Privacy Policy
Last updated 15 June 2026
This Privacy Policy ("Policy") explains how [OPERATOR NAME] (registration code [●], address: [ADDRESS]) ("Operator", "we") collects and processes the personal data of users of the "Svicha Online" web application ("Service").
We process personal data in accordance with the Law of Ukraine "On Personal Data Protection" No. 2297-VI of 01.06.2010 and, for users located in the European Union, with regard to the General Data Protection Regulation (GDPR).
Privacy is sacred to us. Spiritual-guidance conversations are never recorded or stored (zero retention).
1. Data controller (operator)
- Name: [OPERATOR NAME]
- Registration code (EDRPOU / RNOKPP): [●]
- Address: [ADDRESS]
- Privacy contact email: [EMAIL]
2. What data we process
Depending on how you use the Service, we may process:
- a technical anonymous-session identifier (you are anonymous by default — no name, phone, or email required);
- optionally, a name (nickname), email and/or phone number to alert you when a candle is lit or to save an account;
- web push subscription data (for browser notifications) if you enable them;
- candle order data: names for prayer, intent (health / repose), and an optional message;
- booking data (category, modality, time);
- for priests — diocese, parish, bio and ordination document (for verification);
- technical data: cookies and local storage, hosting log data (including IP address), and anonymized analytics events.
3. What we do not store
- The content of spiritual-guidance conversations (text, audio, video) is never recorded or stored on our servers.
- Payment card data is not stored by the Operator — payments are handled by a payment provider.
4. Purposes and legal bases
We process data on the following bases (Art. 11 of Law No. 2297-VI):
- to provide the Service and perform our agreement with you (lighting candles, booking conversations);
- your consent — for notifications (SMS, email, push) and analytics;
- our legitimate interest — security, abuse prevention and moderation.
5. Sharing with third parties (processors)
To operate the Service we engage the following data processors:
- Supabase — database hosting and authentication;
- Cloudflare Stream — streaming and storage of candle-lighting recordings;
- LiveKit — video/audio conversations (content not stored);
- Twilio — sending SMS (with your consent);
- Resend — sending email (with your consent);
- PostHog — anonymized usage analytics;
- Trigger.dev — scheduled jobs (session reminders).
6. Cross-border transfer
Some processors may store data outside Ukraine. Such cross-border transfers are made in accordance with Art. 29 of Law No. 2297-VI to states providing adequate protection and/or on the basis of your consent and appropriate contractual safeguards.
7. Retention periods
- candle-lighting recordings — approximately 30 days, then deleted;
- anonymous-session data — until the session or browser storage is cleared;
- saved-account data — until you request its deletion;
- technical logs — for a limited period necessary for security.
8. Your rights
Under Art. 8 of Law No. 2297-VI (and GDPR where applicable) you have the right to:
- know about the collection and processing of your data;
- access your data;
- request correction of inaccurate data;
- request deletion of your data;
- withdraw consent you previously gave;
- object to processing;
- lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights (the data-protection supervisory authority).
9. Cookies and local storage
We use cookies and local storage necessary for the Service to work (session, chosen theme and language) and — with your consent — for push notifications and anonymized analytics. Analytics does not autocapture typed text and does not record sessions.
10. Data security
We apply organizational and technical measures: row-level security (RLS), encryption in transit, two-factor authentication for clergy and administrators, and data minimization.
11. Children
The Service is intended for persons aged 18 or older (or 16 with parental/guardian consent). We do not knowingly collect data from younger children.
12. Changes to this Policy
We may update this Policy. The current version is always available in the Service with its update date.
13. Contact
For questions about personal data processing and to exercise your rights, contact: [EMAIL].