Privacy Policy
Last updated: 2026-06-15
This Privacy Policy explains how IMMOMAPS NV (BE0764 419 089) ("we", "our") collects, uses, and shares personal data when you use Sunday Bible Readings (the "Service"). It is written to comply with the EU General Data Protection Regulation (GDPR) and the UK GDPR. If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know, delete, correct, and access certain personal information. We do not sell or share personal information for cross-context behavioural advertising.
1. Data controller
The data controller is IMMOMAPS NV (BE0764 419 089), Slachthuisstraat 72, 9000 Ghent, Belgium. Contact: hello@sundaybiblereadings.com.
2. What we collect
- Account data: email address, display name, hashed password, sign-in provider (e.g. Google).
- Reading data: bookmarks, reading progress, streaks, reading-plan history.
- Preferences: tradition, language, reminder time.
- Payment data: when you subscribe, our payment processor Stripe collects your card and billing details. We never see your full card number; we receive a customer/subscription identifier.
- Usage data: if you accept analytics cookies, we collect anonymised pageview, event, and device information via PostHog.
- Technical data: IP address, browser user-agent, server logs for security and abuse prevention.
3. Legal bases (GDPR Art. 6)
- Contract: account creation, subscription billing, delivering the Service.
- Consent: analytics cookies, optional email reminders. You can withdraw consent at any time.
- Legitimate interests: security, fraud prevention, service improvement.
- Legal obligation: tax and accounting records related to paid subscriptions.
4. Sharing
We share data only with the processors needed to run the Service:
- Supabase (database, auth, storage) — EU region.
- Stripe (payments) — global, GDPR-compliant.
- PostHog (analytics, EU region) — only if you accept analytics cookies.
- Google (OAuth sign-in) — only if you choose "Continue with Google".
- Lovable Cloud / Cloudflare (hosting, edge runtime).
We do not sell personal data and do not use it for cross-site advertising.
5. International transfers
Some processors (e.g. Stripe, Cloudflare, Google) operate globally. Transfers outside the EEA are protected by the European Commission's Standard Contractual Clauses and/or adequacy decisions.
6. Retention
- Account & reading data: until you delete your account.
- Payment / billing records: 7 years (tax law).
- Server logs: 30 days.
- Analytics events: 12 months.
7. Your rights (GDPR Art. 15–22)
You have the right to access, rectify, erase, restrict, port, and object to processing of your personal data, and to lodge a complaint with your local supervisory authority. Account deletion is available in Account → Danger Zone and removes all personal data we hold. For other requests, email hello@sundaybiblereadings.com.
8. Cookies
See our Cookie Policy. Strictly-necessary cookies (auth session) are always set; analytics cookies require your consent.
9. Security
We use TLS in transit, encryption at rest, row-level security in the database, and least-privilege service keys. No system is perfectly secure; report vulnerabilities to hello@sundaybiblereadings.com.
10. Children
The Service is not intended for children. We do not knowingly collect personal data from children in violation of applicable law. If you believe a child has provided personal information, please contact us so we can investigate and, where appropriate, delete the information.
11. Changes
We will update the "Last updated" date and, for material changes, notify you by email.