Privacy Policy

1. Who we are

This Privacy Policy describes how Monday Tarot LTD (“Monday Tarot”, “we”, “us”, “our”) collects, uses and protects your personal data when you use our website www.mondaytarot.com (the “Website”) and our related services.

Data controller: Monday Tarot LTD
Contact email: [email protected]

If you have any questions about this Policy or about how we use your data, you can contact us at [email protected].

If Monday Tarot LTD is registered in the UK and you are based in or interact with us from the UK, your personal data will be processed in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.


2. What personal data we collect

We may collect and process the following categories of personal data:

2.1 Data you provide directly

  • Contact details – name, email address and any other details you include when you contact us.
  • Account / booking information (if applicable) – such as login details, your preferences for readings, and communication preferences.
  • Content of communications – emails or messages you send us, feedback, testimonials or support requests.
  • Payment-related information – payments are generally processed by third-party payment providers (e.g. card processors, PayPal, Stripe etc.). We do not store your full card details, but we may receive limited payment metadata from those providers (e.g. transaction ID, status, time, amount).

2.2 Data collected automatically (usage data)

When you visit the Website, we may automatically collect:

  • IP address (which may be truncated or anonymised depending on our analytics setup)
  • Browser type and version, device type, operating system
  • Referring URLs, pages visited, time and date of visit, time spent on pages, click and scroll activity
  • General location (country/region) inferred from your IP (no precise GPS data)

This information is typically collected through cookies and similar technologies (see Section 7).

2.3 Optional information related to readings

If you choose to provide additional context for readings (e.g. personal background, questions, goals, or other information you volunteer), this may also constitute personal data and will be processed in line with this Policy.


3. Why we use your personal data (purposes & lawful bases)

We process your personal data for the following purposes and legal bases:

  1. To provide and manage our services
    • Handling bookings, delivering readings, responding to your enquiries.
    • Legal basis: Performance of a contract or steps taken at your request prior to entering into a contract.
  2. To communicate with you
    • Answering questions, providing customer support, sending service-related notices (e.g. booking confirmations, changes to services).
    • Legal basis: Performance of a contract; legitimate interests (to respond to you and manage our relationship).
  3. To send marketing communications (where applicable)
    • Sending newsletters, updates, offers or new services, only where you have opted in or where allowed by law.
    • Legal basis: Consent; or legitimate interests where permitted (you can opt out at any time).
  4. To improve our Website and services
    • Analysing how visitors use the Website, troubleshooting, testing new features, improving user experience.
    • Legal basis: Legitimate interests (to operate and improve our business and services).
  5. To comply with legal obligations and protect our rights
    • Keeping appropriate records, preventing fraud or abuse, responding to lawful requests from authorities.
    • Legal basis: Legal obligation; legitimate interests (protecting our business and users).

We will only use your personal data for the purposes described above unless we reasonably consider that we need to use it for another compatible purpose. If we need to use it for an unrelated purpose, we will notify you and explain the legal basis.


4. Who we share your data with

We do not sell your personal data.

We may share your personal data with:

  • Service providers / processors
    e.g. hosting providers, email service providers, analytics providers, payment processors, customer support tools. They may only process your data in accordance with our instructions and for the purposes described in this Policy.
  • Professional advisers
    e.g. lawyers, accountants, auditors, where reasonably necessary.
  • Authorities / regulators
    Where required by law or to protect our legal rights (e.g. preventing fraud, responding to lawful requests).
  • Business transfers
    In the event of a merger, acquisition or sale of assets, your data may be transferred as part of that transaction, in which case we will take steps to ensure it remains protected.

5. International transfers

If your personal data is transferred outside the UK or European Economic Area (EEA) (e.g. where our service providers are located overseas), we will ensure that appropriate safeguards are in place such as:

  • Adequacy decisions, or
  • Standard Contractual Clauses (SCCs), or
  • Other mechanisms recognised by applicable data protection law.

6. Data security & retention

We implement appropriate technical and organisational measures designed to protect your personal data against unauthorised access, loss, misuse, or alteration.

We retain your personal data only for as long as necessary for the purposes described in this Policy, and as required by law (e.g. tax/accounting obligations). After this period, we will delete or anonymise your data.

Retention periods may depend on:

  • How long you maintain an active relationship or account with us
  • Our legal obligations
  • The need to resolve disputes or enforce our agreements

7. Cookies & similar technologies

Our Website may use cookies and similar technologies to:

  • Enable core functionality of the site (e.g. navigation, security, session management)
  • Remember your preferences
  • Analyse Website traffic and usage patterns (website analytics)

7.1 What are cookies?

Cookies are small text files stored on your device when you visit a website. They help the site recognise your device and remember certain information about your visit.

7.2 Types of cookies we may use

  • Strictly necessary cookies – required for the basic functioning of the Website (e.g. security, page navigation).
  • Preference cookies – remember your settings or choices (e.g. language or cookie preferences).
  • Analytics cookies – help us understand how visitors interact with the Website so we can improve it (e.g. page views, time on site, navigation paths).

If we use third-party analytics tools (such as Google Analytics), these providers may set their own cookies to collect aggregated statistics about Website usage. We do not use such tools to identify you directly, but the IP and usage data they collect may be considered personal data in some jurisdictions.

7.3 Managing cookies

Most browsers allow you to:

  • View what cookies are stored
  • Delete cookies
  • Block some or all cookies

Please note: blocking essential cookies may affect how the Website functions.

For more information about cookies, you can visit independent resources such as “All About Cookies”.

If we introduce or change specific cookie categories or tools (e.g. marketing pixels), we will update this section and, where required, seek your consent via a cookie banner.


8. Your rights

Depending on where you are located and applicable law, you may have the following rights in relation to your personal data:

  • Right to be informed – to receive clear information about how we use your data (this Policy).
  • Right of access – to obtain a copy of your personal data we hold about you.
  • Right to rectification – to have inaccurate or incomplete data corrected.
  • Right to erasure (“right to be forgotten”) – to request deletion of your personal data in certain circumstances.
  • Right to restrict processing – to request that we limit the way we use your data.
  • Right to data portability – to receive your data in a structured, machine-readable format and transfer it to another controller, where technically feasible.
  • Right to object – to object to processing based on our legitimate interests, and to object to direct marketing at any time.
  • Right to withdraw consent – where processing is based on consent, you may withdraw it at any time (this will not affect processing performed before withdrawal).

To exercise any of these rights, please contact us at [email protected]. We may need to verify your identity before responding.

If UK data protection law applies and you are not satisfied with how we handle your personal data, you also have the right to lodge a complaint with the Information Commissioner’s Office (ICO):

  • Website: ico.org.uk

You may also have similar rights to complain to your local data protection authority if you are based outside the UK.


9. Children’s privacy

Our services and Website are not intended for children under 18. We do not knowingly collect personal data from children under 18. If you believe that a child has provided us with personal data, please contact us and we will delete that information where required by law.


10. Third-party links

The Website may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies before providing any personal data.


11. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services or legal requirements. The updated version will be indicated by a revised “Last updated” date at the top.

We encourage you to review this Policy periodically.


12. How to contact us

If you have any questions about this Privacy Policy, or about how we handle your personal data, please contact:

Monday Tarot LTD
Email: [email protected]