diff --git a/templates/privacy.html b/templates/privacy.html index c7adee7..d1de9f6 100644 --- a/templates/privacy.html +++ b/templates/privacy.html @@ -1,411 +1,13 @@ {{define "privacy-policy"}} -{{template "layout-page-start" (args "Title" "Privacy Policy")}} +{{template "layout-page-start" (args "Title" .Title)}} +
Capytal Icon -

About

-

Privacy Policy

-

- This privacy policy describes how Capytal ("capytal.cc", "we", "us", "Capytal.cc") may collect - personal information and to what degree when you use our websites and services ("Services"), such - as when you: -

-
- Too Long; Didn't Read (TL;DR) -

- Our services are developed by people who care about privacy and do not like to have their - personal and identifiable data tracked by analytics tools without their consent. - We try our best to keep our services in line with regulations such as - GDPR, - - LGDP, and CCPA, while still providing - useful data to understand our users and their priorities. The only type of data collected by our - tracking scripts are: -

-
    -
  • Pages that you visit;
  • -
  • Referrer URL;
  • -
  • Operating system, browser type and device (User-Agent header);
  • -
  • Preferred language (Accept-Language header);
  • -
  • Timezone-based location (this limits us to just know the country configured in your system);
  • -
  • Accessibility settings;
  • -
  • Additional metadata about the pages you visit;
  • -
-

- We do not use cookies to track these informations, we cannot and do not want to - be able to associate an user to any of the said data. The data collected by us is mostly used - to understand things such as what operating system we must prioritize support, what accessibility - concerns we should take care of more, and what languages we should focus on supporting in our - services and websites. -

-

- We do not share any of this data to any third-party, any data provided to us - stay with us and it is used just between us and our first-party services. Any shared data - is due to integrations such as embedded or referred content (for example, YouTube embedded videos). -

-
-

What we collect automatically by default

-

- Capytal.cc by default do not collect any personally-identifiable information on our Services, IP addresses - may or may not appear on automatically-generated log files but these automatically-generated log files - are deleted after every 48 hours. -

-

- Your browser or system may or may not send additional information such as user-agents that we may - automatically collect to provide useful analytics to our developers and administrators. -

-

- We use a self-hosted and self-managed script and analytics tool - (Medama) - to provide us additional data on how you interact with our Services. All analytical - data by default is anonymised, accessed in bulk, and cannot be pointed to you - or any other specific user of our Services, regardless of if you are registered in one of our - Services or not. We DO NOT USE Cookies, IP addresses, and technologies like local storage, - session cookies, IP addresses hashing to collect additional data about you by default, - however, we may use said technologies to provide core functionality on our Services, such data - in most cases is by default not personally-identifiable or used to track you or specific users. -

-

- The following information is collected to provide us analytical data: -

-
-
- Page Events -
-
- When you access or exits a page in one of our Services, we collect that information for - to our servers. Information collected includes but is not exhaustive to: -
    -
  • - Timestamps of the event; -
  • - A randomly generated ID; -
  • -
  • - Event type ("load" or "unload"); -
  • -
  • - Page URL; -
  • -
  • - Referrer URL; -
  • -
  • - Is you are a new visitor or not - - (See below how we track unique visitors); -
  • -
  • - Has you visited the same page before - - (See below how we track unique visitors); -
  • -
  • - Timezone of your browser or system; -
  • -
  • - Time spent on a page in milliseconds; -
  • -
  • - Additional metadata about events (such as if you are logged on the accessed Service - or not, what page theme you are using, clicked links or buttons such as for downloading - a file or contacting us). -
  • -
-
-
- HTTP Headers -
-
- Your browser sends us additional data used to better serve our Services. We collect some of - this data on our analytics tool: "Accept-Language" header used by your browser; "User-Agent" - header, which includes information about your browser type, device and operating system. -
-
- Location -
-
- We do not use IP addresses or IP geolocation to determine your location. - Instead, we determine your country based on - your browser's timezone. Capytal cannot determine your - exact city or region, this is intentional to preserve end user privacy. -
-
- Accessibility Settings -
-
- Capytal may collect your browser's accessibility settings data to better understand the - needs of our users regarding accessibility concerns. -
-
-

