Privacy · Editorial

11Tiger privacy notice

What the desk collects, what it does not, retention, third parties, jurisdiction variation and the reader’s rights.

A privacy notice written for the reader rather than for compliance theatre. Every category of data the desk collects, every category it does not, every third party with access, and the route the reader can take to request a change.

Layered privacy controls on a desktop screen as a metaphor for data discipline
A layered privacy control as a metaphor for data discipline.

What the desk collects

The desk collects three categories. Server logs: IP address, user-agent, the pages requested and the referring URL. Cookies: a session cookie for login state, an analytics cookie for aggregate traffic counts, and an affiliate-cookie set when a reader follows a partner brand link. Email submissions: the message and the email address of the sender, retained for the duration required to action the request and then deleted.

The desk does not collect the reader’s KYC documents. The desk does not collect payment-method details. The desk does not collect biometric identifiers. The desk does not collect precise-location data beyond country-level geolocation that is inherent to the IP address.

URL bar showing the partner domain, conveyed as an integrity check
Confirm the partner URL before submitting any personal information.

What the desk does not collect

The desk does not collect names, addresses, dates of birth, government-ID numbers, phone numbers, bank-account numbers, UPI handles, card numbers, card expiry dates, CVV numbers, or biometric identifiers. The desk’s pages do not request any of that data.

If a page on the desk’s site appears to request that data, the reader should confirm the partner URL against the partner’s own published domain before submitting. A mirror or a phishing page may imitate the desk’s layout without inheriting the desk’s data discipline.

Retention and deletion

13 moServer logs retained in the rolling window. Older logs are archived offline for compliance review only.
90 daysCookies expire on the close of the session or the analytics window. Re-consent is required for renewal.
Action + 30dEmail submissions retained until the request is actioned and the issue is closed. Deletion follows on request.
No KYCIdentity data is collected by the partner brand, not by the desk. The desk does not retain any KYC material.
Reading-room frame showing third-party integrations on a chart
Third-party integrations are listed on this page rather than on partner pages.

Third parties

The desk works with three categories of third party. Hosting and CDN: the page-rendering service that delivers the desk’s pages; analytics: an aggregate-traffic service that records page views, country, and referrer; affiliate network: a network that records which reader clicked which partner brand link, on a per-click basis.

The hosting and CDN provider sees server logs. The analytics provider sees aggregate traffic. The affiliate network sees per-click tracking. None of those providers sees the desk’s editorial inbox. None of them receives the desk’s subscriber list, where applicable. The desk publishes the named providers on the contact page and updates the list on the news desk when a provider changes.

Password manager next to a privacy-control panel
Reader’s controls for access and deletion.

Reader’s rights

Where the applicable data-protection law recognises a reader’s rights — access, correction, deletion, portability, restriction, objection — the desk supports them. The reader routes requests through the contact channel; the desk’s review cadence is 30 days, shorter where the law requires.

The desk does not sell the reader’s data. The desk does not share the reader’s data with a partner brand beyond the per-click affiliate trail. The desk does not honour “do not track” signals as a default because the signal is not standardised; the reader’s preferences are honoured through the cookie-consent surface instead.

Frequently asked questions

What does the desk collect from me?

Server logs, cookies, and email submissions only. The desk does not collect KYC material, payment-method details, biometric identifiers or precise-location data.

Does the desk sell my data?

No. The desk does not sell reader data. The desk’s affiliate network sees per-click tracking only.

How do I request deletion?

Send a deletion request through the contact channel. The desk’s review cadence is 30 days.

Who hosts the desk’s pages?

The hosting and CDN provider named on the contact page. The provider sees server logs only.

How do cookie preferences work?

The cookie-consent surface on the desk’s pages records the reader’s preferences. Re-consent is required for renewal.

Permissions-check frame for the privacy reading checklist.
Permissions-check frame for the privacy reading checklist.

Reading checklist

A working checklist for the reader who lands on this page from the footer to read the data discipline. The desk publishes the data categories it collects, the providers it works with and the routes for the reader’s rights; the checklist is a quick way to confirm the page is current.

Three questions to ask before submitting any personal detail. Is the partner brand’s domain the same as the desk’s named partner? Is the desk’s cookie-consent surface honouring the reader’s preferences? Is the contact channel the desk names reachable at the time the reader wants to file a request?

