PRIVACY POLICY

Effective Date: May 5, 2026
Last Updated: July 14, 2026

1. WEBSITE OPERATOR AND DATA CONTROLLER

This Privacy Policy explains how GraceMethod Innovations LLC, the company operating the somaticshaking.com website and the Somatic Shaking™ brand, collects, uses, stores, discloses, and protects your personal information.

In this Privacy Policy, the terms “GraceMethod Innovations LLC,” “Somatic Shaking™,” “we,” “us,” and “our” refer to:

Legal Name: GraceMethod Innovations LLC
Trade Name and Brand: Somatic Shaking™
Legal Form: Limited Liability Company — LLC
Jurisdiction of Formation: New Mexico, United States
Company File Number: 3085545
Principal Business and Mailing Address: 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, United States
Website: somaticshaking.com
Email: contact@somaticshaking.com

GraceMethod Innovations LLC is the data controller responsible for determining why and how personal information collected through the website and Somatic Shaking™ services is processed.

This Privacy Policy is intended to explain our practices under applicable privacy and data-protection laws, including the European Union General Data Protection Regulation — GDPR — and the California Consumer Privacy Act — CCPA — where those laws apply to our activities.

Under the GDPR, individuals must be informed about the identity and contact details of the controller, the purposes and legal grounds of processing, retention periods, recipients, international transfers, and their applicable rights. (European Commission)

2. SCOPE OF THIS PRIVACY POLICY

This Privacy Policy applies when you:

  • visit somaticshaking.com;
  • complete a form on the website;
  • create an account;
  • register for a session, class, course, workshop, program, or event;
  • purchase a digital product or service;
  • subscribe to our communications;
  • participate in an online or in-person session;
  • contact us by email, messaging application, social media, or another communication channel;
  • provide feedback, a testimonial, photograph, audio recording, or video recording;
  • interact with our advertisements, pages, or digital content.

This Privacy Policy does not automatically apply to independent third-party websites, payment services, communication platforms, social networks, or other services that maintain their own privacy policies.

3. INFORMATION WE COLLECT

3.1. Identification and contact information

We may collect:

  • first and last name;
  • email address;
  • telephone number;
  • country and city;
  • billing address;
  • company name, when relevant;
  • account name or username;
  • account and login information.

3.2. Purchase and payment information

We may collect:

  • products, programs, or services purchased;
  • payment amount and currency;
  • transaction date;
  • order history;
  • payment status;
  • refund or cancellation information;
  • billing information;
  • information required for accounting and tax purposes.

Payments may be processed by authorized third-party payment processors.

We do not normally store complete payment-card numbers, card security codes, or complete banking authentication information on our own servers.

3.3. Program and session participation information

We may collect:

  • the session, program, course, or event for which you registered;
  • attendance information;
  • scheduling preferences;
  • program engagement and progress;
  • responses submitted through registration or participation forms;
  • requests for accommodations or additional support;
  • communications between you and the facilitator;
  • information required to deliver the program or service.

3.4. Health and wellbeing information

In certain circumstances, we may ask you to voluntarily provide information relevant to participation and safety, including:

  • pregnancy;
  • recent injuries or surgical procedures;
  • physical limitations;
  • neurological or cardiovascular conditions;
  • current psychiatric or psychological treatment;
  • relevant medication;
  • other conditions or circumstances that may affect participation.

Health information may constitute a special category of personal data under the GDPR.

When collected, this information is used only for purposes such as general participation screening, determining whether a session should be modified or postponed, identifying potential safety concerns, or recommending that you consult an appropriately qualified healthcare professional.

It is not used to provide medical diagnosis or treatment.

Where required by applicable law, health-related information will be processed only with your explicit consent or under another valid legal condition applicable to special-category data. GDPR Articles 6 and 9 establish separate requirements for ordinary personal data and special categories such as health data. (EUR-Lex)

You are not required to disclose detailed medical information. However, failure to disclose information relevant to participation may mean that we are unable to safely provide certain services.

