PreCanaCourse
  • Homepage
  • The Course
  • For Clergy
  • Reviews
  • Blog
  • Contact
  • Login
Login
EspañolEnglish
Enroll NowMy Course
EspañolEnglish
  • Homepage
  • The Course
  • For Clergy
  • Reviews
  • Blog
  • Contact
  • Login
Enroll NowMy Course
your basket

Cart

Your cart is empty.

Start shopping
Coupon code

Privacy Policy

Table of Contents

  1. Who we are
  2. Data we collect
  3. Legal basis
  4. How we use your data
  5. Sharing with third parties
  6. International data transfers
  7. Your rights
  8. Data retention
  9. Security
  10. Cookies
  11. Children
  12. US Residents — Additional Disclosures
  13. Policy updates
  14. Contact us

1. Who we are

This Privacy Policy describes how PRECANACOURSE Spółka z ograniczoną odpowiedzialnością (operating as PRECANACOURSE sp. z o.o.; "we", "our", "us") collects, uses, and protects your personal data when you use the Pre-Cana Course platform.

Our website: www.precanacourse.com

Registered address: ul. Oleśnicka 16/1, 50-320 Wrocław, Poland

Company identifiers: NIP 8982334303 · KRS 0001243785 · REGON 544857191

Contact: [email protected]

Data Controller: PRECANACOURSE sp. z o.o., ul. Oleśnicka 16/1, 50-320 Wrocław, Poland.

2. Data we collect

2.1 Account data

  • Email address (required for account creation)
  • First and last name (required)
  • Partner's first and last name (optional)
  • Wedding date (optional)
  • Parish name and officiant (optional)

2.2 Special category data (GDPR Art. 9)

By signing up for our pre-marriage course, you implicitly disclose information about your religious beliefs (Catholic faith).

Additionally, during course exercises you may voluntarily share:

  • Reflections on your relationship
  • Information about your sexual life and intimacy
  • Mental health and emotional state observations
  • Family and parenting plans
  • Financial planning details
  • Religious practices and beliefs

By accepting our Terms of Service at registration, you give your explicit and informed consent (GDPR Art. 9(2)(a)) to the processing of this special category data for the sole purpose of providing the course, generating AI feedback on your reflection answers, and tracking your progress. Acceptance is bundled into Terms acceptance to avoid form friction; the substance of the consent (what is processed, by whom, for what purpose) is fully described in this Privacy Policy and in Terms §8a.

You can withdraw this consent at any time by deleting your account via My Account → Data Privacy. Withdrawal stops further processing but does not invalidate processing performed before withdrawal.

2.3 Usage data

  • Course progress (which modules/sections completed)
  • Exercise answers and AI-generated feedback
  • Time spent on lessons (videos watched, audio played)
  • Browser type, IP address (hashed for audit purposes only)

2.4 Payment data

Payment processing is handled by Stripe. We do not store your full card number. We store only:

  • Order number
  • Order amount and currency
  • Billing address (for invoicing)
  • Stripe transaction ID (for refunds)

2.5 Referral data (if you arrived through a partner)

Some visitors reach us through a link shared by one of our program partners — a priest, a marriage-preparation coordinator, or a past student who recommends the course. If you arrived that way and accepted marketing cookies, we record which partner referred you:

  • the partner's referral code, stored in a cookie named precana_ref for 90 days;
  • if you then create an account or sign in, a permanent note on your account of which partner referred you;
  • on your order, the partner credited with it.

The partner never learns who you are. Their panel shows counts and totals only — never your name, e-mail address, order details, or anything you write inside the course. This is a deliberate design decision, not a setting, and we cannot switch it on for a partner who asks.

We use this record for one purpose only: to calculate and pay the commission owed to that partner, and to keep the accounting records that supports. It is not used to profile you and it is not shared with anyone else. See also §9 and our Cookie Policy.

2.6 Partner data (only if you take part in our affiliate program)

This subsection applies only if we have enabled our invitation-only affiliate program on your account. It does not apply to ordinary course participants.

