Privacy Policy
Privacy Policy
Last updated: June 2026
The protection of your personal data is of paramount importance to us. As explained in Section 1 below, we do not consider this website to be subject to the GDPR on a targeting basis; nonetheless, we apply data protection practices modelled on the GDPR and the TDDDG as a matter of policy. This Privacy Policy describes data processing in connection with harbingerstandard.com, with reference to the standards those frameworks set out.
1. Controller
Harbinger Bros. LLC
1309 Coffeen Avenue, Sheridan, WY 82801, United States
Email: support@harbingerpressmedia.com
Contact form: /contact
Harbinger Standard does not specifically direct its content or services at residents of the European Union or European Economic Area, and we do not consider the GDPR to apply to us on a targeting basis under Art. 3 para. 2 GDPR. Nonetheless, as a matter of policy, we apply data protection practices modelled on the GDPR to all visitors regardless of location.
2. Data Protection Officer
No statutory obligation to appoint a DPO exists given the limited scale of data processing. Contact the controller directly for all data protection enquiries.
3. Principles of Data Processing
We process personal data in strict accordance with Art. 5 GDPR principles: lawfulness, fairness, transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. We use a single, cookie-less, anonymous analytics tool to measure aggregate visitor numbers (see Section 8 below); beyond that, we do not operate any tracking or advertising systems and create no user profiles.
4. Server Logs
When you visit our website, your browser automatically transmits technical connection data to our hosting provider's server (technically mandatory). Data categories: IP address, date/time of request, URL, referrer URL, data volume, HTTP status code, browser type/version, operating system. Purpose: Secure and stable website operation, defence against cyberattacks, error diagnosis. Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest). Hosting provider: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. DPA in place per Art. 28 GDPR. Third-country transfer: Based on SCCs (Art. 46 para. 2 lit. c GDPR) and EU-US DPF (Decision (EU) 2023/1795). Retention: Up to 30 days, then automatically deleted.
5. Database
Provider: Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992. DPA in place. SCCs used for international transfers. Only editorial content is stored, with one exception: if you use the contact form, your name, email address, and message are stored here too — see the Contact Form section below. See Supabase Privacy Policy.
Image Delivery
Article images may be hosted on and served directly from Unsplash (Unsplash Inc., Montreal, QC, Canada). When your browser loads an image from Unsplash servers, Unsplash may receive your IP address and standard browser request headers as part of the HTTP connection. We have no control over Unsplash’s data processing. Unsplash’s privacy policy: unsplash.com/privacy
Article images may also be hosted on and served directly from Wikimedia Commons (Wikimedia Foundation, Inc., 1 Montgomery Street, Suite 1600, San Francisco, CA 94104, USA). When your browser loads an image from Wikimedia Commons servers, the Wikimedia Foundation may receive your IP address and standard browser request headers as part of the HTTP connection. We have no control over the Wikimedia Foundation’s data processing. Wikimedia Foundation’s privacy policy: foundation.wikimedia.org/wiki/Policy:Privacy_policy
Email Correspondence
If you contact us by email at support@harbingerpressmedia.com, your message and any attachments are received, stored, and managed through GoDaddy Workspace Email (GoDaddy.com, LLC, 100 S. Mill Ave, Suite 1600, Tempe, AZ 85281, USA), our email hosting provider. GoDaddy processes this correspondence as our data processor, acting on our instructions; we have no control over its underlying infrastructure. GoDaddy's privacy policy: godaddy.com/legal/agreements/privacy-policy
6. Self-Hosted Fonts
All fonts are hosted on our own servers. No connections to Google Fonts, Adobe Fonts, or comparable external services are made.
7. Local Storage
| Name | Type | Purpose | Legal Basis | Retention |
|---|---|---|---|---|
hpm_cookie_consent | Local Storage (First-Party) | Storing cookie consent decision and timestamp | § 25 para. 2 No. 2 TDDDG; Art. 6 para. 1 lit. c GDPR | Until manually deleted |
This entry remains exclusively in your browser and is never transmitted to our servers or third parties. Delete it via: Developer Tools (F12) → Application → Local Storage → harbingerstandard.com → delete hpm_cookie_consent.
8. Anonymous Web Analytics and Other Tracking
We use Vercel Web Analytics, a cookie-less, anonymous analytics service provided by Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA), to measure aggregate visitor numbers. It collects only aggregated, non-personal metrics (e.g. page views, referrers, approximate country-level location), sets no cookies, does not permanently store IP addresses, and does not re-identify visitors across sessions. Legal basis: our legitimate interest in understanding website usage (Art. 6(1)(f) GDPR); no consent is required as no information is stored on or read from your device (§ 25 TDDDG / Art. 5(3) ePrivacy Directive). More information: Vercel Web Analytics privacy documentation.
Beyond Vercel Web Analytics, we expressly do not use: Google Analytics, Google Tag Manager, Matomo, Plausible, or any other cookie-based or profiling analytics service; Google Ads, Facebook Pixel, or any advertising network; social media plugins that transmit data automatically; session replay tools (Hotjar, Mouseflow, etc.); or browser fingerprinting or cross-site tracking technologies.
9. Third-Country Transfers
| Recipient | Country | Transfer Basis | Data |
|---|---|---|---|
| Vercel Inc. | USA | SCCs + EU-US DPF | Server logs |
| Supabase Inc. | Singapore | SCCs | Editorial content only |
10. Security Measures
TLS 1.3 encryption, HSTS, regular security updates, least-privilege access controls, encrypted database connections.
