← iNatalis

Privacy Policy

What we collect, why we collect it, and the control you keep.

Last updated / 27 June 2026

Founder checklist before live launch: replace the legal entity and registered address, confirm the production processor list, and review this with a privacy professional. This page is a practical draft, not legal advice.

This Privacy Policy explains how [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS], handles personal data when you use iNatalis. For the data described here, we act as the data controller. You can reach us at privacy@inatalis.com.

1. Data we collect

  • Birth details: name, birth date, birth time, birth place, and optional gender.
  • Contact details: email address when you ask to be notified, receive a receipt, or contact support.
  • Order details: payment status, report ID, unlock token status, and basic purchase records.
  • Generated content: the natal reading, forecast, PDF metadata, and related chart calculations.
  • Technical data: logs, device and browser information, IP-derived security signals, and operational diagnostics needed to run the service.

2. Why we use it

  • To resolve the birth place, calculate the chart, and generate the reading.
  • To process payment, prevent fraud, and unlock paid access.
  • To deliver email notifications, receipts, and support replies.
  • To secure, debug, monitor, and improve iNatalis.
  • To meet legal, tax, accounting, and dispute-resolution obligations.

3. Legal bases

Where the GDPR applies, we rely on contract performance to prepare and deliver the reading you ordered; consent where you choose to provide optional information or request immediate digital delivery; legitimate interests to secure and improve the service; and legal obligations for tax, accounting, fraud prevention, and dispute handling.

4. Service providers

We use trusted providers to operate iNatalis. They receive only what is needed for their role and process data under their own terms and data processing commitments.

  • Stripe: payments, fraud checks, refunds, disputes, and receipt infrastructure.
  • OpenAI: generation of the written reading from chart and forecast context.
  • Render: backend hosting, database, workers, and operational logs.
  • Vercel: frontend hosting and deployment infrastructure.
  • Resend: transactional email delivery.
  • OpenStreetMap/Nominatim and Photon: birth-place lookup and geocoding.

We do not sell personal data.

5. International transfers

Some providers may process data outside the EU/EEA. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or equivalent recognised mechanisms.

6. Retention

We keep report and order records for as long as needed to deliver the reading, provide support, handle disputes, and meet legal obligations. Generated PDF files may be removed after 90 days. Accounting and payment records may be retained for the period required by law.

7. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, object to, or receive a copy of your personal data, and to withdraw consent where processing is based on consent. You may also have the right to complain to your data protection authority.

To make a privacy request, email privacy@inatalis.com.

8. Cookies and analytics

We use only technologies needed to operate the service unless a cookie banner or consent flow says otherwise. If we add non-essential analytics or marketing pixels, this policy and the consent experience should be updated before launch.

9. Children

iNatalis is intended for adults. We do not knowingly collect personal data from children under 18. If you believe a child has provided data, contact us and we will review and delete it where appropriate.

10. Security

We use reasonable technical and organisational measures to protect the data entrusted to us. No online service can be perfectly secure, but we work to reduce risk through access controls, hosted infrastructure, payment-tokenisation, logging, and operational monitoring.

11. Updates

We may update this policy as the service changes. The date above shows when this version was last revised.