Last updated: August 26, 2026
This Privacy Policy explains what personal information Grace Membership collects, how it is used, and the choices and rights you have. The data controller for this website (www.gracemembership.com) is Udara Bogodage, 1317 Edgewater Dr, Orlando, FL 32804, US. You can reach us about anything in this policy at hi@gracemembership.com.
1. Information we collect
- Account information — name, email address and password (stored hashed) when you register.
- Order and billing information — the details needed to bill your membership: billing name, billing address, email, subscription status and payment history. Your full card number is never collected or stored by us; card details are entered into and processed directly by Stripe, our payment processor. We receive only limited payment metadata from Stripe (such as card brand, last four digits and expiry) so you can recognise and manage your saved payment method.
- Contact messages — the name, email address and message you submit through our contact form (powered by WPForms).
- Technical data — standard server logs and essential cookie data (IP address, browser type, pages requested) generated when any website is used, kept for security and troubleshooting.
2. How we use your information
We use personal information to: create and manage your account; provide access to the members-only library; process subscription payments and send billing receipts and renewal or payment-failure notices; respond to support and contact messages; maintain the security of the Site; comply with tax, accounting and other legal obligations; and, only if you separately opt in, send occasional email updates (which always include an unsubscribe link). We do not sell your personal information, and we do not use it for third-party advertising.
3. Legal bases (for EEA/UK visitors)
Where the GDPR or UK GDPR applies, we process your data on these bases: performance of a contract (providing the membership you purchased), legal obligation (tax and accounting records), legitimate interests (site security, fraud prevention, responding to enquiries) and consent (optional communications, which you may withdraw at any time).
4. Who we share data with (processors)
We share personal data only with service providers who process it on our behalf under appropriate safeguards:
- Stripe — payment processing. Stripe handles your card details under its own privacy policy and PCI-DSS compliance.
- WooCommerce / WordPress — the store platform this site runs on, which stores account and order records in our site database.
- WPForms — processes contact-form submissions on this site.
- Our web-hosting and email providers — infrastructure on which the Site and our support inbox run.
We may also disclose information if required by law, to protect our legal rights, or as part of a business transfer, in which case this policy will continue to apply to your data.
5. Cookies and analytics
The Site uses essential cookies that are required for it to function: session cookies for login, and WooCommerce cookies that keep your cart and checkout working. These cannot be switched off while using the store. We do not run third-party advertising cookies. If we add analytics in future, we will use a privacy-respecting configuration and update this policy first. You can control or delete cookies in your browser settings; blocking essential cookies may prevent login and checkout from working.
6. Data retention
We keep account data while your account exists. Order, subscription and invoice records are kept for as long as tax and accounting laws require (typically up to seven years), after which they are deleted or anonymised. Contact-form messages are kept for up to two years so we can follow up, then deleted. Server logs are rotated on a short cycle.
7. Your rights
Depending on where you live, you may have the right to: access a copy of your personal data; correct inaccurate data; delete your data; port your data to another service; object to or restrict certain processing; withdraw consent at any time for consent-based processing; and complain to your local data-protection authority. California residents additionally have the rights provided by the CCPA/CPRA, including the right to know, delete and correct — and the right to opt out of “sale” or “sharing” of personal information; we do not sell or share personal information as those terms are defined in the CCPA/CPRA. To exercise any right, email hi@gracemembership.com; we respond within the timeframes required by applicable law and will never discriminate against you for exercising a privacy right.
8. Children’s privacy
The Site and Service are intended for adults and are not directed to children under 13 (or the higher minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
9. Security
We protect personal data with measures appropriate to a site of this kind: HTTPS across the whole Site, hashed passwords, access limited to those who need it, and payment processing delegated entirely to Stripe so that card data never touches our servers. No online service can guarantee absolute security, but we work to protect your information and will notify you and the relevant authorities of any breach where the law requires it.
10. International transfers
We are based in the United States and the Site is hosted there, so your information is processed in the US. Where data of EEA/UK residents is transferred internationally, we and our processors rely on recognised safeguards such as Standard Contractual Clauses or an adequacy framework.
11. Changes to this policy
If we change this policy, the updated version will be posted here with a new “Last updated” date, and material changes affecting members will be announced by email.
12. Contact us
Privacy questions and requests: hi@gracemembership.com · Udara Bogodage, 1317 Edgewater Dr, Orlando, FL 32804, US.