THEOXERThe Oxer — home
Legal

Legal and privacy

Who publishes The Oxer, and what happens to your data. The short version: we collect an email address, only if you give us one, and the site sets no cookies at all.

Last updated — 18 August 2026

Who we are

The Oxer is published by Data Forage Limited, a company registered in England and Wales (company no. 12944938). Registered office: 20a High Street, Glastonbury, BA6 9DU.

Data Forage Limited is the data controller for the personal data described below. For anything on this page, including any request about your data, email [email protected].

What we collect

The email roundup. If you give us your address we collect it, so we can send you the roundup and for nothing else. The lawful basis is your consent.

We confirm the address before we use it. Subscribing sends one email asking you to confirm, and nothing is added to the list until you follow that link. If you did not ask to subscribe, ignoring that email is enough — the request goes nowhere. This is also why we cannot be used to sign someone else up.

The roundup is not sending yet. The signup will tell you so plainly if you try it before we open, rather than taking an address and doing nothing with it.

Email you send us. If you write to us — a pitch, a partnership enquiry, anything — we hold your address and what you wrote so we can deal with it. The lawful basis is our legitimate interest in answering our correspondence.

Server logs. Our hosting keeps ordinary request logs, which include IP addresses, to keep the site running and to investigate abuse. The lawful basis is our legitimate interest in a secure, working site. They are kept briefly and are not used to build any profile of you.

What we do not collect

This is the more useful half of the list, so it is specific rather than reassuring.

No cookies. The site sets none. That is why there is no cookie banner — not because we have hidden the choice, but because there is nothing to consent to.

No analytics, advertising or tracking. No Google Analytics, no advertising pixels, no session recording, no fingerprinting. We build no profile of you and cannot tell one visit from another. The one exception is the server logs described above, which record requested paths against an IP address for a short period so the site can be kept running and abuse investigated.

No accounts. There is nothing to sign up for except the roundup, and no password to store.

No third-party requests from your browser. The typefaces are served from our own servers rather than a font service, and the photographs in the feed are fetched by us and passed on, rather than loaded from Instagram by you. Reading this site tells no one else that you were here. Following a link to a post on Instagram does, at which point Instagram’s own terms apply.

Who we share it with

We do not sell your data, and we do not share it for advertising.

Two processors handle roundup data on our instructions and for no purpose of their own: Cloudflare, which stores the subscriber list, and Amazon Web Services, which delivers the email. Our hosting provider processes server logs on the same basis. Beyond that, we share personal data only where the law requires it.

Where a provider is outside the UK or EEA, we rely on an approved transfer mechanism such as the UK International Data Transfer Agreement or Addendum.

How long we keep it

Roundup addresses: until you unsubscribe, or until the roundup ends. Unsubscribing does not delete the row — we keep a record that you asked not to be mailed, because a deleted address can be added again by anyone, and that record is what stops it. An address that never confirms is never on the list. Email correspondence: as long as the matter needs. Server logs: a short period, then discarded.

Your rights

Under UK data protection law you can ask us for a copy of your personal data, ask us to correct or delete it, ask us to restrict or stop processing it, object to processing, and ask for it in a portable form. Where we rely on consent you can withdraw it at any time.

Email [email protected] and we will deal with it. If we get it wrong you can complain to the Information Commissioner’s Office at ico.org.uk, though we would rather you gave us the chance to put it right first.

Children

The site is not directed at children, and we do not knowingly collect personal data from anyone under 13. If you believe a child has given us their details, email us and we will delete them.

Security

The site is served over HTTPS. The strongest protection here is how little we hold: there is no account database to breach, no payment details, and — while no card details, and no personal data beyond a list of email addresses.

Changes to this page

If this page changes in substance we will update the date at the top of it. Continuing to use the site after that means you accept the change.