Skip to content
New this month 24 fresh C++, C#, F#, JavaScript, TypeScript and Lua courses just landed. Browse new releases Use code WELCOME10 for 10% off your first order · 14-day refund

Legal

Privacy Policy

What we collect when you browse, buy or write to us, why we collect it, who else touches it, and how to get it back or have it deleted. We are established in Estonia, so the GDPR applies to everything on this page.

Last updated: 5 August 2026 Written in plain English misteryjj100@gmail.com

The short version

We collect the minimum needed to sell you a course and support you afterwards: your email, your name, your order, and the technical logs every web server keeps. Card numbers go straight to our payment provider and never reach us. We do not sell or rent your data to anyone, ever, and there are no advertising trackers on this site.

This summary is here to help you find your way around. The numbered sections below are the terms that actually apply.

1. Who we are

WisdomCharms is operated by WisdomCharms, registered at Sõpruse pst 145, Tallinn 13418, Estonia. For the purposes of the General Data Protection Regulation (EU) 2016/679 we are the data controller for the personal data described in this policy — that is, we decide what is collected and why.

Because we are established in Estonia, an EU member state, the GDPR applies to us directly, and our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). You will find its details, and how to complain to it, in section 15.

This policy covers this storefront and the transactional and marketing emails we send. It explains what happens to your information in plain language, because a privacy notice you cannot read is not a privacy notice.

Data protection questions go to misteryjj100@gmail.com. There is no separate portal and no ticket queue; the same team that handles orders handles these.

2. What data we collect

Account data

If you create an account: your name, email address, a securely hashed password (we never store the password itself), optionally your country, and your marketing preference. If you never create an account, we never hold any of this.

Order data

When you buy: your first and last name, email address, billing country, the courses in the order, the prices, any coupon code used, the totals, the order number, and the status and dates of the order, including any refund. This is our commercial record of the sale.

Payment metadata

From Stripe we receive and store: whether the payment succeeded, the card brand and the last four digits, the Stripe checkout session and payment intent identifiers, and a link to the Stripe receipt. We do not receive and cannot access your full card number, expiry date or security code.

Support messages

When you use the contact form or email us: your name, your email address, the topic you chose, the message you wrote and the date. Anything you volunteer inside the message — an order number, a screenshot, a description of your setup — is stored with it.

Newsletter data

If you subscribe: your email address, optionally a first name, the page the sign-up came from, and the dates you subscribed and (if you do) unsubscribed.

Technical and log data

Like every web server, ours records the IP address, browser user-agent, requested URL, referring page and timestamp of requests. Application error logs may include the same information plus the internal error trace. This is what lets us find a bug, block an attack and prove a delivery happened.

Cookies

A small number of strictly necessary cookies keep you signed in and keep your cart intact. Full details, including a table of every cookie, are in our Cookie Policy.

What we never collect

We do not ask for your date of birth, your address (beyond the billing country your card issuer supplies), your phone number, or any special-category data such as health, religion, ethnicity or political opinions. Please do not send those to us in a support message.

3. Why we use it, and our legal basis

Under the GDPR we must have a lawful basis for each use. Ours are set out below. If you are somewhere the GDPR does not apply, the table still describes accurately what we do and why — we run one policy for everybody rather than a weaker one for people whose regulator cannot reach us.

What we do Data used Legal basis
Take your order, take payment and email your access links Order data, payment metadata Performance of a contract with you
Keep your library so you can re-open a course years later Account data, order data Performance of a contract
Answer your support message and process refunds Support messages, order data Performance of a contract; legitimate interests (running a support desk)
Keep the site secure, prevent fraud, investigate abuse of the refund guarantee Technical and log data, order data Legitimate interests (protecting our business and our customers)
Understand which courses sell and improve the catalog Aggregated order data Legitimate interests (improving our products)
Send the newsletter Newsletter data Your consent, withdrawable at any time
Keep tax, accounting and payment records Order data, payment metadata Legal obligation

Where we rely on legitimate interests we have balanced those interests against your rights, and we are happy to explain the reasoning if you ask. You can object to any processing based on legitimate interests — see section 8.

