This statement explains which data we process, on what basis, which parties are involved, and what choices you have. The principle: your readings, notes, and moments of reflection remain yours. Last updated: 4 May 2026.
1. Which data we process
Account data: email address, hashed password, account status, time of creation and last login.
Reading data: the questions you ask, the cast lines, the resulting hexagrams, and any notes and moments of reflection you record.
Subscription data: subscription status, start date, renewal date and a Stripe customer id (no card details — we don't see those).
Technical data: session token, IP address at login (briefly, for security), browser/device info in server logs.
2. Why and on what basis
Performance of the contract (Article 6(1)(b) GDPR): keeping your account working, granting premium access, administering payments, storing and re-showing readings.
Legal obligation (sub c): retention periods for financial data.
Legitimate interest (sub f): debugging, protection against abuse, and improving the service on the basis of aggregated data.
We use no consent cookies for tracking; only functional cookies that are needed to run the service.
3. Sub-processors
We engage the following external parties as processors:
- Supabase (database, authentication) — hosted in the EU.
- Netlify (web hosting and edge routing) — global content delivery; server logic runs in an EU region.
- Stripe (payment processing for the premium subscription) — international, subject to the EU-US Data Privacy Framework.
- Google Workspace (email correspondence via consult@i-ching-practice.com) — international, likewise under the Data Privacy Framework.
With each processor a data processing agreement is or will be concluded, setting out the GDPR requirements.
4. International transfer
Stripe and Google process data partly in the United States. Transfer takes place on the basis of the EU-US Data Privacy Framework or standard contractual clauses (SCCs) approved by the European Commission. Supabase and Netlify host the core data in EU regions.
5. Retention periods
Account and reading data: kept as long as your account is active. On a deletion request: removed within thirty days, except for data we are legally required to keep.
Financial data (Stripe administration): seven years, in line with the tax retention obligation.
Server logs: at most thirty days, for security and debugging.
6. Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interest. Send requests to consult@i-ching-practice.com; we confirm within five business days and handle them within one month.
Do you disagree with how we handle your data? You can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) via autoriteitpersoonsgegevens.nl.
7. Cookies
We place only functional cookies: a session cookie for logged-in access and any preferences (for example the sound setting of the consult). No tracking cookies, no marketing pixels, no third-party analytics cookies. That is why no cookie consent banner is needed.
8. Security
Access to your account is secured via Supabase Auth (hashed passwords). Communication between your browser and our servers always runs over HTTPS. Access to production data is limited to what is strictly necessary for managing and maintaining the service.
9. Changes to this statement
We may amend this privacy statement from time to time, for example for new functionality or a new sub-processor. We announce material changes at least thirty days in advance by email or in the app. The current version is always on this page, with the date of the last update at the top.