Misdirect ("we", "us", "our") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our service.
We comply with the EU General Data Protection Regulation (GDPR), the New Zealand Privacy Act 2020, and the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
1. Who We Are
Misdirect is operated by [Your Legal Entity Name], based in [Your Country]. For privacy enquiries, contact us at privacy@misdirect.app.
2. Information We Collect
2.1 Information you provide
- Email address — when you join our pre-registration list or create an account.
- Name — optional, when you provide it during sign-up.
- Account credentials — a hashed password when you create a full account.
- Profile and usage data — practice sessions, tricks, routines, and performance logs you enter into the app.
2.2 Information collected automatically
- IP address — recorded at the time of registration for fraud prevention and legal compliance.
- Cookie preferences — your consent choices are stored.
- Log data — standard server logs (timestamps, pages visited, HTTP method).
3. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA) and United Kingdom, our legal bases are:
- Consent (Art. 6(1)(a)) — for marketing emails and non-essential cookies.
- Contract (Art. 6(1)(b)) — to provide and maintain the service you sign up for.
- Legitimate interests (Art. 6(1)(f)) — for fraud prevention, security, and service improvement.
- Legal obligation (Art. 6(1)(c)) — where required by law.
4. How We Use Your Information
- To deliver the Misdirect service and manage your account.
- To send transactional emails (account verification, password reset, launch notifications).
- To send marketing communications where you have given consent (you may opt out at any time).
- To improve and troubleshoot our service.
- To comply with legal obligations.
- To protect against fraud and abuse.
5. Cookies
We use cookies and similar technologies. Please see our Cookie section below.
You may withdraw cookie consent at any time via the cookie preference link in the footer.
6. Third-Party Services
We use the following third-party processors. Each has been assessed for GDPR/privacy compliance:
- MailerLite — email delivery and marketing. Data may be stored in the EU/US. MailerLite is EU-U.S. Data Privacy Framework certified. MailerLite Privacy Policy.
- Amazon Web Services (AWS) — cloud hosting and storage (region: [Your AWS Region]).
- Stripe — payment processing. We do not store card details. Stripe Privacy Policy.
7. Data Retention
- Pre-registration emails — retained until you unsubscribe or request deletion.
- Account data — retained for the duration of your account plus 30 days after deletion.
- Billing records — retained for 7 years to comply with financial regulations.
- Server logs — retained for 90 days.
8. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — request deletion of your data, subject to legal retention requirements.
- Portability — receive your data in a structured, machine-readable format (GDPR Art. 20).
- Restriction — request we limit processing of your data.
- Objection — object to processing based on legitimate interests or for direct marketing.
- Withdraw consent — at any time, without affecting the lawfulness of prior processing.
To exercise any right, email privacy@misdirect.app. We will respond within 30 days (GDPR) or 20 working days (NZ Privacy Act 2020).
If you believe we have not handled your data correctly, you may lodge a complaint with your local supervisory authority (e.g. the Irish DPC, the UK ICO, the NZ Privacy Commissioner, or the OAIC in Australia).
9. International Transfers
Your data may be processed in countries outside your own. When we transfer data outside the EEA or UK, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or an adequacy decision.
10. Children's Privacy
Misdirect is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have received data from a minor, please contact us immediately at privacy@misdirect.app.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes by email. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact Us
For any privacy-related enquiries:
Email: privacy@misdirect.app
Address: [Your Business Address]