What this site uses
The site uses the information needed to run the service you choose: an email address for signup or sign-in, the details you submit in an inquiry, order and product references for purchase access, and technical session information needed to secure the site.
Payments and orders
Shopify hosts checkout and processes payment. This site stores order, customer, product, and access references needed to match eligible purchases to Studio. It never receives or stores full card numbers.
Bag, security, and session cookies
The shop bag uses a __Host- HttpOnly cookie containing an opaque Shopify cart id. Member, practice, and tool routes use security cookies such as CSRF tokens. Signing in to Studio sets session cookies through Shopify customer accounts.
Campaign attribution
On UNSTUCK campaign pages, fbclid, gclid, gbraid, wbraid, and allowed UTM parameters can be held in sessionStorage for the current tab. They are attached to the Shopify checkout URL only after the visitor selects “Yes, allow for this tab.” Choosing no, making no choice, or blocking session storage leaves those identifiers off the checkout link. The choice is remembered only for that tab session.
Email and inquiries
Newsletter signup uses Klaviyo double opt-in: the address must be confirmed by email, and marketing messages include an unsubscribe link. Contact, lesson, booking, press, archive, accessibility, and support forms use Cloudflare Turnstile for spam checks and can be delivered through Resend. Sending an inquiry does not subscribe the sender to marketing.
Members and Studio
A member record can hold account identity, purchases, Studio access, saved state, messages, lesson relationships, and data needed to operate protected media. Signed-in members can review account controls and request an export, correction, or deletion from the account page.
Hosting and service providers
The site runs on Cloudflare, which can process requests, security signals, and standard server logs. Shopify, Klaviyo, Resend, Cloudflare Turnstile, and embedded media providers process information only when their related feature is used. Their own privacy terms also apply to their services.
Media and microphone access
YouTube players load after you choose to play a video. Browser tools request microphone access only after you start a feature that needs it. Tuner audio stays in the browser. A Studio recording remains local unless a feature explicitly states that it will be uploaded.
Retention schedule
Deletion requests are reviewed manually; submitting one does not immediately delete an account. An active dispute, security investigation, legal hold, or record that must be kept under applicable law can pause deletion of the affected record. The current schedule is:
- Bag, sign-in, member, CSRF, and canary cookies expire after the maximum periods listed on Your privacy choices: 30 days, 10 minutes, 1 hour, 8 hours, and 15 minutes respectively.
- UNSTUCK campaign parameters and their allow-or-decline choice last only for the current browser-tab session.
- Browser-local practice, player, and safe-retry records remain until the related feature clears them or the visitor clears site data.
- Public inquiry and subscriber anti-replay receipts expire 30 days after the attempt. Expired completed receipts are removed in bounded batches during later intake activity.
- Inquiry messages are scheduled for deletion from the active support mailbox 24 months after the last substantive exchange, unless an unresolved order, dispute, safety issue, or legal duty requires the relevant message for longer.
- A Klaviyo marketing profile remains while the subscription is active. After unsubscribe or deletion, a minimal suppression record may be retained so the opt-out continues to be honored.
- Member profile, practice, Studio, purchase, and access records remain while the account or purchased access is active. A verified deletion request is handled within 30 calendar days; records required for an unresolved transaction, security need, or applicable legal duty are reviewed separately.
- The deletion-request record and its status history are scheduled for deletion 24 months after the request closes, unless they are needed to document an unresolved dispute or legal obligation.
Your choices
Unsubscribe from marketing email with the link in each message. To ask for access, export, correction, or deletion of member data, use the account page, email support@seanashemusic.com, or use the privacy contact route. A recorded request is acknowledged on submission and is due for a response within 30 calendar days. Do not send passwords, access tokens, or full payment details.