Draft, not yet reviewed. This privacy policy is a working draft for the site owner's review and has not had a legal review. It is not in effect yet. Items marked [PLACEHOLDER] still need the owner's details.
Privacy policy
Effective date: [PLACEHOLDER: effective date, set on publication] · Last updated: [PLACEHOLDER: date]
Who we are
This policy covers the IAM Platform website and its News Desk (the "site"). The site is operated by ndomitabl holdings LLC, P.O. Box 55, Batesville, Indiana 47006 ("IAM", "we", "us"). For privacy questions, write to [email protected] or to our postal address.
The short version
- We count visits without cookies. We shorten your IP address before using it and never store it, we honor Do Not Track and Global Privacy Control, and you can opt out of counting.
- Our contact form and email sign-up are coming soon. They aren't open, and we collect nothing through them.
- When you click an affiliate link, we log the click (which offer, which page) without storing your IP address or setting a cookie.
- Google Analytics and Google AdSense are not active. If we add them, they will load only after you consent, and never while your browser sends Global Privacy Control or Do Not Track.
- YouTube videos load only when you click them.
- We don't sell your personal information.
1. Visitor counting (cookieless)
When the site's own visitor counter is switched on, a small script on each page sends our server one message (a "beacon") with:
- the page path, with any query string removed
- the domain of the site that referred you (for example
google.com). The script reduces the referring address to its domain in your browser, so the full address is never sent. - a screen-size bucket (mobile, tablet, laptop, or desktop). The script works out the bucket in your browser, so your exact screen size is never sent.
That is all the script sends. It doesn't send campaign tags or any other part of the link.
How we tell daily visitors apart. Our server takes three things: your IP address shortened first (for IPv4 addresses the last of the four numbers is dropped, so it identifies a network of up to 256 addresses; for IPv6 only the first three of eight groups are kept), your browser's user-agent string (which names your browser and operating system), and a random value (a "salt"). It runs them through a one-way function (SHA-256) and keeps the first 32 characters of the result. We call that code the "visitor hash". The same browser on the same network gets the same code for one day, which lets us count daily unique visitors and see that day's pages. Different people on the same network with the same browser can get the same code. We store the code, never the IP address (full or shortened) or the user-agent.
The salt is created fresh each day and is held only in the server's memory. It is never written to our database, to disk, or to backups. It is discarded within about 5 minutes after midnight U.S. Eastern Time, or whenever the server restarts. While that day's salt still exists, the hash is pseudonymous: someone with access to the running server could in principle recompute it from a network address and browser. Once the salt is discarded, the hash can no longer be recomputed, and visits on different days can't be linked. We store the time of each visit rounded down to the hour. We set no cookies. The only thing the site stores in your browser is your "opt out of counting" choice, if you make one (see below). We use this data only to count pageviews and daily unique visitors and to see which pages and topics people read. We treat counter and click records as personal data until they are combined into daily totals.
Abuse protection. To stop floods of fake requests, the server counts requests per IP address for one minute. These counts are kept only in memory, under a keyed code rather than the address itself, and are thrown away every minute (every 15 minutes for failed dashboard logins). Nothing from this is stored.
If your browser has Do Not Track or Global Privacy Control turned on, the script stops in your browser and sends nothing at all. If our server receives a counter request that carries one of these signals anyway (DNT: 1 or Sec-GPC: 1), it doesn't record the visit. It only adds one to a daily count of such requests. Because the script stops first, that count covers only requests our server actually receives. Traffic we identify as automated (search crawlers, link previews, bots) is not recorded either. We keep only a daily count of it.
Opt out of counting. You can tell this browser not to be counted, without changing any browser settings. Your choice is saved as a single value in this browser's local storage (iam-count-optout). Only our counter script reads it, it is never sent to us, and you can undo it here at any time. Clearing your browser's site data also removes it. The opt-out covers the visitor counter. Affiliate clicks are still counted (as described in section 2) so we can match commissions; turn on Global Privacy Control or Do Not Track if you want those counted without a visitor hash.
