Privacy Policy
Learn how Star Decide collects, uses, and protects your personal information.
Introduction
Welcome to Star Decide. We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our astrology application and related services.
By using Star Decide, you agree to the collection and use of information in accordance with this policy. This Privacy Policy is designed to comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
Information We Collect
Personal Information
We may collect personal information that can be used to identify you, including:
- Name and email address
- Date of birth, time, and place of birth
- Profile information and preferences
- Payment information (processed securely through third-party providers)
- Communication preferences
Usage Data
We automatically collect information about how you use our services:
- Feature usage and interaction patterns
- Session duration and frequency
- Device information and operating system
- IP address and general location information
- Performance data and error reports
Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience, analyze usage, and provide personalized content. You can control cookie settings through your browser preferences.
How We Use Your Information
We use your information to:
- Provide and maintain our astrology services
- Generate personalized horoscopes and astrological insights
- Create and manage your natal chart
- Process transactions and send payment confirmations
- Communicate with you about your account and services
- Improve our services and develop new features
- Analyze usage patterns to optimize user experience
- Ensure platform security and prevent fraud
- Comply with legal obligations
Legal Basis for Processing (GDPR)
Under GDPR, we must have a valid legal basis for processing your personal data. Our legal bases depend on the specific processing activity:
Consent
We process some of your personal data based on your explicit consent, which you can withdraw at any time. This includes:
- Marketing communications and promotional content
- Cookies and tracking technologies for analytics
- Data sharing with third parties for personalized experiences
Withdrawing consent will not affect the lawfulness of processing based on consent before its withdrawal.
Contractual Necessity
Processing is necessary for the performance of our contract with you, including:
- Creating and managing your user account
- Providing personalized astrological readings and services
- Processing subscription payments
- Delivering the core features you have requested
Legitimate Interests
We may process your data when we have a legitimate interest that is not overridden by your rights and interests, including:
- Analyzing usage patterns to improve our services
- Preventing fraudulent activities and ensuring platform security
- Conducting analytics and research to develop new features
- Network and information security
Data Sharing and Disclosure
We may share your information in the following circumstances:
- Service Providers: With trusted third-party service providers who assist in operating our services
- Payment Processing: With payment processors to handle transactions securely
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In connection with mergers, acquisitions, or asset sales
- Aggregate Data: We may share anonymized, aggregated data for research and analytics
Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the internet is 100% secure.
Data Retention
We retain your personal information only as long as necessary to provide our services and comply with legal obligations. Specific retention periods include:
- Account Information: Retained until account deletion unless required for legal purposes
- Birth Data & Astrological Readings: Retained for the duration of your account to provide personalized services
- Transaction Records: Retained for 7 years to comply with tax and accounting requirements
- Communications: Retained for 2 years unless related to legal matters
- Usage Analytics: Retained in anonymized form for 2 years for service improvement
- Security Logs: Retained for 90 days for security monitoring, extended to 1 year if related to incidents
You can request deletion of your account and associated data at any time. Upon deletion, all personal data will be permanently removed within 30 days, except where retention is required by law.
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
Right to Access
You have the right to request access to your personal information. We will provide a copy of your personal data in a commonly used electronic format within 30 days of your request. You can access your information through your account settings or by contacting us directly.
Right to Rectification
You have the right to request correction of inaccurate personal information. Through your account settings, you can update most personal information. For corrections that cannot be made through the interface, please contact us directly.
Right to Erasure (Right to be Forgotten)
You have the right to request deletion of your personal information. We will process deletion requests within 30 days, except where we are required to retain data for legal, regulatory, or legitimate business purposes. Once deleted, your data cannot be recovered.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format. You also have the right to transfer this data to another controller without hindrance.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests, including profiling. We will stop processing your data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
Right to Restrict Processing
You have the right to request restriction of processing your personal data in certain circumstances, such as when you contest the accuracy of the data or when the processing is unlawful.
How to Exercise Your Rights
To exercise any of these rights, please contact us using the information provided in the "Contact Us" section. We will respond to your request within 30 days in accordance with GDPR requirements.
International Data Transfers
Your information may be transferred to and processed in countries other than your own, including countries outside the European Economic Area (EEA). We ensure appropriate safeguards are in place to protect your data in accordance with applicable data protection laws, including:
- Standard Contractual Clauses (SCCs): We use European Commission-approved standard contractual clauses for transfers outside the EEA
- Adequacy Decisions: Transfers to countries recognized by the EU as providing adequate data protection
- Technical and Organizational Measures: Encryption, access controls, and other security measures to protect data during transfer and storage
You have the right to obtain a copy of the safeguards used for international data transfers by contacting us using the information in the "Contact Us" section.
Data Protection Officer
In compliance with GDPR, we have appointed a Data Protection Officer (DPO) to oversee our data protection activities. Our DPO is responsible for:
- Monitoring compliance with GDPR and data protection regulations
- Advising on our data protection obligations
- Cooperating with supervisory authorities
- Serving as the contact point for data subjects on data protection matters
You can contact our Data Protection Officer at: [email protected]
Children's Privacy (COPPA & GDPR)
We are committed to protecting the privacy of children and comply with the Children's Online Privacy Protection Act (COPPA) and GDPR requirements for children's data protection.
Age Verification
Our services are not intended for children under 13 years of age. We implement reasonable measures to verify the age of our users, including:
- Explicit age confirmation during registration
- Birth date collection and validation
- Clear warnings about age requirements
- Account termination for users who misrepresent their age
We do not knowingly collect personal information from children under 13. If we discover that we have collected such information, we will take immediate steps to delete it.
Parental Consent
If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us immediately. We will:
- Acknowledge receipt of your parental rights request within 5 business days
- Delete the child's personal information within 10 business days
- Provide confirmation of the deletion
- Take steps to prevent future collection from the same child
Parents and guardians can contact us regarding children's privacy matters at: [email protected]
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and, where feasible, not later than 72 hours after having become aware of it.
Our breach notification will include:
- Description of the nature of the breach
- Name and contact details of our data protection officer
- Likely consequences of the breach
- Measures we have taken or propose to take to address the breach
- Recommendations for how you can protect yourself
EU Representative
For users in the European Union, we have appointed an EU-based representative to facilitate communication with EU data protection authorities and data subjects.
EU Representative Contact:
Email: [email protected]
Address: 123 GDPR Compliance Street, Dublin 2, Ireland
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us using one of the following methods:
General Privacy Inquiries: [email protected]
Data Protection Officer: [email protected]
Children's Privacy (COPPA): [email protected]
EU Representative: [email protected]
In-App Support: Through our in-app support feature
Contact Form: Via the contact form in your profile settings
Exercise Your Rights:
To exercise any of your GDPR rights, please include "GDPR Rights Request" in your email subject line and specify the right you wish to exercise. We will respond to all requests within 30 days as required by law.
Need help or have questions? Our support team can assist.