Information we collect
We collect account details you provide, such as your name and email address; purchase and enrolment records; course progress; messages sent through our contact form; and limited technical information needed to operate and secure the service.
Payment information
Card, UPI, and banking details are handled by the configured payment provider. Mystic Souls stores provider order and payment references, status, amount, refund state, and course information, but does not store full card or bank credentials.
Optional analytics and advertising measurement
If you choose “Allow analytics”, we use Meta Pixel, Meta Conversions API, and Google Analytics 4 to understand page visits, course interest, account creation, enquiries, checkout starts, purchases, and campaign performance. We save campaign parameters such as UTM values, fbclid, gclid, referring page, and first-party Meta browser identifiers. We do not send lesson activity, journal content, passwords, payment credentials, or medical information to advertising platforms.
For server-side Meta conversion matching, contact details associated with a consented conversion are normalised and SHA-256 hashed before transmission. Browser and server events share the same event ID so Meta can deduplicate them. Optional analytics scripts do not load until consent is granted.
Cookies
Necessary cookies support sign-in, security, checkout, and saved privacy choices. Optional Meta and Google cookies support attribution and analytics only after you allow them. You can change your choice at any time through “Cookie choices” in the site footer.
How information is used
We use information to provide accounts and courses, confirm purchases, remember learning progress, answer support requests, measure consented marketing, prevent abuse, maintain records, and comply with legal obligations. We do not sell personal information.
Storage and retention
Account, enrolment, transaction, and consented attribution records are retained for as long as reasonably needed to provide the service, measure the business, and meet accounting or legal requirements. Session records expire automatically. You may ask us to review or delete eligible personal information.
Security
Passwords are stored using salted, computationally expensive hashing. Authentication and attribution use server-managed, HTTP-only cookies. No online service can promise absolute security; please use a unique password and contact us if you suspect misuse.
Your choices
You may decline optional analytics without losing account, checkout, or course access. You may request access, correction, or eligible deletion by emailing hello@mysticsouls.co. We may need to verify your identity before acting on a request.
Updates
We may update this policy as the academy or legal requirements change. Material changes will be reflected by the date above.