Boilerplate

Privacy Policy

Last updated 13 Sep 2026

This is placeholder copy, not legal advice. It is a checklist of the sections a privacy policy usually needs, not a policy. Replace every section below with text that describes what this deployment actually does, and have somebody qualified review it before you rely on it. Requirements differ by jurisdiction (UK GDPR, EU GDPR, CCPA and others all differ) and by what data you collect.

What information we collect

List it plainly: names and email addresses from account registration and the contact form, and whatever your analytics, payment processor or hosting logs record.

Why we collect it

Give the purpose and, where your jurisdiction requires one, the lawful basis for each kind of data.

How long we keep it

State a retention period, or the rule that determines one. "As long as necessary" on its own is not an answer regulators accept.

Who we share it with

Name the categories of processor you actually use — hosting, email delivery, payment, analytics — and say whether any of them are outside your own country.

Cookies

Say which cookies the site sets and what they do. Session and authentication cookies usually need only a mention; analytics and advertising cookies generally need consent.

Your rights

Set out the rights people have over their data — access, correction, deletion, portability, objection — and exactly how to exercise them.

Changes to this policy

Explain how you will announce changes, and keep the "last updated" date accurate.

Contact us

Give the address for data protection enquiries, and the supervisory authority people can complain to if your jurisdiction has one.