← Back to Home

Privacy Policy

Last updated: March 12, 2026


1. Introduction & Data Controller

Welcome to The Ultimate Princess Treatment Formula (“Platform”, “Service”, “we”, “us”, or “our”). This Platform is developed and operated by Sechel Systems, LLC, a Wyoming limited liability company, with offices at 131 Continental Dr, Suite 305, Newark, DE 19713, US (“Company” or “Data Controller”).

This Privacy Policy describes how we collect, use, disclose, store, and protect your personal information when you visit our website, create an account, purchase our digital products, or interact with our community features. By accessing or using the Platform, you acknowledge that you have read and understand this Privacy Policy.

This Privacy Policy should be read together with our Terms of Service.

2. Information We Collect

2.1 Information You Provide Directly

When you create an account, purchase a course, or interact with the Platform, we collect the following categories of information:

Account & Identity Information: First name, last name, email address, and password (stored as a secure cryptographic hash, never in plain text).

Profile Information: Age, country of residence, phone number, and profile image (if uploaded).

Payment Information: Payment details are collected and processed exclusively by Stripe, Inc., our PCI-compliant third-party payment processor. We store your Stripe customer ID, transaction references, amounts paid, currency, and subscription status but never store your credit card numbers, bank account details, or other sensitive financial information on our servers.

User-Generated Content: Posts, comments, reactions, images, and other content you submit through the Platform's community features.

Consent Records: Your acceptance of the Terms of Service and opt-in/opt-out status for marketing communications.

2.2 Information Collected Automatically

When you use the Platform, we may automatically collect:

Usage & Progress Data: Lesson progress (percentage watched, completion status), course engagement metrics, and feature-usage patterns.

Session & Authentication Data: Authentication tokens (JWT), session identifiers, login timestamps, and token-refresh events.

Device & Browser Data: Browser type, operating system, screen resolution, language preferences, and general device information collected through standard web protocols and analytics services.

Geographic Inference: Your approximate geographic location inferred from your IP address (via the x-vercel-ip-country header) or your browser's timezone setting. This is used solely to display prices in your local currency (USD or EUR) and is not stored as a precise geolocation profile.

Analytics Data: We use Vercel Analytics, a privacy-focused analytics service, to collect anonymized usage data such as page views, navigation patterns, and performance metrics. Vercel Analytics does not use cookies and does not track individual users across sites.

2.3 Information from Third Parties

If you choose to sign in using a third-party authentication provider (such as Google or GitHub), we receive your name, email address, and profile image from that provider, in accordance with their privacy policies and the permissions you grant during the sign-in flow. We also receive and store OAuth tokens necessary to maintain your authenticated session.

3. How We Use Your Information

We process your personal information for the following purposes and on the following legal bases:

Service Delivery (Performance of Contract): To create and manage your account, provide access to courses, track your learning progress, deliver community features, and fulfill your purchase.

Payment Processing (Performance of Contract): To process your purchase, manage billing through Stripe, and send purchase confirmations and receipts.

Transactional Communications (Performance of Contract / Legitimate Interest): To send you essential service-related notifications, including account verification emails, purchase confirmations, security alerts, community announcements, and comment-reply notifications.

Marketing Communications (Consent): If you have opted in, to send you promotional emails about programs, offers, and new content. You can withdraw marketing consent at any time.

Platform Improvement (Legitimate Interest): To understand how the Platform is used so we can improve the user experience, develop new features, and optimize performance.

Safety, Security & Compliance (Legitimate Interest / Legal Obligation): To enforce our Terms of Service, detect and prevent fraud or abuse (including chargeback fraud), manage bans and moderation, and comply with applicable legal obligations.

Internal Business Operations (Legitimate Interest): To send internal sale notifications to our team when a purchase is made, which include the buyer's name, email, phone number, country, and payment amount for order fulfillment and customer support readiness.

4. Third-Party Service Providers & Data Processors

We share your personal information with the following categories of third-party service providers who process data on our behalf and under our instructions:

Stripe, Inc. (Payment Processing): Handles all payment processing, checkout, and billing. Your payment data is subject to Stripe's Privacy Policy. Stripe may also provide installment payment options (e.g., Klarna) subject to the applicable provider's terms.

Resend (Email Delivery): Delivers transactional and marketing emails on our behalf, including magic-link authentication emails, purchase confirmations, community announcements, comment-reply notifications, and promotional communications. Emails may contain your name and relevant content context.

VdoCipher (Video Hosting & DRM): Hosts and streams course video content with digital rights management (DRM) protection. VdoCipher receives video playback requests and may collect device/browser fingerprint data for DRM enforcement.

Vercel, Inc. (Hosting, Analytics & File Storage): Hosts the Platform infrastructure. Vercel Analytics collects anonymized usage metrics. Vercel Blob stores uploaded files (profile images, community post images, course documents) as publicly accessible URLs. Files uploaded to Vercel Blob may be accessible via their direct URL even after content is removed from the Platform interface, until the blob is explicitly deleted from storage.

Authentication Providers (Google, GitHub): If you use social login, your authentication data is also governed by that provider's privacy policy. We receive and store OAuth tokens to maintain your session.

Google Fonts: We use Google Fonts for typography rendering. Font files are loaded from Google's servers, which may process your IP address in accordance with Google's Privacy Policy.

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.

5. Cookies & Tracking Technologies

The Platform uses the following types of cookies and similar technologies:

Strictly Necessary Cookies: Authentication session cookies (e.g., next-auth.session-token) that are essential for you to log in and use the Platform. These cannot be disabled.

Analytics: Vercel Analytics uses a cookieless, privacy-focused approach to collect anonymized usage data. No personally identifiable tracking cookies are set by our analytics.

