Version 2.0 · effective 25 July 2026

Privacy Policy

This Privacy Policy explains how Sapienbase, operated by [LEGAL ENTITY] (registered office: [FULL ADDRESS]) — the "data controller" — collects, uses, discloses and protects your personal data when you use our website, apps, purchase flows and communications ("Service"). We aim to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended (CCPA/CPRA) and other applicable data-protection laws.

1. Data we collect

  • Account data: email address, name (optional), password hash, language, marketing preferences.
  • Purchase & billing data: products purchased, order history, invoices. Card and bank details are collected and stored directly by Stripe — we never see or store full card numbers.
  • Content & progress: ebooks accessed, chapter progress, quiz answers, community posts, feedback.
  • Device & usage data: IP address, browser, OS, timestamps, pages visited, referrer, clickstream, session duration.
  • Support data: messages you send to support, coach or the community.
  • Marketing data: email opens/clicks, ad interactions, event data sent to Meta Pixel / Conversions API (see Section 6).
  • Cookies: see our Cookie Policy.

2. Legal bases (GDPR)

  • Contract (Art. 6(1)(b)): creating your account, delivering purchased products, providing subscription features.
  • Legitimate interest (Art. 6(1)(f)): service security, fraud prevention, product improvement, product analytics, first-party marketing to existing customers.
  • Consent (Art. 6(1)(a)): non-essential cookies, marketing emails to prospects, advertising pixels, testimonials.
  • Legal obligation (Art. 6(1)(c)): tax, accounting and consumer-protection recordkeeping.

3. How we use data

  • Operate the Service and deliver purchased digital content.
  • Process payments, issue receipts and manage subscriptions.
  • Communicate with you about your account, orders, and support requests.
  • Send marketing communications (with your consent where required); every marketing email includes a one-click unsubscribe link.
  • Detect, prevent and address fraud, abuse and security incidents.
  • Comply with legal obligations and enforce our Terms.

4. Processors and third parties

We share data only with vetted processors under written agreements:

  • Stripe, Inc. — payment processing, chargebacks, fraud prevention.
  • Supabase / Lovable Cloud — database, auth, storage, hosting infrastructure.
  • Cloudflare, Inc. — CDN, edge runtime, DDoS protection.
  • Resend — transactional and marketing email delivery.
  • Meta Platforms, Inc. — advertising, Meta Pixel and Conversions API (hashed identifiers only; see Section 6).
  • OpenAI, Anthropic and similar — AI model providers powering AI features. We do not send them your account credentials or payment data.

We do not sell your personal data. We do not share data with third parties for their own marketing without your consent.

5. International transfers

Some processors are located outside the EEA/UK (including the United States). Transfers are protected by appropriate safeguards, primarily the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework certification of the recipient.

6. Advertising, Meta Pixel and Conversions API

With your consent, we use the Meta Pixel and the Meta Conversions API to measure conversions and improve advertising performance. We send Meta hashed identifiers (e.g. SHA-256 of email) and event data (e.g. Purchase, InitiateCheckout). You can withdraw consent at any time via the cookie banner or by using the "Do Not Sell or Share My Personal Information" mechanism (CCPA), which we honor globally.

7. Retention

  • Account data: for as long as your account is active, plus up to 24 months after closure for dispute resolution.
  • Purchase & tax records: up to 10 years, as required by applicable tax and accounting law.
  • Marketing data: until you unsubscribe or withdraw consent, plus a short suppression period.
  • Support logs: up to 24 months.
  • Server & security logs: up to 12 months.

8. Your rights (GDPR / UK GDPR)

  • Access, rectification, erasure, restriction, portability, objection.
  • Withdraw consent at any time (without affecting past processing).
  • Lodge a complaint with your local supervisory authority.

To exercise your rights, email privacy@sapienbase.com. We respond within 30 days.

9. Your rights (California / CCPA-CPRA)

California residents have the right to know, delete, correct, and opt out of the sale/sharing of personal information, and to limit the use of sensitive personal information. We do not sell personal information for money and treat cross-context behavioral advertising as "sharing" — you can opt out globally by using the cookie banner or by emailing privacy@sapienbase.com. We do not discriminate against consumers who exercise their rights.

10. Children

The Service is not directed to and may not be used by anyone under 18. We do not knowingly collect data from minors. If you believe a minor has provided us data, contact us and we will delete it.

11. Security

We use industry-standard measures: TLS in transit, encryption at rest for the database, hashed passwords, role-based access, least-privilege secrets, activity logging and regular security reviews. No system is 100% secure; you use the Service at your own risk.

12. Breach notification

In the event of a personal-data breach likely to result in a risk to your rights, we will notify affected users and, where required, the competent supervisory authority within 72 hours of becoming aware of it.

13. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be announced by email or in-app notice with at least 30 days' notice.

14. Contact