Notifications (Click to mark read)
Apps
0 / 0




Change cookie settings

Privacy Notice

Controller: Wisdom of Gaia Ltd ("we", "us", "our")
Controller representative: David Relf
Registered office: 14/2e Docklands Business Centre, 10–16 Tiller Road, London, England, E14 8PX
Company status/type: Active — Private limited company (incorporated 19 September 2025)
Website: https://wisdomofgaia.com/
Privacy contact: [email protected]
ICO registration number: [add ZA-number once issued]

Summary of Google Data Usage

When you use Sign in with Google, we only access your basic profile information (name and email address). We do not store your Google password, we do not access Google Drive or other Google apps, and we never sell or share your Google data with third parties. Full detail is provided in Section 4 below. Our use of Google user data adheres to the Google API Services User Data Policy, including the Limited Use requirements.

1) What this notice covers

This notice explains what personal data we collect, why we collect it, how we use it, who we share it with, how long we keep it, and the rights available to you under the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR) where applicable, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations (PECR), and applicable US state privacy laws (including the California Consumer Privacy Act as amended by the California Privacy Rights Act, "CCPA/CPRA", and comparable laws in other US states). It applies to all visitors and account holders of wisdomofgaia.com and any associated apps or subdomains.

2) How we collect data

  • Directly from you: when you browse, create an account, purchase or subscribe, post in community areas ("Groves"), use tools/apps, complete profile fields, or contact us.
  • Automatically: via cookies and similar technologies (where you consent) and through server logs for security and diagnostics.
  • From third parties: payment providers, email delivery providers, anti-fraud/security tools, and — if you choose to use it — Google Sign-In (see Section 4 below for details specific to Google account data).

3) What we process

  • Account & profile: name, username, email address, password hash and salt (we never store plain-text passwords), date of birth, birth place/time (for astrology features, where provided), membership tier, avatar/profile photo, bio, preferences, and settings.
  • Sign-in method data: if you use email/magic-link sign-in, a hashed verification token; if you use Google Sign-In, your Google account ID, name, and email address as returned by Google (see Section 4).
  • Transactions: order IDs, subscription tier and status, amounts, timestamps, and limited payment metadata via Stripe. We do not store full card numbers on our own servers.
  • Community content: posts, messages, journal entries, readings, saved insights, and uploads you choose to provide within the Groves or your personal space.
  • Support communications: messages you send us and related metadata (e.g. timestamps, subject).
  • Technical & usage data: IP address, device/browser type, pages and features used, referral source, approximate location derived from IP address, and cookie identifiers (where consented).
  • Compliance records: consent and withdrawal records, marketing suppression lists, and audit/security logs.

Special category data: we do not intentionally collect special category data (e.g. health, religious belief, sexual orientation) as defined by UK/EU GDPR. Please avoid submitting sensitive information about yourself in free-text fields (such as journal entries) unless you specifically intend to and understand this is at your own discretion.

4) Google Sign-In and Google API Services User Data

We offer "Sign in with Google" as an optional way to create an account or log in. If you choose this option, here is exactly what we access, how we use it, who (if anyone) sees it, how we protect it, and how it is deleted:

What we access: your Google account's name, email address, and basic profile information, via the openid, email, and profile scopes only. We do not request or access your Google Drive, Gmail, contacts, calendar, photos, or any other Google service or data.

How we use it: solely to create or match your Wisdom of Gaia account, authenticate you on return visits, and pre-fill your name and email on your profile. We do not use Google user data for advertising, ad targeting, or to build a profile of you for any purpose unrelated to providing the Wisdom of Gaia service you signed up for.

Who we share it with: your Google-sourced name and email are stored in the same secure database as all other account data (Section 6) and are visible only to our own systems for the purpose of running your account. Your email address may be passed to our transactional email provider, Brevo, solely to send you service emails (e.g. sign-in confirmations, account notifications) — never for third-party marketing. We do not sell, rent, or transfer Google user data to any third party for advertising, market research, or any purpose beyond operating and improving the Wisdom of Gaia service you use. We do not permit any third party to use Google user data for purposes other than providing or improving Wisdom of Gaia's functionality.

How we protect it: Google-sourced account data is encrypted in transit (HTTPS/TLS) and stored in our access-controlled database alongside your other account data, protected by the same measures described in Section 13 (least-privilege access, security logging, and no storage of your Google password, which we never see).

Retention & deletion: your Google ID and linked profile data are retained for as long as your Wisdom of Gaia account remains active. If you delete your account or ask us to unlink Google Sign-In, we delete or irreversibly disassociate this data from your account within 30 days, following the same process described in Section 8, except where we are legally required to retain limited records (e.g. transaction history for tax purposes).

