Privacy
(Helpfully written by AI)
The short version is that we hold what it takes to post you an envelope, send you an email, and take your money. If you said he could, one other member gets your address every month. No lists are sold to 3rd parties.
What we hold
- Your name and the address to post to, both as you typed it and as the postal database standardises it.
- Your email, for receipts, for telling you an issue has posted, to let you log in and edit your subscription or other account details, and if you consented also for the occasional other email traffic like a newsletter or marketing we send.
- Which tier you’re on, which issues you’ve been sent, and who you were paired with.
- Which boxes you ticked and when, including any you changed later.
- Anything you write to us. If you write in, you’re agreeing we can print it, in a letter, on the site, in a newsletter, or anywhere else we like.
We never see your card. Stripe takes the payment and holds the card, and what comes back to us is a customer reference and whether it worked.
Who else sees anything
- The postal service reads the front of the envelope, which is the entire point of an envelope.
- On the Mafia and the Don, one other member every month gets your name and address so his letter can reach you. The details are on the address page.
- A Don who sponsors your upgrade is told your city and state, and your first name. No street.
- Stripe, for taking the money.
- The printer, which gets a list of names and addresses to print out.
- Cloudflare, which runs this website and holds the database everything above is stored in. That means all of it, and it would be strange to list the printer and leave out the filing cabinet.
- Resend, which is what actually delivers our email, so it handles every address we send to and the contents of what we sent.
- Nobody else. We do not sell your data.
The last few are infrastructure rather than people looking at things. They hold what they hold because it’s impossible to run a website or send an email without somebody’s computers doing it, they’re contractually only allowed to use it to provide that service, and none of them gets to do anything else with it.
Cookies and tracking
Until you press Accept, no tracking cookie is set and nothing that could identify you leaves your browser. The first time you turn up you get a slip at the bottom of the screen with two buttons on it. Analytics still runs in the background, but in a cookieless mode that only counts visits as a group and cannot tell who you are; the paragraphs below say exactly what does and does not happen either way. Decline and the site behaves exactly the same. You can change your mind from the cookies link in the footer of any page.
One other thing gets kept in your browser and it isn’t behind that slip, so here it is plainly. If you arrive through a link somebody published — a gift guide, a review, someone we pay a commission to — that link carries a short code naming them, and we keep that code on your own device for sixty days so that if you buy something, the person who sent you gets paid. It is not an identifier for you. If you never buy anything it expires and we never learn it existed. Clearing your site data removes it.
If you accept, all three run fully: Google Analytics, the Meta pixel and the Pinterest tag set cookies and report your visit, so we can see how many people landed on a page, which ad or which pin they came from, and whether they signed up. If you decline, none of them sets a cookie or can recognise you. Google Analytics still runs, but in a cookieless mode that sends only anonymous counts; the Meta pixel loads but sends nothing at all; and the Pinterest tag does not load.
None of the three is given your email, your name or your address. All three offer a way to send us those so they can match you to an account they already hold, and we have turned that off in all three. What they get is that a browser arrived and what it did here, never who was holding it.
Inside Google Analytics we turn on a feature called Google Signals. If you are signed in to a Google account and you have left ad personalisation switched on there, it tells us rough age, gender and interests for our visitors as a group, and it lets Google work out that a phone and a laptop are the same person rather than two people. We never see your Google account and we never learn your name from it. What reaches us is a group picture, and the reason we want it is to stop paying to put this in front of people who would never want it.
That feature works by using our own first-party cookie and Google’s third-party advertising cookies together. Ours only says a browser came back. Google’s is the one that already knows things about you from everywhere else you have been.
There are three ways out: Decline the banner here and Signals never switches on, because declining withholds the advertising consent it needs. Turn off ad personalisation in your Google account at My Ad Center, which switches it off everywhere and not only on this site. Or install Google’s own Analytics opt-out add-on for your browser.
Getting rid of it after the fact is a fourth thing, and it is not ours to do. Whatever Google has tied to your account you can look at and delete yourself at My Activity. That is Google’s record and not our copy of it, so it covers every site you have been to rather than only this one. Ask us to delete what we hold and that is the section further down, which is a different request to a different party.
One thing we will not do with any of it: work out who you are. We do not hand Google your name, your email or your address, we do not ask it to match what it knows against what we know, and we do not try to pull a single person back out of a report that comes to us as a group. That is a rule Google sets and it is also the one we would want anyway.
What we set either way: two cookies the moment you sign in. One keeps you signed in — it holds no detail about you, only a reference to the session. The other does one small thing, which is let a page show you an Account link instead of a Join button; it says nothing but that you are signed in, and it can open no door on its own. Both go when you sign out or after thirty days, and both are strictly necessary, so neither is behind the banner. Alongside them, whatever Stripe needs to take a payment safely on the payment pages, and the record of which of those two buttons you pressed. None of it is sold.
Receipts, issue notices and anything about your own membership are transactional and you get those while you’re a member. Anything else only happens if you ticked the box, and every one of those has an unsubscribe on it that works the same day.
How long we keep it
Your address goes as soon as you ask. Nothing is deleted on a timer, because a member who comes back after two years away should not have to type it all in again. Invoices and consent records are kept for seven years, because tax and disputes both need them.
Getting a copy, or getting rid of it
Write to us and ask. You get a copy of everything we hold about you within thirty days, in a form you can actually read, and no fee. Ask us to delete it and we delete it, apart from the invoice and consent records above, and we tell you exactly what stayed and why.
If you’re in the UK or the EU, this is your right of access and erasure. If you’re in California, this covers your right to know and your right to delete, and we do not sell your data.
If somebody bought this for you
You never signed up and we have no definite email for you until you give us one. Every envelope has a QR code printed inside it, and that code is how you claim the subscription, add an email and then change anything you like. Until you claim it the code is all you have, and it is all it does. A fresh one is printed inside every issue, so missing one costs you a month and nothing else.
Children
This isn’t for under-18s and we don’t knowingly hold anything about one.
If something leaks
You get told, by email, with what happened and what was in it.