1. Who is responsible
Minderse, UAB is the data controller for personal data processed through selfaxes.com. You can reach our privacy contact at [email protected].
2. What we collect
We keep collection to what the service needs:
- Test data: the gender you pick for the illustrations, your answers, and the scores and persona we compute from them.
- Contact data: the email address you enter before your results, and the name on your card if you type one in.
- Account data: your email, a hashed password, your membership status and the dates of your trial and renewals.
- Payment data: order id, amount, currency, card brand and the last four digits, all supplied by our payment provider. Full card numbers never reach our systems.
- Technical data: IP address, device and browser type, the pages you visit and the steps you complete, plus identifiers in cookies and your browser storage (see the Cookie Policy).
- Campaign data: where you came from (utm parameters, click ids such as fbclid) when you arrive from an ad or a link.
3. Why we use it and on what basis
To run the test and show your results, to deliver your report and membership, to take payment and to send receipts and account emails: performance of our contract with you.
To keep the service secure, prevent fraud and duplicate charges, and understand how the funnel performs: our legitimate interest in running a reliable service.
To measure advertising and show you relevant ads on other platforms: your consent where the law requires it (EEA, UK and Switzerland), otherwise our legitimate interest. You can refuse or withdraw consent at any time.
To send you reminders and news by email after you leave an email address: our legitimate interest in following up on a request you started, with an unsubscribe link in every message.
4. Who processes data for us
We use a small number of providers, each bound by a data processing agreement:
- Solidgate: payment processing, subscriptions and fraud screening.
- Meta Platforms: advertising measurement through the Meta Pixel and the Conversions API. Where consent is required, the pixel only runs after you accept; server-side events use hashed identifiers.
- Klaviyo: email delivery for results reminders and membership emails.
- Resend: transactional email such as receipts, password resets and cancellation confirmations.
- Microsoft Clarity: anonymised session analytics to improve the pages, loaded only after consent where consent is required.
- Our hosting provider (DigitalOcean) and database hosting, where the application and its data run.
5. International transfers
Some providers process data outside the EEA and the UK, including in the United States. Where that happens we rely on the European Commission standard contractual clauses or the UK addendum, plus the providers own certifications where available.
6. How long we keep it
- Test results without an account: 12 months, then deleted or fully anonymised.
- Account and results data: until you delete your account or ask us to, then removed within 30 days.
- Order and invoice records: as long as tax and accounting law requires, typically 7 to 10 years.
- Funnel and tracking events: 24 months.
- Emails you send to support: 3 years after the last message.
7. Your rights (GDPR and UK GDPR)
You can ask to access, correct, delete or receive a copy of your data, restrict or object to how we process it, and withdraw consent at any time without affecting what happened before. Write to the address above; we answer within one month. You also have the right to complain to the supervisory authority where you live.
The quickest route for most requests is your account: the membership page lets you delete your account and results yourself.
8. California residents (CCPA/CPRA)
You have the right to know what personal information we collect and how it is used, to delete it, to correct it, and not to be discriminated against for using these rights. We do not sell personal information. Advertising pixels can count as "sharing" for cross-context behavioural advertising; you can opt out by choosing "Only essential" in the cookie bar, by enabling a Global Privacy Control signal in your browser, or by emailing us.
9. Cookies and similar technologies
The Cookie Policy lists every cookie and browser storage key we use and how to change your choice.
10. Children
The service is for adults. We do not knowingly collect data from anyone under 18. If you believe a minor has used it, contact us and we will delete the data.
11. Security
Data travels over TLS, passwords are stored as salted hashes, access to production systems is limited to the people who need it, and payments are handled by a PCI DSS certified provider. No system is perfectly secure; if a breach affects you we will tell you and the relevant authority as the law requires.
12. Changes
We may update this policy. The date at the top shows the current version. For significant changes we email account holders before they apply.