Wisdom of Gaia Ltd's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5) Why we use your data (lawful bases under UK/EU GDPR)

  • Run the site and deliver requested services (accounts, content, memberships, purchases, emails you asked for). Basis: Contract; Legitimate interests.
  • Authenticate you via Google Sign-In or magic link. Basis: Contract.
  • Payments & fraud prevention. Basis: Contract; Legal obligation; Legitimate interests.
  • Community features (Groves), journals, saved tools. Basis: Contract; Legitimate interests.
  • Support & service messages. Basis: Contract; Legitimate interests.
  • Analytics & product improvement (only where you consent to non-essential cookies). Basis: Consent.
  • Marketing. Email updates with your consent, or where PECR permits for existing customers about similar products/services. Basis: Consent / Legitimate interests.
  • Security, fraud prevention, legal compliance. Basis: Legal obligation; Legitimate interests.

6) Who we share data with

We use vetted processors who act only on our instructions. These currently include:

  • Hosting & infrastructure: our web hosting provider and Cloudflare (CDN, security, and caching).
  • Email delivery: Brevo (transactional emails such as magic links and account notifications).
  • Payments: Stripe (subscription and payment processing).
  • Authentication: Google (if you choose Sign in with Google) and Cloudflare Turnstile (bot/spam protection on our forms).
  • Analytics: Google Analytics (only with your cookie consent).

We require appropriate contractual and security measures (such as Data Processing Agreements) from each processor. We do not sell your personal data to third parties, we do not share it for cross-context behavioural advertising, and — specifically regarding data received via Google Sign-In — we do not transfer it to any third party for any purpose beyond providing or improving Wisdom of Gaia's own functionality (see Section 4 for full detail on Google user data specifically).

7) International transfers

Some of our processors (including Google, Stripe, Cloudflare, and Brevo) may process data outside the UK, including in the EEA and the United States. Where this occurs, we rely on approved safeguards such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, EU Standard Contractual Clauses (where EU GDPR applies), or equivalent adequacy protections, together with appropriate technical and organisational measures.

8) Retention

  • Account data: retained while your account is active, plus up to 2 years afterwards for handling queries or defending legal claims.
  • Transaction records: typically 6 years, in line with UK tax and accounting legal requirements.
  • Server/security logs: 30–180 days, unless a longer period is required for an active investigation.
  • Marketing data: retained until you unsubscribe; suppression lists are retained afterwards to honour your opt-out.
  • Deleted accounts: if you request deletion, we remove or irreversibly anonymise your personal data — including any data received via Google Sign-In — within 30 days, except where we are legally required to retain specific records (e.g. transaction history for tax purposes).

Data Deletion & Account Closure

You can request the complete deletion of your account and all associated data — including any data received via Google Sign-In — at any time by emailing [email protected]. Upon request, we will permanently delete or anonymize your data within 30 days, except where we are legally required to retain specific records (e.g. transaction history for tax purposes).

How to request deletion:

  1. Email [email protected] from the email address associated with your account, with the subject line "Account Deletion Request".
  2. We will verify your identity using the email on file.
  3. We will confirm receipt of your request and complete the deletion within 30 days.
  4. You will receive a final confirmation once deletion is complete.

9) Your rights — UK & EU residents

Under UK GDPR (and EU GDPR, where it applies to you), you have the right to: access your data; rectify inaccurate data; request erasure; restrict processing; object to processing based on legitimate interests or for direct marketing; request data portability; and withdraw consent at any time where processing is based on consent. To exercise these rights, email [email protected]. We will respond within one month (extendable by a further two months for complex requests, with notice to you). You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, or with your local EU supervisory authority if applicable.

10) Your rights — US residents

If you are a resident of California or another US state with a comparable privacy law, you may have the right to: know what personal information we have collected about you and how it has been used and shared; request deletion of your personal information (subject to certain exceptions); correct inaccurate personal information; opt out of the "sale" or "sharing" of personal information (we do not sell or share personal information for cross-context behavioural advertising); and not be discriminated against for exercising these rights. To exercise these rights, email [email protected]. We will verify your request using the email address associated with your account before acting on it.

11) Children

Our services are intended for users aged 18 and over. We do not knowingly collect personal data from children under 13 (or the relevant minimum age in your jurisdiction). If you believe a child has provided us with personal data without appropriate parental or guardian consent, please contact us at [email protected] and we will investigate and delete such data promptly where appropriate.

12) Automated decision-making

We do not use your personal data for any automated decision-making or profiling that produces legal or similarly significant effects on you.

13) Security

We use technical and organisational measures including HTTPS/TLS encryption, access controls, salted password hashing, least-privilege database access, and security logging. No online service can be guaranteed 100% secure, but we work continuously to protect your data and to detect and respond to potential incidents.

Where data could be considered sensitive — including data received via Google Sign-In, payment metadata, and personal journal or community content you submit — we apply additional safeguards: this data is never stored in plain text where encryption is feasible, access is restricted to systems and personnel who need it to operate the service, and we do not use it to train third-party AI models or share it with data brokers.

14) Cookies & similar technologies

We use essential cookies to operate the site (e.g. keeping you signed in). With your consent, we use additional cookies for analytics and, where applicable, marketing. You can change your choices at any time via Cookie settings.

15) Changes to this notice

We may update this notice from time to time to reflect changes in our practices or in applicable law. We will post changes here and update the effective date below. Material changes will be highlighted where appropriate.

Effective date: October 3, 2026

Check Out..