Privacy Policy
Who we are
Our website address is: https://ptarmiganlabs.com.
This site is run by Ptarmigan Labs AB, which is a company incorporated in Sweden. The site is mainly a conduit for my (Göran Sander) personal thoughts on various topics, but every now and then there may also be more corporate topics discussed.
What personal data we collect and why we collect it
Comments
Members can comment on posts. A comment shows your name, and your expertise if you add it, and anyone can read it. You can edit or delete your own comments, and we can hide or remove comments.
Your profile picture comes from Gravatar, a service run by Automattic, if you have one there. Ghost turns your email address into a hash, a scrambled string, and the comment section asks Gravatar for the picture that goes with it. Gravatar's privacy policy: https://automattic.com/privacy/.
Server logs
Like any web server, ours records each request it receives: the IP address it came from, the page, the time and the browser's user agent. We use these logs to stop abuse. An address that keeps failing to sign in, floods the sign-up form or probes for weak spots is blocked at Cloudflare for 7 days. The blog's own logs are kept for about 11 days, and the web server's for about a month.
Contact form
When you send a message through the contact form on the Services page, we receive your name, your email address, your company if you give one, the topic you pick and your message. We use them only to reply to you, and to work with you if that is where the conversation leads.
- The form sends your message to our mailbox by email. Nothing is stored on this website, and the message is not logged.
- The email is delivered by Resend (Plus Five Five, Inc., USA), and our mailbox is at Google Workspace.
- We keep messages as long as the conversation, and any work that follows, needs them. Ask us, and we delete them.
- Spam protection: the form uses Cloudflare Turnstile to tell people from bots. Turnstile processes your IP address, your browser's user agent and TLS fingerprint, and the site the form is on, and uses them to detect and block bots. Cloudflare also uses these signals to improve its bot detection, and for that it is itself responsible. See Cloudflare's Turnstile privacy addendum.
Membership and newsletter
When you sign up for the newsletter, Ghost, the software the blog runs on, stores your email address, your name if you give one, which newsletters you get, and when you signed up. It also stores your approximate location, meaning country and city, worked out from your IP address when you signed up.
It also records how you found the site, where it can: the site you came from, and the post or page you signed up on. The signup form on our home page and product pages sends these with every signup, and we keep that page as a label on your membership, such as "Signup: home". If you allowed it in your privacy choice, your signup also sends the pages you read here in the day before. Ghost then records the post or page that brought you, and the form labels your membership with each of our product pages you looked at, such as "Viewed: Butler SOS".
- Newsletters and sign-in emails are sent by Mailgun (Sinch), from its EU region. Message data is processed and stored in Germany, and Mailgun keeps message bodies for up to 7 days.
- When you open a newsletter, Ghost records that you opened it and which links in it you click.
- Every newsletter has an unsubscribe link, and your account page lets you change what you get. To have your account deleted, ask us.
Cookies and browser storage
Reading the site sets no cookies, and our page statistics (Plausible) don't use any. Cookies are set only if you sign in as a member, and confirming a newsletter subscription signs you in. Ghost then sets two, ghost-members-ssr and ghost-members-ssr.sig, to keep you signed in, and they go when you sign out.
Your browser also keeps a few things for the site:
- Your privacy choice, as
plabs-consent, so we ask only once. You can change it at any time under Privacy choices. - The pages you read here, only if you allow it. The last 15, and the site that sent you, as
ghost-history, in the browser tab you're using, for up to a day. They reach us only if you subscribe to the newsletter. Saying no, then or later, deletes them. - Your light or dark choice, as
plabs-theme, if you use the switch. - Whether you've closed an announcement, as
isAnnouncementBarVisibleandannouncementBarContent, while the blog shows one, until you close the tab.
Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracing your interaction with the embedded content if you have an account and are logged in to that website.
The blog also loads some of its own features from public content-delivery networks. Ghost's sign-up, search, comments and announcement bar come from jsDelivr, and the code highlighting comes from cdnjs (Cloudflare). Your browser fetches them from there, so those networks see your IP address, as with any site you load files from.
