Privacy Policy for joshmon27.com
Last Updated: August 7, 2026 | Effective Date: August 7, 2026
Contact: josh@joshmon27.com
1. Introduction
Josh Walton (“I”, “me”, or “my”) operates joshmon27.com and associated web applications, iOS applications, and Android applications (collectively, the “Services”). This Privacy Policy explains how I collect, use, disclose, and safeguard your information when you use my Services.
I am a software developer based in Lompoc, California, building custom web applications (Laravel/PHP, Vue, WordPress), iOS apps (Swift/Objective‑C), and Android apps (Kotlin/Java) for clients and personal projects including VineCrawl.com, the Bunkie chatbot review system, and client work for organizations like Sleep in Heavenly Peace.
2. Information I Collect
2.1 Information You Provide Directly
| Category | Examples |
|---|---|
| Account / Profile | Name, email, username, password (hashed), avatar |
| Content You Submit | Comments, form submissions, support requests, blog replies |
| Communications | Emails, contact form messages, GitHub issues, feedback |
| Payment Data | Handled by Stripe / Apple / Google — I receive only tokenized confirmations, never full card numbers |
2.2 Information Collected Automatically
| Data Type | Sources | Purpose |
|---|---|---|
| Device & Browser | User‑Agent, OS version, device model, unique identifiers (IDFA/IDFV on iOS, Advertising ID on Android) | Analytics, crash reporting, fraud prevention |
| Usage & Analytics | Pages viewed, features used, session duration, referrer | Product improvement (Plausible / Google Analytics 4) |
| Network / Location | IP address (approximate city/region), timezone | Security, geo‑blocking compliance, CDN routing |
| Error & Performance | Crash logs, stack traces, ANRs, latency metrics | Debugging (Sentry / Firebase Crashlytics) |
| Cookies & Local Storage | Session tokens, CSRF tokens, consent preferences, localStorage cache | Authentication, security, UX persistence |
2.3 Information from Third Parties
| Provider | Data Received | Purpose |
|---|---|---|
| GitHub / Google / Apple OAuth | Public profile (name, email, avatar) | Authentication (OAuth 2.0 / OIDC) |
| Stripe | Payment token, subscription status, billing email | Subscriptions, one‑time payments |
| Firebase / Google Analytics | Pseudonymous event data | App analytics, attribution |
| Sentry | Error context, device info, release version | Error tracking |
| DigitalOcean / Cloudflare | Access logs, WAF events | Hosting, DDoS protection, caching |
3. How I Use Your Information
| Purpose | Legal Basis (CCPA/CPRA / UK GDPR) | Data Categories |
|---|---|---|
| Provide & maintain Services (auth, content, features) | Contract / Legitimate Interest | Account, Device, Usage |
| Process payments & subscriptions | Contract | Payment tokens, email |
| Transactional emails (receipts, password resets, alerts) | Contract / Legitimate Interest | Email, Account |
| Product updates / blog notifications (opt‑in only) | Consent | |
| Analytics & product improvement | Legitimate Interest / Consent (analytics cookies) | Usage, Device |
| Crash reporting & debugging | Legitimate Interest | Crash logs, Device |
| Security, fraud prevention, abuse detection | Legitimate Interest / Legal Obligation | IP, Device, Usage |
| Comply with legal requests (subpoenas, CCPA/CPRA requests) | Legal Obligation | Account, Usage, Communications |
I do not sell your personal information (as defined by CCPA/CPRA). I do not share data for cross‑context behavioral advertising.
4. Data Sharing & Disclosure
| Recipient Category | Purpose | Example Providers | Safeguards |
|---|---|---|---|
| Hosting / Infrastructure | Hosting, CDN, DNS, WAF | DigitalOcean, Cloudflare | DPA / SCCs, SOC2 |
| Analytics | Aggregated usage insights | Plausible, Google Analytics 4 | IP anonymization, DPA |
| Crash / Error Tracking | Debugging | Sentry | DPA, EU/US data centers |
| Payments | Payment processing | Stripe, Apple IAP, Google Play Billing | PCI DSS Level 1, DPA |
| Authentication | OAuth login | GitHub, Google, Apple | Their privacy policies apply |
| Email Delivery | Transactional email | Resend / SendGrid / Postmark | DPA, suppression lists honored |
| Legal Authorities | Valid legal process | Law enforcement, regulators | Only with valid request; notice where permitted |
| Business Transfer | Merger, acquisition, asset sale | Acquirer | Notice provided; buyer bound by this policy |
5. Data Retention
| Data Category | Retention Period |
|---|---|
| Account & profile data | While account active + 30 days after deletion request |
| Transaction / subscription records | 7 years (tax / legal compliance) |
| Analytics events (Plausible / GA4) | 13 months (GA4) / 12 months (Plausible) |
| Crash / error logs (Sentry) | 90 days (default) |
| Server access logs (Cloudflare / DO) | 30 days |
| Support emails / tickets | 3 years after last contact |
| Marketing consent records | Until withdrawn + 2 years |
You may request deletion at any time — see Section 8.
