Legal
Privacy Policy - The Core Skill
1. Introduction
Your privacy is important to us. We are committed to protecting your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Lithuanian law.
This Privacy Policy explains what personal data we collect in connection with thecoreskill.com, why we collect it, on what legal bases we process it, with whom we share it, how long we keep it, how cookies and advertising technologies work on our site, and what rights you have.
We collect and retain personal data primarily to complete purchases, prevent fraud, secure the Service, and meet legal bookkeeping duties. Separate consent-based processing applies to marketing emails and to advertising pixels and conversion APIs.
Use of the Service is also governed by our Terms of Service available at thecoreskill.com/terms-of-service.
2. Data Controller and Contact Details
2.1 Data Controller. The data controller responsible for processing your personal data in connection with thecoreskill.com is Klym Zhuravlov-Iuzefovych, an individual with individual activity certificate №1133162, Verbų skg. 8, Vilnius 11115, Lithuania (“we”, “us”, or “our”).
2.2 Data Protection Officer / privacy contact.
Klym Zhuravlov-Iuzefovych
Email: [email protected]
Postal address: Verbų skg. 8, Vilnius 11115, Lithuania
2.3 General support contact.
Email: [email protected]
3. Scope of the Service
This Privacy Policy applies to the website thecoreskill.com and to the one-time purchase and delivery of AI skill ZIP digital products offered there (the “Service”).
The Service does not provide user accounts, passwords, profiles, or a subscription SaaS platform. Identity exists at the level of your order, email address, and any support correspondence you initiate.
This Policy does not cover third-party AI tools or platforms with which you may later use purchased skill files. Those tools are outside our control and are governed by their own terms and privacy policies.
4. Categories of Personal Data We Collect
We may collect, store, and process the following categories of personal data:
4.1 Checkout, payment, and identity data
- Name
- Email address
- Phone number (collected at checkout when provided as part of checkout fields)
- Billing address
- Transaction metadata (order and invoice identifiers, amounts, currency, tax, timestamps, payment status)
- Payment method tokens and card fingerprints as provided by Stripe (we do not store raw full primary account numbers / full card numbers)
4.2 Support communications
- Email address and message contents (and any personal data you include) when you write to [email protected] or similar channels
4.3 Marketing data (consent only)
- Email address for newsletters or promotional emails sent via Mailgun, only with your consent or clear opt-in
4.4 Technical, security, and antifraud data
- IP address
- Device and browser data (such as user agent, browser type, operating system, language, and similar technical signals)
- Essential logs and security events
- Antifraud signals (including via Stripe and related transaction or device patterns)
4.5 Advertising Pixel and Conversion API data — only after cookie Accept
Only if you select Accept on our cookie banner, we may process advertising measurement and optimisation data, which may include:
- User agent and device/browser information
- Click identifiers
- Email address and phone number if available / provided (phone is used for ads matching / conversion API (CAPI) only if provided and only after Accept)
- Traffic source / referrer
- Conversion events and other ads-optimisation fields reasonably required to measure and optimise campaigns
Such data may be transmitted via Meta, Reddit, and Google site Pixels and their Conversion APIs (including server-side conversion APIs).
5. How We Collect Data
We obtain personal data from:
5.1 You directly — when you complete checkout, provide contact or billing details, opt in to marketing, or contact us for support.
5.2 Automated means — when you browse or use the Service, including essential cookies and logs needed for security, checkout integrity, and operation of the site; and, only if you select Accept, advertising pixels and related technologies.
5.3 Payment and billing partners — such as Stripe and Autumn, which process payment, tax, antifraud, and order-fulfilment related data in connection with your purchase.
5.4 Advertising partners — Meta, Reddit, and Google, only after Accept in a cookie consent, in connection with pixels and Conversion APIs as described in this Policy.
We do not operate user registration or account-creation flows.
