EventTarot
Sign inList your services

Legal

Privacy Policy

Last updated: 27 May 2026

1. Who we are

EventTarot (“we”, “us”, “our”) operates the website eventtarot.com. We act as the data controller for personal data collected through this site. Questions about this policy can be directed to hello@eventtarot.com.

2. Data we collect

We collect the following categories of personal data:

  • Account data — email address, display name, and password hash (via Supabase Auth) when you create an account.
  • Reader profile data — bio, city, photo, rates, and other information you add to your public profile.
  • Enquiry data — name, email, phone, and event details submitted through the contact form on a reader's profile.
  • Review data — name, email, rating, and review text submitted through the review form.
  • Payment data — billing is handled by Stripe; we do not store card numbers. We store your Stripe customer ID and subscription status.
  • Usage data — server logs, IP addresses, and page view data collected automatically.

3. How we use your data

  • To create and manage your account and reader profile.
  • To forward booking enquiries to the relevant reader.
  • To send verification emails for reviews.
  • To process subscription payments via Stripe.
  • To send transactional emails related to your account.
  • To improve the platform and detect abuse.

4. Legal basis (UK GDPR / EU GDPR)

We process your data under the following legal bases: contract performance (account creation and subscription management), legitimate interests (fraud prevention, platform security), and consent (marketing communications, where applicable).

5. Data sharing

We share your data with the following third parties: Supabase (database and authentication), Stripe (payment processing), and Resend (transactional email). We do not sell your personal data to any third party.

6. Data retention

Account data is retained while your account is active and for up to 12 months after deletion. Enquiry data is retained for 24 months. You may request deletion at any time by emailing hello@eventtarot.com.

7. Your rights

Under UK GDPR, you have the right to access, rectify, erase, restrict, and port your data, and to object to processing. To exercise any of these rights, contact us at hello@eventtarot.com. You also have the right to lodge a complaint with the ICO (ico.org.uk).

8. Cookies

We use essential session cookies set by Supabase Auth to keep you logged in. We do not use tracking or advertising cookies.

9. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or a notice on the site. Continued use of EventTarot after changes are posted constitutes acceptance.