Privacy policy
What personal data Geist Labs collects, why, how long it is kept, who it is shared with, and the rights you have over it.
- Effective
- Last updated
This policy explains how Geist Labs handles personal data across geistlabs.dev, our email list, our digital products, and our workshops. It is written to meet the requirements of the EU and UK General Data Protection Regulation and of US state privacy laws including the California Consumer Privacy Act as amended.
Where we act as a processor on a client's behalf during an engagement, the Data processing addendum governs instead of this policy.
01
The short version
- We collect the minimum we need: what you type into the contact form, what you give us to join the email list, and what is needed to fulfil a purchase.
- We use Google Analytics to count readers, and that is the only tracking on this site — and it only runs if you accept it. No advertising pixels, no Meta or LinkedIn tags, no session recording, no cross-site tracking, no data brokers.
- We do not sell or share personal data, and we never have.
- Marketing email is opt-in, asked for separately from anything you download, and one click to leave.
- You can ask us for a copy of your data or ask us to delete it, wherever you live.
02
Who is responsible for your data
Geist Labs is the controller of the personal data described in this policy. Geist Labs is a trading name of Brandon W. Lee, a sole proprietor established in North Carolina, United States; the full identity and postal address are in the Legal notice. Data protection enquiries go to contact@geistlabs.dev, marked for the attention of privacy, or through the contact form. They reach the person who decides, because there is only one.
Data Protection Officer. We have not appointed one. The Article 37 criteria do not apply to us: our core activity is publishing and training, not large-scale monitoring, and we process no special category data at scale.
EU and UK representative. We have no establishment in the EEA or the UK, and we have not appointed an Article 27 representative. We rely on the derogation in Article 27(2)(a): our processing of EEA and UK personal data is occasional, does not include special category data or criminal conviction data, and is unlikely to result in a risk to your rights and freedoms. That is a position we hold today at our current volume, not a permanent one — if regular sales into the EEA or the UK make the processing anything other than occasional, we will appoint a representative and name them here before that happens.
03
What we collect, and why
| Data | Where it comes from | Why we use it | Legal basis (GDPR) | Kept for |
|---|---|---|---|---|
| Name, email address, team size, message | The contact form | To read and answer your enquiry, and to follow up about a workshop you asked about | Art. 6(1)(b) steps prior to a contract, and Art. 6(1)(f) legitimate interest in answering enquiries | 24 months from the last message |
| Email address, and any name you give | Signing up to the email list or requesting a free resource | To deliver the resource, and to send the newsletter if you asked for it | Art. 6(1)(a) consent for marketing; Art. 6(1)(b) to deliver a resource you requested | Until you unsubscribe, then a suppression record only |
| Email open and click events | Our email provider | To see whether the newsletter is worth writing, and to stop sending to dead addresses | Art. 6(1)(a) consent | 24 months |
| Name, billing email, billing country, purchase history, tax status | Checkout | To take payment, deliver the product, meet tax obligations, and handle refunds | Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation for tax and accounting records | 7 years for financial records, as tax law requires |
| Payment card details | You, entered directly with Stripe at checkout | To take payment | Art. 6(1)(b) contract | Never received or stored by us |
| Attendee names, work email, role, and the material you bring to a session | You or your employer, when booking a workshop | To run the session and to issue materials | Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interest in delivering to the booking organisation | 24 months after the engagement ends |
| IP address, request metadata, and server logs | Automatically, when you load a page | Security, abuse prevention, and diagnosing faults | Art. 6(1)(f) legitimate interest in keeping the service secure and working | 30 days |
| Analytics events: pages viewed, referring site, approximate city-level location, device, browser, and a randomly generated Google Analytics identifier | Automatically, through Google Analytics, when you load a page | To see which articles are read and how people find them | Art. 6(1)(a) consent for the cookies and similar storage; Art. 6(1)(f) legitimate interest in understanding readership for the resulting analysis | 2 months for the identifier, then aggregated |
We do not collect special category data, we do not ask for it, and you should not send it to us through the contact form.
Two rows of that table describe processing that is not running yet: the newsletter and the paid product checkout are not live at the date of this policy. They are documented here because the rules that will govern them are settled now, not written after the fact — but until you see a subscribe form or a buy button on this site, no email-list or purchase data exists.
