Privacy Policy

Last updated: May 2026

Introduction

Metaphysical Events ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This policy explains what we collect, why we collect it, who we share it with, how long we keep it, and the choices and rights you have. It applies to our website, tools (tarot, runes, astrology, the grimoire), the practitioner directory and events calendar, the shop, and any related services (collectively, the "Platform").

For the purposes of applicable data-protection law, the operator of the Platform is the data controller. Insert your controlling legal entity, registered address, and a data-protection contact in the placeholders below before publishing.

Information We Collect

We collect the following categories of information:

  • Account information — your name, email address, password (stored only as a salted hash by our authentication provider), and account preferences.
  • Profile information — details you choose to add, such as a bio, avatar image, and your ZIP/postal code (used to power location-based search).
  • Subscription & billing information — your subscription tier and status, and billing records. Card details are entered directly with our payment processor (Stripe) and are never stored on our servers; we retain only a customer reference, the last four digits, and renewal/period metadata.
  • Readings & journal entries — tarot and rune readings you generate, astrology chart inputs (birth date, time, and location), and any private notes or journal entries you save.
  • Business & event listings — if you hold a practitioner subscription, the business profile, credentials, modalities, and event details you publish, including the location you provide for geo-search.
  • Location data — the ZIP/postal code or place you enter for directory and event radius searches and for astrology chart accuracy. We do not track your precise device location in the background.
  • Usage & device data — basic technical information such as IP address, browser type, pages visited, and interactions, used to operate and secure the Platform.

How We Use Your Information & Legal Bases

We process your data for the following purposes:

  • To provide the service (performance of a contract) — creating your account, generating readings, saving journal entries, running searches, and publishing the listings you choose to make public.
  • To process payments and manage subscriptions (performance of a contract) — handling checkout, renewals, upgrades, downgrades, pauses, and cancellations.
  • To operate, secure, and improve the Platform (legitimate interests) — preventing abuse, debugging, and understanding aggregate usage.
  • To send you service messages and, where you opt in, marketing(consent / legitimate interests) — you can opt out of marketing at any time.
  • To comply with legal obligations — tax, accounting, and responding to lawful requests.

Where we rely on consent (for example, non-essential cookies or marketing email), you may withdraw it at any time without affecting prior processing. See our Cookie Policy for details on cookie consent.

Third-Party Processors

We share data with a small set of trusted service providers who process it on our behalf, under contract, and only as needed to deliver the Platform:

  • Stripe — payment processing and subscription billing.
  • Supabase (self-hosted) — our database and authentication, running on infrastructure we control.
  • Wasabi S3 — object storage for uploaded images and media (for example, avatars, listing photos, and downloadable goods).
  • N8n (self-hosted) — workflow automation that powers features such as reading interpretations, notifications, and scheduled maintenance.
  • Email delivery provider — transactional and, where you opt in, marketing email.

We do not sell your personal data. Each processor maintains its own privacy practices governing the data it handles.

Data Retention & Account Deletion

We keep your personal data for as long as your account is active and as needed to provide the Platform. When you request account deletion, we apply a 30-day grace period: your account is first deactivated and scheduled for removal, during which you can recover it. After the grace window elapses, your profile, readings, journal entries, listings, events, and settings are permanently purged, your stored media is deleted, and any active subscription is canceled. We may retain limited records (such as a hashed deletion log and invoices) where required for legal, tax, or audit purposes.

Your Rights & Choices

Subject to applicable law, you have the right to:

  • Access and export your data — download a copy of your account data from your account settings.
  • Rectify inaccurate or incomplete data — edit it in your profile or settings.
  • Delete your account and data — start deletion (with the 30-day grace period) from your account settings.
  • Manage your subscription — upgrade, downgrade, pause, or cancel from your billing page.
  • Opt out of marketing — adjust your communication preferences in your settings.
  • Manage cookie consent — change your choices any time via the cookie preferences in your settings.

Depending on your jurisdiction you may also have rights to restrict or object to processing, to data portability, and to lodge a complaint with your local data protection authority.

International Transfers

Our infrastructure and processors may store or process data in countries other than your own. Where data is transferred across borders, we rely on appropriate safeguards (such as standard contractual clauses or an equivalent mechanism) as required by applicable law.

Security

We implement appropriate technical and organizational measures — including encryption in transit, access controls, and database-level row security — to protect your personal data against unauthorized access, alteration, disclosure, or destruction. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Children's Privacy

The Platform is not directed to children, and we do not knowingly collect personal data from anyone under the age required by your jurisdiction. If you believe a child has provided us data, please contact us so we can remove it.

Changes to This Policy

We may update this policy from time to time. We will revise the "Last updated" date above and, where changes are material, provide additional notice.

Contact Us

If you have questions about this policy or wish to exercise your rights, please reach us through our contact page.