Publication trust
Privacy
How Spec & Signal hosts this site, uses consent-gated audience measurement, and minimizes reader data.
Policy published
Site hosting and services
Spec & Signal is a public static publication hosted on Cloudflare Pages. Cloudflare necessarily receives network request information such as an IP address, requested path, browser headers, and request time to deliver and protect the site. Cloudflare Web Analytics is off. See Cloudflare’s privacy policy for its handling of service data.
The site has no reader accounts, comments, payment flow, advertising tracker, newsletter form, waitlist, or email collection. Spec & Signal does not ask for names, email addresses, VINs, or precise garage information through the site.
Site search uses a static index downloaded from Spec & Signal and processes the query in your browser. A committed query is retained only in the page URL fragment so reload, Back, and Forward work; fragments are not sent in the HTTP request. Search text is not stored by the site, sent to a search provider, or included in analytics.
Optional audience measurement
Spec & Signal uses Google Analytics 4 only after a reader explicitly chooses Allow audience measurement. This is basic consent: before that choice the Google tag is not loaded and no analytics request is sent. Choosing Keep measurement off cannot block reading, search, or any other site function.
The choice is saved in this browser’s local storage with a policy version so the site can remember it. It is not a subscriber identity and is not shared with the newsletter system. If the policy version changes, the site asks again. You can review or reverse the choice from the audience-measurement control in the site footer area.
After permission, Spec & Signal may send an explicit page view; article engagement and reading-depth milestones; internal content selections; a submitted or cleared search action with only a broad result-count bucket; and a source-link selection identified by a repository-owned source label. Automatic pageviews, enhanced measurement, advertising signals, affiliate measurement, and field-vitals collection are off.
Those are the events and custom fields Spec & Signal deliberately supplies. Google Analytics also processes its standard pseudonymous client and session identifiers, first-party analytics cookies, automatically collected events such as first visits and session starts, and technical details such as browser, device, and approximate geographic information after permission. Spec & Signal has disabled Google signals, user-provided data collection, ads personalization, and granular location and device collection in the property settings.
The event contract accepts only fixed categories, bounded counts, query-free paths, and stable public content identifiers. It rejects search terms, email addresses, names, phone numbers, VINs, precise garage data, arbitrary free text, full source or outbound URLs, explicit IP-address parameters, subscriber state, and provider-to-analytics identity joins. Search pageviews use only the registered /search/ path; the query and fragment are excluded. Source interactions use a registered source ID, never the destination URL.
When Google Analytics is allowed, Google’s tag may set first-party analytics cookies and necessarily receives connection metadata, including an IP address in network transport. Spec & Signal does not add an IP address to event fields; Google states that GA4 does not log or store individual IP addresses. Analytics event-level data is configured for the shortest standard retention setting, two months. Aggregate reporting may remain longer under Google’s service behavior.
Revoking permission stops new Spec & Signal analytics events and updates the consent state, but it cannot erase data already sent. To ask about access or deletion, contact quinten@sinclairgrowthsystems.com. See Google’s privacy policy and Contact for the monitored publication contact.
Before newsletter signup can launch
The weekly briefing is coming soon, but Spec & Signal is not collecting email addresses or operating a waitlist. Launching a waitlist would create the same subscriber-data obligations as launching signup, so no email field will appear until an appropriate provider and complete consent, privacy, retention, deletion, abuse-prevention, and sender-compliance controls are approved.
If signup launches later, it will use double opt-in. Subscriber state will belong with the approved mail provider, not in Git or Google Analytics. Provider privacy, retention, deletion, bounce, complaint, and unsubscribe behavior must be reviewed and reflected here before the form is enabled.
This policy changes whenever the actual data flow changes. The identity gate prevents a placeholder publisher or unmonitored contact assertion from qualifying for staging or release.