2. Affiliate links and click logging
Some pages contain affiliate links, which are always labeled (see our advertising & affiliate policy). These links go through a /go/ address on our site or on our tracking subdomain [PLACEHOLDER: tracking subdomain, e.g. t.example.com, if used], which forwards you to the merchant. When our tracking server handles the click, we log the time (rounded down to the hour), the offer, the page you clicked from, its topic, which box the link was in, and the referring domain, plus the same daily-salted hash described above. We store no IP address and set no cookie. If you have Do Not Track or Global Privacy Control turned on, we still forward you and count the click, but without any hash. If the tracking server isn't in use, a static /go/ page on our site forwards you and logs nothing. Either way, the merchant can see that you came from our site (our domain), but not the address of the page you were reading.
Third parties, including affiliate networks, may provide content or advertising on our site, collect information directly from visitors, and place or recognize cookies on your browser.
Affiliate networks and merchants. Once you reach the merchant's site, the merchant and its affiliate network (for example [PLACEHOLDER: networks actually joined, e.g. Amazon Associates, Impact, CJ, Awin]) may set their own cookies or use similar technology to credit the sale to us. That processing happens under their privacy policies, not ours. They send us commission reports, which we import to see earnings per page and offer. Those reports may include order dates, amounts, and the product or campaign. [PLACEHOLDER: confirm what each network report contains; we do not want or import buyer names or contact details]
3. Email signup and membership (planned)
This feature is not live yet, and nothing is collected today. The join page shows "Coming soon" with a disabled form, and no part of the site accepts an email address. This section describes the planned design. When it launches, you will be able to join IAM free with your email address. Your membership depends on staying subscribed to our email list:
- We use your email address to run your membership and to send the newsletters and updates you signed up for. Every email will have an unsubscribe link.
- Unsubscribing closes your membership account. After you unsubscribe, we send one final notice confirming that your membership is closed, and then no further emails.
- Email will be sent through [PLACEHOLDER: email service provider], which processes your address on our behalf. Like most email services, it may record whether an email was opened or a link was clicked. [PLACEHOLDER: state whether open/click tracking is on, and how to avoid it]
- After closure, we keep your address on a suppression list so we don't email you again by mistake, and delete the rest of your account data within [PLACEHOLDER: period].
4. Contact form (coming soon)
The contact form is not open yet. It is shown as "Coming soon" with its fields and submit button disabled, and nothing typed into it is collected or sent. When it opens, we will use the name, email address, and message you enter only to reply and to keep a record of the conversation, and we won't add you to a mailing list because you contacted us. Before it opens, we will update this section to name the service that receives the messages [PLACEHOLDER: form handler / hosting provider that receives and stores messages].
5. Google Analytics 4 and Google AdSense (planned, consent-gated)
Neither is active today. Ad spaces currently show only IAM's own promotions, which use no tracking. The Google Analytics and AdSense loaders on the site each have to pass a consent check first. That check answers "no" by default, and we haven't connected a consent tool yet, so neither service can load. AdSense will stay off until we have integrated a consent tool that Google has certified and that uses the IAB Transparency and Consent Framework (TCF) version 2.3. If we turn these services on:
- Google Analytics 4 would act as an independent check on our own counter. It uses first-party cookies (
_gaand_ga_<ID>, which by default last up to two years) to tell visits apart. Google says GA4 does not log or store IP addresses. We set Google signals and ad personalization off for GA4. - Google AdSense would show ads from Google's network in the labeled ad spaces. Google and its partners use cookies (for example
__gadsand__gpi) and similar technology to serve, measure, and, if you allow it, personalize ads. See how Google uses information from sites that use its services. You can control personalized ads in Google's ad settings. - Neither service will load for any visitor, wherever you are, until you agree through a consent tool, and you will be able to change your choice at any time. [PLACEHOLDER: consent tool and link to reopen it]
- Even after you agree, neither service loads while your browser sends Global Privacy Control or Do Not Track, so with either signal on you get no Google Analytics and no Google ads at all, personalized or not. [PLACEHOLDER: add a "Do Not Sell or Share My Personal Information" link if personalized ads are enabled for California visitors]
Advertising cookies and other ad vendors (applies once ads are enabled)
This part applies only once we turn on Google AdSense or another ad network. No ad network runs on the site today.
Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website or other websites. Google's use of advertising cookies enables it and its partners to serve ads to you based on your visit to this site and/or other sites on the Internet. You may opt out of personalized advertising by visiting Google Ads Settings. Alternatively, you can opt out of some third-party vendors' use of cookies for personalized advertising at www.aboutads.info. Even non-personalized ads may use cookies, web beacons, or your IP address for frequency capping, aggregated measurement, and fraud prevention. Ad vendors and their partners may place and read cookies on your browser, or use web beacons or your IP address, to collect information as a result of serving ads here. See how Google uses information from sites that use its services.
Other ad vendors: none today. Any other ad network we use will be listed here, with a link to its site and its opt-out.
6. YouTube videos (click to load)
Some News Desk posts have a "Watch" section that links to free, official video of the event. Videos from YouTube are embedded with YouTube's privacy-enhanced mode (youtube-nocookie.com), and nothing from YouTube or Google loads until you click the video. Once you click, your browser connects to YouTube, which receives your IP address and may set cookies or use local storage under Google's privacy policy. Videos on other official sites (such as federalreserve.gov) open on those sites.
7. Other third parties
- Images. All images on the site are served from our own domain. Older archived blog posts that used to show images from other websites no longer load them: where the original was gone it has been replaced with a plain "Image no longer available" box, and any we can recover will be served from our own server, so no other site receives a request when you read them. Links in those posts to other websites only contact those sites if you click them.
- Hosting. The site and our server run on Cloudflare (Cloudflare Pages). When launched, server and proxy access logs will be kept for 14 days, and requests to our counter (
/api/hit) and to/go/links will be logged without IP addresses. [PLACEHOLDER: confirm the hosting provider's actual log settings] - Links to other sites. We link to news sources, official sites, and social networks. Their privacy practices are their own.
8. Do Not Track and tracking across sites
- How we respond to Do Not Track. We treat Do Not Track and Global Privacy Control the same way. Our visitor-counter script sends nothing, and our server doesn't record a counter visit that carries either signal. You can also opt out of counting without changing browser settings. Affiliate clicks are still forwarded and counted, but without a visitor hash. Google Analytics and Google AdSense, if we ever enable them, don't load at all while either signal is on.
- Tracking across sites. Our own counter and click log don't track you across other websites or across days. If we enable Google Analytics or ads, Google and its advertising partners may collect information about your online activities over time and across different websites (only if you consent and neither signal is on). After you click a YouTube video, YouTube may do the same. Merchants and affiliate networks may do so once you follow an affiliate link to their sites.