We do not sell, rent or trade your personal data. We do not run advertising networks, we do not build advertising profiles, and we do not share your email address with any third party for their own marketing.

4. Card data: what we never see

All payments run through Stripe on a payment page hosted by Stripe. Your card number, expiry date and security code are entered on Stripe's systems and are transmitted directly to them.

They never pass through our servers, and we never store them — not encrypted, not hashed, not at all. This is deliberate: the safest way to handle a card number is to never hold one. Stripe is a PCI-DSS Level 1 certified service provider, the highest level defined by the payment card industry.

What we hold is the metadata listed in section 2 — enough to identify your order and issue a refund, and nothing that could be used to make a payment.

5. Who we share data with

We share personal data only with the service providers we need in order to run the store. Each acts as our processor under a written agreement, may only use the data to provide the service to us, and may not use it for their own purposes.

Provider What they do What they receive
Stripe Processes card payments and refunds; acts as an independent controller for fraud prevention Your name, email address, billing country, order amount and card details you enter on their page
Our transactional email provider Delivers receipts, access links, password resets and refund confirmations Your email address, your name and the contents of the email
Our hosting and infrastructure provider Runs the servers and database this store lives on, and stores backups Everything described in section 2, at rest and in transit
Our course library host Serves the course material behind your access link The access code, and the request logs generated when you open it

We may also disclose personal data:

  • to our accountants and auditors, for tax and statutory reporting;
  • to our legal advisers, where we need advice;
  • to a bank or card network, when we defend a chargeback;
  • where we are legally required to, by a court order or a valid request from a competent authority — we check that any such request is lawful and proportionate before responding;
  • to a buyer or successor, if the business is sold or merged — in which case your data continues to be protected on terms no less favourable than these, and we will tell you.

6. International transfers

We are established in Estonia and our data is held inside the European Economic Area wherever we can arrange it. Some of our providers — Stripe in particular — operate globally, so your data may be processed outside the EEA, including in the United States.

Where data leaves the EEA, we rely on one of the following safeguards under Chapter V of the GDPR:

  • an adequacy decision by the European Commission covering the destination country; or
  • the European Commission's Standard Contractual Clauses, incorporated into our contract with the provider, together with a transfer impact assessment; and
  • where appropriate, additional technical measures such as encryption in transit and at rest.

You can request a copy of the relevant safeguard by emailing misteryjj100@gmail.com.

7. How long we keep it

We keep personal data only as long as it is useful for the purpose it was collected for, or as long as the law requires — whichever is longer.

Data Retention period
Order, invoice and payment records 7 years from the end of the financial year in which the order was placed, as required of us by the Estonian Accounting Act (Raamatupidamise seadus). We cannot delete these earlier, even on request.
Account data For as long as your account is open, then deleted or anonymised within 30 days of your closing it — except where it is part of an order record above
Support messages 24 months from the last message in the thread
Newsletter subscription Until you unsubscribe, then a suppression record only (your email, so we do not mail you again) for 3 years
Server and application logs 90 days, then automatically deleted
Database backups 35 days on a rolling cycle; deletions propagate as old backups expire
Published reviews Until you ask us to remove them

8. Your rights

Depending on where you live you have some or all of the following rights. We honour all of them for every customer, wherever you are, because it is simpler and fairer than checking your passport.

  • Access. Get a copy of the personal data we hold about you, and an explanation of what we do with it.
  • Rectification. Have inaccurate data corrected — you can fix most of it yourself in your profile.
  • Erasure. Have your data deleted, where we do not have a legal obligation or an overriding legitimate ground to keep it. Order records we must keep for tax purposes are the usual exception, and we will tell you exactly what is being retained and why.
  • Portability. Receive the data you gave us in a structured, commonly used, machine-readable format (we send JSON), or have us send it to another controller where technically feasible.
  • Restriction. Ask us to pause processing while a dispute about accuracy or legitimate interests is resolved.
  • Objection. Object to processing we base on legitimate interests, and object at any time to direct marketing — that objection is absolute and we act on it immediately.
  • Withdraw consent. Where we rely on consent, withdraw it at any time. This does not affect processing that already happened lawfully.
  • Complain. Lodge a complaint with your data protection authority — see section 15.
  • No automated decisions. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.

