Privacy
Privacy policy.
This privacy policy describes how Addictive Posts (“we”, “us”, “our”) collects, uses, stores, discloses, and otherwise processes personal data when you visit addictiveposts.com, join the members kitchen, write to us, or otherwise interact with the site. It is written to meet the transparency duties in the EU General Data Protection Regulation 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, the EU ePrivacy Directive and the UK Privacy and Electronic Communications Regulations (PECR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), other US state consumer privacy laws, Canada’s PIPEDA and CASL, Brazil’s LGPD, Australia’s Privacy Act 1988, COPPA, CAN-SPAM, and CalOPPA. Where a stricter local rule applies to you, we follow that rule.
Controller: Addictive Posts. Contact for privacy requests: hello@addictiveposts.com. Postal correspondence: Correspondence only. No visiting address is published.
Effective / last updated: 3 September 2026.
1. Who we are
Addictive Posts is a cookery publication at addictiveposts.com. We are the controller of personal data processed through this site. We are not established in the EEA or the United Kingdom. We do not currently maintain an Article 27 GDPR / UK GDPR representative because processing of EEA/UK personal data is limited, not large-scale, and not regular monitoring of individuals. If that changes, we will appoint a representative and name them here. Until then, email hello@addictiveposts.com.
We do not have a statutory data protection officer. The same address is the contact for access, deletion, and other rights requests.
2. Scope, current technical state, and honesty
This policy covers the public website, the members kitchen, contact forms, and any email we send from hello@addictiveposts.com or news@addictiveposts.com. It does not cover third-party sites we link to.
Contact notes are emailed to hello@addictiveposts.com on this host. Membership joins are emailed there too. This browser also keeps a membership record in local storage so you can open the members kitchen on this device. A confirmation email to your address is sent only after our Amazon SES sending account is approved; until then we still take the join and notify hello@addictiveposts.com, but we do not send the confirmation. Marketing / the free list from news@addictiveposts.com also waits for that approval and for your unticked-until-ticked consent.
3. Personal data we collect
3.1 Identifiers you give us
- Members join form: name, email address, time of joining, whether you also asked for the free list.
- Contact form: name, email address, the text of your note, and the time you sent it.
- Optional newsletter flag (unchecked until you tick it). Separate from membership.
3.2 Data from your device and the host
- Local storage keys on your device:
addictiveposts.member(membership record),addictiveposts.notes(contact notes you submitted in this browser),addictiveposts.contact.at(a timestamp so the contact form cannot fire twice in 30 seconds). - Ordinary web-server logs generated by the host: IP address, date and time, requested URL, referrer, user-agent (browser and OS), and success or error codes. These exist to run, secure, and debug the site.
3.3 What we do not collect
- Payment card numbers, bank details, or billing address. Membership is FREE until 1,000 subscribers. We will not take a card until a price is published on this site and you agree to it.
- Precise geolocation, government IDs, biometric data, or health records.
- Special-category data under GDPR Article 9. Recipes mention allergens as cookery information, not as data about you. Do not send us medical details in a contact note.
- Advertising identifiers, pixels, or analytics SDKs. We do not run Google Analytics, Meta Pixel, TikTok, or similar.
- Data from data brokers.
Categories for CCPA/CPRA reporting (last 12 months): identifiers (name, email, IP); internet and network activity (pages, logs); customer records equivalent (membership and newsletter preference). We do not collect sensitive personal information as defined in California Civil Code § 1798.140, commercial information beyond membership status, inferences, geolocation, audio/visual employment or education data.
4. Sources
- Directly from you, when you fill a form or email us.
- Automatically from your browser and our hosting provider’s logs, when you load a page.
- We do not buy lists. We do not combine your data with a third-party profile.
5. Purposes and legal bases (GDPR / UK GDPR Article 6)
- Provide membership access you asked for (name, email, join time, local membership flag). Legal basis: performance of a contract, Art. 6(1)(b). While membership is free, the same basis covers the access we actually give you. You also tick an explicit terms box (consent layered on top, Art. 6(1)(a), which you may withdraw by cancelling).
- Reply to a note you sent. Legal basis: legitimate interests in corresponding with a person who wrote to us, Art. 6(1)(f); and your unticked-until-ticked consent that we may email you back, Art. 6(1)(a). You can refuse the box and we will not treat the note as a request for a reply.
- Optional free list from news@addictiveposts.com. Legal basis: consent, Art. 6(1)(a). The box starts unchecked. Withdrawal: email hello@addictiveposts.com or use the unsubscribe link we will put in every list message once mail is live. Consent is also the CASL and PECR basis for commercial electronic messages.
- Security, abuse prevention, and keeping the site up (IP, user-agent, URLs, honeypot fields, form wait timers). Legal basis: legitimate interests, Art. 6(1)(f), balanced against your interest in a working, un-spammed site. Honeypot fields are not stored if empty.
- Legal duties if a competent authority lawfully requires a log or we must keep a record of a rights request. Legal basis: Art. 6(1)(c).
Legitimate-interest balancing: we use logs and anti-bot timers because the site cannot be offered safely without them; we do not profile you for ads; retention is short; you may object by emailing hello@addictiveposts.com.
6. Cookies, local storage, and similar technologies
EU ePrivacy Directive Art. 5(3) and UK PECR require consent for non-essential storage on your device. We currently set no advertising or analytics cookies. What we do use:
- Strictly necessary local storage for the service you asked for (membership record, contact-form rate limit). These are exempt from prior consent as strictly necessary to provide a service you explicitly request.
- The host may set a session or cache-related cookie, or send cache headers, solely to deliver pages. We do not use them to advertise.
Full inventory and how to clear it: Cookies. If we ever add analytics or advertising storage, this policy and the cookies page will be updated first, and a consent banner that blocks those tags until you opt in will go up. We do not currently need a cookie banner because we do not set non-essential cookies.
Do Not Track (CalOPPA): we do not track you across third-party sites, so a DNT header has no extra effect. Global Privacy Control (GPC): we treat GPC as a “do not sell or share” signal. We do not sell or share personal information for cross-context behavioural advertising, so GPC does not change a current practice; it will bind us if that practice ever starts.
7. Retention
- Browser local storage: until you clear site data, cancel membership (one click), or the browser evicts it.
- Hosting logs: whatever the host keeps as standard (typically 14–90 days). We do not export those logs into a marketing file.
- Email correspondence, once mail is live: for the time needed to answer you, then up to 24 months unless a dispute or legal hold requires longer.
- Rights-request records: up to 24 months, to show we complied.
- We do not keep data “just in case”. When a purpose ends, we delete or irreversibly anonymise.
8. Sharing, processors, sale, and “no sale”
We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not disclose it to third parties for their own direct marketing (California Shine the Light, Civ. Code § 1798.83). We do not run a financial-incentive or “pay-for-privacy” programme.
Who may see data as a processor on our instructions:
- The website hosting provider that serves addictiveposts.com (storage of files and server logs).
- The mailbox host for hello@addictiveposts.com (the same hosting account that serves this domain). Contact notes and join notices are delivered there now.
- Amazon Simple Email Service (SES), as a processor for transactional mail only (members confirmation to your inbox, and later the free list if you ticked it), once that sending account is approved. SES is not used for advertising and is not appointed until approval.
- Professional advisers or a competent authority if the law requires it, or to establish, exercise, or defend legal claims.
We do not allow processors to use your data for their own advertising. If we ever appoint a new processor that changes this picture, we will update this section first.
9. International transfers
The site is hosted on infrastructure that may sit outside your country, including outside the EEA and the UK. Where GDPR or UK GDPR applies and the destination is not covered by an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum) with the host, plus the technical measures in section 10. You may ask hello@addictiveposts.com for a summary of the safeguards in place.
10. Security
We use HTTPS, access-controlled hosting, anti-bot timers and honeypots on forms. Membership access on this device is a local-storage record; the join itself is emailed to hello@addictiveposts.com. No method of transmission or storage is perfectly secure. If we become aware of a breach that is likely to result in a high risk to your rights, we will notify you and the competent authority within the time the applicable law requires (72 hours under GDPR Art. 33 where feasible).
11. Children (COPPA, GDPR Art. 8, UK Age Appropriate Design)
The site is a cookery publication for adults. It is not directed at children under 13 (US COPPA) or under 16 (EEA/UK). You must be at least 18 to join members. We do not knowingly collect personal data from children. If you believe we have, write to hello@addictiveposts.com and we will delete it. We do not age-gate the public recipes; a parent or guardian is responsible for a child’s use of the public pages.
12. Automated decisions
We do not make solely automated decisions that produce legal or similarly significant effects (GDPR Art. 22). Form wait-timers and honeypots only reject obvious bots.
13. Your rights — EEA and United Kingdom (GDPR / UK GDPR)
You may:
- Access a copy of your personal data (Art. 15).
- Have inaccurate data corrected (Art. 16).
- Ask for erasure (Art. 17), including after you withdraw consent or object.
- Restrict processing (Art. 18).
- Receive data you gave us in a machine-readable form and send it elsewhere (Art. 20).
- Object to processing based on legitimate interests (Art. 21). We will stop unless we demonstrate compelling legitimate grounds.
- Withdraw consent at any time, without affecting processing before the withdrawal.
- Lodge a complaint with your lead supervisory authority. In the UK that is the ICO (ico.org.uk). In the EEA, your national data protection authority (list: edpb.europa.eu). You may also complain to us first at hello@addictiveposts.com.
We will answer within one month (extendable by two months for complex requests, with notice). We may need to verify you. We will not charge unless a request is manifestly unfounded or excessive.
14. Your rights — California (CCPA/CPRA) and other US states
If you are a California resident, you have the rights in Civ. Code §§ 1798.100–1798.199, including: to know / access; to delete; to correct; to opt out of sale or sharing; to limit use of sensitive personal information (we do not use SPI to infer characteristics); and to non-discrimination for exercising these rights. We have not sold or shared personal information in the preceding 12 months. Categories collected, sources, purposes, and retention are in sections 3–8.
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and other US states with comprehensive privacy statutes have corresponding rights of access, deletion, correction, and opt-out of targeted advertising, sale, and (where the statute says so) profiling. We do not do targeted advertising, sale, or profiling that produces legal or similarly significant effects. Send the same email. An authorised agent may submit a California request; we will verify the agent and you. We will not discriminate against you for exercising a privacy right.
How to submit: email hello@addictiveposts.com with the subject “Privacy request” and the right you want to exercise. We will verify using the email we already have or a reasonable further check. Appeals (where a state law gives you one): reply to our decision within a reasonable time and we will review.
15. Canada (PIPEDA and CASL) and Brazil (LGPD)
PIPEDA: we collect only what we need, for purposes a reasonable person would consider appropriate; we obtain consent (express for the list and membership; implied for strictly necessary logs); we limit use, disclosure, and retention; we safeguard; we are open about our practices; you may access and challenge accuracy via hello@addictiveposts.com. Complaints: Office of the Privacy Commissioner of Canada.
CASL: we send commercial electronic messages only with express consent (unchecked-until-ticked free-list box). Each message, once mail is live, will identify us, include hello@addictiveposts.com, and a working unsubscribe that takes effect promptly and at no cost. Membership service messages are not marketing.
LGPD (Brazil): if you are in Brazil we are a controlador. Legal bases we rely on include consent (Art. 7, I) and legitimate interest (Art. 7, IX) as described in section 5. You may request confirmation of processing, access, correction, anonymisation, portability, deletion, information about sharing, and revocation of consent (Arts. 18–19) via hello@addictiveposts.com. You may complain to the ANPD.
16. Australia and other countries
Australian Privacy Principles: we collect only for our functions, notify you through this policy, use and disclose for those purposes, keep data secure, and let you access and correct it. Complaints:hello@addictiveposts.com, then the OAIC. For every other country: we apply this policy and any mandatory local right you have. Mandatory consumer and privacy rights of your place of residence are not waived.
17. Marketing email (CAN-SPAM, PECR, CASL)
We do not send marketing email until the free-list pipeline is live. When it is: only to addresses that opted in; identity and news@addictiveposts.com in every message; working unsubscribe; no false headers or subject lines; a valid postal address in the message as CAN-SPAM requires (we will publish that address here and in the footer of the email before the first commercial send). Transactional replies to a note you sent are not marketing.
18. How to exercise a right or contact us
Email hello@addictiveposts.com. Say which right you want, and the email you used on the form. If the data still lives only in your browser, you can also delete it yourself: cancel membership on /members, or clear this site’s data in your browser settings. We will still help if you write.
19. Changes
We will change this policy when our practices or the law change. The date at the top is the effective date. Material changes (new processor, new cookie, paid membership, email going live) will be posted here before they take effect. Continued use after the effective date is acceptance of the updated policy, except where the law requires a fresh consent — in that case we will ask.
Related pages: terms, cookies, disclaimer.
Addictive Posts. Correspondence only. No visiting address is published. hello@addictiveposts.com.