6. Your Rights & Choices (CCPA/CPRA & General)
| Right | How to Exercise |
|---|---|
| Know / Access | Email privacy@joshmon27.com — I’ll provide a portable copy within 45 days |
| Delete | Same email — verified deletion within 45 days (backups up to 30 additional days) |
| Opt‑Out of Sale / Sharing | I do not sell or share for cross‑context behavioral advertising |
| Limit Use of Sensitive PI | I do not collect sensitive PI (SSN, precise geolocation, health, biometrics, etc.) |
| Non‑Discrimination | Exercising rights will not degrade your Service experience |
| Authorized Agent | Provide written permission + agent identity verification |
Cookie / Analytics Opt‑Out
- Plausible: No cookies; respects
Do Not Track. - GA4: Use Google Analytics Opt‑out Browser Add‑on or disable analytics cookies via the consent banner.
- Mobile: iOS → Settings → Privacy → Tracking (disable “Allow Apps to Request to Track”); Android → Settings → Google → Ads → “Delete Advertising ID” or “Opt out of Ads Personalization.”
Email Unsubscribe
Every marketing email includes a one‑click unsubscribe link. Transactional emails (receipts, security alerts) cannot be unsubscribed.
7. Children’s Privacy
The Services are not directed to children under 13 (or 16 in the EU/UK). I do not knowingly collect personal information from children. If you believe a child has provided data, contact privacy@joshmon27.com for immediate deletion.
8. Security Measures
| Control | Implementation |
|---|---|
| Encryption in Transit | TLS 1.2+ (Cloudflare managed certs, HSTS, CT logs) |
| Encryption at Rest | DigitalOcean volumes (AES‑256), managed DB encryption |
| Authentication | Argon2id password hashing, TOTP / WebAuthn MFA, OAuth 2.0 + PKCE |
| Session Security | HttpOnly + Secure + SameSite=Lax cookies, short‑lived JWTs with rotation |
| Infrastructure | SSH key‑only access, fail2ban, UFW, automated security updates, VPC isolation |
| Application Security | CSP, X‑Frame‑Options, Referrer‑Policy, SRI for third‑party scripts, parameterized queries / Eloquent ORM, CSRF tokens on all forms |
| Monitoring & Response | Sentry alerts, Cloudflare WAF logs, UptimeRobot, documented incident response plan (72‑hr breach notification where required) |
No system is 100% secure. I encourage responsible disclosure via security@joshmon27.com.
9. Platform‑Specific Disclosures
9.1 iOS App(s) (App Store)
- App Tracking Transparency (ATT): Requested only if/when IDFA is used for attribution. Current apps: no IDFA usage — ATT prompt not shown.
- App Privacy Label (App Store Connect): Declared data types — Contact Info, Identifiers, Usage Data, Diagnostics — linked to this policy.
- Sign in with Apple: Supported where third‑party login offered; hides email via private relay.
- Permissions Requested: Camera / Photo Library / Notifications — only when feature used, with
Info.plistusage descriptions. - Account Deletion: In‑app “Delete Account” flow (Settings → Account → Delete) per App Store Guideline 5.1.1(v).
9.2 Android App(s) (Google Play)
- Data Safety Section (Play Console): Declared — Personal info (name, email), App activity, Device IDs, Crash logs, Performance.
- Permissions: Requested at runtime (
CAMERA,READ_MEDIA_IMAGES,POST_NOTIFICATIONS,ACCESS_FINE_LOCATIONonly if feature enabled). Revocable in system settings. - Play Billing: Used for subscriptions/IAP; Google processes payments — I receive only purchase tokens.
- Advertising ID: Used by Firebase Analytics for attribution; user can reset/opt‑out in Settings → Google → Ads.
- Account Deletion: In‑app flow + web fallback URL provided in Play Console.
9.3 Web Applications (joshmon27.com, VineCrawl.com, client sites)
- Cookies: Only essential (session, CSRF) + optional analytics (Plausible — cookieless; GA4 with consent mode v2).
- Consent Banner: Shown to CA/EU/UK visitors (geolocation via Cloudflare
cf-ipcountryheader). Preference stored inlocalStorage+ cookie. - Third‑Party Embeds: YouTube (no‑cookie domain), GitHub Gists, Stripe.js — governed by their policies.
- Security Headers:
Content‑Security‑Policy,Permissions‑Policy,Cross‑Origin‑Opener‑Policy,Strict‑Transport‑Security.
10. California Privacy Rights (CCPA/CPRA Summary)
| Category | Collected? | Sold? | Shared for Cross‑Context Behavioral Advertising? |
|---|---|---|---|
| Identifiers (name, email, IP, device ID) | Yes | No | No |
| Commercial Information (subscription, purchases) | Yes | No | No |
| Internet / Electronic Activity (usage, logs) | Yes | No | No |
| Geolocation (approx. from IP) | Yes | No | No |
| Inferences (engagement, churn risk) | Yes | No | No |
| Sensitive PI (SSN, precise geo, health, biometrics) | No | — | — |
Designated Request Address: privacy@joshmon27.com
Verification: Email + one additional factor (e.g., last 4 of card on file, recent login IP, or signed declaration).
