Privacy Policy

Last update: 22.10.2025

TAROTICO — PRIVACY POLICY

Last updated: October 2025

Owner: InnOneWeb OÜ
Registry code: 16826593
Address: Harju maakond, Tallinn, Kesklinna linnaosa, Sakala tn 7-2, 10141, Estonia
Email: support@tarotico.com
Website: www.tarotico.com


1. Introduction

This Privacy Policy explains how InnOneWeb OÜ (“we”, “our”, “us”) collects, uses, and protects your personal data when you use Tarotico (the “Platform”), including our website, mobile versions, and digital services.

We are committed to protecting your privacy and handling your personal information transparently, in accordance with the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and applicable international laws.


2. Data We Collect

We collect and process only the data necessary to provide our services and improve your experience. This may include:

a) Account information — name, email address, password (encrypted).
b) Subscription data — payment details (processed securely via third-party providers like Stripe, Revolut, or PayPal; we never store your card data).
c) Usage data — interactions with readings, spreads, and features to improve our recommendations and analytics.
d) Technical data — browser type, device info, IP address (used for security, fraud prevention, and localization).
e) Communication data — messages you send us via contact forms, chat, or email.


3. How We Use Your Data

We use your personal data for the following purposes:

  • To create and manage your account;

  • To provide access to free and paid services;

  • To process payments securely;

  • To send service-related notifications (trial expiry, updates, or subscription info);

  • To personalize your experience and improve the Platform;

  • To comply with legal obligations.

We never sell or rent your personal data to third parties.


4. Legal Basis for Processing (GDPR)

We process your data based on the following legal grounds:

  • Performance of a contract: to provide you with the services you request (Art. 6(1)(b) GDPR).

  • Legal obligation: to comply with accounting, tax, or consumer laws (Art. 6(1)(c)).

  • Legitimate interest: to maintain security, prevent abuse, and improve user experience (Art. 6(1)(f)).

  • Consent: for marketing communications or optional cookies (Art. 6(1)(a)).


5. Cookies and Analytics

We use cookies and similar technologies to enhance your browsing experience, remember your preferences, and analyze site performance.

You can manage or disable cookies through your browser settings at any time.
We use Google Analytics and/or Meta Pixel to understand usage patterns in an anonymized form.

For EU/UK users: tracking cookies are loaded only after you give explicit consent via our cookie banner.


6. Payments and Third-Party Processors

All payments are processed securely through Stripe, Revolut, or PayPal.
We do not store or have access to your full payment details (card numbers, CVV, etc.).

These providers act as independent data controllers in relation to your payment information and comply with PCI-DSS and GDPR standards.


7. Data Storage and Retention

Your personal data is stored securely on servers located in the European Union (EU/EEA).
If we transfer data outside the EU (e.g., to the U.S. via third-party processors), it is done only under recognized safeguards such as Standard Contractual Clauses (SCCs) or adequacy decisions.

We retain your data only as long as necessary for the purposes stated above, typically:

  • Account data — as long as your account is active;

  • Payment records — 7 years (for accounting compliance);

  • Marketing data — until you unsubscribe or withdraw consent.


8. Your Rights (GDPR & UK GDPR)

You have the following rights regarding your personal data:

  • Access: request a copy of your stored data.

  • Correction: request correction of inaccurate data.

  • Deletion: request deletion (“right to be forgotten”).

  • Restriction: limit processing under certain conditions.

  • Portability: receive your data in a machine-readable format.

  • Objection: object to processing for legitimate interest or marketing.

  • Withdrawal of consent: withdraw consent at any time (e.g., for newsletters).

To exercise any of these rights, email us at support@tarotico.com.


9. Data for Users Outside the EU

For users in the United States, Canada, and Australia, we process your data in accordance with globally recognized privacy standards, such as:

  • U.S. CCPA/CPRA (California): You may request access, deletion, or information about how your data is used.

  • PIPEDA (Canada): We collect data only for reasonable, identified purposes and protect it through appropriate safeguards.

  • Australian Privacy Act 1988: You have the right to access, correct, and request deletion of your personal information.

All international users can contact support@tarotico.com for privacy-related inquiries.


10. Email Communications

If you choose to subscribe to our newsletter or updates, we will send occasional emails related to Tarotico news, special content, or offers.
You can unsubscribe at any time via the link in each email.
We use GDPR-compliant email services (such as MailerLite, ConvertKit, or SendGrid).


11. Data Security

We apply strong technical and organizational measures to protect your information, including:

  • SSL encryption (HTTPS)

  • Secure authentication and password hashing

  • Regular security audits and data minimization

However, no online system is completely risk-free, and you acknowledge that you use the Platform at your own discretion.


12. Children’s Privacy

TAROTICO is not directed at individuals under 16 years old.
We do not knowingly collect data from minors.
If you believe a child has provided us with personal data, please contact us for deletion.


13. Updates to This Policy

We may occasionally update this Privacy Policy to reflect legal or operational changes.
Updates will be posted on this page with a new “Last updated” date.
Material changes will be communicated via email or within the Platform.


14. Contact Information

For any privacy-related questions, please contact:

InnOneWeb OÜ
Registry code: 16826593
Address: Harju maakond, Tallinn, Kesklinna linnaosa, Sakala tn 7-2, 10141, Estonia
Email: support@tarotico.com
Website: www.tarotico.com