This explains what personal information we collect, why, who else sees it, and what you can ask us to do about it.
Banana Media Network publishes technology and business journalism at bananamedianetwork.com. We are based in Metro Manila, Philippines, and we handle personal information in line with the Data Privacy Act of 2012 (Republic Act No. 10173).
We have readers in a lot of countries, so this policy is written to hold up outside the Philippines too. If you are in the European Economic Area or the United Kingdom, the sections on lawful bases, international transfers and your rights are written with you in mind. If you are in the United States, see US state privacy rights.
The short version
Everything below this box says the same thing in the exact language a regulator needs. This part is for you.
- Do you sell my information?
- No. Not to advertisers, not to data brokers, not to anyone. There is no version of this site where your email address is for sale.
- Are you tracking me right now?
- Only if you said yes. Until you answer the cookie banner, the analytics and advertising scripts do not run at all. We do keep a count of page views that sets no cookie and cannot be traced to you — that one runs either way.
- What do you actually have of mine?
- Whatever you handed over, and nothing more. If you never subscribed, registered for an event or left a comment, we have no account for you — only the ordinary server logs every website keeps.
- Who else can see it?
- The eight companies named further down, each doing one job — sending the newsletter, delivering the contact form, and so on. We name them rather than writing "our partners", because you cannot check a claim like that.
- Can I get it deleted?
- Yes. Email [email protected] and we will do it. You do not have to explain why, quote a law, or use any particular wording.
- Where is my data kept?
- On a server we run ourselves, not inside a publishing platform. Your account and your comments are in our database, which is a shorter journey than most sites can describe.
What we collect
When you subscribe
Your email address, and your name if you give it. Our publishing platform records when you open our emails and which links you click, so we can tell whether a newsletter was worth sending. Every email has an unsubscribe link, and it works immediately.
When you register for an event
Your name, email address, and anything else the organiser asks for on the registration form. If the event uses check-in, we record whether and when you were checked in at the door.
We share this with the organiser of that event, which is the point of registering. Once shared, the organiser handles it under their own policy rather than ours. We do not sell it and we do not pass it to anyone else.
When you submit an event
Your name, email address, the organisation you represent, and the details of the event. We use your email to tell you whether the submission was approved. Your email address is never published.
The organisation you name, and any hosts you name, appear on the published event page and are gathered onto community pages. Each named host gets a standing page of their own, at a fixed address, listing every event they have fronted here along with the name, job title, photograph, biography and links you entered for them. Naming someone as a host publishes all of that about them, indefinitely — so ask them before you do. To have a host page removed, email [email protected], whether you are the organiser or the host.
Those pages also show how many people registered for each event, and totals per organiser and per host. That is a count and nothing else. No attendee is named or listed anywhere on them, and there is no public ranking of attendees.
Your own attendance page
You can choose to publish the events you have attended on a page of your own. It is off unless you turn it on. Until you do, nothing about which events you attended appears anywhere public, and there is nothing to find.
If you turn it on, the page lists the events you were checked in at — the name you gave at the door, the events, and their dates. It does not show your email address. Its address is a random code rather than your name, so nobody can look for you by guessing. Turning it off removes the page immediately.
Only events you were actually checked in at appear. Registering for an event and not going does not put it there. If you once attended as a walk-in using the same email address you later signed up with, those events are matched to you as well — the address is the link, and we match it exactly, never approximately.
Find the setting on your account page.
When you contact us
The contact form is handled by Web3Forms, which delivers the message to our inbox. We keep what you send so we can reply and refer back to it.
When you book a call
The Book a 45-minute call link takes you off this site to Cal.com, where the booking happens. Nothing about it is stored here, and we do not receive anything you do not type into their form.
Cal.com collects your name, email address, the time you chose and anything you write in the notes. It records your timezone so the slots it shows you are in your own local time. The booking is then written to our Google Calendar and Google generates the Google Meet link, so the same details reach Google as well.
