Skip to main content

This site complies with: GDPR (EU), CCPA/CPRA (California), PIPEDA (Canada), Quebec Law 25, Colorado Privacy Act, UK GDPR, and WCAG 2.2 Level AA accessibility standards.

Privacy & Cookie Policy

Last Updated: November 11, 2025 | Privacy Policy Version 1.0

Consent Version 2.7 (Current)

Data Controller

Entity: ColePreece.com

Operated By: Cole Preece (United States)

Contact Email: coal_thrill_0p@icloud.com

Information We Collect

The following information may be collected when you use our contact forms:

  • Name (first and last)
  • Email address
  • Mailing address (optional)
  • Birthday month and day (optional, year intentionally not collected)
  • IP address (for security)
  • User agent/browser information (for security)
  • Optional message content
  • Company and role (optional, Get in Touch form only)

Legal Basis for Processing

  • Consent: Consent for marketing communications (Stay in Touch form)
  • Legitimate Interest: Legitimate interest for responding to inquiries (Get in Touch form)

Purpose of Collection

We collect and process your information for the following purposes:

  • Direct mail and email list management
  • Birthday reminders (automated emails 2 weeks before birthdays)
  • Responding to inquiries and contact requests
  • Sending holiday cards (if consent provided)
  • Site security and abuse prevention

Data Retention

  • Stay in Touch submissions: Until deletion requested or 5 years of inactivity
  • Get in Touch submissions: 2 years from last contact

Third-Party Processors

We use the following trusted service providers to process your data:

Upstash/AWS

Purpose: Encrypted database storage (AES-256-GCM)

Location: US/EU data centers

Vercel

Purpose: Website hosting and edge computing

Location: Global CDN

Resend

Purpose: Email delivery service

Location: US/EU

Google reCAPTCHA

Purpose: Bot protection and spam prevention

Location: US

International Data Transfers

Your data may be processed and stored in the United States and European Union through our service providers (Upstash/AWS, Vercel, Resend). All transfers comply with applicable data protection laws, including GDPR adequacy decisions and Standard Contractual Clauses where applicable.

Your Rights

GDPR Rights (EU/UK/EEA)

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to data portability (Article 20)
  • Right to object (Article 21)
  • Right to withdraw consent (Article 7(3))

CCPA/CPRA Rights (California)

  • Right to know what personal information is collected
  • Right to know if personal information is sold or shared
  • Right to opt-out of sale or sharing
  • Right to deletion
  • Right to non-discrimination

To exercise your rights: Contact us at coal_thrill_0p@icloud.com or use our Privacy Center for self-service access.

🌍 Your Privacy Center

World-Class Data Control & Transparency

✓ Built to comply with the world's most robust privacy laws:

🇪🇺 GDPR (Europe)🇬🇧 UK GDPR🇨🇭 Swiss Privacy Law🇨🇦 PIPEDA (Canada)🇨🇦 Quebec Law 25🇺🇸 CCPA/CPRA (California)🇺🇸 CPA (Colorado)🤖 EU AI Act

What You Can Do in the Privacy Center:

👁️

View Your Data

See everything we've stored about you - complete transparency into all personal information, submission details, and technical metadata

📥

Download Your Information

Export in JSON or CSV format - data portability guaranteed under GDPR and CCPA

✏️

Update Information

Change your email, address, birthday, or message anytime - keep your information accurate

🎛️

Manage Consent Preferences

4 granular toggles: email updates, birthday emails, holiday/birthday cards, and article announcements

🔕

Unsubscribe Instantly

One-click unsubscribe from all communications - no email required

🗑️

Delete Your Data

Request permanent deletion with 30-day recovery period - full GDPR "Right to be Forgotten" compliance

How to Access Your Privacy Center:

  1. 1.Visit colepreece.com/privacy-center
  2. 2.Enter your email address
  3. 3.Click the secure magic link sent to your inbox (expires in 15 minutes)
  4. 4.Manage your preferences in the dashboard

🔒 Secure Authentication

We use magic link authentication with 15-minute expiring tokens to ensure only you can access your data. No passwords are required or stored. Each access link can only be used once and expires automatically for your protection.

Right to Lodge a Complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection authority:

Automated Decision-Making

None. We do not use automated decision-making or profiling that produces legal effects or significantly affects you.

Security Measures

We implement the following security measures to protect your data:

  • TLS 1.3 encryption in transit
  • AES-256-GCM encryption at rest
  • Rate limiting (5 submissions per hour per IP)
  • Google reCAPTCHA v2 bot protection
  • Input sanitization and XSS prevention
  • OWASP Top 10 compliance
  • ISO 27001-compliant hosting

Cookie Usage

This site uses the following cookies:

Cookie NamePurposeDurationCategory
cookie-consentStores your cookie preferences12 monthsStrictly Necessary
dark-modeRemembers your dark mode preferencePersistentFunctional
_ga, _ga_*Google Analytics tracking (only with consent)2 yearsAnalytics(Requires consent)

California & Colorado Data Privacy Rights

California & Colorado Data Privacy Rights: ColePreece.com does not sell or share personal information. This site does not require a 'Do Not Sell or Share My Personal Information' link because it is expressly stated that your data will never be sold or shared with third parties.

CASL Compliance (Canada)

For Canadian users (CASL): All marketing communications require express consent. You can unsubscribe at any time using the link provided in emails or by contacting us directly.

PIPEDA Compliance (Canada)

Privacy Officer: Cole Preece (coal_thrill_0p@icloud.com)

Retention Schedule: Personal information is retained only as long as necessary for the purposes outlined in this policy, or as required by law.

ColePreece.com is owned and operated by Cole Preece (United States).

Quebec Law 25 Compliance

Profiling Technology: This site does not use automated profiling technology. Any future use of such technology will require explicit opt-in consent.

Granular Consent: Consent is requested separately for each purpose (email updates, birthday cards, holiday cards, article announcements).

AI Act Compliance

If AI tools are used for content recommendations or analysis, users will be notified. Data is never used for AI model training without separate explicit consent. All decisions involve human review.

Children's Privacy

This site is not intended for use by persons under 16 years of age. We do not knowingly collect personal information from children.

Changes to This Policy

Material changes to this privacy policy will result in email notification to all registered users. The 'Last Updated' date at the top of this page reflects the most recent revision.

Contact Us

For questions about this privacy policy or to exercise your data protection rights, please contact:

Email: coal_thrill_0p@icloud.com

You can also use our Privacy Center to access, download, update, or delete your personal information.