For partners we additionally process:

  • Payout details — depending on the method chosen: bank account holder name, IBAN, SWIFT/BIC, bank name and country, and the holder's address; or a Revolut tag, phone number, or e-mail; or a PayPal e-mail address.
  • Country of tax residence, whether you act as a private individual or through a business, any business or tax identification number, and any tax-residence documents you provide (see Affiliate Program Terms §11).
  • Commission and payout records — amounts, currencies, dates, and payment references.
  • Aggregate performance figures — daily click and enrolment counts for your referral link. We store these as daily totals only, without IP addresses or browser fingerprints of the people who clicked.

Payout details are treated as financial data: they are encrypted at rest (§8), are never returned to your browser in full — the panel shows a masked form such as IBAN ****1234 — and are readable in unmasked form only by administrators who need them to execute a payment.

3. Legal basis for processing

We process your data under the following legal bases (GDPR Art. 6 and 9):

  • Performance of a contract (Art. 6(1)(b)) — to provide you with access to the course you purchased.
  • Explicit consent for special category data (Art. 9(2)(a)) — for processing of reflection answers that may reveal religious beliefs, relationship details, sexual life, or other special category data. This consent is given by accepting our Terms of Service at registration; Terms §8a describes the substance of the consent in plain language. You can withdraw consent at any time by deleting your account in My Account.
  • Consent (Art. 6(1)(a)) — for marketing emails. Opt-in, non-required.
  • Legal obligation (Art. 6(1)(c)) — for invoicing data, retained for tax purposes for 5 years following the end of the calendar year in which the tax obligation arose (Polish Tax Ordinance Art. 86 §1).
  • Legitimate interests (Art. 6(1)(f)) — for security and fraud prevention (IP hash, login attempt tracking).
  • Consent (Art. 6(1)(a)) — for the referral cookie described in §2.5. It is classified as a marketing cookie, so it is set only if you accept marketing cookies. Refusing costs you nothing: any partner discount still applies to your order.
  • Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) — for the partner data in §2.6. We need payout and tax-residence details to perform the affiliate agreement, and we are required to keep records of payments made under Polish accounting and tax law.

Clergy review-access requests are processed under Art. 9(2)(e) ("data manifestly made public by the data subject") — clergy disclose their role voluntarily to obtain verification, and their role is typically public via diocesan registers. Data is used solely for verification and deleted after the review decision plus a short audit window.

4. How we use your data

  • To provide the pre-marriage course content (videos, audio, scriptures, exercises)
  • To generate AI-powered feedback on your reflection answers (via OpenAI)
  • To track your progress and issue completion certificates
  • To send transactional emails (welcome, password reset, completion)
  • To send marketing emails (only with your explicit consent)
  • To improve our course content (anonymized analytics)
  • To comply with legal obligations (invoicing, tax)

5. Sharing with third parties

We share data with the following processors (each has a Data Processing Agreement with us):

