SuaLabs OÜ (“we,” “us,” or “our”) operates the website reverseyourage.org and the TIMELESS book and coaching program. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have over it. We are registered in Estonia (Registry code 17510478, Tornimäe tn 5, 10145 Tallinn, Estonia) and subject to the General Data Protection Regulation (GDPR) as an EU-based data controller. We also respect the rights of California residents under the CCPA.
1. Who We Are
Data Controller: SuaLabs OÜ
Registry code: 17510478
Address: Tornimäe tn 5, 10145 Tallinn, Estonia
Contact: [email protected]
2. What Data We Collect and Why
2.1 Email Address (Lead Magnet)
When you request the free guide (“The Physical Layer Protocol”) on our /14-upgrades page, we collect your email address. We use it to:
- Deliver the requested PDF guide
- Send follow-up emails about the TIMELESS protocol and program
- Notify you of relevant updates, launches, and offers
Legal basis (GDPR): Consent (Article 6(1)(a)). You may withdraw consent at any time by clicking the unsubscribe link in any email we send.
2.2 Purchase Data (Book Orders)
Book purchases are processed entirely through Shopify on behalf of SuaLabs OÜ. Shopify collects your name, email, shipping address, and payment information. We receive only the order confirmation and shipping details needed to fulfill your order. We do not store raw payment card data. Shopify’s own privacy policy governs its data handling: shopify.com/legal/privacy.
Legal basis (GDPR): Contract performance (Article 6(1)(b)).
2.3 Booking Data (Free Diagnosis Call)
When you book a free call, you provide your name, email, and optionally a phone number through our booking tool. We use this to schedule and conduct the call and to send relevant follow-up.
Legal basis (GDPR): Legitimate interest (Article 6(1)(f)) — pre-contractual inquiry.
2.4 Technical and Usage Data
Our server logs may automatically record your IP address, browser type, referring page, and pages visited, solely for security and server diagnostics. We do not use third-party analytics platforms (e.g., Google Analytics) on this site. We do not build behavioral profiles.
Legal basis (GDPR): Legitimate interest (Article 6(1)(f)) — maintaining server security and uptime.
2.5 Currency Detection
To display the book price in your local currency, our site makes a single anonymous request to the public API at ipapi.co to detect your country’s ISO currency code. No personal data is stored by us from this request. See ipapi.co’s privacy policy at ipapi.co/privacy.
3. Third-Party Services We Use
| Service | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Kit (ConvertKit) | Email delivery and automation | Email address | kit.com/privacy |
| Shopify | Book purchase processing | Name, email, address, payment | shopify.com/legal/privacy |
| Tella | Video hosting and playback | IP address (viewer) | tella.tv/privacy |
| ipapi.co | Currency detection | IP address (anonymous lookup) | ipapi.co/privacy |
We do not sell your personal data to any third party. Ever.
4. Cookies
This website does not set first-party tracking or analytics cookies. Embedded third-party services (Shopify Buy Button, Tella video player) may set their own cookies when you interact with those elements. You can control cookies through your browser settings.
5. Data Retention
- Email subscribers: We retain your email until you unsubscribe or request deletion, whichever comes first.
- Order data: Retained by Shopify for as long as required by applicable accounting and tax law (typically 7 years in the EU).
- Server logs: Automatically purged after 30 days.
6. Your Rights (GDPR)
If you are in the European Economic Area, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — ask us to delete your data (“right to be forgotten”)
- Restriction — ask us to limit how we process your data
- Portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interest
- Withdraw consent — unsubscribe from emails at any time via the link in any email, or by emailing us
To exercise any of these rights, email us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (aki.ee) or your local supervisory authority.
7. Your Rights (CCPA — California Residents)
If you are a California resident, you have the right to know what personal information we collect, request deletion of your personal information, and opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact us at [email protected].
8. International Data Transfers
SuaLabs OÜ is established in Estonia (EU). When we use Kit (ConvertKit) or Shopify, your data may be processed in the United States. These transfers are governed by Standard Contractual Clauses (SCCs) as approved by the European Commission, ensuring an equivalent level of data protection.
9. Children’s Privacy
This website is intended for adults only. We do not knowingly collect personal data from anyone under the age of 16. If you believe a minor has provided us with personal data, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects when the most recent changes were made. Continued use of the site after changes constitutes acceptance of the updated policy. For material changes, we will notify active email subscribers.
11. Contact
Questions, requests, or concerns about this Privacy Policy: [email protected]
SuaLabs OÜ
Tornimäe tn 5, 10145 Tallinn, Estonia
Registry code: 17510478