August 8, 2026
Privacy Policy
1. Data Controller
The personal data controller is Crystal Processing Karol Mróz, ul. 3-go Maja 40 lok. 25, 07-300 Ostrów Mazowiecka, NIP: 7591754851, REGON: 521179100. Contact email: kontakt@mystic-tarot.pl.
For personal data matters, contact the provider by email. A data protection officer has not been appointed unless later indicated separately in the service.
2. Data We Process
We process data provided by the user: email address, question or intention for the spread, accepted consents, account data, name if provided, and selected language.
We process data generated by the service: selected cards, order status, payment status, Stripe payment identifier, spread identifier, generated interpretation, and order creation and completion dates.
We process technical and security data: IP address, user-agent, request headers, server logs, Cloudflare Turnstile anti-bot information, and basic session or login data.
We do not store full payment-card data or bank login data. Payments are processed by Stripe.
3. Purposes and Legal Bases
Free spread, order acceptance, payment, and interpretation delivery: Article 6(1)(b) GDPR, performance of a contract or steps before entering into a contract.
Account and reading history: Article 6(1)(b) GDPR.
Settlements, accounting, and tax obligations: Article 6(1)(c) GDPR.
Complaints, establishment, exercise or defence of claims, abuse prevention, and service security: Article 6(1)(f) GDPR, the controller's legitimate interest.
Order-related and user-support email communication: Article 6(1)(b) or 6(1)(f) GDPR. Direct marketing will be used only if an appropriate consent or other lawful basis is implemented.
4. AI and Automatic Generation of Interpretations
The interpretation is generated automatically using an AI provider based on the question or intention, language, and selected cards.
This generation is not automated decision-making producing legal effects or similarly significant effects for the user. The user receives entertainment and reflective content and decides independently whether to use it.
The user should not enter special-category data, such as detailed health data, sexual-life data, political opinions, religion, or third-party data. If the user nevertheless provides such data, it will be used only to generate and handle the ordered interpretation.
5. Recipients and Providers
Data may be entrusted or disclosed to the following categories of recipients: hosting and server infrastructure, PostgreSQL, Stripe, Anthropic, Cloudflare Turnstile, Brevo SMTP, Google OAuth, IT support, accounting, and legal support providers.
Data may be disclosed to public authorities only when required by law or a valid request from an authorized authority.
6. Transfers Outside the EEA
Some technology providers, especially payment, AI, security, or login providers, may process data outside the European Economic Area.
In such cases, appropriate safeguards are used, such as standard contractual clauses, adequacy decisions, or other mechanisms provided by the GDPR. Details may be requested by email.
7. Retention Period
Order, payment, and accounting data is kept for the period required by tax and accounting law, generally 5 years from the end of the tax year in which the obligation arose.
Complaint and claims data is kept for the duration of the matter and the limitation period for claims.
Account data is kept until account deletion unless further retention is needed for legal, settlement, security, or claims reasons.
Security logs are kept for the period needed to protect the service and analyze incidents, usually no longer than 12 months unless a specific incident requires longer retention.
8. User Rights
The user has the right to access data, receive a copy, rectify, erase, restrict processing, data portability, object to processing based on legitimate interest, and withdraw consent where processing is based on consent.
The user has the right to lodge a complaint with a competent supervisory authority.
Data requests should be sent to the controller's email. The controller may ask for additional information needed to confirm the identity of the requester.
9. Voluntary Provision of Data
Providing data is voluntary, but without an email address it is impossible to place an order and send confirmation of the contract and interpretation.
Not providing account data prevents account creation, but does not block the purchase itself if guest checkout is available.
10. Security
We use technical and organizational measures appropriate to the risk, including encrypted transmission in production, access control, rate limiting, anti-bot protection, security headers, error monitoring, and restricted administrative access.
No internet solution provides an absolute security guarantee, so the user should protect their password, email, and device.