Legal
Privacy notice
Version 1.0 · Last updated 25 August 2026
Happy Book Mail (“we”, “us”) operates happybookmail.com and the Happy Book Mail newsletter. We apply one conservative global standard to everyone, rather than weaker country-by-country defaults. This notice explains what we collect, why, and the choices you have.
1. Who is responsible
The data controller is Happy Book Mail, reachable at privacy@happybookmail.com (or hello@happybookmail.com for anything else). Formal legal entity details are added to this section as commercial operations scale.
2. What we collect and why
| Data | Purpose | Basis |
|---|---|---|
| Email address (readers) | Send the newsletter you asked for; double opt-in proof; suppress bounces/complaints | Consent (you subscribed and confirmed) |
| Reading preferences (genres, moods, formats, frequency) | Improve relevance of issues; all fields optional; editable any time | Consent |
| Consent records (timestamp, source page, notice version) | Prove permission-based sending; honor revocations | Legitimate interest (legal compliance) |
| Author submission data (contact details, book metadata, links) | Review submissions, communicate decisions, deliver and report campaigns | Contract / legitimate interest |
| Pseudonymous click events (redirect token, time, coarse browser hint) | Aggregate, bot-filtered measurement of which recommendations readers act on | Legitimate interest; minimized — no raw email in URLs or analytics |
| Security logs (short-lived, may include IP) | Abuse prevention, rate limiting, incident response | Legitimate interest |
We do not buy, scrape, or auto-enroll email lists. We launch for adults (18+) and do not knowingly collect children's data.
3. Vendors
We use a newsletter/email delivery provider (e.g. Kit), a transactional email sender (e.g. Resend), a managed database host, and web hosting/CDN. Each receives only the data needed for its function under written agreements. When we add or change a vendor that processes personal data, we update this section and our internal vendor list.
4. Cookies & measurement
The public site works without marketing cookies. We use privacy-minimized first-party measurement (aggregate counts of issue/book interactions via our redirect service) and do not run cross-site advertising trackers. Where local law requires consent for non-essential cookies, we ask before setting them, and essential functions keep working if you decline.
5. Retention
- Active subscriber data: until you unsubscribe, then kept only as suppression/consent evidence.
- Consent records: kept as long as needed to prove permission (append-only).
- Submissions: retained for editorial history; deleted or anonymized on request unless needed for an active campaign or dispute.
- Click events: pseudonymous and aggregated; raw events pruned on a documented schedule.
- Security logs: short-lived (days to weeks).
6. Your rights
Wherever you live, you can: get a copy of your data, correct it, delete it, object to processing, withdraw consent (unsubscribe), and complain to a regulator if you have one. Email privacy@happybookmail.com — we acknowledge within 3 business days and aim to fully resolve requests within the legally required period for your jurisdiction. You never need to create an account to exercise any right.
7. Transfers
We operate globally; providers may process data in the United States and other countries. We rely on provider safeguards (such as standard contractual clauses) and minimize what crosses borders in the first place.
8. Changes
Material changes are announced in the newsletter and dated here. If a change needs new consent, we ask for it.
This notice is our implementation baseline; it is not legal advice, and final policies are reviewed with counsel before commercial scale.