Privacy
This page describes the limited data clarin.info processes. It is an explanation from the site operator, not legal advice.
Who operates this site
clarin.info is an independent domain name offered for acquisition. It is not a news service and it is not affiliated with any newspaper. Questions about this notice can be sent to clarin@clarin.info.
What the public pages do
The public site describes the domain and accepts acquisition offers. It does not ask you to create an account, and it does not set a tracking cookie.
First-party measurements
The site keeps its own request statistics so the operator can see whether people and crawlers actually arrive. The measurement runs on this server. There is no third-party analytics service and no advertising tracker.
A small script, /assets/js/track.js, sends the page path, the referring address, and the page status to /collect.php. If the browser sends a Do Not Track signal of 1, that script does not run. The server may still record the request in its access log, because the web server already received it.
The access log is read on a schedule so requests that never run the script are still visible. Those include many bots and requests for old addresses. A page that both runs the script and appears in the log is stored once.
What is stored
- The time of the request, in UTC.
- The path only. Query strings are removed, so values such as tokens or addresses in the URL are not copied into the analytics database.
- The response status, such as 200 or 404.
- The referring domain, when one was sent. Search-engine hosts are labeled. The rest of the referring URL is not kept.
- A coarse device class and browser family, taken from the user-agent string. The full user-agent string is not stored.
- A daily visitor estimate: a salted hash of a truncated network prefix and the user-agent string. IPv4 is reduced to a /24 prefix and IPv6 to a /48 prefix before hashing. The salt changes each UTC day and is discarded after the raw records are. The full IP address is not stored.
- A bot label. Known crawler names are marked identified. Empty user agents, common download tools, and a short list of probe paths are marked suspected. Everything else is treated as a possible person. This labeling is not perfect.
What is not stored
- Full IP addresses.
- Tracking cookies, or a browser fingerprint built from screen size, fonts, canvas, or similar details.
- Account data. The public site does not have accounts.
- Country, unless a current GeoIP database is installed. The database on this server is too old to use, so country is not recorded.
- Sensitive query-string values.
The private dashboard
An administrator can sign in to review analytics and offers. That sign-in sets a session cookie limited to the /admin path. The cookie is marked Secure, HttpOnly, and SameSite=Strict. Failed sign-in attempts are throttled. The dashboard is not linked from the public page.
Acquisition offers
If you submit an offer, the site stores your name, email address, optional company, proposed price, optional message, the time, and a private conversation that follows. That information is used to review the offer, reply to you, and keep a record of the negotiation. A confirmation and later replies are emailed to you. The operator can also receive an email and a text message that a message arrived. The text does not include your email address.
Offer details are not published, are not placed in the analytics totals, and are not sent to a third-party analytics service. A private link in the email opens only your conversation. The link expires, works once, and is stored only as a hash.
The offer form also keeps a short-lived session cookie so it can check a verification image and reject forged submissions. That cookie is not used to follow you across other sites.
Submitting an offer does not create a binding purchase agreement.
How long it is kept
Individual request rows are deleted after 35 days. Daily aggregates are kept for about 400 days so a month can still be reviewed after the raw rows are gone. Sign-in attempt records are deleted after 2 days. The Apache access log is rotated by the hosting panel on its own schedule and can still contain IP addresses and query strings. That file is not published and is not copied wholesale into the analytics database.
Why it is processed
The operator is deciding whether to develop or sell this domain and needs a record of requests the server actually received. The data is minimized to that purpose. If a privacy law applies to you, the operator's basis is the legitimate interest in understanding aggregate use of a site they run, balanced against the limited data described above. You can email clarin@clarin.info to ask what is held or to raise an objection.