This policy explains what applegreenshop.com collects when you visit, why, who else is involved, and what you can ask us to do about it. It applies to this website only. Once you follow a link to another site, that site’s own policy takes over.
We are a small publisher, not a retailer. We do not sell anything, we take no orders, and we never see or handle payment card details.
What we collect
Information you send us through the contact form
Our contact page runs on the Contact Form 7 plugin. When you submit it we receive whatever you typed into it, normally a name, an email address and a message. Two things happen to that submission. It is emailed to us, and it is also saved as a record in this website’s own database by the Contact Form CFDB7 plugin, which stores form entries inside WordPress so they are not lost if an email bounces.
Please do not put anything sensitive in that form. It is a general enquiry box on a website, not a secure channel. We only need enough to answer you.
Server access logs
Like effectively every website, our web server writes an access log entry for each request. A typical entry records your IP address, the date and time, the page or file requested, the response code, the referring page and your browser’s user agent string. These logs exist for operations and security: diagnosing errors, spotting abusive traffic, and investigating an attack. They are not used for advertising.
Analytics
We run our own first-party analytics rather than an advertising network’s tracker. It records the page address and path you viewed, the referring page, your browser, operating system and device type, your user agent string and browser language, and a coarse location, normally at country level, derived from your IP address. It also records when someone clicks an outbound link to Amazon, including which product link was clicked.
To tell one visit from another, the analytics script generates a random identifier and keeps it in your browser’s local storage, plus a second short-lived identifier in session storage. These are not names, email addresses or account numbers, and we do not try to connect them to a real identity. Clearing your browser’s site data removes them.
Cookies
WordPress and the caching layer that speeds this site up may set cookies, for example to remember that you left a comment, to keep a logged-in session for site staff, or to serve you the right cached version of a page. Amazon sets its own cookies once you follow one of our outbound links, and we neither control nor read those. The full breakdown is in our cookie policy.
What we do not do
- We do not sell or rent personal information.
- We do not run third-party advertising networks or behavioral ad targeting on this site.
- We do not build profiles about individuals, and we do not make automated decisions that produce legal effects.
- We do not ask you to create an account, and we do not process payments.
Why we are allowed to process this (legal bases)
For readers in the UK, the EU and other places with similar law, our legal bases are these. Server logs and security measures rest on our legitimate interest in keeping the site running and defending it against abuse. Analytics rests on our legitimate interest in understanding which pages are useful, kept proportionate by using first-party measurement and not sharing the data with ad networks, and on your consent where local law requires consent for storage on your device. Handling your contact form message rests on your consent, given by choosing to write to us, and on our legitimate interest in replying. Where we rely on consent, you can withdraw it at any time by writing to us.
How long we keep things
We would rather be accurate than reassuring here. Contact form entries stay in the site database until we remove them. We clear old entries periodically and we will delete yours on request, but this site does not run an automatic purge on a fixed timetable, so we are not going to promise a number of days we cannot enforce. Server access logs are rotated and overwritten by the server on its own schedule, generally within weeks rather than years. Analytics records are kept in aggregate for as long as they remain useful for understanding traffic. Email correspondence sits in a mailbox until it is deleted.
Who else is involved
Our hosting provider operates the server this site runs on and therefore processes everything that reaches it, including the logs described above. Email providers carry messages between you and us. Amazon receives your click when you follow an outbound product link and applies its own privacy policy from that point on. A network and security layer may sit in front of the site to filter malicious traffic. We do not pass your contact form message to anyone else, and no part of this site feeds an advertising exchange.
These providers may be located outside your country, including in the United States. Where personal data moves across borders, it does so under the safeguards those providers offer in their own terms.
Children
This site is written for adults buying household electronics and appliances. It is not directed at children, and we do not knowingly collect personal information from anyone under 13, or under 16 where local law sets that threshold. If you believe a child has sent us information through the contact form, write to us and we will delete it.
Your rights under GDPR
If the UK GDPR or EU GDPR applies to you, you have the right to ask for a copy of the personal data we hold about you, to have inaccurate data corrected, to have data erased, to restrict or object to processing (including objecting to analytics carried out under legitimate interests), to receive data you gave us in a portable format, and to withdraw consent. You also have the right to complain to your national data protection authority.
Your rights under CCPA and CPRA
If you are a California resident, you have the right to know what categories of personal information we have collected and why, to request deletion of that information, to request correction, and not to be discriminated against for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioral advertising, as those terms are defined in California law, so there is no opt-out link to offer. The categories we collect are identifiers such as an IP address, internet activity such as pages viewed and links clicked, and whatever you voluntarily type into the contact form.
How to make a request
Email [email protected] and say what you want us to do. Tell us enough to find the record, such as the email address you used in the contact form and roughly when you wrote. We will respond within a reasonable period and within the time limits set by applicable law.
One honest limitation: most of what this site records is not tied to a name. If all that exists is a line in a server log or an anonymous analytics record, we may have no way to prove which entries are yours, and we will not go hunting through logs on a guess. We will tell you plainly if that is the situation rather than pretending to act on it.
Security
We keep the site software patched, restrict administrative access, and serve the site over an encrypted connection. No website can promise perfect security, and we are not going to claim it. If we become aware of a breach affecting personal data, we will act on it and notify people where the law requires.
Changes
We may update this policy as the site changes. The version published here is the one that applies. Continuing to use the site after an update means the revised policy governs your use of it.
Questions about anything above: [email protected].