Your cancel and reschedule links are in the confirmation email Cal.com sends you. We keep the calendar entry while it is useful as a record of who we have spoken to, and you can ask us to delete it at [email protected].
Automatically
Our servers record the usual request information: IP address, browser and device type, the page requested, and the referring page. Cloudflare, our content delivery network, records the same for security and abuse prevention.
We also run Cloudflare Web Analytics, which counts page views, referrers and countries. It sets no cookie and builds no profile of you: there is no identifier that follows you between visits, and nothing it records can be traced back to a person. Because it stores nothing on your device it is not covered by the cookie banner, and it runs whatever you answer there.
If you accept analytics cookies, Google Analytics 4 records which pages you visit, what brought you here, and roughly where you are — country and city, worked out from your IP address, which Google Analytics does not store. We read it in aggregate. If you do not accept them, none of it is collected at all.
When you play a podcast episode we count the play. We store a one-way hash of your IP address and browser identifier rather than the values themselves, so repeated plays are not double-counted and the record cannot be traced back to you.
Cookies and similar technologies
We use cookies for three purposes:
- Essential. Keeping you signed in, and remembering whether you chose light or dark mode. The site does not work properly without these, so they are set without asking.
- Analytics. Understanding which articles are read and how people arrive, in aggregate.
- Advertising. Where we display advertising, our partners and their vendors may set cookies to measure performance and to limit how often you see the same advertisement.
Analytics and advertising cookies are not set until you accept them. A banner asks on your first visit. Until you answer it, those scripts are held back and nothing beyond the essential cookies is stored.
You can change your answer whenever you like from the Cookie settings link in the footer. Declining costs you nothing except our count of you. If your browser sends a Global Privacy Control signal, we take that as a decision to decline and we do not show you the banner at all.
Third parties that may set cookies through this site include Google — for analytics, and, where advertising is displayed, as an advertising vendor. Google uses advertising cookies to serve advertisements based on your prior visits to this and other websites.
Opting out of personalised advertising. You can turn it off in Google Ads Settings, or opt out of a wider set of vendors at aboutads.info and youronlinechoices.eu. Most browsers also let you refuse or delete cookies, though refusing essential ones will stop you signing in.
Why we are allowed to use it
If you are in the EEA or the UK, the law asks us to name a lawful basis for each use rather than just describing it. Ours are:
- Consent — analytics and advertising cookies, and subscribing to a newsletter. Withdraw it and we stop.
- Performance of a contract — running your account, and passing your registration to the organiser of the event you registered for. We cannot do the thing you asked for without these.
- Legitimate interests — server and security logging, abuse prevention, cookieless page-view counts, aggregate podcast play counts, and answering a business enquiry you brought to us, including a call you booked. We use the least identifying form that still works, which is why play counts are hashed rather than stored against you and why the page-view counter sets nothing on your device.
- Legal obligation — where the law requires us to keep or disclose something.
Who processes data on our behalf
Listed by what each one does, with the operator named after it. Naming them is a disclosure and not a recommendation — we are saying who touches your information, not endorsing anybody. The law would let us write "an email provider" and stop there. We would rather you could check.
- Hosting — a rented virtual server that holds the site's database. The one entry given as a category rather than a company, because publishing where a database physically sits is a security question and not a transparency one. Ask and we will tell you.
- Content delivery and security — Cloudflare, which also produces the cookieless page-view count described above.
- Newsletter and transactional email — Brevo.
- Contact form delivery — Web3Forms.
- Readership measurement — Google Analytics, only where you accepted analytics cookies.
- Advertising — Google, where advertising is displayed.
- Comment profile pictures — Gravatar, run by Automattic.
- Call scheduling — Cal.com, with Google providing the calendar entry and the video link.
We ask you to question what you read here. It would be a strange thing to ask while declining to say who we hand your email address to.
Our content management system is not on that list, because it is not a service. It is software installed on our own server, so your account, your comments and your event registrations never leave it — there is no publishing company in the middle to name. The events, registration and comment systems are ours as well.
