Bayley Beach, Rowayton, ConnecticutCommunity sauna on the Connecticut coastBook the whole haus for your peopleSessions from $44
TYDEHAUS

Last updated September 1, 2026

PRIVACY

This is what we collect, why, who sees it, and how to have it removed. It describes what the site actually does, and we will change it if the site changes.

THE SHORT VERSION

  • We collect what we need to run a sauna: who is coming, how to reach them, and a signed waiver.
  • We never sell your details, share them for advertising, or hand them to anyone who is not helping us run the business.
  • There are no ads, no analytics and no tracking cookies on this site.
  • Card details go straight to Stripe. We never see them.
  • You do not need an account to book one seat or buy a gift card. Booking for others, membership and packs use one, and you can sign in with a passkey or an emailed code instead of a password if you prefer.
  • Email us and we will delete what we hold about you, apart from a signed waiver, which is a legal record.

WHO WE ARE

TYDE LLC, trading as TYDE HAUS, a community sauna at Bayley Beach in Rowayton, Connecticut. Questions about anything on this page go to haus@tydehaus.com. A person reads it.

WHAT WE COLLECT, AND WHY

Only what a particular thing needs.

Joining the opening list

Your name and email address, and whether you are interested in membership. We send one email asking you to confirm the address. Until you do, you are not on the list and we will not write again.

Membership

Your name, email and phone number, which plan you chose, and which house you would use. Payment details and your billing address are collected by Stripe on Stripe’s own page. We receive a reference to the subscription, and Stripe tells us when a payment succeeds or fails.

Booking a session (when booking opens)

Your name, email and phone number, how many people are coming, and the names of anyone you book for. If you add a guest’s email, we send them their own confirmation and waiver link. We also ask for your birthday, month and day only, never the year, so we can say happy birthday. That one is optional.

The waiver

Everyone who uses the sauna signs a release. It asks for your legal name, date of birth, home address, phone number and email, and the name of a parent or guardian if you are under eighteen. We also record the time you signed, your IP address, and which browser you used, as evidence that you agreed. This is the most personal thing we hold, and it is held for the reasons in “How long we keep it” below.

Gift cards and the shop

Your name, email and phone number, and what you bought. If you send a gift card to someone, the name and email you give for them and any message you write. We use that only to deliver the card.

Asking about a private event

Your name, email, phone number if you give it, and whatever you write in the message.

Visiting the site

Nothing that identifies you. We do not use analytics or advertising tools. The site loads its fonts from Adobe and Google, which means those companies see your IP address when a page loads, in the same way any website that uses their fonts does. We are looking at hosting the fonts ourselves so that even this stops.

WHO SEES IT

The people who work at TYDE HAUS, and three services we rely on to run it. Each one gets only what its job needs.

  • Stripe handles every payment. Your card number never touches our systems. Stripe keeps your billing address and payment history under its own privacy policy.
  • Resend delivers our email. It sees the address it is sending to and the contents of the message, the way any email service does.
  • Vercel hosts the site and the database, in the United States.

That is the whole list. We do not sell your details, rent them, swap them, or give them to advertisers. Nothing is exported to a personal email account or a spreadsheet somewhere. The only place your details live is our database, and the only people who can open it are the people running the business.

WHERE IT LIVES

In the United States, on servers run by Vercel. Nothing is stored or copied outside the US.

MARKETING

We only send marketing email to people who have said yes. On the opening list, confirming your address is the yes. On the booking form there is a box, and we will also write to you about your booking whether or not you tick it, because that is not marketing. Text messages need a separate, unticked box; we will never text you about offers unless you asked us to.

Every marketing email will have a way to stop them, and you can also just reply and say so. Stopping marketing email does not affect anything else, and we will still send you your booking confirmations.

If somebody books a session and adds you as a guest, we will send you your confirmation and your waiver link. We will not add you to any marketing list on their say-so. Only you can do that.

HOW WE LOOK AFTER IT

  • Everything travels over an encrypted connection.
  • Passwords, where people choose to use one, are stored only as a one-way hash, checked against known data breaches when set, and never written to a log. Sign-in is rate limited. Staff sign in by a link sent to their email that works once.
  • Card details never reach us. Stripe is certified to the highest level for handling them.
  • The database is not reachable from the internet. Only the site can talk to it.
  • Codes and links we email you, like a gift card code or a sign-in code, are kept out of our server logs and expire quickly. A sign-in code lasts ten minutes; a confirmation or reset link lasts an hour and works once.
  • Being a member gets you a free seat only when you are signed in to your own account with a confirmed email. Somebody who merely knows your email address cannot book in your name for free.
  • Nobody can change your details by typing your email into a form. Public forms can add a missing phone number to your record, but never replace one that is there.

COOKIES

Two, and neither tracks you. If you sign in to an account, a cookie keeps you signed in for thirty days, refreshed when you come back. If you work here and sign in to the staff area, a cookie keeps you signed in for twelve hours. Neither can be read by any script, and nothing is set for ordinary visitors, so there is no banner to click.

Behind the account cookie we keep a record of each sign-in: the time, the internet address and the browser it came from. That is how we can tell a sign-in that was not you, and end it. The record goes when the session expires, thirty days after you last used it. Sign-in attempts are counted for a minute at a time, by address, to slow down anyone guessing passwords, and those counts are thrown away the next day.

The shop remembers what is in your bag in your own browser, and the booking page keeps a random key so a double-tapped button does not hold your seats twice. Neither contains anything about you and neither leaves your device. Stripe’s payment page sets its own cookies on Stripe’s domain, under Stripe’s policy.

HOW LONG WE KEEP IT

  • Signed waivers: seven years. A waiver is a legal record of an agreement. It protects you as well as us, and its usefulness depends on the details in it, so we keep it for the period a claim could be brought. We cannot delete it early on request, and we say so here rather than pretending otherwise.
  • Payments and orders: seven years, because they are tax records.
  • Your contact details: while you are a customer, and for three years after your last visit or purchase. After that we have no reason to hold them.
  • An unconfirmed list signup: thirty days, then it is removed.
  • A private event enquiry: two years, in case you book again.

None of this depends on somebody remembering. A job runs every day and removes what has passed its date.

YOUR CHOICES

Email haus@tydehaus.com from the address we have for you and ask. We will:

  • Tell you what we hold about you.
  • Correct anything that is wrong.
  • Delete your details. Your name, contact details, birthday and any notes are removed, and you are taken off every list. Your signed waiver and your payment records stay for the periods above, because they are legal and financial records, and they are the only things that do.
  • Stop marketing to you, immediately.

We aim to do all of this within a week. There is no charge and no form to fill in.

CHILDREN

Children under eight cannot use the sauna. Anyone under eighteen needs a parent or guardian to sign their waiver, and we record that person’s name. We do not knowingly collect anything from a child under thirteen through the website. If you think we have, tell us and we will remove it.

CHANGES

If we change what we collect or who sees it, this page changes first, and the date at the top moves. If a change matters, for example a new service that sees your details, we will email people it affects rather than rely on anyone re-reading this.

TYDE LLC · Rowayton, Connecticut · haus@tydehaus.com