SOLÈNE (“SOLÈNE”, “we”, “us” or “our”) respects your privacy. This policy explains what personal data we collect, why, how we protect it, and the rights you have over it. We extend the core data-protection rights of the EU GDPR to everyone, wherever you live.
01 Who we are
SOLÈNE provides Destiny-Matrix readings interpreted through a psychology-informed lens. For the purposes of the GDPR and similar laws, SOLÈNE is the data controller responsible for your personal data. You can reach us about anything in this policy, or to exercise your rights, at:
Before public launch, the operator’s registered legal name and postal address will be added here to fully identify the controller. [Registered business name and postal/registered address to be inserted.]
02 What data we collect
We collect only what we need to give you your Matrix and run your account:
- Account details — your name, email address, and a securely hashed version of your password (or, if you sign in with Google, no password at all — see section 05); optionally your preferred language, chosen avatar and email preferences.
- Matrix inputs — your date of birth and the gender you select, used to calculate your Matrix and personalise your readings. Your date of birth is treated as personal data; we do not collect special-category data (such as health, ethnicity or religious beliefs).
- Readings you generate — the charts and reports created for you (and, on the Signature plan, for other people whose details you choose to enter). If you enter another person’s details, you confirm you have a proper basis to do so.
- Purchase records — the plan you bought, amount, currency, date, and payment references from our processor. We never receive or store your full card number.
- Technical & session data — a strictly-necessary login cookie, plus limited security metadata such as IP address and browser user-agent, used to keep your account secure. Separately, we collect cookie-free, aggregate visit statistics that do not identify you — see section 04.
- Communications — messages you send us, and account emails we send you (such as verification and password resets).
You can always calculate your Matrix, view your chart and receive the Free Snapshot without creating an account or making a purchase. Used this way, we do not store your inputs to an account.
03 How and why we use your data
We use your personal data for the following purposes, each with a legal basis under the GDPR:
- To provide the service — creating your account, calculating your Matrix, generating and storing your reports and PDFs. Basis: performance of a contract.
- To process payments — completing checkout, granting your plan, and recording what you bought. Basis: contract; legal obligation for accounting.
- To keep accounts secure — authentication, session management, rate-limiting and fraud prevention. Basis: our legitimate interests.
- To send account emails — verification, password resets, and purchase confirmations. Basis: contract; legitimate interests.
- To send optional updates — news and Matrix insights, only if you opt in; you can opt out anytime. Basis: consent.
- To meet legal obligations — for example retaining transaction records. Basis: legal obligation.
04 Cookies
We use a single strictly-necessary cookie to keep you signed in. It is an httpOnly, Secure, SameSite=Lax session cookie and cannot be read by scripts. Because this cookie is essential to a service you have asked for, it does not require consent.
We do not use advertising cookies, cross-site trackers, or profiling of any kind.
Visitor statistics. To understand how the site is used — which pages people read, and roughly where visitors come from — we use Umami, a privacy-focused analytics service. It sets no cookies and stores nothing on your device. It records only aggregate information about a visit: the page viewed, the site that referred you, and general technical details such as browser, operating system, device type, screen size and approximate country. It does not fingerprint your device, does not store your IP address (it is used only in the moment, to work out an approximate country), and cannot follow you to other websites or identify you personally. Because nothing is stored on or read from your device, this does not require a cookie banner. This analytics data is processed in the European Union.
05 Who we share data with
We do not sell your personal data, and we do not share it for advertising. We use a small number of trusted providers (“processors”) who process data on our behalf and under contract:
- Payment processing — Stripe, to take payments securely.
- Sign-in with Google — if you choose “Continue with Google” instead of creating a password, Google confirms your identity and passes us your name, email address and confirmation that the email is verified. We store those, together with an identifier Google gives us so we can recognise you next time. We never receive your Google password. Google’s own privacy notice governs what it does with the sign-in. Using Google is entirely optional — an email and password works exactly the same.
- Email delivery — a transactional email provider, for verification, reset and confirmation emails.
- Visitor analytics — Umami, which produces aggregate visit statistics without cookies or personal identifiers, processed in the European Union. See section 04.
- Hosting, database & file storage — cloud providers who host the application, database and your generated PDF reports.
We may also disclose data where required by law, to protect our rights or users’ safety, or in connection with a business transfer (such as a merger or acquisition), in which case we will notify you.
06 Payments
Payments are handled by Stripe. Your card details are entered on Stripe’s secure, PCI-compliant checkout and processed by Stripe as an independent controller — we never see or store your full card number. We receive only a confirmation of payment and limited references (such as a session or payment identifier, amount and currency) so we can unlock your purchase and keep a record. Stripe’s own privacy notice governs its processing of your payment data.
07 International transfers
Some providers may process data outside your country, including outside the European Economic Area. Where personal data is transferred internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, or an equivalent lawful transfer mechanism, so your data stays protected.
08 How long we keep data
We keep your personal data for as long as your account exists and for as long as we need it:
- Account, matrices & reports — kept until you delete them or close your account.
- Sessions — expire automatically (a sliding period of up to 30 days) and are swept regularly; security tokens are short-lived.
- Purchase & transaction records — retained as long as necessary for accounting, tax and legal obligations, even after account deletion, in a minimised form.
When you delete your account, we remove your profile, your matrices, your reports and your stored PDF files.
09 How we protect your data
Security is built into the service. Passwords are hashed with argon2id and never stored in plain text. Traffic is served over HTTPS with HSTS. Session and verification tokens are stored only as hashes. Report PDFs are served through short-lived, signed download links accessible only to the account that owns them. We apply access controls, rate-limiting and input validation throughout. No system is perfectly secure, but we work to protect your data using current best practices.
10 Your rights
Wherever you live, we offer you the following rights over your personal data:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — ask us to delete your data (“right to be forgotten”).
- Restriction & objection — limit or object to certain processing, including processing based on legitimate interests.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent — opt out of marketing emails at any time, without affecting the service.
You can exercise the most common rights yourself in My Space: Download My Data exports everything we hold in JSON, and Delete Account permanently removes your data and stored PDFs. For anything else, email contact@solenematrix.com and we will respond within the timeframe required by law (generally within one month). If you are in the EEA or UK, you also have the right to complain to your local data-protection supervisory authority.
11 Notice for California residents
If you are a California resident, the CCPA/CPRA gives you rights to know what personal information we collect, to access or delete it, and to be free from discrimination for exercising those rights. The categories we collect are described in section 02 above. We do not sell your personal information, and we do not share it for cross-context behavioural advertising. You can exercise your rights using the tools in My Space or by contacting us at the email above.
12 Children
SOLÈNE is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
13 The nature of our readings
SOLÈNE’s readings are intended for self-reflection and personal insight. They are not medical, psychological, legal or financial advice, and are not automated decisions that produce legal or similarly significant effects about you. You remain in control of any decisions you make.
14 Changes to this policy
We may update this policy from time to time as the platform evolves or the law changes. When we do, we will revise the “Last updated” date above and, for material changes, take reasonable steps to let you know.
15 Contact us
For any question about this policy or your personal data, contact us at contact@solenematrix.com.