Privacy Policy
What we collect, what we do with it, how to get it deleted. The short version: we collect what's needed, we don't sell it.
We respect that your inbox, your data, and your attention are limited. This page explains what Data Phoenix collects, what we do with it, how long we keep it, and how to get it deleted.
What we collect
Three categories of data:
- Account data — when you create an account: email, name, password hash, optional profile fields (location, bio, social handles). Updated whenever you edit your profile.
- Activity data — what you read, which episodes you watched, which events you RSVPed to, which comments you posted. Used to power your dashboard and personalised recommendations.
- Operational data — IP address, browser, timestamps of sign-in attempts. Used for security, fraud prevention, and to debug delivery problems with your account.
What we don't collect
- We don't fingerprint or track across the web. There's no Facebook pixel, no LinkedIn Insight tag, no third-party retargeting cookies.
- We don't read or analyse the contents of your email replies to our newsletters — they go to a human inbox.
- We don't sell, rent, or trade your personal data to anyone.
How we use it
- To run the platform — sign you in, show your saved items, render your dashboard, deliver newsletters you subscribed to.
- To improve it — aggregate usage patterns ("which sections do members open"), never per-person product decisions.
- To stay legal — billing records, tax records, sanctions-screening checks for paid customers.
Cookies and storage
We use a small number of first-party cookies:
dp_session— encrypted session cookie. Expires after 30 days of inactivity.dp_consent— your cookie banner choice. Lasts one year.dp_theme— light-mode preference. Lasts indefinitely; cleared by browser reset.
We use Plausible Analytics — cookie-less, no cross-site tracking, retention 30 days. No third-party ad cookies.
Who can see your data
- You — through /account and the data export tool on /account/security.
- Our staff — only when needed for support or to investigate abuse. Access is logged.
- Service providers — Stripe (billing), AWS SES (transactional email), Listmonk (newsletter), Plausible (analytics). Each has a data-processing agreement with us.
We don't share with advertisers, brokers, or affiliates. We disclose data to authorities only when legally compelled and notify you when we can.
How long we keep it
- Account data — for as long as your account is active. Deleted within 30 days of account deletion.
- Activity data — anonymised after 24 months unless you've explicitly saved it.
- Billing records — kept for 7 years for tax reasons, even after account deletion.
- Newsletter unsubscribes — kept indefinitely so we don't accidentally re-add you.
Your rights
Under GDPR, CCPA, and similar regimes, you can:
- Access — see the data we hold. Use the export tool on /account/security.
- Correct — update profile fields any time.
- Delete — delete your account from /account/security. Billing records retained per tax law (see above).
- Object & restrict — email privacy@dataphoenix.info and we'll process the request within 30 days.
International transfers
Data is processed on servers in the EU (eu-central-1) and in the US (us-west-2). Transfers between regions use Standard Contractual Clauses with each sub-processor.
Security
We encrypt at rest (AES-256) and in transit (TLS 1.3). Passwords are hashed with Argon2id. Two-factor authentication is available on /account/security — strongly recommended for paid accounts.
Changes to this policy
We update this policy when our practices change. Material changes get a notice on the site + email to account holders 30 days before they take effect. Latest version is always at dataphoenix.info/privacy.
Questions on this policy — privacy@dataphoenix.info. Our DPO reads and responds within 30 days.