11. Privacy Rights We Extend to All Visitors
Although, as explained above, we do not consider the GDPR to apply to us on a targeting basis, we voluntarily extend the following rights, modelled on the GDPR, to all visitors: right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21), and withdrawal of consent (Art. 7 para. 3). Exercise these rights by contacting: support@harbingerpressmedia.com. We aim to respond within one month.
12. Raising Concerns with a Data Protection Authority
Although we do not consider ourselves subject to the jurisdiction of EU/UK supervisory authorities for the reasons explained above, if you believe such an authority nonetheless has jurisdiction over your complaint, you may contact the data protection supervisory authority in your country of residence, workplace, or the place of the alleged infringement.
13. Additional Notices for Other Jurisdictions and Data Breaches
13.1 United Kingdom (UK GDPR)
The rights described in Section 11 apply equally to visitors in the United Kingdom under the UK GDPR and the Data Protection Act 2018. The supervisory authority is the Information Commissioner's Office (ICO).
13.2 California, USA (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (“CCPA/CPRA”) grants you the following rights: the right to know what personal information we have collected about you, its sources, and the purpose of collection; the right to delete personal information we have collected from you, subject to certain exceptions; the right to correct inaccurate personal information; and the right to non-discrimination for exercising your rights. We do not sell or share your personal information, so no opt-out mechanism is required. We do not collect sensitive personal information as defined under the CPRA. To submit a request, email support@harbingerpressmedia.com with the subject line “California Privacy Request.” We respond within 45 days, with a possible 45-day extension where reasonably necessary. Categories of personal information collected in the preceding 12 months: internet or electronic network activity information (server log data including IP addresses and browser identifiers). We have not sold or shared any personal information.
13.3 Canada (PIPEDA)
Visitors from Canada have rights under the Personal Information Protection and Electronic Documents Act (“PIPEDA”) and applicable provincial legislation, including the right to access your personal information held by us and to challenge its accuracy. To exercise these rights, contact support@harbingerpressmedia.com.
13.4 Australia (Privacy Act 1988)
If you are located in Australia, the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to our processing of your personal information. You have the right to access and seek correction of your personal information, and to lodge a complaint about a potential breach of the APPs. Complaints may be directed to us at support@harbingerpressmedia.com and, if unresolved, to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
13.5 India (DPDP Act 2023)
If you are located in India, the Digital Personal Data Protection Act, 2023 (“DPDP Act”) applies to our processing of your personal data. As a Data Principal, you have the right to obtain a summary of the personal data we process about you, the right to correction and erasure of your personal data, and the right to grievance redressal. To exercise these rights or raise a grievance, contact support@harbingerpressmedia.com. Unresolved grievances may be escalated to the Data Protection Board of India.
13.6 South Korea (PIPA)
If you are located in South Korea, the Personal Information Protection Act (“PIPA”) applies to our processing of your personal information. You have the right to access, correct, delete, and suspend the processing of your personal information. To exercise these rights, contact support@harbingerpressmedia.com. Complaints may also be directed to the Personal Information Protection Commission (PIPC) of the Republic of Korea.
13.7 South Africa (POPIA)
If you are located in South Africa, the Protection of Personal Information Act 4 of 2013 (“POPIA”) applies to our processing of your personal information. You have the right to access, correct, and request deletion of your personal information, and to object to its processing. To exercise these rights, contact support@harbingerpressmedia.com. Complaints may also be directed to the Information Regulator of South Africa.
13.8 Nigeria (NDPA)
If you are located in Nigeria, the Nigeria Data Protection Act 2023 (“NDPA”) applies to our processing of your personal data. You have the right to access, rectify, and request erasure of your personal data, and to object to its processing. To exercise these rights, contact support@harbingerpressmedia.com. Complaints may also be directed to the Nigeria Data Protection Commission (NDPC).
13.9 Kenya (Data Protection Act 2019)
If you are located in Kenya, the Data Protection Act, 2019 applies to our processing of your personal data. You have the right to access, correct, and request deletion of your personal data, and to object to its processing. To exercise these rights, contact support@harbingerpressmedia.com. Complaints may also be directed to the Office of the Data Protection Commissioner (ODPC) of Kenya.
13.10 Notification of Personal Data Breaches
Although we do not consider ourselves bound by Articles 33–34 GDPR for the reasons explained above, we apply, as a matter of policy, breach-notification practices modelled on those provisions: in the event of a personal data breach likely to result in a risk to your rights and freedoms, we aim to notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, describing the nature of the breach and the measures taken or proposed.
14. No Automated Decision-Making (Art. 22 GDPR)
We do not use automated decision-making or profiling.
15. Media Privilege
Harbinger Standard invokes the journalistic media privilege (Art. 85 GDPR) insofar as necessary for journalistic work and source protection.
16. Contact Form
If you use the contact form at /contact, we collect and store your name, email address, and message content in our application database in order to respond to your inquiry. This data is stored via our database provider, Supabase Inc., and is accessible only to authorised personnel who handle correspondence. Legal basis: Art. 6(1)(b) GDPR (necessary to respond to your request) or, where no contractual relationship is established, Art. 6(1)(f) GDPR (legitimate interest in handling incoming communications). We retain contact form submissions for as long as necessary to address your inquiry and for a reasonable period thereafter for documentation purposes, typically no longer than 12 months, unless a longer retention period is required by law. You may request earlier deletion of your message at any time by contacting us.
17. Changes
This Privacy Policy may be updated to reflect legal requirements or service changes. The date of last update appears at the top.