[ Privacy ]

Privacy Policy

This is a draft for review. It is not legal advice, and it is not published. Prepared by the Privacy and DPO desk (Ingrid Halvorsen) for the CLO desk (Eleanor Whitfield), for JP's review with qualified counsel. Nothing here has been reviewed by a lawyer. It exists to save counsel time by describing what NLNT actually does with personal data, verified against the running systems, rather than starting from a template. Do not publish it, link it, or create a route for it until counsel has cleared it and the open items below are decided. Draft date: 6 August 2026 Status: unpublished draft, no version number assigned Placeholders: anything in [BRACKETS] is unresolved and is listed in README.md

---

1. Who we are

Nerds Like Nice Things ("NLNT", "we", "us") publishes the website at https://www.nerdslikenicethings.com and the email newsletter *The Tuesday Upgrade*.

We are the controller of the personal data described in this policy. That means we decide what is collected and why.

  • Legal entity: [LEGAL ENTITY NAME]
  • Registered address: [REGISTERED ADDRESS]
  • Contact for privacy questions: [email protected]

Josh Perry is the person accountable for privacy at NLNT and the person who reads and answers privacy correspondence. NLNT is a one-person publication. There is no privacy team, no ticket portal for readers, and no telephone line.

2. What this policy covers

This policy covers the public website and the newsletter.

It does not cover the staff administration area at /admin, which is not open to readers and is described here only where it matters for context.

3. What we collect, and from whom

We collect very little. As of the date of this draft, there are three categories.

3.1 Your email address, if you subscribe to the newsletter

The signup form on the website asks for one thing: an email address. When you submit it, your address is sent to beehiiv, the service that stores our subscriber list and sends the newsletter. Nothing else from the form is transmitted, and your address is not written to any NLNT database.

Along with your address, our website tells beehiiv that the signup came from our site (as a source label). beehiiv then records its own information about your subscription, such as the date you subscribed, whether the subscription is active, and, once we send you an email, whether it was delivered, opened, or clicked. That information is generated and held by beehiiv, not by us, and we can see it through beehiiv's interface.

beehiiv's subscriber records can also hold a first and last name. Our signup form does not ask for a name and does not send one.

3.2 Anything you send us by email

If you email us, we receive your address, your message, and whatever else you choose to put in it. Our mail is carried by Google Workspace. If your message leads to work we need to track (a correction request, a rights question, a request about your own data), a record of it may be logged in our internal ticket system.

3.3 Technical records created by delivering the site

Serving a web page necessarily involves your device's IP address and the request it makes. Our hosting and network providers (Vercel and Cloudflare) process that traffic and keep their own operational logs, in the ordinary way that any website's infrastructure does. We do not build a profile from those logs, and we do not combine them with anything else.

3.4 What we do not collect

Verified on 6 August 2026 against the live site:

- We run no analytics product. There is no Google Analytics, no tag manager, no Plausible, no PostHog, no third-party measurement of any kind on the reader-facing site. - We run no advertising and no tracking pixels. There is no ad network, no retargeting tag, no social pixel. - The reader-facing pages load nothing from a third party. Fonts, images, styles, and scripts are all served from our own domain. Your browser is not asked to contact any other company in order to read an article. Article images are stored on our own infrastructure and passed through our domain before they reach you. - We have no reader accounts, no logins, no comments, and no forms other than the newsletter signup. - We do not buy personal data, and we do not receive it from data brokers.

The only outbound contact with other companies happens when you deliberately click a link in an article to an outside source. See section 9.

4. Cookies

We set no cookies on the reader-facing site.

This was checked, not assumed. On 6 August 2026 we requested the home page, the About page, the Glossary, and an article page from the live site and inspected the response headers. None of them set a cookie. We also searched the site's source code: the only cookie handling in the codebase belongs to the staff administration area.

The staff administration area at /admin sets a session cookie when a member of staff logs in. That is a login cookie for the people who run the publication. It is never set on a reader's browser by reading the site.

Because we set no cookies and run no tracking, we do not show a cookie consent banner. [OPEN: counsel to confirm no consent mechanism is required given the above, and to say what must change if any analytics or embedded media is added later.]

5. Why we use your data, and on what legal basis

We use your email address for one purpose: to send you the newsletter you asked for, and to handle your subscription (including honouring an unsubscribe).

For readers in the EU or UK, where the GDPR applies, our lawful basis is your consent under Article 6(1)(a). You give it by entering your address in the signup form and submitting it. You can withdraw it at any time using the unsubscribe link at the bottom of every newsletter, or by emailing us. Withdrawing consent does not affect emails we already sent.

We use email correspondence for the purpose you sent it for. Where we keep a record of it in order to run the publication properly (for example, to track a correction), our basis is our legitimate interest in operating an accountable publication, under Article 6(1)(f).

Technical delivery logs held by our hosting providers rest on our legitimate interest in keeping the site running and secure, under Article 6(1)(f).

We do not sell personal data. We do not share it for advertising. We have no advertising business.

6. Who processes your data on our behalf

These are the companies that handle personal data for us. Each acts on our instructions.

ProviderWhat it does for usWhat personal data it touches
beehiivStores the newsletter subscriber list and sends the newsletter. It is our system of record for the audience.Your email address, subscription status and dates, and email engagement records it generates.
VercelHosts and runs the website.Request data and operational logs, including IP addresses. The site's production deployment is served from Vercel's iad1 region (United States).
CloudflareSits in front of the site as our DNS and network layer, and serves traffic from the edge location nearest you.Request data and network logs, including IP addresses.
SupabaseRuns the database and file storage behind the publication: articles, images, internal records, and our ticket system.Reader newsletter data does not go here. It may hold a record of correspondence you send us. The project is hosted in Supabase's ca-central-1 region, in Canada (verified 6 August 2026).
Google WorkspaceCarries our email.Anything contained in an email you send us or we send you.

[OPEN: each of these needs its data-processing terms confirmed and recorded. That has not been done, and this policy does not claim it has.]

7. Where your data goes

NLNT is a small publication with an international readership and providers in more than one country. Two facts matter.

Our database is in Canada. The Supabase project that holds our articles, internal records and ticket system is hosted in Canada. Newsletter subscriber data is not stored there, but correspondence records may be.

Our other providers are in the United States. beehiiv, Vercel, Cloudflare and Google are United States companies, and our site is served from United States infrastructure.

If you are in the EU or the UK, this means personal data you give us is transferred outside your country, to Canada and to the United States, when we use these services.

[OPEN: the transfer mechanism for each provider (Standard Contractual Clauses, the EU-US Data Privacy Framework, the UK Addendum, or reliance on Canadian adequacy) needs to be identified and recorded before this policy is published. This draft deliberately states the transfer as a fact and does not assert a mechanism we have not verified.]

8. How long we keep things

Being straight about this: NLNT does not yet operate a written retention schedule, and this draft will not invent one.

What is true today:

- Newsletter subscribers. Your record stays in beehiiv for as long as you are subscribed. If you unsubscribe, beehiiv keeps a record that you unsubscribed, which is what stops us mailing you again. If you ask us to delete you entirely, we delete the record in beehiiv. - Email correspondence. Kept in our mailbox unless you ask us to remove it. - Provider logs. Held by Vercel and Cloudflare under their own retention periods, which we do not control.

[OPEN: JP to decide the retention periods he is willing to commit to in public, for each category above. A published policy should state a period only if there is a mechanism that enforces it. There is no such mechanism today.]

9. Links to other sites

Articles cite and link to outside sources, and sometimes to the makers, producers and retailers we write about. Those links are ordinary editorial references. Following one takes you to a site we do not run and whose privacy practices are not ours.

No link on this site is an affiliate link, and no link earns us a commission. If that ever changes, it will be disclosed on the page and this policy will be updated.

10. Your rights and how to use them

Depending on where you live, you may have the right to ask us for a copy of the personal data we hold about you, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent.

How to exercise any of them: email [email protected].

There is no web form. There is no portal. A real person reads that mailbox and answers.

What happens next: we will ask you to confirm you are the person the data is about, usually by replying from the address in question. We will not act on a deletion request without that confirmation, because acting on an unverified request is itself a privacy failure. Where the GDPR applies, we will respond within one month of your request, as it requires.

The fastest route to stop receiving the newsletter is the unsubscribe link at the foot of every issue. It works without contacting us.

If you are in the EU or UK and you are not satisfied with our answer, you have the right to complain to your national data protection authority.

[OPEN: whether NLNT is required to designate a Data Protection Officer under Article 37, or an EU or UK representative under Article 27. Our reading is that neither is likely at this scale and with this processing, but it is a question for counsel, not for us to assert.]

11. If you are in California

The CCPA and CPRA apply to businesses that meet at least one statutory threshold: annual gross revenue above the statutory amount, buying or selling or sharing the personal information of large numbers of consumers, or deriving half or more of revenue from selling or sharing personal information.

NLNT meets none of them today. Our newsletter list is five addresses, all of which are the founder's own test and working accounts. We have no revenue from personal data. We do not sell or share personal information as those terms are defined.

We say this plainly rather than publishing a California section that implies obligations we are not subject to. If you are in California and you want your data deleted or want to know what we hold, email us at the address above and we will handle it the same way we handle any other request.

[OPEN: counsel to confirm this characterisation, and to say at what point NLNT should publish a full California section.]

12. Children

The site is written for adults and is not directed at children. We do not knowingly collect personal data from anyone under 13, and the only thing we collect at all is an email address someone types in. If you believe a child has subscribed, email us and we will remove the record.

13. Security

Our site runs on managed infrastructure (Vercel, Cloudflare, Supabase, beehiiv) and is served over HTTPS with HSTS enabled. Administrative access to the publication's systems is limited to the founder.

We hold no security certification, and this policy does not claim one. No small publication can promise that data is perfectly safe, and we are not going to say otherwise.

14. Changes to this policy

If our data practices change, this policy changes with them, and the change will be dated. Material changes to how we use subscriber data will be announced in the newsletter rather than made quietly.

15. Contact

[email protected] [LEGAL ENTITY NAME] [REGISTERED ADDRESS]

---

*End of draft. See README.md in this folder for what was verified, what was assumed, and the decisions needed before this can be published.*