Privacy policy

MYSTIC REBELS

PRIVACY POLICY

Last Updated: July 24, 2026

.policy-date { font-size: 0.8rem; color: #666666; /* Muted gray */ margin-top: -10px; /* Pulls it closer to the main heading */ margin-bottom: 20px; font-style: italic; }

Mystic Rebels LLC, doing business as Mystic Rebels (“Mystic Rebels,” “we,” “us,” or “our”), respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit mysticrebels.com, use a customer account, purchase products or memberships, book or receive services, participate in Mystic Circle, communicate with us, join or use an affiliate or practitioner program, or otherwise interact with us.

This Policy applies unless a more specific notice governs the activity. Our Consumer Health Data Privacy Policy applies to consumer health data and should be read together with this Policy. If applicable law provides greater rights, we will honor those rights. This Policy is not a contract that waives non-waivable privacy rights.

1. Who we are

Mystic Rebels LLC is the business responsible for the personal information described in this Policy. Our notice address is 7901 4th St N Ste 300, St Petersburg, Florida 33702, USA. Privacy requests may be emailed to vibe@mysticrebels.com.

2. Personal information we collect

Depending on how you interact with us, we may collect:

Contact and identity information. Name, email address, telephone number, billing and shipping addresses, country, and identifiers associated with your account.

Account and profile information. Customer-account details, login or authentication records, preferences, membership status, usernames, profile content, and account activity. Shopify customer accounts may use passwordless or other authentication methods.

Transaction and commercial information. Products viewed or purchased, order history, subscriptions, refunds, discounts, gift cards, delivery status, and payment-related information. Payment card data is generally processed by Shopify or the applicable payment provider rather than stored directly by Mystic Rebels.

Device, browsing, and network information. IP address, browser, device, operating system, referral URL, pages viewed, clicks, session activity, cookies, pixels, and similar technologies.

Marketing and preference information. Subscription status, consent records, message engagement, campaign interactions, interests, and communication preferences.

Booking and service information. Appointment details, intake responses, service history, correspondence, scheduling information, preferences, and notes used to provide or improve future services.

Astrology and personal-context information. Birth date, birth time, birth location, current location, and personal information voluntarily provided about relationships, family, finances, career, spirituality, goals, or circumstances.

Consumer health and wellness information. Health, symptom, medication, supplement, pregnancy or fertility, mental or emotional, dietary, sleep, substance-use, lifestyle, and family-health information voluntarily provided for a wellness service. See our separate Consumer Health Data Privacy Policy.

Recordings and derived materials. With consent, audio, video, captions, transcripts, and generated reading or follow-up materials, together with limited notes derived from them.

Community and user-generated content. Mystic Circle posts, comments, reactions, profile information, reviews, ratings, uploaded content, chat messages, and wishlist activity. Content posted in public or member-visible areas is visible to the audience indicated by that service.

Affiliate and practitioner information. Referral links, cookie and click identifiers, attributed orders, commissions, payment and tax information, program activity, and communications.

Fraud, security, and compliance information. Signals used to authenticate accounts, prevent abuse, investigate incidents, enforce agreements, handle disputes, and meet legal obligations.

Inferences. Preferences or interests inferred from purchases, site interactions, wishlists, or communications, but not inferences from health, intake, birth, session, recording, transcript, or client-file data for advertising.

3. Sources of information

We collect information directly from you; automatically from your browser or device; from Shopify and other vendors that support our store and services; from persons who purchase for or refer you; from affiliates, practitioners, and community activity; and from advertising, analytics, fraud-prevention, shipping, and payment partners. We may combine information from these sources when permitted by law.

4. How we use information

Provide, personalize, fulfill, deliver, and support products, digital downloads, appointments, readings, memberships, community access, and customer accounts.

Process orders, payments, subscriptions, shipping, refunds, fraud screening, and customer-service requests.

Create and maintain client files so future bookings, advice, and recommendations can account for relevant history and preferences.

Schedule and conduct sessions, create requested follow-up materials, and honor recording choices.

Operate wishlists, reviews, chat, affiliate tracking, practitioner administration, and referral payments.

Send transactional or service communications and, with appropriate consent or another lawful basis, marketing communications.

Measure site performance, understand engagement, personalize the storefront, and conduct advertising subject to consent and opt-out rights.

Secure our services, prevent abuse, enforce policies, protect rights and safety, resolve disputes, and comply with law.

Develop, test, and improve business processes and services using appropriately limited information.

We do not use health, birth, intake, session, recording, transcript, or client-file information to create advertising audiences, measure advertisements, personalize advertisements, or upload customer lists to advertising platforms.

