Last updated: September 26, 2026
Introduction
This website (mosessolaoke.com) is owned and operated by Moses Sola-Oke. Your privacy is important to me. This policy explains what information is collected, how it is used, and your rights regarding your data.
This policy complies with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
Scope
This policy applies to all visitors and users of mosessolaoke.com, regardless of location. If you are located in the European Economic Area (EEA), United Kingdom, or California, additional rights and protections apply to you as described in this policy.
Analytics and Tracking
This site uses a single, self-hosted analytics provider:
Umami (self-hosted, privacy-friendly, cookieless)
- Used to measure general usage (e.g., page views, referrers, device type, screen size, approximate geography at a broad level like country/region).
- Does not use cookies and does not store personally identifiable information. Visitors are not tracked individually across sessions or sites, and no cross-site identifier is set.
- Self-hosted on my own infrastructure — visit data is not shared with or processed by a third-party analytics company.
- Loaded via app-managed script in production for all visitors; it does not require a cookie-consent banner because it does not use cookies or collect personal data.
Learn more: Umami — Privacy
Data Collection and Use
Personal Information Defined
"Personal information" or "personal data" means any information that identifies, relates to, describes, or could reasonably be linked with you. This includes but is not limited to:
- Contact information: Name, email address
- Technical information: IP address (when temporarily processed), browser type, device type, screen size
- Usage data: Pages viewed, referrer sources, time on site, clicks, scrolls, and interaction patterns
- Preferences: Theme selection
What We Collect
-
Contact Forms: If you submit a contact form, your name, email, and message are collected for the purpose of responding to your inquiry. This information is not shared with third parties except as required by law.
-
Analytics Data: As described in the Analytics section, we collect anonymized usage data, including Core Web Vitals / page performance metrics, to understand how visitors use the site and improve user experience.
-
Post Interactions: When you like a blog post, a hashed identifier (derived from your IP address with a salt) is stored in our Neon PostgreSQL database along with the post slug. This allows us to track which posts you've liked and prevent duplicate likes. Raw IP addresses are not stored.
-
Cookies and Local Storage: Browser local storage is used to remember your preferences (such as theme selection). Analytics does not use cookies.
Legal Basis for Processing (GDPR)
For visitors in the EEA/UK, we process your personal data on the following legal bases:
- Legitimate interests: Anonymized, cookieless analytics; responding to contact form inquiries, improving website functionality, preventing fraud and abuse
- Legal obligation: Complying with applicable laws and regulations
Data Retention
- Contact form submissions: Retained only as long as needed to respond to your inquiry and fulfill any related request (typically 30-90 days). If you'd like a submission deleted sooner, contact me and I will remove it.
- Analytics data: Umami data is retained on my self-hosted instance and is periodically aggregated/pruned; it is never sold or shared with third parties.
Your Rights and Choices
All Visitors
- Disable cookies: You can disable cookies in your browser settings (this site's analytics does not use cookies, so this will not affect analytics).
- Contact form deletion: You may request deletion of your contact form submission by contacting me directly.
GDPR Rights (EEA/UK Visitors)
If you are located in the European Economic Area or United Kingdom, you have the following rights under GDPR:
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate personal data
- Right to erasure ("right to be forgotten"): Request deletion of your personal data in certain circumstances
- Right to restriction: Request that we restrict processing of your personal data in certain cases
- Right to data portability: Receive your personal data in a structured, machine-readable format
- Right to object: Object to processing of your personal data based on legitimate interests
- Right to lodge a complaint: File a complaint with your local data protection authority
To exercise any of these rights, contact me using the contact information at the end of this policy.
CCPA Rights (California Residents)
If you are a California resident, you have the following rights under CCPA:
- Right to know: Request disclosure of the categories and specific pieces of personal information collected, sources, purposes, and third parties with whom it's shared
- Right to delete: Request deletion of your personal data (subject to certain exceptions)
- Right to opt-out: Opt out of the "sale" of personal information (Note: We do not sell personal information)
- Right to non-discrimination: Exercise your rights without discriminatory treatment
To exercise these rights, contact me using the contact information at the end of this policy. I will respond within 45 days of receiving your request.
Data Security
I implement reasonable technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- HTTPS encryption for all data transmitted between your browser and the server
- Secure hosting infrastructure provided by Netlify
- Limited access to contact form submissions (accessible only by me)
- Regular security updates and monitoring
However, no method of transmission or storage is 100% secure. While I strive to protect your data, I cannot guarantee absolute security.
Data Breach Notification
In the unlikely event of a data breach that affects your personal information, I will:
- Notify affected individuals without undue delay (within 72 hours for GDPR)
- Describe the nature of the breach and potential consequences
- Provide information about measures taken to address the breach
- Offer recommendations to mitigate potential harm
- Notify relevant supervisory authorities as required by law
International Data Transfers
This website is hosted on servers that may be located outside your country of residence. By using this site, you acknowledge that your data may be transferred to and processed in countries that may not have the same data protection laws as your jurisdiction.
For EEA/UK visitors, data transfers to third countries are conducted in compliance with GDPR requirements, including:
- Adequacy decisions by the European Commission
- Standard contractual clauses (SCCs)
- Privacy Shield frameworks (where applicable)
Automated Decision-Making and Profiling
This website does not use automated decision-making or profiling that produces legal effects or similarly significant effects on you.
Children's Privacy
This website is not directed to children under the age of 13 (or 16 in the EEA/UK). I do not knowingly collect personal information from children. If you believe a child has provided personal information to me, please contact me immediately, and I will delete such information.
Third-Party Services
This site uses the following third-party services, each with their own privacy policies:
- Umami — Self-hosted, privacy-friendly, cookieless analytics, including anonymized Core Web Vitals / page performance metrics; loaded via app-managed script for all visitors
- Netlify — Hosting provider and serverless functions
- Neon — PostgreSQL database for post interactions (likes, views)
- Data stored: Post slugs, hashed user identifiers (derived from IP addresses), like/view counts
- Raw IP addresses are not stored; instead, IP addresses are hashed with a salt before being stored
- Neon Privacy Policy
I am not responsible for the privacy practices of these third-party services. I encourage you to review their privacy policies.
Do Not Sell My Personal Information
I do not sell, rent, or trade your personal information to third parties. This site does not engage in the sale of personal data as defined by CCPA or other privacy laws.
Changes to This Policy
I may update this privacy policy from time to time to reflect changes in practices, technology, legal requirements, or other factors. When I make material changes, I will update the "Last updated" date at the top of this policy.
Your continued use of the site after changes are posted constitutes your acceptance of the updated policy. I encourage you to review this policy periodically.
Contact
For questions, concerns, or to exercise your rights regarding this privacy policy or your personal data, please contact me:
- Via contact form: Use the contact form on this website
- Email: Available through the contact form
- Response time: I will respond to privacy-related inquiries within 30 days (or as required by applicable law)
Data Protection Officer
As a small personal website, I do not have a dedicated Data Protection Officer. All privacy-related inquiries should be directed to me as the site owner using the contact information above.
Supervisory Authority
If you are located in the EEA/UK and believe I have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
Last reviewed: September 26, 2026
This privacy policy is effective as of the date listed above and governs all use of this website.