Skip to main content

Privacy Policy

Last updated: March 2026

1. Introduction

The Narratologist (narratologist.io) is operated by Oz Kabala ("we," "us," or "our"). We respect your privacy and are committed to protecting the personal information you share with us. This policy explains what data we collect, how we use it, which third parties may process it, and what rights you have.

Where applicable, this policy is aligned with the EU General Data Protection Regulation (GDPR) and other relevant data-protection frameworks. By using the site you acknowledge the practices described here.

2. What Data We Collect

2.1 Data You Provide Voluntarily

  • Guild / newsletter sign-up: email address only.
  • Contact forms: name, email, organization (optional), and your message.
  • Digital purchases (single article or monthly subscription): email address and payment details (processed by Lemon Squeezy / Stripe).

2.2 Data Collected Automatically

  • Server data: our hosting provider (Vercel) automatically collects technical data such as IP address, browser type, operating system, and access time — for security and performance purposes only.
  • Google Analytics (GA4): via Google Tag Manager, we collect usage data including page views, session data, device type, and approximate geographic location. IP anonymization is enabled. See Section 6 for details.
  • Local storage (localStorage): the site stores minimal data in your browser’s local storage. See Section 5 for details.

3. How We Use Your Data

PurposeData typeProcessorLegal basis
Sending the newsletterEmailBeehiivConsent
Responding to inquiriesName, email, messageResendConsent
Payment processingEmail, payment details, IPLemon Squeezy / StripeContract performance
Purchase notificationsEmail, purchase detailsResendContract performance
Usage analytics & site improvementPage views, session, device, approximate locationGoogle Analytics (GA4)Legitimate interest
Hosting & infrastructureTechnical data (IP, browser)VercelLegitimate interest
Email routingEmail address, message contentCloudflareLegitimate interest

4. Third-Party Services

The site relies on the following services, each of which may process a subset of your data:

  • Vercel — hosting and deployment (US-based, SOC 2 certified). Collects technical data such as IP address, browser type, OS, and access time.
  • Beehiiv — newsletter management and delivery (US-based). Stores subscriber email addresses, open rates, and click data.
  • Lemon Squeezy (via Stripe) — payment processing for digital purchases. Processes email, payment information, and IP address. US-based. See Section 7.
  • Resend — transactional email service (US-based). Processes email addresses and message content for contact forms and purchase notifications. See Section 8.
  • Cloudflare — email routing (forwards oz@narratologist.io to the operator’s inbox) and DNS services. See Section 9.
  • Google Analytics (GA4) — usage analytics via googletagmanager.com. IP anonymization is enabled. See Section 6.
  • Sanity — content management system. Does not collect any data from site visitors.

We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes.

5. Cookies & Local Storage

This site does not use advertising cookies or third-party tracking cookies. The following data is stored in your browser:

  • localStorage — Guild membership status: the site stores a value indicating whether you have signed up for the Guild. This is not a cookie, is never sent to a server, and is used solely to personalize the interface (e.g., showing "Guild" instead of "Join the Guild").
  • localStorage — Purchase status: for digital purchases (single article or subscription), the site stores a value indicating access to paid content. This value does not contain payment details.
  • Google Analytics cookies: GA4 may set cookies (_ga, _ga_*) to identify sessions and measure usage. See Section 6 for opt-out options.

You can delete all localStorage data and cookies at any time via your browser settings.

6. Google Analytics & Opt-Out

We use Google Analytics 4 (GA4) via Google Tag Manager to analyze usage patterns and improve the site. Data collected includes:

  • Page views and session duration.
  • Device type, operating system, and browser.
  • Approximate geographic location (country/city level).
  • Referral source.

IP anonymization is enabled — your full IP address is not stored. Google processes the data on US-based servers in accordance with Google’s Privacy Policy.

Opt-out options:

7. Payment Processing (Lemon Squeezy / Stripe)

Digital purchases on the site are processed by Lemon Squeezy, which uses Stripe as its payment processor. Both are US-based.

