Privacy Policy

Effective Date: May 10, 2026
Last Updated: June 10, 2026

This Privacy Policy describes how securesql.info (“this site,” “I,” “me”) collects, uses, retains, and protects information when you visit https://www.securesql.info. This site is operated by John Menerick, a sole practitioner based in Castro Valley, California, USA.


1. Information Collected

1a. Information Collected Automatically

When you visit this site, the following data is collected automatically by infrastructure and analytics services:

Data Type Source Purpose
IP address Cloudflare CDN DDoS mitigation, security, CDN routing
Browser type and version Cloudflare / Google Analytics Compatibility reporting
Operating system Google Analytics Audience reporting
Pages visited and time on page Google Analytics Content performance
Referral source (how you arrived) Google Analytics Traffic analysis
Approximate geographic location (city/country level) Google Analytics Audience reporting
Device type (desktop/mobile/tablet) Google Analytics Responsive design testing

No precise location data, no persistent user identifiers, and no behavioral profiles are created or stored by this site directly.

1b. Information You Provide Voluntarily

  • Booking requests: If you use the Calendly scheduling link on this site, you submit your name, email address, and any notes directly to Calendly, Inc. That data is governed by Calendly’s Privacy Policy, not this one.
  • Email contact: If you email [email protected], your email address and message content are received and stored in the email provider’s systems. This information is used only to respond to your inquiry.

1c. What Is Not Collected

  • No account registrations or passwords
  • No payment information
  • No health or financial data
  • No persistent tracking cookies set by this site directly (third-party services may set their own — see Section 3)

For visitors in the European Economic Area (EEA), United Kingdom, or Switzerland, data is processed under the following legal bases:

Processing Activity Legal Basis
Analytics (Google Analytics) Legitimate interest (understanding site performance) — you may opt out at any time (see Section 6)
Security and CDN (Cloudflare) Legitimate interest (protecting the site and its visitors from malicious traffic)
Email correspondence Legitimate interest (responding to direct inquiries you initiate)
Booking via Calendly Contractual necessity (facilitating a meeting you request)

3. Third-Party Services

This site uses the following third-party processors. Each operates under its own privacy policy:

Service Purpose Privacy Policy
Cloudflare CDN, DDoS protection, DNS cloudflare.com/privacypolicy
Google Analytics Visitor analytics policies.google.com/privacy
Google Fonts Typography policies.google.com/privacy
Calendly Meeting scheduling calendly.com/privacy
GitHub Pages Site hosting docs.github.com/site-policy

Google Analytics is configured with IP anonymization enabled. No raw IP addresses are transmitted to Google.


4. Cookies

This site does not set first-party cookies for tracking or advertising.

Third-party services loaded on this site (Google Analytics, Google Fonts, Cloudflare) may set their own cookies or use similar storage mechanisms. You can manage or block these using your browser’s cookie controls or a browser extension such as uBlock Origin.

To opt out of Google Analytics across all sites: tools.google.com/dlpage/gaoptout.


5. Data Retention

Data Category Retention Period
Google Analytics session and event data 14 months (configured at the property level)
Cloudflare access logs Up to 7 days per Cloudflare’s default log retention
Email correspondence Retained for the duration of the business relationship, then deleted within 12 months of last contact
Calendly booking data Per Calendly’s retention policy (typically 2 years)

This site does not maintain its own server-side database of visitor records.


6. Your Rights

For EU/EEA/UK Residents (GDPR)

You have the following rights regarding your personal data:

  • Right of access — Request a copy of any personal data held about you.
  • Right to rectification — Request correction of inaccurate data.
  • Right to erasure (“right to be forgotten”) — Request deletion of your personal data where no overriding legal basis exists for its retention.
  • Right to restriction — Request that processing be limited while a dispute is resolved.
  • Right to data portability — Request your data in a structured, machine-readable format.
  • Right to object — Object to processing based on legitimate interests.
  • Right to withdraw consent — Where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, contact: [email protected]. Requests will be acknowledged within 72 hours and fulfilled within 30 days. If you are unsatisfied with the response, you have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or your EU member state’s data protection authority).

For California Residents (CCPA / CPRA)

Under the California Consumer Privacy Act and California Privacy Rights Act, California residents have the right to:

  • Know what personal information is collected, used, shared, or sold.
  • Delete personal information collected from you (subject to certain exceptions).
  • Correct inaccurate personal information.
  • Opt out of sale or sharing of personal information — this site does not sell or share personal information for cross-context behavioral advertising.
  • Limit use of sensitive personal information — this site does not collect sensitive personal information as defined by CPRA.
  • Non-discrimination — exercising your privacy rights will not result in different service or treatment.

To submit a CCPA/CPRA request, contact: [email protected]. Requests are fulfilled within 45 days, with a single 45-day extension available if reasonably necessary.


7. Data Security

This site is operated by a CISSP-certified security engineer and takes the following measures to protect data in transit and at rest:

  • HTTPS enforced on all connections via Cloudflare TLS
  • HTTP Strict Transport Security (HSTS) header active
  • Static site architecture (Jekyll/GitHub Pages) — no server-side database reduces attack surface significantly
  • Cloudflare Web Application Firewall active
  • No administrative credentials stored in the site codebase

No method of internet transmission is 100% secure. If you have a security concern about this site, please follow the responsible disclosure process outlined at https://www.securesql.info/Security.md.


8. Breach Notification

In the event of a data breach affecting personal information collected or processed in connection with this site, affected individuals will be notified:

  • EU/EEA residents: Within 72 hours of becoming aware of the breach, per GDPR Article 33/34 requirements, where the breach is likely to result in a risk to rights and freedoms.
  • California residents: In the most expedient time possible, consistent with California Civil Code § 1798.82.
  • All other affected individuals: Within a reasonable timeframe, with notification via email (where an email address is on file) or prominent site notice.

Notification will include: the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed.


9. Children’s Privacy

This site is not directed at children under 13 (or under 16 for EEA residents). No personal information is knowingly collected from children. If you believe a child has submitted personal information through this site, contact [email protected] for immediate deletion.


10. International Transfers

This site is hosted on infrastructure that may process data in the United States and other countries. Cloudflare and Google operate globally. For EEA/UK visitors, data transferred to the US is subject to Standard Contractual Clauses (SCCs) or other transfer mechanisms maintained by those processors.


11. Changes to This Policy

Material changes to this policy will be noted with an updated “Last Updated” date at the top of this page. Continued use of the site after a policy update constitutes acceptance of the revised terms. For significant changes, a notice may be posted on the homepage.


12. Contact

Data controller: John Menerick
Location: Castro Valley, California, USA
Email: [email protected]
Response time: Within 72 hours for privacy-related requests

For EEA residents who are unsatisfied with a response, supervisory authority contact information is available at edpb.europa.eu.