Privacy Policy

Last updated:

Template notice: this policy is a starting point written for a small personal website. Replace every TODO with your real details and have it reviewed before you rely on it. It is not legal advice.

1. Who we are

This website (“Woffle”, “we”, “us”) is operated by TODO: your name or registered business name, TODO: postal address. We are the data controller for the personal data described below. You can reach us at TODO@example.com.

2. What data we collect

We keep data collection to the minimum needed to run the site.

DataWhen it is collectedSource
Name, email address, message text When you submit the contact form You
Consent flag and submission timestamp When you submit the contact form Automatic
IP address, browser user agent, requested URL, response status On every request, in standard server logs Automatic
Theme preference (light or dark) When you use the theme toggle Stored in your browser only

We do not ask for payment details, government identifiers or any special-category data (health, biometrics, political or religious beliefs, and similar). Please do not include such information in a contact message.

3. Why we use it and our legal bases

We do not use your data for advertising, profiling or automated decision-making, and we never sell it.

4. Cookies and local storage

This site sets no advertising or analytics cookies. The only client-side storage is a single localStorage entry named woffle-theme that remembers whether you chose light or dark mode. You can clear it at any time through your browser settings, and the site keeps working without it.

TODO: if you later add analytics, embedded videos, maps or a font CDN, list them here and add a consent banner where required.

5. Who we share data with

We share personal data only with service providers that help us run the site:

These providers act on our instructions. We may also disclose data if we are legally required to do so, or to protect our rights and the safety of others.

6. How long we keep data

7. How we protect data

The site is served over HTTPS. Access to messages and hosting accounts is limited to the site owner and protected by strong, unique passwords and two-factor authentication. Submissions are validated and rate limited to reduce spam and abuse. No system is perfectly secure, so please avoid sending confidential information through the form.

8. Your rights

Depending on where you live, you may have the right to request access to your data, correction of inaccurate data, deletion, restriction of or objection to processing, a portable copy, and withdrawal of consent at any time. Residents of California may also request details of the categories of personal information collected and disclosed, and may opt out of any “sale” or “sharing” of personal information — we do not sell or share personal information.

To exercise any right, email TODO@example.com. We will respond within 30 days. Exercising your rights is free and will never lead to worse treatment. If you are in the UK or EU and are unhappy with our response, you can complain to your national data protection authority.

9. International transfers

Our providers may process data outside your country, including in the TODO: United States. Where that happens we rely on appropriate safeguards such as standard contractual clauses or an adequacy decision.

10. Children’s privacy

This site is not directed at children under 13 (or under 16 where local law sets a higher age) and we do not knowingly collect their data. If you believe a child has sent us personal data, contact us and we will delete it.

11. Changes to this policy

We may update this policy as the site changes. The “last updated” date above always reflects the current version, and significant changes will be highlighted on the home page.

12. How to contact us

Questions about privacy? Email TODO@example.com or write to TODO: postal address.