04
Cookies and tracking
This site uses Google Analytics 4 and nothing else. There are no advertising pixels, no Meta or LinkedIn tags, no session recording, no heatmaps, no A/B testing tools, and no cross-site tracking.
| Storage | Set by | Purpose | Lifetime |
|---|---|---|---|
_ga | Google Analytics | Distinguishes one browser from another so a repeat visit is not counted as a new reader | 2 years |
_ga_<container> | Google Analytics | Holds the analytics session state | 2 years |
| Strictly necessary storage | This site | Serves pages and keeps the contact form working | Session |
The strictly necessary storage is exempt from the consent requirement under Article 5(3) of the ePrivacy Directive. The Google Analytics cookies are not exempt. They require your prior consent in the EEA and the UK, and they require the ability to opt out under US state privacy law.
Where we currently stand, stated plainly: the consent banner is live, and analytics is off until you turn it on. The Google Analytics script is not requested, not loaded, and sets no cookies unless you choose Accept analytics — this is the script itself being withheld, not a consent signal sent to a tag that has already loaded. The two buttons are identical in size, colour, and prominence, and each is a single click; there is no pre-ticked box, no delay on the reject button, and no version of "reject" that means "ask me again on the next page". Your choice is stored in your browser's local storage under geist-analytics-consent and is never sent to us or to anyone else.
You can change it at any time through Cookie settings in the site footer, on every page. Withdrawing consent deletes the _ga cookies and reloads the page without analytics, so the withdrawal takes effect immediately rather than at your next visit. Clearing your browser storage clears the choice, and you will simply be asked again.
Three further things are true and worth knowing:
- Google Analytics 4 does not log or store IP addresses. Your IP is used in transit to derive an approximate, city-level location and is then discarded.
- We have not enabled Google Signals, ads personalisation, or any advertising integration on the property. The data is not used to build an advertising profile of you, by us or by Google on our behalf, and it is not joined to anything Google knows about you elsewhere.
- Declining, or never answering, has no effect on anything else on the site: nothing is gated behind the banner and no feature degrades. If you would rather not rely on us at all, your browser's cookie settings, any content blocker, or Google's official opt-out add-on will each block it independently.
Google Ireland Limited and Google LLC act as our processor for this under Google's Measurement Controller-Controller Data Protection Terms and its data processing terms. Google LLC is certified under the EU-US Data Privacy Framework.
Some browsers send a Global Privacy Control signal. We honour it as a valid opt-out of sale and sharing, and we act on it as an instruction not to load analytics. If your browser sends the signal, the banner never appears and the analytics script never loads — you are opted out before you are asked, because asking again would be ignoring an answer you have already given. Open Cookie settings and the panel will tell you that is what happened.
05
Who we share data with
We do not sell personal data. We do not share it for cross-context behavioural advertising. We do not disclose it to data brokers.
We use a small number of service providers who process data on our instructions under written terms:
| Provider | What it does | Data involved | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | Hosts the website and holds request logs, and sends transactional email from the contact form via Amazon SES | IP address, request metadata, name, email, message content | United States, us-east-1 |
| Google LLC and Google Ireland Limited | Runs Google Analytics | Analytics events and the analytics identifier described above | United States and Ireland |
| Stripe | Sells digital products as merchant of record: takes payment, calculates and remits tax, and handles payment disputes | Billing details, billing country, tax status, purchase history | United States and Ireland, per Stripe's data processing terms |
We do not currently operate a marketing email list, and no email marketing provider holds your data. If we launch a newsletter it will run on Amazon SES alongside the contact form, and this table and the retention table above will be updated before the first send rather than after it.
Stripe is the exception in that table. Because Stripe is the merchant of record for digital product sales rather than a supplier acting on our instructions, it decides for itself what it must do with your billing and tax data to meet its own legal obligations as the seller. For that data Stripe is an independent controller alongside us, not our processor, and Stripe's own privacy policy governs what it does with it. The consequences for you are set out in the Terms of sale.
The current list is maintained here and in the Data processing addendum. We will update it before adding a provider that handles personal data.
We may also disclose data where we are legally required to, to establish or defend legal claims, or to a successor if the business is sold — in which case we will tell you first.
06
International transfers
Geist Labs operates from the United States and uses providers that operate globally. Where personal data of people in the EEA, the UK, or Switzerland is transferred outside those regions, we rely on:
- The European Commission's Standard Contractual Clauses (Decision 2021/914), with the UK International Data Transfer Addendum for UK transfers and the Swiss adaptations where relevant; or
- The EU-US Data Privacy Framework, where the receiving provider is certified under it.
