Version 2.2 · effective 8 August 2026

Privacy Policy

This Privacy Policy explains how Sapienbase, operated by Viraly Marketing Management (registered office: United Arab Emirates (full registered address on request)) — the "data controller" — collects, uses, discloses and protects your personal data when you use our website, apps, purchase flows and communications ("Service"). We aim to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended (CCPA/CPRA) and other applicable data-protection laws.

1. Data we collect

  • Account data: email address, name (optional), password hash, language, marketing preferences.
  • Purchase & billing data: products purchased, order history, invoices. Card and bank details are collected and stored directly by Stripe — we never see or store full card numbers.
  • Content & progress: ebooks accessed, chapter progress, quiz answers, community posts, feedback.
  • Device & usage data: IP address, browser, OS, timestamps, pages visited, referrer, clickstream, session duration.
  • Support data: messages you send to support, coach or the community.
  • Marketing data: email opens/clicks, ad interactions, event data sent to Meta Pixel / Conversions API (see Section 6).
  • Cookies: see our Cookie Policy.

2. Legal bases (GDPR)

  • Contract (Art. 6(1)(b)): creating your account, delivering purchased products, providing subscription features.
  • Legitimate interest (Art. 6(1)(f)): service security, fraud prevention, product improvement, product analytics, first-party marketing to existing customers.
  • Consent (Art. 6(1)(a)): non-essential cookies, marketing emails to prospects, advertising pixels, testimonials.
  • Legal obligation (Art. 6(1)(c)): tax, accounting and consumer-protection recordkeeping.

3. How we use data

  • Operate the Service and deliver purchased digital content.
  • Process payments, issue receipts and manage subscriptions.
  • Communicate with you about your account, orders, and support requests.
  • Send marketing communications (with your consent where required); every marketing email includes a one-click unsubscribe link.
  • Detect, prevent and address fraud, abuse and security incidents.
  • Comply with legal obligations and enforce our Terms.

4. Sub-processors

We share personal data only with vetted sub-processors, under written data-processing agreements, on a need-to-know basis and for the purposes below. This list is current at the effective date of this Policy and is updated when we change providers.

Sapienbase sub-processors
ProviderPurposeData categoriesLocation
Stripe, Inc.Payment processing, subscriptions, fraud screening, chargeback handling, invoicingEmail, name, billing country, payment method (held by Stripe), order and dispute data, IP and device signals at checkoutUSA / EU
Supabase (Lovable Cloud)Application database, authentication, file storage, server functionsAccount data, password hash, purchases, content progress, support records, logsEU / USA
Cloudflare, Inc.CDN, edge runtime, DNS, DDoS protection, bot mitigationIP address, request metadata, user agentGlobal edge network
ResendTransactional and marketing email delivery, inbound reply handlingEmail address, name, message content, delivery/open/click eventsUSA / EU
Meta Platforms, Inc.Advertising measurement via Meta Pixel and Conversions API (consent-based)Hashed email, event data (page view, initiate checkout, purchase), IP, browser identifiersUSA / EU
OpenAI, Anthropic, Google (AI models)AI features: generation, summaries, assistant answersPrompt content you submit and minimal session context. No credentials, no payment data. Providers are contractually barred from training on our API dataUSA / EU
LovableApplication hosting, deployment and platform operationsDeployment logs, request metadataEU / USA

We may also disclose data to professional advisers (accountants, lawyers), to authorities where legally required, and to an acquirer in the context of a merger, acquisition or asset sale — in which case we will notify you and the acquirer remains bound by this Policy.

We do not sell your personal data and we do not share it with third parties for their own independent marketing without your consent.

5. International transfers

Some processors are located outside the EEA/UK (including the United States). Transfers are protected by appropriate safeguards, primarily the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework certification of the recipient.

6. Advertising, Meta Pixel and Conversions API

With your consent, we use the Meta Pixel and the Meta Conversions API to measure conversions and improve advertising performance. We send Meta hashed identifiers (e.g. SHA-256 of email) and event data (e.g. Purchase, InitiateCheckout). You can withdraw consent at any time via the cookie banner or by using the "Do Not Sell or Share My Personal Information" mechanism (CCPA), which we honor globally.

7. Retention

  • Account data: for as long as your account is active, plus up to 24 months after closure for dispute resolution.
  • Purchase & tax records: up to 10 years, as required by applicable tax and accounting law.
  • Marketing data: until you unsubscribe or withdraw consent, plus a short suppression period.
  • Support logs: up to 24 months.
  • Server & security logs: up to 12 months.