6. Purposes of Processing
We process personal data for the following purposes:
| Purpose | Typical data | Notes |
|---|---|---|
| Perform checkout, payment, tax calculation, order confirmation, and delivery / download access | Identity, billing, transaction data, Stripe tokens | Core contract performance |
| Track downloads and order fulfilment (Autumn) | Order identity, email, download and technical signals | Aligned with purchase and tax records |
| Send transactional emails (Stripe and/or Mailgun) | Name, email, order information | Not marketing |
| Customer support and dispute handling | Support email content, order references | Contract-related and/or legitimate interests |
| Bookkeeping, accounting, tax, and legal compliance (Lithuania and EU) | Financial and identity records required by law | Legal obligation; typically ~10 years |
| Antifraud, abuse prevention, and security monitoring | IP, device data, fingerprints, logs, billing patterns | Legitimate interests; up to 10 years for antifraud signals |
| Personalising services and operational analytics related to checkout / Service operation (Autumn; non-ad where applicable) | Technical and order-related data | Distinct from consent-based advertising cookies |
| Marketing emails via Mailgun | Consent only; withdraw anytime | |
| Advertising measurement and optimisation (Meta / Reddit / Google Pixel) | Ads event and matching data as listed in Section 4.5 | Consent only (Accept) in a cookie consent |
| Advertising measurement and optimisation (Meta / Reddit / Google conversion API (CAPI)) | Ads event and matching data as listed in Section 4.5 | Consent only (Accept) in a cookie consent |
| Establishing, exercising, or defending legal claims | Relevant subset of the above | Legitimate interests / legal claims |
7. Lawful Bases for Processing
We process personal data under the following lawful bases (GDPR Article 6):
7.1 Contractual necessity (Article 6(1)(b)) — to take steps at your request prior to a purchase and to perform the purchase contract, including checkout, payment, delivery / download access, transactional communications, and core order administration.
7.2 Legal obligation (Article 6(1)(c)) — to comply with Lithuanian and EU tax, accounting, bookkeeping, and other statutory record-keeping duties.
7.3 Legitimate interests (Article 6(1)(f)) — to secure the Service; prevent and investigate fraud and abuse; maintain essential logs; improve the reliability of checkout and delivery operations where not overridden by your rights; handle support; and establish, exercise, or defend legal claims. We balance these interests against your privacy rights and expectations.
7.4 Consent (Article 6(1)(a)) — for marketing emails; and for non-essential cookies and Meta, Reddit, and Google Pixel and Conversion API transmissions when you select Accept. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
We do not rely on legitimate interests as the basis for non-essential advertising cookies, pixels, or Conversion API transmissions. Those activities require your Accept consent as described in Section 8.
8. Cookies and Similar Technologies; Accept / Reject; Pixel and CAPI
8.1 Essential cookies and similar technologies. We use essential cookies and similar technologies required to operate the Service securely. These may include technologies needed to remember your cookie choice, enable checkout integrity, support basic fraud prevention, and maintain security and load balancing. Essential cookies do not require consent under applicable ePrivacy rules, but we still inform you about them here.
8.2 Your choice — Accept or Reject. Our cookie banner presents two equal, prominent options only: Accept and Reject. We do not require you to navigate granular category toggles in order to refuse non-essential advertising technologies.
8.3 If you choose Reject.
- We set essential cookies only.
- We do not load Meta, Reddit, or Google advertising pixels.
- We do not send conversion events to those platforms’ Conversion APIs for advertising optimisation (including server-side CAPI).
- Reject means no Pixel and no CAPI conversion sends to Meta, Reddit, or Google.
8.4 If you choose Accept.
- We may load Meta, Reddit, and Google pixels; and
- We may transmit conversion and related optimisation data to those platforms through their pixels and Conversion APIs (including server-side CAPI).
- Data may include device and browser information (such as user agent), click identifiers, traffic source, and — where available — contact matching fields such as email or phone number you provided at checkout.
- Phone is used for ads matching / CAPI only if you provided a phone number and only after Accept.
8.5 Withdrawal of consent. You may withdraw cookie / advertising consent later (for example by clearing cookies, using any site controls we offer, or contacting [email protected]). After withdrawal, we will stop non-essential Pixel and CAPI transmissions going forward. Withdrawal does not affect processing that was lawful before withdrawal. Payment, security, and legal records remain governed by their own lawful bases and retention rules.
