Last updated: September 2026
At Web Tactics, your privacy is fundamental. This policy explains what information we collect when you visit our website or contact us, how we use it, and how we protect it.
We collect information you provide directly to us, including:
We also collect certain technical data automatically when you visit our website, such as your browser type, device type, pages visited, and approximate geographic location. This data is used solely to improve site performance.
We use the information we collect to:
We do not sell, rent, or trade your personal information to third parties.
Contact form and newsletter submissions are processed through Web3Forms, a secure third-party form service. Your data is stored on their encrypted servers in accordance with their privacy standards.
We implement industry-standard security measures to protect your information. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
Our website uses minimal cookies — primarily technical session data to ensure the site functions properly (such as your audio preference). We do not use advertising or tracking cookies.
By using our website, you consent to the use of these essential cookies.
Our website may include links to third-party platforms (Instagram, LinkedIn, YouTube). We are not responsible for the privacy practices of these external sites and encourage you to review their privacy policies.
We use Google Fonts to render typography on this site. This involves requests to Google's servers and is subject to Google's privacy policy.
Payments — Stripe. Online payments on our shop are processed by Stripe Payments Europe Ltd. When you complete a purchase, your payment details (card number, expiry, CVC, billing address) are collected directly by Stripe — we never see or store your full card details. Stripe shares with us only the order metadata required to fulfil your purchase: name, email, phone, billing country, amount, and a Stripe order reference. Stripe's privacy policy is available at stripe.com/privacy.
Advertising — Meta Pixel & Conversions API. We use the Meta (Facebook) Pixel and the server-side Conversions API to measure the performance of our advertising campaigns and to build retargeting and lookalike audiences. This may include sending Meta hashed (non-reversible SHA-256) versions of your email and phone number when you submit a form or make a purchase, along with anonymous identifiers (cookies, IP address, user-agent) and event data such as page views, scroll depth, and clicks. Meta's data policy is available at facebook.com/policy.php. You can opt out of personalised advertising at facebook.com/adpreferences.
Poster is the internal Web Tactics tool that publishes our own videos to our own YouTube channels. It is described at webtactics.org/poster. Poster uses YouTube API Services, and by operating it we agree to be bound by the YouTube Terms of Service. Google's own handling of data is described in the Google Privacy Policy.
Who uses it. One person: the owner of Web Tactics. There is no public sign-up and no third-party access. The only YouTube accounts Poster can reach are the channels owned and operated by Web Tactics, each authorised individually by that owner.
What it accesses. Through Google's OAuth 2.0 consent screen, Poster is granted permission to upload videos to a channel, set their titles, descriptions, tags and thumbnails, and add them to that channel's playlists. It reads the channel's own title and playlist list to do so. It does not read comments, subscriber data, analytics, or anything about other users or channels.
What it stores, and where. The OAuth token for each channel is stored only on the operator's own computer, in plain files, and is used solely to perform the uploads described above. Poster keeps a local log of what it uploaded (video id, title, time) so the same video is never uploaded twice. No YouTube data is stored on any server, shared with any third party, or used for advertising or profiling.
Retention and deletion. Tokens are refreshed by Google as they expire and are deleted from the operator's machine when a channel is disconnected. Authorisation can be revoked at any time from the Google security settings page; once revoked, Poster can no longer reach that channel and any stored token for it becomes unusable and is removed. To request deletion of any locally stored data, contact bashar@webtactics.org.
You have the right to:
To exercise any of these rights, contact us at info@webtactics.org.
We may update this privacy policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. We encourage you to review this page periodically.
If you have any questions about this privacy policy or how we handle your data, please contact us: