What the desk collects, why, and how to ask for the data to be removed.
What the desk collects
The desk collects the minimum amount of information needed to operate the editorial site and respond to reader inquiries. The desk does not collect viewer analytics beyond what the editor's hosting infrastructure records for the desk's own use.
Reader emails
Where a reader emails the desk at [email protected], the desk retains the email content for the purpose of replying, plus a short audit trail of the reply. The desk does not share reader emails with third parties.
Operational logs
The editor's hosting infrastructure records HTTP access logs for the desk's own use. Logs are retained for 30 days and then deleted.
Cookies and tracking
The desk does not use third-party tracking cookies. The desk does not use third-party analytics. The desk's hosted pages do not load scripts from third-party advertising or analytics networks.
How to ask for the data to be removed
Readers can ask for the desk to remove the email content and audit trail by replying to the original email or emailing [email protected]. The desk removes the data within 14 days and replies with a removal-confirmation note.
Updates to this policy
The desk updates this privacy policy when the desk's editorial practice changes. Updates are dated and posted on the dispatch stream; readers who have emailed the desk are notified of material changes by email.
Reader depth
Reading the privacy policy against the data the desk actually collects
Three habits the desk follows when reading the privacy policy against the reader data the desk actually collects.
The first habit is to keep the policy short by design. The desk's privacy policy is short enough that a reader can re-read the policy in under two minutes and audit the desk's data-collection practice against the policy itself. The policy is published on /privacy/ and reproduced in summary form in the footer of every page. The desk does not expand the policy into a long-form document unless a reader asks for the expansion.
The second habit is to publish what the desk actually collects. The desk collects reader emails when the reader emails the desk. The desk does not collect viewer analytics beyond what the editor's hosting infrastructure records for the desk's own use. The desk does not use third-party tracking cookies, third-party analytics or scripts from third-party advertising or analytics networks.
The third habit is to keep the data-removal policy short by design. The desk removes reader emails within 14 days of a removal request and replies with a removal-confirmation note. The desk does not require readers to identify themselves to file a removal request. The desk removes the data whether or not the reader provides a reason for the request.
Where the desk diverges from coverage that mirrors trade-press reads is on the data-collection discipline. Trade press will sometimes publish a privacy policy that does not name the third-party data collectors. The desk does not. The desk publishes a list of what the desk actually collects and names each category, and the desk dates every update so a reader can audit the cadence.
The desk also treats the privacy policy as a working document. Rows move up the policy-ladder as sources confirm; rows that fall off the publisher or operator page get removed, not retained as a footnote. The policy is rebuilt from publisher and operator pages only. A row the desk kept for "tracking purposes" is a row the reader cannot verify, so the desk removes rather than retains. This is sometimes the slower choice; it is always the more honest choice.
Editorial cycle: weekday-morning source-scan, weekday-afternoon narrative-edit, weekly patch workshop. Verification timestamps on the dispatch stream.
Editorial working notes
How the desk reads this
A working description of the editorial cadence the desk follows on this route.
The privacy policy is built around the minimum data the desk collects to operate the editorial site. The desk does not collect viewer analytics beyond what the editor's hosting infrastructure records for the desk's own use. The desk does not use third-party tracking cookies, third-party analytics or scripts from third-party advertising or analytics networks.
Reader emails are retained for the purpose of replying. The desk does not share reader emails with third parties; the desk does not use reader emails for marketing; the desk does not subscribe readers to newsletters. Reader emails are deleted within 14 days of a removal request and after 30 days of inactivity on the desk's reply thread.
Operational logs are retained for 30 days and then deleted. The editor's hosting infrastructure records HTTP access logs for the desk's own use. The logs are not used to identify individual readers, and the desk does not tie browsing history to reader inquiries. The desk does not store IP addresses beyond what the hosting infrastructure records in the standard log format.
What the privacy policy does not cover. The privacy policy does not cover third-party websites the desk links to, including the disclosed first-party route operated by gogotofly.com. Readers who follow the disclosed first-party route are subject to the operator's privacy policy, not the desk's. The desk's privacy policy applies only to the desk's own site and the desk's own reply emails.
The privacy policy is reviewed at the end of each calendar month. The review reads the policy against the desk's editorial cycle, the corrections register, and the hosting infrastructure's log retention. Where the review changes a data-collection practice, the policy is updated with the change. Where the policy is consistent with the practice, the policy is left alone; the desk does not edit a working document without cause.
Worked example
How the cycle reads in practice
A worked trace of the editorial cycle on this page.
A worked example of a reader-filed removal request. A reader emails the desk at [email protected] and asks for the desk to delete the reader's email content and audit trail. The desk reads the request within 24 hours on weekdays. The desk deletes the email content and audit trail within 14 days of the request. The desk replies with a removal-confirmation note.
Where the policy covers a worked operational-log deletion. The editor's hosting infrastructure records HTTP access logs for the desk's own use. The logs are not used to identify individual readers; the logs are deleted after 30 days; the logs are not tied to reader inquiries. The desk does not extend the retention period without a legal basis.
Where the policy covers a worked third-party-data policy. The disclosed first-party route operated by gogotofly.com is governed by the operator's privacy policy, not the desk's. Readers who follow the disclosed first-party route are subject to the operator's privacy policy. The desk's privacy policy applies only to the desk's own site.
Where the policy covers a worked sub-processor policy. The desk does not use sub-processors for reader data. The desk's hosting infrastructure is the desk's own infrastructure; the desk does not share reader data with third-party infrastructure providers beyond what the standard email or hosting service provides.
Where the policy covers a worked cross-border policy. The desk is registered in the EU; readers in other regions may be subject to additional local requirements. The desk's editorial cycle reads the desk's hosting infrastructure's log retention; the desk does not transfer reader data outside the desk's own region except where the reader's email provider transfers the email across regions on the reader's behalf.
Editorial practice
How the desk reads this in practice
A working description of the editorial cadence the desk follows on this page.
A worked example of an operational-log deletion. The editor's hosting infrastructure records HTTP access logs for the desk's own use. The logs are not used to identify individual readers; the logs are deleted after 30 days; the logs are not tied to reader inquiries. The deletion is automated; the desk does not manually delete logs.
Where the policy covers a worked sub-processor-policy review. The desk reviews the sub-processor policy at the end of each calendar month. The review reads the sub-processor policy against the desk's editorial cycle, the corrections register, and the hosting infrastructure's log retention. Where the review changes a sub-processor practice, the policy is updated with the change.
Where the policy covers a worked cross-border-policy review. The desk is registered in the EU; readers in other regions may be subject to additional local requirements. The desk's editorial cycle reads the desk's hosting infrastructure's log retention; the desk does not transfer reader data outside the desk's own region except where the reader's email provider transfers the email across regions on the reader's behalf. The cross-border policy is reviewed at the end of each calendar month.
Where the policy covers what the desk retains for accounting. The desk retains reader correspondence for the purpose of replying, plus a short audit trail of the reply. The retention period is 30 days. The data is deleted after that unless the inquiry is part of an ongoing corrections cycle. The accounting practice is documented on /methods/ and reproduced in summary form on /about/.
What the desk will do if the privacy policy is updated. The desk publishes a dated dispatch on the dispatch stream if the policy is updated. The dispatch stream is the audit trail for every change the desk makes to the policy. Readers who follow the dispatch stream can audit the desk's privacy hygiene against the public policy. The cadence is documented on /methods/.
Watch the bracketViewer-supported. Age 18+ where required.