— I — Who we are.
GUSTUX ("we", "us", "the magazine") is a small membership publication operated by GUSTUX LLC. We're the data controller for the information described in this policy.
Our office is in the United States. Our membership is global. We've drafted this policy to align with GDPR, CCPA, and the principles we'd want anyone collecting our data to follow.
— II — What we collect.
When you visit the public site.
Standard server logs (IP address, user agent, page requested, timestamp) kept for 30 days, then deleted. We don't keep these for analytics; we keep them for security and debugging.
When you apply.
Everything you put in the application form: name, email, the prose you write, your travel background. The editors read it; that's the whole point.
When you become a member.
- Your account details (name, email, password hash, billing info handled by our payment processor — we never see your card number).
- Your journal entries, photos, atlas pins, routes, and any notes you keep in the GUSTUX Journal.
- Messages and dispatches you post in The Hall or file to the magazine.
- Settings — your theme, language, notification preferences.
— III — Why we collect it.
The honest list:
- To run your account. Email goes with the account; password lets you in; billing lets us send the magazine.
- To make the app work. Your journal needs to sync; the cost archive needs your contributions; the routes need somewhere to live.
- To run the magazine. Bylines need names. The Annual goes to a mailing address. Pitches and notes need to be readable by editors.
- To stop abuse. Logs and rate limits keep the chat civil and the application form from being spam-bombed.
We do not collect data to "improve your experience" via behavioural targeting. We don't have behavioural targeting.
— IV — How we store it.
Account data and journal content live on managed databases hosted in the US and EU (depending on where you sign up). Backups are encrypted at rest and rotated every 7 days, kept 30 days, then deleted.
Photos are stored in object storage with the same encryption posture. Photo originals are kept; thumbnails are derived.
Passwords are hashed with bcrypt; we never see the plaintext. Resetting requires email access — we'll never ask for your password.
— V — What we share, and don't.
We do not sell your data. Not to advertisers, not to data brokers, not to "marketing partners," not to anyone.
We use the following sub-processors, each for a specific operational purpose:
- Supabase — auth and database hosting
- Stripe — payments (they see card details; we don't)
- Postmark / SendGrid — transactional email (sign-in links, replies)
- Cloudflare — CDN and DDoS protection
Each sub-processor sees only the data needed for its function. None of them are allowed to use it for their own purposes. Contracts include GDPR-standard data processing terms.
If we ever change this list, we'll update this page and email members.
— VI — Cookies and tracking.
We use cookies for two things:
- Keeping you signed in (a session cookie).
- Remembering your theme and language preferences.
No analytics cookies. No third-party trackers. No pixels. The site loads zero third-party scripts beyond Google Fonts (which we serve over a privacy-conscious domain).
— VII — Your rights.
Regardless of where you live, you have the following rights with respect to your data:
- Access — ask us what we have on you.
- Export — download everything in a portable format (one click in your settings).
- Correct — fix anything that's wrong.
- Delete — remove your account and everything in it.
- Object — tell us to stop processing your data in any specific way.
- Complain — to a supervisory authority (your local data protection regulator) if you think we've stepped over the line.
Use settings inside the app for export and deletion. For anything else, email [email protected] — a real person reads it.
— VIII — Children.
GUSTUX is for adults. We do not knowingly collect data from anyone under 18. If you're a parent and believe your child has signed up, write to us and we'll delete the account.
— IX — International transfers.
If you sign up from outside the US, your data may be transferred to and stored on servers in the US. Where that happens, we rely on Standard Contractual Clauses and the EU-US Data Privacy Framework. You can object to this transfer by emailing us, and we'll discuss alternatives.
— X — Changes to this policy.
We may update this policy from time to time. If we make a material change, we'll email members before it takes effect and post a notice at the top of this page for 30 days. The version number and effective date at the top of this page will always reflect the current state.
— XI — Get in touch.
Privacy questions, concerns, or requests: [email protected]
For everything else: the contact form
Mailing address: GUSTUX LLC, [address forthcoming], United States.