Your profile picture
If you comment, the picture beside your name comes from Gravatar, a service run by Automattic. Finding it means a request to Gravatar carrying a one-way hash of your email address rather than the address itself. We do not send Automattic your address in readable form, and we receive nothing back but an image.
You control what appears. Create a Gravatar account with the same email you use here and your picture follows you; do nothing and you get your initials instead, which is the default. There is no way to upload a picture to this site directly — we do not store one.
If you would rather your browser never contacted Gravatar at all, most browsers and privacy extensions can block it, and the comments still work without it.
Where your information goes
Some of these operate outside the Philippines, so your information may be processed abroad, including in the United States and the European Union.
The site runs on our own server rather than on a publishing platform. Your account, your event registrations and your comments sit in a database we operate, not in a third party's product — so the list above is shorter than it would otherwise be, and each entry on it does one job rather than holding everything.
Where personal information is transferred out of the EEA or the UK, we rely on the Standard Contractual Clauses approved by the European Commission, and the UK Addendum to them, as incorporated in these providers' data processing terms.
Our Terms of Use cover what you may do with what you find here, and what happens to anything you submit.
What we do not do
We do not sell your personal information. We do not share your email address with advertisers. We do not use your registration for one event to market unrelated events to you without asking first.
How long we keep it
- Subscriber records — until you unsubscribe or ask us to delete them.
- Event registrations — up to two years after the event, so organisers can report on attendance.
- Contact messages — up to two years.
- Booked calls — the calendar entry stays for up to two years, the same as a contact message, because that is what it is a record of. Cal.com keeps its own copy under its own policy.
- Server and security logs — typically 30 days.
- Podcast play counts — indefinitely, but only in the hashed form described above, which is not linked to you.
- Page-view counts — retained by Cloudflare on its own schedule, as totals rather than as anything attached to a visitor. There is nothing here to delete on request because there is nothing identifying you in it.
US state privacy rights
If you live in California, Colorado, Connecticut, Virginia, or another state with a comprehensive privacy law, you have the right to know what we hold about you, to have it corrected or deleted, and to opt out of its sale or of targeted advertising. The section below is how you exercise all of it. We do not charge you for asking and we do not treat you differently afterwards.
We do not sell personal information, and we do not share it for cross-context behavioural advertising as California defines that term. Where advertising is displayed, declining advertising cookies and the vendor opt-outs above cover it. We do not use sensitive personal information to target advertising, and we do not knowingly process the personal information of anyone under 16 for it.
Your rights
Wherever you live, you can ask us to show you what we hold about you, correct it, delete it, or stop using it. You can withdraw consent at any time, and you can object to direct marketing outright.
If you are in the EEA or the UK you can also ask us to restrict how we use it, and to send you a copy in a portable form. Nothing here is decided by automated profiling — a person handles these.
Write to [email protected]. We reply within 30 days and we do not charge for it. We may ask you to confirm who you are before handing over a copy of anything, which protects you rather than obstructs you.
If you are not satisfied with how we handled it, you can complain to the National Privacy Commission of the Philippines. In the EEA you may complain to your own country's data protection authority instead, and in the UK to the Information Commissioner's Office.
Children
This site is not intended for children under 13, and we do not knowingly collect their information. Where local law sets a higher age for consenting to data processing — 16 in much of the EEA — we apply that age instead. If you believe a child has given us personal information, tell us and we will remove it.
Security
The site is served over HTTPS, and access to member and registration data is restricted to people who need it. No system is perfectly secure and we will not pretend otherwise, but if a breach affects you we will notify you and the National Privacy Commission as the law requires.
Changes
We will update the date at the top when this policy changes. If a change materially affects how we use your information, we will say so by email or by a notice on the site.
Contact
Banana Media Network
Metro Manila, Philippines
[email protected]
Privacy questions and requests go to the same address, and reach the person responsible for data protection here.