8.6 Controller-held ads data. Identifiable advertising / optimisation event data that we store is retained for a maximum of thirteen (13) months, and we delete or anonymise it sooner when you withdraw consent and the data are no longer needed. Partner-side retention is separate and not fully controlled by us.
9. Sharing with Third Parties and Partners
We share personal data with the following third parties and partners only as needed for the purposes described in this Policy. Advertising pixels and conversion APIs for Meta, Reddit, and Google are used only if you select Accept.
Some partners may process personal data as independent controllers (or, in limited advertising contexts, as joint controllers) under their own privacy policies — especially advertising platforms and payment antifraud networks. Where a partner acts under its own policy, that policy also applies to the processing it controls.
9.1 Autumn (Recase, Inc.)
- Address: 2261 Market Street #22390, San Francisco, CA 94114, USA
- Data: name, email, phone (if provided), billing and order data, device and technical data, download and order events as applicable
- Purpose: billing and checkout management, tracking downloads, personalising services, analytics, and marketing-related processing (marketing and ads-related processing remains subject to required consents where applicable)
9.2 Stripe
Stripe Payments Europe Ltd. — The One Building, 1 Grand Canal Street Lower, Dublin D02 H210, Ireland
Stripe, Inc. — 354 Oyster Point Blvd, South San Francisco, CA 94080, USA
- Data: name, email, phone (if provided), payment method tokens / fingerprints, billing address, country / state, transaction and technical / antifraud data
- Purpose: billing and checkout, payment processing, tax calculation, compliance, analytics, antifraud, transactional emails
We do not store raw full card numbers; card data on Stripe’s rails is handled by Stripe.
9.3 Mailgun
Mailgun Technologies, Inc. — 112 E Pecan St #1135, San Antonio, TX 78205, USA
Mailgun Technologies SAS — 43 Rue de Dunkerque, 75010 Paris, France
- Data: name, email, and order- or support-related content as needed for messaging
- Purpose: transactional emails; marketing emails only with consent
9.4 DigitalOcean LLC
- Address: 101 Avenue of the Americas, 10th Floor, New York, NY 10013, USA
- Data: data hosted on infrastructure supporting the Service, which may include personal data processed by the Service
- Purpose: hosting and infrastructure
9.5 Meta (Pixel + CAPI — only on Accept in a cookie consent)
Meta Platforms, Inc. — 1 Meta Way, Menlo Park, CA 94025, United States
Meta Platforms Ireland Limited — Merrion Road, Dublin 4, D04 X2K5, Ireland
- Data: advertising event and matching data as described in Section 4.5
- Purpose: advertising measurement, conversion tracking, and ads optimisation
- Condition: only if you select Accept in a cookie consent
9.6 Reddit (Pixel + CAPI — only on Accept in a cookie consent)
Reddit, Inc. — 303 2nd Street, South Tower, 5th Floor, San Francisco, CA 94107, United States
Reddit Netherlands B.V. — Looiersgracht 43, 1016 VR Amsterdam, Netherlands
- Data: advertising event and matching data as described in Section 4.5
- Purpose: advertising measurement, conversion tracking, and ads optimisation
- Condition: only if you select Accept in a cookie consent
9.7 Google (Pixel + CAPI — only on Accept in a cookie consent)
Google LLC — 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States
Google Ireland Limited — Gordon House, Barrow Street, Dublin 4, Ireland
- Data: advertising event and matching data as described in Section 4.5
- Purpose: advertising measurement, conversion tracking, and ads optimisation
- Condition: only if you select Accept in a cookie consent
9.8 Other disclosures
We may also disclose personal data:
- to competent authorities when legally required;
- to professional advisers (legal, accounting) under confidentiality obligations where necessary; and
- where required to establish, exercise, or defend legal claims.
10. International Transfers
Please read this section carefully.
Your personal data may be transferred to, processed in, or stored in countries outside the European Union and the European Economic Area, including the United States, in connection with payment processing, hosting, email delivery, billing tools, and advertising partners.
Those countries may not provide the same level of data protection as EU/EEA law.
