Privacy

Privacy policy

What Two Timezones collects, what it does not, what the advertising partners do on their own account, and how to get out of all of it.

Last updated

Read this before launch

This page is a working template, not legal advice. It honestly describes how the site is built to behave, but it must be reviewed by a lawyer in the operator’s jurisdiction before the site goes live. What you are legally required to disclose — and what you must obtain consent for before setting a single advertising cookie — depends on where your readers are: the GDPR and the UK GDPR for the EEA and Britain, the CCPA/CPRA for California, and a growing list of other US state laws. Passages marked [REVIEW] need a real decision and a real answer before this page is published.

What we collect

Short version: aggregate analytics, and your email address if you hand it to us. There is no account system, no comment section, no upload, and nothing to buy, so there is very little else to collect.

  • Analytics. Which pages are read, how readers arrived (search engine, social network, direct), approximate country, and broad device type. We use it to decide what to write next. No analytics tool is currently installed on this site. [REVIEW: name the provider here, and link its policy, once one is added.]
  • Newsletter subscriptions.Your email address, the date you subscribed, and which page’s form you used. Nothing else — no name, no country, no interest profile, no scoring.
  • Server logs. Our hosting provider records IP addresses and browser user agents for a short period as part of running and protecting the service. We do not mine them and we do not join them to anything else. [REVIEW: state your host and its log retention period.]
  • Your theme preference. Light or dark, stored in your own browser. It never reaches our servers.

What we never collect: accounts or passwords, payment details, comments or user-submitted text, uploads, precise location, or any of the special categories of data — health, sexuality, religion, politics. We do not build a reading profile attached to you, and we do not buy data about you from anyone.

Cookies and local storage

We set no advertising or tracking cookie of our own. Your theme choice is kept in your browser’s local storage, which is not a cookie and is never transmitted. Anything else on the page that stores an identifier belongs to a third party — the analytics provider, or an advertising network — and is described below.

Advertising partners

This site is paid for by advertising. Ad units are rendered inside sandboxed frames, which stops a network from reading our pages or your session — but inside its own frame a network can still set cookies and device identifiers, see your IP address and user agent, and use them to decide which ad to show. That processing is the network’s, under its own privacy policy, not ours.

No advertising partner is configured yet. When one is added it will be named here, and in our ads.txt, which is the public list of every company authorised to sell advertising on this site.

We never give an advertising partner your email address, and the newsletter list is never uploaded to an ad platform for matching or targeting.

Your choices and how to opt out

  • Browser controls. Every major browser can block or delete third-party cookies, and several block cross-site tracking by default. An ad blocker also works; nothing on this site is gated behind letting ads run.
  • Industry opt-out pages. Google’s ad settings at myadcenter.google.com; the US DAA at optout.aboutads.info; the NAI at optout.networkadvertising.org; and, in Europe, youronlinechoices.eu. These set opt-out signals per browser, so you have to repeat them on each device.
  • Global Privacy Control. If your browser sends a GPC signal, we treat it as a valid opt-out of any sale or sharing of personal information where the law recognises it.
  • Consent, where consent is required. Readers in the EEA and the UK must be asked before non-essential cookies are set, and personalised advertising cannot run until they agree. [REVIEW: a certified consent management platform must be installed and wired to the ad slots before launch if any meaningful share of the audience is in those regions. Describe it here — who provides it, what refusing means, and how to change your answer later.]
  • California and comparable US states.[REVIEW: decide whether serving personalised advertising counts as “sharing” under the CPRA for this site. If it does, a “Do Not Sell or Share My Personal Information” link is required in the footer, and it must work.]

The newsletter list

We use your address for one thing: sending the letter described on the newsletter page. We do not sell it, rent it, share it with advertisers, or pass it to another publication.

  • How long we keep it. Until you unsubscribe. If the letter is discontinued, the list is deleted rather than kept for later.
  • Unsubscribing. Every email has a one-click unsubscribe link at the foot. It removes you immediately; you do not have to tell us why.
  • Deletion. Unsubscribing suppresses your address; if you want the record erased entirely, email hello@twotimezones.comwith “Data request” in the subject and we delete it within 30 days. We may ask you to send that request from the subscribed address, because we have no other way to know it is yours.
  • Delivery. [REVIEW: name the email service provider that stores the list and sends the mail, and link its privacy policy. It is a processor and must be disclosed.]

Your rights

Depending on where you live you may have the right to see what we hold about you, correct it, delete it, object to or restrict how it is used, receive a copy in a portable format, and — in the EEA and UK — complain to your national data protection authority. In California and several other US states you may have the right to know, delete, correct, and opt out of sale or sharing, without being treated differently for doing so.

In practice, what we hold about a reader is almost always one row: an email address and a date. To exercise any of these rights, email hello@twotimezones.com. We answer within 30 days, and usually the same week.

[REVIEW: identify the data controller — legal entity name, registered address, and an EU or UK representative if one is required — and state the lawful basis you are relying on for analytics and for advertising.]

Children

This site is written for adults and is not directed at children. Please do not subscribe to the newsletter if you are under 16. If we learn that we hold an address belonging to a child, we delete it. [REVIEW: the digital consent age is 13 to 16 depending on the country; confirm the threshold that applies to your audience.]

Storage, transfers and security

The site is served over HTTPS. The newsletter list is held in the site’s own database and access is limited to the people who run it. No system is perfectly secure, and we will not pretend otherwise — but the worst case here is the loss of a list of email addresses, which is exactly why we do not collect anything else.

[REVIEW: state where the site and database are hosted, which countries data is processed in, and the transfer mechanism — standard contractual clauses or an adequacy decision — if readers in the EEA or UK are involved.]

Changes and contact

When this policy changes, the date at the top of the page changes with it. If a change is material — a new category of data, a new partner with access to it — we will say so in the newsletter rather than hope you re-read the page.

Questions, requests and complaints: hello@twotimezones.com. Our terms of use cover the rest of the relationship, and the editorial policycovers how the content itself is made. [REVIEW: add the operating entity’s legal name and a postal address — several jurisdictions require both on this page.]