← Back to SoulPrint

Privacy Policy

Last updated: May 2026

SoulPrint ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you use our website and services, in compliance with the General Data Protection Regulation (GDPR) and applicable EU data protection laws.

1. Data Controller

SoulPrint operates as the data controller for personal data collected through this website. For any privacy inquiries, please contact us at the email provided on our website.

2. Data We Collect

Payment Data: Your email address is collected via Stripe during checkout. We do not store or have access to your full credit card details — Stripe processes all payment information securely.

Quiz Responses: Your name, date of birth, birth city, birth time (optional), gender, country, and all personality quiz answers you voluntarily provide.

Generated Content: The personalized report created from your quiz responses.

3. Legal Basis for Processing

We process your personal data based on: (a) Contract performance — to deliver the personalized report you purchased; (b) Legitimate interest — to improve our service and handle errors; (c) Consent — for any optional cookies or future marketing communications.

4. How We Use Your Data

Your data is used solely to: generate your personalized SoulPrint report; deliver the report to your email address; process your payment; and handle any errors or support requests related to your order.

5. Data Sharing

We share data only with the following third-party processors, solely for service delivery: Stripe (payment processing), Supabase (database hosting), Anthropic (report generation), Resend (email delivery), and Vercel (website hosting).

We never sell, rent, or share your personal data with advertisers, data brokers, or any other third parties.

6. Data Retention

We retain your order and quiz data for up to 12 months after purchase for support purposes. After this period, data is automatically deleted. You may request earlier deletion at any time.

7. Your Rights (GDPR)

Under GDPR, you have the right to: access your personal data; rectify inaccurate data; request deletion ("right to be forgotten"); restrict processing; data portability; object to processing; and withdraw consent at any time. To exercise any of these rights, contact us. We will respond within 30 days.

8. Cookies

We use only essential cookies required for the website to function. We do not use tracking cookies, analytics cookies, or advertising cookies.

9. Data Security

We implement industry-standard security measures including HTTPS encryption, secure database access controls, and encrypted data transmission. Payment processing is handled entirely by Stripe, a PCI DSS Level 1 certified provider.

10. International Transfers

Some of our service providers may process data outside the EU/EEA. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.

11. Changes

We may update this policy periodically. Changes will be posted on this page with an updated revision date.