Privacy Policy

Unshackled Soul ยท Last updated: September 29, 2026

This Privacy Policy explains how Prosperity Pathfinders, LLC, doing business as Unshackled Soul and operating under the Unshackled Soul brand ("Company," "we," "us," or "our") collects, uses, stores, shares, and protects personal information when you visit https://theunshackledsoul.com/, purchase or use our products and Services, participate in communities or events, connect business systems, use software-enabled or AI-assisted features, or otherwise interact with us.

This Policy is intended to describe our practices. Where applicable law requires consent for a particular processing activity, we will seek that consent separately. If a business Client provides personal information about employees, customers, contractors, or other persons for us to process on the Client's behalf, the Data Processing Addendum may also apply.

1. Information We Collect

Information you provide directly may include name, email, phone number, mailing or billing address, account and login information, purchase history, program enrollment details, scheduling information, survey or assessment responses, birth information, goals, personal reflections, messages, support requests, community posts, testimonials, photos, videos, and other content you choose to provide.

For business-focused Services, we may also collect Business Data such as company name, role, business stage, revenue or financial information, offer and pricing information, expenses, team structure, compensation information, responsibilities, process information, technology stack, software usage, operational metrics, customer or vendor information, business assets, intellectual property information, implementation results, calendars, documents, and other records you choose to provide.

If you connect a third-party system, we may receive information made available through the connection and permissions you grant, such as accounting, payments, CRM, scheduling, project management, document storage, analytics, email, or other business-system data.

We may automatically collect device and usage information such as IP address, browser, device type, operating system, pages viewed, links clicked, referring source, approximate location, date and time, cookies, analytics events, email engagement, account activity, error logs, security events, and feature usage.

We may receive information from service providers, payment processors, advertising platforms, analytics providers, referral partners, social media platforms, customer-support tools, or other third parties where permitted by law.

2. Payment Information

Payments may be processed by third-party processors. We generally do not store full payment-card numbers or complete payment credentials on our own systems.

Payment processors process information under their own terms and privacy practices. We may receive transaction identifiers, payment status, limited card metadata, billing contact information, subscription status, and other information needed to administer the purchase.

3. Sensitive Personal Information and Restricted Data

Some personal-growth Services may invite you to voluntarily share information about relationships, emotions, family circumstances, personal history, spiritual beliefs, identity, health-related experiences, or other sensitive reflections. You control what you choose to share.

Business-focused Services may also involve personal data about employees, contractors, customers, or other individuals if a Client chooses to provide it. Business Clients are responsible for ensuring they have a lawful basis and authority to provide such information.

Unless we expressly approve otherwise in writing and appropriate safeguards or agreements are in place, do not provide protected health information subject to HIPAA, full payment-card data, passwords, private authentication keys, Social Security numbers, government identification numbers, biometric templates, export-controlled data, classified information, or other highly regulated or security-sensitive data not reasonably necessary for the Service.

We are not a HIPAA covered entity or business associate merely because a Client operates in healthcare. We will not accept HIPAA-regulated protected health information as a business associate unless we first execute a separate Business Associate Agreement and expressly approve that processing.

4. How We Use Information

We may use information to provide, personalize, administer, secure, and support products and Services; create accounts; process payments; deliver reports and personalized outputs; operate diagnostic tools; provide Navigator or AI-assisted features; perform business analysis; conduct strategic reviews; manage communities; respond to support requests; communicate about active Services; maintain records; detect fraud or misuse; enforce contracts; comply with law; and protect rights and security.

We may use information to improve our products, methodology, user experience, reliability, security, and internal operations.

Where permitted, we may use contact and engagement information for newsletters, marketing, advertising measurement, and promotional communications. You may opt out of promotional email at any time.

5. Business Data and Third-Party Personal Data Provided by Clients

Business Clients retain ownership of their underlying Business Data. We process Business Data only for purposes permitted by the applicable agreement, this Policy, and any applicable DPA.

