Your Privacy on HeavyDutyJournal.com
We respect your privacy and are committed to protecting it through transparent data practices. This policy explains what data we collect, how we use it, your rights, and the choices you have. It applies to HeavyDutyJournal.com, our contributor platform, newsletter, and all related services.
1. Information We Collect
Information You Provide Directly
- Contact Information: Name, email address, company, phone number (optional), job title, and professional background
- Contributor Profile: Biography, professional photo, website/LinkedIn links, areas of expertise, and article submissions
- Newsletter Subscription: Email address, content preferences, job role, and topics of interest
- Communications: Support requests, feedback, business inquiries, and any information you choose to share
- User-Generated Content: Comments, forum posts, uploaded images, and any content you publish
- Payment Information: Billing details processed securely through our payment provider (we do not store full payment card numbers)
Information Collected Automatically
- Usage Data: Pages visited, time spent, click patterns, referral sources, search queries, and user flow
- Device Information: Browser type/version, operating system, screen resolution, device identifiers
- Location Data: IP-based approximate geographic location (country/region level)
- Cookies & Storage: Session data, preferences, authentication tokens, and performance metrics
- Server Logs: Access logs, error reports, security events, and performance data
⚠️ Public Information Notice
Any personal information you include in published articles, comments, or public profiles may become permanently accessible to search engines and the public.
2. How We Use Your Information
Core Platform Operations
- Operate and maintain HeavyDutyJournal.com, contributor dashboards, and publishing tools
- Process, review, edit, and publish contributor submissions while maintaining editorial standards
- Manage user accounts, authentication, and access permissions
- Provide customer support and respond to inquiries or technical issues
- Process payments for advertising, sponsored content, and premium services
Communications & Marketing
- Send transactional emails (account notifications, submission updates, password resets)
- Deliver newsletters and promotional content (only with explicit consent)
- Personalize content recommendations based on your interests and engagement
- Conduct surveys and gather feedback to improve our services
Analytics & Improvement
- Analyze usage patterns to improve site performance, user experience, and content strategy
- Monitor security threats, prevent abuse, and maintain platform integrity
- Generate aggregated reports for internal business purposes and advertiser insights
- Conduct A/B testing to optimize features and user interface elements
Legal & Compliance
- Comply with applicable laws, regulations, and legal processes
- Enforce our Terms of Use and other agreements
- Protect rights, property, and safety of users and the public
- Respond to law enforcement requests and court orders when required
3. Legal Basis for Processing (GDPR)
Processing Bases We Rely On
- Consent: Newsletter subscriptions, non-essential cookies, marketing communications
- Contract Performance: Account management, content publishing, contributor services, payment processing
- Legitimate Interests: Site security, analytics, fraud prevention, content improvement, direct marketing to existing customers
- Legal Obligations: Compliance with applicable laws, tax requirements, and regulatory requirements
- Vital Interests: Protection of health, safety, or security in emergency situations
Consent Management
You can withdraw consent at any time through:
- Newsletter unsubscribe links in every email
- Cookie preference banner (displayed on first visit and accessible via footer link)
- Account settings in your contributor dashboard
- Contacting us directly at [email protected]
Withdrawing consent won't affect the lawfulness of processing before withdrawal.
4. Cookies & Tracking Technologies
Types of Cookies We Use
- Essential Cookies: Required for core functionality, security, and user authentication (always active)
- Functional Cookies: Remember your preferences, settings, and personalization choices
- Analytics Cookies: Help us understand site usage and improve user experience
- Performance Cookies: Monitor site speed, reliability, and technical performance
Managing Cookies
- Cookie Banner: On your first visit, you can accept or customize cookie preferences
- Browser Settings: Most browsers allow you to control cookies through settings
- Delete Cookies: You can delete existing cookies and prevent future ones
- Impact: Blocking essential cookies may impact site functionality
Cookie Details
| Cookie Type | Purpose | Duration |
|---|---|---|
| Session | User authentication, security tokens | Browser session |
| Preferences | Language, display settings, cookie consent | 1 year |
| Analytics | Usage patterns, page views, user journeys | Up to 2 years |
| Performance | Load times, error tracking | 30 days |
5. Analytics & Performance
What We Measure
We use analytics tools to understand:
- Most popular content and topics among heavy-duty professionals
- User journey patterns and content discovery methods
- Technical performance issues and optimization opportunities
- Geographic distribution of our audience (aggregated, non-personal)
- Newsletter engagement rates and content effectiveness
Analytics Tools We Use
- Google Analytics 4: Website traffic and user behavior analysis (with IP anonymization enabled)
- Server-Side Analytics: Performance monitoring and error tracking
- Email Analytics: Open rates and click tracking for newsletter optimization
Data is aggregated whenever possible to protect individual privacy while enabling service improvements.
