Ownership checks
Users access their own profiles, spreads and orders.
Security & privacy
The product uses account ownership, role permissions, private file delivery and controlled reader access so spreads never appear on public pages or in openly accessible resources.
Core safeguards
No single checkbox makes a private product. The important part is how ownership, files and roles interact.
Users access their own profiles, spreads and orders.
A tarot reader sees only eligible orders assigned to their active persona.
Spread images use private storage and authenticated delivery rather than public gallery URLs.
REST nonces, validation, file type checks and size limits reduce obvious abuse.
Important order, consent and delivery events can be recorded.
The application layer is intended to remain outside search indexing.
Data minimisation
The strongest privacy control is not collecting unnecessary information in the first place.
External processors
Payment providers and WooCommerce process transaction and billing data according to the configured checkout.
An AI API may receive the selected context, cards, meanings and working text required for generation or recognition.
A geocoding provider may receive the place search text used to resolve location details.
E-mail infrastructure processes messages and service notifications.
The operator must maintain current processor terms, access control and retention settings.
The final legal documents must accurately name the operator, purposes, legal bases, recipients and retention.
FAQ
They are designed for a private authenticated flow, not ordinary public media-library exposure.
Administrative access should be limited to what is necessary for service, security and dispute handling.
Not necessarily. Legal, tax, fraud-prevention or dispute records may need to be retained or anonymised for defined periods.
The final production environment should enable strong authentication, especially for tarot-reader and administrator accounts.