Last updated: July 24, 2026
Reading this counts toward your daily meditation time…
This Privacy Policy explains what data I collect about you when you use tarotfellow.com (the “site”) or the Tarot Fellow mobile app (the “app”), why I collect it, who I share it with, and what rights you have over it. I am Rick Chiantaretto, doing business as Tarot Fellow, and “I”, “me”, and “my” refer to me as the business operator and data controller.
Tarot Fellow is operated in the United States. Information you provide will be transferred to and stored in the United States. By using the site or app, you consent to that transfer.
Who Can Use Tarot Fellow
Tarot Fellow’s tarot and spiritual content is provided for entertainment and personal-reflection purposes only. The app is intended for people 13 years of age or older. If you are under 18, you confirm that you have your parent or guardian’s permission to use it. I do not knowingly collect personal information from anyone under 13; if I become aware that I have, that data will be immediately deleted. Contact me to request removal of any such data.
What I Collect and Why
You do not need to provide any personal data to browse the site. Some features β placing an order, creating an account, using the app, requesting a reading β require information so I can deliver the service.
Account and profile
When you create an account I store your name, email address, password (as a one-way hash β I never see your plain password), and, if you choose to share it, your birthday. I use this to sign you in, address you correctly, send you order confirmations, and offer a small birthday surprise.
Orders and payments
When you buy something I store your billing and shipping address, the items in the order, the total, the carrier and tracking number, and a reference to the payment. Card payments are processed by my payment processor β I never see or store your full card number, CVC, or PIN. Card data is entered into a secure field hosted by the payment processor and tokenized on their side. I do receive the last four digits and card brand for receipts and dispute handling.
Mobile app data
When you use the Tarot Fellow iOS app I additionally process:
- A secure session token that authenticates your device to my server.
- A device-level preference for Face ID / Touch ID sign-in. The actual biometric data never leaves your device β only the on/off preference is stored.
- A push-notification token (once push is enabled) so I can send notifications you’ve opted in to. The token is handled through Google Firebase Cloud Messaging and delivered to your device by the Apple Push Notification service. Tokens are tied to your account so I can stop sending you notifications if you sign out or delete the app.
- Usage and diagnostic data through Google Firebase: app analytics (Firebase Analytics: which features and screens you use, shop searches, add-to-cart and purchase events) and crash and performance diagnostics (Firebase Crashlytics: iOS version, device model, crash logs). This is used only to operate and improve the app; it is not used for advertising, not sold, and not shared with data brokers.
- Your analytics choice: you can turn app usage and crash analytics on or off anytime in the app under Account > Settings (“Share usage data”). In the EEA, UK, and Switzerland, app analytics is off until you opt in.
Readings and Card of the Day
When you draw a Card of the Day or generate a reading, I store: the question you asked (if any), the significator and cards drawn, the AI-generated interpretation, and the timestamp. This is so you can revisit the reading from “My Readings”. I do not sell, share, or use your reading questions for anything other than producing your reading and saving it back to you.
To contextualize the interpretation, the question and card data are sent to my AI provider (Anthropic) for processing. See “Third-Party Processors” below.
Comments and contact form
If you leave a comment on the site I store the data shown in the comment form, your IP address, and your browser user-agent (used to help with spam detection). An anonymized hash of your email address may be sent to an avatar lookup service to display a profile picture alongside your comment. After your comment is approved, your name (and avatar, if any) is publicly visible.
If you submit the contact form, the submission is stored and forwarded to me. It includes your IP address, the submission timestamp, the name, email, website, and message you provided.
Non-personal site data
I may collect non-personal information including the browser you use, your device type, operating system, internet service provider, and details about how you connect β used for performance tuning and security.
If you are located in the European Economic Area (EEA) or the United Kingdom, I am regulated under the General Data Protection Regulation (GDPR) and am the controller of your personal information for the purposes of those laws.
How I Use Your Data
- To deliver the services β fulfilling orders, generating readings, sending you the Card of the Day, sending receipts and shipping notifications.
- To run my account β taxes, accounting, fraud and abuse prevention.
- To improve the site and app β performance, debugging, and product decisions, using aggregated and de-identified data wherever possible.
- To communicate with you β order updates, customer-service responses, and (if you’ve opted in) marketing emails or push notifications.
Cookies
I collect domain information and “cookies” (small files saved on your hard drive by your web browser) to analyze website performance, track usage patterns, save information from your previous visits, and customize your experience.
Required technical or functional cookies
Some cookies make sure parts of the site work properly and that your preferences are remembered β so, for example, items stay in your shopping cart until you’ve paid.
