Privacy Policy

Last updated: February 2026

1. Introduction

Crystal Stream Tarot ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.

We comply with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and applicable international privacy laws including the EU General Data Protection Regulation (GDPR) where applicable.

2. Information We Collect

Personal Information

  • Email address (required for account creation)
  • Password (stored securely using encryption)
  • Date of birth (optional, used for personalised readings)
  • Display name (optional)

Usage Data

  • Reading history and questions asked
  • Token purchase and usage history
  • Journal entries you create
  • Technical data (IP address, browser type, device information)

3. How We Use Your Information

  • To provide and maintain our tarot reading services
  • To personalise your readings based on your birth date
  • To process payments and manage your token balance
  • To send transactional emails (purchase confirmations, welcome emails)
  • To improve our services and user experience
  • To comply with legal obligations

4. Cookies and Tracking

We use essential cookies to:

  • Authentication cookies: To keep you logged in securely
  • Session cookies: To remember your preferences during your visit

We do not use advertising cookies or sell your data to third parties. You can disable cookies in your browser settings, but this may affect your ability to use our services.

5. Data Sharing and Disclosure

We do not sell, trade, or rent your personal information. We may share your data with:

  • Payment processors: Stripe processes payments securely; we do not store your card details
  • AI service providers: To generate tarot interpretations (no personal data is shared, only reading context)
  • Legal authorities: If required by law or to protect our rights

6. Data Security

We implement appropriate technical and organisational measures to protect your personal information, including:

  • Encryption of passwords using bcrypt
  • Secure HTTPS connections
  • Regular security assessments
  • Limited access to personal data

7. Your Rights

Under Australian Privacy Law and GDPR (where applicable), you have the right to:

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your account and data
  • Portability: Request your data in a portable format
  • Objection: Object to certain processing of your data

To exercise these rights, please contact us at [email protected]

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. Reading history is kept to allow you to review past readings. You may request deletion of your account and associated data at any time.

9. Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

11. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

Email: [email protected]