Privacy Policy
Effective Date: May 10, 2026
Last Updated: June 10, 2026
This Privacy Policy describes how securesql.info (“this site,” “I,” “me”) collects, uses, retains, and protects information when you visit https://www.securesql.info. This site is operated by John Menerick, a sole practitioner based in Castro Valley, California, USA.
1. Information Collected
1a. Information Collected Automatically
When you visit this site, the following data is collected automatically by infrastructure and analytics services:
| Data Type | Source | Purpose |
|---|---|---|
| IP address | Cloudflare CDN | DDoS mitigation, security, CDN routing |
| Browser type and version | Cloudflare / Google Analytics | Compatibility reporting |
| Operating system | Google Analytics | Audience reporting |
| Pages visited and time on page | Google Analytics | Content performance |
| Referral source (how you arrived) | Google Analytics | Traffic analysis |
| Approximate geographic location (city/country level) | Google Analytics | Audience reporting |
| Device type (desktop/mobile/tablet) | Google Analytics | Responsive design testing |
No precise location data, no persistent user identifiers, and no behavioral profiles are created or stored by this site directly.
1b. Information You Provide Voluntarily
- Booking requests: If you use the Calendly scheduling link on this site, you submit your name, email address, and any notes directly to Calendly, Inc. That data is governed by Calendly’s Privacy Policy, not this one.
- Email contact: If you email
[email protected], your email address and message content are received and stored in the email provider’s systems. This information is used only to respond to your inquiry.
1c. What Is Not Collected
- No account registrations or passwords
- No payment information
- No health or financial data
- No persistent tracking cookies set by this site directly (third-party services may set their own — see Section 3)
2. Legal Basis for Processing (GDPR)
For visitors in the European Economic Area (EEA), United Kingdom, or Switzerland, data is processed under the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Analytics (Google Analytics) | Legitimate interest (understanding site performance) — you may opt out at any time (see Section 6) |
| Security and CDN (Cloudflare) | Legitimate interest (protecting the site and its visitors from malicious traffic) |
| Email correspondence | Legitimate interest (responding to direct inquiries you initiate) |
| Booking via Calendly | Contractual necessity (facilitating a meeting you request) |
3. Third-Party Services
This site uses the following third-party processors. Each operates under its own privacy policy:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Cloudflare | CDN, DDoS protection, DNS | cloudflare.com/privacypolicy |
| Google Analytics | Visitor analytics | policies.google.com/privacy |
| Google Fonts | Typography | policies.google.com/privacy |
| Calendly | Meeting scheduling | calendly.com/privacy |
| GitHub Pages | Site hosting | docs.github.com/site-policy |
Google Analytics is configured with IP anonymization enabled. No raw IP addresses are transmitted to Google.
4. Cookies
This site does not set first-party cookies for tracking or advertising.
Third-party services loaded on this site (Google Analytics, Google Fonts, Cloudflare) may set their own cookies or use similar storage mechanisms. You can manage or block these using your browser’s cookie controls or a browser extension such as uBlock Origin.
To opt out of Google Analytics across all sites: tools.google.com/dlpage/gaoptout.
5. Data Retention
| Data Category | Retention Period |
|---|---|
| Google Analytics session and event data | 14 months (configured at the property level) |
| Cloudflare access logs | Up to 7 days per Cloudflare’s default log retention |
| Email correspondence | Retained for the duration of the business relationship, then deleted within 12 months of last contact |
| Calendly booking data | Per Calendly’s retention policy (typically 2 years) |
This site does not maintain its own server-side database of visitor records.
6. Your Rights
For EU/EEA/UK Residents (GDPR)
You have the following rights regarding your personal data:
- Right of access — Request a copy of any personal data held about you.
- Right to rectification — Request correction of inaccurate data.
- Right to erasure (“right to be forgotten”) — Request deletion of your personal data where no overriding legal basis exists for its retention.
- Right to restriction — Request that processing be limited while a dispute is resolved.
- Right to data portability — Request your data in a structured, machine-readable format.
- Right to object — Object to processing based on legitimate interests.
- Right to withdraw consent — Where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these rights, contact: [email protected]. Requests will be acknowledged within 72 hours and fulfilled within 30 days. If you are unsatisfied with the response, you have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or your EU member state’s data protection authority).
For California Residents (CCPA / CPRA)
Under the California Consumer Privacy Act and California Privacy Rights Act, California residents have the right to:
- Know what personal information is collected, used, shared, or sold.
- Delete personal information collected from you (subject to certain exceptions).
- Correct inaccurate personal information.
- Opt out of sale or sharing of personal information — this site does not sell or share personal information for cross-context behavioral advertising.
- Limit use of sensitive personal information — this site does not collect sensitive personal information as defined by CPRA.
- Non-discrimination — exercising your privacy rights will not result in different service or treatment.
To submit a CCPA/CPRA request, contact: [email protected]. Requests are fulfilled within 45 days, with a single 45-day extension available if reasonably necessary.
7. Data Security
This site is operated by a CISSP-certified security engineer and takes the following measures to protect data in transit and at rest:
- HTTPS enforced on all connections via Cloudflare TLS
- HTTP Strict Transport Security (HSTS) header active
- Static site architecture (Jekyll/GitHub Pages) — no server-side database reduces attack surface significantly
- Cloudflare Web Application Firewall active
- No administrative credentials stored in the site codebase
No method of internet transmission is 100% secure. If you have a security concern about this site, please follow the responsible disclosure process outlined at https://www.securesql.info/Security.md.
8. Breach Notification
In the event of a data breach affecting personal information collected or processed in connection with this site, affected individuals will be notified:
- EU/EEA residents: Within 72 hours of becoming aware of the breach, per GDPR Article 33/34 requirements, where the breach is likely to result in a risk to rights and freedoms.
- California residents: In the most expedient time possible, consistent with California Civil Code § 1798.82.
- All other affected individuals: Within a reasonable timeframe, with notification via email (where an email address is on file) or prominent site notice.
Notification will include: the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed.
9. Children’s Privacy
This site is not directed at children under 13 (or under 16 for EEA residents). No personal information is knowingly collected from children. If you believe a child has submitted personal information through this site, contact [email protected] for immediate deletion.
10. International Transfers
This site is hosted on infrastructure that may process data in the United States and other countries. Cloudflare and Google operate globally. For EEA/UK visitors, data transferred to the US is subject to Standard Contractual Clauses (SCCs) or other transfer mechanisms maintained by those processors.
11. Changes to This Policy
Material changes to this policy will be noted with an updated “Last Updated” date at the top of this page. Continued use of the site after a policy update constitutes acceptance of the revised terms. For significant changes, a notice may be posted on the homepage.
12. Contact
Data controller: John Menerick
Location: Castro Valley, California, USA
Email: [email protected]
Response time: Within 72 hours for privacy-related requests
For EEA residents who are unsatisfied with a response, supervisory authority contact information is available at edpb.europa.eu.