, and policies. Your conversations with school chatbots are visible to that school's owner. You must agree to this before chatting.
  • Quick Lesson Notes — speech-to-text and AI formatting: A private audio recording is sent to our configured speech-to-text processor. The resulting transcript and any student name, activity and level supplied by the instructor are sent to the configured text-model provider to clean the note, create a title and extract action items. The recording, transcript and generated results are then stored as the lesson note.
  • Profile prefill from your website or a PDF: When you list a school or register as an instructor you can paste page links or upload a PDF so the form is drafted for you. We fetch the pages or read the PDF in memory and send the text to the configured text-model provider (section 6) to extract the form fields. Neither the file nor the page text is stored: only the values that appear in the form, which you can edit or clear, are sent when you submit. Nothing runs until you tick the consent box next to the tool.
  • AI-assisted messaging: When schools reply to your messages, they may use AI to help draft responses. AI-assisted replies are labelled as such.
  • Search ranking: Schools and instructors are ranked in search results using algorithms that consider relevance, ratings, verification status, and how complete a profile is. Paying does not move a listing up these results. Separately, schools and instructors can buy a small, fixed number of Sponsored slots at the top of the first page of results; every sponsored listing carries a Sponsored label and has to meet the same eligibility rules as every other listing. This is not automated decision-making under Article 22 as it does not produce legal or similarly significant effects on individuals.

Under the EU AI Act (compliance deadline August 2026), we label all AI interactions clearly. You always know when you are interacting with an AI system.

6. Who We Share Your Data With

We do not sell your personal data. We never have and we never will.

  • Ski schools you book with: Your name, email, phone (if provided), booking details, experience level, and any pre-arrival questionnaire responses are shared with the school you book. The school becomes an independent data controller for this data.
  • Stripe (payment processing): Find a Ski School creates the online charge on its Stripe platform account, and Stripe Connect transfers the provider's share to its connected account. Stripe processes card data independently under its own privacy policy.
  • Speech-to-text and AI text processors: The processor active for a feature receives the inputs needed to perform it. For Quick Lesson Notes this includes the audio recording for speech-to-text, followed by the transcript and supplied student name, activity and level for text processing. The text provider is configurable and may be Anthropic, OpenAI, Google, Groq, Together AI, Mistral, DeepSeek, OpenRouter or xAI. Ask [email protected] for the active subprocessor list and applicable terms.
  • Email delivery — EmailIt: Your email address is shared for transactional and marketing email delivery.
  • Error monitoring — Sentry: When the app encounters an unexpected error, Sentry receives a report so we can diagnose and fix it. Before sending, we strip query parameters and tokens from URLs in the report and remove user identifiers that Sentry would otherwise default-collect (email, IP address, username). Free-text error messages and stack traces are sent as-is — please avoid including personal data in custom error messages. Sentry processes the report under their own privacy policy. Sentry is only initialised once you accept the analytics cookie category; decline it and no report is sent at all.
  • Privacy-friendly analytics — Plausible: We use Plausible to count page views and understand how visitors find the site. Plausible does not use cookies and does not collect personal data — it stores only aggregate metrics, with IP addresses processed in memory and discarded. The Plausible instance is hosted in the EU.
  • Website analytics — Google Analytics: We use Google Analytics (GA4) to understand traffic patterns and measure marketing effectiveness. GA4 collects device and browser metadata, approximate location derived from your IP address, and pages visited. Google processes this data under their privacy policy and as a data processor on our behalf. You can opt out via the Google Analytics opt-out browser add-on.
  • Maps — Google Maps Platform: Resort and school location maps are served by the Google Maps Platform. When a map loads, Google receives your IP address and the map coordinates requested. Google processes this data under their privacy policy.
  • Infrastructure and security — Cloudflare: Traffic passes through Cloudflare's CDN for performance and security. We also use Cloudflare Turnstile to protect forms from automated abuse — Turnstile analyses browser signals without traditional CAPTCHAs. IP addresses are processed by Cloudflare under their privacy policy.
  • Push notifications — Firebase Cloud Messaging: If you opt in to browser push notifications, messages are delivered via Google's Firebase Cloud Messaging (FCM) service. FCM receives a device-specific push token but not your personal data. Google processes this token under their privacy policy.
  • Hosting provider: Our application and database are hosted on infrastructure that may process personal data as a sub-processor.
  • Law enforcement: We may disclose data if required by law, court order, or to protect the safety of our users.

