Privacy Policy
Last updated: 19 July 2026
1. Who we are
The controller of the personal data described in this policy is SIA EASYMAT, registration number 40203221390, Brīvības gatve 397-33, Rīga, LV-1024, Latvia. You can contact us at [email protected].
This policy explains how we process personal data when you use leyaaitarot.com, complete the website reading quiz, receive transactional email, opt in to limited email offers, access your passwordless reading library, order a clarification, make a payment through Stripe, or contact support.
2. Data we collect
- Website and technical data: IP address, browser, device, user agent, page URL, referrer, approximate country, security logs and server logs.
- Advertising and analytics data: UTM parameters, campaign IDs, ad IDs, placement, fbclid, Meta browser identifiers such as fbp and fbc where available and permitted.
- Service data: your name and email address, selected cards, topic, question, optional context, clarification questions, secure visit/session identifiers, reading status, library links and delivery events.
- Optional email marketing data: the consent text version, source and timestamp, follow-up delivery status, and any later withdrawal or unsubscribe event. Your question and reading text are not included in marketing email.
- Payment data: payment status, order information and transaction references processed through Stripe. We do not store full card details.
- Support data: messages you send to us by email or another support channel we make available.
3. Why we use the data
- To provide the requested entertainment/self-reflection reading, any clarification you order, your private reading library and related communication.
- To process payments, refunds and customer support requests.
- To send transactional email confirming that we received your question and notifying you when the reading is ready.
- If you explicitly choose it on the quiz contact step or private result page, to send occasional Lea Tarot offers and useful materials. The current automated follow-up for one reading contains no more than two emails. You can unsubscribe at any time without affecting service email.
- To measure product usage and advertising performance, including PostHog Cloud EU, Meta Pixel and Meta Conversions API, only where consent and applicable law allow it.
- To protect the website, prevent abuse and keep records required for legal, tax and accounting reasons.
4. Legal bases
- Contract: to deliver the reading and handle related service communication.
- Consent: for optional sales follow-up email, non-essential cookies, marketing tracking and similar technologies where required. Email consent is collected separately from cookie and advertising consent.
- Legitimate interests: to secure the service, prevent abuse and understand basic performance.
- Legal obligation: to keep required payment, tax and accounting records.
5. Service providers
We may use service providers including Resend for transactional email and separately consented follow-up email, Stripe for payments, PostHog Cloud EU for consented product analytics and privacy-protected session replay on public landing pages, Meta Platforms for consented Pixel and Conversions API measurement, Cloudflare for security and delivery, Google Fonts for typography, hosting providers for server infrastructure, and internal admin notification tools. These providers process data under their own terms and privacy practices.
Some providers may process data outside the EEA. Where this happens, we use a transfer mechanism recognised by applicable data-protection law, such as an adequacy decision or appropriate safeguards, where required.
6. Retention
- Free reading photo, short audio and transcript: available in the library for 30 days after submission.
- Paid PDF, its related photo, audio and transcript, and paid clarification results: available until you remove that reading from the library. Removing it hides the entry and revokes its result links; it is not an account-level erasure request.
- Passwordless library links expire after 15 minutes and are single-use. Library sessions expire after 30 days unless you sign out or revoke them sooner.
- Questions, reading requests, transactional email status and other service records: retained only as long as reasonably necessary to deliver and support the service, prevent abuse, resolve disputes and meet legal obligations. You may request deletion earlier where no legal exception applies.
- Email marketing consent and withdrawal records: retained as needed to honour your current preference and demonstrate when consent was given or withdrawn. Pending sales follow-ups are cancelled immediately after a purchase or unsubscribe.
- Consented product analytics, pseudonymous usage events and privacy-masked landing-page replay: according to the shortest retention configured in PostHog Cloud EU and only for as long as needed to improve the service.
- Advertising identifiers, UTM parameters and campaign attribution data: up to 180 days.
- Payment, refund and accounting records: for the period required by applicable tax and accounting law.
7. Your rights
If you are in the EEA/UK, you may request access, correction, deletion, restriction, portability, or object to processing. You may withdraw consent at any time where processing is based on consent; this does not affect processing before withdrawal.
You can withdraw optional email marketing consent using the unsubscribe link in every sales email or from the private result page. To exercise your other rights, email [email protected]. You may also lodge a complaint with your local data-protection authority; in Latvia, this is the Data State Inspectorate.
8. Age limit
Our service is intended for adults aged 18 or older. We do not knowingly provide readings to minors.