( / PRIVACY )

What we collect, why, and how to make us delete it.

Last updated 25 August 2026

This policy covers magictext.online and the services sold through it. It is written to be understood. Where a legal term is unavoidable, it is explained.

Yury Kovalenok of 1500 Preston Rd, Apt 1314, Plano, TX 75093 is the controller of the personal data described here. Contact: magictext0011@gmail.com.

The short version

What we collect

WhenWhatWhyLawful basis (GDPR)
You visit a pagePath, referring site, screen-size band, timestamp, and a daily-rotating salted hash. No IP or user-agent is stored.To know which pages are read Legitimate interest — no individual is identifiable
You book a consultationName, email, chosen time, timezone, and what you wrote about your problemTo hold the slot and prepare for the callPerformance of a contract
You send a research or project requestName, email, company, and every answer you gave in the formTo read it and quote for itSteps taken at your request before a contract
You payAmount, currency, status, and Stripe's reference. Never the card numberTo know the payment succeeded, and for accountingContract, and legal obligation for tax records
We email youThe address and the message contentConfirmations, quotes, invoicesContract

What we do not collect

No card numbers. No advertising identifiers. No location beyond what an IP implies in the moment a hash is computed. No cookies on visitors — see the cookie policy, which shows the audit. No data about you from anywhere other than you.

Who else touches it

ProcessorWhat forWhere
StripeTaking payment. They are the controller of your card data, not us.US / global — policy
BrevoDelivering confirmations and invoicesEuropean Union
NamecheapRunning the serverUnited States — not Russia; see below

That is the whole list. No analytics vendor, no CRM, no ad network, no data broker.

International transfers

The server is located in the United States. If you are in the UK, EEA or Switzerland, your data may be processed outside your country. Where that happens we rely on the UK/EU Standard Contractual Clauses or an adequacy decision, as applicable to each processor above.

How long we keep it

DataKept for
Visit recordsRolling 24 months, then deleted. Already non-identifying.
Bookings and requests you did not proceed with12 months, then deleted
Engagements and their correspondenceDuration of the work, then 6 years
Payment and invoice records7 years, because tax law requires it

Your rights

If you are in the UK or EEA you have the right to access your data, correct it, have it erased, restrict or object to how we use it, receive a portable copy, and withdraw consent where consent was the basis. If you are in California, you may know what is collected, request deletion, correct it, and are entitled not to be discriminated against for asking. We do not sell or share personal information, so there is nothing for you to opt out of.

Email magictext0011@gmail.com. We answer within 30 days and do not charge. We may ask you to confirm the request came from the address on file — that is the only identity check.

You can also complain to your data protection authority: the ICO in the UK, or your national authority in the EEA. We would rather you told us first.

Security

Traffic is encrypted in transit. Admin access requires a password stored only as a hash, is rate limited, expires after twelve hours, and every state-changing action carries a CSRF token. Payment pages are Stripe's, not ours. Secrets live in the server environment, never in source code.

Children

These services are sold to businesses and professionals. They are not directed at anyone under 16, and we do not knowingly collect their data.

Changes

If this policy changes materially we will say so here and update the date above. If a change affects work already underway, we will email you rather than rely on you noticing.

← All policies