Privacy Policy
This policy describes how The Checklist Co. Ltd. (company registration no. 0105568060109), operator of kevinsomany.com, collects and uses your personal data. It covers newsletter subscriptions, account sign-in, paid membership, cookies, and your data-protection rights under the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Thai Personal Data Protection Act B.E. 2562 (PDPA).
Who is responsible for your data
The data controller is The Checklist Co. Ltd., 81/1 Room 503, Floor 5, Soi 2, Sukhumvit Road, Klongtoei, Bangkok 10110, Thailand. Contact: k3v1n@arisadesiam.com.
No EU/EEA or UK Art.27 representative has been appointed at this stage.
What data is collected and why
The data we collect depends on how you use the site:
- Newsletter subscription: your email address and chosen language, used to send you the newsletter and to manage your subscription. Collected when you submit the subscribe form.
- Account sign-in (via Google): your email address, display name, and profile picture URL, received from Google when you sign in with Google. Used to authenticate you and to link your account to a membership.
- Paid membership: your subscription status, plan type (monthly or annual), and member-since date, received from our payment provider Polar when you subscribe. Used to grant and verify access to members-only content.
- Session: a session identifier stored in an HTTP-only, same-site cookie by our authentication system (Better Auth). Used to keep you signed in. This is a strictly necessary technical cookie and does not track you.
- Bot protection: Cloudflare Turnstile evaluates a signal from your browser on the subscribe form. This is a privacy-friendly bot-protection mechanism that does not set persistent tracking cookies and does not build a profile of you across sites.
- Theme preference: a light/dark mode preference stored in your browser's local storage. This never leaves your device and is not personal data.
Legal basis for processing
We rely on the following legal bases:
- Contract (GDPR Art.6(1)(b); PDPA s.24(3)): processing your account data and membership status is necessary to provide the paid membership service and deliver members-only content.
- Consent (GDPR Art.6(1)(a); PDPA s.19): sending you the newsletter requires your active opt-in at sign-up. You may withdraw consent at any time by unsubscribing.
- Legitimate interest (GDPR Art.6(1)(f); PDPA s.24(5)): security logging and fraud prevention, where these interests are not overridden by your rights.
How newsletter sign-up works
Newsletter sign-up uses a double opt-in: you submit your email, receive a confirmation email, and the subscription is only recorded once you click the confirmation link. Nothing is sent before you confirm.
You can withdraw your consent and stop receiving newsletters at any time using the unsubscribe link in any email, or by contacting us at the address above.
Who receives your data (sub-processors)
We share your data only with the service providers listed below, each of which processes your data on our behalf:
- Cloudflare, Inc. (USA): site hosting (Cloudflare Workers), database (Cloudflare D1), and bot protection (Cloudflare Turnstile). Privacy policy: cloudflare.com/privacypolicy.
- Resend, Inc. (USA): email delivery. Privacy policy: resend.com/privacy.
- Polar Software, Inc. (USA): payment processing, subscription management, and merchant-of-record services. Privacy policy: polar.sh/legal/privacy-notice.
- Stripe, Inc. (USA): card payment processing (accessed via Polar). Privacy policy: stripe.com/privacy.
- Google LLC (USA): OAuth sign-in (Google Sign-In). Privacy policy: policies.google.com/privacy.
International transfers
All five sub-processors above are based in the United States, which is outside the EU/EEA and does not have an EU adequacy decision. Transfers to each of them rely on Standard Contractual Clauses (SCCs) approved by the European Commission under GDPR Art.46(2)(c).
For transfers from Thailand, the transfers rely on the same contractual safeguards consistent with PDPA s.28.
How long data is kept
Newsletter email and locale: kept until you unsubscribe or request deletion.
Account (OAuth) data: kept while your account exists. OAuth tokens (access token, refresh token) are encrypted at rest using AES-256-GCM. You may request deletion by contacting us.
Membership data: kept for the duration of your subscription and for as long as needed to comply with legal obligations (such as accounting and tax record-keeping requirements).
Session data: each session expires after at most 30 days. Expired session rows, including the associated IP address and browser user-agent, are deleted automatically by a daily cleanup process. Signing out deletes the session immediately.
Cookies and browser storage
This site uses the following:
- Session cookie (auth): an HTTP-only, same-site cookie set by our authentication system to keep you signed in. This is strictly necessary for the service to function and is exempt from consent requirements under ePrivacy Directive Art.5(3).
- Cloudflare Turnstile (bot protection): a technical signal evaluated by Turnstile when you submit the subscribe form. Turnstile does not set persistent tracking cookies. Strictly necessary for security. For details, see Cloudflare's Turnstile Privacy Addendum: cloudflare.com/turnstile-privacy-policy.
- Local storage (theme): your light/dark preference is stored in your browser's local storage. This does not leave your device and is not personal data.
Your rights
Depending on where you live, you have the following rights:
- Right of access: request a copy of the personal data we hold about you (GDPR Art.15; PDPA s.30).
- Right to rectification: request correction of inaccurate data (GDPR Art.16; PDPA s.35).
- Right to erasure: request deletion of your data (GDPR Art.17; PDPA s.33).
- Right to restriction: request that we limit how we use your data while a dispute is resolved (GDPR Art.18).
- Right to data portability: receive your data in a structured, machine-readable format (GDPR Art.20).
- Right to object: object to processing based on legitimate interests (GDPR Art.21).
- Right to withdraw consent: withdraw your newsletter consent at any time without affecting the lawfulness of processing before withdrawal (GDPR Art.7(3); PDPA s.19).
- Right to complain: lodge a complaint with your local supervisory authority. In Thailand: the Personal Data Protection Committee (PDPC). In the EU/EEA: the supervisory authority of your member state. In the UK: the ICO (ico.org.uk).
Data breaches
In the event of a personal data breach, we will notify the relevant supervisory authority (in Thailand: the PDPC) without undue delay and, where feasible, within 72 hours of becoming aware, as required by PDPA s.37 and GDPR Art.33.
Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay and, in any case, within 30 days.
What this site does not do
This site does not use third-party tracking cookies and does not track you across other websites. It does not sell, rent, or share your personal data with advertisers or any party beyond the sub-processors listed above.
Some posts contain clearly labeled affiliate links: if you follow one and later make a purchase, the destination company may pay this site a commission. This site shares no personal data with those partners; any cookies the destination site sets are governed by its own privacy policy. See the Affiliate Disclosure page at /disclosure/ for full details.
Changes to this policy
If we make material changes to this policy we will post an updated version on this page and update the "last updated" date. We will notify active subscribers by email where required by law.