Privacy Policy
Last updated: July 31, 2026
This privacy policy explains what personal information this site collects, why it is collected, how long it is kept, who else can see it and what you can do about it. It covers this website only and does not cover the advertising networks or other third-party sites we link to, each of which operates under its own policy and its own controller. This site is an independent publisher of reference material about advertising platforms, such as our page on Popunder Ad Network; it is not an advertising network, it does not operate user accounts, and it never handles payment credentials.
The operator of this site is the data controller for the processing described here, and full identification details are available on request. Questions, requests and complaints go to [email protected]. This version takes effect on 31 July 2026 and replaces any earlier version.
The law that applies
The operator is based in New Zealand and processes personal information in line with the Privacy Act 2020 and its Information Privacy Principles. Because the site is read internationally, additional regimes apply to particular readers. Visitors in the European Economic Area and the United Kingdom are covered by the General Data Protection Regulation, Regulation (EU) 2016/679, and its UK equivalent. Residents of California are covered by the California Consumer Privacy Act as amended by the California Privacy Rights Act. Where these regimes grant a stronger right than New Zealand law, we apply the stronger right rather than the minimum.
What we collect
Information you give us directly. If you write to any of the addresses published on the contact page, we receive your email address, whatever name you sign with, and the content of your message including any attachments and previous correspondence in the thread. We do not operate a registration system, a newsletter or a comment facility, so there is no account data, no password and no profile associated with you.
Information collected automatically. Like any website, this one records technical data when a page is served. That includes your IP address, which identifies the network you connect from and allows approximate country-level location and abuse prevention; your user agent string, which names your browser and version and lets us confirm that pages render correctly; your operating system and device class, which we use to check that the mobile layout works; the pages you open and the time spent on them, which tells us which material is useful and which is not; and the referring address, which tells us whether you arrived from a search engine, another site or directly.
What we never collect. We do not ask for and do not want payment card numbers, bank details, advertising platform logins, campaign data, government identity documents or any special category data such as health, biometric, political or religious information. If you send material of that kind to us unprompted, we delete it and tell you that we have.
Why we process it
Correspondence is processed for one purpose: to read, verify and answer your message, and to keep a record of corrections so that we can show what was changed and when. Technical data is processed to deliver pages, to keep the site available and defended against automated abuse, and to understand in aggregate which pages are read and where readers arrive from. Aggregate analytics inform editorial decisions about what to research next; they are not used to build a profile of you, to make automated decisions about you, or to target advertising.
We do not sell personal information, and we do not share it for cross-context behavioural advertising as those terms are defined under California law. We run no advertising network on this site and no third-party ad tags.
Legal bases
For readers covered by the GDPR, our legal bases are as follows. Answering your correspondence rests on legitimate interests under Article 6(1)(f), namely responding to someone who has chosen to contact us, and in some cases on steps taken at your request prior to entering into a contract under Article 6(1)(b). Server logs and security processing rest on legitimate interests under Article 6(1)(f) in operating a secure and functioning website. Any non-essential analytics or cookies set beyond what is strictly necessary rest on your consent under Article 6(1)(a), which you may withdraw at any time without affecting processing already carried out.
Who else sees it
We do not sell, rent or trade personal information. A small number of service providers process data on our behalf under contract, each restricted to what their function requires: the hosting provider that stores the site files and generates server logs; the content delivery network that serves static assets and filters malicious traffic; the email provider that carries correspondence to and from the addresses on this domain; and, where enabled, an analytics provider that reports aggregate traffic patterns. Each acts on our instructions and may not use the data for its own purposes.
Beyond those processors, we disclose personal information only where the law requires it, such as a valid order from a court or regulator, or where disclosure is necessary to establish, exercise or defend a legal claim. If the site changes ownership, records may transfer to the new operator, and we would publish notice of that on this page before it takes effect.
Transfers outside your country
Our providers may store or process data outside New Zealand, including in the United States and the European Union. Where personal information covered by the GDPR leaves the European Economic Area, transfers are made under an adequacy decision where one exists, and otherwise under the European Commission's Standard Contractual Clauses together with any additional safeguards the circumstances require. Where information covered by the Privacy Act 2020 is sent overseas, we take reasonable steps to satisfy ourselves that comparable safeguards apply, as required by Information Privacy Principle 12.
How long we keep it
Correspondence is kept for 24 months from the last message in the thread, after which it is deleted, except where it documents a published correction. Correction records are kept for as long as the affected page remains online, because they are the evidence behind a change we made publicly. Server logs are retained for 90 days and then discarded. Aggregate analytics, which no longer identify an individual, may be kept indefinitely. Where a longer period is required by law or to defend a legal claim, we keep only what that purpose requires.
Your rights
You may ask us for a copy of the personal information we hold about you, and for confirmation of whether we hold any at all. You may ask us to correct information that is wrong or incomplete. You may ask us to delete information, and we will do so unless a legal obligation requires us to keep it. You may ask us to restrict processing while a dispute about accuracy is resolved, and you may object to processing carried out on the basis of legitimate interests. Where processing rests on consent, you may withdraw it at any time. Where technically applicable, you may request your data in a portable, machine-readable format.
Send requests to [email protected], stating which right you are exercising. We respond within 20 working days under New Zealand law and within one month under the GDPR, extendable by two further months for complex requests, in which case we tell you within the first month. We do not charge for these requests and we do not require an account to make one.
If you are unhappy with our response, you may complain to the Office of the Privacy Commissioner in New Zealand, to your national supervisory authority in the European Economic Area, or to the Information Commissioner's Office in the United Kingdom. You are not required to raise the matter with us first, although it is usually faster.
Security
The site is served exclusively over HTTPS with TLS encryption, so traffic between your browser and our server cannot be read in transit. Access to correspondence and hosting controls is limited to the people who need it, protected by unique credentials and multi-factor authentication. We hold no payment data and no user accounts, which removes the two categories most often targeted in breaches of publishing sites. No system is perfectly secure, and if a breach occurs that is likely to cause serious harm we will notify affected people and the relevant authority within the timeframes the applicable law requires.
Children
This site publishes professional reference material about advertising platforms and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has sent us personal information, write to [email protected] and we will delete it.
Changes to this policy
When this policy changes we update the date at the top of the page and, where the change materially affects your rights or how your information is used, we describe the change in a notice on this page. Continuing to use the site after a change takes effect means the revised policy applies to you. Related documents are the terms of use, which govern use of the site itself, the editorial policy, which governs how our content is produced, and the author page, which identifies who produces it.