Privacy Policy

Privacy Policy for joshmon27.com

Last Updated: August 7, 2026  |  Effective Date: August 7, 2026

Contact: josh@joshmon27.com

1. Introduction

Josh Walton (“I”, “me”, or “my”) operates joshmon27.com and associated web applications, iOS applications, and Android applications (collectively, the “Services”). This Privacy Policy explains how I collect, use, disclose, and safeguard your information when you use my Services.

I am a software developer based in Lompoc, California, building custom web applications (Laravel/PHP, Vue, WordPress), iOS apps (Swift/Objective‑C), and Android apps (Kotlin/Java) for clients and personal projects including VineCrawl.com, the Bunkie chatbot review system, and client work for organizations like Sleep in Heavenly Peace.

2. Information I Collect

2.1 Information You Provide Directly

CategoryExamples
Account / ProfileName, email, username, password (hashed), avatar
Content You SubmitComments, form submissions, support requests, blog replies
CommunicationsEmails, contact form messages, GitHub issues, feedback
Payment DataHandled by Stripe / Apple / Google — I receive only tokenized confirmations, never full card numbers

2.2 Information Collected Automatically

Data TypeSourcesPurpose
Device & BrowserUser‑Agent, OS version, device model, unique identifiers (IDFA/IDFV on iOS, Advertising ID on Android)Analytics, crash reporting, fraud prevention
Usage & AnalyticsPages viewed, features used, session duration, referrerProduct improvement (Plausible / Google Analytics 4)
Network / LocationIP address (approximate city/region), timezoneSecurity, geo‑blocking compliance, CDN routing
Error & PerformanceCrash logs, stack traces, ANRs, latency metricsDebugging (Sentry / Firebase Crashlytics)
Cookies & Local StorageSession tokens, CSRF tokens, consent preferences, localStorage cacheAuthentication, security, UX persistence

2.3 Information from Third Parties

ProviderData ReceivedPurpose
GitHub / Google / Apple OAuthPublic profile (name, email, avatar)Authentication (OAuth 2.0 / OIDC)
StripePayment token, subscription status, billing emailSubscriptions, one‑time payments
Firebase / Google AnalyticsPseudonymous event dataApp analytics, attribution
SentryError context, device info, release versionError tracking
DigitalOcean / CloudflareAccess logs, WAF eventsHosting, DDoS protection, caching

3. How I Use Your Information

PurposeLegal Basis (CCPA/CPRA / UK GDPR)Data Categories
Provide & maintain Services (auth, content, features)Contract / Legitimate InterestAccount, Device, Usage
Process payments & subscriptionsContractPayment tokens, email
Transactional emails (receipts, password resets, alerts)Contract / Legitimate InterestEmail, Account
Product updates / blog notifications (opt‑in only)ConsentEmail
Analytics & product improvementLegitimate Interest / Consent (analytics cookies)Usage, Device
Crash reporting & debuggingLegitimate InterestCrash logs, Device
Security, fraud prevention, abuse detectionLegitimate Interest / Legal ObligationIP, Device, Usage
Comply with legal requests (subpoenas, CCPA/CPRA requests)Legal ObligationAccount, Usage, Communications

I do not sell your personal information (as defined by CCPA/CPRA). I do not share data for cross‑context behavioral advertising.

4. Data Sharing & Disclosure

Recipient CategoryPurposeExample ProvidersSafeguards
Hosting / InfrastructureHosting, CDN, DNS, WAFDigitalOcean, CloudflareDPA / SCCs, SOC2
AnalyticsAggregated usage insightsPlausible, Google Analytics 4IP anonymization, DPA
Crash / Error TrackingDebuggingSentryDPA, EU/US data centers
PaymentsPayment processingStripe, Apple IAP, Google Play BillingPCI DSS Level 1, DPA
AuthenticationOAuth loginGitHub, Google, AppleTheir privacy policies apply
Email DeliveryTransactional emailResend / SendGrid / PostmarkDPA, suppression lists honored
Legal AuthoritiesValid legal processLaw enforcement, regulatorsOnly with valid request; notice where permitted
Business TransferMerger, acquisition, asset saleAcquirerNotice provided; buyer bound by this policy

5. Data Retention

Data CategoryRetention Period
Account & profile dataWhile account active + 30 days after deletion request
Transaction / subscription records7 years (tax / legal compliance)
Analytics events (Plausible / GA4)13 months (GA4) / 12 months (Plausible)
Crash / error logs (Sentry)90 days (default)
Server access logs (Cloudflare / DO)30 days
Support emails / tickets3 years after last contact
Marketing consent recordsUntil withdrawn + 2 years

You may request deletion at any time — see Section 8.