  • OpenAI, Inc. (US), with the EEA contracting entity being OpenAI Ireland Ltd — for AI-generated feedback on your exercise answers. Your answers are sent to OpenAI's API. We do NOT send your name or email to OpenAI — only the answer text with a non-identifying user ID. OpenAI does NOT train models on API data per their DPA. Privacy policy: openai.com/policies/privacy-policy.
  • Stripe, Inc. (US), with the EEA contracting entity being Stripe Payments Europe, Ltd. (Ireland) — for card payment processing, including Apple Pay and Google Pay transactions routed through Stripe's Payment Request Button. Apple Pay and Google Pay do not create a separate data controller relationship with us; the underlying card credential is tokenized by Apple/Google and handled by Stripe. Privacy policy: stripe.com/privacy.
  • PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg) for EEA/UK customers and PayPal, Inc. (US) for US customers — for PayPal payment processing when you choose PayPal at checkout. We receive the transaction ID, order amount, and billing details necessary to fulfil the order; we do not receive your PayPal login credentials or bank account details. Privacy policy: paypal.com/legalhub/privacy-full.
  • Cloudflare, Inc. (US) — for CDN, DDoS protection, WAF, routing our analytics traffic (see the PostHog entry below; our Google Tag Manager, Google Analytics and Google Ads tags are likewise loaded from, and report through, our own domain, and Cloudflare forwards that traffic to Google), and Cloudflare Turnstile, a privacy-preserving CAPTCHA that protects our public forms and sign-in page from automated abuse. Privacy policy: cloudflare.com/privacypolicy.
  • Google LLC (US) — Google reCAPTCHA v3 (invisible) on the checkout page, to detect fraudulent or automated PayPal payments. Unlike our analytics and advertising use of Google services (below), reCAPTCHA loads as a payment-security measure and therefore runs independently of your cookie-consent choice. Its use is subject to Google's Privacy Policy and Terms of Service.
  • Google LLC (US) — Google Analytics 4, Google Tag Manager, and Google Ads. These services are only loaded after you grant cookie consent via our banner (see §9). Google Consent Mode v2 is used to ensure no measurement or advertising data is collected before you opt in. When you complete a purchase, we also use Google Ads Enhanced Conversions: the email address, phone number and name from your order are one-way hashed (SHA-256) on our server, so they never leave it in readable form, and are sent to Google together with your postal code and country. Google uses them only to match your purchase to the ad you clicked, so we can measure whether our ads work — not to build an advertising profile of you. This follows the same cookie-consent choice as the rest of our Google tags. Privacy policy: policies.google.com/privacy.
  • PostHog, Inc. (US) — product analytics and session replay, run on PostHog Cloud EU, so the data is stored in an EU data centre (AWS, Frankfurt, Germany) rather than in the United States. Like our Google analytics tags, PostHog loads only after you grant cookie consent via our banner (see §9), and it does not run inside the course area at all. On our public pages, cart and checkout it records: which pages you view, clicks and similar interactions, aggregated heatmaps of where visitors click and scroll, and a session recording — a replay of your visit reconstructed from mouse movement, scrolling, clicks and page changes, together with messages your browser writes to its developer console. Text you type into form fields is masked in those recordings, and card details are entered inside Stripe's own frame, which cannot be recorded at all. PostHog never receives your reflection answers, and we have configured it so that visits are counted without building a stored profile of each visitor. Declining analytics cookies prevents all of the above. Privacy policy: posthog.com/privacy.
  • Hostinger International, Ltd. (Lithuania, EU) — for hosting our website and database in an EU data center.
  • Brevo SAS (France, EU) — for sending transactional and marketing emails. Primary processing remains in the EU. Privacy policy: brevo.com/legal/privacypolicy.

We do NOT "sell" or "share" your personal information as those terms are defined by the California Consumer Privacy Act (CCPA/CPRA), including for cross-context behavioral advertising. We have not done so in the preceding 12 months and have no plans to do so. We do NOT share your reflection answers with anyone outside the processors listed above.

5a. International data transfers

Some of our processors are established in, or transfer personal data to, the United States. We rely on two complementary legal bases for these transfers:

