← back to theba.sh
Privacy Policy
Last Updated: April 2026
Overview
theba.sh ("we," "us," or "our") operates the theba.sh website and service. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services.
Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our services.
1. Information We Collect
Information You Provide Directly
- Email Address: When you subscribe to our newsletter, we collect your email address. This is optional and used solely to deliver our daily digest and weekly recap emails.
- Usage Source: When you sign up, we record where you signed up from (e.g., "daily:2026-04-14", "weekly", or "site") to understand user behavior.
- No Other Personal Data: We do not collect your name, phone number, location, or any other personal information unless you voluntarily provide it via email or contact form.
Information Collected Automatically
- Analytics Data: We use Google Analytics to understand how visitors use our site. This includes pages viewed, time spent on site, browser and device information, general location (country/region level, not precise), and referrer information. Google Analytics does not collect personally identifiable information.
- Cookies: Google Analytics uses cookies to track your session. You can disable these by using browser privacy settings or Google's browser extension.
- Server Logs: Our hosting provider (Vercel) may collect standard web server logs including IP address, request timestamp, browser user agent, and HTTP status codes. These logs are retained for a limited time and used for security and performance monitoring.
2. How We Use Your Information
- Newsletter Delivery: Your email is used only to send you daily digest emails (6 times per day), weekly recap emails (Sunday), and occasional important service announcements.
- Analytics: We analyze site usage to understand which digests are most valuable, improve site performance, and track feature usage (shares, related digests, etc.).
- Service Improvement: We may use aggregated, anonymized data to improve theba.sh.
3. Newsletter Service Provider
Newsletter emails are delivered via Buttondown (buttondown.email) or a custom email service. These services are GDPR-compliant and do not use your email for marketing purposes outside theba.sh.
4. Data Sharing
We do not sell, rent, or share your personal information with third parties. Your email is shared only with:
- Buttondown (if using their service) - for email delivery only
- Your custom email service (if configured) - for email delivery only
All service providers are contractually obligated to maintain data confidentiality.
5. Data Retention
- Email Addresses: Retained indefinitely unless you unsubscribe. You can unsubscribe from any newsletter email.
- Google Analytics: Data is retained for 14 months by default.
- Server Logs: Retained by Vercel for 3 days.
6. Your Rights
- Access: You can request what data we have about you.
- Deletion: You can request deletion of your email address from our newsletter at any time by unsubscribing.
- Data Portability: You can request a copy of your data.
- Opt-Out: You can disable Google Analytics tracking using browser privacy settings or Google's opt-out extension.
7. Security
We implement industry-standard security measures:
- HTTPS encryption for all traffic
- Security headers to prevent common attacks
- Regular security audits
- No storage of sensitive payment information
However, no security system is 100% secure. We cannot guarantee absolute security.
8. Children's Privacy
theba.sh is not directed to children under 13. We do not knowingly collect data from children. If we become aware of data collection from a child under 13, we will delete it immediately.
9. Third-Party Links
Our site may contain links to external websites. We are not responsible for their privacy practices. Please review their privacy policies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the "Last Updated" date. Continued use of the site constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
Email: hello@theba.sh
12. Compliance
This Privacy Policy complies with:
- GDPR (General Data Protection Regulation)
- CCPA (California Consumer Privacy Act)
- PIPEDA (Personal Information Protection and Electronic Documents Act)
If you are a resident of these jurisdictions, you have additional rights outlined above.