Privacy
What we collect, and why we collect it.
Dendora Collective is a small operation with one guide and a short list of tools that keep the practice running. This page says exactly what personal data we collect, who else sees it, how long we keep it, and how to ask us to delete it.
Who this policy covers
One guide, one small stack, no data broker in sight.
Dendora Collective ("Dendora," "we," "us") operates dendoracollective.com and the readings, sessions, and community wall offered through it. Until a fiscal sponsorship or standalone nonprofit filing is finalized, we operate under the softer "nonprofit doorway" framing used across this site: we are structured and run like a nonprofit, and we intend to seek formal recognition, but we do not yet claim tax-exempt status in this policy.
This policy applies to anyone who visits the site, casts a free oracle reading, books a session, buys one of our priced offerings, posts to the community wall, or writes to the guide directly.
What we collect
Five categories of data, each with one job.
We collect the minimum needed to run the reading or session you asked for. We do not run behavioral advertising, and we do not maintain a general-purpose profile of visitors who are just browsing.
Name and email
Collected when you book a session, buy an offering, join the Guild, submit a voice cast, request a scholarship reading, or write to the guide. Used to confirm your purchase, schedule and deliver your session, send receipts, and reply to you. This is the only data required to use the free oracle — casting a reading on the oracle page requires no account and no personal information at all; the question you type stays in your browser.
Birth date, time, and place
Collected only if you use the Birth Profile or Pairing Reading doorways, which use this information to calculate the specific chart underlying your reading. This data is processed client-side where the calculation allows it, and where it must reach the guide (for a live or written reading), it is used solely to produce that one reading — see retention below for how briefly we hold it. It is never required to use the free oracle, the daily key, or the shadow inventory.
Voice recordings
Collected if you record your question for the Voice-Note Cast, and generated by the guide if you choose an audio reflection in return. We treat voice recordings as sensitive, biometric-adjacent data under the California Consumer Privacy Act's "sensitive personal information" category and the Illinois Biometric Information Privacy Act's treatment of voiceprints, even though a short spoken reflection is not itself a voiceprint used for identification. In practice that means: we do not use recordings for anything beyond delivering your reflection, we do not run voice identification or biometric matching against them, and we hold them on a short, published retention window — see retention below.
Payment data
Collected when you buy any priced offering or make the $22 pay-it-forward contribution. Dendora never sees or stores your card number, CVV, or full billing details. Checkout runs entirely inside Stripe's hosted payment flow; we receive only a transaction confirmation, the amount, and the last four digits of the card for your receipt.
Community wall content
Collected when you post a question or reply on the community wall. Posts are pseudonymous by default and are reviewed by a moderator before the guide or another practitioner answers. We keep post content to run and moderate the wall; see retention for how long.
On pricing language
The 15-minute session, full session, bundle, cohort, cohort trio, Guild membership, voice-cast offerings, and gift-a-reading purchases are commercial exchanges: you pay a fixed or chosen price and receive a specific reading, session, or object in return. We call these "offerings," not contributions, because there is no tax deduction associated with them. The $22 pay-it-forward add-on is different: it funds a scholarship seat for someone else, you receive nothing in return, and it is described in our materials as a contribution.
How we use it
To run the thing you asked for.
- ·Deliver readings and sessions. Scheduling, video links, written and audio reflections, and receipts.
- ·Respond to you. Volunteer notes, scholarship requests, and general correspondence with the guide.
- ·Run the community wall. Moderation, matching questions to answers, and keeping the wall legible.
- ·Bookkeeping and legal compliance. Transaction records we are required to keep for tax and accounting purposes.
- ·Security. Rate-limiting and bot protection on forms and checkout, so the practice stays available to real people.
- ·Marketing and nurture email, only if you opt in. If you check that box, or purchase certain offerings, your contact record may receive occasional follow-up email through our CRM. You can unsubscribe from any such email at any time using the link in the message, without affecting your ability to book sessions.
Who else sees it
Five vendors. No data broker.
We use a short list of named sub-processors to run the site. We do not sell personal data to anyone, and we do not share it for cross-context behavioral advertising.
| Sub-processor | What it does | Data it sees |
|---|---|---|
| Stripe | Payment processing for every offering and the pay-it-forward contribution. | Card and billing details (never stored by Dendora), name, email, purchase amount. |
| Google Calendar & Google Meet | Scheduling booked sessions and hosting the video call. | Name, email, session date and time, calendar invite details. |
| Gmail API | Transactional email: booking confirmations, reading delivery, receipts, password-free links. | Name, email, and the content of transactional messages. |
| GoHighLevel (GHL) | Customer relationship management — contact records, tags, and follow-up. Also used for marketing and nurture email sequences, not only service delivery. | Name, email, purchase history, tags, and email engagement data. |
| Cloudflare | Infrastructure: R2 stores voice-cast audio files, KV and D1 store site data (transparency counters, gift codes, community wall posts, rate-limit records), and Workers run the backend logic that ties it together. | Audio files, community wall post content, and operational site data. |
Each of these vendors is contractually restricted to using your data to provide their service to us, and each maintains its own security and privacy program. We review this list periodically and will update it here if it changes.
