Effective Date: 6 February 2026
At COT Digest (“we”, “us”, “our”), we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store and protect your information when you use our newsletter and data platform at https://cotdigest.com (the “Service”).
1. Information We Collect
We collect the following types of information:
1.1 Information You Provide
- Email address: Required to deliver newsletters and manage your subscription
- Name: Collected when you create a paid account (optional for free newsletter subscriptions)
- Password: Encrypted and stored securely for account authentication (paid accounts only)
- Payment information: Processed securely through Stripe. We do not store full credit card details on our servers
1.2 Information Collected Automatically
- IP address: Collected when you sign up or interact with the Service
- Browser and device information: User agent, browser type, device type and operating system
- Usage data: Login times, pages visited, newsletter opens and clicks (where available), and interaction with the Service
- Consent records: Timestamps and source of your consent for email communications and data processing
2. How We Use Your Data
We use your personal data for the following purposes:
- Service delivery: To send you newsletters, manage your subscription, and provide access to COT data and reports
- Account management: To create and maintain your account, authenticate logins, and manage your subscription preferences
- Payment processing: To process subscription payments, manage billing, and handle refunds (where applicable) via Stripe
- Communication: To send service-related emails (e.g., subscription confirmations, payment receipts, account updates) and respond to your inquiries
- Legal compliance: To comply with legal obligations, enforce our Terms and Conditions, and protect our rights
- Service improvement: To analyse usage patterns, improve our content and platform, and develop new features
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
3. Legal Basis for Processing
Under UK GDPR and applicable data protection laws, we process your data based on:
- Consent: When you subscribe to newsletters or opt-in to marketing communications
- Contract: To perform our obligations under the subscription agreement (e.g., delivering newsletters, processing payments)
- Legitimate interests: To improve the Service, prevent fraud, and ensure security (where these interests do not override your rights)
- Legal obligation: To comply with applicable laws and regulations
4. Data Sharing and Third Parties
We do not sell your personal data. We only share your data with trusted third parties in the following circumstances:
- Stripe: Payment processing and subscription management. Stripe’s use of your data is governed by their Privacy Policy
- Email service providers: To deliver newsletters and transactional emails (e.g., Mailgun or similar providers)
- Hosting and infrastructure: Data is stored on secure servers managed by our hosting providers
- Legal requirements: When required by law, court order, or to protect our rights, property or safety
All third parties are required to handle your data in accordance with applicable data protection laws and our instructions.
5. Data Storage and Security
Your data is stored securely on servers located in the United Kingdom and/or the European Economic Area (EEA). We implement industry-standard technical and organisational measures to protect your data from unauthorised access, alteration, disclosure or destruction, including:
- Encryption of data in transit (HTTPS/TLS) and at rest where appropriate
- Secure password storage using industry-standard hashing algorithms
- Regular security assessments and updates
- Access controls limiting data access to authorised personnel only
While we strive to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
6. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy:
- Active accounts: Data is retained while your account is active and for a reasonable period after cancellation to comply with legal obligations
- Free subscribers: Email addresses and related data are retained until you unsubscribe or request deletion
- Payment records: Retained as required by law (typically 7 years for tax and accounting purposes in the UK)
- Consent records: Retained to demonstrate compliance with data protection laws
When data is no longer needed, we will securely delete or anonymise it in accordance with our retention policies.
7. Your Rights
Under UK GDPR and applicable data protection laws, you have the following rights:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your data (subject to legal retention requirements)
- Restriction: Request that we limit how we process your data in certain circumstances
- Data portability: Request a copy of your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Withdraw consent: Withdraw consent for email marketing or other consent-based processing at any time
You can exercise many of these rights directly through your account settings. To exercise other rights or if you have questions, contact us at privacy@cotdigest.com. We will respond within one month (or inform you if we need more time).
You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) if you believe we have not handled your data appropriately. Visit ico.org.uk for more information.
8. Cookies and Tracking
We use cookies and similar technologies to:
- Maintain your login session and account preferences
- Analyse website usage and improve the Service
- Remember your preferences and settings
You can control cookies through your browser settings. Note that disabling cookies may affect the functionality of the Service, particularly for logged-in users.
9. International Transfers
Your data is primarily stored and processed within the UK and EEA. If we transfer data outside the EEA, we ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses approved by the European Commission) to protect your data in accordance with UK GDPR.
10. Children’s Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. We will post the updated policy on this page and update the effective date. Material changes will be communicated via email or a prominent notice on the Service where appropriate. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data rights, or have concerns about how we handle your data, please contact us at:
Email: privacy@cotdigest.com
Postal Address: [Your business address, if applicable]