Privacy policy
Last updated: [DATE]
Who we are
BuySignal is an independent product-review publication operated by [COMPANY LEGAL NAME], [BUSINESS ADDRESS], [COUNTRY/STATE].
For the purposes of the UK and EU General Data Protection Regulation, [COMPANY LEGAL NAME] is the data controller for the personal data described in this policy. Privacy questions and requests go to [CONTACT EMAIL].
The short version
We are a small publisher, not an advertising technology company. We do not run reader accounts, we do not sell data, and we do not build advertising profiles. What we do collect is mostly anonymous counting — how many people clicked which product button — plus the ordinary technical logs that every web server keeps.
What we collect
Affiliate click events. When you click an outbound product link that passes through our /go/ redirect, we record an event containing:
- which product or link was clicked;
- the date and time;
- the page the click happened on;
- a coarse device category (mobile, tablet or desktop) derived from the browser's user-agent string;
- the referring page, where your browser supplies one;
- campaign parameters (utm_source, utm_medium, utm_campaign and similar) when they are present in the URL.
These events are stored as counts, not as a personal history. We do not attach your name, email address or an advertising identifier to them, and we do not attempt to link separate clicks into a profile of one individual.
Server logs. Our hosting provider records standard technical logs for security, abuse prevention and debugging: IP address, requested URL, timestamp, HTTP status, user-agent string and referrer. IP addresses are personal data in the EU and UK, which is why they are covered here even though we never use them for marketing.
Messages you send us. If you email us — a correction, an enquiry, a legal notice — we hold that message and your address so we can reply and keep a record of what was raised.
Analytics, where enabled. The site may use a privacy-respecting analytics service to count page views and referrers in aggregate. Where such a service is in use it is configured without cross-site tracking and without advertising identifiers. Current provider: [ANALYTICS PROVIDER, or "none"].
Administrator accounts. Staff accounts (username, email, name, hashed password, sign-in timestamps, failed-attempt counters and an audit log of administrative actions) exist so that the site can be edited. This applies to our team, not to readers.
What we do not collect
- No reader accounts. You never need to register, and there is nothing to register for.
- No selling or renting of personal data. Ever, to anyone, for any purpose. We do not "share" personal information for cross-context behavioural advertising as defined under the CCPA/CPRA.
- No cross-site advertising profiles. We do not run third-party ad networks, retargeting pixels or data-broker tags.
- No payment details. We do not sell anything and never take a payment, so no card or bank data is collected here.
- No sensitive categories. We do not knowingly collect health, biometric, precise-location, financial-account or similar sensitive data.
Cookies and local storage
We use as little of both as the site can function on:
- Administrator session cookie. A strictly necessary, HTTP-only cookie set only when a member of staff signs in to the admin area. Readers never receive it.
- Local storage for dismissed announcements. If you close a site announcement bar, that dismissal is remembered in your browser's local storage so the banner does not reappear. It stays on your device, is not readable by us, and clearing your browser data removes it.
- Cookies set by others after you leave. When you click through to a merchant, the merchant or its affiliate network sets its own cookie on its own domain. That is what allows a sale to be credited to us. We cannot read those cookies, and the third party's policy applies from that moment on.
You can block or delete cookies and clear local storage in your browser settings. Doing so does not stop you reading anything on this site.
Third parties
- Affiliate networks and merchants. ClickBank, Digistore24, JVZoo, WarriorPlus, Impact, Amazon Associates and the individual merchants they host. Their processing begins when you follow an outbound link and is governed by their own privacy policies. See our affiliate disclosure for how those relationships work.
- Embedded video. Where a page embeds video, we use the provider's privacy-enhanced mode where one is offered, so that the provider does not set tracking cookies unless you actually press play.
- Hosting and infrastructure. Our hosting provider, [HOSTING PROVIDER], processes requests and keeps the server logs described above, acting as our processor under a data-processing agreement.
- Email. Messages you send us are handled by our email provider, [EMAIL PROVIDER].
We do not pass reader data to anyone else, and we do not permit our processors to use it for their own purposes.
Legal bases for processing (UK/EU)
- Legitimate interests (Article 6(1)(f)) for aggregate click counting, security logging and abuse prevention — we need to know which pages are useful and to keep the site standing up. We have balanced this against your interests and consider the impact low because the data is not used to identify or profile individuals.
- Consent (Article 6(1)(a)) for any non-essential cookie or analytics technology where the law of your country requires it. Where consent is required, it is asked for, and it can be withdrawn at any time.
- Contract and legitimate interests for administrator accounts, which exist to run the publication.
- Legal obligation (Article 6(1)(c)) where we must retain or disclose information to comply with law.
How long we keep things
- Affiliate click events: [24] months, then deleted or irreversibly aggregated into counts.
- Server logs: typically [30–90] days, per our hosting provider's retention settings.
- Email correspondence: up to [24] months, or longer where a legal matter requires it.
- Administrative audit logs: [24] months, for accountability and security review.
Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you and receive a copy;
- rectify data that is inaccurate or incomplete;
- erase data ("right to be forgotten") where there is no overriding reason to keep it;
- restrict or object to processing carried out on the basis of legitimate interests, including any profiling;
- data portability — receive your data in a structured, machine-readable format;
- withdraw consent at any time where processing relies on consent;
- non-discrimination for exercising your rights (CCPA/CPRA), and to know what categories of information have been collected, disclosed or sold — for us, none have been sold or shared for advertising.
To exercise any of these, email [CONTACT EMAIL] with "Privacy request" in the subject line and tell us what you want. We will respond within one month (UK/EU) or 45 days (California), and will tell you if we need an extension. There is no charge for a reasonable request.
Because we hold almost nothing that identifies an individual reader, we may be unable to locate records relating to you specifically. In that case we will say so, and explain why, rather than guess.
Complaints. If you are unhappy with how we have handled your data you may complain to your supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, your national data protection authority. We would appreciate the chance to put it right first.
International transfers
Our hosting, email and analytics providers may process data in countries outside your own, including the United States. Where personal data is transferred out of the UK or the European Economic Area, it is covered by an appropriate safeguard — the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or an adequacy decision. Details of the specific mechanism used by each provider are available on request from [CONTACT EMAIL].
Children's privacy
This site is intended for adults and is not directed at children. We do not knowingly collect personal data from anyone under [16]. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We will update this page when our practices change. The "last updated" date at the top always reflects the current version, and material changes will be summarised at the top of the page for a reasonable period. Continuing to use the site after a change means the revised policy applies to you.
Contact
Questions, requests or complaints about privacy: [CONTACT EMAIL], or by post to [COMPANY LEGAL NAME], [BUSINESS ADDRESS], [COUNTRY/STATE].
See also our terms of use and our affiliate disclosure.
This page is a template supplied with the site software. It is general information, not legal advice. Before you rely on it, complete every bracketed placeholder and have the finished text reviewed by a qualified lawyer or compliance professional in your jurisdiction.