3.5. Communication information

We may collect:

  • emails and messages sent to us;
  • customer-support requests;
  • questions and complaints;
  • feedback;
  • survey responses;
  • information voluntarily communicated during a conversation;
  • privacy-rights requests and related correspondence.

3.6. Photographs, recordings, and testimonials

With appropriate permission, we may collect or use:

  • photographs;
  • audio recordings;
  • video recordings;
  • written testimonials;
  • statements describing an individual experience;
  • materials recorded during sessions, workshops, or events.

Promotional use of a person’s identifiable image, voice, testimonial, or personal experience will be based on consent, an authorization, or another appropriate agreement.

Consent to photography or recording is not ordinarily required as a condition of participating in a Somatic Shaking™ session unless the event has been clearly presented in advance as a recorded production or filming event.

3.7. Technical and automatically collected information

When you use the website, we or our service providers may automatically collect:

  • IP address;
  • approximate geographic location;
  • browser type;
  • device type;
  • operating system;
  • browser language;
  • pages visited;
  • date and time of access;
  • time spent on the website;
  • referring website or traffic source;
  • entry and exit pages;
  • interactions with pages and forms;
  • cookie identifiers;
  • analytics and advertising identifiers;
  • security and diagnostic information.

3.8. Sources of information

We may receive information:

  • directly from you;
  • automatically through the website;
  • through cookies and similar technologies;
  • from payment processors;
  • from registration and scheduling platforms;
  • from technical service providers;
  • from analytics or advertising platforms, where legally permitted;
  • from publicly available sources, when relevant and lawful.

4. HOW WE USE YOUR INFORMATION

4.1. Providing products and services

We may use your information to:

  • process purchases and registrations;
  • deliver digital products;
  • provide access to courses and programs;
  • organize sessions and events;
  • administer accounts;
  • send confirmations and receipts;
  • provide access links and scheduling information;
  • respond to support requests;
  • process cancellations and refunds;
  • fulfill our contractual obligations.

4.2. Supporting participation and safety

Where relevant, we may use information you provide to:

  • identify possible participation concerns or contraindications;
  • discuss reasonable modifications;
  • recommend consultation with a qualified professional;
  • postpone or decline participation when a session may be inappropriate;
  • respond to a safety concern occurring during a session.

This information is not used to diagnose, treat, cure, or prevent a medical or mental-health condition.

4.3. Communicating with you

We may use your information to:

  • respond to questions;
  • provide customer support;
  • communicate scheduling changes;
  • send access information;
  • provide important service notices;
  • notify you about updates to our terms or policies;
  • address complaints or disputes.

4.4. Marketing and educational communications

With your consent where required, we may use your information to send:

  • newsletters;
  • promotional offers;
  • information about new programs;
  • invitations to sessions, workshops, or events;
  • educational content;
  • information about somatic practices;
  • personalized or retargeted advertising where such technologies are used.

You may unsubscribe from marketing emails at any time by using the unsubscribe link contained in the email or by contacting us.

Withdrawing marketing consent does not prevent us from sending essential administrative or transactional communications relating to a purchase, account, or active program.

4.5. Website analytics and improvement

We may use information to:

  • understand how the website is used;
  • troubleshoot technical problems;
  • improve website functionality;
  • improve the customer experience;
  • test new features;
  • measure advertising and marketing performance;
  • develop new services and educational products;
  • detect fraud or misuse;
  • maintain platform and account security.

4.6. Legal, tax, and compliance purposes

We may use or retain information to:

  • issue invoices and receipts;
  • maintain accounting records;
  • comply with tax obligations;
  • respond to lawful requests;
  • enforce agreements;
  • protect our legal rights;
  • investigate suspected fraud or misuse;
  • resolve disputes;
  • establish, exercise, or defend legal claims.

