The short version
If you're not signed in, this site sets no cookies at all. Nothing to accept, nothing to refuse. There's no consent banner on this site because there's nothing to consent to.
If you sign up for the newsletter, we will have your name and email address. We use them to send you the newsletter. We don't sell, rent, or share them with anyone who isn't strictly necessary to deliver the thing you asked for.
If you are signed in, there's a cookie that keeps you signed in, and a set of analytics cookies from HubSpot — the CRM we use for the consulting side of the business. Those can recognize your browser between visits. We describe them properly below rather than calling them harmless. We don't use advertising cookies; we don't run ads, and we don't sell or rent anything about you.
The rest of this page is the details. It's written to be read, not to be survived.
Who we are
VarOps LLC
1209 Mountain Road PL NE, STE R
Albuquerque, NM 87110
United States
VarOps LLC is the data controller for the information described in this policy.
Privacy contact: privacy@varops.com
EU/UK Representative (Article 27, GDPR):
We have appointed DataRep as our representative in the European Union and the United Kingdom. If you are in the EU or UK, you may contact them regarding any matter relating to your personal data.
Email: datarequest@datarep.com — please quote VarOps LLC in the subject line.
DataRep is our Article 27 Representative. We are not required to appoint a Data Protection Officer and have not appointed one.
What we collect, and why
We collect as little as we can get away with. Here is all of it.
If you subscribe or create an account
| What | Why | Legal basis |
|---|---|---|
| Name | To address you properly | Contract — you asked us to send you things |
| Email address | To send you the newsletter and columns you signed up for | Contract |
| Your subscription preferences | So we send what you asked for and not what you didn't | Contract |
| Login session data | To keep you signed in | Contract |
We use Ghost as our publishing platform and Mailgun to deliver email. Both are US-based service providers acting on our instructions. See “Where your data goes” below.
If you comment
Registered members can comment on articles. When you do, we store your comment, your display name, and the time you posted. Comments are public — that's the point of them. Don't put anything in a comment you wouldn't want a stranger to read, because a stranger will read it.
Legal basis: legitimate interest — running a publication where readers can respond.
If you visit without signing up
We count you. We don't identify you.
Our analytics is a self-hosted version of Umami, running on our own infrastructure. It records page views, referring sites, approximate country-level location, and the type of device you're using. It sets no cookies, collects no IP addresses, uses no persistent identifiers, and cannot follow you across websites or across sessions. The data never leaves our servers and is never shared with a third party.
We do this so we know which columns are read and which are ignored. It is not possible for us to work out who you are from it.
Legal basis: legitimate interest — understanding whether anyone is reading.
All of the above applies whether or not you ever sign up. If you do sign up, see "Cookies" below, because signing in enables a second layer we describe there.
If you contact us about working together
This one deserves a fuller explanation, and it's below under Before we speak with you.
Cookies
If you're not signed in, there are no cookies. Nothing to accept, nothing to refuse.
If you're signed in, three things set them.
Our site sets a session cookie, so you stay signed in, and issues short-lived security tokens during login and signup. Those are strictly necessary — they exist to make the thing you asked for work.
Stripe, which handles subscription payments, sets __stripe_mid and __stripe_sid. They are fraud checks on the payment flow and have nothing to do with reading.
And HubSpot, the CRM we run our consulting practice on, sets these:
Cookie | What it does |
|---|---|
| recognises your browser between visits |
| visit counts and timestamps |
| current session |
| whether the browser was restarted |
We use them for one purpose: understanding which reading leads to a commercial conversation, because the consulting work pays for the magazine. We don't profile readers, we don't act on it editorially, and it plays no part in what you're shown.
We don't use advertising, social media, or cross-site tracking cookies, and we don't embed third-party media players or social widgets — when we show something from another platform, it is still a screenshot and a link.
There's no cookie banner. If you're not signed in, there is nothing to consent to. The cookies that keep you signed in are strictly necessary and can't be refused without breaking the thing you asked for. HubSpot's analytics cookies are neither of those, so if you'd rather we didn't set them, tell us at hi@varops.com and we won't.
