1. Scope, controller and contact
This review draft covers the SoulFul GLO website, mobile application and proposed website subscription integration. The legal operator/controller name, registered address and applicable contact requirements must be confirmed by the owner; the existing unverified “LLC” description is not treated as established fact. For privacy requests contact Contact Us. This draft has no effective date until approved.
2. Account, website and support information
Account services use information such as email, sign-in identifiers and account verification status. Website requests may generate IP address, device/browser and request logs. The Contact Us form requests first name and email, with optional last name and phone. Submitted contact details are relayed through the hosting mail service to support@soulfulglo.com and soulfulhealing.fareast@gmail.com. The relay uses a keyed IP hash for abuse controls. Do not submit passwords, payment-card numbers or unnecessary health information.
3. Paddle payment information
When a Paddle purchase is available and you use it, Paddle collects the payment and billing information needed for the transaction, tax, fraud controls, receipts and billing support. SoulFul GLO receives relevant purchase identifiers and subscription status to provide access; the website integration is not designed to receive full card details. Paddle processes information under its own Privacy Notice and is not described here solely as our processor.
4. RevenueCat subscription records
RevenueCat is used for subscription and entitlement management. The proposed web flow links a SoulFul GLO account identifier with provider product, customer, transaction and subscription records, purchase/expiry status and related events. These records support access, restoration and support. A browser purchase callback alone does not establish entitlement. Review RevenueCat’s Privacy Policy. Website integration remains subject to pre-launch verification.
5. Firebase and Google services
Firebase supports account authentication and application data services. The proposed web integration uses verified account identifiers, email verification and subscription status records to bind purchases to the correct account. Google processes service information under its applicable terms; see Firebase privacy information. Actual enabled services, storage locations, retention and contractual roles require owner confirmation before approval.
6. Journal, wellness and health information
Depending on the features and permissions you choose, the app may handle journal content, activity records and connected health information. These can be sensitive. This website billing update does not authorise sending journal entries or health readings to Paddle for checkout or to advertising systems. The owner must verify actual on-device/cloud handling, permission flows and any sharing before this draft becomes effective; it does not claim all data stays on the device.
7. Analytics, cookies and embedded content
The current website includes Google Analytics and embedded media, which can process device, interaction and network information. Account and language features may use browser storage. Consent requirements, exact cookies, advertising features and retention must be audited before approval. This draft does not claim that tracking waits for consent or that an unimplemented opt-out control exists. See Google’s Privacy Policy for Google services.
8. Purposes, legal bases and sharing
Information supports account access, content delivery, verified subscriptions, support, fraud prevention and required recordkeeping. Applicable legal bases may include contract performance, legal obligations, legitimate interests and consent where required. The owner and lawyer must map each actual purpose to its lawful basis. Relevant service providers include hosting/email services, Google/Firebase, RevenueCat and Paddle; their roles and cross-border safeguards must be verified. Disclosure may also be necessary for valid legal requests or a properly notified business transfer.
9. Retention, security and deletion
Use account deletion controls or contact support to request deletion. Subscription cancellation is separate. Some transaction or security records may need to be retained for legal obligations or dispute handling; no unverified fixed retention or deletion deadline is promised here. Access controls and secure transport reduce risk but cannot guarantee perfect security. The owner must approve a category-specific retention schedule and verify provider deletion and backup handling.
10. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to processing, obtain a copy of information or withdraw consent, and complain to a competent regulator. Contact support@soulfulglo.com; proportionate identity verification may be needed. Withdrawing consent does not reverse earlier lawful processing. App permissions can be reviewed in device settings. Jurisdiction-specific rights, appeals and representative details require legal review.
11. Children, changes and approval
Age requirements, parental-consent procedures and regional child-privacy obligations must be verified before approval. A material policy change should be communicated through an appropriate notice, with consent where required. This draft replaces neither consumer rights nor a required consent process. Owner verification, qualified legal review, reviewed translations and an effective date remain outstanding.