Legal
Privacy Policy
How this static editorial website handles personal information, privacy rights, and regional notices.
Last updated: April 24, 2026
This Privacy Policy is a template for carmaxxink. Replace the placeholder contact details in src/config/site.ts before launch and have the final policy reviewed for your actual business, analytics, ads, newsletter, affiliate, and hosting setup.
Who We Are
Controller / business name: carmaxxink
Contact email: privacy@example.com
Mailing address: Add your business mailing address here
Information We Collect
As currently configured, this static site may process limited information:
- Technical data such as IP address, browser, device, referring page, and server logs handled by the hosting provider, CDN, or security provider.
- Information you send voluntarily by email or another contact method, such as name, email address, and message content.
- Admin-only browser storage on
/admin, including a session-only GitHub token and optional local article drafts. - Article images and content intentionally uploaded by an administrator.
How We Use Information
- To operate, secure, monitor, and improve the website.
- To respond to messages and legal requests.
- To publish and manage editorial content.
- To comply with applicable legal obligations.
Legal Bases for EU/UK Visitors
Where GDPR or UK GDPR applies, we rely on one or more of these legal bases:
- Legitimate interests, such as operating and securing a public website.
- Consent, where required for non-essential cookies, newsletters, or marketing.
- Contract, if you request a service or enter into an agreement with us.
- Legal obligation, where retention or disclosure is required by law.
Cookies and Browser Storage
See the Cookie Policy. The public site does not require non-essential cookies by default. If analytics, advertising, embedded media, or affiliate tools are added later, this policy and the cookie controls must be updated before launch.
Sharing Information
We may share limited information with service providers that help operate the website, such as hosting, CDN/security, GitHub, email, analytics, or deployment providers. We may also disclose information when required by law or to protect rights, security, and users.
International Transfers
Depending on your location and the providers used, information may be processed in the United States, the European Economic Area, or other countries. Where required, use appropriate transfer safeguards with vendors.
Retention
We keep information only as long as reasonably necessary for the purposes described above, unless a longer period is required by law. Browser session data for the GitHub token is intended to clear when the admin browser session ends.
Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or port personal information. You may also have the right to withdraw consent and lodge a complaint with a data protection authority.
To exercise rights, contact privacy@example.com.
California Privacy Notice
This section is intended to support California privacy notice requirements where they apply, including CCPA/CPRA and CalOPPA concepts. As currently configured, this site is not designed to sell personal information or share personal information for cross-context behavioral advertising.
- Categories collected: identifiers, internet or network activity, user-submitted communications, and admin-published content where applicable.
- Sources: you, your browser/device, hosting/security providers, and administrators.
- Purposes: website operation, security, communication, publishing, legal compliance, and troubleshooting.
- Sale/share: no sale or sharing for cross-context behavioral advertising is intended in the default implementation.
- Sensitive personal information: not intentionally collected by the default public site.
- Do Not Track: the site does not currently respond to browser Do Not Track signals.
Children
This website is not directed to children under 13 in the United States or the equivalent minimum age in other jurisdictions. Do not knowingly collect children’s personal information without appropriate consent and review.
Security
We use reasonable technical and organizational measures for a static website. No internet transmission or hosting environment is completely secure.
Changes
We may update this Privacy Policy. The updated version will be posted here with a revised date.