11. International Data Transfers
I am based in California, USA. Your data is processed on servers in San Francisco (DigitalOcean SFO3) and Cloudflare’s global network. If you are in the EU/UK:
- I rely on Standard Contractual Clauses (2021/914) with subprocessors.
- No adequacy decision for the U.S. post‑Schrems II; you may withdraw consent for analytics/optional processing at any time.
- I do not maintain an EU establishment; if Art. 27 GDPR applies to you, contact me to designate a representative.
12. Changes to This Policy
Material changes will be announced via:
- Banner on joshmon27.com for 30 days
- Email to registered users (if transactional/contact email on file)
- In‑app notification (mobile apps)
- Updated “Last Updated” date above
Continued use after the effective date constitutes acceptance.
13. Contact Information
Data Controller: Josh WaltonAddress: Lompoc, CA 93436, United States
Email: privacy@joshmon27.com (also josh@joshmon27.com)
Contact Form: https://joshmon27.com/contact
Security Reports: security@joshmon27.com
Appendix A: Cookie & Storage Inventory (Web)
| Name | Domain | Type | Purpose | Expiry |
|---|---|---|---|---|
session_id / laravel_session | joshmon27.com | First‑party cookie | Authentication session | Session / 2 hrs |
XSRF-TOKEN | joshmon27.com | First‑party cookie | CSRF protection | Session |
plausible_session | joshmon27.com | localStorage (Plausible) | Anonymous session ID (no cookie) | 30 min |
_ga, _ga_* | joshmon27.com | First‑party cookie (GA4) | Analytics (consent‑mode v2) | 13 months |
stripe_sid, stripe_mid | js.stripe.com | Third‑party cookie | Fraud prevention (Stripe.js) | 1 year |
__cf_bm, cf_clearance | cloudflare.com | Third‑party cookie | Bot management, WAF | 30 min / 1 year |
sentry-sc, sentry-replay | joshmon27.com | First‑party cookie / localStorage | Session replay, error context | Session / 1 day |
No advertising cookies. No third‑party tracking pixels (Facebook, TikTok, etc.).
Appendix B: Mobile Permissions Actually Requested
| Permission | iOS Key / Android Manifest | Feature | Required? |
|---|---|---|---|
| Camera | NSCameraUsageDescription / CAMERA | Profile photo, QR scan (VineCrawl) | Optional (runtime) |
| Photo Library | NSPhotoLibraryUsageDescription / READ_MEDIA_IMAGES | Avatar upload | Optional |
| Notifications | UNUserNotificationCenter / POST_NOTIFICATIONS | Push alerts (Bunkie, client apps) | Optional |
| Location (Precise) | NSLocationWhenInUseUsageDescription / ACCESS_FINE_LOCATION | Vineyard check‑in (VineCrawl) | Optional, opt‑in |
| Biometric / Face ID | NSFaceIDUsageDescription / USE_BIOMETRIC | App unlock (client projects) | Optional |
No background location, microphone, contacts, SMS, or call logs.
Appendix C: Subprocessor DPA Links
| Subprocessor | DPA / Data Processing Addendum |
|---|---|
| DigitalOcean | https://www.digitalocean.com/legal/data-processing-agreement |
| Cloudflare | https://www.cloudflare.com/dpa/ |
| Stripe | https://stripe.com/dpa |
| Sentry | https://sentry.io/legal/dpa/ |
| Plausible Analytics | https://plausible.io/dpa |
| Google (Firebase/Analytics) | https://cloud.google.com/terms/data-processing-addendum |
| Apple (Sign in with Apple, APNs) | https://www.apple.com/legal/privacy/data-processing/ |
| GitHub (OAuth) | https://docs.github.com/en/site-policy/privacy-policies/github-data-protection-addendum |
| Resend / SendGrid | https://resend.com/dpa / https://sendgrid.com/dpa/ |
Appendix D: Deployment Notes (for you)
- Policy URL:
https://joshmon27.com/privacy(also linked in footer, app settings, App Store / Play Console) - Last Updated:
2026-08-07— update this date + header on every change - Cookie Consent: Implemented via lightweight vanilla JS (
/js/consent.js) reading/writingcookie_consentcookie +localStorage.consent; respectsnavigator.doNotTrackandGlobal Privacy Controlheader - DSAR Endpoint:
POST /api/privacy/request→ logs toprivacy_requeststable, emails you, auto‑replies with ticket ID - Account Deletion:
DELETE /api/user/account(requires password re‑auth + TOTP if enabled) → queues job: anonymize PII, revoke tokens, cancel Stripe subscription, delete Sentry user data, send confirmation email - Annual Review: Calendar reminder every August 7 — review subprocessors, cookie inventory, permission list, retention schedule