Privacy Policy

Simple and transparent privacy practices for TarotDaily

Last updated: January 2025

What We Collect

We collect minimal information to provide TarotDaily:

  • Analytics data: Page visits, app usage, and performance metrics (via Vercel Analytics and Google Analytics)
  • Technical information: Browser type, device info, IP address, and performance data
  • Account data: Email address, password (encrypted), and account preferences (if you create an account)
  • Reading data: Tarot card selections, spread types, notes, and timestamps (stored in Supabase)
  • Payment data: Subscription status and billing information (processed by our secure payment processor, not stored by us)
  • Communication data: Information you provide when contacting us

How We Use Your Information

We use your information to:

  • Provide services: Generate tarot readings, save your history, and manage your account
  • Process payments: Handle subscriptions through our secure payment processor and manage premium features
  • Improve the app: Analyze usage patterns to enhance user experience and fix issues
  • Performance monitoring: Track app performance and identify technical problems
  • Customer support: Respond to your questions and provide assistance
  • Legal compliance: Meet regulatory requirements and protect our rights
  • Security: Protect against fraud and unauthorized access

Information Sharing

We may share your information with:

  • Vercel: Hosting and analytics services (performance data, usage statistics)
  • Google Analytics: Website analytics and user behavior insights
  • Supabase: Database and authentication services (account data, reading history)
  • Lemon Squeezy: Payment processing and subscription management
  • Legal authorities: When required by law or to protect our rights
  • Business transfers: In case of merger, acquisition, or sale of assets

Important: We never sell your personal information. All third-party services are bound by strict data protection agreements.

Payments & Merchant of Record

We use Lemon Squeezy as our Merchant of Record to process payments, manage taxes, and issue invoices/receipts. Lemon Squeezy is the legal seller for purchases made in our checkout and processes your billing details and payment method. See the Lemon Squeezy Privacy Policy and Buyer Terms for details on how payment data is handled.

Cookies and Tracking

We use cookies and similar technologies for:

  • Essential cookies: Authentication, security, and basic functionality
  • Analytics cookies: Vercel Analytics and Google Analytics to understand usage patterns
  • Performance cookies: Monitor app performance and identify technical issues
  • Preference cookies: Remember your settings and reading preferences

You can control cookies through your browser settings. Disabling certain cookies may affect app functionality.

Data Retention

We retain your information for as long as necessary to provide our services:

  • Account data: Kept while your account is active, deleted 30 days after account deletion
  • Reading history: Stored until you delete your account or individual readings
  • Analytics data: Aggregated and anonymized after 26 months (Google Analytics standard)
  • Payment data: Not stored by us - managed by our payment processor according to their retention policies
  • Logs and technical data: Retained for up to 90 days for security and debugging

You can request deletion of your data at any time by contacting us or deleting your account.

Your Rights

You can:

  • Access your personal information
  • Correct inaccurate information
  • Delete your information
  • Opt out of marketing emails
  • Control cookie preferences

Contact us at contact@tarotdaily.app to exercise these rights.

Data Security

We protect your information using industry-standard security measures:

  • Encryption: All data is encrypted in transit (HTTPS) and at rest
  • Authentication: Secure login through Supabase with password hashing
  • Access control: Limited access to user data by authorized personnel only
  • Regular updates: Security patches and vulnerability assessments
  • Third-party security: Vercel, Supabase, and our payment processor maintain SOC 2 compliance

While we implement strong security measures, no system is 100% secure. We continuously monitor and improve our security practices.

Changes

We may update this privacy policy occasionally. We'll notify you of significant changes through the app or by email.

Contact Us

Questions about privacy, data requests, or this policy? Contact us at:

Email: contact@tarotdaily.app

Website: https://tarotdaily.app

Data Protection Officer: contact@tarotdaily.app

For payment-related issues, please contact our payment processor's support team directly as they handle all billing matters.