Where we transfer personal data out of the EEA, we take steps required by GDPR Chapter V, which may include reliance on:
- an adequacy decision of the European Commission (such as, where applicable, the EU–U.S. Data Privacy Framework for certified organisations);
- the European Commission’s Standard Contractual Clauses; and/or
- other appropriate safeguards under Article 46 GDPR.
You may contact [email protected] for more information about relevant safeguards applicable to a particular transfer.
Please note: once advertising or payment partners receive data, additional processing may occur under their policies and in their locations, which we do not fully control.
11. Retention
We keep personal data only as long as necessary for the purposes described in this Policy, including legal requirements (storage limitation).
| Category | Retention |
|---|---|
| Payment, tax, and bookkeeping records | Typically ten (10) years under Lithuanian bookkeeping / accounting practice; longer if law requires |
| Autumn order / download records | Aligned with purchase and tax records — typically ten (10) years |
| Antifraud signals and related investigation data | Up to ten (10) years |
| Support emails / ticket content | Generally two (2) years from closure or last correspondence; extended if a dispute or legal claim arises |
| Technical / security logs | Generally two (2) years, unless longer needed for incident investigation |
| Marketing email list | Until consent is withdrawn, plus a brief suppression record as needed to honour opt-outs |
| Ads / CAPI event data held by us (the controller) | Maximum thirteen (13) months; delete or anonymise sooner on consent withdrawal when no longer needed |
| Partner-side ads and payment data | Per partner policies; not fully controlled by us |
We may retain data longer where required to establish, exercise, or defend legal claims, or where a longer statutory period applies.
Erasure and legal archives. The right to erasure is limited where GDPR Article 17(3) applies (for example legal obligation or legal claims). Payment and tax archives generally cannot be deleted early merely because marketing or advertising consent is withdrawn.
12. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure. These measures include access limitation, use of reputable service providers and partners, and security-minded hosting and payment providers.
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
13. Your Rights Under the GDPR
Under the GDPR, you have the following rights concerning your personal data (subject to conditions and exceptions in the GDPR):
- Right of access (Article 15) — to obtain confirmation whether we process your personal data and, where we do, access to that data and related information.
- Right to rectification (Article 16) — to have inaccurate personal data corrected and incomplete data completed.
- Right to erasure (Article 17) — to request deletion of personal data, subject to lawful exceptions (including legal obligations and legal claims).
- Right to restriction of processing (Article 18) — to request that we restrict processing in certain circumstances.
- Right to object (Article 21) — to object to processing based on legitimate interests, including profiling based on those grounds; and to object to direct marketing at any time.
- Right to data portability (Article 20) — where applicable, to receive personal data you provided to us in a structured, commonly used, machine-readable format, and to transmit those data to another controller.
- Right to withdraw consent (Article 7(3)) — where processing is based on consent, to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
- Right to lodge a complaint — with a supervisory authority. In particular, you may contact the State Data Protection Inspectorate of the Republic of Lithuania (Valstybinė duomenų apsaugos inspekcija, VDAI), or the supervisory authority of your habitual residence, place of work, or place of the alleged infringement.
How to exercise your rights. Contact our Data Protection Officer / privacy contact at [email protected], or write to Verbų skg. 8, Vilnius 11115, Lithuania.
We may need to verify your identity in a manner proportionate to the risk of disclosure. We will respond without undue delay and in any event within one (1) month of receipt of a valid request, which period may be extended by up to two further months where necessary due to complexity or number of requests, in which case we will inform you of the extension and the reasons for it.
14. Children and Eligibility
The Service is directed to persons who are at least eighteen (18) years of age, or the age of majority in their jurisdiction if higher, consistent with our Terms of Service.
We do not knowingly collect personal data from children who do not meet this requirement. If you believe we have collected such data, contact [email protected] so we can take appropriate steps.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time by publishing the updated version on this page.
16. Contact
For privacy and data-protection requests:
Data Protection Officer / privacy contact
Klym Zhuravlov-Iuzefovych
Email: [email protected]
Postal address: Verbų skg. 8, Vilnius 11115, Lithuania
For general support:
Email: [email protected]