What the desk does well. The page separates “what the desk collects” from “what the desk does not collect” in plain language. The third-party list is named and updated on the news desk when a provider changes.

What the desk is still working on. A standing list of every named provider’s data-handling certificate link. A standing citation table for the cookie categories.

A reading cadence the desk recommends. Read the privacy notice once on a quiet afternoon. Re-read the third-party list whenever the desk announces a provider change.

A channel-checklist as a metaphor for the desk’s privacy discipline.
A channel-checklist as a metaphor for the desk’s privacy discipline.

Desk note: the desk’s cookie-consent surface

The desk exposes a cookie-consent surface on every page that loads a cookie or sets a state. The surface records the reader’s preferences and re-asks on each new consent window. The desk does not default to a “accept all” button; the surface is a real consent interaction rather than a modal that closes the moment the reader scrolls.

The three cookie categories the desk uses are a session cookie for login state, an analytics cookie for aggregate traffic and an affiliate cookie set when a reader follows a partner-brand link. The session cookie expires when the browser closes. The analytics cookie expires on the analytics window. The affiliate cookie is set and read by the affiliate-network provider.

The desk does not sell the reader’s data. The desk does not share the reader’s data with a partner brand beyond the per-click affiliate trail. Where the desk’s own analytics provider changes, the change is announced on the news desk with the effective date and the new provider’s name. Where the affiliate-network provider changes, the same cadence applies.

The reader’s rights under applicable data-protection law are honoured through the contact channel. Access, correction, deletion, portability, restriction and objection are all supported; the desk’s review cadence is 30 days, shorter where the law requires. A reader who wants to escalate a privacy request beyond the desk’s published channels can approach the appropriate data-protection authority in the reader’s jurisdiction.

Eligibility-check frame for the privacy limits section.
Eligibility-check frame for the privacy limits.

Limits of the privacy notice

The privacy notice on this page covers the desk’s editorial material only. The partner brand’s privacy notice governs the partner brand’s product offering. A reader who places a paid entry on the partner brand’s platform is governed by the partner brand’s privacy notice rather than by the desk’s.

The privacy notice covers data the desk collects directly. Data the partner brand collects is governed by the partner brand’s notice. The two documents are independent; the desk does not have visibility into the partner brand’s data-handling practices and does not publish a soft version of them.

The privacy notice is updated on the desk’s review cadence. Material changes are announced on the news desk with the effective date and a clear diff to the prior version. A reader’s continued use of the desk’s pages after an effective date is treated as acceptance of the updated notice.

Login and recovery support as part of the privacy discipline.
Login and recovery support as part of the privacy discipline.

Caveats on the privacy notice

Three caveats the desk publishes on the privacy notice. The desk’s privacy notice covers the desk’s editorial material only; the partner brand’s privacy notice governs the partner’s product offering.

The second caveat: the desk does not have visibility into the partner’s data-handling practices. The desk publishes what is verifiable from public records and links to authoritative sources rather than republishing a softer version.

The third caveat: a material change to the desk’s notice is announced on the news desk with an effective date. The reader’s rights under applicable data-protection law are honoured through the contact channel on the desk’s published cadence.

A reader who has found a discrepancy between the desk’s published notice and a partner’s published notice is welcome to send the corrections email; the next privacy-page refresh reflects the new caveat.

Budget-boundary frame for the privacy closing note.
Budget-boundary frame for the privacy closing note.

Closing note from the desk

The privacy desk closes its read with a note on the three categories of data. Server logs, cookies and email submissions. The desk does not collect KYC documents, payment-method details, biometric identifiers or precise-location data.

The three third-party categories the desk works with are hosting and CDN, analytics, and affiliate network. Each provider has a stated purpose and a stated data-disclosure boundary.

The cookie-consent surface on the desk’s pages records the reader’s preferences and re-asks on each new consent window. The desk does not default to a “accept all” button.

The reader’s rights under applicable data-protection law are honoured through the contact channel on the desk’s published cadence. The deck’s review cadence is 30 days, shorter where the law requires.

The desk’s coverage area is published on the about page. A reader who wants a different area of coverage is welcome to send a corrections email with a proposed coverage-area addition.