  • The EU-U.S. Data Privacy Framework (DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF — adequacy decisions of the European Commission under Article 45 GDPR, applicable where the receiving processor is actively certified to the relevant DPF.
  • The European Commission's Standard Contractual Clauses 2021/914 ("SCCs") under Article 46(2)(c) GDPR, with supplementary measures, applicable where DPF certification does not cover the transfer or as an automatic fallback in our processors' Data Processing Agreements.
ProcessorRoleLocation / EU contracting entityTransfer mechanism
OpenAI, Inc.AI feedback on exercisesEEA users contract with OpenAI Ireland Ltd; intra-group onward transfer to OpenAI, Inc. (US)EU SCCs 2021/914 Module 3 + supplementary measures (no personal identifiers sent to API, no training on API data per DPA, AES-256-GCM encryption at rest)
Stripe, Inc.Card, Apple Pay & Google Pay processingEEA users contract with Stripe Payments Europe, Ltd. (Ireland); intra-group onward transfer to Stripe, Inc. (US)EU-U.S. DPF (Art. 45 GDPR); EU SCCs as automatic fallback under Stripe's Data Transfers Addendum
PayPalPayPal payment processingEEA/UK users contract with PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg); onward transfer to PayPal, Inc. (US) for group functionsEU SCCs 2021/914 under PayPal's Data Protection Addendum; PayPal (Europe) is the primary controller for EEA/UK payments
Cloudflare, Inc.CDN, WAF, DDoS protection, Turnstile CAPTCHA, analytics traffic routingDirect EEA → USEU-U.S. DPF (Art. 45 GDPR); EU SCCs as fallback in Cloudflare's DPA
Google LLCAnalytics & advertising (loaded only after cookie consent)Direct EEA → USEU-U.S. DPF (Art. 45 GDPR); EU SCCs as fallback in Google Ads Data Processing Terms
Google LLCreCAPTCHA v3 — checkout bot/fraud protection (loads independently of cookie consent)Direct EEA → USEU-U.S. DPF (Art. 45 GDPR); EU SCCs as fallback in Google's Data Processing Terms
PostHog, Inc.Product analytics, heatmaps and session replay (loaded only after cookie consent; not loaded in the course area)PostHog Cloud EU — data stored in Frankfurt, Germany (AWS eu-central-1). The processor entity is PostHog, Inc. (US), which may access the data from outside the EEA for support and operationsEU-U.S. DPF, UK Extension and Swiss-U.S. DPF (Art. 45 GDPR), which PostHog confirms it participates in; EU SCCs 2021/914 with the UK Addendum incorporated in the same DPA as fallback
Brevo SASTransactional & marketing emailFrance (EU)No EU → US transfer for primary processing; any onward sub-processor transfers covered by SCCs in Brevo's DPA
Hostinger International, Ltd.Hosting (database, files)Lithuania (EU data center)No EU → US transfer

US government access notice. US law (notably Section 702 of the Foreign Intelligence Surveillance Act and Executive Order 12333) may, in defined circumstances, permit US public authorities to request access to data processed by US-based providers. The EU-U.S. DPF was adopted by the European Commission on 10 July 2023 after the US established, via Executive Order 14086, additional safeguards including binding limits on signals intelligence and a two-layer independent redress mechanism — including the Data Protection Review Court (DPRC) — which EU/UK/Swiss residents can use without cost via their national data protection authority. Where transfers rely on EU SCCs, we apply supplementary measures (encryption in transit and at rest, access controls, data minimization).

You can request a copy of the SCCs or further information about our transfer safeguards by emailing [email protected].

6. Your rights (GDPR Chapter 3)

You have the following rights regarding your personal data:

  • Right of access (Art. 15) — download all your data as JSON. Available at My Account → Data Privacy → Download My Data.
  • Right to rectification (Art. 16) — correct inaccurate data via My Account → Profile.
  • Right to erasure (Art. 17) — delete your account and data. Available at My Account → Data Privacy → Delete My Account. 30-day grace period (you can cancel deletion within 30 days). Invoicing data is retained for the legal obligation period (5-7 years per local tax law) but anonymized.
  • Right to data portability (Art. 20) — machine-readable JSON export (same as Right of access).
  • Right to restrict processing (Art. 18) — contact [email protected].
  • Right to object (Art. 21) — withdraw consent for marketing emails at My Account → Profile → Unsubscribe.
  • Right to lodge a complaint — with your local supervisory authority (ICO in UK, UODO in Poland, CNIL in France, etc.).

United Kingdom users. If you reside in the United Kingdom, your personal data is processed in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Your rights under UK GDPR are equivalent to those described above for EU users. You have the right to lodge a complaint with the United Kingdom Information Commissioner's Office (ICO) at ico.org.uk/concerns.

7. Data retention

  • Course data (exercises, progress, AI feedback): retained while your account is active + 2 years after course completion. After 2 years, you receive an email asking whether to keep or delete the data.
  • Account data (profile, email): retained while account is active. Deleted within 30 days of account deletion request.
  • Invoicing data: retained for 5 years from the end of the calendar year in which the tax obligation arose, as required by Polish Tax Ordinance Art. 86 §1. Anonymized after account deletion.
  • Marketing data: retained until you unsubscribe.
  • Audit logs (IP hash, login attempts): retained 6 months for security purposes, then automatically deleted.
  • Referral record (§2.5): the precana_ref cookie expires after 90 days. The note of which partner referred you is deleted together with your account; the attribution stored on an order follows the retention of the order itself.
  • Partner payout details (§2.6): deleted when you delete your account or leave the affiliate program. Records of payments already made to you are retained for 5 years from the end of the calendar year in which they were made, as required by Polish accounting and tax law — we cannot delete these on request, but they are limited to what the law requires (amount, date, currency, recipient, reference).