When a Client provides personal data about employees, contractors, customers, vendors, or other individuals and instructs us to process it on the Client's behalf, the Client generally determines the purposes and means of that processing and we act as a processor, service provider, or contractor to the extent applicable.

The Client is responsible for providing legally required notices, obtaining consents where needed, limiting data to what is appropriate, and responding to individuals whose data the Client controls, except to the extent the DPA assigns assistance obligations to us.

6. AI-Assisted and Automated Processing

Some Services may use AI, language models, document extraction, software rules, scoring, automation, or similar technologies to summarize information, classify records, identify potential patterns, generate diagnostic hypotheses, draft recommendations, support Navigator responses, or improve workflow.

We may transmit limited information to AI or technology providers acting as service providers or subprocessors when necessary to provide the feature. Where commercially available and reasonably appropriate, we will configure providers handling Client Confidential Business Information so customer content is not used to train generalized public models.

We do not treat automated outputs as infallible. Material business findings or recommendations may require human review, Client validation, additional evidence, or professional advice depending on the decision involved.

7. Connected Accounts and Integrations

If you choose to connect a third-party account or system, you authorize us and our applicable providers to access, retrieve, transmit, normalize, analyze, store, and display information available through the permissions you grant for purposes of delivering the Service.

We do not obtain broader access than the technical permissions made available through the connection. You are responsible for selecting appropriate permissions and ensuring you are authorized to connect the system.

You may revoke or disconnect an integration through available settings or by contacting us. Revocation stops future access where technically available, but previously processed data may remain subject to contractual, legal, backup, or retention requirements.

8. Cookies, Analytics, Advertising, and Tracking Technologies

Our Website may use cookies, pixels, tags, scripts, analytics tools, and similar technologies to maintain sessions, remember preferences, understand usage, improve performance, measure conversions, prevent fraud, and support marketing.

The Website currently uses the following third-party tags and pixels, which are loaded in the header of every page: Google Analytics (Google LLC), which collects device, browser, page-view, referral, approximate-location, and event data to help us understand how the Website is used; the Google Ads tag and conversion event snippet (Google LLC), which measure whether visits that begin with a Google advertisement lead to actions such as booking a call, requesting a free resource, or making a purchase, and which may be used to show you our advertisements on Google properties and partner sites; the Meta Pixel (Meta Platforms, Inc.), which measures the same kinds of actions and may be used to show you our advertisements on Facebook, Instagram, and other Meta services and to build audiences of people similar to our visitors; and the Google Search Console verification tag, which only confirms that we control the Website and does not itself collect visitor data. These providers may set their own cookies, receive your IP address, browser information, and the pages you view, and may combine this information with other information they hold about you. When a conversion is recorded, we may pass the type of action, a transaction or booking identifier, and the purchase amount and currency to these providers; we do not pass your name, email address, or other directly identifying information through these tags. Google's practices are described at https://policies.google.com/technologies/partner-sites and Meta's at https://www.facebook.com/privacy/policy/.

We also use Microsoft Clarity (Microsoft Corporation) on the Website and selected Atlas landing pages to understand page use through interaction measurements, heatmaps, and session recordings. Clarity may collect pages viewed, clicks, scrolling, browser and device information, IP address, and cookies or similar identifiers. We mark the Recovery application and Atlas intake areas for masking in Clarity recordings. Microsoft's privacy practices are described at https://privacy.microsoft.com/privacystatement.

Because these advertising tags may be used to show you our advertisements elsewhere, certain laws may characterize this activity as "sharing," "targeted advertising," or cross-context behavioral advertising. You may opt out of this activity by using the controls described below, by contacting us at support@theunshackledsoul.com with the subject line "Opt out of targeted advertising," or, where we honor it, by enabling the Global Privacy Control signal in your browser. Where applicable, we will provide any additional legally required disclosures and opt-out mechanisms.

You may be able to manage cookies through browser settings, a consent-management tool, or other privacy controls made available on the Website. You may also opt out of Google Analytics using the browser add-on at https://tools.google.com/dlpage/gaoptout, manage Google advertising personalization at https://adssettings.google.com, manage Meta advertising preferences within your Facebook or Instagram account settings, and learn about industry opt-outs at https://optout.aboutads.info. Blocking or deleting cookies may affect some Website features.

