Privacy Policy
This page says what data reaches us when you read The iBulletin, why we hold it, who else sees it, and how to delete it. The site is ad-supported, which is why most of what follows exists: editorial work needs almost nothing about you, advertising technology a great deal. Last updated: August 2026.
What we collect, and what we do not
Nothing about you is needed to read a bulletin. No reader accounts, no comment logins, no registration wall, no meter counting your articles. If you have never emailed us or subscribed to the email bulletin, we do not know who you are.
What arrives is the ordinary technical exhaust of a website, plus whatever you send us. Most advertising data is collected by other companies through tags on the page, so it is listed beside ours.
- Analytics. Which bulletins are opened, the page you came from, approximate location from your IP address, your device and browser.
- Server and delivery logs. IP address, user agent, timestamp, file requested. This is what tells us we are being scraped.
- Email bulletin. Your address, when you confirmed it, and delivery events such as bounces and opens.
- Anything you email us. Tips, corrections, complaints, advertising enquiries and the rest of the message.
- Advertising identifiers. Cookies and identifiers set by our ad server and the programmatic exchanges, for capping, measurement, fraud checks and personalisation where you consented.
Why we use it, and on what basis
The purposes are short to state. Get the site to your screen. See which bulletins are read. Send the email bulletin to people who asked for it. Sell advertising and get paid correctly. No reader profiles are built for our own use, and we have never sold or rented the list.
Where the law asks for a legal basis, ours are these. Consent for advertising storage, analytics storage and the email bulletin. Legitimate interest for security logging, aggregate measurement and defending the site against abuse. Contract for advertiser dealings, and legal obligation where a record must be kept for tax or a claim. Behavioural advertising gets no legitimate-interest claim from us: it runs on consent or not at all, and a refusal means non-personalised advertising, which pays us less. That is the trade and we are not going to dress it up.
Who else touches it, and where it goes
Five kinds of company see some of it: our hosting and delivery provider, our analytics provider, our email provider, our ad server, and the programmatic exchanges that fill inventory we have not sold directly. All are contracted to use it for our purpose only, apart from the exchanges, which also act on their own account. The rules a partner accepts first are on our advertising page.
We name categories rather than brands, because the exchange list changes and a stale list is worse than an honest description. Ask with PRIVACY in the subject and we will say who is live that week. The limit is downstream: once a bid request leaves the page we cannot follow the data, so we can drop a partner but not audit one. Several are established outside the UK and the EU, mostly in the United States, so data moves under the standard contractual clauses, the UK addendum, or an adequacy decision.
Cookies, tags and the consent signal
What gets set in your browser, by whom and for how long is itemised in our cookie policy. Strictly necessary storage is set either way. Analytics and advertising storage waits for your answer in the consent manager, reachable from the cookie settings link in the footer of every page, and you can change it whenever you like.
We honour the Global Privacy Control signal where a browser sends one, and treat it as an opt out of sale and sharing where a law recognises it. Refusing everything locks you out of nothing, because a banner that punishes a no is not really asking.
How long we keep things
Old reader data is a liability rather than an asset, so retention is short and dull. Where a provider’s setting decides the window, we take the shortest available.
Where an investigation, a legal claim or a regulator requires it, one record may be held longer, then deleted. Otherwise these are the periods we work to.
- Server and delivery logs: a rolling 30 days, longer only for a security investigation.
- Analytics: event-level data for no more than 14 months. Aggregate reports we keep.
- Email bulletin: until you unsubscribe, then your address alone as a suppression record.
- Correspondence: while the matter is open, then archived up to two years. Correction mail stays with the story’s record.
- Advertising identifiers: the partner’s lifespans, listed in the cookie policy. Clearing browser storage removes them.
If you are in the UK or the EU
These rights are law rather than a courtesy, and using one costs nothing. Email support@theibulletin.com with PRIVACY at the front of the subject line. We will ask for enough to find your record and will not demand identity documents. You get a reply within one month, and we say so inside the month if something needs longer.
One honest limitation. We can delete you from our systems and stop our own processing. We cannot delete an identifier an exchange holds, because we never held it. For that, withdraw advertising consent, then use the industry opt outs listed in the cookie policy. The rights themselves:
- Access: a copy of what we hold about you.
- Rectification: correction of anything wrong.
- Erasure: deletion, unless we have an overriding reason to keep it.
- Restriction: a pause while a dispute is settled.
- Portability: what you gave us, in a machine-readable file.
- Objection: to anything run on legitimate interest, and absolutely to direct marketing.
- Withdrawal of consent, at any point, without a reason.
- A complaint to your data protection authority, before or after coming to us.
If you are in California
California gives you the same core set: to know what is collected and where it goes, to have it corrected, to have it deleted, to opt out of the sale or sharing of personal information, to limit the use of sensitive personal information, and not to be treated worse for asking. We do not intentionally collect sensitive personal information.
We do not sell personal information for money and never have. Passing an identifier to an exchange so it can choose a personalised advertisement counts as sharing for cross-context behavioural advertising, so we treat it as sharing. Use the Do Not Sell or Share My Personal Information link in the footer, or switch advertising off in the consent manager, which does the same job. An authorised agent may act for you with written permission, and nobody gets a worse site for opting out.
Children
The iBulletin is written for adults and is not directed at children. We publish no children’s content, do not knowingly collect anything from a child under 13, and do not let a buyer treat our inventory as child-directed.
You must be at least 16 to subscribe to the email bulletin or send us material, which is our rule rather than the legal floor everywhere. If a parent or guardian tells us we hold a child’s data, we delete it and confirm that in writing.
Changes, and who answers
The date at the top moves when the text moves. A material change, meaning a new category of data, a new purpose or a new kind of partner, gets a short note saying what changed, and subscribers get a line about it in an email bulletin. Where a change needs your consent we ask again through the consent manager.
Privacy requests and questions about this page go to support@theibulletin.com with PRIVACY in the subject. One address, read and triaged by our editors, and our contact page explains the labelling. If this page describes something other than what happens on the site, tell us, and we will fix the page or fix the site.