A full list of our sub-processors is available upon request at [email protected].

7. International Data Transfers

Some of our service providers are based in the United States. When personal data is transferred outside the UK or EEA, we ensure appropriate safeguards:

  • EU-US Data Privacy Framework (DPF): Where our US providers are certified under the DPF (including Anthropic, Google, Stripe, and Sentry), transfers are covered by the European Commission's adequacy decision of July 2023. For UK transfers, the UK Extension to the DPF applies.
  • Standard Contractual Clauses (SCCs): As a secondary safeguard, we also execute SCCs approved by the European Commission (June 2021 version) with all US-based processors. For UK transfers, we use the UK International Data Transfer Agreement or the UK Addendum to EU SCCs.

We have conducted Transfer Impact Assessments for each US-based processor. Copies of our transfer safeguards are available on request.

8. How Long We Keep Your Data

We retain personal data only as long as necessary for the purpose it was collected, unless a longer retention is required by law:

Data typeRetention periodReason
Account dataUntil you delete your accountContract
Booking records7 years (anonymised after account deletion)Financial record-keeping obligation
Messages2 yearsLegitimate interest
AI chatbot conversations12 monthsConsent
GPS tracking dataUser-configurable (default: until deleted)Consent
Lesson notesUp to 3 years; identifying text and the in-app audio reference are then anonymisedConsent or another applicable lawful basis
Health details in bookingsBooking duration plus 12 monthsExplicit consent
ReviewsPublished indefinitely; anonymised on deletionLegitimate interest
Support tickets3 years after resolutionLegitimate interest
Identity verification records6 years after account deletionFraud prevention and defence of legal claims
Audit logs7 yearsLegal obligation (security)
Consent records3 yearsLegal obligation (proof of consent)
Marketing preferencesUntil consent is withdrawnConsent
Analytics data (Plausible)Aggregate metrics retained indefinitely; no per-visitor data storedLegitimate interest
Error reports (Sentry)90 days, then automatically purgedLegitimate interest (debugging)

When you delete your account, we delete all your private data. Financial records (bookings, payments) are anonymised — your name and email are replaced with "[deleted]" — and retained for 7 years per legal obligation. Audit logs are retained for security purposes.

9. Cookies

We use cookies and similar technologies. You can manage your preferences at any time using our cookie banner or by visiting our Cookie Policy. We use five categories of cookies: Strictly Necessary (always active), Functional, Analytics, Marketing, and AI & Chatbot. Non-essential cookies are only placed after you give consent.

10. Your Rights

Under UK GDPR and EU GDPR, you have the following rights:

  • Right of access (Art. 15): Request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16): Correct inaccurate or incomplete data. You can update most data directly in your account settings.
  • Right to erasure (Art. 17): Request deletion of your personal data. We will delete or anonymise your data within 30 days, subject to legal retention obligations.
  • Right to restriction (Art. 18): Request that we limit processing of your data while a dispute is resolved.
  • Right to data portability (Art. 20): Receive your data in a structured, machine-readable format (JSON).
  • Right to object (Art. 21): Object to processing based on legitimate interest. We will stop processing unless we have compelling grounds.
  • Right to withdraw consent: Where processing is based on consent, you can withdraw it at any time. For lesson notes, tell both us and the relevant school or instructor so that future Quick Notes recordings stop. Withdrawal does not affect the lawfulness of processing before it was withdrawn.
  • Right regarding automated decisions (Art. 22): You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not currently make such decisions.

How to exercise your rights: Email us at [email protected], or use our self-service Data Privacy Request Form. We will respond within 30 days. If your request is complex, we may extend this by a further 60 days with notice.

You also have the right to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL) at cnil.fr, or with the data protection authority in your own country.

11. Data Security

We implement technical and organisational measures to protect your data:

  • All data is transmitted over HTTPS (TLS 1.2+).
  • Passwords are hashed using bcrypt before storage — we never store or see your actual password.
  • Session tokens are cryptographically signed and expire after inactivity.
  • Payment data is processed entirely by Stripe — we never store card numbers.
  • Database access is restricted and encrypted.
  • We use Cloudflare for DDoS protection and bot detection (without CAPTCHAs).
  • All security-relevant actions are recorded in an immutable audit log.
  • Two-factor authentication (2FA) is available for all accounts and enforced for administrators.
  • Input validation (using Zod schemas) is applied to every API endpoint to prevent injection attacks.

No system is 100% secure. Where required, we will notify the relevant supervisory authority within 72 hours of becoming aware of a breach, in accordance with GDPR Article 33. If the breach is likely to pose a high risk to you, we will also notify you without undue delay.

12. Children's Privacy

Our platform is not directed at children under 16 (EU) or 13 (UK). We do not knowingly collect personal data from children under these ages without parental consent. Ski lesson bookings for children are made by parents or guardians, and the parent's account and consent governs that data.

If you believe we have collected data from a child without appropriate consent, please contact us immediately and we will delete it.

13. User-Generated Content and Reviews

When you leave a review, your first name, rating, and review text are published publicly on the school or instructor's profile. Reviews are moderated according to our Review Policy. You can request removal of a review through our support system, and we will assess whether removal is appropriate under our legitimate interest in maintaining platform trust.

If you delete your account, reviews are anonymised (attributed to "Former Student") rather than deleted, to maintain the integrity of the review system for other skiers.

14. Ski School and Instructor Data

If you are a ski school owner or instructor, we process your data differently from skier data. Your school name, location, lesson offerings, pricing, and instructor qualifications are published as public data to help skiers find and compare schools.

When a skier books with you, their personal data (name, email, experience level) is shared with you. You become an independent data controller for that booking data and are responsible for handling it in accordance with applicable data protection laws. We recommend you maintain your own privacy policy.

Instructor certification documents, verification submissions, and business registration data are stored securely and accessible only to you and our verification team.

Widget embed analytics. If you embed our booking widget or reviews widget on your own website, we log aggregate counts of how often the widget loads, grouped by the host that embedded it. This data is used to surface usage statistics to you in your dashboard and to help us understand product adoption. We do not store visitor IP addresses, cookies, User-Agent strings, or any other identifier of the visitors who see the widget — only the hostname of the page that embedded it (taken from the standard HTTP Refererheader) and a daily load count. This processing is based on our legitimate interest in operating and improving the service.

WordPress plugin telemetry (opt-in only). Our WordPress plugin can optionally send us a daily heartbeat with your FASS embed token, the plugin version, your WordPress version, and your site hostname. This channel is off by default — it only activates when you tick the "Send anonymous usage info to FASS" toggle in the plugin's settings page. Ticking the toggle is your explicit consent for this processing under UK and EU GDPR Article 6(1)(a); unticking it stops the plugin from sending further heartbeats immediately and is recorded locally in your WordPress site's settings. We do not receive your site admin email, your visitors' data, or any free-text settings — only the four fields listed above. We use this data to understand plugin version distribution and to plan support for older WordPress versions.

15. Changes to This Policy

We may update this privacy policy from time to time. When we make material changes, we will notify you by email (if you have an account) and display a prominent notice on the platform. The "Last updated" date at the top of this page reflects the most recent revision. Your continued use of the platform after changes constitutes acceptance of the updated policy.

16. Contact Us

If you have questions about this privacy policy or how we handle your data:

Lead supervisory authority: Commission Nationale de l'Informatique et des Libertés (CNIL), France. Website: cnil.fr.

EU, EEA and UK residents: You may also contact the data protection authority in your own country. A list of European authorities is available at edpb.europa.eu.