How we determine unique visitors

-

- We do not use IP addresses or Cookies to determine unique visitors by default. - To preserve privacy and not rely or personal identifiers, we use a browser cache-based approach - to track unique visitors of our Services. If you visit one of our Services websites, your - browser will cache our tracking script, and reuse it on future visits instead of requesting - to our services again. This allows us to differentiate between new and returning visitors, and - does not allows us to identify individual users. -

-

What information you disclose to us we collect

-

- Capytal just collects personally-identifiable information when you disclose it to us while - using our Services, such as when registering an account. -

-

- We do not collect personally-identifiable and analytical data in a matter that one can be - associated to another. All analytical data collected automatically as mentioned above, is - stored in a anonymised form and cannot be associated with a specific user or personally-identifiable - information. -

-

- When using our Services, the following personal information may be disclose to us: -

-
-
- Username -
-
- Your username is used to allow you to login to our Services; -
-
- Password -
-
- We store a hashed password derivate from your password to allow you to login to our Services - secretly; -
-
- Email -
-
- Your email is used to contact you and to register you on Services that do not use username. - We never share your email with any third-parties; -
-
- Service specific additional data -
-
- You may disclose to us additional data required to use one of our Services. This includes, - for example, but is not exhaustive to: -
    -
  • Messages, posts and chats;
  • -
  • Images, videos, and other used-generated content;
  • -
  • - Technical information, such as log files or hardware specification, may be requested - in Services focused on bug tracking and report; -
  • -
  • Your public SSH keys, used on, for example, - our Forge service - to give you access to specific features of the Service; -
  • -
  • - IPs and other medatada. Your system, browser or application may or may not send - information in the form of IP addresses and other forms such as user-agents, this - information might be recorded on automatically-generated log files, these are deleted - every 48 hours, in addition to being private and not shared to any third-parties. -
  • -
-
-
-

What do we use your personal information for?

-
-

- Core functionality -

-

- Some of our Services require personal information to work properly. In some cases, - you can substitute personal information for pseudonymous or valid false personal information - (such as non-working email addresses) if you do not want to disclose personal information. - Most Services on Capytal require some degree of personal information to provide core functionality. -

-

- Moderation and detect malicious activity -

-

- Your personal information might be collected on automatically-generated log files to detect - possible malicious activity, to aid in moderation of other users, or to detect bots that - are improperly programmed. -

-

- Automatically-generated log files are deleted every 48, though we might choose to keep some - log files in some cases, such as in the case of an outage or attack on our infrastructure. -

-
-

What measures we employ to protect you personal information?

-

- Capytal employs a variety of security measures to protect personal information from being - breached by malicious actors. These measures include hashing, encryption, containerization - and other industry-standard measures. -

-

Do we use cookies and other technologies?

-

- Yes. Some of our Services may use cookies and similar technologies to store your preferences or - check if you are logged into an account. These cookies do not store any personally-identifiable - information in most cases and are not used to get analytical data about you. -

-

Is information shared to other third-parties?

-

- We do not share your personal information with third-parties. However, some - Capytal services may be federated, meaning that any messages, chats, public account data - are shared with any similar servers, such as in case of - ActivityPub-compatible Services (example of these - services include but is not exhaustive to: - - Mastodon, - - Pixelfed, and - - Lemmy) -

-

- Some information and data, such as username, posts, and user-generated content may be shared - publicly by you while using our Services. This include cases such as, for example, creating a - public bug report on our Forge Service. It is up to you to not share personally-identifiable - information on these public channels, we do not take responsibility on personally-identifiable - information being shared by you accidentally or not on these public Services. -

-

Legal Action exception

-

- Your personally-identifiable data may be requested by legal authorities - and used for legal and regulatory responsibilities if necessary, in such cases we may try - to preserve and fight for your privacy if we think the reason isn't justifiable, but we - cannot prevent authorities to access your information if preventing it results in legal - and financial issues for us. -