How long we keep it
Short windows, published in advance.
- ·Voice and audio files. Retained approximately 90 days after delivery, then permanently deleted, unless you opt into a personal library when you receive your reflection — in which case we keep it until you delete it yourself or ask us to close your account.
- ·Birth-data reading inputs. Your birth date, time, and place are retained only as long as needed to generate the specific reading you requested, then deleted from our systems. Any copy of the finished reading you download or save is yours to keep; we do not retain a separate copy of your birth data alongside it.
- ·Community wall posts. Retained indefinitely as part of the public wall unless you ask us to remove your post or the post is removed by moderation.
- ·Transaction and booking records. Retained for as long as required by applicable tax and accounting rules.
- ·Deletion requests. We commit to honoring a verified deletion request within 30 days of receiving it, subject to records we are legally required to retain (such as tax records tied to a completed purchase).
Your rights
The same rights, wherever you are.
We extend the following rights to every visitor, regardless of where you live, rather than limiting them to residents of a particular state or country.
- We do not sell or share your personal data. Not for money, and not in exchange for other value, including cross-context behavioral advertising.
- Limit the use of sensitive personal information. Under the CCPA, you may ask us to limit our use of sensitive personal information (such as the birth data or voice recordings described above) to what is necessary to deliver the reading you requested. Contact us below to make this request; because we do not use sensitive data for secondary purposes like advertising or profiling in the first place, honoring this request will not change how your reading is delivered.
- Global Privacy Control (GPC) is honored automatically. If your browser or extension sends a GPC opt-out signal, we treat it as a valid request to opt out of any sale or share of personal data and to decline non-essential cookies, without requiring you to fill out a separate form.
- Access, correct, delete, and export your data. You can ask us what personal data we hold about you, ask us to correct it, ask us to delete it, or ask for a copy in a portable format — the same bundle of rights the GDPR guarantees EU residents, offered here to anyone who asks.
- Appeal. If you disagree with how we handled a privacy request, write to us again and say so; the guide personally reviews every appeal.
To exercise any of these rights, contact us using the details in Contact us below. We may need to verify your identity (typically by confirming the email address on file) before completing a request that involves deleting or exporting data.
Cookies & tracking
Nothing loads until you say yes.
The site uses a small number of strictly necessary cookies to remember your theme preference, keep your session working during checkout, and support fraud prevention. These load automatically because the site cannot function without them.
Non-essential cookies — analytics, in particular — only load after you accept them in the cookie-consent banner shown on your first visit. If you decline, or if your browser sends a Global Privacy Control signal, analytics stay off for that visit and future visits from that browser. You can change your choice at any time by clearing your browser's site data for dendoracollective.com, which resets the banner.
That same acceptance also covers a small first-party analytics system we run ourselves, entirely on our own Cloudflare infrastructure — a genuine alternative to Google Analytics or Meta Pixel, not a layer built on top of either. It records page views, approximately where on a page people tend to click (to see which parts of a layout are actually being used — never the text or content of what was clicked), how far down a page people scroll, and how long a page stays open. If you start filling out a form on the site but leave without submitting it, we record which field you last touched — never anything you typed into it. It never uses persistent fingerprinting to recognize the same visitor across separate visits, and what it collects never leaves Cloudflare's own infrastructure or reaches Google, Meta, or any other third party. It is governed by the exact same consent choice described above: nothing is recorded until you accept, and a decline — or a Global Privacy Control signal — turns it off exactly as it turns off Google Analytics or Meta Pixel. Raw, per-visit detail is kept for 30 days, after which it is folded into aggregate daily totals and the underlying detail is discarded.
Children’s privacy
Not directed at children.
Dendora Collective is not directed at children under 13 (or under 16 where a higher local threshold applies), and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
International visitors
Processed in the United States.
Dendora Collective operates in the United States, and the vendors listed above process data on infrastructure located in the United States. If you access the site from outside the United States, your data will be transferred to and processed in the United States, which may not offer the same legal protections as your home jurisdiction. By using the site, you consent to this transfer. We honor the access, correction, deletion, and export rights described above regardless of where you are located, as one way of narrowing that gap.
Changes to this policy
We’ll say so, plainly, right here.
If we materially change what we collect, how we use it, or who we share it with, we will update the "Last updated" date at the top of this page and, for material changes, post a notice on the site for at least 30 days. Continuing to use the site after a change takes effect means you accept the updated policy; if you do not agree, please stop using the site and contact us to request deletion of your data.
Contact us
Privacy requests, questions, and appeals.
Write to privacy@dendoracollective.com for anything on this page — access, correction, deletion, export, a sensitive-data limitation request, or a question about a vendor. We reply personally, and we commit to resolving verified requests within 30 days.