1. Data controller
The controller of personal data processed in connection with the Astro Tarot Online Website and Application is AURORA MAREK WOLAN, Polish Tax ID (NIP) 5170124465, 84 Olbrachta Street, 35-614 Rzeszów, Poland.
Privacy questions and rights requests may be sent to admin@astrotarotonline.com. The Controller has not appointed a data protection officer; contact is made directly with the Controller.
This Policy is effective from 31 July 2026.
2. Scope
This Policy covers astrotarotonline.com, app.astrotarotonline.com, User Accounts, AstroMatrix™ Quick Spreads, Reader Spreads, Subscriptions, payments, contact forms and cooperation with Tarot Readers.
It does not govern independent third-party websites or services linked from the Website or Application. Those providers process data under their own terms.
3. Categories of personal data
Account and authentication
- display name, email address, user identifier, language, registration date and accepted document version;
- for Google or Apple sign-in, provider identifier and information made available according to the User's selection;
- session, login, security and abuse-prevention information.
People and entity profiles
- label, name, relationship, optional description and photograph;
- date of birth, optional time and accuracy, place of birth, coordinates and time zone needed for calculations;
- for an entity, name, type, relationship, description and optional formation date.
Spreads and orders
- selected scope, profiles and snapshots used for a spread;
- cards, positions, interpretation, engine version, contextual data and spread history;
- for Reader orders, the question, context, selected reader, notes, photograph of the physical spread, statuses and deadlines.
Payments and accounting
- order number, amount, currency, payment status, Stripe/WooCommerce identifiers and sales-document details;
- the Controller does not receive the full card number, CVC or online-banking credentials.
Technical and support data
- IP address, browser and device type, logs, timestamps, cookies and local identifiers;
- support, complaint and correspondence content;
- security signals processed through Cloudflare Turnstile.
4. Data sources
Data is obtained from the User, automatically from the device and Application, from Google or Apple when social sign-in is used, from Stripe and WooCommerce in connection with payment and from the assigned Tarot Reader during order fulfilment.
Where a User adds another person's information, the User is the source. The Controller does not automatically contact that person and relies on the User's representation that a lawful basis exists.
5. Purposes and legal bases
Providing information needed for an Account, purchase and service is voluntary but necessary for performance. Optional information is not a condition of basic use.
| Purpose | Legal basis |
|---|
| Account creation, authentication, profiles, spread preparation and storage, orders and Subscriptions | Article 6(1)(b) GDPR – contract performance or steps before contract |
| payments, invoices, accounting, tax duties and required archives | Article 6(1)(c) GDPR – legal obligation |
| security, Turnstile, abuse prevention, logs, access control and protection of claims | Article 6(1)(f) GDPR – legitimate interests |
| support, complaints and dispute handling | Article 6(1)(b), (c) or (f) GDPR depending on the matter |
| optional marketing, newsletters, analytics or non-essential cookies if enabled | Article 6(1)(a) GDPR – consent |
| establishment, exercise or defence of legal claims | Article 6(1)(f) GDPR – legitimate interests |
6. Sensitive and third-party information
The Application is not designed to collect special-category data such as detailed health or diagnosis information, religion, sex life, political views or biometric identifiers.
Do not submit identity-document numbers, full medical records, card details or credentials. If unnecessary data is submitted, the Controller may remove it, restrict access or request a new submission.
The User is responsible for the lawfulness of another person's data. Following a justified request, the Controller may restrict or erase such data unless an overriding legal basis requires retention.
7. AstroMatrix™, automation and OpenAI API
Quick Spreads use automated astrological, numerological and contextual calculations together with a language-model service to compose the interpretation. A spread does not produce legal or similarly significant effects; the User always decides whether to use it.
Minimised information needed for a task may be sent to the OpenAI API, including descriptive profile or relationship context, selected cards, a Reader-order question and notes, and a spread photograph where image recognition is used.
The Controller does not send OpenAI full payment details or passwords. Under OpenAI's current business and API terms, API inputs and outputs are not used for model training by default unless the business customer opts in. The Controller does not intend to opt in User content for training.
For Reader Spreads, tools may support drafting or card recognition, but the final interpretation is reviewed and delivered by the assigned experienced Tarot Reader.