Analytical cookies
I use analytical cookies to understand how the site is used and to optimize the experience.
Comment cookies
If you leave a comment, you can opt in to saving your name, email, and website in cookies for your convenience next time. These last no longer than one year.
Login cookies
If you have an account and log in, I’ll set a temporary cookie to check whether your browser accepts cookies (no personal data; discarded when you close the browser). I’ll then set additional cookies to save your login and screen-display choices: login cookies last two days, screen-option cookies a year. “Remember Me” extends login to two weeks. Logging out removes the login cookies. If you edit or publish an article, an additional cookie storing the post ID is saved and expires after one day.
Social media buttons
The site includes share buttons for Facebook, X (formerly Twitter), Instagram, YouTube, and TikTok. Those buttons load code from those platforms and may place cookies of their own. The platforms may also store and process information to show you targeted content. Please review each platform’s privacy policy to understand what they do with that data β I retrieve as little as possible and anonymize where I can.
Third-Party Processors
I rely on the following services to operate Tarot Fellow. Each has its own privacy policy:
| Service | Details & Privacy Policy URL |
|---|---|
| Payment Processors (Stripe, PayPal) | Card and PayPal payments. Stripe: stripe.com/privacy. PayPal: paypal.com/us/legalhub/privacy-full |
| Anthropic | AI provider for the Card of the Day and personalised reading interpretation contextualization and assistance. Your question, significator, and drawn cards are sent to Anthropic’s AI model so it can write the interpretation. anthropic.com/privacy |
| Shipping Carriers (USPS, UPS, FedEx) | Your shipping address, name, weight, and dimensions are shared to print labels and track packages. |
| Google Firebase (mobile app) | First-party analytics (Firebase Analytics), crash and diagnostic reporting (Firebase Crashlytics), and push-notification delivery (Firebase Cloud Messaging) in the iOS app. Used only to operate and improve the app; not used for advertising, not sold, and not shared with data brokers. firebase.google.com/support/privacy |
| Apple (Push Notifications & In-App Purchases) | Final delivery of push notifications to your iOS device, and processing of in-app reading-credit purchases. I receive confirmation that a purchase occurred, not your card details. apple.com/legal/privacy |
| Google Analytics & Google Ads | Site analytics and advertising measurement, managed through Google Tag Manager. Purchase events, page views, and conversion data are sent to Google. These advertising and measurement tools run on the tarotfellow.com website only; the iOS app uses no advertising or retargeting. policies.google.com/privacy |
| Meta (Facebook) Pixel | Advertising and retargeting on the tarotfellow.com website only (not used in the app). Page views and purchase events are sent to Meta to measure ad performance and enable retargeting. facebook.com/privacy/policy |
| Cloudflare | Bot protection and security. Every page request passes through Cloudflare, which processes your IP address and request headers to detect and block malicious traffic. cloudflare.com/privacypolicy |
| Google reCAPTCHA v3 | Spam and bot prevention on the checkout page. reCAPTCHA collects hardware and software information (device and application data) and sends it to Google for analysis. policies.google.com/privacy |
| GoAffPro | Affiliate program management. If you arrive at the site through an affiliate link, GoAffPro records the referral source and any resulting conversion. goaffpro.com/privacy-policy |
| CusRev (Customer Reviews) | Product and store review collection and display. Reviewer name and review content are shared with CusRev to power the review system. cusrev.com/privacy-policy |
| Website Infrastructure Provider | Site hosting, comments, and security. automattic.com/privacy |
What Specific Services Track
Comment Likes
Accessible to users logged in to TarotFellow.com. To process a comment like, I use your user ID/username, the local site-specific user ID (if you’re signed in), and a true/false data point for whether you liked a specific comment. If you perform a like action from one of my mobile apps, the following is additionally tracked: IP address, user agent, timestamp of event, blog ID, browser language, country code, and device info.
Contact Form
The submission is stored in the site’s database and emailed to me. The email includes the submitter’s IP address, timestamp, name, email, website, and message. Post and post-meta data tied to the submission are also synced; the original IP and user-agent are stored in post meta.
Google Analytics
Please refer to the Google Analytics documentation for the specific data it collects. Purchase events send order number, product ID and name, product category, total cost, and quantity. Page views and (potentially) video plays are sent, along with cart additions/removals, product listing views and clicks, product detail views, and purchases.
Likes
To process a post like, I use: IP address, user ID, post ID, user agent, timestamp, browser language, and country code.
Protect
To check login activity and potentially block fraudulent attempts, I use: the attempting user’s IP, the attempted email/username, and all IP-related HTTP headers. Failed login attempts are recorded (including IP and user agent) and a cookie is set for one day to remember whether a user has completed a captcha. The Tarot Fellow app additionally enforces a per-IP rate limit on login attempts.
