Refund policy

Last updated: July 29, 2026

1. Who We Are

Lost Folks ApS (“Lost Folks”, “we”, “us” and “our”) is the data controller for the personal data described in this Privacy Policy, except where another party is expressly identified as an independent data controller.

Lost Folks ApS
CVR: 44743604
Nørre Farimagsgade 52, 2 th
1364 Copenhagen K
Denmark

Email: support@lostfolks.com
Phone: (+45) 30 64 45 99

This Privacy Policy explains how we collect, use, disclose, retain and protect personal data when you visit lostfolks.com (the “Website”), purchase products or saunas, book or attend a retreat, communicate with us or otherwise interact with Lost Folks.

Our Terms and Conditions govern purchases and participation. This Privacy Policy governs our processing of personal data. Providing this notice does not mean that all processing is based on consent. We identify the relevant legal bases below.

2. Personal Data We Collect

The personal data we collect depends on how you interact with us.

2.1 Contact and Account Data

We may collect:

- name;
- billing and delivery address;
- email address and telephone number;
- account login details, preferences and settings;
- company name, CVR number, job title and business contact details; and
- communication and customer-service history.

2.2 Order and Transaction Data

We may collect:

- products and services viewed, added to a basket, ordered, returned or cancelled;
- order number, purchase date, price, currency and invoice details;
- delivery method, tracking information and delivery status;
- payment method, transaction reference, payment status and card authorisation or capture status;
- refund, cancellation, complaint and warranty information; and
- information required to prevent fraud or resolve a payment dispute.

Full payment-card details are normally processed directly by Shopify, Shopify Payments or another payment provider and are not made available to Lost Folks. We may receive limited payment information such as card type, last digits, transaction identifier and payment status.

2.3 Sauna Sales, Delivery and Service Data

For sauna quotations, purchases, delivery, installation and service, we may also collect:

- delivery and installation-site address;
- site-access information and contact details for the Buyer’s representatives;
- sauna specifications, drawings, requested modifications and approvals;
- information about foundations, crane access, electrical connections, drainage and installation;
- contact details for transport, crane, electrical, flooring or repair contractors;
- delivery inspections, photographs and video of the sauna or site;
- maintenance, installation and service records; and
- correspondence, evidence and technical information relating to defects, damage or claims.

2.4 Retreat Booking and Participation Data

For retreat bookings and participation, we may collect:

- booking and payment status;
- retreat dates, accommodation and activity selections;
- age confirmation and participation requirements;
- dietary preferences;
- emergency-contact name, relationship and telephone number;
- transport or voluntary carpooling preferences;
- information about accessibility or mobility needs; and
- information needed to manage cancellations, transfers, complaints or incidents.

2.5 Health and Other Sensitive Retreat Data

To plan and deliver a retreat safely, we may ask for limited information about allergies, intolerances, injuries, pregnancy, relevant medical conditions or physical and mental health circumstances.

Health data is a special category of personal data. We collect only information reasonably necessary for safety, catering, accessibility or participation. We normally process this information with your explicit consent under Article 9(2)(a) GDPR together with an applicable basis under Article 6 GDPR.

In a genuine emergency where you are unable to consent, we may process or disclose necessary health information to protect your or another person’s vital interests under Articles 6(1)(d) and 9(2)(c) GDPR.

Withdrawing consent does not affect processing that was lawful before withdrawal. If specific information is necessary for us to provide accommodation, catering or an activity safely, withdrawal or refusal to provide it may mean that we cannot offer the affected service or allow participation. We will explain this where relevant.

Health and safety information is not used for advertising, profiling or unrelated marketing.

2.6 Photographs, Video and Testimonials

We may take photographs or video at retreats, events or sauna deliveries. We will request separate consent before using identifiable images, video, testimonials or personal stories for marketing where consent is the appropriate legal basis.

You may decline marketing photography without affecting your purchase or retreat booking. You may withdraw consent for future use by contacting us. Withdrawal does not affect prior lawful use, and it may not always be possible to recall material that has already been printed or lawfully published, but we will stop new use where reasonably practicable.

