BRANDED REVIEW COPY · Not published or approved · Revised source wording retained
Divine Design seal
DIVINE DESIGN LLC
DISCOVER · DESIGN · DIRECT

Privacy Policy

Effective date: July 27, 2026

This Privacy Policy describes how Divine Design LLC ("Divine Design," "we," "us," or "our"), a Wyoming limited liability company, collects, uses, discloses, and safeguards personal information in connection with our technology-licensing, consulting, health & wellness coaching, and product services, and our websites (the "Services"). By using the Services, you agree to this Policy.

1. Our Role: Controller vs. Service Provider

We act as a controller/business for information about our consulting and coaching clients, product customers, prospects, and website visitors. Where our licensed technology processes data on a Licensee's behalf, the Licensee is the controller and we act as a service provider/processor, handling that data only per our agreement and the Licensee's instructions. If you are an end customer of a Licensee, please review that Licensee's privacy notice.

2. Information We Collect

Information you provide

Information collected automatically

3. Statutory Categories, Sources, Purposes, and Disclosures

The table maps the categories of personal information we handle (using California Consumer Privacy Act categories, as amended) to sources, purposes, and disclosures. We do not sell personal information for money, and we do not "share" it for cross-context behavioral advertising as defined under U.S. state privacy laws. We do not sell or share mobile opt-in information or SMS consent for third-party marketing; reply STOP to opt out of texts at any time.

CategoryExamplesSourcesPurposeSold / Shared
IdentifiersName, email, phone, address, IP, account IDYou; your devices; providersProvide and support the Services; fulfill ordersNo
Commercial informationEngagement, order, and billing recordsYou; payment providersProcess payments and manage engagements/ordersNo
Internet/electronic activityUsage, pages, actions, device/browser dataAutomaticallyOperate, measure, secure, improveNo
Geolocation (approximate)General location from IPAutomaticallySecurity, fraud prevention, localizationNo
Sensitive personal informationLogin credentials; health/wellness info you share for coachingYouAuthentication; delivering Coaching Services onlyNo
Inferences (limited)Preferences derived to personalize/improveDerivedService improvement and personalizationNo

4. Sensitive Personal Information

Sensitive personal information we may handle includes credentials for accounts you hold with us, authorization tokens for Connected Accounts, any health or wellness information you voluntarily share for Coaching Services, and sensitive content that may appear within a Connected Account you authorize us to process (Section 15). We do not collect or store passwords for Connected Accounts; access is by authorization token issued through the provider's OAuth flow, stored securely and revocable by you at any time. We use sensitive information only to authenticate your account, to deliver the coaching you request, and to provide the Connected Account features you have enabled. We do not use or disclose sensitive personal information to infer characteristics about you, and we do not use it for purposes beyond those permitted by law. You may request that we limit our use of sensitive personal information (Section 11). We handle this information with the safeguards described in Section 13.

5. Sub-processors and Service Providers

We engage vetted service providers and sub-processors under contracts requiring them to protect information and use it only to provide services to us. These include: cloud hosting and infrastructure; our technology and communications providers; payment processing (PowerPay Direct and its licensed processing partners for coaching and product payments; and bank/ACH for license and consulting fees); order fulfillment and shipping; and analytics. A named sub-processor list is available to clients under a data-processing agreement on request. The specific underlying processors and gateways are kept confidential.

6. Payment Processing

Coaching and Product payments are processed through PowerPay Direct and its licensed payment-processing partners and gateways. License and consulting fees are generally invoiced and paid by bank transfer/ACH. All payment providers operate under their own terms, privacy policies, and PCI-DSS obligations. Card details are entered directly into the processor's or gateway's secure systems; we receive only limited transaction information and do not receive or store complete card numbers.

7. How We Use Information

8. Automated Processing and Personalization

Our Services include personalization and AI-assisted features that use automated processing to tailor content and recommendations. We do not use automated decision-making that produces legal or similarly significant effects about you without human involvement. Coaching guidance is delivered by or under the direction of a human. You may contact us with questions about our automated processing.

9. How Long We Keep Information

We retain personal information for as long as needed to provide the Services and for legitimate business and legal purposes, then delete or de-identify it. Retention criteria include the duration of your engagement or account, tax/accounting/legal requirements, dispute resolution, and routine backup cycles. Coaching-related information is retained only as long as reasonably necessary to provide and document the coaching, unless you request earlier deletion.

10. Cookies, Tracking, and Opt-Out Signals

We and our providers use cookies, pixels, and similar technologies to operate, secure, measure, and improve the Services. You can control cookies through your browser and any controls we offer. We honor the Global Privacy Control (GPC) and similar opt-out preference signals where required. If we later introduce advertising cookies or pixels whose use results in a "sale" or "sharing" under applicable law, we will update this Policy and provide a clear opt-out.

11. Your U.S. State Privacy Rights

Residents of U.S. states with comprehensive privacy laws — including California, Virginia, Colorado, Connecticut, Utah, Texas, and others as they take effect — may have rights to: access/know; correct; delete; portability; opt out of sale, sharing/targeted advertising, and certain profiling (we do not sell or share); and limit the use of sensitive personal information. We will not discriminate against you for exercising these rights.