5. LEGAL BASES FOR PROCESSING UNDER THE GDPR

Where the GDPR applies, we rely on one or more of the following legal bases.

5.1. Performance of a contract

Processing may be necessary to:

  • register you for a service;
  • process your payment;
  • provide a purchased product;
  • deliver a session or program;
  • maintain your account;
  • respond to a request made before entering into a contract.

5.2. Consent

We may rely on consent for:

  • marketing communications;
  • optional cookies;
  • analytics or advertising technologies where consent is required;
  • photographs and promotional recordings;
  • testimonials;
  • certain health-related information;
  • other optional processing activities.

You may withdraw your consent at any time.

Withdrawal does not affect the lawfulness of processing performed before consent was withdrawn.

5.3. Legitimate interests

We may rely on our legitimate interests for purposes such as:

  • operating and improving our services;
  • maintaining website and account security;
  • preventing fraud;
  • managing customer relationships;
  • responding to non-marketing communications;
  • understanding service performance;
  • protecting our rights.

We will rely on legitimate interests only when we determine that our interests are not overridden by your fundamental rights and freedoms.

5.4. Legal obligations

We may process or retain information when necessary to comply with:

  • tax and accounting requirements;
  • court orders;
  • legally valid government requests;
  • regulatory obligations;
  • other applicable legal requirements.

Consent, contractual necessity, legal obligations, and legitimate interests are among the lawful grounds recognized under EU data-protection rules. (European Commission)

5.5. Special-category information

Where health information or another special category of personal data is involved, we will also rely on an applicable condition under Article 9 GDPR, such as explicit consent, where appropriate.

6. SHARING AND DISCLOSURE OF INFORMATION

We do not sell or rent personal information in exchange for money.

We may share information with service providers that assist us in operating our business, including:

  • website-hosting providers;
  • payment processors;
  • email-delivery platforms;
  • scheduling and booking services;
  • course and membership platforms;
  • video-conferencing services;
  • cloud-storage providers;
  • analytics providers;
  • customer-relationship management systems;
  • accounting providers;
  • legal and professional advisers;
  • advertising platforms, when used in accordance with applicable law.

These providers may process information only for the relevant service or purpose and must protect the information in accordance with applicable contractual and legal requirements.

Where a third party processes personal data on our behalf under the GDPR, the relationship should be governed by an appropriate contract or other legal instrument, and the processor must provide sufficient data-protection safeguards. (European Commission)

6.1. Legal disclosures

We may disclose information:

  • when required by applicable law;
  • in response to a valid court order;
  • in response to a legally binding request from a government authority;
  • to investigate suspected fraud;
  • to protect the safety, rights, or property of an individual;
  • to establish, exercise, or defend legal claims.

6.2. Business transfers

If GraceMethod Innovations LLC is involved in a merger, acquisition, restructuring, financing, sale of assets, or transfer of business operations, personal information may be transferred as part of that transaction.

Where required, affected individuals will be notified of a material change in the controller or use of their information.

6.3. Advertising and California privacy law

We do not sell personal information in the ordinary meaning of selling information for money.

However, certain advertising, analytics, or tracking technologies may be considered “sharing” or “selling” under California law even when no money is exchanged.

Where the CCPA applies to our activities and we engage in covered selling or sharing, we will provide any legally required opt-out mechanism and honor qualifying opt-out preference signals.

The CCPA applies only to businesses that meet its applicable legal criteria and thresholds. Businesses subject to it must maintain an accessible privacy policy and provide the notices and consumer controls required by California law. (cppa.ca.gov)

7. INTERNATIONAL DATA TRANSFERS

GraceMethod Innovations LLC is formed in the United States.

Your personal information may be transferred to, stored in, or processed in the United States or other countries where we or our service providers operate.

Privacy and data-protection laws in those countries may differ from those in your country of residence.