2.7 Website, Device and Usage Data

When you use the Website, we and our technology providers may collect:

- IP address;
- browser, device and operating-system information;
- unique device or cookie identifiers;
- pages viewed, links clicked and navigation activity;
- shopping-basket and checkout activity;
- referring website and approximate location derived from IP address; and
- security, performance and diagnostic information.

Non-essential analytics and advertising data is collected only in accordance with your cookie choices and applicable law.

3. Where Personal Data Comes From

We collect personal data:

- directly from you when you browse, create an account, place an order, book a retreat, complete a form or contact us;
- automatically through the Website, cookies and similar technologies;
- from Shopify, payment providers, delivery companies and other service providers acting for us;
- from sauna manufacturers, installers, crane companies and repair contractors involved in your order;
- from retreat instructors, accommodation or catering providers where necessary to deliver the retreat;
- from a person or business that books, orders or communicates on your behalf;
- from publicly available business sources where relevant to a B2B relationship; and
- from advertising or social-media platforms, subject to your settings and applicable consent requirements.

If you provide personal data about another person, such as a retreat participant, emergency contact, employee or contractor, you must be authorised to do so and should direct that person to this Privacy Policy.

4. Why We Use Personal Data and Our Legal Bases

4.1 To Enter Into and Perform a Contract

We process personal data where necessary to:

- respond to a request for a quotation;
- confirm and manage orders and retreat bookings;
- reserve and collect payment at the agreed time;
- produce, customise, deliver and service products and saunas;
- organise accommodation, meals and retreat activities;
- communicate important booking, delivery or safety information;
- handle changes, cancellations, returns, complaints and warranty claims; and
- provide customer support.

Legal basis: Article 6(1)(b) GDPR – steps taken at your request before entering into a contract and performance of a contract.

4.2 To Comply With Legal Obligations

We process personal data where necessary for bookkeeping, tax, consumer, product-safety, package-travel, legal-claim and regulatory obligations, and to respond to lawful requests from public authorities.

Legal basis: Article 6(1)(c) GDPR – compliance with a legal obligation.

4.3 Legitimate Interests

We may process personal data where necessary for our legitimate interests in:

- operating and improving our business and Website;
- securing accounts, payments and systems;
- detecting and preventing fraud or misuse;
- documenting orders, specifications, delivery condition and customer approvals;
- establishing, exercising or defending legal claims;
- managing safety, incidents and access at retreats and sauna sites;
- maintaining appropriate business-customer relationships; and
- producing aggregated or de-identified business analysis.

Legal basis: Article 6(1)(f) GDPR. We use this basis only where our interests are not overridden by your rights and interests. You may object to processing based on legitimate interests as described in Section 13.

Where establishing, exercising or defending a legal claim requires sensitive personal data, we may rely on Article 9(2)(f) GDPR.

4.4 Consent

We rely on consent where required for:

- email, SMS or similar direct marketing;
- non-essential analytics or advertising cookies;
- specified uses of identifiable photographs, video or testimonials;
- sharing contact details for voluntary carpooling; and
- health data provided for retreat planning, except where another Article 9 condition applies.

Legal basis: Articles 6(1)(a) and, for health data, 9(2)(a) GDPR.

Consent is voluntary and can be withdrawn at any time. Withdrawal does not affect processing carried out lawfully before withdrawal.

5. Payments and Card Reservations

Our Website is hosted by Shopify. Payments may be handled by Shopify Payments or another payment provider.

For retreat bookings, a payment amount may be authorised and reserved when the booking is made, but Lost Folks does not charge or receive payment before the retreat begins, in accordance with our Terms and Conditions. We process the authorisation status, any need to renew the authorisation and the final payment status to administer the booking.

Payment providers process payment-card and anti-fraud information under their own legal responsibilities and privacy notices. We share only the information necessary to authorise, collect, refund or investigate a payment.

6. Retreat Information

6.1 Sharing for Retreat Delivery

We may share the minimum necessary retreat information with instructors, accommodation providers, caterers or other providers involved in the retreat.

Dietary information may be shared with catering staff. Relevant health, allergy, accessibility or emergency information is shared only with people who reasonably need it for safety or delivery. We do not routinely provide an entire medical description where a more limited instruction is sufficient.

