Privacy Policy
How YesNoTarot.org collects, uses, and protects information.
Last updated: 2026-09-12
Chen Wenjiang ("we", "us", or "our") operates YesNoTarot.org (the "Service") as an individual / sole trader under the laws of the People's Republic of China. We are committed to protecting your privacy.
This Privacy Policy ("Policy") explains how we collect, use, store, and share your personal information when you use the Service, and the rights available to you. Please read it carefully before using the Service. By using the Service, you agree to this Policy.
1. Data Controller
The data controller for the Service is:
- Controller: Chen Wenjiang, an individual / sole trader operating under the laws of the People's Republic of China
- Privacy email: support@yesnotarot.org
- Data Protection Officer: Not applicable
2. Personal Information We Collect
2.1 Information you provide directly
- Account information: name, email address, profile image, authentication provider identifiers, and account security information. Where password login is used, passwords are stored only in protected, hashed form.
- Reading information: the question you submit, the cards selected, reading type, language, the generated interpretation, and the time of creation. Signed-in readings may be associated with your account so you can view your history. Anonymous readings may be associated with a random visitor identifier stored in your browser.
- Payment information: transaction amount, currency, payment status, plan and billing period, and identifiers issued by the payment provider. We do not receive or store your complete payment card number — card data is processed by our payment processor (see Section 5).
- Communications: support tickets, emails, and feedback you send us, including any attachments you choose to provide.
Your questions may reveal personal or sensitive information. Please do not submit information you do not want processed, and do not include another person's private information without a lawful reason. Do not submit confidential records, payment card details, government identification numbers, or health records.
2.2 Information we collect automatically
- Device and network data: IP address, a salted hash derived from an IP address, browser and device type, operating system, language, time zone, and referral information.
- Usage data: pages and features used, reading counts, timestamps, session duration, and activity used to apply usage limits and protect the Service.
- Log data: request timestamps, error information, and performance metrics.
- Cookies and similar technologies: see Section 4.
3. How We Use Your Information
We use your information for the purposes below. Where the EU or UK GDPR applies, the corresponding legal basis is shown.
- Service delivery and maintenance — generating and delivering tarot readings, and operating your account. Legal basis: performance of a contract.
- Billing and payment processing — activating subscriptions, managing renewals and cancellations, and handling refunds. Legal basis: performance of a contract.
- Customer support — responding to your requests. Legal basis: performance of a contract or our legitimate interests.
- Service notifications — billing, security, and policy notices. Legal basis: our legitimate interests, or legal obligation.
- Security and fraud prevention — enforcing reading limits, detecting abuse, and protecting users and the Service. Legal basis: our legitimate interests.
- Product analytics and improvement — understanding performance and improving the Service. Legal basis: our legitimate interests (or your consent, where a cookie-based analytics tool is enabled).
- Legal compliance — meeting tax, accounting, and regulatory obligations. Legal basis: legal obligation.
- Marketing — only where you have opted in. Legal basis: your consent.
We may aggregate or anonymize data for statistical purposes. Such data can no longer be linked to any individual.
4. Cookies & Tracking Technologies
We use cookies, browser storage, and similar technologies. You can control them through your browser settings.
- Strictly necessary — keeping you signed in, account security, applying reading limits, and core site operation. These cannot be disabled without breaking the Service.
- Functional — remembering your language and interface preferences. You can disable these.
- Analytics — aggregate, anonymous usage statistics. You can disable these. Where enabled, we may use privacy-focused cookieless analytics (Plausible) or, if configured, a cookie-based provider such as Google Analytics.
Blocking essential cookies or clearing browser storage may sign you out, reset your preferences, or prevent some features from working. Clearing identifiers solely to bypass reading limits does not lift those limits; other anti-abuse signals may still apply.
5. Sharing & Disclosure
We do not sell your personal information, including as defined under applicable laws such as the CCPA.
We share information only in the following circumstances:
- Service providers — hosting, database, storage, email, and authentication vendors that help us operate the Service, bound by confidentiality obligations. These currently include Cloudflare (hosting, database, and content delivery), Resend (transactional email), and Google (optional sign-in via Google OAuth).
- Payment processing — payment card data is processed exclusively by our PCI-DSS certified payment processor, Waffo Pancake, and is not stored on our servers. Waffo Pancake acts as the merchant of record for purchases and handles invoicing, applicable taxes, and receipts.
- AI model providers — to generate your reading, the text of your question, the selected cards, the requested language, and the instructions needed to produce the reading are sent to the active third-party AI provider. These may include Google, Alibaba (Qwen), and OpenAI, accessed through OpenRouter. AI providers process this information under their own terms and privacy practices.
