Privacy Policy
Effective and last updated: July 22, 20261. Who This Policy Covers
WavePoint operates wavepoint.space and controls the personal information described in this policy. This policy covers the website, account features, chart tools, purchases, emails, analytics, and advertising choices.
You can ask a privacy question or exercise a privacy right by emailing contact@wavepoint.space.
2. Information We Process
The information we process depends on what you choose to do:
- Website and device information — Internet Protocol address, browser and device class, operating system, approximate region, canonical page, acquisition source, interactions, performance, and sanitized error categories. Optional analytics providers receive this information only after you allow Analytics.
- Account information — Email address, authentication identifier, display name if provided, account dates, and security or preference records needed to operate your account.
- Birth-chart computation information — Birth date, optional birth time, place, coordinates, time zone, and calculated chart details. Anonymous charts are processed for the requested calculation and are not stored as an account record. We store birth information only when a signed-in person explicitly saves it.
- Purchase and delivery information — Product, price, currency, tax, order and payment status, customer or delivery email, minimum billing or tax locality, and non-secret provider references needed for fulfillment, refunds, fraud handling, accounting, and reconciliation. Stripe processes card and payment credentials; WavePoint does not store full card details.
- Communications — Newsletter choices, delivery status, support requests, contact messages, and the minimum suppression record needed to honor an unsubscribe or complaint.
- Consent choices — Your separate Analytics and Advertising decisions, when you made them, and the policy version. The browser stores this record so WavePoint can enforce your choice.
3. Why We Use Information
We process information only for stated purposes and use the legal basis that applies where you live:
- Provide the service or fulfill a contract — Calculate a requested chart, maintain an account, process an order, deliver a product, and provide support.
- Meet legal obligations — Keep required tax, accounting, refund, fraud, and transaction records.
- Protect legitimate interests — Secure the service, prevent abuse, diagnose outages, reconcile payments, and defend legal claims, balanced against your rights.
- Use your consent — Run product analytics, associate consented behavior with an account or customer context, send marketing email, or select and measure advertising. You can withdraw an optional choice at any time.
WavePoint does not use analytics or birth information to make automated decisions that produce legal or similarly significant effects about you.
4. Analytics and Business Measurement
Analytics is off until you allow it. If you choose Analytics, PostHog and Google Analytics help us understand acquisition, product use, reliability, conversion, retention, and purchases.
- For a signed-in member, PostHog activity may use a stable account analytics identifier. This lets us understand a consented journey across visits and features without placing an email address in each event.
- Approved customer context may include member, customer, or subscriber status; account or customer age; product category or SKU; purchase count; value and currency; and paid, refunded, or disputed outcomes. Stripe and WavePoint's order database remain the sources of truth.
- On pages where birth data can appear, PostHog receives only explicit coarse actions such as viewing the calculator, computing a chart, downloading a formal chart, opening the poster configurator, previewing a product, or starting checkout. A signed-in action may use the same account analytics identifier, but it cannot create or update a PostHog person profile from that page.
- Session replay and automatic interaction, exception, log, heatmap, performance, survey, and feature-flag collection stay off on birth-data pages. Google Analytics also stays off on those pages.
- On other pages, PostHog may use masked session replay and explicit or automatic product events. Form inputs, request bodies, request headers, and browser console logs are excluded from replay.
We apply a material analytics-policy change prospectively. A new disclosure does not authorize WavePoint to relabel or join data collected under an older choice.
5. Information Kept Out of Analytics
Analytics events do not contain the following information:
- Exact birth date, time, place, coordinates, time zone, placements, aspects, houses, chart fingerprints, chart titles, or identity lines.
- Email, name, phone number, postal or billing address, support or message content, and other free text.
- Card details, credentials, signed download links, asset references, saved-chart IDs, internal order IDs, or Stripe customer, Checkout Session, payment, and invoice IDs.
- URL query strings or fragments. Analytics providers receive the canonical page without private chart or checkout state.
We do not sell this information. We do not use birth inputs, calculated chart details, or birth-route behavior to target advertising.
6. Advertising
Advertising is a separate, optional choice. If you allow Advertising and ads are available in your location, Google AdSense may use cookies and other identifiers to select, personalize, deliver, and measure ads under Google's policies. Ads do not run on pages where birth data can appear.
WavePoint does not load AdSense in the European Economic Area, the United Kingdom, Switzerland, or when location eligibility cannot be resolved. The eligibility check returns only eligible, restricted, or unknown; WavePoint does not retain the country from that check.
WavePoint does not sell personal information for money. Depending on the law where you live, personalized advertising may be called targeted advertising, a sale, or sharing. You can reject or turn off Advertising at any time through the Privacy choices link in the footer.
7. Service Providers
We give each provider only the information needed for its stated job:
- Supabase— Authentication, account data, explicitly saved birth information, and WavePoint's first-party order records. Supabase Privacy Policy
- Stripe — Checkout, payment, tax, refund, and fraud processing. Stripe Privacy Policy
- Brevo — Transactional delivery and marketing email when separately authorized. Brevo Privacy Policy
- Vercel — Hosting, network delivery, and security. Vercel Privacy Policy
- PostHog — Consented product, account, and customer analytics. PostHog Privacy Policy
- Google — Consented Google Analytics and AdSense. Google Privacy Policy
- OpenStreetMap Nominatim — Geocoding the place you enter so WavePoint can perform the requested chart calculation. This is a computation dependency, not analytics. OpenStreetMap Foundation Privacy Policy
Providers may process information in the United States and other countries where they operate. We use contractual, technical, and organizational safeguards appropriate to the transfer and the service.
8. Retention
We keep information only for its stated purpose, a required business record, or an active legal obligation:
- Account and explicitly saved chart data remain until you remove them or delete the account, subject to required business records described below.
- An abandoned pending order expires after 30 days. If its account owner deletes the account first, it is deleted sooner.
- Delivery contact details and the full address snapshot become eligible for scrubbing 18 months after an order is delivered, canceled, or refunded. A later refund starts a new period.
- Core order, status, product, amount, tax-locality, and non-secret reconciliation records may be kept for seven years after the latest final order event for accounting, tax, refund, fraud, and legal purposes.
- Newsletter information remains until you withdraw, with the minimum suppression evidence retained to prevent another unauthorized send.
- We keep analytics only while it serves the measurement purposes described here, then delete or aggregate it. Before connecting purchase outcomes to analytics, we will set and document the provider retention period and deletion path.
9. Your Choices and Rights
You can open Privacy choices from the footer to allow, reject, or withdraw Analytics and Advertising separately. Withdrawing a choice stops future optional collection and clears WavePoint-controlled browser identifiers. It does not affect processing that was lawful before withdrawal.
Depending on where you live, you may ask to access, correct, export, delete, restrict, or object to processing of your personal information. You may also withdraw consent and lodge a complaint with your local data-protection authority.
California residents may also have rights to know, correct, and delete personal information; to opt out of sale, sharing, or targeted advertising; and to receive equal service after using a privacy right. Use Privacy choices to turn off Advertising, or email us for another rights request.
Some information cannot be deleted immediately when we must keep it to complete an order, prevent fraud, resolve a dispute, or meet tax, accounting, or other legal duties. We will explain any applicable limit.
10. Security
We use encrypted transport, restricted access, provider controls, data minimization, and tested application boundaries to protect personal information. No system can guarantee absolute security, but access is limited to the people and providers that need it for an authorized purpose.
11. Children
WavePoint is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If you believe a child has provided information, contact us so we can investigate and delete it where required.
12. Changes to This Policy
We post policy changes here with a new effective date. If a change materially expands optional processing, we ask for a new choice before that processing begins. A more permissive policy does not retroactively authorize a new use of previously collected information.
13. Contact
For privacy questions or rights requests, visit our contact page or email contact@wavepoint.space.