Privacy Policy
Effective Date: August 27, 2026 Last Updated: August 27, 2026
This Privacy Policy explains how Individual Entrepreneur Rudeiskii Aleksandr (“Company”, “we”, “us”, “our”) collects, uses, discloses, and protects information when you use sherules.me and its related progressive web application (the “Service”).
We are committed to protecting your privacy and processing personal data in accordance with applicable data protection laws, including the EU/UK General Data Protection Regulation (“GDPR”) where applicable.
1. Information We Collect
1.1 Information You Provide
- Account information: email address, username/display name, PIN (stored as a secure hash, never in plain text).
- Authentication data: WebAuthn/biometric credentials are processed and stored locally on your device by your device’s secure hardware; we do not receive or store your biometric data itself, only a cryptographic public key used to verify authentication.
- Payment information: handled entirely by our third-party payment processor / merchant of record. We receive limited transaction metadata (e.g., subscription status, plan, transaction ID) but do not receive or store your full card details.
- Communications: messages you send us via support channels.
1.2 Information Collected Automatically
- Usage data: pages/features accessed, actions taken within the Service, timestamps.
- Device and technical data: device type, operating system, browser type, IP address, general location derived from IP (city/country level), and unique device identifiers used for push notifications.
- Cookies and similar technologies: used for authentication sessions, preferences, and (where consented) analytics. See Section 7.
1.3 Information from Third Parties
- Our payment processor (merchant of record) may share limited billing and subscription-status data with us to enable account provisioning.
2. How We Use Your Information
We use the information we collect to:
- provide, operate, and maintain the Service;
- authenticate your account and secure it against unauthorized access;
- process subscriptions, billing, and payments (via our payment processor);
- send transactional communications (e.g., receipts, security alerts, service notices);
- send push notifications you have enabled;
- send product and service communications, such as monthly account activity reports or feature reminders, which you may opt out of at any time;
- send marketing communications, but only where you have opted in, and only until you opt out;
- monitor, analyze, and improve the Service’s performance and reliability;
- detect, prevent, and address fraud, abuse, or security incidents;
- comply with legal obligations.
3. Legal Basis for Processing (GDPR)
Where GDPR applies, we rely on the following legal bases:
- Contract: processing necessary to provide the Service you signed up for (account, subscription, core functionality).
- Consent: for marketing communications, optional push notifications, and non-essential cookies/analytics. You may withdraw consent at any time.
- Legitimate interests: for security, fraud prevention, improving the Service, and sending product and service communications (e.g., account activity reports, feature reminders), balanced against your rights.
- Legal obligation: for tax, accounting, and regulatory compliance.
4. How We Share Your Information
We do not sell your personal data. We share information only in the following circumstances:
- Service providers: hosting providers, payment processor (merchant of record), email delivery services, push notification services (e.g., Apple APNs / Web Push), and analytics providers, each bound by contractual confidentiality and data protection obligations.
- Legal requirements: where required to comply with applicable law, legal process, or governmental request.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to continued protection of your data under this Policy.
- With your consent: for any other purpose disclosed to you at the time of collection.
5. International Data Transfers
As we operate internationally, your data may be processed in countries other than your own, including countries that may not have data protection laws equivalent to those in your jurisdiction. Where we transfer personal data from the EEA/UK to a third country, we rely on appropriate safeguards such as Standard Contractual Clauses.
5a. Sub-Processors
We use the following categories of sub-processors to operate the Service; an up-to-date list with specific vendor names is available on request at support@sherules.me:
- Infrastructure/hosting provider (VPS, email delivery, VPN/network infrastructure)
- Payment processor / merchant of record
- Push notification providers (Apple APNs, Web Push services)
- Analytics provider (only where you have consented to analytics cookies)
We remain responsible for ensuring these sub-processors provide an adequate level of data protection through contractual safeguards.
5b. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required by law, and will notify affected users without undue delay where the breach is likely to result in a high risk to them, describing the nature of the breach and the steps we are taking.
5c. Additional Rights for California Residents (CCPA/CPRA)
If you are a California resident, you additionally have the right to: know what personal information we collect and how it is used and shared; request deletion of your personal information; correct inaccurate information; opt out of the “sale” or “sharing” of personal information (we do not sell personal information); and not be discriminated against for exercising these rights. To exercise these rights, contact support@sherules.me.
6. Data Retention
We retain personal data for as long as your account is active and as necessary to provide the Service. After account deletion, we delete or anonymize personal data within 30 days, except where retention is required for legal, tax, accounting, or dispute-resolution purposes.
7. Cookies and Tracking Technologies
We use:
- Strictly necessary cookies: required for login sessions and core functionality (no consent required).
- Preference cookies: to remember your settings.
- Analytics cookies: used only with your consent, to understand usage patterns and improve the Service.
You can manage cookie preferences through the cookie banner presented on first visit, or through your browser settings.
8. Your Rights
Depending on your location, you may have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request deletion of your data (“right to be forgotten”);
- object to or restrict certain processing;
- request a portable copy of your data;
- withdraw consent at any time (without affecting prior lawful processing);
- lodge a complaint with your local data protection authority.
To exercise these rights, contact us at support@sherules.me. We will respond within the timeframe required by applicable law (typically 30 days).
9. Data Security
We implement technical and organizational measures to protect your data, including encryption in transit, hashed credential storage, WebAuthn-based authentication, and access controls on our infrastructure. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
10. Children’s Privacy
The Service is not intended for individuals under 18 years of age, and account registration requires age confirmation. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from a minor, we will delete it promptly and may terminate the associated account. If you believe a minor has provided us personal data, contact support@sherules.me immediately.
10a. Do Not Track
Some browsers offer a “Do Not Track” signal. Because there is no industry-standard interpretation of this signal, we currently do not respond to it; you can still manage tracking through the cookie controls described in Section 7.
10b. Security Incident Response
We maintain internal procedures for detecting, investigating, and responding to security incidents, including access logging, encryption of data in transit, and periodic review of server and VPN infrastructure access controls.
11. Push Notifications
If you enable push notifications, we collect a device/browser push token used solely to deliver notifications to you. You can disable push notifications at any time via your device or browser settings, which will stop further delivery and cause us to delete the associated token.
12. Third-Party Payment Processing
Our payment processor acts as the merchant of record for subscription purchases and independently processes your payment data (including card details) under its own privacy policy. We recommend reviewing that provider’s privacy policy for details on how your payment data is handled.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notice before taking effect. The “Last Updated” date at the top reflects the most recent revision.
14. Contact Us
For questions about this Privacy Policy or to exercise your data rights, contact:
Email: support@sherules.me
Address: 10 Hyusisayin poghota, Yerevan, Armenia
