← Back to home

Privacy

Privacy policy

This policy describes how My Astro Year (myastroyear.com) and our personal yearly astrology reading handle your data. We aim to be transparent about what we collect, why, how long we keep it, and what rights you have under the GDPR (EU 2016/679) and applicable privacy laws.

Last updated: July 13, 2026

1. Data controller

Controller: the operator of My Astro Year ("Controller"), reachable via the contact form at myastroyear.com and info.uzeneted@gmail.com.

The Controller is responsible for processing your personal data lawfully, fairly, and transparently.

2. What personal data we collect

We may collect data in the categories below. We don't collect everything from every visitor — only what you provide or what's technically necessary to run the service.

Quiz and order (to prepare your reading)

  • Name
  • Email address
  • Birth date
  • Birth time (or an indication that it's unknown)
  • Birth place (as text)
  • Quiz answers (e.g. focus area, life situation, challenges, optional personal note up to 500 characters)
  • Gender selection (quiz option)

Payment and order fulfillment

Card details are handled directly by Stripe; we don't store full card numbers or CVC codes.

  • Email address (Stripe checkout and invoicing)
  • Stripe transaction IDs (session ID, payment intent ID, amount, currency, timestamp)
  • Order status, download token and expiry
  • Generated reading text and PDF (to deliver the service)

Contact and support

  • Name, email address, and message text (contact form)
  • Correspondence created during support

Marketing / reminder emails (only where permitted)

Promotional emails are sent only where we have a valid legal basis. You can unsubscribe from any such email.

  • Email address and name (e.g. abandoned checkout or promo reminder, if sent)
  • Promo email status (sent / failed)

Ad measurement and traffic source (optional)

Traffic source data is stored in browser sessionStorage until the quiz starts; it may be linked to your order and reading.

  • UTM parameters (source, medium, campaign, etc.)
  • Click IDs (e.g. fbclid, gclid)
  • Referrer and entry path
  • Meta (Facebook) Pixel events — if the pixel is enabled

Technical logs

  • IP address, browser and device data (hosting provider logs)
  • Server and error logs for operation and security

3. Purpose and legal basis

Each type of processing has a defined purpose and legal basis under GDPR Article 6:

Preparing and delivering your personalized reading — contract performance [Art. 6(1)(b)]

Processing payment, invoicing, and purchase records — contract performance and legal obligation [Art. 6(1)(b), (c)]

Email delivery and download links — contract performance [Art. 6(1)(b)]

Customer support, complaints, guarantee, and refunds — contract performance / legitimate interest [Art. 6(1)(b), (f)]

Abandoned checkout / promo reminders — legitimate interest or consent, depending on the email type [Art. 6(1)(a) or (f)]; unsubscribe anytime

Site operation, security, and troubleshooting — legitimate interest [Art. 6(1)(f)]

Ad campaign measurement (Meta Pixel, UTM) — legitimate interest or consent, depending on settings [Art. 6(1)(a) or (f)]

4. Processors and data transfers

We use trusted processors to run the service. They access data only on our instructions and only as needed to provide the service.

Some providers may host servers outside the European Economic Area (e.g. the United States). Transfers are typically based on Standard Contractual Clauses (SCCs) or the provider's GDPR compliance framework.

Vercel

  • Purpose: hosting, CDN
  • Data: technical logs, IP address, request metadata

Supabase

  • Purpose: database and backend storage (quiz, purchases, readings, contact messages)
  • Data: stored data listed in section 2

Stripe

  • Purpose: online payment and transaction handling
  • Data: email, transaction details (Stripe handles card data)

Replicate

  • Purpose: AI text generation (personal reading)
  • Data: prompt with quiz and birth details in summary form

Mailgun / SMTP

  • Purpose: transactional and promotional email
  • Data: recipient email, name, subject, body, PDF attachment

Meta Platforms (Facebook Pixel) — if enabled

  • Purpose: ad measurement and conversion tracking
  • Data: pixel events, cookies, device and browser data

5. How long we keep data

We don't keep data longer than necessary. Typical retention periods:

Ordered reading, quiz answers, and purchase data: for contract fulfillment, then as required for accounting and tax (often up to 8 years for invoice-related data), or while a legal claim or support case is open

Download link (token): 7 days from creation — then the link expires; the reading remains available by email

Contact messages: up to 2 years after the case is closed, unless law requires longer

Promo / checkout recovery records: usually up to 2 years

Server logs: typically 30–90 days, depending on the host

6. Automated processing

We use automated systems to prepare your reading: code-based astrology calculations, then AI for wording. This is not automated decision-making with legal effect under GDPR Article 22 — we don't approve, deny, or make binding decisions about you solely by automation.

7. Your rights

Under the GDPR, you may have the following rights (where applicable):

To exercise your rights, contact us via the Contact page or info.uzeneted@gmail.com. We may ask you to verify your identity. We usually respond within 30 days.

You may also lodge a complaint with your local data protection authority.

  • Access — ask whether we process your data and what data we hold
  • Rectification — request correction of inaccurate data (e.g. a mistyped email)
  • Erasure — request deletion where we no longer have a legal basis to keep data
  • Restriction — request that we limit processing in certain cases
  • Portability — request your provided data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interest; for marketing, anytime
  • Withdraw consent — where processing is consent-based (doesn't affect prior lawful processing)

8. Security

We use appropriate technical and organizational measures (HTTPS, access controls, secure credentials, trusted providers). No online service can guarantee absolute security.

9. Cookies and local storage

We use technical tools needed for the site to work.

You can limit or delete cookies in your browser; some features (e.g. payment) may not work correctly without them.

  • sessionStorage: temporary UTM/traffic source data during the quiz — not cookies; cleared when the session ends
  • Meta (Facebook) Pixel: marketing cookies/identifiers if active — governed by Meta's policy
  • Stripe: may use its own cookies on the checkout page for fraud prevention

10. Minors

The service is intended for people 18 and older. We don't knowingly collect data from anyone under 16. If we learn we have, we'll delete it.

11. Changes to this policy

We may update this policy (e.g. new features, processors, or legal changes). The date at the top shows when it was last revised. For significant changes, we may provide additional notice where required.

12. Privacy contact

For privacy questions, rights requests, or deletion requests, contact us via the Contact page or info.uzeneted@gmail.com. We'll respond within a reasonable time and no later than 30 days.

Have a question? Contact us