Before we speak with you
If you contact us about a transformation engagement, a workshop, or working together in any capacity, we do our homework before the conversation.
Here's what that means, plainly. We review publicly available professional information, including your company's website and other public materials, your professional background, and your public technical or written work. We do this so we arrive at the call already informed, rather than spending your 30 minutes explaining your business to us.
We look at what you do professionally. We don't look at your private life. No home addresses, no dates of birth, no family, nothing outside the professional frame. Not because a policy forbids it — because it would be useless to us, and because a firm that builds trust architecture for a living has no business behaving otherwise.
We keep the conclusion, not the file. What we retain is a short, synthesized summary — the kind of paragraph a colleague would write before a meeting. We don't build or maintain a growing dossier on you, nor do we retain the underlying material.
If you'd rather we didn't, tell us at privacy@varops.com and we won't.
Legal basis: legitimate interest — preparing properly for a commercial conversation you initiated with us.
What we don't do
- We don't sell your personal information. We never have and we won't.
- We don't rent, trade, or share your data with advertisers or data brokers.
- We don't run advertising on this site, and we don't let anyone pay to reach you through it.
- We don't build advertising or behavioral profiles about you.
- We don't use your data to train AI models. Our columns are produced by an AI editorial pipeline — that pipeline reads the news, not our readers.
Where your data goes
We use a small number of service providers to run the site. Each acts on our instructions, under contract, and only for the purpose described here — for most of them, delivering what you asked for; for HubSpot, running the commercial side of the business.
| Provider | What they do | Where |
|---|---|---|
| Ghost | Publishing platform, member accounts, comments | US / EU |
| Mailgun | Email delivery | US |
| HubSpot | CRM, and analytics for signed-in members | US / EU |
| Umami (self-hosted) | Analytics — on our own servers, no third party involved | Our infrastructure (US) |
| Our hosting provider | Runs the servers | US / EU |
VarOps LLC is a US company, and some of our providers are US-based. If you are in the EU or the UK, your personal data is transferred to the United States. We rely on Standard Contractual Clauses with our processors for these transfers. You can ask us for details at privacy@varops.com.
We may also disclose personal data if legally compelled to do so — a court order or a lawful government request. We'll narrow the disclosure as far as the law allows.
How long do we keep things
- Newsletter and account data: for as long as you're subscribed, plus a short period afterward to handle any follow-up. Unsubscribe, and we will delete you, other than a minimal suppression record, so we don't accidentally email you again.
- Comments: until you or we delete them.
- Analytics: aggregate counts only. There is nothing personal in there to retain.
- Pre-call research summaries: kept for the life of the commercial conversation and a reasonable period after. Ask us to delete it and we will.
Your rights
Wherever you are, you can email privacy@varops.com and ask us to show you what we hold, correct it, or delete it. We'll do it. You don't need to cite a statute at us.
For the record, the formal position:
If you're in the EU or UK (GDPR), you have the right to access your data, correct it, erase it, restrict or object to how we use it, port it elsewhere, and withdraw consent where consent is the basis. You may contact our Article 27 Representative (DataRep, above) or us directly. You also have the right to complain to your national supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).
If you're in California (CCPA/CPRA), you have the right to know what we collect, to delete it, to correct it, and to opt out of "sale" or "sharing" of personal information. We don't sell or share personal information as those terms are defined, so there is nothing to opt out of — but the right exists, and we're telling you about it. We won't discriminate against you for exercising it.
Everywhere else: the same. Email us.
We'll respond within 30 days.
Children
This site isn't for children, and we don't knowingly collect data from anyone under 16. If you think we have, email privacy@varops.com and we'll delete it.
Security
We take reasonable technical and organizational measures to protect your data: encryption in transit, access controls, and the most effective security measure available — collecting as little as possible in the first place. Data you don't hold cannot leak.
No system is perfectly secure, and we won't pretend otherwise.
Changes to this policy
We'll update this page when our work changes — and the date at the top will change with it. If a change is material, we'll tell subscribers by email rather than quietly editing the page and hoping nobody notices.
Questions
privacy@varops.com — a person reads it.