Privacy Policy
Effective Date: February 1, 2026
Summary (In Plain English)
- We collect only the information needed to run this site and its features.
- We do not sell personal data and do not use advertising networks.
- We do not run Google Analytics.
- We use secure authentication practices and industry-standard encryption.
- Analytics and non-essential data collection occur only with your consent.
- You can access, update, or delete your account at any time.
- If you are in the EU or California, you have additional rights described below.
1. Scope and Definitions
This Privacy Policy applies to Happy Clam LLC and the website located at happyclamllc.com, including associated subdomains and application services operated by Happy Clam LLC (collectively, the "Site").
- Personal Information / Personal Data
- means information that identifies or reasonably relates to an identifiable person.
- Account Data
- refers to information provided when registering or managing an account.
- User Content
- refers to comments, ratings, or other material you submit.
- Service Providers
- are third-party vendors who process data solely to operate the Site.
2. Information We Collect
A. Information You Provide
Account Information
- First name, last name, and email address.
- Password (stored only as a one-way bcrypt hash, 12 rounds; never in plain text).
- Profile preferences (e.g., theme, language, cookie consent preferences).
User-Generated Content
- Photo comments (content, timestamps, reply/thread relationships).
- Photo ratings (1–5 stars).
- Article comments and ratings.
B. Automatically Collected Information
Security and Authentication Data
- Login IP address (temporarily processed for security).
- Login timestamps.
- Failed login attempt counts.
- Account lockout events.
Technical Context
- Browser type and version.
- Viewport size.
- Referrer information.
- UTM parameters.
- Session identifiers.
Analytics (With Consent Only)
- Page views.
- Scroll depth.
- Time on page.
- Approximate location (country/city derived from IP).
- Device and browser category.
For analytics, IP addresses are hashed before storage. Raw IP addresses may be briefly processed in memory for rate limiting, security, or geolocation lookups but are not stored in plain form for analytics purposes.
3. Legal Bases for Processing (EU Residents)
If you are located in the European Economic Area (EEA), we rely on the following lawful bases:
- Contract: To create and maintain your account.
- Legitimate Interests: To secure the Site, prevent abuse, and improve functionality.
- Consent: For optional analytics cookies and non-essential tracking.
- Legal Obligation: Where required by applicable law.
4. Cookies and Consent
We use only two cookies:
For logged-in users, cookie preferences are also stored with your account so they apply across devices and survive cache clears.
We do not use advertising cookies or third-party marketing trackers.
Analytics tracking occurs only if consent is granted via the “Manage Cookies” link in the footer.
5. How We Use Information
We use information to:
- Authenticate users and protect accounts.
- Provide account features (profiles, comments, ratings).
- Improve site functionality (if analytics consent is granted).
- Send transactional emails (account activation, password reset, account notices).
- Detect and prevent unauthorized access or abuse.
We do not send marketing emails.
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
6. Data Sharing and Disclosures
We do not sell personal information.
We do not share personal information for third-party marketing.
We share data only with the following service providers, solely to operate the Site:
- Resend — transactional email delivery.
- MongoDB Atlas — database hosting.
- AWS S3 — image and asset storage.
- AWS CloudWatch — infrastructure monitoring.
- Sentry — error tracking (may include request metadata such as URL, user agent, and error context; sensitive fields are scrubbed where applicable).
- geoip-lite — local IP geolocation lookup (IP not sent to external API).
We may also disclose information:
- To comply with legal obligations or lawful requests.
- To protect the rights, safety, or security of users or the Site.
- In connection with a business transfer (e.g., merger or acquisition).
- With your explicit direction.
7. Data Retention
We retain data only as long as necessary for operational, security, and legal purposes.
- Account Data: Retained while your account is active. Upon deletion request, identifying fields are anonymized within 30 days.
- User Content: Retained until deleted by you or your account is deleted.
- Security Logs: Retained for up to 90–180 days for fraud prevention and audit.
- Analytics Data: Retained for 90 days, then purged.
- Backups: May persist for up to 30 days before rotation.
Anonymized or aggregated data may be retained longer.
8. How We Protect Information
- Passwords are hashed using bcrypt (12 rounds).
- All traffic is encrypted via HTTPS.
- Session tokens are stored in HttpOnly cookies.
- Accounts are locked after repeated failed login attempts.
- Analytics IP addresses are hashed before storage.
- Access to production systems is restricted.
While we use industry-standard safeguards, no system can guarantee absolute security.
9. International Data Transfers
Our infrastructure may be hosted in the United States or other jurisdictions depending on service provider configuration.
If you access the Site from outside the United States, your information may be transferred to and processed in the United States.
Where applicable, we rely on service provider safeguards for cross-border data transfers.
10. Your Rights and Choices
Account Controls
You may:
- Access and update your profile in account settings.
- Delete your account using the deletion endpoint.
- Edit or delete your comments at any time.
- Manage analytics consent via the footer.
Account Deletion
Deletion is implemented as a soft-delete:
- Identifying fields (name, email) are anonymized.
- Minimal audit records may be retained for integrity and abuse prevention.
- Permanent hard deletion may occur during maintenance cycles.
GDPR (EU Residents)
You have the right to:
- Access your data.
- Rectify inaccuracies.
- Erase personal data.
- Restrict processing.
- Object to processing.
- Request data portability.
To exercise these rights, email derrick@happyclamllc.com. We will respond within 30 days.
CCPA (California Residents)
You have the right to:
- Know what personal information is collected.
- Request deletion.
- Opt out of sale (we do not sell personal data).
To submit a request, email derrick@happyclamllc.com. We may verify your identity before fulfilling requests.
11. Do Not Track
For optional analytics and cookie consent, we respect the browser “Do Not Track” (DNT) signal. When DNT is enabled, analytics will not run regardless of cookie consent.
12. Links to Other Sites
The Site may contain links to external websites. We are not responsible for the privacy practices of those third parties.
13. Children’s Privacy
The Site is not directed to children under 13. We do not knowingly collect personal information from children under 13.
14. Changes to This Policy
We may update this Privacy Policy from time to time. The Effective Date at the top reflects the latest revision. Material changes will be noted on this page.
For the rules that govern use of this site, please also review our Terms of Service .
15. Contact
For privacy-related questions or requests:
Derrick Meade
Happy Clam LLC
Email: derrick@happyclamllc.com