6. Third-Party Services
Service Providers We Work With
- Hosting & CDN: Hostinger (website hosting and content delivery)
- Email Services: Newsletter delivery and transactional email systems
- Analytics: Google Analytics 4 (privacy-focused configuration)
- Security: Cloudflare (DDoS protection, SSL, threat monitoring)
- Payment Processing: Stripe (secure payment handling)
- Forms & Data: WordPress plugins for contact forms and submissions
Data Sharing Safeguards
- All service providers are bound by data processing agreements
- They can only access data necessary for their specific services
- We regularly review third-party security and privacy practices
- Data is encrypted in transit (TLS/SSL) and at rest where technically feasible
- A current list of sub-processors is available upon request
7. Email Communications
Transactional Emails
These are necessary for service delivery and cannot be unsubscribed:
- Account registration confirmations and welcome messages
- Password resets and security alerts
- Article submission confirmations and editorial feedback
- Comment notifications and reply alerts
- Important policy or service changes
- Payment receipts and billing notifications
Marketing Communications
Opt-in only — you control these:
- Weekly newsletter with curated industry content
- Editor's picks and featured contributor highlights
- New content alerts based on your selected interests
- Special announcements and event invitations
- All marketing emails include easy one-click unsubscribe
⚠️ Email Tracking: We track basic email metrics (opens, clicks) to improve content and delivery. You can opt out of tracking by disabling remote images in your email client or contacting us to be added to our no-track list.
8. Contributor Accounts
Data We Collect for Contributors
- Account Information: Username, email, password (hashed), account creation date
- Profile Information: Display name, bio, photo, social links, areas of expertise
- Submission History: Articles submitted, publication status, editorial communications
- Activity Data: Login history, dashboard usage, content management actions
- Payment Information: For paid contributor arrangements (processed via Stripe)
Public Profile Visibility
When you create a contributor profile, the following may be publicly visible:
- Display name and author byline on published articles
- Professional biography and photo (if provided)
- Links to your website or professional profiles (if provided)
- List of your published articles on your author page
You can control profile visibility through your dashboard settings or by contacting support.
9. Comments & Community
Comment Data
- Comment Content: The text of your comment and any links included
- Author Information: Name, email (not publicly displayed), website (optional)
- Metadata: IP address, browser user agent, timestamp
- Gravatar: If you use Gravatar, your profile image may be displayed
Comment Moderation
- Review Process: Comments may be held for moderation before publication
- Spam Detection: Automated systems help identify spam and inappropriate content
- Community Standards: Comments violating our guidelines may be edited or removed
- Human Review: Flagged comments are reviewed by human moderators
⚠️ Public Comments
Comments are publicly visible and may be indexed by search engines. Do not include sensitive personal information in comments.
10. Advertising & Sponsored Content
Our Advertising Approach
HeavyDutyJournal.com displays advertising to support our editorial operations. Here's how advertising affects your data:
Types of Advertising
- Direct-Sold Ads: Banner ads and sponsored content sold directly to industry advertisers
- Sponsored Articles: Clearly labeled paid content from industry partners
- Newsletter Sponsorships: Sponsored sections in our email newsletters
Data & Advertising
- No Personal Data Sale: We do not sell your personal information to advertisers
- Aggregated Reporting: Advertisers receive aggregated performance metrics only
- Contextual Targeting: Ads are primarily matched to content topics, not personal profiles
- Clear Labeling: All sponsored content is clearly disclosed per FTC guidelines
For detailed information about our advertising policies, see our Refund, Returns & Advertising Policy.
11. AI & Automated Decision Making
How We Use Automated Systems
- Content Moderation: Automated systems help identify spam, inappropriate content, or policy violations in comments and submissions
- Personalization: Algorithms suggest relevant articles based on your reading history and stated preferences
- Security: Automated monitoring for suspicious activity, fraud prevention, and threat detection
- Editorial Assistance: AI tools may assist with content formatting, SEO optimization, and basic editing
- Email Optimization: Send-time optimization and subject line testing
Your Rights Regarding Automated Decisions
- Human Review: Important decisions affecting your account or content are always reviewed by human moderators
- Right to Contest: You have the right to request human review of any automated decision that significantly affects you
- Transparency: We will explain the logic involved in automated decisions upon request
✓ No Solely Automated High-Impact Decisions: We do not make decisions with significant legal or similarly significant effects based solely on automated processing without human involvement.
