1. Who We Are (Data Controller)
The data controller responsible for your personal data is Wabbit Software Łukasz Fedorko, a sole trader registered in Poland:
- Registered address: ul. Bitwy Warszawskiej 1920 r. 14 lok. 107, 02-366 Warsaw, Poland
- NIP (tax identification number): 7141757720
- Email: contact@crystalcore.app
If you have questions about how your data is handled, write to us at the address above.
2. What Data We Collect, Why, and Our Legal Basis
CrystalCore is designed to collect as little as possible. You can generate free readings without an account. An account is needed only to buy a reading and to restore your purchases later, and it consists of nothing more than your email address — we never ask for a password.
A. Your Account and Readings
- What is collected: Your email address, the dates of birth you enter for readings, your purchase history (which readings and reports you bought, and when), and a temporary one-time login code. Login codes are stored hashed, expire after 10 minutes, and an email address is locked for 15 minutes after 5 failed attempts.
- Why: To generate your readings, to give you access to what you paid for on any device, and to protect accounts from brute-force login attempts.
- Legal Basis: Performance of a contract (Art. 6(1)(b) GDPR), and legitimate interests in securing the service (Art. 6(1)(f) GDPR).
- Where it is stored: Google Firebase (Firestore), acting as our hosting and database processor.
B. Transactional Emails (Resend)
- What is collected: Your email address and the content of service messages we send you — your login code, unlock confirmations, and notification that a report is ready.
- Why: These emails are how the service is delivered; they are not marketing, and we do not send newsletters.
- Legal Basis: Performance of a contract (Art. 6(1)(b) GDPR). Emails are delivered through Resend.
C. Invoicing (iFirma)
- What is collected: Your billing name, email address, purchased product, amount, and tax identification number (NIP) if you provide one.
- Why: To issue invoices and keep accounting records as required by Polish tax law.
- Legal Basis: Compliance with a legal obligation (Art. 6(1)(c) GDPR). Invoices are issued through our accounting provider, iFirma.
D. Payment Processing (Stripe)
- What is collected: When you purchase a reading, your payment details, billing information, and device/behavioral data are collected directly by our payment processor, Stripe. CrystalCore does not collect, view, or store your credit card information.
- Why: To securely process your payment and prevent fraudulent transactions.
- Legal Basis: Processing is necessary for the performance of a contract (Art. 6(1)(b) GDPR) and legitimate interests in fraud prevention (Art. 6(1)(f) GDPR). Please review Stripe's Privacy Policy for details on their data handling.
E. Analytics and Marketing (Google & Meta)
- What is collected: IP addresses, cookie identifiers, device information, and browsing behavior on our site.
- Why: We use Google Analytics to understand website traffic, and Google Ads and Facebook Pixel to measure the effectiveness of our marketing campaigns and deliver relevant advertisements.
- Legal Basis: Your explicit consent (Art. 6(1)(a) GDPR). These tools are only activated if you accept them via our cookie consent banner. You can withdraw this consent at any time.
3. How We Share Your Data
We do not sell your data. We only share what is necessary with our trusted third-party processors:
- Google Firebase (Google Ireland Ltd.): Hosting and database — stores your account, dates of birth and purchase history.
- Stripe: Secure payment processing and fraud detection.
- Resend: Delivery of login codes and service emails.
- IFIRMA SA (ul. Grabiszyńska 241 G, 53-234 Wrocław, Poland, KRS 0000281947): Issuing invoices and keeping accounting records.
- Google (Alphabet Inc.): Website analytics and ad targeting.
- Meta (Facebook Ireland Ltd.): Marketing attribution and ad targeting.
4. International Data Transfers
Some of our processors (Stripe, Google, Meta, Resend) are based in or transfer data to the United States. iFirma processes data within the European Union. Any transfer of your data outside the European Economic Area (EEA) is safeguarded by the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring your data receives an equivalent level of protection.
5. Data Retention
- Account, Dates of Birth and Purchase History: Kept for as long as your account exists, so that you can restore access to what you bought. Ask us to delete it and we will, except where we must keep invoicing records.
- Login Codes: Deleted or expired within minutes of being issued.
- Invoicing Data: Retained for 5 years from the end of the accounting year, as required by Polish tax law.
- Payment Data: Governed by Stripe's retention policies to comply with global financial and tax regulations.
- Analytics & Marketing Data: Cookie data is retained according to the specific lifespans of Google and Meta cookies (typically ranging from session-length up to 24 months), or until you clear your browser cookies or withdraw your consent.
6. Automated Decision-Making and Profiling
We do not use your data for automated decision-making that produces legal effects concerning you. Google and Meta may use your browsing data to build marketing profiles to show you relevant ads, provided you have given your consent.
7. Your GDPR Rights
Under the General Data Protection Regulation, you have the following rights:
- Right to Access: Request a copy of the personal data processed about you.
- Right to Rectification: Request correction of inaccurate data.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your data, subject to legal and financial retention requirements.
- Right to Restrict Processing: Request a temporary halt on processing your data.
- Right to Data Portability: Request your data in a structured, machine-readable format.
- Right to Object & Withdraw Consent: You may withdraw your consent for analytics and marketing cookies at any time via our website's cookie settings.
To exercise any of these rights, please email contact@crystalcore.app.
8. Right to Lodge a Complaint
If you believe our processing of your personal data violates data protection laws, you have the right to lodge a complaint with a supervisory authority. As we are established in Poland, our lead supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych — UODO), ul. Stawki 2, 00-193 Warsaw, Poland — uodo.gov.pl. You may also lodge a complaint with the supervisory authority in your own country of residence.
9. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal obligations. The latest version will always be available on this page with the updated "Effective Date."