Privacy policy
1. Who we are
CritFrame (critframe.com) is operated by CritFrame Media, which is the data controller (in Korea: 개인정보처리자) for this website. Privacy contact / privacy officer (개인정보 보호책임자): CritFrame Media — Privacy, contact@critframe.com.
2. The short version
- No ads, no tracking cookies, no accounts. We don’t run advertising at the moment.
- We measure traffic with Cloudflare Web Analytics (a small script Cloudflare adds to our pages), which does not use cookies or local storage and does not fingerprint visitors.
- We count page views and share-button clicks ourselves, without cookies: we never store your IP address or browser details, only daily totals (see section 3a).
- If you email us, we use your email only to reply.
- Videos are only loaded from YouTube if you click to play them.
3. What we process and why
| Data | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Technical request data (IP address, browser user agent, requested URL, time) processed by our host, Cloudflare | Delivering the website, security, preventing abuse | Legitimate interests (Art. 6(1)(f)) | As set out in Cloudflare’s privacy policy; we do not keep separate server logs |
| Aggregated page-view statistics (page, referrer, country, device type) via Cloudflare Web Analytics | Understanding which articles are read | Legitimate interests (Art. 6(1)(f)) | Aggregated; retained as set out in Cloudflare’s privacy policy |
| Email address and message content when you contact us | Replying to tips, corrections, privacy and rights requests | Legitimate interests / steps at your request (Art. 6(1)(b), (f)) | Up to 12 months after the matter is closed, unless needed longer for legal reasons |
3a. Our own view and share counter
To count article views and share-button clicks, and to show popular articles, our site sends a small request to our own server (hosted on Cloudflare) when a page loads or a share button is clicked. No cookies or local storage are used and nothing is shared with third parties.
- Counting each reader once per day: we combine your IP address and browser user agent with a random value (a “salt”) that changes every day, and keep only a one-way hash of the result. The IP address and user agent themselves are never stored. Hashes are deleted after two days, together with the salt, so they cannot be linked across days.
- What we keep: daily totals per page — views, unique daily views, and share clicks per network — plus daily totals by referrer category (search, social, direct, other), country (from Cloudflare’s network), device type (mobile, tablet, PC) and site language. We do not keep full referrer URLs.
- Automated traffic (bots, link previews, prefetching) is filtered out and not counted.
- Purpose and legal basis: understanding which articles are read and showing view counts and “Most read” lists — legitimate interests (Art. 6(1)(f)). The totals we keep do not identify anyone; we keep them for as long as the site runs.
We do not sell personal data, we do not use it for advertising, and we do not make automated decisions with legal or similarly significant effects about you.
4. Cookies and local storage
CritFrame does not set cookies. If you use the dark-mode switch or dismiss the language banner, your choice is stored only in your browser’s local storage and is never sent to us. You can clear it at any time in your browser settings.
Embedded video: YouTube videos are shown as a placeholder. Nothing is loaded from YouTube until you click play; then the video loads from youtube-nocookie.com and Google’s privacy policy applies.
If we introduce advertising in the future, we will update this policy and ask for consent where required before any non-essential cookies are set.
5. Processors and international transfers
| Recipient | Role | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, CDN, security, web analytics, email forwarding | United States and global network |
| Microsoft Corporation (Microsoft 365), the operator’s business email provider | Mailbox that receives emails forwarded from contact@critframe.com | As set by Microsoft’s data-location terms for the operator’s account; see the Microsoft Privacy Statement |
Transfers outside the EEA/UK rely on appropriate safeguards such as the EU–US Data Privacy Framework or Standard Contractual Clauses, where applicable.
For Korean users (국외 이전 고지): personal information described in section 3 is transferred to Cloudflare, Inc. (United States) over the network at the time you visit the site, for the purposes and retention periods above. Contact: Cloudflare’s privacy team, as listed in Cloudflare’s privacy policy. You may refuse by not using the site or not emailing us; core content remains accessible without providing any information directly.
6. Your rights
Under the GDPR (EEA/UK visitors): you can request access, rectification, erasure, restriction, data portability, and object to processing based on legitimate interests. You may also lodge a complaint with your local data protection authority.
Under Korea’s Personal Information Protection Act: you can request access, correction, deletion and suspension of processing of your personal information.
To exercise any right, email contact@critframe.com. We respond within one month (GDPR) or within 10 days (PIPA).
Help in Korea: Personal Information Infringement Report Center (privacy.kisa.or.kr, ☎ 118); Personal Information Dispute Mediation Committee (www.kopico.go.kr, ☎ 1833-6972); Supreme Prosecutors’ Office cybercrime (☎ 1301); National Police Agency cyber bureau (ecrm.police.go.kr, ☎ 182).
7. Children
CritFrame is a general-audience news site and does not knowingly collect personal data from children. We do not ask for age or account information.
8. Security
The site is served over HTTPS only. We minimise the data we hold and limit mailbox access to CritFrame Media’s authorised staff.
9. Changes
We will post any changes on this page with a new “last updated” date. Significant changes will be noted on the homepage.