Privacy Policy
This policy explains what personal data the Signos Ifá application processes, for what purpose, and what your rights are, in accordance with the General Data Protection Regulation (GDPR, EU 2016/679) and Spain’s Organic Law 3/2018 (LOPDGDD).
1. Data controller
The controller is the Oluwo Michel Muñoz (Òṣé Fún Oní Ṣàngó, Ọmọ Odù), author and editor of the application.
2. What data we collect
We only process the data necessary for you to have an account:
- Email address, which you provide when registering or signing in.
- Password, which is always stored encrypted; never in readable text.
- Status of your subscription (if in the future you subscribe to a paid version).
We do not collect your real name, location, contacts, or browsing data for advertising purposes. The app does not show advertising or sell your data to third parties.
3. What we use your data for
- Create and manage your account and sign you in.
- Give you access to the content and, where applicable, to the paid versions you subscribe to.
- Handle your support inquiries.
4. Legal basis
The processing is based on your consent (when creating the account) and on the performance of the service you request (GDPR, art. 6.1.a and 6.1.b).
5. With whom it is shared
To provide the service we use providers that act as data processors:
- Supabase — authentication and database, with servers in the European Union (Ireland).
- RevenueCat and the Google Play and App Store stores — only if you contract a subscription from the app, to process the payment and validate the purchase.
If you contract a subscription directly on our website (signosifa.com), payment is handled by Stripe (Link), which does not act as processor but as seller (Merchant of Record) and independent controller — see the details just below.
No data transfers are made for commercial purposes outside these services.
Web payments (Merchant of Record). The sale and collection of the subscriptions contracted on signosifa.com is carried out by Stripe through Link (“Sold through Link”), which acts as seller (Merchant of Record) and as independent controller of the payment operation data (card data —under PCI-DSS standard—, billing, taxes, and order management). Signos de Ifá does not store or have access to your full card number. On our part, as controllers of your account and the service, we process only the data necessary to activate and manage your subscription (email, plan, customer and subscription identifiers, status, and activation history). Legal basis: performance of the contract (art. 6.1.b GDPR). Stripe may process data outside the EEA with appropriate safeguards (standard contractual clauses). See Stripe’s privacy policy (stripe.com/es/privacy).
6. How long they are kept
We keep your data as long as you maintain the account. If you delete it, your data is deleted from our systems, except for what the law requires us to keep.
7. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction and portability at any time:
- By writing to signosifa@gmail.com.
- Or deleting your account from the app itself: account menu (top icon) → «Delete my account». This action permanently deletes your data.
If you believe we have not properly addressed your request, you can file a complaint with the Spanish Data Protection Agency (www.aepd.es).
8. Minors
The application is not directed to minors under 14 years of age and we do not knowingly collect data from minors.
9. Security
We apply reasonable technical measures: encrypted connections, encrypted stored passwords, and restricted access to the database.
10. Changes to this policy
If we update this policy, we will publish the new version in the app with its update date.
