Legal information

Privacy Policy

Learn how Star Decide collects, uses, and protects your personal information.

Last updated November 3, 2024

Introduction

Welcome to Star Decide. We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our astrology application and related services.

By using Star Decide, you agree to the collection and use of information in accordance with this policy. This Privacy Policy is designed to comply with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.

Information We Collect

Personal Information

We may collect personal information that can be used to identify you, including:

  • Name and email address
  • Date of birth, time, and place of birth
  • Profile information and preferences
  • Payment information (processed securely through third-party providers)
  • Communication preferences

Usage Data

We automatically collect information about how you use our services:

  • Feature usage and interaction patterns
  • Session duration and frequency
  • Device information and operating system
  • IP address and general location information
  • Performance data and error reports

Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience, analyze usage, and provide personalized content. You can control cookie settings through your browser preferences.

How We Use Your Information

We use your information to:

  • Provide and maintain our astrology services
  • Generate personalized horoscopes and astrological insights
  • Create and manage your natal chart
  • Process transactions and send payment confirmations
  • Communicate with you about your account and services
  • Improve our services and develop new features
  • Analyze usage patterns to optimize user experience
  • Ensure platform security and prevent fraud
  • Comply with legal obligations

Data Sharing and Disclosure

We may share your information in the following circumstances:

  • Service Providers: With trusted third-party service providers who assist in operating our services
  • Payment Processing: With payment processors to handle transactions securely
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with mergers, acquisitions, or asset sales
  • Aggregate Data: We may share anonymized, aggregated data for research and analytics

Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the internet is 100% secure.

Data Retention

We retain your personal information only as long as necessary to provide our services and comply with legal obligations. Specific retention periods include:

  • Account Information: Retained until account deletion unless required for legal purposes
  • Birth Data & Astrological Readings: Retained for the duration of your account to provide personalized services
  • Transaction Records: Retained for 7 years to comply with tax and accounting requirements
  • Communications: Retained for 2 years unless related to legal matters
  • Usage Analytics: Retained in anonymized form for 2 years for service improvement
  • Security Logs: Retained for 90 days for security monitoring, extended to 1 year if related to incidents

You can request deletion of your account and associated data at any time. Upon deletion, all personal data will be permanently removed within 30 days, except where retention is required by law.

Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

Right to Access

You have the right to request access to your personal information. We will provide a copy of your personal data in a commonly used electronic format within 30 days of your request. You can access your information through your account settings or by contacting us directly.

Right to Rectification

You have the right to request correction of inaccurate personal information. Through your account settings, you can update most personal information. For corrections that cannot be made through the interface, please contact us directly.

Right to Erasure (Right to be Forgotten)

You have the right to request deletion of your personal information. We will process deletion requests within 30 days, except where we are required to retain data for legal, regulatory, or legitimate business purposes. Once deleted, your data cannot be recovered.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format. You also have the right to transfer this data to another controller without hindrance.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests, including profiling. We will stop processing your data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Right to Restrict Processing

You have the right to request restriction of processing your personal data in certain circumstances, such as when you contest the accuracy of the data or when the processing is unlawful.

How to Exercise Your Rights

To exercise any of these rights, please contact us using the information provided in the "Contact Us" section. We will respond to your request within 30 days in accordance with GDPR requirements.

International Data Transfers

Your information may be transferred to and processed in countries other than your own, including countries outside the European Economic Area (EEA). We ensure appropriate safeguards are in place to protect your data in accordance with applicable data protection laws, including:

  • Standard Contractual Clauses (SCCs): We use European Commission-approved standard contractual clauses for transfers outside the EEA
  • Adequacy Decisions: Transfers to countries recognized by the EU as providing adequate data protection
  • Technical and Organizational Measures: Encryption, access controls, and other security measures to protect data during transfer and storage

You have the right to obtain a copy of the safeguards used for international data transfers by contacting us using the information in the "Contact Us" section.

Data Protection Officer

In compliance with GDPR, we have appointed a Data Protection Officer (DPO) to oversee our data protection activities. Our DPO is responsible for:

  • Monitoring compliance with GDPR and data protection regulations
  • Advising on our data protection obligations
  • Cooperating with supervisory authorities
  • Serving as the contact point for data subjects on data protection matters

You can contact our Data Protection Officer at: [email protected]

Children's Privacy (COPPA & GDPR)

We are committed to protecting the privacy of children and comply with the Children's Online Privacy Protection Act (COPPA) and GDPR requirements for children's data protection.

Age Verification

Our services are not intended for children under 13 years of age. We implement reasonable measures to verify the age of our users, including:

  • Explicit age confirmation during registration
  • Birth date collection and validation
  • Clear warnings about age requirements
  • Account termination for users who misrepresent their age

We do not knowingly collect personal information from children under 13. If we discover that we have collected such information, we will take immediate steps to delete it.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and, where feasible, not later than 72 hours after having become aware of it.

Our breach notification will include:

  • Description of the nature of the breach
  • Name and contact details of our data protection officer
  • Likely consequences of the breach
  • Measures we have taken or propose to take to address the breach
  • Recommendations for how you can protect yourself

EU Representative

For users in the European Union, we have appointed an EU-based representative to facilitate communication with EU data protection authorities and data subjects.

EU Representative Contact:
Email: [email protected]
Address: 123 GDPR Compliance Street, Dublin 2, Ireland

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us using one of the following methods:

General Privacy Inquiries: [email protected]

Data Protection Officer: [email protected]

Children's Privacy (COPPA): [email protected]

EU Representative: [email protected]

In-App Support: Through our in-app support feature

Contact Form: Via the contact form in your profile settings

Exercise Your Rights:

To exercise any of your GDPR rights, please include "GDPR Rights Request" in your email subject line and specify the right you wish to exercise. We will respond to all requests within 30 days as required by law.

Need help or have questions? Our support team can assist.