Privacy policy
Last updated: June 10, 2026
1. Data controller and scope
This policy applies to the Soulmaper website (soulmaper.com) and the Soulmaper mobile app. Your personal data is processed in accordance with Turkish Law No. 6698 (KVKK) and the GDPR (EU/EEA), and, where applicable, global data protection regulations such as the CCPA/CPRA (California). You can reach the data controller at support@soulmaper.com.
2. Data we collect
Account data: the email address and name provided when you sign in with Google or Apple; we do not collect a separate email/password. Content data: birth date, time and place; the palm photo you upload. Usage and device data: analytics cookies and usage statistics only with your explicit consent; error logs. Payment data: web payments are processed by Lemon Squeezy as Merchant of Record; your card details never reach our servers.
3. Purposes and legal bases
We process your data for the following purposes and on the following bases: • Creating your account and providing the Service (generating your readings, recognizing your subscription) — performance of a contract (GDPR art. 6(1)(b)). • Complying with legal obligations (tax, record-keeping) — legal obligation (art. 6(1)(c)). • Security, fraud prevention and service improvement — legitimate interest (art. 6(1)(f)). • Analytics cookies and marketing communications — explicit consent (art. 6(1)(a)); you may withdraw consent at any time.
4. Cookies and consent
Only cookies strictly necessary for the site's operation are enabled by default. Analytics cookies never run without your explicit consent; the default choice in the cookie notice is 'decline', and you can change your preference at any time.
5. Who we share data with
Your data is shared only to the extent necessary to provide the Service, with these processors: Supabase (authentication and database), Google and Apple (sign-in providers), Lemon Squeezy (payments, Merchant of Record), PostHog (consent-based analytics) and Sentry (error logs). We never sell your data to third parties.
6. International data transfers
Our service providers' servers may be located abroad (e.g. in the EU and the US). Transfers are made under Standard Contractual Clauses (SCCs) and equivalent safeguards under the GDPR, and under mechanisms compliant with art. 9 of the KVKK.
7. Retention
Account data is kept while your account is active. When you delete your account, your personal data is deleted or irreversibly anonymized within a reasonable period, subject to legal retention obligations (e.g. invoice records). Palm photos are kept only as long as the analysis requires.
8. Your rights
Depending on your jurisdiction (KVKK art. 11, GDPR arts. 15-22, CCPA/CPRA), you have the rights of access, rectification, erasure ('right to be forgotten'), restriction of processing, data portability, objection and withdrawal of consent; under the CCPA, also the right to opt out of the 'sale' of data (we do not sell your data) and the right to non-discrimination. Send requests to support@soulmaper.com; we respond within the statutory deadlines after verifying your identity.
9. Right to complain
You retain the right to lodge a complaint with the Personal Data Protection Authority in Türkiye (KVKK), or with the data protection supervisory authority of your country of residence in the EU/EEA.
10. Security
Your data is encrypted in transit with TLS; access is restricted through technical and administrative measures including row-level security (RLS), access controls and the principle of least privilege. In the event of a data breach, we notify the relevant authorities and affected users in line with our legal obligations.
11. Automated processing and profiling
Your readings are generated automatically by AI from the data you provide. These outputs are for entertainment and personal guidance only; we do not make automated decisions that produce legal effects concerning you or similarly significantly affect you.
12. Children's privacy
The Service is not directed at users under 18. Data we identify as belonging to a user under 18 is deleted without delay.
13. Changes
This policy may be updated from time to time; material changes are announced on the site and the 'Last updated' date is revised.
14. Contact
For all privacy questions and requests: support@soulmaper.com