Policies
Privacy policy
- Last updated
- 8 September 2026
- Version
- 2026-09-08
- Analytics
- None, on any page
- Logs kept
- 30 days
- Health data
- Covered separately
This policy covers everything that is not health data: the pages you visit, the emails we send, the payment Stripe processes on our behalf, and the records we are obliged to keep. We do not run advertising or analytics code anywhere on this site. We do not sell or share personal information. You can ask for a copy or a deletion at any time.
What this covers, and what it does not
This policy covers the ordinary information a website and a small business collect: an email address, a payment reference, a line of correspondence, a server log, one cookie.
It does not cover your intake answers or your photograph. Those are health information, they are held under a different legal basis, and they have their own document — the health data notice. Where the two overlap, that one governs. Nothing in this policy weakens it.
The controller of everything described here is Bencao House · Hangzhou, Zhejiang Province, People’s Republic of China. Write to us at privacy@bencaohouse.com.
What we collect outside the intake
- Your email address, and a name if you choose to give one. We do not require a real name and we do not check it.
- A Stripe payment reference: an identifier, an amount, a currency, a date, and the country your card was issued in. Never a card number.
- Correspondence: what you write to us, and what we write back.
- Server logs, described in the next clause.
- One cookie, described in the cookie notice.
We do not build a profile of you. We do not buy data about you. We do not have an advertising business, an affiliate arrangement, or a partner who would like a copy of anything.
Server logs
Our host records what any web server records in order to stay upright: the time of a request, the path requested, the response status, the rough size of the response, the browser’s user-agent string, and the requesting IP address.
Those logs exist so that we can see an error and fix it. They are kept for 30 days and then discarded. They are not joined to your account, they are not used to work out who you are, and they are never used for measurement or marketing. On the routes that touch health information the log line is truncated: the path is recorded, the query string is not.
The lawful basis for holding them is our legitimate interest in running a site that works and is not being attacked.
No analytics, anywhere on this site
There is no Google Analytics, no Meta pixel, no TikTok pixel, no heatmap recorder, no session replay, no A/B testing tool and no tag manager. Not on the essays, not on the homepage, not on the intake. This is unusual enough that it is worth saying in a sentence you can check: view the source of any page and look for a script we did not write.
We do know how many reports we sell, because Stripe tells us, and we know roughly how many people read a page, because the host counts requests without identifying anyone. That has been enough.
Payment
Payment is processed by Stripe. Card details are entered on Stripe’s own hosted page, are transmitted to Stripe, and never reach our servers — we could not leak a card number, because we never hold one.
Stripe acts as an independent controller for its own fraud prevention and regulatory obligations, and its privacy policy governs that. What comes back to us is a reference, an amount, a date, the last four digits of the card, and the issuing country. We keep those for seven years because tax law says so.
Stripe may place its own cookies on its checkout page, on its own domain. The cookie notice says what they are for.
We send three kinds of email: a receipt, your report, and a reply when you write to us. All three are necessary to do the thing you paid for, and you cannot unsubscribe from them without asking us to cancel.
Anything else — a seasonal note, a new essay — is a separate opt-in, asked for with an unticked box, and one click unsubscribes. We do not send that email more than once a month, and we have never sold or rented the list.
Open tracking and click tracking are switched off in our email provider’s settings. We do not know whether you opened your report. If you would like a delivery confirmation, ask and we will look at the delivery log directly.
Who else sees any of it
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we have no arrangement under which anyone receives it in exchange for anything. Under California law that means there is nothing for you to opt out of, and we offer no financial incentive in return for your data because there is no scheme it could feed.
The companies that necessarily see something are the ones that run the plumbing:
- Supabase — database and file storage, European Union region.
- Vercel — hosting and edge routing. Sees requests, stores nothing.
- Stripe — payment.
- Our email provider — carries the receipt and the report.
Each is bound by a data processing agreement and acts only on our instructions. If we ever change one, this list changes with it, and the version at the top of the page moves.
If we received a binding legal order for someone’s records, we would comply only so far as the order actually required, and we would tell the person unless we were forbidden to. We have not received one.
How long we keep it
| Record | Kept for |
|---|---|
| Server logs | 30 days |
| Email correspondence | 24 months |
| Mailing-list subscription | Until you unsubscribe, then 30 days for the suppression record |
| Payment records | 7 years, required by tax law |
| Consent records | 6 years |
Intake answers, photographs and reports run on their own clock, set out in the health data notice.
Your rights, and how to use them
Wherever you live, we will do all of the following on request: tell you what we hold, send you a copy, correct anything wrong, delete it, stop using it, or hand it over in a machine-readable file. We do not ask why.
Write to privacy@bencaohouse.com from the address you used. We reply within 72 hours, finish within 30 days, and charge nothing. If we cannot verify that the request is yours, we ask one question you would know the answer to rather than demand identity documents.
- California. Rights to know, delete, correct and limit under the CCPA as amended by the CPRA. We do not sell or share, and we do not discriminate against anyone who exercises a right.
- United Kingdom and European Economic Area. The full set of GDPR rights, including the right to complain to the Information Commissioner’s Office or to your national supervisory authority without asking us first.
- Elsewhere. The same, by policy rather than by statute.
No decision about you is made automatically. There is no profiling and no scoring anywhere in this business.
Security, and what happens if we get it wrong
Everything travels over TLS 1.3. Records are encrypted at rest. Access is by named individual account with two-factor authentication, never a shared login, and every read of a record is logged. Nobody has a copy of the database on a laptop.
If a breach happens, we will tell the relevant supervisory authority within 72 hours and tell the people affected without undue delay, in plain language: what went, when, what we have done, and what you should do. We will not wait for certainty about the scale before saying that something happened.
Children
This service is for adults. You must be 18 or older to buy a report, and we do not knowingly collect anything from anyone younger. If you tell us that a record belongs to someone under 18, we delete it and refund the fee without asking anything further.
We do not write reports about a child from a parent’s account. If you are worried about a child, please see someone in person where you live.
Changes, and who to write to
The date and version at the top of this page are the ones in force. Material changes are emailed to anyone who bought a report in the previous twelve months, at least fourteen days before they take effect. Typographical corrections are made without notice.
Anything about your information: privacy@bencaohouse.com. Anything else, including a complaint: care@bencaohouse.com.
The reading
A short policy, because there is not much to describe.
An email address, a payment reference, one cookie and a server log. If that is acceptable, the reading itself is thirty questions and a photograph.