How to exercise. Submit a request to support@d3designs.net. We will verify your identity before responding within the timeframe required by law. You may use an authorized agent, subject to verification, and may appeal a declined request by replying to our decision. If your data was provided by a Licensee, please direct your request to that Licensee.

12. Data Location

We are based in and process personal information in the United States, and the Services are intended for U.S. users. If you access the Services from outside the United States, you understand your information will be processed in the United States.

13. Security

We use administrative, technical, and physical safeguards designed to protect information appropriate to its sensitivity, including encryption in transit, access controls, and least-privilege practices. Health-related and other sensitive information is held with additional safeguards, including encryption in transit and at rest, access limited to personnel who need it for the service you requested, separate storage from general business records, and contractual confidentiality obligations on any service provider that handles it. Whether particular information is regulated under HIPAA depends on the role in which it is received; where we act as a business associate of a covered entity, that work is governed by the applicable business associate agreement rather than by this Policy. If we become aware of a security breach affecting your personal information, we will notify you and any affected parties as required by law and without undue delay. No system is completely secure, and we cannot guarantee absolute security.

14. Children's Privacy

The Services are intended for users 18 or older. We do not knowingly collect personal information from children. If you believe a child provided us information, contact us and we will delete it.

15. Connected Accounts and Google API Services

Some Services work with accounts you already control — such as email, calendar, file storage, or CRM systems ("Connected Accounts"). You authorize each connection, and we access only the permission scopes you grant. You may revoke access at any time through the provider's security settings or by contacting us.

What we access. Depending on the Services you request: [list the actual scopes in plain language — for example: read message metadata and content in the mailbox you connect; read calendar events; read files you designate]. We do not access accounts or scopes you have not authorized.

What we do with it. We use Connected Account data only to provide and improve the specific features you asked for — for example organizing, summarizing, extracting tasks or themes, and producing reports and dashboards for you.

Google API Services — Limited Use. Divine Design's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, with respect to data obtained through Google APIs:

  • We use it only to provide or improve the user-facing features you have connected it for, and we do not use it for unrelated purposes.
  • We do not sell it, and we do not transfer it except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition after obtaining your explicit prior consent.
  • We do not use it for advertising of any kind, including serving, targeting, personalizing, or measuring advertising.
  • We do not use it to determine creditworthiness or for lending purposes, and we do not use it in any credit, lending, insurance, employment, or housing decision.
  • We do not allow humans to read it, except in these limited cases: with your affirmative consent for specific messages; where necessary for security purposes such as investigating abuse or resolving a security incident; to comply with applicable law; or where the data has been aggregated and anonymized so that it can no longer be associated with you, and then only for internal operations. Aggregation or de-identification does not release derived information from the other restrictions in this Section.
  • We do not use it to train generalized artificial intelligence or machine learning models, and we do not permit any provider to do so. We process this data only through provider arrangements we have verified prohibit training on it. Where no compliant arrangement is available for a given provider or feature, we do not send this data to that provider.

These commitments apply to information derived from Google API data as well as to the data itself.

16. AI Processing and Derived Insights

Where you have asked for AI-assisted features, content from your Connected Accounts and materials you provide may be processed by third-party model providers under contract with us to produce summaries, extracted tasks, themes, classifications, and reports ("derived insights").

17. Separation Between Services

Divine Design offers distinct services, and data does not move between them.

18. Retention and Deletion of Connected Account Data

Different categories of data have different lifecycles. The table states what we do on each trigger.

CategoryOn disconnect or requestOn engagement end
Authorization tokensRevoked and deleted immediatelyRevoked and deleted immediately
Raw content and attachments retrieved from a Connected AccountDeleted within [30] daysDeleted within [30] days
Derived insights — summaries, themes, extracted tasksDeleted within [30] days unless embedded in a deliverable you have asked us to keepSame
Deliverables you commissioned — reports, dashboards, exportsRetained per your written instruction; available for export for [30] days after termination, then deleted unless you instruct otherwiseSame
Operational logs — access and error records containing limited metadataRetained up to [90] days for security and troubleshooting, then deletedSame
BackupsExpire on their own cycle, within [35] days; not restored to active use after a deletion requestSame
Business records — contracts, invoices, tax recordsRetained under Section 9 and used for no other purposeSame

De-identification is not a release. Where we retain aggregated or anonymized information, the restrictions in Section 15 continue to apply to anything derived from Google API data.

To request deletion, contact us using Section 19. We will confirm in writing when deletion is complete. These timelines are consistent with the export and data-handling provisions of the Terms and Conditions; if the two ever conflict as to Connected Account data, this Policy controls.

19. Contact Us

Divine Design LLC
Attn: Privacy
Wyoming, USA
Email: support@d3designs.net

20. Changes to This Policy

We may update this Policy from time to time. We will revise the "Effective date" above and, for material changes, provide additional notice. Continued use after changes take effect constitutes acceptance.

21. Governing Law

This Policy is governed by the laws of the State of Wyoming, without regard to conflict-of-laws principles, except where a mandatory privacy law of your jurisdiction applies.