Emergency information may be shared with emergency services, healthcare professionals, authorities or relevant persons where reasonably necessary to protect life, health or safety.

6.2 Voluntary Carpooling

Transport is not included in a retreat unless expressly stated. If you ask us to help coordinate voluntary carpooling, we will obtain your permission before sharing your name and relevant contact or journey information with another participant.

Any carpooling arrangement is made directly between participants. You can withdraw permission before your information is shared or ask us to stop further sharing.

7. How We Share Personal Data

We share personal data only where necessary for the purposes described in this Privacy Policy.

Recipients may include:

- Shopify and providers of hosting, ecommerce, account and checkout services;
- banks, card schemes, payment and fraud-prevention providers;
- bookkeeping, accounting and invoicing providers;
- fulfilment, postal, freight, transport, crane and storage providers;
- sauna manufacturers, technical suppliers, installers and approved repair contractors;
- retreat accommodation, catering, instructors and activity providers;
- IT, cloud-storage, communications and customer-support providers;
- analytics, advertising and social-media providers, subject to applicable consent requirements;
- insurers and professional advisers such as accountants, auditors and lawyers;
- public authorities, courts, law enforcement or regulators where legally required; and
- a potential buyer, investor or successor in a genuine business transaction, subject to appropriate confidentiality and legal safeguards.

Some recipients process data only on our documented instructions as processors. Others, such as payment providers, carriers, Shopify consumer services or public authorities, may act as independent data controllers for their own processing. Their privacy notices also apply to that processing.

We do not sell personal data for money. Certain advertising or Shopify features may be treated as “sale”, “sharing” or targeted advertising under some non-European privacy laws. Where applicable, we provide the required notice and opt-out controls.

8. Shopify

Shopify provides the ecommerce platform used by Lost Folks and processes customer and Website information to host the store, enable checkout, operate security and provide other services.

Shopify generally acts as our processor when handling customer data on our instructions. Shopify may act as an independent data controller when you use Shopify consumer services such as Shop or Shop Pay, or for certain enhanced services.

If Shopify Network Intelligence or other enhanced features are enabled, Shopify may use interactions with our store together with information from other merchants to provide fraud prevention, analytics, personalisation or advertising services. In the EEA, non-essential use is subject to applicable consent choices and privacy settings.

You can read Shopify’s Consumer Privacy Policy and use its privacy controls here:

https://www.shopify.com/legal/privacy/consumers

https://privacy.shopify.com

9. Cookies and Similar Technologies

We use cookies and similar technologies for:

- strictly necessary functions such as security, basket, checkout, payments and cookie preferences;
- preferences and Website functionality;
- analytics and performance measurement; and
- advertising and marketing measurement.

Strictly necessary technologies may be used without consent where permitted by law. Analytics, advertising and other non-essential technologies are used only after the required consent has been obtained.

You can accept, reject or adjust non-essential cookies through the Website’s cookie banner or privacy settings. Withdrawing consent does not affect the lawfulness of earlier processing, but prevents future non-essential use on that device where the controls operate correctly.

The cookie banner or separate Cookie Policy identifies the specific cookies and providers currently active, their purposes and lifetimes. Browser settings may also block cookies, but this can affect Website functionality.

10. International Data Transfers

Shopify and some other providers may process personal data outside Denmark or the European Economic Area.

Where personal data is transferred to a country outside the EEA that has not been recognised as providing adequate protection, we use or require an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses, together with supplementary safeguards where required.

Shopify states that EEA customer data is initially processed by Shopify International Limited in Ireland and that affiliated entities and subprocessors may assist in accordance with Shopify’s Data Processing Addendum.

You may contact us for further information about the relevant transfer safeguards.

11. Retention

We retain personal data only for as long as necessary for the relevant purpose, including legal, accounting, safety and claim requirements.