8. Your rights (GDPR / UK GDPR)

  • Access, rectification, erasure, restriction, portability, objection.
  • Withdraw consent at any time (without affecting past processing).
  • Lodge a complaint with your local supervisory authority.

To exercise your rights, email privacy@sapienbase.com from the address registered on your account. We respond within 30 days and may extend by a further two months for complex requests, telling you why. Requests are free unless manifestly unfounded or excessive. We may ask for limited additional information to verify your identity before acting — we use it only for verification. If you use an authorised agent, we require written proof of authority.

If you are unhappy with our response, you may lodge a complaint with your local data protection authority. In the EU, you can find yours via the European Data Protection Board; in the UK, the ICO.

9. Your rights (California / CCPA-CPRA)

California residents have the right to know, access, delete, correct, and opt out of the sale/sharing of personal information, and to limit the use of sensitive personal information. We do not sell personal information for money and treat cross-context behavioral advertising as "sharing" — you can opt out globally by using the cookie banner or by emailing privacy@sapienbase.com. We do not discriminate against consumers who exercise their rights: exercising a right never changes your price, your access, or the quality of support you receive.

Do Not Sell or Share My Personal Information. Use the cookie preferences control to withdraw advertising consent, or email us with the subject "Do Not Sell or Share". We also honor the Global Privacy Control (GPC) browser signal as a valid opt-out request, and we apply it globally rather than only to California visitors.

Categories. In the last 12 months we collected the categories of personal information described in Section 1 (identifiers, commercial/purchase information, internet activity, and inferences drawn for advertising measurement), disclosed them for business purposes to the sub-processors listed in Section 4, and shared identifiers and internet-activity data for cross-context behavioral advertising where consent was given. We do not knowingly collect or sell the personal information of minors under 16.

10. Other US state privacy rights

If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you have the right to confirm whether we process your personal data, to access and obtain a portable copy, to correct inaccuracies, to request deletion, and to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects. We do not engage in that kind of profiling (see Section 11).

Submit requests to privacy@sapienbase.com. We respond within 45 days, extendable once by a further 45 days where reasonably necessary. If we decline a request, you may appeal by replying to our decision with the subject "Privacy appeal"; we will respond to the appeal within 60 days and, if the appeal is denied, tell you how to contact your state Attorney General. Where required (Colorado, Connecticut, Virginia), we obtain consent before processing sensitive data — we do not intentionally collect sensitive categories such as health, biometric, precise geolocation, or government-ID data.

11. Automated decision-making and profiling

We do not make decisions producing legal effects or similarly significant effects about you by purely automated means, and we do not use your data for credit scoring, employment, insurance, housing or eligibility decisions. We use limited, non-significant automation for: fraud and abuse scoring at checkout (performed by Stripe Radar, with human review before any account action), audience and conversion measurement for advertising (consent-based, see Section 6), and content recommendations inside the library based on what you have opened. You can object to profiling for marketing purposes at any time by withdrawing advertising consent or emailing us; this never restricts your access to purchased content.

12. Cookies and consent records

Non-essential cookies and advertising tags are set only after consent where required. We keep a record of your consent choice (what you consented to, when, and the policy version in force) so we can demonstrate lawful processing and honor withdrawals. You can change or withdraw your choice at any time; withdrawal takes effect immediately for future processing and does not affect processing already carried out lawfully. Full detail, including a cookie-by-cookie table, is in our Cookie Policy.

13. Children

The Service is not directed to and may not be used by anyone under 18. We do not knowingly collect data from minors. If you believe a minor has provided us data, contact us and we will delete it.

14. Security

We use industry-standard measures: TLS in transit, encryption at rest for the database, hashed passwords, role-based access, least-privilege secrets, activity logging and regular security reviews. Card data is handled exclusively by Stripe and never reaches our systems. No system is 100% secure; you use the Service at your own risk. Details are in our Security Practices.

15. Breach notification

In the event of a personal-data breach likely to result in a risk to your rights, we will notify affected users and, where required, the competent supervisory authority within 72 hours of becoming aware of it.

16. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be announced by email or in-app notice with at least 30 days' notice. The version number and effective date at the top of this page always identify the current text.

17. Contact

  • Data controller: Viraly Marketing Management, United Arab Emirates (full registered address on request)
  • Privacy: privacy@sapienbase.com
  • General: legal@sapienbase.com
  • We have not appointed a statutory Data Protection Officer, as we are not required to; privacy requests are handled by the contacts above.
See also