Privacy Policy
Last updated:
Template notice: this policy is a starting point written for a small personal website. Replace every TODO with your real details and have it reviewed before you rely on it. It is not legal advice.
1. Who we are
This website (“Woffle”, “we”, “us”) is operated by TODO: your name or registered business name, TODO: postal address. We are the data controller for the personal data described below. You can reach us at TODO@example.com.
2. What data we collect
We keep data collection to the minimum needed to run the site.
| Data | When it is collected | Source |
|---|---|---|
| Name, email address, message text | When you submit the contact form | You |
| Consent flag and submission timestamp | When you submit the contact form | Automatic |
| IP address, browser user agent, requested URL, response status | On every request, in standard server logs | Automatic |
| Theme preference (light or dark) | When you use the theme toggle | Stored in your browser only |
We do not ask for payment details, government identifiers or any special-category data (health, biometrics, political or religious beliefs, and similar). Please do not include such information in a contact message.
3. Why we use it and our legal bases
- To reply to you. Contact form data is used only to answer your enquiry. Legal basis: your consent, and our legitimate interest in responding to messages sent to us.
- To keep the site working and secure. Server logs help us find errors, block abuse and apply rate limits. Legal basis: legitimate interest in the security and availability of the site.
- To remember your display preference. The theme value stays in your browser. Legal basis: strictly necessary for a feature you asked for.
We do not use your data for advertising, profiling or automated decision-making, and we never sell it.
4. Cookies and local storage
This site sets no advertising or analytics cookies. The
only client-side storage is a single localStorage entry
named woffle-theme that remembers whether you chose light
or dark mode. You can clear it at any time through your browser
settings, and the site keeps working without it.
TODO: if you later add analytics, embedded videos, maps or a font CDN, list them here and add a consent banner where required.
5. Who we share data with
We share personal data only with service providers that help us run the site:
- Hosting provider: TODO: e.g. Render, Railway, Netlify — stores the site files and server logs.
- Email provider: TODO: e.g. Fastmail, Gmail — receives and stores contact messages.
- Source code hosting: GitHub, which stores the site’s code (not your messages).
These providers act on our instructions. We may also disclose data if we are legally required to do so, or to protect our rights and the safety of others.
6. How long we keep data
- Contact messages: up to TODO: 12 months after our last exchange, then deleted.
- Server logs: up to TODO: 30 days, unless needed longer to investigate abuse.
- Theme preference: until you clear your browser storage.
7. How we protect data
The site is served over HTTPS. Access to messages and hosting accounts is limited to the site owner and protected by strong, unique passwords and two-factor authentication. Submissions are validated and rate limited to reduce spam and abuse. No system is perfectly secure, so please avoid sending confidential information through the form.
8. Your rights
Depending on where you live, you may have the right to request access to your data, correction of inaccurate data, deletion, restriction of or objection to processing, a portable copy, and withdrawal of consent at any time. Residents of California may also request details of the categories of personal information collected and disclosed, and may opt out of any “sale” or “sharing” of personal information — we do not sell or share personal information.
To exercise any right, email TODO@example.com. We will respond within 30 days. Exercising your rights is free and will never lead to worse treatment. If you are in the UK or EU and are unhappy with our response, you can complain to your national data protection authority.
9. International transfers
Our providers may process data outside your country, including in the TODO: United States. Where that happens we rely on appropriate safeguards such as standard contractual clauses or an adequacy decision.
10. Children’s privacy
This site is not directed at children under 13 (or under 16 where local law sets a higher age) and we do not knowingly collect their data. If you believe a child has sent us personal data, contact us and we will delete it.
11. Changes to this policy
We may update this policy as the site changes. The “last updated” date above always reflects the current version, and significant changes will be highlighted on the home page.
12. How to contact us
Questions about privacy? Email TODO@example.com or write to TODO: postal address.