Legal

Privacy Policy

Last updated 19 August 2026

The short version: we ask before we measure anything, we keep only what the site needs to run, and we do not sell personal information.

Stacked & Tossed is published by The Stacked & Tossed Test Kitchen. This policy covers stackandtossed.com. It is written to be read, not to be survived.

What we collect

Analytics

We use privacy-conscious analytics to understand page performance and usage. Analytics may process a pseudonymous session identifier, browser/device information, language, approximate country inferred from time zone, page URL, referrer, and performance measurements. We do not use analytics to sell personal information.

None of that runs until you accept it. While your choice is undecided — and permanently if you decline — this site blocks the analytics requests in your browser before they are sent. The Cookie Notice lists the vendor, the stored identifiers, and how the block works.

Newsletter email

The Weekly Stack sign-up asks for one thing: an email address. When you submit it, we store the address, the date you subscribed, and which page you subscribed from in our own database. We use it for the newsletter and nothing else, and every issue carries an unsubscribe link.

Each submission also writes one row to an abuse log: the address, a one-way salted hash of your IP address, and your browser's user agent string. We keep the hash rather than the address it came from, so the log can tell us that a single network sent nine hundred signups without telling us whose network it was. That log is what stops the form being used to mail-bomb strangers.

No newsletter has been sent yet, and no email provider is connected — the sending hook exists but is switched off. We will name the provider here before we turn it on.

Server logs

Our host records standard request logs — IP address, timestamp, requested URL, user agent, response status — because a web server cannot answer a request without them. They keep the site up and absorb abuse. They are not analytics, they are not enriched, and they are not used to build a profile of you.

What we do not do

  • We do not sell personal information, and we do not share it for cross-context behavioural advertising.
  • We do not run ad profiling. The ad slots on the site are empty reservations today — no ad script, no tag, no third-party request. If that changes, those scripts will load only after you have consented, and this policy will say so before they ship.
  • We do not use analytics to identify you. There are no accounts and no logins, so there is no identity to attach anything to.
  • We do not run cross-site trackers, fingerprinting, or session replay.

Retention

  • Analytics session identifier: rotates after 30 minutes of inactivity. It is not a durable identifier and does not follow you between sites.
  • Analytics events: retained for no more than 12 months, after which they are deleted or kept only as aggregate counts that identify nobody.
  • Your consent choice: stored in your own browser until you change it or clear your browser data. It never leaves your device.
  • Newsletter address: kept until you unsubscribe. Unsubscribing marks the record so we do not mail you again; ask us to delete it outright and we will.
  • Newsletter abuse log: the address, hashed IP, and user agent recorded with each submission are deleted after 180 days. The rate-limit counters behind them are discarded after two days.
  • Server logs: kept for a short operational window by our host and then rotated out.

How to opt out

Open the consent control in the Cookie Notice and choose Decline. The change takes effect immediately, in every open tab, with no reload and no account.

Switching on Global Privacy Control or Do Not Track in your browser has the same effect and needs no visit here at all. Clearing your browser storage resets the question, and we will ask again.

Third parties

  • Supabase — our database processor. Your browser reads published recipes from it, and it is where a newsletter signup is stored: the address, the signup date and page, and the abuse-log row described above.
  • Our deploy and hosting platform — serves every page and operates the same-origin analytics proxy at /~api/analytics, which is backed by a Tinybird analytics pipeline. The measurement script is injected by that platform, which is exactly why consent is enforced in your browser rather than by leaving the script out.
  • Email provider — none connected today. A signup is stored in our own database and goes no further; the sending hook is switched off, and the provider will be named here before it is switched on.

We do not authorise any of these to use your data for their own advertising, and no third-party ad or affiliate script runs on the site today.

Children

The site is written for adults who cook, not for children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has sent us something, write to us and we will delete it.

Changes

When this policy changes we update the date at the top. If a change materially widens what we process, we reset the stored consent choice and ask again rather than assuming your old answer still covers it.

Contact

Questions, corrections, or a request to delete something: hello@stackandtossed.com. You can also use the contact page. We answer as The Stacked & Tossed Test Kitchen — there is no individual author to ask for.