Privacy Policy
Last updated: May 20, 2026
A devotional life is a private one. This platform is designed to collect the smallest possible amount of personal data, and we never sell data to third parties. This policy describes exactly what we collect, why, and what rights you have.
1. Data we collect
When you place an order: your email address (to deliver the download link), the display name you choose to provide, and the PayPal order id. When you visit the site: your IP address (hashed with a 24-hour rotating salt — we do NOT store raw IPs), browser user agent, timestamp, and the path you viewed. When you contact us: the contents of your message and the email you provide. We do NOT collect payment-card details, government identification numbers, or biometric data.
2. How we use data
Your email is used to deliver the download link, send receipts, and reply to your messages. Hashed IPs are used for rate-limiting and aggregate, anonymous usage statistics. PayPal order ids are used to look up your purchase when you contact support. We do NOT use your data for targeted advertising, do NOT sell to third parties, and do NOT share with marketing partners.
3. Third-party processors
We share only the minimum necessary data with two technical service providers: (a) PayPal — for payment processing (receives the order email and amount); (b) Resend — for transactional email delivery (receives the recipient email and message contents). Both have their own privacy policies and comply with GDPR. We do not share with any other party unless we receive a lawful request from a competent authority in Vietnam.
4. Storage and security
Data lives in a SQLite database on servers we manage. Secret keys (PayPal client secret, Resend API key, and so on) are encrypted at rest with AES-256-GCM using a master key kept outside the database. All transport is HTTPS-only. Backups are stored encrypted.
5. Cookies and browser storage
We use only technical cookies that are strictly necessary for the service: a CSRF token (to prevent forged requests), an admin session cookie (only for site administrators), and a sticky access cookie named b_site_<slug>. The sticky cookie applies only when you visit an invite-only storefront via a private invitation link; it has a one-year lifetime and stores the literal value "1" — no identifying information. We do NOT use any advertising cookies and do NOT embed any third-party trackers (no Google Analytics, no Facebook Pixel).
6. Your rights
You have the right to: (a) request a copy of all data we store about you; (b) request corrections if anything is wrong; (c) request full deletion (we will delete within 30 days, except for order records we are required to retain under Vietnamese accounting law — at least 5 years); (d) request data portability to another service; (e) withdraw consent at any time. Submit any of these requests by email using the address shown in the footer; we verify identity through your registered email before processing.
7. Children
The service is not directed at people under 16. We do not knowingly collect data from children. If we discover that data belonging to someone under 16 has been collected, we will delete it as soon as we are notified.
8. Changes to this policy
This policy may be updated when our data practices change. The updated date is always shown at the top of the page. Material changes will be announced by email to customers who purchased in the past 12 months.
9. Privacy contact
Any privacy-related question or request, please send it to [email protected] with the subject line starting with [Privacy] for fastest triage.