Privacy policy
Last updated 29 August 2026
Archaeology Teahouse is a small, independent publication. We built it to need as little of your data as possible, and this page describes all of it in plain language.
Who we are
Archaeology Teahouse is run by Sandee Oster. Any question you have about your data can be directed at her through the contact page.
What we don't do
No advertising, no ad trackers, no analytics scripts, and no social-media pixels. Reading this site does not follow you around the internet. The single exception to "no third-party code" is described under Newsletter below: an anti-bot check that runs only on the signup form, never while you read.
If we ever add visitor statistics, they will be first-party and cookieless: daily aggregate counts (views, rough country from network data, which site referred you) with nothing that can link your visits from one day to the next. This paragraph will be rewritten with specifics before any of that goes live.
What the server sees
Like almost every website, our server keeps short-lived technical logs (your IP address, the pages requested, and your browser's self-description) to keep the site running and to spot abuse. These logs rotate automatically and are not used to profile readers. The site is served through Cloudflare, which processes the same technical data to protect against attacks; Cloudflare acts as our infrastructure provider, not as an advertiser.
Should something on the site break, a technical report is sent to Sentry (an error-monitoring service) so we can fix it as soon as possible. Those reports are scrubbed before they leave the server — they only describe what the code was doing, never who you, our Teahouse patrons, are, nor any of your information.
Cookies
The public site sets no cookies. A session cookie exists only if you sign in to an account. It does one job — keeping you signed in — and expires when the session does.
Accounts and email
If you create an account, we store your email address, a securely hashed password (we cannot see the password itself), and when the account was made — nothing more. We send you a one-time verification email, and nothing else unless you have asked for it. We never share or sell email addresses.
You can delete your account yourself, any time, from your account page. Deleting removes your email address and sign-in immediately and permanently. What technically remains is an anonymous placeholder record that no longer says anything about you — it exists so that anything you may one day have published here (such as comments, when they arrive) isn't silently torn out of other people's conversations. If you want even that placeholder gone, say so via the contact page and it will be erased entirely.
The contact page
Messages sent through the contact page arrive in our email inbox like ordinary correspondence — you won't be added to any sort of email list.
Support payments
If you choose to support the Teahouse financially, the payment itself happens with Paystack, our payment provider — your card details go to them and never touch this site. What we store is the receipt's outline: which plan, the amount, when it was paid, and the provider's transaction reference. We keep those records because payment history is the one thing we cannot honestly erase on request — it is our bookkeeping. Deleting your account stops any monthly support and anonymizes the account as described above; the payment records keep only the anonymous placeholder to point at. Paystack's own handling of your data is covered by their privacy policy. How to stop a subscription or get money back is a separate page: refunds and cancellation.
Newsletter
Signing up for the newsletter is double opt-in: we email you a confirmation link, and nothing is sent until you click it. We store your email address, when you signed up, and the network address the signup came from — that record is our proof of your consent, which the law (GDPR and POPIA) requires us to keep. Every email we ever send includes a one-click unsubscribe link; unsubscribing stops all mail immediately. We keep the unsubscribed address only so we never mail it again — if you would rather it be erased entirely, say so via the contact page and it will be.
The signup form is protected by Cloudflare Turnstile, an anti-bot check. It is the only third-party code on the site, it loads only on pages with a signup box, and it shows Cloudflare your browser's technical characteristics — not your name or email — solely to answer "is this a human?".
Where data lives
The site is hosted in Germany (Hetzner, Falkenstein). Images are stored with Cloudflare R2 in Western Europe. Transactional email is delivered by Resend.
Your rights
Under the GDPR (EU) and POPIA (South Africa) you can ask what we hold about you, ask for it to be corrected, or ask for it to be deleted. For most readers the honest answer is "nothing at all." If you have an account, the delete button on your account page does most of it yourself; for anything beyond that, get in touch via the contact page and it will be done.
You can direct any data concern or question at us — or complain to a data protection authority: in the EU, the authority of your own country.
Changes
Whenever the site starts doing something new with data, this policy is updated first and the date at the top of this page changes.