Data processed during a purchase:

  • Email address.
  • Credit card / payment method details (processed directly by Stripe — we never see or store your card information).
  • IP address (for fraud prevention and security).
  • Transaction details (product, amount, date).

Stripe holds PCI DSS Level 1 certification, the highest security standard in the payment industry. For details: Stripe Privacy Policy.

8. Transactional Email (Resend)

We use Resend (US-based) to send transactional emails:

  • Contact forms: when you submit a contact form, your message is sent to us via Resend. Data processed: email address and message content.
  • Purchase notifications: after a digital purchase, Resend sends a notification to the site operator with purchase details.

Resend does not use this data for its own purposes and acts as a data processor only.

9. Email Routing (Cloudflare)

The address oz@narratologist.io is routed via Cloudflare Email Routing to the operator’s personal inbox. Cloudflare processes the sender’s email address, message headers, and content solely for the purpose of routing. In addition, Cloudflare provides DNS services for the site’s domain.

10. International Data Transfers

Several of our third-party providers are based in the United States. This means personal data may be transferred and processed outside your country of residence:

ServiceLocationData transferred
VercelUS (SOC 2)Technical data (IP, browser)
BeehiivUSEmail addresses
Lemon Squeezy / StripeUS (PCI DSS Level 1)Email, payment details, IP
ResendUSEmail addresses, message content
Google AnalyticsUSUsage data, device, approximate location
CloudflareGlobalInbound email, DNS

We work exclusively with providers that maintain recognized security standards. For visitors from the EU, these transfers are carried out under mechanisms recognized by GDPR, including Standard Contractual Clauses (SCCs).

11. Data Security

We take reasonable security measures to protect your personal information, including:

  • Encrypted communication (HTTPS/TLS) on all pages.
  • Restricted access to administrative systems.
  • Use of providers with recognized security certifications (SOC 2, PCI DSS).
  • HMAC signature verification on all Lemon Squeezy webhook payloads.
  • Input sanitization on all forms and emails.

That said, no method of transmission or storage is 100% secure. We cannot guarantee absolute protection against every threat.

Breach notification: in the event of a data breach that may affect your privacy, we will notify the relevant authorities and affected individuals within 72 hours of discovering the incident, in accordance with GDPR requirements.

12. Data Retention

  • Newsletter: your email address is stored by Beehiiv until you request its removal.
  • Contact forms: details are retained for one year and then deleted, unless a business relationship has been established.
  • Purchase data: transaction records are held by Lemon Squeezy / Stripe in accordance with regulatory requirements (up to 7 years).
  • Technical data (Vercel): retained for up to 30 days by the hosting provider.
  • Google Analytics: user data is retained for 14 months and then automatically deleted.
  • localStorage: persists in your browser until you manually clear it or clear your browser data.

13. Your Rights

Under GDPR and applicable data-protection laws, you have the following rights:

  • Right of access: request to know what personal data we hold about you.
  • Right to rectification: request correction of inaccurate or incomplete data.
  • Right to erasure: request deletion of your personal data ("right to be forgotten").
  • Right to data portability: receive the personal data you provided to us in a structured, commonly used format (e.g., CSV), or request that we transfer it directly to another controller where technically feasible.
  • Right to withdraw consent: unsubscribe from the newsletter at any time via the unsubscribe link in any email, or by contacting us directly.
  • Right to restriction of processing: request that we limit how we process your data in certain circumstances.
  • Right to object: object to processing based on legitimate interest.

To exercise your rights, email us at oz@narratologist.io. We will respond within 30 days.

Filing a complaint: if you believe your privacy has been violated, you have the right to lodge a complaint with your local data-protection supervisory authority in accordance with Article 77 of the GDPR.

14. Children Under 16

This site is not intended for children under the age of 16. We do not knowingly collect personal data from minors. If we become aware that such data has been collected, we will delete it immediately.

15. Changes to This Policy

We may update this policy from time to time. In the event of a material change, we will publish a notice on the site and/or notify newsletter subscribers. We encourage you to review this page periodically. The date of the last update is noted at the top of the page.

16. Contact

For questions about this privacy policy or to exercise your rights:

See also: Terms of Use · Accessibility Statement