9. Free-article limit (planned, not built)
Not built yet. We may later limit non-members to three free articles. Nothing on the site counts the articles you read today. Before any such limit goes live, we will update this section to describe exactly what it uses and what it stores. [PLACEHOLDER: describe the mechanism and its retention once it is designed and reviewed]
10. How long we keep data
| Data | Kept for |
|---|---|
| Daily salt used to make visitor hashes | Never stored. Held only in the server's memory and discarded within about 5 minutes after midnight U.S. Eastern Time, or when the server restarts |
Pageview and /go/ click records (visitor hash from a shortened IP address, no IP address, time rounded down to the hour) | 90 days. Then they are combined into daily totals with no visitor hash and no time of day, and the individual records are deleted. On our current database (SQLite) deleted records are overwritten and the file is compacted. Deleted records can remain in backups until those backups roll off (see "Backups"), and on a PostgreSQL database until it is vacuumed and its logs and snapshots are rotated |
| Daily totals (pageviews, unique-visitor counts, pages, referring domains, screen-size buckets, clicks; no visitor hash), skipped-visit counts, and analytics comparison reports | 13 months, then deleted |
| Earnings reports from ad and affiliate networks (no personal data) | 7 years (tax records), then deleted |
| Contact form messages (when launched) | 24 months after the last message in the conversation, then deleted. None are collected today |
| Email membership (when launched) | While you are a member. Closed accounts are hard-deleted within 30 days of closure, keeping only a suppression entry (your email address or a code made from it, and the opt-in and opt-out dates) so we never email you again by mistake |
| Billing records for paid membership (when launched) | 7 years (tax records), held mainly by the payment processor. We will never store card numbers |
| Consent records from the consent tool (when launched) | 13 months after your last choice, then you are asked again |
| Google Analytics 4 user-level data (when launched) | 2 months (the shortest GA4 retention setting) |
| Server and proxy access logs (when launched) | 14 days, with no IP addresses for counter and /go/ requests |
| Database backups (when launched) | 30 days, rolling: each backup is overwritten after 30 days. The daily salt is never in a backup |
11. Your rights
Depending on where you live, you may have the right to ask for access to the personal information we hold about you, to correct it, to delete it, or to object to or restrict how we use it, and to receive a copy in a portable format. Contact us using the details above. We will respond within the time the law requires (for example, one month under the GDPR and 45 days under the CCPA), and we may need to verify your identity first. We won't treat you differently for using these rights.
About counter and click records: these hold no IP address, cookie, or account. Once the day's salt is discarded (within about 5 minutes after midnight U.S. Eastern Time), we can't tell which records relate to you. That is by design. During the day a record is made, while that day's salt is still in the server's memory, its hash is pseudonymous rather than anonymous.
- EU, UK, and Swiss visitors (GDPR / UK GDPR): we rely on our legitimate interests for cookieless visitor counting and affiliate click logging (understanding readership and earnings with minimal data). We rely on your consent for Google Analytics, personalized ads, and loading YouTube videos. We will rely on your request for membership emails and replies to the contact form once those features open. You can withdraw consent at any time, and you may complain to your local data protection authority. Some of our providers may process data outside your country. [PLACEHOLDER: transfer safeguards, e.g. standard contractual clauses or the EU-US Data Privacy Framework, per vendor]
- California residents (CCPA / CPRA): you have the right to know what personal information we collect and how we use it, and to delete it, correct it, and opt out of its "sale" or "sharing". We do not sell personal information. If personalized ads are turned on, that may count as "sharing" for cross-context behavioral advertising. You will be able to opt out with the link noted above or with Global Privacy Control. The categories we collect today are: identifiers (hashed visitor IDs, kept up to 90 days), internet activity (pages viewed, referring domain, affiliate clicks, with times rounded down to the hour), and general device information (screen-size bucket). We will collect email addresses and names only once the planned membership and contact form open.
- Residents of other U.S. states: residents of some U.S. states (including Indiana, Virginia, Colorado, Connecticut, Texas, and Oregon) have rights to confirm whether we process their personal data, to access, correct, and delete it, to obtain a copy, and to opt out of targeted advertising, sale, and profiling. These laws may not apply to a site our size, but we extend these rights to all U.S. visitors. To make a request, contact us using the details below. Appeals: if we decline your request, in whole or in part, you can appeal by replying to our response with "Appeal" in the subject line. We will answer your appeal in writing within [PLACEHOLDER: 45 or 60 days; confirm with counsel] and explain our decision. If we deny your appeal, you can contact your state attorney general (for Indiana residents, the Indiana Attorney General's office).
12. Children
The site is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete it.
13. Security
We keep the amount of data we collect small, shorten IP addresses and hash them rather than storing them, use HTTPS, and limit access to our dashboards to authorized people. No system is perfectly secure, but we work to protect what we hold.
14. Changes to this policy
We will update this page when our practices change, for example when a planned feature above goes live, and change the "last updated" date. For significant changes we will give notice on the site [PLACEHOLDER: and by email to members, once membership exists].
15. Contact
ndomitabl holdings LLC · P.O. Box 55, Batesville, Indiana 47006 · [email protected] · contact page. Our contact form is coming soon.