Search
Any visitor-chosen search filters and query data are used to process the search on my servers.
Sharing
When sharing content via email I use the sharing party’s name and email address (pulled from your account if you’re logged in), IP address (for spam checking), user agent (for spam checking), and the email body. Google reCAPTCHA v3 is active on the checkout page; your IP address and device data are shared with Google as part of spam and bot detection.
Simple Payments
Payment processing is handled by my payment processors (Stripe and/or PayPal). All credit-card data is entered through hosted fields or pop-up windows secured by the payment processor. No credit-card data is entered on tarotfellow.com or stored on my servers.
Subscriptions
To start a subscription I use the subscriber’s email and the ID of the post or comment being subscribed to. For new subscriptions I also collect basic server data β HTTP request headers, IP address, and the requested page URL β exclusively to monitor for abuse and spam. A functionality cookie is set for 347 days to remember an active subscriber’s choices.
Shop and Checkout Services
For payment processing: purchase total, currency, and billing information. For taxes: cart value, shipping value, and destination address. For checkout shipping rates: destination address, purchased product IDs, dimensions, weight, and quantities. For shipping labels: name, address, and the dimensions, weight, and quantities of products purchased.
How Long I Keep Your Data
- Account data. Kept as long as your account is active.
- Order records. Kept indefinitely for tax, accounting, and dispute purposes. If you delete your account, personal details on past orders are anonymized (replaced with “Anonymous” and a placeholder email) but the financial record itself stays.
- Reading history. Kept as long as your account is active. Deleted when you delete your account.
- Card of the Day cache. Cleared on account deletion.
- Push tokens and per-device app data. Cleared on account deletion or when you sign out.
- Comments. Retained indefinitely so I can recognize and approve follow-up comments automatically instead of holding them in a moderation queue.
- User profiles for registered users. Stored in the user profile. You can see, edit, or delete your information at any time (you cannot change your username). Website administrators can also see and edit that information.
- Security logs and failed-login records. Kept up to one year for abuse prevention.
Your Rights
You have rights over your personal data. Depending on where you live they include:
- Access. Request a copy of the personal data I hold about you.
- Correction. Request that I correct anything inaccurate.
- Deletion. Request that I delete your data (subject to data I’m obliged to keep for legal, tax, or security reasons).
- Portability. Receive your data in a structured, machine-readable format.
- Restriction or objection. Ask me to stop or limit certain processing.
- Withdrawal of consent. Where processing is based on consent (e.g., marketing email), you can withdraw it at any time.
- Complaint. EEA/UK residents have the right to complain to their local data-protection authority.
Account deletion (mobile app)
You can delete your Tarot Fellow account directly from the iOS app β Account β Delete my account. Deletion removes your account, profile, birthday, saved readings, reading credits, Card of the Day history, wishlist, saved address, notification settings, and push tokens. Past order records remain for tax and accounting purposes but personal details on them are anonymized.
California residents (CCPA / CPRA)
If you live in California you have the right to know what categories of personal information I collect, the right to request access to and deletion of your personal information, the right to correct inaccurate personal information, and the right not to be discriminated against for exercising these rights. I do not sell or share your personal information for cross-context behavioral advertising.
How to make a request
To exercise any of these rights please use the site’s contact form and include “GDPR” or “CCPA” in the subject line if relevant. I’ll verify the request and respond within the timeframe your law requires (generally 30 days).
How I Protect Your Data
I have security plans and software in place to protect your data, and I monitor for breaches. Passwords are stored as one-way hashes. Payment data is tokenized by the payment processor and never touches my servers. The mobile app uses signed, short-lived session tokens. Failed login attempts are rate-limited. I do not publish all of my security infrastructure, but a more detailed report β including breach-response procedures β can be provided on request.
International Transfers
Tarot Fellow is operated in the United States. If you are in the EEA, UK, or another jurisdiction with restrictions on transferring personal data abroad, by using the services you consent to your data being transferred to and processed in the United States. I take reasonable steps to ensure your data continues to receive equivalent protection in transit and at rest.
Changes to This Policy
I may update this Privacy Policy from time to time. When I do, I’ll update the “Last updated” date at the top of this page. If a change is material β meaning it meaningfully affects your rights or how I use your data β I’ll do my best to notify you in the app or by email before it takes effect.
Questions?
If you have any questions or concerns about this Privacy Policy, the information I hold about you, or you wish to change your personal information in my records, please contact me through tarotfellow.com/contact (please include “GDPR” or “CCPA” in the subject line if relevant).
