Privacy Policy
Effective Date: [INSERT DATE]Last Updated: [INSERT DATE]
This Privacy Policy describes how andygalpin.com (the "Site," "we," "us," or "our") collects, uses, and protects information when you visit the Site or subscribe to The Catalyst newsletter. By using the Site, you agree to the practices described below.
If you are a resident of California, please also see Section 10 for additional rights and disclosures.
1. Information We Collect
Information You Provide
When you subscribe to The Catalyst newsletter or otherwise interact with the Site, you may provide information such as your name and email address. You may also voluntarily provide information when contacting us directly.
Information Collected Automatically
When you visit the Site, certain information is collected automatically, including:
- IP address and approximate location
- Browser type, device type, and operating system
- Pages viewed, time spent on pages, and referring URLs
- Cookies and similar tracking technologies (see Section 6)
2. How We Use Information
We use the information we collect to:
- Deliver The Catalyst newsletter and related communications
- Respond to your inquiries
- Operate, maintain, and improve the Site
- Analyze usage trends and Site performance
- Comply with legal obligations and protect against fraud or misuse
3. We Do Not Sell Your Information
Our Commitment
We do not sell, rent, lease, or trade your personal information to third parties for their marketing purposes. The information you provide is used solely to deliver the services you have requested and to operate the Site.
We may share information only in the limited circumstances described in Section 5 (Third-Party Service Providers), such as with vendors who help us operate the Site or deliver the newsletter, or when required by law.
4. The Catalyst Newsletter
When you subscribe to The Catalyst, we collect your email address and any other information you choose to provide. Subscription is based on your affirmative consent. We use this information to send you the newsletter and occasional related communications.
You can unsubscribe at any time using the one-click unsubscribe link in any newsletter email, after which we will stop sending marketing communications to you, though we may retain certain records as required by law or for legitimate business purposes (such as honoring your opt-out request). Each newsletter email also includes our valid physical postal address, as required by applicable law.
5. Third-Party Service Providers
We use trusted third-party providers to help us operate the Site and deliver our services. These may include:
- Email service provider (e.g., [INSERT PROVIDER NAME]) to deliver The Catalyst
- Analytics providers (e.g., [INSERT PROVIDER NAME]) to understand Site usage
- Hosting and infrastructure providers to operate the Site
- Customer support and communication tools if applicable
These providers are contractually obligated to handle your information in accordance with applicable privacy laws and only for the purposes for which they are engaged. We do not authorize them to use your information for their own marketing.
6. Cookies & Tracking Technologies
The Site uses cookies and similar technologies to operate the Site and, with your consent, to understand how it is used. We use the following categories:
- Strictly necessary cookies — required for the Site to function, including the administrator login area. These are always on.
- Analytics cookies — help us understand how visitors use the Site so we can improve it. Off by default. We only set these if you opt in through our cookie banner or preferences modal.
You can change your cookie preferences at any time using the Cookie Preferences link in our Site footer. Most browsers also allow you to control cookies through their settings; disabling strictly necessary cookies may affect Site functionality.
We honor the Global Privacy Control (GPC) signal as a valid opt-out. If your browser is sending GPC, analytics cookies will remain off regardless of any on-site selection.
7. Data Retention
We retain personal information only as long as necessary for the purposes for which it was collected, or as required by law. Specifically:
- Newsletter subscriber data: retained while you remain subscribed, plus a reasonable period after unsubscribing for record-keeping and to honor opt-outs (typically up to 3 years).
- Analytics data: typically retained for [INSERT PERIOD, e.g., 26 months] in aggregated or anonymized form.
- Inquiry and correspondence: retained as long as needed to respond, plus a reasonable period for record-keeping (typically up to 2 years).
- Records required by law: retained for the period required by applicable law (for example, tax and accounting records typically for up to 7 years).
When personal information is no longer needed, we securely delete or anonymize it.
8. Data Security & Breach Notification
We take reasonable administrative, technical, and physical measures to protect the information we collect from loss, theft, misuse, and unauthorized access. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
In the event of a data breach affecting your personal information, we will notify you and applicable authorities in accordance with applicable law.
9. Your Rights & Choices
Depending on where you live, you may have rights regarding your personal information, including the right to:
- Access the information we hold about you
- Request correction of inaccurate information
- Request deletion of your information
- Opt out of marketing communications
- Withdraw consent where processing is based on consent
To exercise any of these rights, contact us at [INSERT EMAIL]. We will respond within the timeframe required by applicable law. Residents of California have additional rights described in Section 10.
10. California Residents (CCPA/CPRA)
This section applies to residents of California and supplements the rest of this Policy. Under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), you have specific rights regarding your personal information.
Categories of Personal Information We Collect
In the past 12 months, we have collected the following categories of personal information:
| Category | Examples | Source | Business Purpose |
|---|---|---|---|
| Identifiers | Name, email address, IP address | You; automatic collection | Deliver newsletter; operate Site |
| Internet/network activity | Pages viewed, time on site, referring URLs | Automatic collection | Site analytics and improvement |
| Geolocation data | Approximate location derived from IP | Automatic collection | Analytics; security; legal compliance |
| Inferences | Inferred content preferences | Derived from above | Improve and personalize content |
We do not knowingly collect "sensitive personal information" as defined under the CPRA. We do not collect personal information from individuals we know to be under 16.
Categories of Third Parties
We may disclose the categories of personal information above to service providers (such as our email platform, analytics provider, and hosting provider) for the business purposes described, and to legal authorities when required.
Sale and Sharing of Personal Information
We do not "sell" personal information for monetary value. The CPRA also defines "sharing" broadly to include disclosing personal information to third parties for cross-context behavioral advertising. To the extent that any tracking technologies used on the Site constitute "sharing" under the CPRA, you have the right to opt out. You can do so by:
- Clicking the "Do Not Sell or Share My Personal Information" link in our Site footer
- Adjusting your preferences in our cookie banner
- Enabling the Global Privacy Control (GPC) in your browser — we honor GPC as a valid opt-out signal
- Contacting us at [INSERT EMAIL]
Your California Rights
- Right to know what personal information we have collected, used, disclosed, sold, or shared
- Right to delete personal information we have collected from you, subject to legal exceptions
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information
- Right to limit use of sensitive personal information (we do not currently collect sensitive personal information)
- Right to non-discrimination for exercising any of these rights
Submitting a Request
To exercise any of these rights, contact us at [INSERT EMAIL]. We will verify your identity by matching information you provide with information we already hold. We will respond within 45 days, with an extension of up to 45 additional days if reasonably necessary.
Authorized Agents
You may designate an authorized agent to make a request on your behalf. The agent must provide written authorization signed by you, and we may require you to verify your identity directly with us.
11. Children's Privacy
The Site is not directed to children under the age of 13, and we do not knowingly collect personal information from children. If you believe a child has provided information to us, please contact us and we will take steps to delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page. Significant changes will be communicated through the Site or by email where appropriate.
13. Contact Us
If you have questions about this Privacy Policy or how your information is handled, please contact:
Andy Galpin
Email: [INSERT EMAIL]
[INSERT MAILING ADDRESS]