8. Security

We use industry-standard security measures (GDPR Art. 32):

  • HTTPS (TLS 1.3) for all data in transit
  • AES-256-GCM encryption-at-rest for sensitive user data (reflection answers, partner names, religious data)
  • Bcrypt password hashing
  • Two-factor authentication (2FA) available for accounts
  • Rate limiting and brute-force protection
  • WAF (Web Application Firewall) via Cloudflare
  • Bot protection via Cloudflare Turnstile (public forms & sign-in) and Google reCAPTCHA v3 (checkout payment fraud-prevention)
  • Daily malware scans
  • Regular security audits

In the event of a data breach affecting your personal data, we will notify you within 72 hours per GDPR Art. 33-34, unless the data was encrypted (in which case notification may not be required).

9. Cookies

We use essential cookies for login session, shopping cart, security, and consent state. We may also use analytics and advertising cookies (Google Analytics 4, Google Tag Manager, Google Ads, and PostHog — the last of which also records a replay of your visit, see §5) — these are loaded only after you grant consent via our cookie banner. Google Consent Mode v2 is configured so that no measurement or advertising data is collected before you opt in; the PostHog tag is held inert until consent is given and sends nothing at all until then.

We also set a first-party referral cookie (precana_ref, 90 days) when you arrive through a partner's link, so that the partner who recommended the course can be credited. It is classified as a marketing cookie and is set only with your consent — see §2.5.

You can change or withdraw your consent at any time by clicking the cookie preferences link in the footer. For the full list of cookies, retention periods, and details on how to change your consent, see our Cookie Policy.

10. Children

Our Service is intended for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. For residents of California (CCPA/CPRA) and Delaware (DPDPA), we do not knowingly sell or share personal information of any user under 16. If we learn that we have inadvertently collected personal information from a minor, we will delete it without undue delay. If you believe a minor has provided us with personal data, please contact us at [email protected].

11. US Residents — Additional Disclosures

This section provides additional information for US residents. It applies in addition to the rest of this Privacy Policy. We provide it as a single integrated section (rather than a separate "US Privacy Notice") for clarity. We are not currently subject to the threshold requirements of the California Consumer Privacy Act (CCPA/CPRA) or other US state privacy statutes, but we offer the disclosures and rights below voluntarily.

11.1 We do not sell or share your personal information

We do not "sell" or "share" your personal information as those terms are defined by the CCPA/CPRA, including for cross-context behavioral advertising. We have not done so in the preceding 12 months and have no plans to do so. Because we do not sell or share, no "Do Not Sell or Share My Personal Information" link is required, and none is provided.

11.2 Categories of personal information collected

In the preceding 12 months we have collected the following categories of personal information from US residents. None of the categories below have been sold or shared.

CCPA categoryExamples relevant to our ServiceCollected?Source
A. IdentifiersName, email, account ID, hashed IPYesYou; security logs
B. Customer records (Cal. Civ. Code §1798.80(e))Billing address, order history, partner name (optional); for affiliate program participants only: payout account details, stored encrypted (§2.6)YesYou; Stripe
C. Protected classificationsReligious beliefs (implied by Catholic course enrollment)YesYou
D. Commercial informationPurchase records, refund historyYesYou; Stripe
E. Biometric information—No—
F. Internet / network activityLogin timestamps, course progress, exercise interactions, referring partner code if you arrived through a partner link (§2.5)YesYou; our servers
G. GeolocationCountry only (derived from IP for compliance / fraud detection)Yes (country-level)Our servers; Cloudflare
H. Sensory / audio-visual—No—
I. Professional / employmentRole-related information for clergy verification requests onlyYes (clergy only)You (clergy form)
J. Education information—No—
K. InferencesAI-generated feedback drawn from your reflection answersYesOpenAI (processor)

Purposes: providing the course, generating AI feedback, processing payments, issuing certificates, transactional and (with consent) marketing email, security, legal compliance. Retention: as described in §7. Disclosure recipients: only the processors listed in §5; never sold; never shared for cross-context behavioral advertising.

