This policy explains what NewCookware collects when you visit newcookware.com, why it is collected, who else can see it, and what you can ask us to do about it. It is written to be read rather than to be skimmed past, so it names the actual systems involved instead of describing them in the abstract.
NewCookware is a publisher of appliance research, not a store. You cannot open an account here or check out here, and we never ask for a payment card, a bank detail or a delivery address. If a page appears to ask you for one, it is not ours.
What we collect
Information you type into the contact form
The contact page carries a form built with the Contact Form 7 plugin. When you submit it, the message is emailed to us and a copy is also saved into this website’s own database by a companion plugin (Contact Form DB, commonly called CFDB7). That stored copy includes whatever you put in the fields: your name if you give one, your email address, the subject and the body of your message. It may also include the date and time of submission and technical details captured with it.
Please do not put anything sensitive into that form. It is a plain website database, not a secure messaging system. Never send us financial details, government identification numbers, health information or passwords. If you need to tell us something confidential, do not use the form.
Server access logs
Like effectively every website, the web server records each request it serves. A typical log line contains your IP address, the date and time, the page requested, the response code, the referring page if there is one, and your browser’s user agent string. These logs are generated automatically and are used to keep the site running, investigate errors, and identify abusive traffic such as scrapers and brute-force attempts. A bot protection layer reads the same signals for the same purpose.
Analytics
The site runs its own analytics rather than a third-party advertising network. A small script records page views, the path you visited, the referring source, approximate device and browser type, language, and clicks on outbound product links. Those events go to an analytics service operated by the same people who run this site. To recognize a returning visitor and avoid counting one person as several, the script stores a random identifier in your browser, using local storage and a first-party cookie. That identifier is a random string, not your name, and it is tied to no account, because there are no accounts here.
Your IP address is visible to the analytics endpoint as part of any ordinary web request, and it is used for coarse geographic and anti-abuse purposes rather than to build a profile of you. We do not sell analytics data, we do not run behavioral advertising, and we do not operate an advertising exchange.
Cookies and similar storage
WordPress sets cookies in some circumstances, particularly for logged-in administrators, and the WooCommerce components that render the product pages may set session and cart cookies even though nothing can be bought here. The caching layer that serves pages quickly uses cookies to decide which cached version you receive. The analytics script sets the identifier described above, and the outbound link handler sets a first-party cookie so a click can be matched to a later event. Full detail, including how to control this in your browser, is on the cookie policy page.
What happens when you leave for Amazon
When you click a product button, you leave this site. The click may pass through a redirect on a domain we operate, which attaches affiliate tracking information, and you then land on Amazon. From that moment Amazon’s own privacy policy applies, not this one. Amazon sets its own cookies, applies its own tracking and advertising, and collects whatever it collects. We do not control any of it, we cannot switch it off for you, and we cannot see your Amazon account, your basket or your order. What we may eventually see is an aggregated commission report saying a purchase occurred. It does not name you. Read the details on the affiliate disclosure page.
Why we are allowed to process this
Where the UK GDPR or the EU GDPR applies to you, our legal bases are these. Server logs, security measures and aggregate audience measurement rest on our legitimate interest in keeping the site available, secure and worth publishing. Handling a message you sent us rests on our legitimate interest in answering correspondence, and on taking steps at your request. Any non-essential storage on your device, including the analytics identifier, rests on your consent, which you can withdraw at any time through your browser settings as described in the cookie policy. We do not process special category data, and we ask you not to send us any.
Who else sees it
The site runs on a rented server operated by a hosting provider, which necessarily processes everything the site stores. A content delivery and security network may sit in front of the site and see requests passing through. Email from the contact form travels through a mail provider. The analytics service receives the analytics events. Amazon receives you once you follow an outbound link. We do not sell personal information, rent mailing lists, or share your details with manufacturers or retailers.
Some of these providers operate servers outside your own country, including in the United States. Where a transfer of that kind involves personal data protected by the GDPR, it relies on the transfer mechanisms those providers put in place, such as standard contractual clauses.
How long it is kept
We will be honest about this rather than quote a number we cannot enforce. Contact form submissions stay in the site database until they are deleted, and we clear out old correspondence periodically rather than on a fixed schedule. Server access logs rotate on whatever cycle the hosting stack is configured for, which is typically a matter of weeks, and we do not control that timetable directly. Analytics events are retained in aggregate for as long as they remain useful for understanding what people read. Cookies expire on the schedule set out in the cookie policy, and the outbound click cookie can persist for up to two years unless you clear it.
If you ask us to delete a message you sent, we will delete it, and that is a commitment we can actually keep.
Children
This site is written for adults buying household appliances. It is not directed at children and we do not knowingly collect personal information from anyone under 16. If you believe a child has sent us a message through the contact form, write to us and we will delete it.
Your rights
If the GDPR applies to you, you have the right to ask what we hold about you, to have inaccurate information corrected, to have information erased, to restrict or object to processing, to receive a portable copy of information you provided, and to withdraw consent at any time. You also have the right to complain to your national data protection authority.
If you are a California resident, the CCPA and CPRA give you the right to know what categories of personal information have been collected and the purposes for collection, to request deletion, to request correction, and to be free from discrimination for exercising those rights. You also have the right to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined in California law, so there is nothing to opt out of, but the right stands regardless.
Making a request
Write to [email protected] with PRIVACY in the subject line and tell us what you want done. Because we hold no accounts, the practical way to find your data is the email address you originally wrote from, so use it if you can. We will respond within the period the applicable law allows, normally one month. If we cannot identify any data belonging to you, we will say so rather than guess.
Changes to this policy
Sites change, plugins change, and this policy is updated when they do. The current version is the one published on this page, and continuing to use the site means you accept it.