Overview
Your privacy matters. This Privacy Policy explains what data we collect, why we collect it, and how we handle it. By using our website and services, you agree to this policy.
What we collect
- Basic usage data: pages viewed, referrer, approximate location, device & browser (for performance and abuse prevention).
- Form submissions: name, email, message, optional attachment.
- User-submitted photos: if you choose to submit.
Cookies & local storage
We use minimal cookies/local storage for session preferences (language, UI state), security/anti-abuse (e.g., CAPTCHA), and privacy-centric analytics.
Analytics
We use privacy-respecting analytics (no cross-site tracking). We look at aggregate insights only.
User submissions (photos & text)
- You must have rights to the content you submit.
- Submissions may be stored temporarily in a quarantine bucket for review.
- Once approved, content may be published and referenced (e.g., in covers-index.json).
- We may keep minimal logs (timestamps, content IDs) for moderation and security.
Legal bases (GDPR)
- Contract / legitimate interests: operate the site, respond to contact, prevent abuse.
- Consent: when you tick “I agree…” for submissions or marketing.
- Compliance: where law requires.
Your rights
Where applicable (GDPR/UK GDPR/PDPA/CCPA), you may request access, correction, deletion, objection/restriction, or portability (where technically feasible). Contact us to exercise rights.
Data retention
- Contact emails: kept as business records per legal requirements.
- Moderation logs: retained for security; rotated periodically.
- Quarantine uploads: deleted if rejected; approved content kept while published.
Security
We implement reasonable technical and organizational measures (encryption in transit, access control, rate limiting, CAPTCHA).
International transfers
Data may be processed in other countries with industry-standard protections and agreements.
Children
Our services are not directed to children under 13 (or age defined by local law). Do not submit data if underage.
Third parties
We use service providers (e.g., email delivery, object storage, CDN). They process data on our behalf under contracts.
Do Not Track / CCPA
We do not sell personal data. For California residents, you may request disclosures and deletion as permitted by law.
Changes
If we update this policy, we will revise the “Last updated” date and version. Significant changes may be communicated on the site.
Contact
If you have questions or requests, please contact us at support@example.com.