Where the GDPR applies to an international transfer, we will use an applicable transfer mechanism where required, which may include:

  • an adequacy decision;
  • European Commission Standard Contractual Clauses;
  • appropriate contractual and organizational safeguards;
  • another transfer mechanism permitted by applicable law.

The European Commission recognizes adequacy decisions and Standard Contractual Clauses as mechanisms that may support lawful international transfers of personal data. (EUR-Lex)

8. DATA RETENTION

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, tax, security, and dispute-resolution requirements.

Our general retention periods may include:

  • payment, invoice, and transaction records: for the period required by applicable tax and accounting law, which may be up to seven years;
  • active customer-account information: while the account remains active and generally for up to two years after closure;
  • registration and participation records: for the duration of the relevant program and generally for up to two years afterward;
  • customer-support and email communications: generally for up to two years after the matter is resolved;
  • safety or participation-screening information: only for as long as reasonably necessary for participation, safety, legal compliance, or the defense of legal claims;
  • marketing information: until you unsubscribe, withdraw consent, or the information is no longer required;
  • technical and analytics information: according to the settings and retention periods of the relevant tool, generally no longer than reasonably necessary;
  • media permissions and testimonials: for the authorized period of use and as long as necessary to document the permission granted.

When information is no longer required, it may be deleted, anonymized, or securely retained where continued retention is legally required.

A request for deletion does not necessarily require us to delete records that must be retained for tax, accounting, fraud-prevention, contractual, or legal purposes.

9. DATA SECURITY

We use reasonable technical, administrative, and organizational safeguards designed to protect personal information against:

  • unauthorized access;
  • unauthorized disclosure;
  • loss;
  • misuse;
  • alteration;
  • destruction.

Measures may include:

  • HTTPS encryption;
  • password-protected systems;
  • secure authentication;
  • access restrictions;
  • software and security updates;
  • backup procedures;
  • security monitoring;
  • confidentiality obligations;
  • use of specialized payment processors;
  • collection of only the information reasonably required.

No method of electronic transmission, internet communication, or electronic storage is completely secure.

We therefore cannot guarantee absolute security.

If a personal-data breach occurs, we will assess the incident and take the actions required by applicable law.

10. COOKIES AND SIMILAR TECHNOLOGIES

The website may use:

  • strictly necessary cookies;
  • functional cookies;
  • analytics cookies;
  • advertising cookies;
  • pixels;
  • local-storage technologies;
  • similar identifiers and tracking technologies.

Strictly necessary cookies may be used to support website functionality, security, payment processing, and account access.

Where consent is legally required, non-essential analytics or advertising cookies will not be activated until the user has made the relevant choice.

You may be able to:

  • accept or reject non-essential cookies;
  • change your preferences through the website’s consent-management tool;
  • delete cookies through your browser;
  • block certain technologies through your browser or device settings.

Disabling some cookies may affect website functionality.

European privacy rules include requirements relating to cookies and technologies used for online tracking and monitoring. (European Commission)

11. YOUR PRIVACY RIGHTS

Your rights depend on your location and the laws applicable to our processing.

11.1. Rights under the GDPR

Where the GDPR applies, you may have the right to:

  • receive information about how your personal data is processed;
  • request access to your personal data;
  • obtain a copy of your personal data;
  • request correction of inaccurate or incomplete data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to certain processing;
  • receive eligible information in a portable, machine-readable format;
  • withdraw consent at any time;
  • object to direct marketing;
  • lodge a complaint with a competent data-protection authority;
  • request information about international transfers;
  • avoid certain decisions based solely on automated processing that produce legal or similarly significant effects.

These rights are subject to the conditions, restrictions, and exceptions established by applicable law. The European Commission identifies access, rectification, erasure, restriction, portability, objection, and withdrawal of consent among the rights available under the GDPR. (European Commission)

11.2. Rights of California residents

Where the CCPA applies, California residents may have the right to:

  • know what personal information is collected;
  • request access to personal information;
  • request deletion of eligible personal information;
  • request correction of inaccurate information;
  • opt out of covered selling or sharing;
  • limit certain uses of sensitive personal information;
  • receive information about categories of sources, purposes, and recipients;
  • receive equal service and not be discriminated against for exercising a privacy right;
  • use an authorized agent to submit a qualifying request.

