Privacy Policy
The SpaceInfo Club — spaceinfo.club
Version: 2.2 — updated 21 September 2026 · Effective date: 21 September 2026 · Replaces: the version dated 09 September 2026
1. Who is responsible for your data
The SpaceInfo Club – Email: [email protected]
We have not appointed a Data Protection Officer; we are not required to. Write to the address above for anything concerning your data, and a person will read it.
2. What this policy covers
This policy explains how we handle personal data when you visit spaceinfo.club, register for a free webinar or masterclass, subscribe to our newsletter, create an account, take one of our courses, or contact us.
It sits alongside our Cookie Policy, which explains the trackers themselves, and our Terms and Conditions.
3. What we collect, and where it comes from
You give us directly:
- your first name and email address, when you register for a webinar, subscribe, or create an account;
- your account credentials;
- billing details, when you purchase through our store — processed by WooCommerce and our payment provider, see §5;
- anything you write to us, post in a course, or ask during a live session;
- optionally, what you tell us about your background, your studies or your goals.
We collect automatically:
- usage data: pages visited, time on page, referrer, approximate location derived from IP, device and browser type;
- your progress inside a course: which modules you opened and completed. We use this to run the course and, where relevant, to handle a First Orbit Guarantee request;
- identifiers set by cookies and similar technologies, subject to your consent — see the Cookie Policy.
We receive from third parties:
- aggregated advertising and audience data from Google and Meta, where you interacted with our ads.
We do not buy personal data, and we do not collect special categories of data (health, beliefs, political opinions and so on). Please do not send them to us.
4. Why we use it, and our legal basis
| What we do | Legal basis |
| Deliver a course, membership or masterclass you registered or paid for; give you access; handle refunds | Contract — Art. 6(1)(b) GDPR |
| Send service messages: joining links, reminders, receipts, access details, changes to a Programme | Contract — Art. 6(1)(b) |
| Send our newsletter and marketing emails | Consent — Art. 6(1)(a). Freely given, separate from any purchase, withdrawable at any time |
| Email our existing customers about our own similar products | Legitimate interest / soft spam — Art. 130(4) Italian Privacy Code. Every message carries a one-click opt-out |
| Analytics, to understand what works on the site | Consent — Art. 6(1)(a), collected through the cookie banner |
| Advertising, remarketing and audience building on Google and Meta | Consent — Art. 6(1)(a), collected through the cookie banner. See §8 on profiling |
| Keep the site secure, prevent fraud and abuse | Legitimate interest — Art. 6(1)(f) |
| Invoicing, tax and accounting records | Legal obligation — Art. 6(1)(c) |
| Establish, exercise or defend legal claims | Legitimate interest — Art. 6(1)(f) |
Providing your data is not a statutory obligation. For a purchase or a registration it is a contractual necessity: without a name and an email we cannot give you access or send you the joining link. For marketing it is entirely optional, and refusing has no effect on anything you have bought.
Withdrawing consent is always possible and takes effect for the future. It does not make what we did before unlawful.
5. Who else sees your data
We do not sell your personal data and we do not share it for anyone else’s independent marketing.
A note that matters for accuracy: much of our stack runs on our own website, not on someone else’s cloud. Our course platform (Tutor LMS), our funnel and opt-in forms (WPFunnels) and our email automation (Mail Mint) are software installed on our own hosting. The plugin makers do not receive your data. What matters for you is therefore who hosts, who transmits, who processes payment or who tracks — and that is this list:
| Who | What they do | Where |
| Hostinger | Web hosting and databases — where the site and its data physically live | EU |
| Cloudflare | DNS, CDN, security and bot protection in front of the site | US / global |
| WooCommerce | Runs our store, order and checkout process — software installed on our own hosting, like Tutor LMS and WPFunnels above | Runs on our own server (Hostinger) |
| WooCommerce Stripe Gateway | Actually takes your card or other payment and holds your billing data. Live and processing real payments as of 21 September 2026 (confirmed by Sebastiano) — it was still in test/sandbox mode when we last checked, on 9 September 2026. | US (Stripe) |
| Brevo | Transmits the emails our automation generates — confirmed 9 September 2026 as the SMTP/API service configured in Mail Mint | EU (France) |
| beehiiv | Runs our newsletter; holds subscriber names and email addresses | US |
| Google (Analytics, Ads, Tag Manager, Fonts, reCAPTCHA) | Site analytics, advertising, remarketing, form protection and web fonts | US |
| Meta (Facebook/Instagram pixel and ads) | Advertising, conversion measurement and audience building | US / Ireland |
| WEBINAR PLATFORM | Hosts the live sessions | Ref. To Google above |
We may also disclose data to our accountant, our lawyers, or a public authority where the law requires it.