-

Embedded and referenced content

-

- Embedded content from other providers may be available in our Service, these providers may track - your interaction with their and our content. For example, if you click in an embedded video - from YouTube, - Google will track you interaction. -

-

- Similarly, content and other third-parties services may be referenced via hyperlinks, accessing - third-parties content may end with your data being shared with a third-party which we cannot - have control over on how and what data is handled and processed. -

-

- You are recommended to review third-party's Privacy Policies before interacting with them. -

-

Data retention policy

-

- Automatically-generated log files or server logs are deleted every 48 hours, but may be kept - for longer to investigate malicious behaviour as outline above. -

-

- Information that you provide to us might be store indefinitely or as long as Capytal and our - Services survives, unless you personally delete it yourself or request us to delete it. -

-

Your rights

-

Whether your area has enacted or not the - European Union's General Data Protection Regulation (GDPR), - Brazil's General Personal Data Protection Law - (Portuguese: Lei Geral de Proteção de Dados Pessoais) (LGPD), - California Consumer Privacy Act (CCPA), - or similar law or regulation, you have the following rights if permissible by law: -

-
-
The right of access
-
- The right of access ensures you are allowed to know - what personal information Capytal has collected, stored or recorded about you. - Also referred as "The Right to Know". -
-
The right to ratification
-
- The right to ratification means that you are allowed to change any personal - information about you on our Services that you see as invalid, false or misleading. -
-
The right to data control
-
- The right to data control means that you can request us to anonymise, block or delete - any unnecessary, excessive, or non-compliant personal data of yours. -
-
The right to data independence
-
- The right of data independence means that you can request us to provide means to - move your personal data to another service or product provider. -
-
The right to data knowledge
-
- The right of data knowledge means that you have the right to know if and how your - personal data has been shared to third-parties if permissible by law. Legal and - regulatory authorities may request us to not disclose sharing of personal data. -
-
The right to erasure
-
- The right to erasure means that any personally-identifiable information that Capytal - has collected, stored or recorded about you will be deleted in up to 96 hours after - the initial request. Note that you will have to provide us some personal information - that we can go search for and delete. Also referred as "The Right to Delete" or - "The Right to be forgotten". -
-
-

- To exercise your rights, send an email to legal@capytal.cc -

-

Versions of this Policy

-

- We provide translated versions of this policy in different languages, so users of our - Services can understand how we collect, process and secure their data regardless of - their native language. The - Brazilian Portuguese version of this Policy applies specifically to users under - the jurisdiction of the Federative Republic of Brazil, otherwise, the English version - (the version you are currently accessing) applies to all other users under any other - jurisdiction. -

-

- Copies of this Policy - are also available on our Forge, these copies are formatted differently to provide - better version management and comparison of the Policy versions. -

-

Changes to this privacy policy

-

- We reserve the right to make changes to this privacy policy at any time. -

-

- In the case of significant changes to this privacy policy, you will be notified by us - via email in a period of, at minimum, 30 days before the new policy is applied. If you - are not registered on any of our Services and/or have not disclosed to us any direct - way to contact you, the same notification will be sent on our social media platforms. It - is recommended to check this page often, referring to the date of the last modification - listed at the bottom. You can also check for differences between the Policy past versions - on our Forge. -

-

- If you object any of the changes to the Policy, you must cease using this Website and - any of the Services provided by Capytal that this Policy applies on. By accessing this - Website or our Services, you agree with the terms described by this Policy. -

-

- Unless stated otherwise, the current privacy policy listed in this page (https://capytal.cc/PRIVACY.md) applies to - all data we collect about you. -

-

Legal Contact Information

-

- For any questions, legal concerns, or exercising of your rights, contact us via email at - legal@capytal.cc -

-

Last updated at April 07, 2025

+ {{.Content}}
{{template "nav-bar" (args "Lang" .Lang)}} {{template "footer" (args "Lang" .Lang)}}