Privacy Policy
1. Who we are
Beauty is Power LLC ("we", "us", "our") operates this site and the Members Dashboard at members.perfumedpages.xyz. We act as the data controller for personal data described in this policy.
Contact: hello@perfumedpages.xyz.
2. Personal data we collect
We deliberately collect as little as possible. In full, this is everything stored about you on our systems:
| Category | What exactly | Source |
|---|---|---|
| Account record | Your email address, your enrollment tier (new or alumni), your access status (active, revoked, or expired), the plan identifier from your purchase, the date you enrolled, the date your access expires, and any note we add if we have to correct your record manually | Created from your checkout |
| Sign-in token | A single-use random token linked to your email address, held for 15 minutes and deleted the moment it is used | Generated when you request a sign-in link |
| Session cookie | One cookie, pp_session, containing your email address and an expiry timestamp, cryptographically signed so it cannot be altered | Set in your browser when you sign in |
| Billing data | We hold no billing data. Your card details, billing address, and transaction history live with Paythen and its payment processor, Stripe. All we receive is your email address and which plan you purchased | Paythen |
| Communications | Emails you send us, and our replies | Provided by you |
What we do not collect: no passwords (none exist), no card numbers, no analytics or usage tracking, no IP address logs, no device fingerprints, no location data, no record of which pages you visit or how long you spend on them, and no advertising or profiling data of any kind.
3. Legal basis (GDPR / UK GDPR Art. 6)
- Contract performance (Art. 6(1)(b)) — holding your email address and access status so we can give you the program you paid for, and sending you the sign-in links and account emails required to deliver it.
- Legal obligation (Art. 6(1)(c)) — tax and accounting records, and responding to lawful requests.
- Consent (Art. 6(1)(a)) — for any optional marketing email you opt into, and for any non-essential cookies. At present we set none.
4. How we use your data
- Check that you are an enrolled member when you open a members-only page.
- Email you a one-time sign-in link when you request one.
- Email you account notices — enrollment confirmation, access changes, payment problems, changes to these terms.
- Comply with legal and tax obligations.
We do not use your data to profile you, score you, target advertising at you, or train any automated decision-making or machine-learning system.
5. Sharing & processors
We share data only with the processors below, who act on our instructions:
| Processor | Purpose | Data reaching them |
|---|---|---|
| Cloudflare, Inc. (USA) | Site hosting (Pages), member database (D1), sign-in token storage (KV), network delivery | Email address, tier, access status, plan identifier, dates |
| Paythen (Australia) | Checkout and payment plans | Everything you enter at checkout. Paythen is the controller of that data; see their privacy policy |
| Stripe | Card processing, via Paythen | Your card details. Paythen is not itself a payment processor — it uses Stripe, which is PCI Service Provider Level 1 certified. We never see or store card numbers |
| Brevo (Sendinblue SAS, France) | Sign-in links, account emails, mailing list | Email address, tier, access status |
Third-party content loaded by your browser. Some pages load web fonts from Google Fonts (fonts.googleapis.com, fonts.gstatic.com), and a small number of interactive tools load code libraries from the unpkg CDN. When your browser fetches these files it necessarily reveals your IP address to those providers. We do not receive that information, and we do not use it.
Discord. The program community runs on Discord. If you join, Discord Inc. is a separate, independent controller of everything you do there, under its own terms and privacy policy. We do not export or store Discord data.
We do not sell personal data, we do not share it with advertisers, and we do not share it with data brokers.
6. International transfers
Cloudflare is US-based and operates a global network, so data may be processed outside the EEA and UK. Brevo is established in France and processes within the EU. Where personal data is transferred outside the EEA or UK we rely on the EU Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework for transfers to certified US recipients. Paythen operates from Australia and its terms are governed by the law of New South Wales; payments are received and processed in Australia. Australia is not covered by an EU adequacy decision, so those transfers rely on the Standard Contractual Clauses.
7. Retention
Your account record is kept for as long as your access is active. Access automatically lapses 12 months after enrollment.
Sign-in tokens are deleted automatically after 15 minutes or on first use, whichever comes first. Your session cookie expires 30 days after you sign in, and is cleared immediately if you sign out.
If you ask us to delete your data, we remove your account record within 30 days of your request, keeping only what tax and accounting law requires us to keep.
Records of members whose access has ended are cleared during a review we carry out at least every three months. Between reviews an expired record may still exist in our database, but it no longer grants access to anything. You do not have to wait for a review — ask us at hello@perfumedpages.xyz and we will delete it within 30 days.
8. Your rights
Depending on where you live, you may have the right to:
- Access a copy of your personal data (GDPR Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data ("right to be forgotten", Art. 17)
- Restrict or object to processing (Art. 18, 21)
- Port your data to another service (Art. 20)
- Withdraw consent at any time, without affecting prior lawful processing
- Lodge a complaint with your local supervisory authority (e.g., the UK ICO, Ireland DPC, your state attorney general, or the California Privacy Protection Agency)
California residents additionally have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of "sale" or "sharing" of personal information. We do not sell or share personal information for cross-context behavioral advertising.
To exercise any right, email hello@perfumedpages.xyz. We respond within 30 days.
9. Cookies & browser storage
We set exactly one cookie, pp_session, and only after you sign in. It is strictly necessary and requires no consent. We set no analytics, advertising, or tracking cookies.
Separately, several practice tools save your work in your browser's own local storage so it survives a page refresh — your notebook entries, journal entries, word clouds, and map progress. That data never leaves your device and we cannot see it. Clearing your browser storage deletes it permanently, and we hold no copy to restore. Full detail in the Cookie Policy.
10. Security
There are no passwords to steal, because we do not use them. You sign in with a one-time link that works once and expires after 15 minutes.
Your session cookie is signed with HMAC-SHA256, so it cannot be forged or edited, and is set HttpOnly (unreadable by scripts), Secure (HTTPS only), and SameSite=Lax (not sent from other sites). All traffic is encrypted in transit with HTTPS/TLS. Members-only pages deny access by default and are opened only for a valid session belonging to an active member.
No system is completely secure, but we hold very little about you, which is itself the strongest protection we can offer.
11. Children
The program and Members Dashboard are intended for users 18 and older. We do not knowingly collect data from anyone under 18. If you believe a minor has enrolled, contact us and we will delete the account.
12. Affiliate & referral links
Material pages link to suppliers so you can source your own materials. Many of these run through ShopMy (shopmy.us / go.shopmy.us). If you click one and buy something, we may earn a commission at no extra cost to you.
Clicking an affiliate link hands you off to ShopMy and then to the merchant, both of which may set their own cookies and record the click. That processing is governed by their privacy policies, not this one. Nothing is shared with them unless you click, and links are never personalised to you — every member sees the same link.
13. Changes to this policy
We will post material changes here and, where appropriate, notify members by email. The "Last updated" date at the top reflects the current version.
14. Contact
Beauty is Power LLC — hello@perfumedpages.xyz.