Privacy Policy
Here we clearly explain what data we collect, how we use it, and how you can exercise your rights.
We only collect the data strictly necessary to calculate your numerology profile. We never sell or share your personal information with third parties.
1. Data controller
Numerología.io
Contact email: privacy@numerologia.io
For any inquiry related to your personal data or to exercise your rights, you can contact us directly by email.
2. Data we collect
We only collect the data necessary to provide you with the service:
- Full name — used to calculate your numerology numbers (Expression, Soul Urge, and Personality) using the Pythagorean system. Not used for any other purpose.
- Date of birth — used to calculate your Life Path and all your temporal cycles (Personal Year, Personal Month, 52-day cycles). Not used for any other purpose.
- Email address — used for platform authentication and account-related communications (confirmations, reminders, if you enable them).
- Anonymous usage data — technical logs (pages visited, actions taken) to improve the service. Not linked to your identity.
We do not collect postal addresses, phone numbers, or identity documents. Payment data (card numbers, bank details) is processed exclusively by LemonSqueezy, our payment provider, and never passes through our servers.
3. Legal basis for processing
The processing of your personal data is based on:
- Art. 6.1.b GDPR — Performance of a contract: the processing of your name, date of birth, and email is necessary to provide you with the service you have requested (calculation of your numerology profile and access to the platform).
- Art. 6.1.a GDPR — Consent: for sending marketing communications or optional notifications, whenever you have given your explicit consent.
- Art. 6.1.f GDPR — Legitimate interest: for anonymous usage data used to improve service performance and security.
4. Purpose of processing
We use your data exclusively for:
- Calculating and displaying your personal numerology profile
- Generating your personalized daily energy calendar
- Managing your authentication and session on the platform
- Sending you account-related communications (if you have enabled them)
- Improving the service through anonymous technical analysis
We do not use your data for third-party advertising, commercial profiling, or automated decision-making with legal effects.
5. Data retention period
We retain your data as long as your account remains active. If you delete your account, your personal data (name, date of birth, email) will be permanently deleted within a maximum of 30 calendar days.
Anonymous technical logs may be retained for up to 12 months for security and performance analysis purposes.
6. Your rights
As a data subject, you have the following rights over your personal data:
- Access: the right to obtain confirmation of whether we process your data and to receive a copy.
- Rectification: the right to correct inaccurate or incomplete data.
- Erasure (right to be forgotten): the right to request deletion of your data when it is no longer necessary or you withdraw your consent.
- Portability: the right to receive your data in a structured, machine-readable format.
- Objection: the right to object to processing based on legitimate interest.
- Restriction: the right to request that we limit the use of your data under certain circumstances.
You can exercise any of these rights by sending an email to privacy@numerologia.io. We will respond within a maximum of 30 days.
You also have the right to file a complaint with the competent supervisory authority. In Spain: Spanish Data Protection Agency (AEPD).
7. Recipients and international transfers
Your data is processed by the following service providers:
- Supabase (database and authentication) — hosted on AWS EU-West-1 (Ireland), within the European Economic Area. Supabase complies with the GDPR and has adequate safeguards for data transfers.
- Resend (email delivery) — used to send the authentication OTP code and account communications. Only receives your email address, never your name or date of birth.
- LemonSqueezy (payment processing) — acts as Merchant of Record to process subscriptions and one-time payments. Receives your email address and the data necessary to complete the transaction. LemonSqueezy manages tax compliance (VAT) in your country. Their privacy policy is available at lemonsqueezy.com/privacy.
We do not transfer data to countries outside the EEA without adequate safeguards. All providers are contractually obligated to process your data in accordance with the GDPR.
8. Cookies
We only use the strictly necessary technical cookies for the platform to function:
- Session cookies: necessary to maintain your authenticated session on the platform. They cannot be disabled if you wish to use the service.
We do not use tracking, advertising, or third-party analytics cookies (such as Google Analytics). If we incorporate analytics in the future, we will update this policy and request your consent.
9. Security
We implement technical and organizational measures to protect your data:
- Data transmission via TLS/HTTPS
- Storage with encryption at rest
- Access control via Row Level Security (RLS) in the database
- Secure authentication via OTP or Google OAuth
- Access restricted to authorized personnel
10. Updates to this policy
We may update this privacy policy in the future. If we make significant changes, we will notify you by email or through a prominent notice on the platform. The "last updated" date at the top always reflects the current version.
For inquiries, contact us at privacy@numerologia.io.