6. Your Rights & Choices (CCPA/CPRA & General)

RightHow to Exercise
Know / AccessEmail privacy@joshmon27.com — I’ll provide a portable copy within 45 days
DeleteSame email — verified deletion within 45 days (backups up to 30 additional days)
Opt‑Out of Sale / SharingI do not sell or share for cross‑context behavioral advertising
Limit Use of Sensitive PII do not collect sensitive PI (SSN, precise geolocation, health, biometrics, etc.)
Non‑DiscriminationExercising rights will not degrade your Service experience
Authorized AgentProvide written permission + agent identity verification

Cookie / Analytics Opt‑Out

  • Plausible: No cookies; respects Do Not Track.
  • GA4: Use Google Analytics Opt‑out Browser Add‑on or disable analytics cookies via the consent banner.
  • Mobile: iOS → Settings → Privacy → Tracking (disable “Allow Apps to Request to Track”); Android → Settings → Google → Ads → “Delete Advertising ID” or “Opt out of Ads Personalization.”

Email Unsubscribe

Every marketing email includes a one‑click unsubscribe link. Transactional emails (receipts, security alerts) cannot be unsubscribed.

7. Children’s Privacy

The Services are not directed to children under 13 (or 16 in the EU/UK). I do not knowingly collect personal information from children. If you believe a child has provided data, contact privacy@joshmon27.com for immediate deletion.

8. Security Measures

ControlImplementation
Encryption in TransitTLS 1.2+ (Cloudflare managed certs, HSTS, CT logs)
Encryption at RestDigitalOcean volumes (AES‑256), managed DB encryption
AuthenticationArgon2id password hashing, TOTP / WebAuthn MFA, OAuth 2.0 + PKCE
Session SecurityHttpOnly + Secure + SameSite=Lax cookies, short‑lived JWTs with rotation
InfrastructureSSH key‑only access, fail2ban, UFW, automated security updates, VPC isolation
Application SecurityCSP, X‑Frame‑Options, Referrer‑Policy, SRI for third‑party scripts, parameterized queries / Eloquent ORM, CSRF tokens on all forms
Monitoring & ResponseSentry alerts, Cloudflare WAF logs, UptimeRobot, documented incident response plan (72‑hr breach notification where required)

No system is 100% secure. I encourage responsible disclosure via security@joshmon27.com.

9. Platform‑Specific Disclosures

9.1 iOS App(s) (App Store)

  • App Tracking Transparency (ATT): Requested only if/when IDFA is used for attribution. Current apps: no IDFA usage — ATT prompt not shown.
  • App Privacy Label (App Store Connect): Declared data types — Contact Info, Identifiers, Usage Data, Diagnostics — linked to this policy.
  • Sign in with Apple: Supported where third‑party login offered; hides email via private relay.
  • Permissions Requested: Camera / Photo Library / Notifications — only when feature used, with Info.plist usage descriptions.
  • Account Deletion: In‑app “Delete Account” flow (Settings → Account → Delete) per App Store Guideline 5.1.1(v).

9.2 Android App(s) (Google Play)

  • Data Safety Section (Play Console): Declared — Personal info (name, email), App activity, Device IDs, Crash logs, Performance.
  • Permissions: Requested at runtime (CAMERA, READ_MEDIA_IMAGES, POST_NOTIFICATIONS, ACCESS_FINE_LOCATION only if feature enabled). Revocable in system settings.
  • Play Billing: Used for subscriptions/IAP; Google processes payments — I receive only purchase tokens.
  • Advertising ID: Used by Firebase Analytics for attribution; user can reset/opt‑out in Settings → Google → Ads.
  • Account Deletion: In‑app flow + web fallback URL provided in Play Console.

9.3 Web Applications (joshmon27.com, VineCrawl.com, client sites)

  • Cookies: Only essential (session, CSRF) + optional analytics (Plausible — cookieless; GA4 with consent mode v2).
  • Consent Banner: Shown to CA/EU/UK visitors (geolocation via Cloudflare cf-ipcountry header). Preference stored in localStorage + cookie.
  • Third‑Party Embeds: YouTube (no‑cookie domain), GitHub Gists, Stripe.js — governed by their policies.
  • Security Headers: Content‑Security‑Policy, Permissions‑Policy, Cross‑Origin‑Opener‑Policy, Strict‑Transport‑Security.

10. California Privacy Rights (CCPA/CPRA Summary)

CategoryCollected?Sold?Shared for Cross‑Context Behavioral Advertising?
Identifiers (name, email, IP, device ID)YesNoNo
Commercial Information (subscription, purchases)YesNoNo
Internet / Electronic Activity (usage, logs)YesNoNo
Geolocation (approx. from IP)YesNoNo
Inferences (engagement, churn risk)YesNoNo
Sensitive PI (SSN, precise geo, health, biometrics)No

Designated Request Address: privacy@joshmon27.com
Verification: Email + one additional factor (e.g., last 4 of card on file, recent login IP, or signed declaration).