11.3 Your rights as a US resident

Although we are not currently subject to the threshold requirements of US state privacy laws, we voluntarily extend the following rights to all US residents:

  • Right to know what personal information we have collected, used, disclosed, and (if applicable) sold or shared.
  • Right to delete personal information we have collected from you, subject to lawful exceptions (e.g., tax retention).
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing — not applicable, as we do not sell or share.
  • Right to limit the use of sensitive personal information to purposes necessary to provide the Service.
  • Right to non-discrimination for exercising any of these rights.
  • Right to use an authorized agent (residents of CA, CT, CO, DE) — we will require verification.
  • Right to appeal a denial of a privacy request (residents of VA, CO, CT).

How to exercise these rights. All rights above are implemented through the same mechanisms used to satisfy our GDPR obligations — a machine-readable JSON export of your data, a self-service account deletion flow with a 30-day grace period, and email-based correction and appeal handling. See §6 for in-product links, or use the contact addresses in §11.5.

11.4 State-specific notes

California (CCPA/CPRA). We will respond to verifiable consumer requests within 45 days (extendable by an additional 45 days where reasonably necessary, with notice). Requests may be submitted by an authorized agent with appropriate written authorization. The California "Shine the Light" law (Cal. Civ. Code §1798.83) does not apply because we do not disclose personal information to third parties for their direct marketing.

Nevada (NRS 603A). Although we do not sell personal information, Nevada residents may direct us not to sell their covered information by emailing [email protected] with the subject line "Nevada Opt-Out".

Virginia-model states (VCDPA, CPA, CTDPA, UCPA, OCPA, MCDPA, ICDPA, TIPA, FDBR, DPDPA, NHDPA, NJDPA, MODPA, MNCDPA, RIDTPPA, KCDPA, MN). We honor the rights of access, deletion, correction, and (where applicable) opt-out and appeal as outlined in §11.3. Residents of these states may submit requests as described in §11.5.

Illinois Biometric Information Privacy Act (BIPA). We do not collect, capture, purchase, receive through trade, or otherwise obtain any biometric identifiers or biometric information as defined by 740 ILCS 14/.

New York SHIELD Act. We maintain a written information security program with reasonable administrative, technical, and physical safeguards (see §8) that meet or exceed the requirements of N.Y. Gen. Bus. Law §899-bb for personal information of New York residents.

11.5 Contact for US privacy requests

Email [email protected] using one of the following subject lines so we can route your request correctly:

  • "California Privacy Request" — for CCPA/CPRA rights.
  • "Nevada Opt-Out" — for NRS 603A opt-out direction.
  • "Privacy Appeal" — to appeal a denied privacy request.
  • For all other US state privacy rights, use a subject line that identifies your state.

We respond to verifiable US privacy requests within 45 days where state law requires it.

12. Policy updates

We may update this Privacy Policy from time to time. We will notify you via email of any material changes. If the changes require new consent, we will ask you to re-consent at next login. Continued use after notification constitutes acceptance.

13. Contact us

For any privacy-related questions, requests, or complaints:

Email: [email protected]

Postal: PRECANACOURSE sp. z o.o., ul. Oleśnicka 16/1, 50-320 Wrocław, Poland

Data Controller: PRECANACOURSE Spółka z ograniczoną odpowiedzialnością (NIP 8982334303, KRS 0001243785).

If we don't respond within 30 days, you can lodge a complaint with the Polish data protection authority (UODO, uodo.gov.pl) or with the supervisory authority of your country of residence.

PreCanaCourse

Faithful Catholic marriage preparation for engaged couples seeking an intentional beginning.

"What God has joined together, let no one separate." — Mt 19:6

Quick Links

  • Course Content
  • For Priests
  • Reviews
  • Blog
  • Contact

Resources

  • Articles
  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Refund Policy

Contact

[email protected]

© 2026 PreCanaCourse. All rights reserved. • Made with ♥ for Catholic couples.