Privacy policy
Privacy should be designed, not promised vaguely.
Prototype policy · legal review required before launch
Information collected
The live service may collect contact details, booking information, payment status, intake responses, session-related resources, assignments, evaluations, and technical security logs. Payment card information should be handled directly by Stripe and not stored on the website server.
Why information is used
Information may be used to schedule and deliver sessions, communicate with clients, process payments, issue invoices, provide portal resources, meet legal obligations, protect the service, and improve operations.
Service providers
Potential providers include Stripe for payments, Google Workspace for email and calendar, a secure hosting and database provider, a video provider, and an email delivery service. Final vendors and data-processing terms must be listed before launch.
International clients
Clients may access the service from outside the United States. The final policy must explain cross-border data transfers and rights that apply in relevant jurisdictions.
Retention and deletion
The production system must define how long each data category is retained and how clients can request access, correction, export, or deletion where applicable.
Contact
The final policy will provide Lucy’s verified business and privacy contact details.