The fediverse
The blog is also on the fediverse, as @[email protected]. If you follow it, or reply to, like or repost one of its posts from a fediverse account such as Mastodon, your server sends us your public profile (your handle, name and profile picture) along with what you did. We store that on our server, so we can see it and reply. Ask us, and we'll delete it.
Analytics
We do not use Google Analytics or similar service in the ad-tech industry to track usage of the site.
Instead we use Plausible, which is a privacy-first online analytics service. We are interested in what pages on the site are most popular, but we are NOT interested in providing Google or similar companies with information about our visitors. Thus Plausible.
Why we're allowed to use your data
Data protection law (the GDPR) requires a legal basis for each use of personal data. Ours are:
- Contact form: answering your enquiry, and taking the steps towards an agreement that you ask for (Article 6(1)(b)), and our legitimate interest in answering messages (Article 6(1)(f)).
- Newsletter and membership: your consent when you sign up (Article 6(1)(a)). You can unsubscribe at any time.
- Comments: providing the comment feature you use as a member (Article 6(1)(b)).
- Server logs, spam protection and blocking attacks: our legitimate interest in keeping the site safe (Article 6(1)(f)).
- Page statistics: our legitimate interest in knowing which pages are read (Article 6(1)(f)). Plausible is built not to collect personal data.
- The fediverse: our legitimate interest in running the blog's fediverse account (Article 6(1)(f)).
- The pages you read before you subscribe: your consent in the privacy choice (Article 6(1)(a)). You can withdraw it at any time, under Privacy choices.
Who we share your data with
We don't sell your data, and we don't share it for advertising. We use a few service providers to run the site, and they process data on our behalf:
- Cloudflare (Cloudflare, Inc., USA) delivers every page and protects the site against attacks, so every request passes through its network. It also runs the contact form and its spam check.
- Contabo hosts the server the blog runs on, in Germany.
- Mailgun (Sinch) sends newsletters and sign-in emails from its EU region.
- Resend (Plus Five Five, Inc., USA) delivers contact-form messages to us.
- Google Workspace (Google, USA) hosts our email.
- Plausible counts page views without cookies, from the EU.
Where a provider is outside the EU, the transfer is covered by the EU–US Data Privacy Framework or by the EU's standard contractual clauses.
How long we retain your data
- Contact messages: as long as the conversation, and any work that follows, needs them.
- Membership: until you ask us to delete your account. Unsubscribing stops the newsletter but keeps the account.
- Comments: until you or we delete them.
- Newsletter emails at Mailgun: up to 7 days.
- Server logs: about 11 days for the blog and about a month for the web server. A blocked address stays blocked for 7 days.
- The fediverse: as long as the blog's fediverse account exists, or until you ask us to delete it.
- Bookkeeping: if you become a client, invoices and other accounting records are kept for as long as Swedish law requires.
- The pages you read, if you allowed it: in your browser for up to a day. What reaches us with a signup is kept with your membership.
What rights you have over your data
You can ask us for a copy of the personal data we hold about you, and have it corrected or deleted. You can also ask us to limit how we use it, object to how we use it, or have it sent to you or to another service in a machine-readable form. Where we rely on your consent, as for the newsletter, you can withdraw it at any time. We don't delete what the law requires us to keep, such as bookkeeping records.
To use any of these rights, write to info <at> ptarmiganlabs <dot> com.
If you think we handle your data wrongly, you can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY): https://www.imy.se.
Contact information
For questions regarding this policy, please reach out to info <at> ptarmiganlabs <dot> com.
Additional information
How we protect your data
The blog runs on a server in Germany. Every request reaches it through Cloudflare, which also serves the site's other pages from its own network. We keep the server locked down: it accepts web traffic only from Cloudflare, and it blocks repeated abuse automatically.
What automated decision making and/or profiling we do with user data
None.