9. How We Share Information

We may disclose information to service providers and subprocessors that support hosting, storage, databases, authentication, payments, email, analytics, advertising, communications, forms, scheduling, video, communities, customer support, file processing, AI or language-model services, integrations, professional services, security, and related infrastructure.

We may also disclose information with your consent; to comply with law or legal process; to address security, fraud, safety, or policy violations; to protect legal rights; to professional advisers; or in connection with a merger, acquisition, financing, reorganization, sale, or transfer of the business.

We do not sell personal information in the traditional sense of selling customer lists for money. If our activities constitute a sale, sharing, or targeted advertising under applicable law, we will provide applicable notices and choices.

10. Subprocessors and Service Providers

For business processing subject to a DPA, we may engage subprocessors under written terms requiring appropriate confidentiality, security, and data-protection obligations.

We maintain a Subprocessor Framework describing the categories of providers we use and how business customers may obtain the current list. The current list may be made available through a designated Website page or upon request to support@theunshackledsoul.com.

Where required by applicable law or contract, we will provide appropriate notice of material new subprocessors and a process for raising reasonable data-protection objections.

11. Controller and Processor Roles; Data Processing Addendum

For personal data we collect and use for our own purposes, such as account administration, billing, security, legal compliance, customer support, Website analytics, and direct communications, we generally act as a controller or business as those terms are defined by applicable law.

When we process personal data solely on behalf of a business Client and according to that Client's documented instructions, we generally act as a processor, service provider, or contractor to the extent applicable.

The Company's DPA is incorporated into an eligible business Client's agreement to the extent required for processor or service-provider processing. The DPA addresses instructions, confidentiality, security, subprocessors, rights requests, incidents, deletion, international transfers, and related obligations.

12. Aggregate and De-Identified Information

We may create aggregate or de-identified information derived from Service usage, diagnostic patterns, intervention outcomes, Business Data, or other information, subject to applicable law and contractual restrictions.

We may use such information for analytics, benchmarking, methodology and product improvement, quality assurance, research, generalized insights, and development of future features, provided it does not reasonably identify a Client, business, employee, customer, or other individual.

We will not attempt to re-identify data treated as de-identified except as permitted by law for purposes such as validating de-identification, security, or compliance.

13. Email Marketing and Communications

We may send transactional messages relating to purchases, accounts, access, scheduling, support, security, legal notices, or active Services.

We may send marketing communications when permitted. You may unsubscribe from promotional emails through the unsubscribe mechanism or by contacting us. Unsubscribing from marketing does not prevent necessary transactional communications.

14. Data Retention

We retain information for as long as reasonably necessary to provide Services, maintain accounts, fulfill contracts, comply with legal, tax, accounting, and reporting obligations, resolve disputes, prevent fraud, enforce agreements, maintain security, and support legitimate business operations.

Retention periods may differ by data type, Service, legal requirement, backup cycle, and contractual obligation. When information is no longer reasonably needed, we may delete, anonymize, aggregate, or securely dispose of it.

For business personal data processed under a DPA, return or deletion at termination is governed by the DPA and applicable law, subject to legal retention and backup limitations.

15. Security

We maintain commercially reasonable administrative, technical, and organizational safeguards appropriate to the nature of the information and Service. Measures may include access controls, authentication, least-privilege practices, encryption in transit, encryption at rest where supported, backups, logging, vendor management, secure configuration, incident response, and personnel confidentiality obligations.

No system is completely secure. You are responsible for securing your credentials, devices, connected systems, and authorized users and for notifying us promptly of suspected unauthorized access.

Business customers with additional security requirements should address them in a written enterprise agreement or DPA before submitting regulated data.

16. Your Privacy Choices and Requests

Depending on applicable law, you may have rights to access, correct, delete, obtain a portable copy of, restrict, object to, or otherwise control certain personal information.

