Privacy Policy

    Last updated: February 15, 2026

    1. Introduction

    GOLDEXCODE INNOVATIONS INC., a Delaware corporation ("we", "us", "our") operates the Witch-Book platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our website and services. We comply with the following regulations:

    • EU/EEA: General Data Protection Regulation (GDPR)
    • United Kingdom: UK GDPR & Data Protection Act 2018
    • United States: California Consumer Privacy Act (CCPA/CPRA), Virginia CDPA, Colorado CPA
    • Brazil: Lei Geral de Proteção de Dados (LGPD)
    • Russia: Federal Law No. 152-FZ on Personal Data
    • China: Personal Information Protection Law (PIPL)
    • South Africa: Protection of Personal Information Act (POPIA)
    • Japan: Act on Protection of Personal Information (APPI)
    • South Korea: Personal Information Protection Act (PIPA)
    • Argentina: Personal Data Protection Law No. 25.326
    • Mexico: Federal Law on Protection of Personal Data (LFPDPPP)

    2. Data Controller

    The data controller responsible for your personal data is:

    GOLDEXCODE INNOVATIONS INC.
    A Delaware corporation
    Email: hello@witch-book.com

    For EU/EEA inquiries, you may contact our Data Protection Officer (DPO) at hello@witch-book.com.

    3. Personal Data We Collect

    3.1 Data You Provide

    • Account information: name, email address, password
    • Profile information: display name, avatar, bio, spoken languages, timezone
    • Practitioner data: specialty, experience, social media links, availability
    • Transaction data: booking details, payment information, wallet balances
    • Communications: messages, reviews, blog posts, timeline posts
    • Support inquiries and feedback

    3.2 Data Collected Automatically

    • Device and browser information (type, version, operating system)
    • IP address and approximate geolocation
    • Usage data: pages visited, features used, session duration
    • Cookies and similar tracking technologies (see our Cookie Policy)
    • Referral source and search queries

    3.3 Data from Third Parties

    • Social media profiles when you import content (TikTok, Instagram, Facebook)
    • Payment processor data (Stripe)
    • Authentication providers (if using social login)

    4. Legal Bases for Processing (GDPR / UK GDPR)

    • Contract: Processing necessary to provide our services (Art. 6(1)(b))
    • Consent: Where you have given explicit consent, e.g., marketing communications, cookies (Art. 6(1)(a))
    • Legitimate interest: Fraud prevention, security, analytics, service improvement (Art. 6(1)(f))
    • Legal obligation: Tax, accounting, law enforcement compliance (Art. 6(1)(c))

    5. How We Use Your Data

    • Provide, maintain, and improve our platform and services
    • Process bookings, payments, and transactions
    • Verify practitioner identities and qualifications
    • Send transactional emails (booking confirmations, receipts)
    • Send marketing communications (with consent)
    • Provide AI-powered tools (tarot readings, dream interpretation, etc.)
    • Moderate content and ensure community safety
    • Detect and prevent fraud, abuse, and security incidents
    • Comply with legal obligations
    • Generate aggregated, anonymized analytics

    6. Data Sharing & Disclosure

    We do not sell your personal data. We may share data with:

    • Service providers: hosting, payment processing, email delivery, AI model providers — bound by data processing agreements
    • Practitioners: When you book a session, the practitioner sees your name, booking details, and any notes you provide
    • Legal authorities: When required by law, court order, or to protect rights and safety
    • Business transfers: In the event of a merger, acquisition, or sale of assets

    7. International Data Transfers

    Your data may be transferred to and processed in countries outside your jurisdiction. We ensure adequate protection through:

    • EU Standard Contractual Clauses (SCCs)
    • UK International Data Transfer Agreement (IDTA)
    • Adequacy decisions where applicable
    • Binding Corporate Rules (BCRs) of our service providers

    Russia (152-FZ): Primary storage and processing of Russian citizens' personal data is performed on servers located within the Russian Federation where applicable.

    8. Data Retention

    • Account data: Retained while your account is active, plus 30 days after deletion request
    • Transaction records: 7 years (legal/tax obligations)
    • Usage logs: 12 months
    • Marketing consent records: Duration of consent plus 3 years
    • Content you publish: Until you delete it or your account is closed

    9. Your Rights

    9.1 GDPR / UK GDPR Rights (EU/EEA/UK)

    • Right of access (Art. 15)
    • Right to rectification (Art. 16)
    • Right to erasure / "right to be forgotten" (Art. 17)
    • Right to restrict processing (Art. 18)
    • Right to data portability (Art. 20)
    • Right to object (Art. 21)
    • Right not to be subject to automated decision-making (Art. 22)
    • Right to withdraw consent at any time
    • Right to lodge a complaint with a supervisory authority

    9.2 CCPA/CPRA Rights (California, USA)

    • Right to know what personal information is collected
    • Right to delete personal information
    • Right to opt-out of sale/sharing of personal information
    • Right to non-discrimination for exercising your rights
    • Right to correct inaccurate personal information
    • Right to limit use of sensitive personal information

    We do not sell personal information. To exercise your rights, email hello@witch-book.com or use the settings in your account.

    9.3 LGPD Rights (Brazil)

    • Confirmation of processing and access to data
    • Correction of incomplete or inaccurate data
    • Anonymization, blocking, or deletion of unnecessary data
    • Data portability
    • Information about shared data
    • Right to revoke consent

    9.4 Russian Federation (152-FZ)

    • Right to access and obtain information about processing
    • Right to correction, blocking, or deletion
    • Right to withdraw consent
    • Right to file complaints with Roskomnadzor

    9.5 Other Jurisdictions

    If you are located in China (PIPL), South Africa (POPIA), Japan (APPI), South Korea (PIPA), Argentina, Mexico, or any other jurisdiction with data protection laws, you are entitled to exercise your rights under applicable local legislation. Contact us at hello@witch-book.com.

    10. Children's Privacy

    Our services are not intended for children under 16 (or the minimum age required by applicable law). We do not knowingly collect data from children. If we learn that we have collected personal data from a child, we will delete it promptly.

    11. Security

    We implement industry-standard security measures including:

    • Encryption in transit (TLS/SSL) and at rest
    • Row-level security policies for database access
    • Regular security audits and vulnerability assessments
    • Access controls and authentication safeguards
    • Incident response procedures

    12. Changes to This Policy

    We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice on our platform. Continued use of our services after changes constitutes acceptance.

    13. Contact Us

    For questions, concerns, or to exercise your data rights:

    • Email: hello@witch-book.com
    • DPO (EU/EEA): hello@witch-book.com