12. Information Sharing
When We Share Your Information
We do not sell your personal information. We may share your data in these limited circumstances:
Service Providers
- Third-party vendors who help us operate our services (hosting, email, analytics, payments)
- These providers are contractually bound to protect your data and use it only for specified purposes
Legal Requirements
- When required by law, subpoena, court order, or government request
- To protect our rights, property, or safety, or that of our users or the public
- To investigate potential violations of our Terms of Use
Business Transfers
- In connection with a merger, acquisition, reorganization, or sale of assets
- You will be notified via email and/or prominent notice on our site of any change in ownership or uses of your personal information
With Your Consent
- When you explicitly authorize us to share specific information
- When you make information public through comments, articles, or profile settings
13. Data Retention
How Long We Keep Your Data
We retain your information only as long as necessary for the purposes described in this policy:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account Data | Duration of account + 3 years | Legal compliance, dispute resolution |
| Published Content | Indefinitely (or until deletion requested) | Editorial archive, public record |
| Comments | Indefinitely (or until deletion requested) | Community discussion continuity |
| Newsletter Subscribers | Until unsubscribe + 30 days | Processing unsubscribe request |
| Transaction Records | 7 years | Tax and legal requirements |
| Server Logs | 90 days | Security, troubleshooting |
| Analytics Data | 26 months (aggregated) | Trend analysis, reporting |
| Support Tickets | 3 years after resolution | Service history, training |
After retention periods expire, data is securely deleted or anonymized. You may request earlier deletion subject to legal and legitimate business requirements.
14. Security Measures
Technical Safeguards
- Encryption: TLS/SSL encryption for all data in transit
- Secure Storage: Encrypted databases and secure cloud infrastructure
- Password Security: Passwords are hashed using industry-standard algorithms
- Firewall Protection: Web application firewall and DDoS protection
- Regular Updates: Timely security patches and software updates
Operational Safeguards
- Access Controls: Role-based access limiting who can view personal data
- Monitoring: Continuous security monitoring and intrusion detection
- Backups: Regular encrypted backups with secure offsite storage
- Vendor Assessment: Security review of third-party service providers
- Incident Response: Documented procedures for security incidents
⚠️ No System is 100% Secure
While we implement reasonable security measures, no method of transmission or storage is completely secure. We cannot guarantee absolute security of your information.
15. Data Breach Notification Procedures
Our Response Process
- Detection & Assessment: Immediate investigation to determine scope, source, and impact of any breach
- Containment: Swift action to prevent further unauthorized access or data loss
- Regulatory Notification: Notification to relevant supervisory authorities within 72 hours where required by GDPR
- User Notification: Direct communication to affected users without undue delay when personal data is at high risk
- Documentation: Comprehensive recording of breach details, effects, and remedial actions
- Remediation: Implementation of additional security measures to prevent future incidents
What We'll Tell You
If your data is affected by a breach, our notification will include:
- Nature of the breach and types of data involved
- Likely consequences and risks
- Measures we've taken and are taking to address the breach
- Steps you can take to protect yourself
- Contact information for questions
16. Children's Privacy
Age Restrictions
HeavyDutyJournal.com is designed for industry professionals and is not directed at children.