Each of the above acts as our processor under a data processing agreement, except Google and Meta, which act as independent or joint controllers for parts of their advertising activities under their own terms.
6. Transfers outside the EEA
Some of the recipients above are established in the United States. Where personal data is transferred outside the European Economic Area, we rely on:
- the EU–US Data Privacy Framework, where the recipient is certified under it; or
- the European Commission’s Standard Contractual Clauses, with a transfer impact assessment and, where necessary, additional technical and organisational measures.
You may ask us for a copy of the safeguards in place for a specific transfer by writing to [email protected].
7. How long we keep it
| Data | Retained |
| Account and course data | While the account is open, then 12 months, unless a longer period is required for legal claims |
| Purchase, invoice and tax records | 10 years, as required by Italian law |
| Newsletter and marketing data | Until you withdraw consent or unsubscribe, then a minimal suppression record so we do not email you again |
| Webinar registration data (if you never became a customer) | 24 months from the event |
| Recordings of live sessions | While the replay is available, and thereafter in our archive unless you ask for removal — see §9 |
| Analytics data | Per the tool’s setting; Google Analytics is set to 14 months |
| Server and security logs | 30–90 days |
| Refund and guarantee correspondence | 10 years, as part of the contract record |
8. Profiling and advertising
We use Google and Meta advertising tools that build audiences and show you our ads based on your behaviour on our site — including remarketing and lookalike-style audiences. This is profiling for direct marketing purposes.
Two things follow, and they are unconditional:
- You can object at any time, and we must stop. No reason required, no balancing test (Art. 21(2)–(3) GDPR).
- It only happens if you consented through the cookie banner. Decline marketing cookies, or change your choice later through the banner’s preferences, and it does not happen at all.
We do not make decisions about you that produce legal or similarly significant effects on the basis of automated processing alone (Art. 22 GDPR). Nothing we automate decides whether you get access, a refund, or a place on a course; a person does that.
9. Live sessions and recordings
Our live sessions are recorded, and we say so at the start of each one.
- If you attend with camera and microphone off and do not post in the chat, you do not appear in the recording. That is the default.
- If you turn on your camera or microphone, or write in the chat, that participation may be captured and included in the replay we make available to registrants.
- You can ask us to remove you — write to [email protected] and we will edit you out or remove the recording. You do not have to explain why.
- If we ever want to use a clip of an identifiable participant in advertising, we ask that person specifically and in advance. We never treat your acceptance of our Terms as permission for that.
10. Your rights
Under the GDPR you have the right to: access your data; have it rectified; have it erased; restrict processing; object to processing based on legitimate interest, and object absolutely to direct marketing; receive your data in a portable format; and withdraw consent at any time.
How to exercise them: email [email protected]. There is no charge.
How fast we respond: we reply without undue delay and in any event within one month of receiving your request. Where a request is complex or where you have made several, we may extend by up to two further months — and if we do, we will tell you within the first month and explain why. This is the standard set by Article 12(3) GDPR.
If you are unhappy with how we handled it, you may lodge a complaint with a supervisory authority — in Italy, the Garante per la Protezione dei Dati Personali (garanteprivacy.it); or, if you live or work elsewhere in the EU, with the supervisory authority of your own country, which Article 77 GDPR entitles you to do. You may also go to court.
11. Marketing: how to stop hearing from us
Every marketing email carries a one-click unsubscribe link. You can also write to [email protected] and simply say stop.
Unsubscribing from marketing does not cancel a course you have paid for, and does not stop the service messages you need — access details, receipts, and notices about a Programme you hold.
12. Children
Our services are not directed to anyone under 16, and we do not knowingly collect their data. To purchase a Programme you must have reached the age of majority in your country, or have the consent of a parent or guardian — see §9 of our Terms and Conditions.
If you believe a child has given us personal data, write to [email protected] and we will delete it.
13. Security
We use HTTPS across the site, access controls on the administrative back end, a security and bot-protection layer in front of the site, and regular backups. No system is perfectly secure; if a breach occurs that is likely to result in a high risk to your rights, we will notify you and the Garante as Articles 33 and 34 GDPR require.
14. Changes to this policy
We may update this policy. The version number and effective date at the top change when we do. Where a change materially affects how we use data about you, we will tell you by email before it takes effect. We keep dated copies of previous versions and will provide one on request.
15. Contact
[email protected] — for privacy requests, put Privacy in the subject line.
The SpaceInfo Club