Our general retention approach is:

- order, invoice and accounting material: for five years from the end of the financial year to which it relates, or longer if another legal requirement applies;
- account data: while the account remains active and afterwards for a limited period required for orders, security, legal obligations or claims;
- quotation and ordinary customer-service data that does not result in a purchase: normally for up to two years after the last meaningful contact, unless needed for a dispute or requested to be deleted earlier;
- sauna specifications, approvals, delivery records, service history and claim documentation: for the duration of the customer relationship and normally for up to five years afterwards, or longer where necessary for an active claim or legal obligation;
- retreat booking and ordinary participation data: normally for up to two years after the retreat, except information included in accounting records or required for a claim;
- retreat health, allergy, accessibility and emergency-contact information: normally deleted or anonymised within 30 days after the retreat, unless an incident, complaint, legal claim or legal obligation requires limited information to be retained for longer;
- marketing data: until consent is withdrawn or we no longer use it, after which we may retain minimal information on a suppression list to ensure that we respect the opt-out;
- photo, video and testimonial material: for the period stated when consent is obtained, until consent is withdrawn for future use, or until the material is no longer needed; and
- cookie and analytics data: for the periods shown in the cookie banner or Cookie Policy.

We may retain data for longer where reasonably necessary to establish, exercise or defend a legal claim. When data is no longer required, it is deleted, anonymised or securely restricted.

12. Security

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Measures may include access controls, account security, encryption in transit, secure service providers, backups, restricted access to sensitive retreat information and procedures for handling security incidents.

No transmission or storage method is completely secure. Please do not send full payment-card details or unnecessary medical information by ordinary email. Use the secure or designated method communicated by Lost Folks where available.

13. Your Rights

Subject to the conditions and exceptions in applicable law, you may have the right to:

- receive information about our processing;
- request access to your personal data;
- correct inaccurate or incomplete data;
- request deletion;
- request restriction of processing;
- receive data you provided in a structured, commonly used and machine-readable format and, where technically feasible, have it transmitted to another controller;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- withdraw consent at any time;
- request information about relevant international-transfer safeguards; and
- lodge a complaint with a data-protection authority.

We do not use solely automated decision-making that produces legal or similarly significant effects for you. Automated fraud or security tools may flag an order for review, but Lost Folks may perform a human assessment before taking a significant action where required.

To exercise your rights, contact support@lostfolks.com. We may request information necessary to verify your identity and protect data from unauthorised disclosure.

We normally respond within one month. This may be extended where a request is complex or numerous, as permitted by law. Rights are not absolute; if we cannot fully comply, we will explain the applicable reason.

14. Marketing Preferences

We send email, SMS or similar direct marketing only where permitted by law, normally based on consent.

You can unsubscribe through the link in a marketing message or by contacting support@lostfolks.com. We may continue to send non-marketing communications necessary for an order, booking, retreat, safety notice, service case or legal obligation.

Opting out of marketing does not automatically delete order or other information that we must retain for another lawful purpose.

15. Children

The Website, sauna sales and retreats are not directed at children. You must be at least 18 years old to place an order or booking unless Lost Folks expressly agrees otherwise in writing and obtains any information or permission required from a parent or guardian.

If you believe a child has provided personal data without appropriate authorisation, contact us so we can investigate and delete it where required.

16. Third-Party Websites and Social Media

The Website may link to third-party websites, social-media platforms or services. Those parties control their own processing, and their privacy policies apply. Lost Folks is not responsible for the privacy practices of services it does not control.

Information you publish in a public review, social-media comment or other public area may be visible and reused by others. Please avoid posting sensitive information publicly.

17. Complaints

Please contact us first at support@lostfolks.com if you have questions or concerns about our processing.

You also have the right to lodge a complaint with the Danish Data Protection Agency:

Datatilsynet
Carl Jacobsens Vej 35
2500 Valby
Denmark

Email: dt@datatilsynet.dk
Website: https://www.datatilsynet.dk

If you live outside Denmark, you may also contact the data-protection authority in your country of residence or work.

18. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our services, providers, legal obligations or processing practices.

We will publish the revised version on the Website and update the “Last updated” date. Where a change materially affects your rights or how we use data already collected, we will provide additional notice or obtain consent where required.

19. Contact

Questions, requests and consent withdrawals should be sent to:

Lost Folks ApS
Nørre Farimagsgade 52, 2 th
1364 Copenhagen K
Denmark

Email: support@lostfolks.com
Phone: (+45) 30 64 45 99