- Legal requirements — where required by law, court order, or a lawful regulatory request.
- Business transactions — in a merger, acquisition, or similar event, with advance notice and continued protections.
- With your consent — for any other purpose, with your explicit prior consent.
6. Data Security
We apply reasonable technical and organizational measures intended to protect your information:
- Encryption in transit: TLS / HTTPS for all traffic to and from the Service.
- Secure storage: credentials are hashed; sensitive values are encrypted where stored.
- Access controls: least-privilege access, with access limited to what is needed to operate the Service.
- Signed payment notifications: payment webhooks are cryptographically verified before they are trusted.
- Pseudonymous anti-abuse identifiers: reading limits use a salted hash or random identifier rather than your raw IP address where possible.
No internet transmission or storage system is completely secure, so we cannot guarantee absolute security. Please keep your credentials safe and do not share them.
In the event of a security incident affecting your rights, we will notify you and the relevant authorities as required by law, and within 72 hours of becoming aware of the incident where that deadline applies.
7. Data Retention
We retain information only for as long as reasonably necessary for the purposes described in this Policy.
- Account information — while your account is active. If you ask us to delete your account, we delete the associated personal information within 30 days of verifying your request.
- Reading history — up to 365 days for subscribers, and up to 30 days for free and trial users. You can delete individual signed-in readings from your history at any time.
- Anonymous visitor identifiers — held in your browser's local storage for up to 1 year, unless you clear them earlier.
- Transaction records — retained for the period required by applicable tax, accounting, and financial record-keeping obligations, and to resolve disputes. We do not delete these on request where the law requires us to keep them.
- Security and error logs — up to 90 days.
Deleting information from active systems may not immediately remove copies from encrypted backups, which age out on their own schedule.
8. Your Data Rights
Depending on where you live, you may have the following rights:
- Right to be informed — to know what data we collect and how we use it
- Right of access — to obtain a copy of your personal information
- Right to rectification — to correct inaccurate or incomplete data
- Right to erasure — to request deletion under certain conditions
- Right to restrict processing — to temporarily suspend processing in certain cases
- Right to data portability — to receive your data in a machine-readable format
- Right to object — to object to processing based on legitimate interests, or to marketing
- Right to withdraw consent — to withdraw consent for consent-based processing at any time
To exercise any of these rights, contact support@yesnotarot.org from the email address associated with your account. We respond within 30 calendar days. We may need to verify your identity before completing a request.
You may also lodge a complaint with your local data protection authority, or with the competent supervisory authority in your country of residence, place of work, or place of the alleged infringement.
9. Marketing & Opt-Out
We may send service emails that are necessary to operate your account — for example, verification emails, security alerts, and billing notices. These are not marketing and cannot be unsubscribed from while your account is active.
With your consent, we may also send marketing communications about the Service. You can opt out at any time by using the unsubscribe link in any marketing email or by contacting us. Opting out of marketing does not affect essential service notifications such as billing or security alerts.
10. International Data Transfers
Our servers and our providers are located in multiple regions, including the United States, the European Union, and the Asia-Pacific region. Cloudflare operates a global edge network, so your data may be processed in a country other than your own.
For international transfers, we safeguard your data through:
- Data processing agreements incorporating the EU Standard Contractual Clauses (SCCs), or an equivalent approved transfer mechanism.
- Transfers only to recipients that provide a level of protection consistent with applicable law.
11. Children's Privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16. Paid subscriptions are available only to people who are at least 18 years old, or who have reached the age of legal majority where they live.
If you believe a child has provided us with personal information, please contact us at support@yesnotarot.org and we will review and delete it promptly.
12. Third-Party Links & Services
The Service may include links to, or integrations with, third-party services — for example, payment pages hosted by our payment provider, or sign-in through Google. This Policy applies only to data we directly collect. We are not responsible for the privacy practices of third parties, and we encourage you to review their policies before use.
13. Policy Changes
We may update this Policy when our practices, providers, or legal obligations change. The updated date appears at the top of this page.
For material changes, we will provide at least 15 days' advance notice by email or by an in-product notice before the change takes effect. Continued use after the effective date constitutes acceptance of the revised Policy.
14. Contact Us
- Privacy email: support@yesnotarot.org
- Support email: support@yesnotarot.org
- Controller: Chen Wenjiang, an individual / sole trader operating under the laws of the People's Republic of China
- Business hours: Monday to Friday, 09:00–18:00 (UTC+8)
Requests about your personal information are handled through the same monitored inbox. We respond within 30 calendar days.
Last updated: 12 September 2026