8. Tarot Reader access
The selected Tarot Reader receives information necessary for the assigned paid order: the question, context, names or descriptions of selected people, photographs, birth details used in the order and entity information.
The Tarot Reader does not receive passwords, full payment details, other readers' orders or technical coordinates and engine data not required for performance.
Access is restricted by role and order assignment. Tarot Readers are bound by confidentiality and the Operator's cooperation rules.
9. Recipients
- hosting, email, system administration, backup and IT-support providers;
- WordPress and WooCommerce as elements of the Application infrastructure;
- Stripe for payments, Subscriptions, refunds and fraud prevention;
- OpenAI for API services supporting content generation and analysis;
- Cloudflare for Turnstile and form-abuse prevention;
- Google and Apple where the User chooses social sign-in;
- OpenStreetMap/Nominatim for searching and geocoding a place name entered by the User;
- the selected Tarot Reader solely for the assigned order;
- accountants, legal advisers, insurers and public authorities where access is legally required or necessary to protect claims.
10. Transfers outside the EEA
Some technology providers may process data outside the European Economic Area. In that case the Controller relies on a transfer mechanism permitted by the GDPR, such as an adequacy decision, standard contractual clauses or an applicable certification framework, and applies additional safeguards where required.
Information about the current mechanism used by a particular provider is available in that provider's privacy documentation or upon request to the Controller.
11. Retention
Periods may be shortened when data is no longer needed or extended where required by law, proceedings, a complaint, security or defence of claims.
| Category | Period or criterion |
|---|
| Account, profiles and saved spreads | while the Account is active and, after deletion is requested, until the deletion and backup cycle is completed, except for records required by law or needed for claims |
| Reader orders, questions, interpretations and spread photographs | for performance, complaints and the applicable limitation period; unnecessary data is then erased or anonymised |
| unpaid or abandoned orders | normally up to 30 days unless longer retention is needed for security or payment investigation |
| accounting and tax records | for the period required by tax and accounting law, generally five years calculated under the applicable rules |
| technical and security logs | normally 30–90 days, longer only for an incident or claim |
| correspondence and complaints | until the matter is closed and then for the applicable claim period |
| Nominatim place-search cache | up to 30 days |
| consent-based data | until consent is withdrawn or the purpose ends earlier |
12. Cookies, local storage and Turnstile
The Website and Application use technologies necessary for authentication, session maintenance, language selection, cart functions, security and saved preferences. Some functions cannot operate without them.
Cloudflare Turnstile analyses technical browser and interaction signals to distinguish a human request from automated abuse. Data is sent to Cloudflare under that service's privacy terms.
Non-essential analytics or marketing cookies may be used only after the required consent. The Cookie Policy provides the current details and technology list.
13. Data-subject rights
Requests may be sent to admin@astrotarotonline.com. The Controller may request information needed to verify identity and protect the Account.
- access to personal data and a copy;
- rectification;
- erasure where the legal conditions are met;
- restriction of processing;
- data portability for data processed automatically on consent or contract;
- objection to processing based on legitimate interests;
- withdrawal of consent at any time without affecting earlier lawful processing;
- a complaint to the President of the Polish Personal Data Protection Office (UODO) or another competent supervisory authority.
14. No legally significant automated decisions
The Application may automatically select and arrange elements of a Quick Spread, but it does not make decisions about the User producing legal or similarly significant effects.
A spread is symbolic information. The User decides whether and how to use it.
15. Security
The Controller applies organisational and technical measures appropriate to risk, including role-based access, private file storage, request validation, encrypted secrets, backups, security logging and limiting Tarot Reader access to assigned orders.
No system provides absolute security. Users should protect passwords, devices and email accounts and promptly report suspicious events.
16. Account deletion
The User may start Account deletion in the Application or send a request to the Controller. Before deletion, needed spreads should be downloaded and active orders and renewals reviewed.
Operational data no longer needed is erased. Payment, accounting, evidence and dispute records may remain for legally required or claim periods with restricted access.
17. Minors
The services are intended for adults. The Controller does not intend to knowingly collect data from persons using the Application as Users before age 18.
Where credible information indicates that a minor created an Account, the Controller may block it and take steps to erase data subject to legal duties.
18. Policy changes
This Policy may be updated because of legal, provider, function or processing changes. The update date appears at the beginning.
Material changes affecting an active Account will be communicated in the Application or by email where appropriate.