We do not use advertising cookies, cross-site tracking pixels, or behavioral targeting technologies on the Platform.

6. International Data Transfers

The Company is based in the United States (Wyoming). Our infrastructure providers, payment processors, and other service providers operate in the United States and other countries. If you are located outside the United States, your personal information will be transferred to and processed in the United States and potentially other jurisdictions that may not provide the same level of data protection as your home country.

For Users in the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on the following transfer mechanisms as applicable: (a) the European Commission's adequacy decisions; (b) Standard Contractual Clauses (SCCs) approved by the European Commission; or (c) the data recipient's participation in a recognized framework (e.g., EU-U.S. Data Privacy Framework). By using the Platform, you acknowledge and consent to the transfer of your information as described in this Section, subject to applicable safeguards.

7. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, subject to the following guidelines:

Account Data: Retained for as long as your account is active. Upon account deletion, personal data is removed within thirty (30) days, except as noted below.

Payment & Transaction Records: Retained for a minimum of seven (7) years to comply with tax, accounting, and financial-reporting obligations.

User-Generated Content: Posts and comments may be retained in anonymized form (with your personal identifiers removed) after account deletion to maintain the integrity of community discussions for other Users.

Moderation & Ban Records: Records of enforcement actions (including ban reasons and actor identifiers) are retained for as long as necessary to enforce our Terms of Service and prevent re-registration by banned Users.

Uploaded Files: Profile images and community-post images stored in Vercel Blob are deleted when you remove or replace them, or when your account is deleted. Files associated with cascading database deletions may remain as orphaned blobs until they are identified and cleaned up by our systems.

8. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information. We honor these rights regardless of where you reside, to the extent technically feasible:

8.1 Rights Available to All Users

Access: The right to request a copy of the personal data we hold about you.

Correction: The right to request correction of inaccurate or incomplete data. You can update most profile information directly in your account settings.

Deletion: The right to request deletion of your personal data, subject to the retention exceptions described in Section 7. You can also delete your account directly from the Platform settings.

Portability: The right to receive your data in a structured, commonly used, machine-readable format.

Withdraw Consent: Where processing is based on consent (e.g., marketing emails), you may withdraw consent at any time without affecting the lawfulness of processing performed before withdrawal.

8.2 Additional Rights for EEA/UK Residents (GDPR)

Restriction of Processing: The right to request that we restrict the processing of your data in certain circumstances.

Objection: The right to object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds.

Supervisory Authority: The right to lodge a complaint with a data protection supervisory authority in your country of residence.

8.3 Additional Rights for California Residents (CCPA/CPRA)

Right to Know: You have the right to know the categories and specific pieces of personal information we collect, the purposes for collection, and the categories of third parties with whom we share it.

Right to Delete: You have the right to request deletion of personal information we have collected, subject to legal exceptions.

No Sale / No Sharing: We do not sell or share (as defined by the CCPA/CPRA) your personal information for cross-context behavioral advertising.

Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

8.4 How to Exercise Your Rights

To exercise any of these rights, please contact us at support@gurmanova.guru. We will verify your identity before processing your request and respond within thirty (30) days (or within the timeframe required by applicable law). If we need additional time, we will notify you of the extension and the reason.

9. Data Security

We implement reasonable technical and organizational measures to protect your personal information, including:

Passwords are securely hashed using industry-standard cryptographic algorithms (bcrypt) and never stored in plain text.

All data transmissions are encrypted using TLS (Transport Layer Security) protocols.

Payment information is handled exclusively by PCI DSS-compliant processors (Stripe). We do not process or store raw card data.

Access to personal data within our systems is restricted to authorized personnel on a need-to-know basis.

Video content is protected by DRM (Digital Rights Management) technology provided by VdoCipher.

While we take reasonable steps to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security and are not liable for unauthorized access resulting from factors beyond our reasonable control.

10. Children's Privacy

The Platform is intended only for individuals who are at least eighteen (18) years of age. We do not knowingly collect personal information from anyone under the age of 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@gurmanova.guru, and we will promptly delete such information from our systems.

11. User-Generated Content & Public Information

When you post content in community feeds or comment sections, that content is visible to other authenticated Users of the Platform. Your display name, profile image, country, and age may be displayed alongside your posts and comments. Please be aware that information you share in community features is accessible to other Users and may be copied or shared by them outside the Platform.

We may include excerpts of your posts or comments in email notifications sent to other Users (e.g., announcement emails or comment-reply notifications). These emails are transactional in nature and necessary for the operation of the community features.

Images uploaded as part of community posts or as your profile image are stored on publicly accessible cloud storage (Vercel Blob). While access to community features requires authentication, the direct URL of an uploaded image may be accessible without authentication. Please exercise caution when uploading images that contain sensitive or personal content.

12. Marketing Communications

If you have opted in to receive marketing communications during account registration, we may send you emails about new programs, offers, content updates, and related promotions. You can withdraw your consent at any time by:

Clicking the “unsubscribe” link in any marketing email.

Contacting us at support@gurmanova.guru.

Withdrawing marketing consent does not affect transactional or service-related communications (e.g., purchase confirmations, security alerts, community notifications), which are necessary for the operation of the Platform.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the “Last updated” date at the top of this page and notify you via email or through the Platform at least fifteen (15) days before the changes take effect. We encourage you to review this policy periodically. Continued use of the Platform after the effective date of any changes constitutes your acknowledgment of the updated Privacy Policy.

14. Contact Us

If you have any questions or concerns about this Privacy Policy, our data practices, or wish to exercise your privacy rights, please contact us at:

Sechel Systems, LLC

131 Continental Dr, Suite 305

Newark, DE 19713, US

Email: support@gurmanova.guru