5. Legal bases for EEA, UK, and similar jurisdictions

Where a legal basis is required, we process information as necessary to perform a contract or take requested pre-contract steps; comply with legal obligations; pursue legitimate interests such as operating, securing, supporting, and improving our business where those interests are not overridden by your rights; establish or defend legal claims; protect vital interests where applicable; or based on consent. You may withdraw consent prospectively. Withdrawal does not affect processing already lawfully completed.

Where special-category or sensitive information requires an additional condition or separate consent, we will obtain it or use another condition permitted by law. If we cannot lawfully process information needed for a requested service, we may be unable to provide it.

6. Cookies, analytics, and advertising technology

We and our providers may use cookies, pixels, tags, software development kits, local storage, and similar technologies for essential store functions, security, preferences, analytics, personalization, affiliate attribution, and advertising. Providers may include Shopify and advertising or analytics services associated with Meta, Google, Pinterest, and TikTok.

Where required, non-essential technologies are used only after consent. You can use our cookie-preference controls and data-sharing opt-out page, if available in your region, and browser settings. Blocking technologies may affect site features. We recognize Global Privacy Control and other legally required opt-out preference signals for the browser or device sending the signal.

7. Sale, sharing, and targeted advertising

Mystic Rebels does not sell personal information for money. We do not upload customer lists to advertising platforms. However, some privacy laws define “sell,” “share,” or “targeted advertising” broadly enough to include disclosure of online identifiers or activity through advertising cookies, pixels, or similar technology. To the extent our activity falls within those definitions, you may opt out through our data-sharing opt-out page, cookie controls, a recognized Global Privacy Control signal, or by contacting us.

We do not knowingly sell or share personal information of anyone under 18, and we do not sell, share, or use health, birth, intake, session, recording, transcript, or client-file information for targeted advertising.

8. How we disclose information

We may disclose personal information to the following recipients for the purposes described in this Policy:

Commerce and payments. Shopify and its checkout, payment, fraud, customer-account, email, and related services.

Memberships, bookings, sessions, and workflow. Appstle, Circle, Appointo, Zoom, Google Workspace, Gmail, Google Drive, Zapier, Make, and OpenAI services configured for authorized business processing.

Marketing, reviews, wishlists, and chat. Omnisend, Shopify Email, Judge.me, Wishlist Hub, Chizy, ShopSifu, Shopify Inbox, and permitted advertising or analytics partners.

Production, fulfillment, and delivery. Printful, Printify, Gelato, Merchize, InkedJoy, NinjaPOD, Tapstitch, Spreadconnect, Bookvault, carriers, customs authorities, and delivery partners.

Digital delivery. FetchApp, Shopify Digital Products, Fileflare, and other providers used to securely deliver purchased files.

Affiliate and practitioner administration. GoAffPro, assigned practitioners, and authorized program administrators.

Professional, legal, and protective recipients. Accountants, legal advisers, insurers, security providers, regulators, courts, law enforcement, or others when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or handle a claim.

Business transactions. A buyer, investor, lender, adviser, successor, or other participant in a proposed or completed merger, financing, reorganization, acquisition, sale, or transfer, subject to appropriate safeguards.

Vendor names and functions may change as our business evolves. Providers process information under their own terms and privacy notices and, where applicable, our instructions and contractual safeguards.

9. Sensitive intake, readings, and client files

Health and wellness intake, astrology intake, birth information, private session content, and client-file notes are treated as sensitive. We limit access to authorized Mystic Rebels personnel, the practitioner assigned to provide the requested service, and technical processors necessary to operate the service. We do not disclose this information to unrelated parties or use it for advertising.

Client files may contain relevant facts or recommendations from an intake, session, transcript, or delivered reading so future bookings, advice, and recommendations can reflect your history. Our separate Consumer Health Data Privacy Policy provides more detail about health-related information and applicable rights.

10. Recordings, transcripts, delivered readings, and AI-assisted processing

A booking may offer a choice about recording. Recordings are not automatic. We verify the choice and manually start a recording only after consent. If a session or delivered reading is recorded, Zoom cloud recordings and transcripts are configured to auto-delete within 14 days and become unrecoverable from that storage.

A recording or transcript may be downloaded or transferred temporarily for an authorized automation or production step. Mystic Rebels does not intentionally retain the raw recording or transcript after that step. A generated PDF or similar deliverable is sent in the follow-up email and is not intentionally retained by Mystic Rebels. Relevant information may be summarized in a secure client file.

We may use service providers, including automation and AI-enabled tools, to assist with transcription, organization, drafting, or delivery. We configure those tools for business processing and do not intentionally submit sensitive client information for public model training or advertising. Provider-side logs, backups, or security records may persist under provider terms and law even after Mystic Rebels deletes its working copy.

11. Marketing communications

Purchasing from us does not, by itself, enroll you in promotional marketing. We send marketing email only when you affirmatively subscribe or where another lawful basis permits it. You may unsubscribe through any marketing email or by contacting us. We may still send non-promotional messages about orders, accounts, bookings, memberships, security, policy changes, or other service matters.

If we introduce SMS or WhatsApp marketing, we will obtain any separately required consent and provide required opt-out instructions. Consent to marketing is not a condition of purchase unless expressly permitted by law.

12. Community, reviews, and public content

Mystic Circle may permit a real name or username. Reviews, posts, comments, reactions, profile details, or other content you choose to publish may be visible to other members or the public according to the feature used. Do not post sensitive information you do not want that audience to see. We may moderate, retain, or remove content to administer the community, enforce rules, protect users, or comply with law.

13. Affiliate and practitioner programs

GoAffPro and similar tools may use a referral link, click identifier, device or browser information, and a cookie lasting up to 30 days to attribute a qualifying purchase. We also process affiliate or practitioner account, payment, tax, performance, and communication information to operate the program. Program participants are subject to their separate agreement.

Current affiliate-program terms: Mystic Rebels Affiliate Program Terms

14. Independent third parties

Our services may link to or feature independent affiliates, partners, practitioners, platforms, or sellers. Unless we expressly state otherwise, they do not represent Mystic Rebels and control their own privacy practices. Review their notices before providing information. This does not alter Mystic Rebels’ responsibility for information we control or direct them to process for us.

15. Retention

We retain each category of personal information for as long as reasonably necessary for the purposes described in this Policy, to maintain an ongoing relationship, comply with law, resolve disputes, enforce agreements, protect security, and maintain appropriate business records. Retention periods differ by record and jurisdiction.

Client files used for continuity are retained by default for the ongoing client relationship and may be retained indefinitely unless you submit a verified written request for deletion, we determine the information is no longer reasonably necessary, or applicable law requires a shorter period or periodic review. We use those files only to inform future bookings, advice, recommendations, continuity, and service support—not advertising.

Recordings and transcripts in Zoom cloud storage are configured to auto-delete within 14 days. Temporary working copies and generated PDFs are not intentionally retained after authorized processing or delivery. Order, tax, accounting, fraud, consent, dispute, and legal records may be kept for the period required or reasonably appropriate under law. Deletion may not immediately remove information from encrypted backups or records that we must retain; retained information remains protected and is isolated from ordinary use.

16. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information, including access controls and use of service providers intended to support secure processing. No transmission or storage method is completely secure. You are responsible for protecting access to your email, devices, and account-authentication methods.

17. Your privacy rights and choices

Depending on where you live and subject to exceptions, you may have the right to confirm whether we process your information; access, correct, delete, or receive a portable copy; withdraw consent; restrict or object to processing; opt out of sale, sharing, targeted advertising, or certain profiling; limit use or disclosure of sensitive information; obtain information about recipients; and appeal a denied request. You may also lodge a complaint with your local privacy authority.

To exercise a right, email vibe@mysticrebels.com or use an available privacy-choice page. State the right requested and the email or account involved. We may verify identity and authority, request only information reasonably necessary for verification, and use an authorized agent where law permits. We will respond within the legally required time. If we deny a request, you may appeal by replying with “Privacy Appeal” in the subject line. We do not unlawfully discriminate for exercising privacy rights.

You can manage marketing choices through unsubscribe links, cookie choices through our preference controls, and qualifying sale, sharing, or targeted-advertising choices through our data-sharing opt-out page or a recognized Global Privacy Control signal.

18. International transfers

Mystic Rebels is based in the United States and uses providers that may process information in the United States and other countries. Those countries may have different privacy laws. Where required, we use an approved transfer mechanism or other appropriate safeguards. You may contact us for information about applicable safeguards.

19. Adults only

Our store, accounts, memberships, and services are intended only for adults age 18 or older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information, contact us so we can investigate and take appropriate action.

20. Changes to this Policy

We may update this Policy to reflect changes in law, technology, vendors, or business practices. We will post the revised Policy with a new effective date and provide additional notice or obtain consent when required. Material changes apply prospectively unless law permits otherwise.

21. Contact us

Mystic Rebels LLC
7901 4th St N Ste 300
St Petersburg, FL 33702, USA
Email: vibe@mysticrebels.com