Privacy Notice
This Privacy Notice explains how Immortelle Technologies Limited T/A Sweatt collects, uses, shares, retains and protects personal information when you use the Platform, communicate with us, participate in an activity, work with us as a Provider, or receive employer-sponsored benefits.
1. Who controls your information
Immortelle Technologies Limited T/A Sweatt is responsible for personal information processed for operating the Platform, account administration, payment orchestration, support, safety, analytics and marketing. A Provider is separately responsible for information it collects to deliver an activity, manage attendance, assess health or accessibility needs, or comply with its own legal obligations.
Contact: [email protected]
2. Information we collect
2.1 Information you provide
- Identity and account data: name, date of birth or age confirmation, profile image, username and credentials.
- Contact data: email address, telephone number, address and notification preferences.
- Booking data: activities viewed, booked, joined, attended, cancelled, waitlisted or reviewed; participant names; booking notes; QR or check-in status.
- Payment data: billing details, transaction amount, payment status, refunds, chargebacks, payment token and limited card metadata such as brand and last four digits. Full card data should be handled by Payment Partners.
- Provider data: business identity, representatives, tax and bank details, schedules, qualifications, licences, insurance, contracts, incident records and payout information.
- Communications: support requests, messages with Providers, surveys, complaints, recordings where notified, and safety reports.
- User Content: reviews, photographs, comments and other submitted content.
- Health and accessibility data: only where voluntarily provided or necessary for safe participation, accessibility support or an incident. Such information is minimised and shared with the relevant Provider only as necessary.
- Employer programme data: employer or sponsor, eligibility identifier, credit allocation, use of sponsored benefits and programme administration information.
2.2 Information collected automatically
- Device and technical data: IP address, device type, browser, operating system, app version, identifiers, language and time zone.
- Usage data: screens viewed, searches, clicks, referral source, session times, crashes, performance and interaction events.
- Approximate or precise location: only where enabled and necessary for nearby search, maps, check-in, fraud prevention or another clearly described feature.
- Cookie and similar technology data as described in the Cookie Notice.
- Security data: login attempts, authentication method, fraud signals, device reputation and audit logs.
2.3 Information from others
- Providers and organisers, including attendance, cancellations, incidents and eligibility.
- Payment Partners, banks and card networks, including payment outcome, fraud flags and chargebacks.
- Employers or sponsors, limited to programme eligibility and funding administration.
- Referral partners, social-login or identity providers where you choose to connect them.
- Public or lawful third-party sources used for business verification, fraud prevention, sanctions screening or legal compliance.
3. How we use information
- Create and secure accounts; authenticate users; and provide customer support.
- Display listings, recommendations, maps, availability and relevant search results.
- Create, manage, confirm, modify and cancel bookings and attendance.
- Process payments, refunds, credits, payouts, invoices, disputes and chargebacks.
- Send booking confirmations, reminders, safety notices, service messages and Provider communications.
- Prevent fraud, misuse, security incidents, unauthorised access and unlawful activity.
- Investigate complaints, incidents, injuries, harassment, disputes and policy breaches.
- Administer employer-funded or sponsored programmes.
- Analyse use, measure performance, debug, develop features and improve accessibility.
- Personalise content and recommendations, subject to applicable choices.
- Send marketing where you have consented or where otherwise permitted, with an opt-out.
- Comply with legal obligations, court orders, tax duties, accounting, audits and regulatory requests.
- Establish, exercise or defend legal claims.
- Protect the vital interests, rights, safety and property of users, Providers, Sweatt and others.
4. Legal and fair-processing grounds
Sweatt will process personal information only for a legitimate and disclosed purpose. Depending on the context, processing may be necessary to perform a contract, comply with law, protect safety, pursue a legitimate business interest that does not unfairly override the individual's interests, or act on consent. Where sensitive health information is processed, Sweatt will use a specific lawful basis and apply additional safeguards.
Although Trinidad and Tobago's Data Protection Act, Chap. 22:04 is not yet fully operational, Sweatt intends to follow its general privacy principles and commercially reasonable international privacy practices.
5. Sharing
We may share information with:
- the Provider and other participants where necessary to deliver a booking, coordinate a group activity or show an appropriate participant list;
- Payment Partners, banks, card networks and fraud-prevention providers;
- cloud hosting, communications, analytics, maps, customer-support, identity, security and professional-service providers acting under contract;
- an employer or programme sponsor, generally limited to eligibility, funding, aggregate utilisation, invoicing and programme administration. Detailed activity history will not be shared unless clearly disclosed, authorised or required;
- insurers, emergency responders, medical personnel and relevant authorities where necessary for safety or claims;
- law-enforcement, courts, regulators and government bodies where lawfully required or reasonably necessary;
- a buyer, investor or successor in a genuine financing, reorganisation, merger or sale, subject to confidentiality and appropriate notice; and
- other persons where you direct or consent.
We do not sell personal information for money. We will disclose any materially different data-monetisation practice before introducing it.
6. International processing
Some service providers may process information outside Trinidad and Tobago, including in the United States, Canada, the United Kingdom, the European Economic Area or other jurisdictions. Sweatt will use contracts, security reviews, data minimisation and other appropriate safeguards for cross-border processing.
7. Retention
We retain information only as long as reasonably necessary for the relevant purpose, including:
- account data while the account is active and for a reasonable period after closure;
- booking, payment, invoice and payout records for the period required by tax, accounting, payment-network and legal obligations;
- support, dispute, chargeback, fraud and incident records for the applicable limitation, investigation or insurance period;
- security logs for a limited risk-based period;
- marketing preferences until changed, plus suppression records needed to honour opt-outs; and
- de-identified or aggregated information that no longer identifies an individual.
A detailed internal retention schedule specifies exact periods by data category.
8. Security
We use proportionate administrative, technical and physical safeguards, which may include encryption in transit, restricted access, strong authentication, tokenised payments, logging, backups, vulnerability management, vendor controls and incident-response procedures.
No system is completely secure. Users should use unique credentials and promptly report suspected compromise.
9. Children
The Platform is not intended for a child to create an independent account unless Sweatt introduces a specifically designed minor account with verified guardian consent. Information about minors should be provided by or with the authority of a parent or guardian and limited to what is necessary for booking, safety and participation.
10. Your choices and rights
Subject to applicable law and verification, you may request:
- access to personal information held about you;
- correction of inaccurate or incomplete information;
- deletion where retention is no longer required;
- restriction or objection to certain processing;
- withdrawal of consent, without affecting earlier lawful processing;
- a portable copy of certain information where reasonably supported;
- closure of your account; and
- review of a significant automated decision, if Sweatt introduces one.
Some information cannot be deleted immediately because of bookings, payments, fraud prevention, legal claims, safety, accounting or legal retention. We will explain material limitations.
You may opt out of marketing through the message or account settings. You may disable location or push notifications in your device settings, though some features may stop working.
11. Automated tools and recommendations
Sweatt may use rules or models to rank search results, recommend activities, detect fraud, identify suspicious transactions or moderate content. These tools support platform operations and do not ordinarily make legal or similarly significant decisions without human review. We will provide further notice before introducing materially different automated decision-making.
12. Data incidents
Sweatt will investigate suspected personal-data breaches, take reasonable containment and remediation steps, and notify affected persons or authorities where required or appropriate based on risk.
13. Updates and contact
We may update this Notice as services and law change. Material changes will be communicated through the Platform, email or another reasonable channel.
Questions or requests: [email protected]. Complaints may also be directed to any competent Trinidad and Tobago authority once the relevant oversight framework is operational.