9. How to exercise your rights

Email misteryjj100@gmail.com and say which right you want to use. Please write from the email address on your account or order — if you cannot, we may ask a couple of questions to confirm your identity, because handing your data to the wrong person would be a far worse outcome than a short delay.

  • We acknowledge every request within 2 business days.
  • We complete it within 30 days, and usually within a week. If a request is genuinely complex we may extend by up to two further months, and we will tell you why before the first month is up.
  • There is no charge. We only reserve the right to charge a reasonable fee for a manifestly unfounded or excessive request, and we have never had to.

For access and portability requests we send a JSON export containing your account record, your orders and order items, your support messages and your newsletter status.

10. Cookies and analytics

This site sets only strictly necessary cookies — the ones that keep you signed in, protect forms against cross-site request forgery, and remember what is in your cart. There is no advertising pixel, no cross-site tracker and no third-party analytics script on this store by default.

Every cookie is listed by name, purpose and lifetime in our Cookie Policy, along with instructions for controlling cookies in each major browser.

11. Marketing email

We send two very different kinds of email:

  • Transactional email — receipts, access links, password resets, refund confirmations and important service notices. These are part of the contract and you cannot unsubscribe from them while you have an active account or a recent order.
  • The newsletter — new releases, discount codes and one practical technique per issue. This is consent-based, roughly weekly, and every issue has a one-click unsubscribe link in the footer. We act on unsubscribes immediately.

We do not sell or share our list. We do not buy lists either — every address on ours was typed in by the person who owns it.

12. Children under 16

This store is intended for people aged 16 and over, and our courses are written for an adult and teenage-developer audience. We do not knowingly collect personal data from anyone under 16.

If you are a parent or guardian and believe a child under 16 has given us personal data, email misteryjj100@gmail.com. We will delete the account and the associated data promptly, and refund any purchase made from it, regardless of the 14-day window.

13. How we protect your data

  • The entire site is served over HTTPS; we do not accept unencrypted connections.
  • Passwords are stored as bcrypt hashes, individually salted. Nobody at WisdomCharms can read your password, and a password reset is the only way back in.
  • No card data exists in our systems to steal — see section 4.
  • Administrative access is limited to the small number of people who need it, and every admin action against an order is attributable.
  • Databases and backups are encrypted at rest, and backups are access-controlled separately from the live system.
  • Dependencies are patched on a regular schedule, and security releases are applied out of band.

No system is perfectly secure, and anyone who tells you otherwise is selling something. If a breach does occur that is likely to result in a risk to your rights and freedoms, we will notify the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) within 72 hours, as Article 33 of the GDPR requires, and tell affected customers directly and promptly, in plain language, including what happened and what you should do.

Found a vulnerability? Please tell us at misteryjj100@gmail.com. We will not take action against researchers who report in good faith and give us reasonable time to fix the issue.

14. Changes to this policy

We update this policy when what we do with data changes — a new processor, a new product type, a change in the law. The “Last updated” date at the top always reflects the current version.

For material changes we email account holders and newsletter subscribers before the change takes effect, and we post a notice on the site. Where a change requires your consent, we ask for it rather than assuming it.

15. Contact and complaints

Privacy questions, data requests and complaints all go to misteryjj100@gmail.com, or by post to WisdomCharms, Sõpruse pst 145, Tallinn 13418, Estonia.

If you are not satisfied with how we have handled your request, you have the right to complain to a data protection supervisory authority. Ours — because we are established in Estonia — is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon):

https://www.aki.ee/en

If you live in another EU or EEA country you may complain instead to the supervisory authority where you live or where you work, and it will co-operate with ours. We would appreciate the chance to put things right first — but it is your right, it costs nothing, and you do not need our permission to use it.

Data controller

WisdomCharms Sõpruse pst 145, Tallinn 13418, Estonia misteryjj100@gmail.com

Prices are shown in USD. Any applicable tax is calculated at checkout.

Questions about this policy?

A real person at WisdomCharms reads every message and replies within one business day. If anything on this page is unclear, or you think it treats you unfairly, tell us — we would rather fix the wording than argue about it.