Privacy
Privacy policy
This policy describes how My Astro Year (myastroyear.com) and our personal yearly astrology reading handle your data. We aim to be transparent about what we collect, why, how long we keep it, and what rights you have under the GDPR (EU 2016/679) and applicable privacy laws.
Last updated: July 13, 2026
1. Data controller
Controller: the operator of My Astro Year ("Controller"), reachable via the contact form at myastroyear.com and info.uzeneted@gmail.com.
The Controller is responsible for processing your personal data lawfully, fairly, and transparently.
2. What personal data we collect
We may collect data in the categories below. We don't collect everything from every visitor — only what you provide or what's technically necessary to run the service.
Quiz and order (to prepare your reading)
- Name
- Email address
- Birth date
- Birth time (or an indication that it's unknown)
- Birth place (as text)
- Quiz answers (e.g. focus area, life situation, challenges, optional personal note up to 500 characters)
- Gender selection (quiz option)
Payment and order fulfillment
Card details are handled directly by Stripe; we don't store full card numbers or CVC codes.
- Email address (Stripe checkout and invoicing)
- Stripe transaction IDs (session ID, payment intent ID, amount, currency, timestamp)
- Order status, download token and expiry
- Generated reading text and PDF (to deliver the service)
Contact and support
- Name, email address, and message text (contact form)
- Correspondence created during support
Marketing / reminder emails (only where permitted)
Promotional emails are sent only where we have a valid legal basis. You can unsubscribe from any such email.
- Email address and name (e.g. abandoned checkout or promo reminder, if sent)
- Promo email status (sent / failed)
Ad measurement and traffic source (optional)
Traffic source data is stored in browser sessionStorage until the quiz starts; it may be linked to your order and reading.
- UTM parameters (source, medium, campaign, etc.)
- Click IDs (e.g. fbclid, gclid)
- Referrer and entry path
- Meta (Facebook) Pixel events — if the pixel is enabled
Technical logs
- IP address, browser and device data (hosting provider logs)
- Server and error logs for operation and security
3. Purpose and legal basis
Each type of processing has a defined purpose and legal basis under GDPR Article 6:
Preparing and delivering your personalized reading — contract performance [Art. 6(1)(b)]
Processing payment, invoicing, and purchase records — contract performance and legal obligation [Art. 6(1)(b), (c)]
Email delivery and download links — contract performance [Art. 6(1)(b)]
Customer support, complaints, guarantee, and refunds — contract performance / legitimate interest [Art. 6(1)(b), (f)]
Abandoned checkout / promo reminders — legitimate interest or consent, depending on the email type [Art. 6(1)(a) or (f)]; unsubscribe anytime
Site operation, security, and troubleshooting — legitimate interest [Art. 6(1)(f)]
Ad campaign measurement (Meta Pixel, UTM) — legitimate interest or consent, depending on settings [Art. 6(1)(a) or (f)]
4. Processors and data transfers
We use trusted processors to run the service. They access data only on our instructions and only as needed to provide the service.
Some providers may host servers outside the European Economic Area (e.g. the United States). Transfers are typically based on Standard Contractual Clauses (SCCs) or the provider's GDPR compliance framework.
Vercel
- Purpose: hosting, CDN
- Data: technical logs, IP address, request metadata
Supabase
- Purpose: database and backend storage (quiz, purchases, readings, contact messages)
- Data: stored data listed in section 2
Stripe
- Purpose: online payment and transaction handling
- Data: email, transaction details (Stripe handles card data)
Replicate
- Purpose: AI text generation (personal reading)
- Data: prompt with quiz and birth details in summary form
Mailgun / SMTP
- Purpose: transactional and promotional email
- Data: recipient email, name, subject, body, PDF attachment
Meta Platforms (Facebook Pixel) — if enabled
- Purpose: ad measurement and conversion tracking
- Data: pixel events, cookies, device and browser data
5. How long we keep data
We don't keep data longer than necessary. Typical retention periods:
Ordered reading, quiz answers, and purchase data: for contract fulfillment, then as required for accounting and tax (often up to 8 years for invoice-related data), or while a legal claim or support case is open
Download link (token): 7 days from creation — then the link expires; the reading remains available by email
Contact messages: up to 2 years after the case is closed, unless law requires longer
Promo / checkout recovery records: usually up to 2 years
Server logs: typically 30–90 days, depending on the host
6. Automated processing
We use automated systems to prepare your reading: code-based astrology calculations, then AI for wording. This is not automated decision-making with legal effect under GDPR Article 22 — we don't approve, deny, or make binding decisions about you solely by automation.
7. Your rights
Under the GDPR, you may have the following rights (where applicable):
To exercise your rights, contact us via the Contact page or info.uzeneted@gmail.com. We may ask you to verify your identity. We usually respond within 30 days.
You may also lodge a complaint with your local data protection authority.
- Access — ask whether we process your data and what data we hold
- Rectification — request correction of inaccurate data (e.g. a mistyped email)
- Erasure — request deletion where we no longer have a legal basis to keep data
- Restriction — request that we limit processing in certain cases
- Portability — request your provided data in a structured, machine-readable format
- Objection — object to processing based on legitimate interest; for marketing, anytime
- Withdraw consent — where processing is consent-based (doesn't affect prior lawful processing)
8. Security
We use appropriate technical and organizational measures (HTTPS, access controls, secure credentials, trusted providers). No online service can guarantee absolute security.
9. Cookies and local storage
We use technical tools needed for the site to work.
You can limit or delete cookies in your browser; some features (e.g. payment) may not work correctly without them.
- sessionStorage: temporary UTM/traffic source data during the quiz — not cookies; cleared when the session ends
- Meta (Facebook) Pixel: marketing cookies/identifiers if active — governed by Meta's policy
- Stripe: may use its own cookies on the checkout page for fraud prevention
10. Minors
The service is intended for people 18 and older. We don't knowingly collect data from anyone under 16. If we learn we have, we'll delete it.
11. Changes to this policy
We may update this policy (e.g. new features, processors, or legal changes). The date at the top shows when it was last revised. For significant changes, we may provide additional notice where required.
12. Privacy contact
For privacy questions, rights requests, or deletion requests, contact us via the Contact page or info.uzeneted@gmail.com. We'll respond within a reasonable time and no later than 30 days.
Have a question? Contact us