- Minimum Age (US): You must be at least 13 years old to use our services (COPPA compliance)
- Minimum Age (EU/UK): You must be at least 16 years old, or the minimum age in your country if lower (GDPR compliance)
- Account Creation: You must be at least 18 years old to create a contributor account
If We Discover Child Data
- If we learn we've collected personal information from a child under the applicable minimum age without verified parental consent, we will delete that information promptly
- If you believe we have information from or about a child, please contact us immediately at [email protected]
17. International Data Transfers
Where Your Data May Be Processed
HeavyDutyJournal.com is based in the United States. If you access our services from outside the US, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
Transfer Safeguards
- Standard Contractual Clauses (SCCs): We use EU-approved SCCs for transfers from the EU/UK to the US
- Data Processing Agreements: All international service providers sign agreements ensuring adequate protection
- Privacy Shield Framework: Where applicable, we work with providers certified under relevant frameworks
- Adequacy Decisions: We rely on EU adequacy decisions where available for third-country transfers
Your Rights
If you're in the EU/UK, you have the right to:
- Request information about the safeguards we use for international transfers
- Obtain a copy of the Standard Contractual Clauses upon request
- Lodge a complaint with your local supervisory authority regarding international transfers
18. Your Privacy Rights
EU/UK (GDPR) Rights
- Access: Request copies of your personal data
- Rectification: Correct inaccurate or incomplete information
- Erasure: Request deletion of your personal data ("right to be forgotten")
- Portability: Receive your data in a structured, machine-readable format
- Restriction: Limit how we process your data
- Objection: Object to processing based on legitimate interests or direct marketing
- Withdraw Consent: Remove consent for specific processing activities
- Lodge Complaints: Contact supervisory authorities about privacy concerns
US State Privacy Laws
- California (CCPA/CPRA): Know, access, correct, delete, and opt out of sale/sharing
- Virginia (CDPA): Access, correct, delete, and opt out of targeted advertising
- Colorado (CPA): Access, correct, delete, and opt out of profiling
- Connecticut (CTDPA): Access, correct, delete, and data portability
- Texas (TDPSA): Access, correct, delete, and opt out of sale
- Oregon (OCPA): Access, correct, delete, and data portability
- Montana (MCDPA): Access, correct, delete, and opt out of targeted ads
✓ We Do Not Sell Personal Information: HeavyDutyJournal.com does not sell your personal information to third parties for monetary consideration. If this practice ever changes, we will provide clear notice and opt-out mechanisms as required by law.
Do Not Sell/Share My Personal Information
Although we do not currently sell or share personal information for cross-context behavioral advertising, you may submit a "Do Not Sell or Share" request at any time:
- By Email: Send a request to [email protected] with "Do Not Sell" in the subject line
- By Contact Form: Submit via our contact page and select "Privacy Request"
19. Exercising Your Rights
How to Submit a Privacy Request
Request Methods
- Email: [email protected] with "Privacy Request" in the subject line
- Contact Form: Submit a request and select "Privacy Request" from the dropdown
- Account Settings: Some requests (data export, account deletion) can be initiated through your contributor dashboard
What to Include
- Your full name and email address associated with your account
- Specific description of your request (access, deletion, correction, etc.)
- Any additional information to help us locate your data
Verification Process
- We will verify your identity before processing requests to protect your privacy
- Verification may include confirming account ownership via email or providing additional information
- Authorized agents must provide written authorization from the data subject
Response Timeline
- Acknowledgment: Within 5 business days of receiving your request
- GDPR Requests: Completed within 30 days (extendable by 60 days for complex requests)
- CCPA/US State Requests: Completed within 45 days (extendable by 45 days if necessary)
- No Fee: We do not charge for reasonable privacy requests
Appeals Process
If we deny your request, you may appeal by:
- Responding to our denial with additional information or clarification
- Contacting us at [email protected] with "Privacy Appeal" in the subject
- Filing a complaint with your local data protection authority (EU/UK residents)
20. Policy Changes
How We Update This Policy
- Regular Review: We review and update this policy periodically to reflect changes in our practices, technologies, or legal requirements
- Version Tracking: Each version is numbered and dated at the top of the policy
- Change Log: Material changes are summarized in update notices
How We Notify You
- Minor Changes: Updated "Last Updated" date and version number
- Material Changes: Email notification to registered users and/or prominent website notice
- Significant Changes: 30 days advance notice before changes affecting your rights take effect
Your Choices
- Continued use of our services after changes constitutes acceptance of the updated policy
- If you disagree with changes, you may close your account and request data deletion
- Previous versions of this policy are available upon request
21. Contact Information
Privacy Questions? We're Here to Help
EU/UK Representative
If you are located in the EU or UK and have privacy concerns, you may also contact your local data protection authority:
- UK: Information Commissioner's Office (ICO) — ico.org.uk
- EU: Your national Data Protection Authority
Related Policies
- Terms of Use — Rules governing use of our services
- Refund Policy — Billing and advertising terms
- Cookie Policy — Detailed cookie information
HeavyDutyJournal.com Privacy Policy
Policy Version 2.1 · Effective January 21, 2026
This version supersedes all previous versions.
For questions about this policy, contact [email protected]
Legal Notice: This privacy policy is provided for informational purposes and does not constitute legal advice. Privacy laws vary by jurisdiction and continue to evolve. For specific legal questions, consult qualified legal counsel.