Privacy and data
What we collect, which is very little.
This describes how the site behaves as built. It is written to be checkable rather than comprehensive.
The short version
- No analytics, no advertising trackers, no tracking of any kind.
- No cookies. Two local storage items — your appearance preference and your answer to the consent banner — both of which stay on your device. See cookies and local storage.
- No accounts, no comments, no profiles.
- We hold your email address only if you gave it to us, and only to do the thing you gave it to us for.
What we collect, and why
Server logs
Our host records standard request information — IP address, user agent, requested URL, timestamp — as part of serving the site and defending it from abuse.
Lawful basis: legitimate interest in operating and securing the service. Retention: as set by our hosting provider, typically weeks rather than months. We do not combine these with anything else, do not build profiles from them, and do not export them.
If you subscribe to the newsletter
We store the email address you submit, and the date you submitted it. Nothing else — we do not ask for a name and do not attempt to infer one.
Lawful basis: your consent, given by submitting the form. Retention: until you unsubscribe. Every email carries a one-click unsubscribe, and unsubscribing deletes the address rather than moving it to a suppression list.
The form also records a timestamp of when the page loaded, used only to detect automated submissions. It is discarded with the request.
If you email us or use the contact form
We keep the correspondence so we can reply and, where relevant, so there is a record of a correction request.
Lawful basis: legitimate interest in answering people who contact us. Retention: as long as the thread is useful, and for corrections, as long as the article exists. We do not add correspondents to any mailing list.
What we deliberately do not do
- No analytics. We do not know how many people read this page, and have accepted that trade.
- No advertising trackers or ad scripts.
- No third-party fonts, scripts or stylesheets. Typefaces are downloaded at build time and served from this domain, so visiting a page does not tell anyone else you were here.
- No social embeds. Share links are plain URLs, not widgets.
- No selling or sharing of personal information, in the specific sense those words carry under the CCPA and CPRA. There is no opt-out link on this site because there is nothing to opt out of.
Who else processes anything
The complete list of third parties that can see anything about you:
- Our hosting provider, which serves the pages and keeps the request logs described above.
- Our email provider, if and only if you subscribe to the newsletter or use the contact form. They process the address on our instructions and do not use it for anything else.
Both are data processors acting under contract. There is no third party in the list that exists to observe readers, because we have not added one.
Market data
Prices in the ticker are fetched by our server on a five-minute cycle and rendered into the page before it reaches you. Your browser never contacts the data providers, so they never see your address or that you visited.
Links to other sites
Merxtio links out, including to commercial partners. Once you follow a link you are on someone else’s site under their policy, not ours.
Affiliate links may carry a parameter identifying Merxtio as the referrer so a commission can be attributed. We are not told who followed the link, and the attribution mechanism runs on the merchant’s own domain — how that works is set out in full on the partners page.
Children
Merxtio is written for adults and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has sent us their details, tell us and we will delete them.
International transfers
The site is served from a global content network, so pages may be delivered from a server near you regardless of where you are. Where a processor moves personal data outside the EEA or the UK, they do so under the safeguards their own terms provide — standard contractual clauses or an adequacy decision.
Your rights
Under the GDPR in the EU and UK, and comparable state laws in the US including the CCPA and CPRA, you can ask what we hold about you, ask for it to be corrected, ask for it to be deleted, ask for a copy in a portable format, or object to processing.
Given everything above, the answer is usually “an email thread” or “a newsletter subscription”. Write to hello@merxtio.com and we will action it. We aim to respond within a few days and are required to within one month.
If you are in the EEA or UK and are not satisfied with how we handled a request, you can complain to your national data protection authority. In the UK that is the Information Commissioner’s Office.
Security
The site is served over HTTPS with HSTS. There are no accounts and therefore no passwords to protect. Form submissions are rate-limited and validated on the server. We do not store payment details because we do not take payments.
If this changes
If the site starts collecting something it does not collect today — analytics, an ad network, comments — this page changes first. There is no version of that where the policy lags the behavior. Material changes will be dated here rather than made silently.