Core Privacy Safeguards at a Glance
1. Data Controller & Operator Identity
This Privacy Policy governs the collection, processing, and protection of personal data by Plod & Ponder Publications ("Plod & Ponder", "we", "us", or "our"), founded and operated by Chandler Kellogg, operating under the laws of the State of South Carolina and the United States.
Our designated supervisory contact for data protection inquiries and Data Subject Access Requests (DSAR) is:
2. Information We Collect and Process
We adhere to strict data minimization principles. We collect only what is strictly necessary to deliver, secure, and maintain our digital atlas, monographs, and services:
- Server Telemetry & Diagnostic Access Logs: When you access our website, our hosting infrastructure automatically records technical access metadata. This includes your Internet Protocol (IP) address, browser user-agent, operating system, requested URL path, referring URL, HTTP status code, and timestamps.
- Voluntary Correspondence & Form Submissions: If you initiate contact through our intake form, dispatch email correspondence, report an issue via the bug reporter widget, or subscribe to our newsletter gazette, we collect your name, email address, message body, and any attachments or system context voluntarily submitted.
- Functional Local Browser Storage (localStorage): We do not use third-party cookies. We utilize client-side
localStorageexclusively to preserve your explicit interface preferences, including:- Active visual theme, reduced motion preferences, and sensory typography choices.
- Locale suggestion toast dismissal flags (
plod_locale_suggestion_dismissed) so you are not repeatedly prompted.
3. Legal Bases for Data Processing (GDPR & UK GDPR Articles 13 & 14)
For individuals residing within the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data under the following lawful bases set forth in Article 6 of the General Data Protection Regulation (GDPR):
Legitimate Interests (GDPR Art. 6(1)(f))
We process automated server access logs and telemetry based on our legitimate interest in securing our digital infrastructure, detecting denial-of-service (DDoS) attacks, preventing fraud, troubleshooting server errors, and ensuring global network performance.
Consent (GDPR Art. 6(1)(a))
We process your contact details for gazette subscriptions, reader inquiries, and collaboration requests solely based on your affirmative consent. You have the unconditional right to withdraw consent at any time by utilizing the unsubscribe link or emailing [email protected].
4. Third-Party Service Providers & Processors
We do not sell your personal data. We engage a limited number of trusted infrastructure vendors to operate our platform:
| Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Google Cloud / Firebase | Global edge CDN hosting and static file delivery | IP address, server access logs | United States / Global Edge |
| Google Workspace | Inbound correspondence and contact intake | Name, email, message body | United States |
| Self-Hosted Telemetry | Privacy-respecting performance metrics (Zero-cookies) | Aggregated page views, GPC signals | United States |
5. International Data Transfers
Plod & Ponder is headquartered and operated in the United States. If you access our website from outside the United States (including the EEA, UK, Canada, or Asia), please be advised that any data processed will be transferred to, stored, and processed in the United States.
To safeguard cross-border transfers from the EEA and UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and the UK Information Commissioner's Office (ICO), alongside industry-standard encryption protocols (TLS 1.3 in transit) and strict administrative access controls.
6. Your Legal Privacy Rights (US Multi-State & International)
Depending on your jurisdiction of residence (including California under CalOPPA and CCPA/CPRA, Colorado under CPA, Virginia under VCDPA, Connecticut under CTDPA, Utah under UCPA, the European Union under GDPR, and the UK under UK GDPR), you are entitled to specific statutory rights regarding your personal information:
- Right to Know & Access: The right to request confirmation of whether we process your data and receive a readable copy.
- Right to Deletion / Erasure: The right to request deletion of personal information we have collected from you, subject to statutory exceptions.
- Right to Rectification: The right to correct inaccurate or incomplete personal records.
- Right to Data Portability: The right to receive your data in a structured, commonly used, and machine-readable format.
- Right to Opt-Out of Sale or Behavioral Profiling: We do not sell or share your data for cross-context behavioral advertising. You are permanently opted out by default.
- Right to Non-Discrimination: We will never deny services, alter prices, or degrade quality if you exercise your statutory privacy rights.
How to Submit a Data Subject Access Request (DSAR)
To exercise any of the rights above, please dispatch an email to [email protected] with the subject line "Data Subject Access Request". Please identify your state or country of residence and describe your request with sufficient detail. We verify identity via return email and fulfill verified requests within 30 days (GDPR) or 45 days (US statutes) without fee.
7. Global Privacy Control (GPC) & Do Not Track Signals
We strongly support consumer privacy automation. When our platform detects an automated Global Privacy Control (GPC) signal emitted by your browser (navigator.globalPrivacyControl === true) or a Do Not Track (DNT) header, our client-side monitoring provider automatically disables all third-party analytics and telemetry scripts.
8. Children's Online Privacy Protection Act (COPPA Compliance)
Our website, publications, digital tools, and services are directed exclusively at individuals aged 13 and older. We do not knowingly collect, solicit, or maintain personal information from children under 13 (or under 16 within the EEA and United Kingdom). If we become aware that personal information has been collected from a child under 13 without verified parental consent, we take immediate steps to delete such data from our records.
If you are a parent or guardian and believe your minor child has provided us with personal information, please contact us immediately at [email protected].
9. Modifications to this Privacy Policy
We reserve the right to revise this Privacy Policy periodically to reflect changes in regulatory statutes, technical infrastructure, or editorial operations. Any changes will be posted to this URL with an updated effective date at the top of this document. Continued use of the website following published updates signifies your acknowledgment of the revised terms.