Privacy Policy
What this site collects, why, and how to reach me about it.
This covers jaystants.com and the social accounts I run under the Jaystants name. I'm the only person operating any of it — there's no team, no ad network, and no data broker relationship anywhere in this picture.
Who's responsible for this
I'm Jay Stants, and I'm the sole data controller for jaystants.com — the person who decides what gets collected and why. I'm based in the United States. If you're in the EU, UK, or Switzerland, that's the jurisdiction this site and its hosting mostly run under, though the rights described below apply to you regardless of where I am.
What this site collects
Visiting the site
Page views are measured with Cloudflare Web Analytics. It doesn't use cookies or any persistent identifier, and it can't track you across other sites — it reports aggregate numbers (how many people viewed a page, roughly where from) with nothing tying a visit back to an individual. Where a legal basis is needed for this, it's legitimate interest in understanding whether the site is reaching anyone — there's nothing here that identifies you, so most GDPR authorities don't treat this kind of measurement as personal data processing at all.
The contact form
If you submit the form at the bottom of the homepage, I collect exactly what you type: your name, email address, and message. The legal basis is straightforward — you're asking me to respond, so processing that message is necessary to do exactly that. That submission is checked by Cloudflare Turnstile to filter out bots (it loads on the homepage itself, not only at the moment you click send), then sent as an email to my own inbox through Resend, an email-delivery API. Your submitter IP address and country are included in that email for spam context — the legal basis there is my legitimate interest in not getting flooded with junk.
My own code doesn't write anything from the form to a database — the email is the only copy I keep. Cloudflare's infrastructure may retain its own short-term operational logs of the request as part of running the platform, under Cloudflare's retention policy rather than mine; I don't have a separate database or export of form submissions.
Social media integrations
I run a self-hosted publishing tool that posts to my own LinkedIn profile and my own "Jaystants - Netdevops & Network Automation" Facebook Page. Neither connection lets anyone but me post, and neither collects data about the people who see, like, or comment on what gets posted.
LinkedIn — connected under three scopes:
- openid — confirms which LinkedIn account is connected
- profile — reads basic profile info (name, photo) to identify that account
- w_member_social — publishes posts to my own LinkedIn feed
Facebook Page — connected under Meta's Graph API with these permissions:
- pages_show_list — identifies which Page belongs to my account
- pages_manage_posts — publishes, edits, and removes my own posts
- pages_manage_engagement — manages comments on my own posts
- pages_read_engagement — reads the Page's own posts, follower counts, and profile data
- read_insights — reads performance metrics for my own Page
- business_management — confirms the Page's connection to my Business Portfolio
There's no user-account system on my end for either integration, no other person can connect their own account to this tool, and nothing from it is sold, shared, or used for advertising. Once something's posted, LinkedIn and Meta are each responsible for their own platform's handling of anyone who views, likes, or comments on it — their privacy policies, not this one, cover that.
Cookies
Nothing on this site sets a cookie of my own. The only thing that comes close is Cloudflare Turnstile on the homepage's contact form, which Cloudflare documents as using short-lived, session-scoped signals rather than a persistent tracking cookie — it doesn't build a profile of you, follow you across sites, or outlive the one check it's running. Cloudflare treats this as a strictly-necessary security function, the same category as fraud prevention, which is generally exempt from cookie-consent requirements under EU law — that's my read of it, not a substitute for your own legal advice if you need certainty. Because nothing here is used for tracking or advertising, this site doesn't run a cookie-consent banner.
Where your data goes
Cloudflare and Resend act as processors here — they handle data on my instructions, for the purposes described above, and nothing more. LinkedIn and Meta are independent controllers for their own platforms once I've posted something through them.
All four are US-headquartered. If you're in the EU, UK, or Switzerland, that means your data can leave your region when it passes through them. Each one currently certifies under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions), backed by Standard Contractual Clauses if that certification ever lapses — that's the legal mechanism that's supposed to keep the protection level equivalent regardless of where the data physically sits. I don't control their certifications directly; if you want the current status, each publishes it (Cloudflare, Resend, LinkedIn, and Meta all maintain their own Data Privacy Framework and DPA pages).
Data retention
Analytics data is aggregate and not tied to individuals. Contact-form submissions aren't stored by this site at all — once the email sends, that's the only copy I keep, and it lives in my inbox under whatever retention my own email provider uses. LinkedIn and Facebook access tokens are kept only as long as each integration stays connected, and I can revoke either one at any time from that platform's own settings, which immediately cuts off access.
Your rights
Depending on where you are, you may have the right to access the data I have connected to you, correct it, have it deleted, restrict or object to how it's used, get a copy in a portable format, or — where something is based on consent — withdraw that consent. In practice, on a one-person site like this, that means: email me at the address below and I'll handle it directly. There's no automated system to route it through, so a direct email is the fastest way to get an answer.
If you're in the EU, UK, or Switzerland and think I've mishandled your data, you also have the right to lodge a complaint with your local data protection authority — you don't have to come to me first, though I'd rather you did so I can actually fix it.
Children's privacy
This site is a professional/technical portfolio and isn't directed at children. I don't knowingly collect information from anyone below the age of consent that applies where they live — as low as 13 in some countries, up to 16 in others under GDPR.
Changes to this policy
If what this site collects changes, I'll update this page and move the date at the top.
Contact
Questions about any of this: [email protected].
Looking for something else? Get in touch.