This privacy policy explains what TheWeal collects from people who visit theweal.com, why we collect it, how long we keep it, who else sees it, and what your rights are. It is written in plain English with no surprises. If anything is unclear, email privacy@theweal.com.
Last updated: May 28, 2026. This policy supersedes all earlier versions. Material changes will be announced via a notice on this page and, where relevant, via email to newsletter subscribers.
Who we are
TheWeal is operated by TheWeal Editorial (a publishing entity registered in Delaware, USA). Mailing address available on request via privacy@theweal.com. The data controller for the purposes of GDPR is TheWeal Editorial.
What we collect
We collect data in three categories:
1. Information you provide directly
- Newsletter subscription — your email address, the date of subscription, the source of subscription (e.g., a specific article), and any preferences you set.
- Contact form / email correspondence — whatever you choose to send us. We retain the email exchange for the period necessary to handle the matter.
- Comments (if comments are enabled on the site) — your name, email (not displayed), and the comment text.
2. Information collected automatically
- Server logs — your IP address, the URL requested, the response code, your browser user-agent, the referring URL, and the timestamp. Retained for 30 days for security and operational purposes.
- Analytics — aggregated, anonymised page-view data. We use a privacy-respecting analytics service that does not assign persistent identifiers and does not require cookies for first-party visits.
- Cookies and localStorage — see the cookie policy for details.
3. Information from third parties
- Newsletter delivery analytics — our email service provider records opens and clicks for the purpose of newsletter delivery quality. You can opt out by unsubscribing.
- Affiliate program data — when you click an affiliate link to a partner exchange, we may receive aggregated reports about whether the click resulted in a signup. These reports do not include personally identifying information about you.
Why we collect what we collect
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Email (newsletter) | Send the newsletter you subscribed to | Consent |
| IP address (logs) | Server security, abuse prevention | Legitimate interest |
| Analytics (anonymised) | Understand which articles readers find | Legitimate interest |
| Cookies (functional only) | Page operation, tab states, theme | Strictly necessary |
| Contact form | Respond to your message | Legitimate interest |
We do not run behavioural advertising on TheWeal. We do not place cross-site tracking pixels. We do not sell, rent, or share personal data with marketing companies.
How long we keep it
- Newsletter email — until you unsubscribe. After unsubscribe, retained for 30 days on a suppression list to prevent accidental re-add.
- Server logs — 30 days, then deleted.
- Analytics — aggregated data retained indefinitely; no individual-level records retained.
- Contact form / email — retained for 24 months for matter-handling and follow-up.
- Comments — retained while the article is live unless you request deletion.
Who we share it with
TheWeal shares data only with vendors necessary to operate the site:
- Hosting provider (Hetzner) — receives server traffic, including IP addresses, as part of normal operation.
- Email delivery — newsletter emails are delivered via a service provider that processes the recipient address. We do not provide your email to any other party.
- Analytics provider — receives aggregated, anonymised pageview data; does not receive personally identifying information.
- CDN / DDoS protection (Cloudflare) — receives request metadata, IP addresses, and basic traffic patterns for security purposes.
We do not share data with advertising networks. We do not share data with crypto projects or exchanges. We do not share data with brokers.
Your rights
Under GDPR (if you are in the EU or UK), you have:
- Right of access — to a copy of the personal data we hold about you.
- Right of rectification — to correct inaccurate data.
- Right of erasure — to have your data deleted (subject to legal-retention requirements).
- Right of portability — to receive your data in a portable format.
- Right of restriction — to restrict our use of your data while a dispute is resolved.
- Right of objection — to object to processing based on legitimate interest.
- Right of withdrawal — to withdraw consent at any time (e.g., unsubscribe).
- Right to lodge a complaint — with your local data protection authority.
Under CCPA (if you are a California resident), you have:
- The right to know what personal information we collect, use, and share.
- The right to delete personal information we hold about you.
- The right to opt out of the sale of personal information. We do not sell personal information.
- The right to non-discrimination for exercising your CCPA rights.
To exercise any of these rights, email privacy@theweal.com. We respond within statutory timelines — 30 days under GDPR, 45 days under CCPA. We may ask you to verify your identity (typically by responding from the email address you originally provided).
Children’s privacy
TheWeal is not directed to children under 13 (US) or under 16 (EU/UK). We do not knowingly collect personal information from anyone in those age groups. If we discover such data has been collected inadvertently, we delete it.
International transfers
TheWeal operates from servers physically located in Germany. EU/UK readers’ data does not leave the EU/UK in regular operation. US-based readers’ data may be processed in both the US and EU under standard contractual clauses where applicable.
Security
We use industry-standard security practices: HTTPS site-wide (HSTS enforced), encrypted database backups, restricted admin access, two-factor authentication on all admin accounts, and CSP headers to mitigate cross-site scripting. We are not perfect — no organisation is — but we treat security as a baseline expectation.
If you discover a security vulnerability on TheWeal, please email security@theweal.com. We respond within 24 hours and credit responsible disclosure.
Changes to this policy
We update this policy when our practices change. Material changes are announced on this page (with a date stamp) and via email to newsletter subscribers. Continued use of TheWeal after a material change implies acceptance of the updated policy.
Contact
Privacy questions, data requests, or complaints: privacy@theweal.com.