1. Scope and controller
This policy applies to the Tarotip website, accounts, and related services. Send privacy questions to [email protected].
2. Information we collect
- Account data: name or nickname, email, verification status, and basic profile information returned by Google sign-in.
- Service content: questions, selected cards and spreads, AI readings, follow-ups, and private reading history.
- Subscription data: plan, status, Stripe customer and subscription identifiers, and transaction outcomes; we do not store full card numbers.
- Usage and technical data: feature counts, quotas, check-ins, IP address, device and browser data, timestamps, essential logs, and security events.
- Support data: information you choose to include when contacting us.
3. Purposes and legal bases
- Contract: create accounts, generate readings, save history, deliver subscription benefits, and manage billing.
- Legitimate interests: secure the service, prevent abuse, diagnose faults, measure reliability, and improve the product.
- Consent: send optional communications or use non-essential technology where consent is legally required.
- Legal obligations: maintain tax, accounting, fraud, dispute, and regulatory records.
4. Service providers and disclosures
We share data with providers only as needed to operate the service and restrict their use through contracts and access controls. Current key categories include:
- Google for optional account sign-in and authentication.
- Stripe for checkout, subscriptions, the billing portal, payments, and fraud prevention.
- Resend for email verification, password resets, and essential service messages.
5. Reading content and sensitive data
Reading questions may be private. Do not submit card numbers, identity documents, detailed health records, another person’s secrets, or data you do not have the right to share. To generate a reading, the relevant question, cards, and limited context are sent to our AI provider.
7. Retention
Account and reading data is generally retained while your account is active. After a verified deletion request, we delete or anonymize data that is no longer needed. Billing, transaction, security, and dispute records may be retained longer for legal or legitimate business needs. Backup copies expire through normal rotation.
8. International transfers and security
Providers may process data outside your country. Where required, we use contractual safeguards and reasonable technical and organizational controls. No internet service can promise absolute security; we will provide legally required notice of a qualifying data incident.
9. Your rights and choices
Depending on local law, you may request access, correction, export, deletion, or restriction, withdraw consent, or object to processing. Use available account tools or email [email protected]; we may verify your identity. You may also complain to your local data protection authority.
10. Children, updates, and contact
The service is not intended for anyone under 18, and we do not knowingly collect their data. We may update this policy and show the new date here, with reasonable notice for material changes. Send privacy requests to [email protected].