11. International Data Transfers

I am based in California, USA. Your data is processed on servers in San Francisco (DigitalOcean SFO3) and Cloudflare’s global network. If you are in the EU/UK:

  • I rely on Standard Contractual Clauses (2021/914) with subprocessors.
  • No adequacy decision for the U.S. post‑Schrems II; you may withdraw consent for analytics/optional processing at any time.
  • I do not maintain an EU establishment; if Art. 27 GDPR applies to you, contact me to designate a representative.

12. Changes to This Policy

Material changes will be announced via:

  • Banner on joshmon27.com for 30 days
  • Email to registered users (if transactional/contact email on file)
  • In‑app notification (mobile apps)
  • Updated “Last Updated” date above

Continued use after the effective date constitutes acceptance.

13. Contact Information

Data Controller: Josh Walton
Address: Lompoc, CA 93436, United States
Email: privacy@joshmon27.com (also josh@joshmon27.com)
Contact Form: https://joshmon27.com/contact
Security Reports: security@joshmon27.com

Appendix A: Cookie & Storage Inventory (Web)

NameDomainTypePurposeExpiry
session_id / laravel_sessionjoshmon27.comFirst‑party cookieAuthentication sessionSession / 2 hrs
XSRF-TOKENjoshmon27.comFirst‑party cookieCSRF protectionSession
plausible_sessionjoshmon27.comlocalStorage (Plausible)Anonymous session ID (no cookie)30 min
_ga, _ga_*joshmon27.comFirst‑party cookie (GA4)Analytics (consent‑mode v2)13 months
stripe_sid, stripe_midjs.stripe.comThird‑party cookieFraud prevention (Stripe.js)1 year
__cf_bm, cf_clearancecloudflare.comThird‑party cookieBot management, WAF30 min / 1 year
sentry-sc, sentry-replayjoshmon27.comFirst‑party cookie / localStorageSession replay, error contextSession / 1 day

No advertising cookies. No third‑party tracking pixels (Facebook, TikTok, etc.).

Appendix B: Mobile Permissions Actually Requested

PermissioniOS Key / Android ManifestFeatureRequired?
CameraNSCameraUsageDescription / CAMERAProfile photo, QR scan (VineCrawl)Optional (runtime)
Photo LibraryNSPhotoLibraryUsageDescription / READ_MEDIA_IMAGESAvatar uploadOptional
NotificationsUNUserNotificationCenter / POST_NOTIFICATIONSPush alerts (Bunkie, client apps)Optional
Location (Precise)NSLocationWhenInUseUsageDescription / ACCESS_FINE_LOCATIONVineyard check‑in (VineCrawl)Optional, opt‑in
Biometric / Face IDNSFaceIDUsageDescription / USE_BIOMETRICApp unlock (client projects)Optional

No background location, microphone, contacts, SMS, or call logs.

Appendix C: Subprocessor DPA Links

SubprocessorDPA / Data Processing Addendum
DigitalOceanhttps://www.digitalocean.com/legal/data-processing-agreement
Cloudflarehttps://www.cloudflare.com/dpa/
Stripehttps://stripe.com/dpa
Sentryhttps://sentry.io/legal/dpa/
Plausible Analyticshttps://plausible.io/dpa
Google (Firebase/Analytics)https://cloud.google.com/terms/data-processing-addendum
Apple (Sign in with Apple, APNs)https://www.apple.com/legal/privacy/data-processing/
GitHub (OAuth)https://docs.github.com/en/site-policy/privacy-policies/github-data-protection-addendum
Resend / SendGridhttps://resend.com/dpa / https://sendgrid.com/dpa/

Appendix D: Deployment Notes (for you)

  • Policy URL: https://joshmon27.com/privacy (also linked in footer, app settings, App Store / Play Console)
  • Last Updated: 2026-08-07 — update this date + header on every change
  • Cookie Consent: Implemented via lightweight vanilla JS (/js/consent.js) reading/writing cookie_consent cookie + localStorage.consent; respects navigator.doNotTrack and Global Privacy Control header
  • DSAR Endpoint: POST /api/privacy/request → logs to privacy_requests table, emails you, auto‑replies with ticket ID
  • Account Deletion: DELETE /api/user/account (requires password re‑auth + TOTP if enabled) → queues job: anonymize PII, revoke tokens, cancel Stripe subscription, delete Sentry user data, send confirmation email
  • Annual Review: Calendar reminder every August 7 — review subprocessors, cookie inventory, permission list, retention schedule

This policy is tailored to your actual stack (Laravel/PHP, Vue/Alpine, DigitalOcean, Cloudflare, Stripe, Sentry, Plausible/GA4, Firebase, native iOS/Android) and your status as a California‑based sole developer/contractor. It satisfies CCPA/CPRA, CalOPPA, App Store Guideline 5.1.1, Play Console Data Safety, and baseline GDPR transparency requirements for a U.S.‑based service with incidental EU users.

Ready to publish? Drop this into a Custom HTML block on your Privacy Policy page, hit Publish, and update the privacy policy URL in App Store Connect / Play Console / footer.