You can ask us for a copy of the relevant safeguards.
07
How long we keep data
Retention periods are set out per data type in the table above. The principle behind them is simple: we keep data for as long as it serves the purpose it was collected for, plus any period that tax, accounting, or limitation law requires. After that it is deleted or irreversibly aggregated.
Unsubscribing leaves a minimal suppression record — usually a hashed email address — so that we do not accidentally email you again. That record exists only to honour your choice.
08
Security
We keep data on reputable managed infrastructure, restrict access to the people who need it, use encryption in transit throughout, and keep the number of systems holding personal data deliberately small. No system is perfectly secure, but the smallest attack surface is the strongest control we have, and we design for it.
If a breach affecting your personal data occurs, we will notify the competent supervisory authority within 72 hours where the GDPR requires it, and notify you directly without undue delay where the risk to you is high.
09
Your rights in the EEA, the UK, and Switzerland
You have the right to:
- Access — get confirmation of whether we hold data about you, and a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have data deleted where there is no overriding reason for us to keep it.
- Restriction — have processing paused while a dispute about accuracy or legitimate interest is resolved.
- Portability — receive data you gave us in a structured, machine-readable format, or have it sent to another controller.
- Object — object to processing based on legitimate interest. You can object to direct marketing at any time, and we will stop, without exception.
- Withdraw consent — at any time, without affecting the lawfulness of what was done before you withdrew it.
To exercise any of these, use the contact form or the privacy inbox. We will respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. We do not charge for this, and we do not treat you differently for asking.
You also have the right to lodge a complaint with your national supervisory authority — the list is maintained by the European Data Protection Board — or with the UK Information Commissioner's Office. We would appreciate the chance to resolve it first.
10
Your rights in the United States
If you live in California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you have the right to know what personal information we have collected, to access a copy of it, to correct it, to delete it, and to opt out of sale, sharing, targeted advertising, and profiling with legal or similarly significant effects.
Two of those are easy to answer here: we do not sell personal information for money, and we do not use it for targeted advertising or for profiling of that kind. We have not enabled Google Signals, ads personalisation, or any advertising integration on our analytics property, which is what would turn analytics into "sharing for cross-context behavioural advertising" under California law. Google acts as our service provider for analytics under Google's data processing terms and is contractually barred from using the data for its own purposes.
If you would rather not be counted at all, the opt-out is the same one described in the cookies section, and it works today.
For the record, in the twelve months before the date of this policy we collected the categories of personal information described in the tables above — identifiers, commercial information, and internet activity in the form of server logs and analytics events — for the business purposes stated there. We disclosed identifiers, commercial information, and internet activity to service providers for those purposes only. We did not sell any category of personal information, and we did not share any category for cross-context behavioural advertising, including the personal information of anyone we know to be under 16.
You may use an authorised agent to make a request; we will ask for proof of their authority. We will not discriminate against you for exercising any right. If we deny a request, you may appeal by replying to our decision, and we will respond within the period your state's law allows.
Requests go through the contact form or the privacy inbox.
11
Marketing email
Marketing email is opt-in. We ask for it separately from anything you download, and consent to marketing is never a condition of receiving a free resource — that separation is required by Article 7(4) GDPR and it is also just how we would want to be treated.
Where consent is confirmed by a double opt-in, you will get an email asking you to confirm before anything else is sent. Every marketing email carries a one-click unsubscribe and our postal address, as CAN-SPAM requires. We honour unsubscribes immediately rather than within the ten days the law allows.
We may still send you transactional messages you cannot opt out of while a relationship is live — a purchase receipt, a download link, a change to these terms, or a scheduling message for a workshop you booked.
12
Children
The site is not directed at anyone under 16, and we do not knowingly collect their personal data. If you believe a child has given us data, tell us and we will delete it.
13
Automated decision-making
We do not make decisions about you by automated means that produce legal or similarly significant effects, and we do not carry out profiling of that kind.
14
Changes to this policy
We may update this policy. The Last updated date at the top always reflects the current version. Where a change is material — a new purpose, a new category of recipient, a new transfer mechanism — we will announce it on the site and, where we have your consent and the change requires it, ask you again.
15
Contact
Privacy questions, requests, and complaints go through the contact form, the privacy inbox in the Legal notice, or the postal address published there.