Privacy Policy

August 10, 2026

Last updated: 9 August 2026

This Privacy Policy describes how we collect, use and protect your personal data when you use the TeaTime Chinese website, its podcast platform and related services (the "Service"). It should be read together with our Terms of Use.

1. Data controller

We have not appointed a Data Protection Officer (DPO); our processing volumes do not trigger the obligation under Article 37 GDPR. You can reach us at the address above for any question about your data.

2. Personal data we process

  • Account data — email, display name, hashed password.
  • OAuth data — if you sign in with Google: profile picture, Google identifier, email provided by Google.
  • Community content — letters, comments and replies you publish.
  • Donation data — amount, currency, donor name and email, Stripe payment reference. Card numbers are handled by Stripe and never reach our servers.
  • Newsletter data — email address, opt-in timestamp.
  • Server logs — IP address, user agent, requested URL, response code, timestamp.
  • Analytics data — pages viewed, referrer, country, device and browser type, aggregated and not linked to your identity. Collected only with your consent.
  • Diagnostic data — technical error message, affected page, site version.

Your browser preferences (theme, language, audio) are stored locally on your device and are not personal data we process.

3. Purposes and legal bases

PurposeLegal basis (GDPR art. 6)
Operating the Service and your accountPerformance of a contract — art. 6(1)(b)
Processing donations and issuing receiptsPerformance of a contract — art. 6(1)(b)
Sending the newsletterConsent — art. 6(1)(a)
Website audience measurementConsent — art. 6(1)(a)
Detecting technical errorsLegitimate interest — art. 6(1)(f)
Security, fraud prevention, loggingLegitimate interest — art. 6(1)(f)
Accounting, tax and legal record-keepingLegal obligation — art. 6(1)(c)
Responding to user requestsLegitimate interest — art. 6(1)(f)

4. Recipients and processors

We share personal data only with the processors listed below, each bound by a written agreement:

  • Stripe Payments Europe Ltd. (Ireland) — payment processing.
  • Brevo SAS (France) — newsletter delivery.
  • Google Ireland Ltd. — OAuth sign-in (only if you use it).
  • Hostinger (Europe) — application and database hosting.

Our analytics (Umami) and error-tracking (GlitchTip) tools run on our own infrastructure: no data is sent to any third party for those purposes.

We do not sell, rent or trade your personal data.

5. Transfers outside the EU

Most processing takes place within the European Economic Area. Where a processor transfers data outside the EEA (for example Stripe to the United States), the transfer is covered by the European Commission's Standard Contractual Clauses or an equivalent adequacy mechanism. A copy of those safeguards is available on request.

6. Retention periods

CategoryPeriod
Account dataFor the life of the account; deleted within 30 days of closure.
Community contentUntil deleted or the account is closed; anonymised thereafter.
Donation receipts10 years from the donation, as required by accounting and tax law.
Newsletter dataUntil you unsubscribe; the address is kept on a suppression list to honour your opt-out.
Server logs30 days, unless extended for a security investigation.
Analytics data13 months, in line with the CNIL's recommendation.
Error reports90 days.

7. Cookies and trackers

Strictly necessary cookies, exempt from consent under Article 82 of the French Data Protection Act:

  • BEARER — HttpOnly, Secure, SameSite=Lax session token that keeps you signed in.
  • cc_cookie — stores your cookie choices for 6 months.

Tracker subject to your consent:

  • Audience measurement — we use Umami, self-hosted at umami.teatimechinese.com. It sets no cookies and collects no data that identifies you. It is loaded only after you agree, and sends nothing to third parties.

You can change or withdraw your consent at any time via the Cookies link in the footer of every page.

We also use GlitchTip, hosted on our own servers, to detect technical errors. It sets no cookies and records only diagnostic information — error message, affected page, site version — on the basis of our legitimate interest in keeping the Service working.

Theme, language and audio preferences are stored in your browser's local storage, on your device. We use no advertising cookies and no third-party advertising trackers.

8. Security

We implement technical and organisational measures appropriate to the risk: transport encryption (HTTPS/TLS), password hashing, HttpOnly cookies, role-based access control, regular backups and updates. In the event of a data breach posing a risk to your rights and freedoms, we will notify the competent authority within 72 hours and inform you where the law requires it (GDPR art. 33–34).

9. Your rights

Subject to applicable law, you have the following rights:

  • access to your data and to obtain a copy (art. 15);
  • rectification of inaccurate data (art. 16);
  • erasure (art. 17);
  • restriction and objection (art. 18, 21);
  • portability (art. 20);
  • withdrawal of consent at any time, without affecting the lawfulness of prior processing (art. 7);
  • instructions on what happens to your data after your death (French Act 78-17, art. 85).

To exercise these rights, write to nathan@teatimechinese.com. We respond within one month. In case of a dispute, you may lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, 75007 Paris, France, www.cnil.fr, or with the supervisory authority of your habitual residence.

10. Minors

The Service is not directed at anyone under 15 in France, 16 in EEA member states that require it, or 13 elsewhere. We do not knowingly collect personal data from minors below the applicable threshold. If you become aware that a child has provided us with data, contact us so we can delete it.

11. Automated decision-making and profiling

We do not carry out any automated decision-making producing legal or similarly significant effects concerning you, nor any profiling within the meaning of Article 22 GDPR.

12. Changes

We may update this Policy. The "Last updated" date at the top reflects the most recent version. Substantial changes are announced on the Service at least 15 days before they take effect.

13. Contact

For any question, write to nathan@teatimechinese.com.