You may also have rights to opt out of targeted advertising, sale or sharing of personal data, or certain profiling. Rights vary by jurisdiction and are subject to exceptions.

Submit a request to support@theunshackledsoul.com or by mail to 1710 Keller Pkwy #6353, Keller, TX 76248. We may verify your identity or authority before acting on a request.

17. Texas Privacy Rights

Where the Texas Data Privacy and Security Act applies, Texas residents may have rights to confirm whether personal data is processed, access data, correct inaccuracies, delete personal data, obtain portable data, and opt out of certain targeted advertising, sale of personal data, or qualifying profiling.

If we deny a request and Texas law provides an appeal right, you may appeal by replying to our decision or emailing support@theunshackledsoul.com with the subject line "Privacy Appeal." We will respond as required by applicable law.

We will not discriminate against you for exercising privacy rights provided by applicable law.

18. Other U.S. State Privacy Rights

Residents of other U.S. states may have additional privacy rights where a state privacy law applies to us. We will process verified requests and provide notices or opt-out mechanisms as required by applicable law.

If a law requires a specific mechanism for targeted advertising, sale, sharing, sensitive-data processing, or appeals, we will make that mechanism available when applicable.

19. EEA, UK, and International Privacy Rights

If you are in the European Economic Area, United Kingdom, or another jurisdiction with similar laws, you may have rights including access, correction, deletion, restriction, objection, portability, withdrawal of consent, and complaint to a supervisory authority, subject to applicable law.

Where required, we rely on lawful bases such as performance of a contract, legitimate interests, legal obligations, consent, or protection of vital interests.

Information may be processed in the United States and other countries where our providers operate. Where a legally required transfer mechanism applies, we may use approved mechanisms such as the European Commission Standard Contractual Clauses and, where applicable, recognized UK transfer mechanisms or other lawful safeguards.

20. Children's Privacy

Our Website and Services are intended primarily for adults. We do not knowingly collect personal information from children under 13 through general Website or program use.

Persons under 18 may not purchase or participate without any consent and written Company approval required by the applicable Service and law.

21. Testimonials, Reviews, and Public User Content

Private participation does not automatically authorize public use of your name, image, confidential story, business results, or private materials.

If we want to use identifiable private Client material for marketing or a case study, we may request separate consent. Public reviews or comments you voluntarily post may be referenced to the extent permitted by law and platform terms.

You may request that we discontinue future use of a voluntarily provided testimonial, subject to practical limitations for materials already distributed or incorporated into completed media.

22. Communities, Group Spaces, and Recordings

Information you voluntarily share in a group space may be visible to other participants. We require participants to follow confidentiality rules but cannot guarantee their conduct.

Some live sessions may be recorded for replays, quality, or internal purposes. Where practical, participants will be informed. Public marketing use of identifiable recorded contributions requires appropriate permission as described above.

23. Third-Party Links and Platforms

Our Website and Services may link to or rely on third-party websites and platforms. Their privacy practices are governed by their own policies. We are not responsible for their independent practices or security beyond our contractual relationship with them.

24. Affiliate Links and Recommendations

Some links may be affiliate links. If you purchase through them, we may receive compensation where disclosed. A recommendation does not transfer responsibility for the third party's privacy practices, products, or services to us.

25. Business Transfers

If the Company is involved in a merger, acquisition, financing, restructuring, sale, bankruptcy, or transfer of assets, information may be transferred as part of the transaction subject to applicable law and appropriate confidentiality or privacy protections.

26. Changes to This Privacy Policy

We may update this Policy from time to time. The Last Updated date will be revised when changes are posted. Where law requires additional notice or consent for a material change, we will provide it.

27. Contact Us

Unshackled Soul | Legal Business: Prosperity Pathfinders, LLC dba Unshackled Soul | Email: support@theunshackledsoul.com

Mailing Address: 1710 Keller Pkwy #6353, Keller, TX 76248 | Website: https://theunshackledsoul.com/

Read the Terms of Use