Privacy Policy
Last updated: February 11, 2026
Introduction
Thank you for visiting andresromeroarcas.com ("the Website"). This Privacy Policy explains how I collect, use, store, and protect your personal information when you use this website. Your privacy is important to me, and I am committed to protecting your personal data in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
By using this website, you consent to the data practices described in this policy.
1. Information I Collect
I collect the following types of information when you interact with this website:
1.1 Information You Provide Directly
- Contact Form: When you submit the contact form, I collect your name, email address, subject, and message content.
- Newsletter Subscription: When you subscribe to my newsletter, I collect your email address and optionally your first name.
- Free Resource Subscription: When you sign up for free resources, I collect your email address and name.
1.2 Information Collected Automatically
- IP Address: Your IP address is collected automatically for rate limiting and security purposes.
- Browser Information: User agent data (browser type, version, operating system) is collected for technical purposes.
- Theme Preference: Your light/dark mode preference is stored locally in your browser using localStorage.
1.3 Cookies and Similar Technologies
This website uses localStorage (a browser storage mechanism similar to cookies) to remember your theme preference (light or dark mode). This is considered a functional storage mechanism and is essential for providing you with a personalized experience.
I do not use tracking cookies, advertising cookies, or third-party analytics cookies. For more details, please see my Cookie Policy.
2. How I Use Your Information
I use the information I collect for the following purposes:
- Communication: To respond to your inquiries submitted through the contact form.
- Newsletter: To send you email newsletters and updates about my work (only if you subscribe).
- Free Resources: To provide you with access to free resources and materials you've requested.
- Security & Rate Limiting: To protect the website from abuse, spam, and malicious activity using IP address-based rate limiting.
- User Experience: To remember your theme preference and provide a better browsing experience.
3. Legal Basis for Processing (GDPR)
If you are located in the European Union, I process your personal data based on the following legal grounds:
- Consent: When you subscribe to my newsletter or submit forms, you provide explicit consent for data processing.
- Legitimate Interest: I have a legitimate interest in responding to your inquiries and protecting my website from abuse.
- Contract: When you request free resources, processing is necessary to fulfill that request.
4. Third-Party Services
I use the following third-party services that may access or process your personal information. Each service has its own privacy policy:
4.1 Email & Newsletter Services
- Beehiiv: Used for email newsletter delivery. Privacy Policy
- Resend: Used for transactional email delivery (contact form notifications). Privacy Policy
4.2 Data Storage
- Notion: Contact form submissions are stored in a Notion database. Privacy Policy
- Supabase: Free resource subscriber data is stored in a Supabase database. Privacy Policy
4.3 Font Delivery
- Google Fonts: Fonts are loaded from Google's servers. Google may collect usage data. Privacy Policy
Note: These third-party services may store data on servers located outside your country, including in the United States. By using this website, you consent to this international data transfer.
5. Data Retention
I retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy:
- Contact Form Data: Stored indefinitely in Notion for record-keeping unless you request deletion.
- Newsletter Subscriptions: Retained until you unsubscribe from the newsletter.
- Free Resource Subscriptions: Retained in Supabase until you request deletion.
- IP Address Logs: Used temporarily for rate limiting and not permanently stored.
- Theme Preference: Stored in your browser's localStorage indefinitely until you clear browser data.
6. Your Rights
Under GDPR, CCPA, and other data protection laws, you have the following rights regarding your personal data:
- Right to Access: You can request a copy of the personal data I hold about you.
- Right to Rectification: You can request correction of inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten"): You can request deletion of your personal data.
- Right to Restrict Processing: You can request that I limit how I use your data.
- Right to Data Portability: You can request your data in a structured, machine-readable format.
- Right to Object: You can object to certain types of processing, including direct marketing.
- Right to Withdraw Consent: You can withdraw your consent at any time (for newsletter, unsubscribe via email link).
To exercise any of these rights, please contact me at: andres.romero.arcas@gmail.com
I will respond to your request within 30 days.
7. Security
I take the security of your personal information seriously and implement appropriate technical and organizational measures to protect it from unauthorized access, disclosure, alteration, or destruction. These measures include:
- HTTPS encryption for all data transmitted to and from the website
- Rate limiting to prevent abuse and spam
- Secure third-party services with industry-standard security practices
- Regular security updates and monitoring
However, no method of transmission over the internet or electronic storage is 100% secure. While I strive to protect your data, I cannot guarantee absolute security.
8. Children's Privacy
This website is not intended for children under the age of 16. I do not knowingly collect personal information from children. If you believe I have inadvertently collected data from a child, please contact me immediately, and I will take steps to delete such information.
9. International Data Transfers
Your personal information may be transferred to and processed in countries outside your country of residence, including the United States, where data protection laws may differ. By using this website, you consent to such transfers.
I ensure that any international data transfers comply with applicable legal requirements, including the use of Standard Contractual Clauses where necessary.
10. Changes to This Privacy Policy
I may update this Privacy Policy from time to time to reflect changes in my practices or legal requirements. When I make significant changes, I will update the "Last updated" date at the top of this page.
I encourage you to review this Privacy Policy periodically to stay informed about how I protect your information.
11. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or how I handle your personal data, please contact me:
- Email: andres.romero.arcas@gmail.com
- Website: andresromeroarcas.com
12. Complaints
If you are located in the European Union and believe that I have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority.