Privacy Policy
1. Our Privacy Philosophy
The Pedal Ledger is built on a "Privacy by Design" principle. We do not use tracking cookies, we do not store IP addresses, and we do not use third-party analytics scripts (like Google Analytics).
2. Data We Collect
We process minimal, non-identifiable data to maintain the site's functionality. This includes:
- Anonymous Traffic Metrics: We count visits to pedals to determine popularity, but this data cannot be linked back to you.
- Server Logs: Standard logs (browser type, timestamp) are kept for security purposes and are purged regularly.
3. Third-Party Affiliate Tracking
When you click a price link to a retailer, you are redirected to a third-party site. These retailers (and their affiliate networks, such as Awin or Impact) will place a "tracking cookie" on your device. This cookie's sole purpose is to ensure The Pedal Ledger receives credit for the referral. You can manage these cookies through your browser settings.
4. Email Notifications
Price Alerts
When you subscribe to a price alert, we store your email address (encrypted at rest), your target price, and the pedal you're tracking. Your email is encrypted using Fernet symmetric encryption before storage.
- Verification: Before activating alerts, we send a verification email to confirm you own the address.
- Storage: Your email is encrypted at rest. We retain the minimum data needed.
- Deletion: When your price target is hit, we crypto-erase your email (overwrite with zeros) and delete the alert record. We only keep an anonymous record of "a trigger was sent for pedal X at price Y" for our analytics.
- Opt-out: Every notification includes an unsubscribe link.
Weekly Digest
The weekly digest is a separate subscription from price alerts. If you subscribe:
- Your email is stored encrypted, separate from any price alerts.
- You can unsubscribe at any time via links in any email.
- You may have both a digest subscription and active price alerts — these are independent.
5. Your Rights
Under UK GDPR and the Data (Use and Access) Act 2026, you have the right to request access to your personal data, request correction of inaccurate data, request erasure of your data ("right to be forgotten"), and object to processing.
Since price alert emails are crypto-erased upon trigger and digest subscriptions can be deleted instantly via unsubscribe links, we handle erasure requests promptly. Contact us at [email protected].