Some rights and obligations apply only when a company falls within the legal definition of a business subject to the CCPA. (cppa.ca.gov)

11.3. Exercising your rights

To submit a privacy request, contact:

contact@somaticshaking.com

Please explain which right you wish to exercise and provide enough information for us to identify the relevant records.

We may request reasonable information to verify your identity and protect personal data from unauthorized access.

We will respond within the period required by applicable law.

A request may be limited or refused where permitted by law, including where retention is necessary for:

  • legal compliance;
  • tax and accounting records;
  • fraud prevention;
  • contract performance;
  • dispute resolution;
  • establishment or defense of legal claims;
  • protection of another person’s rights.

11.4. Complaints

Where the GDPR applies, you may lodge a complaint with the data-protection authority in the country where you live, work, or believe a violation occurred.

You are also encouraged to contact us first so that we have an opportunity to address your concern.

12. AUTOMATED DECISION-MAKING

Unless we expressly inform you otherwise, we do not use personal information to make decisions based solely on automated processing that produce legal or similarly significant effects concerning you.

We may use automated tools for:

  • spam filtering;
  • fraud detection;
  • website analytics;
  • communication segmentation;
  • advertising measurement;
  • recommending content or programs.

These tools are not used to provide a medical, psychiatric, psychological, or therapeutic diagnosis.

13. THIRD-PARTY LINKS AND SERVICES

Our website and communications may link to third-party services, including:

  • payment platforms;
  • scheduling platforms;
  • video-conferencing services;
  • social networks;
  • messaging applications;
  • course platforms;
  • partner websites;
  • external educational resources.

These services operate under their own privacy policies and terms.

GraceMethod Innovations LLC does not control and is not responsible for the independent privacy, security, or data-processing practices of those third parties.

You should review the privacy policy of each external service before providing personal information.

14. CHILDREN’S PRIVACY

Somatic Shaking™ services are not intended for individuals under 18 years of age.

We do not knowingly collect personal information directly from individuals under 18 without an appropriate legal basis and, where required, authorization from a parent or legal guardian.

If we become aware that personal information has been collected from a minor contrary to applicable law, we will take reasonable steps to delete it.

A parent or legal guardian who believes that a minor has provided personal information may contact:

contact@somaticshaking.com

15. EUROPEAN UNION REPRESENTATIVE

GraceMethod Innovations LLC is established outside the European Union.

Where Article 27 GDPR legally requires us to appoint a representative in the European Union, the representative’s identity and contact information will be made available in this section or through another clearly accessible privacy notice.

Article 27 may require a controller located outside the EU to appoint a written representative where the controller offers goods or services to individuals in the EU or monitors their behavior, subject to the exceptions provided by the GDPR. (EUR-Lex)

EU Representative: To be added if and when legally required and formally appointed.

16. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy to reflect:

  • changes to our services;
  • changes to the technologies we use;
  • changes to our service providers;
  • changes to our information-processing practices;
  • legal or regulatory developments;
  • changes to the structure of our business;
  • security or operational improvements.

The updated version will be published on the website with a revised “Last Updated” date.

Where required or appropriate, we may provide additional notice by email or through a prominent website notification.

17. CONTACT US

For questions, complaints, or privacy requests, contact:

GraceMethod Innovations LLC
Brand: Somatic Shaking™
Jurisdiction: New Mexico, United States
Company File Number: 3085545
Business and Mailing Address: 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, United States
Email: contact@somaticshaking.com
Website: somaticshaking.com

Effective Date: May 5, 2026
Last Updated: July 14, 2026

 

LET'S CHAT!