Privacy & cookies
This page explains what this website collects, what it sets on your device, who else touches it and what you can ask us to do about it. It covers visitors everywhere, including the European Economic Area, the United Kingdom and the United States.
Last updated 29 August 2026
The short version
- If you are here to read the site, nothing is stored on your device by us. The only cookie this site sets belongs to our own team signing in to manage it, and it is never issued to visitors.
- There is no analytics, no advertising and no social tracking on this site. No Google Analytics, no Meta pixel, no third party embeds on the pages.
- We only get personal details if you choose to send them, through the contact form, email, phone or WhatsApp.
- We do not sell or share personal information, in the ordinary sense or in the specific sense those words carry under California law.
- You can ask us for a copy of what we hold, or ask us to delete it, by writing to info@bashlogs.com.
Who is responsible
Bashlogs operates this website and decides why and how the personal data described here is handled. In the language of the GDPR, we are the data controller.
You can reach us at info@bashlogs.com, on +92 335 6461518, or by post at our office in Lahore, Pakistan. Please put "privacy" in the subject line so it reaches the right person quickly.
We are based outside the European Economic Area and the United Kingdom. That does not reduce your rights: if we handle data about people in those regions in connection with offering services to them, the GDPR and UK GDPR apply to us and we honour them.
Cookies this site sets
A cookie is a small file a site asks your browser to keep. This one is the only one we set.
| Name | Purpose | Category | Lifetime |
|---|---|---|---|
bashlogs_session | Keeps a signed-in session for the Bashlogs team in the admin area at /admin. It holds a random token and nothing else. It is never set for ordinary visitors, because it is only created when someone signs in. | Strictly necessary | Until the session expires or you sign out |
It is marked httpOnly, so scripts on the page cannot read it, Secure, so it only travels over HTTPS, and SameSite=Lax, so it is not sent along with requests started by other sites.
What this site does not set
No analytics cookies. No advertising or retargeting cookies. No social media pixels. No fingerprinting. The typefaces are served from our own domain rather than fetched from Google at page load, so viewing a page does not announce your visit to a font provider either.
Because the one cookie above is strictly necessary for a function you have asked for, the ePrivacy rules do not require us to ask permission for it, and we do not pretend otherwise. The choice below is about anything optional we might add later.
Your cookie choice
We keep an optional category available so that if we ever add analytics, it is switched off by default and only runs for people who have said yes. Rejecting costs you nothing: no part of this site is withheld, and no feature stops working.
What we collect
If you contact us
The contact form on this site stores exactly five things: your name, your email address, your company if you give one, the subject, and your message. That is the whole record. Your IP address is not stored with it.
To stop the form being used to send floods of mail, we count recent submissions against a one-way hash of the sending IP address. The hash is held in memory for a few minutes and then discarded. It is never written to the database and it cannot be turned back into an address.
If you email, call or message us on WhatsApp instead, we hold whatever that conversation contains, in the mailbox or account it arrived in.
If you just read the site
Our hosting provider records ordinary server logs for every request, which include IP addresses, so that the service can be run and defended against attack. We do not build profiles from them and we do not combine them with anything else.
What we never ask for
This site takes no payments and hosts no accounts for visitors. We do not ask for card details, identity documents, dates of birth, or any of the special categories of data such as health, biometrics, religion or political views. Please do not send those to us through the contact form.
Why we are allowed to use it
For visitors in the EEA and the UK, the GDPR requires a lawful basis for every use. Ours are:
- Steps towards a contract. When you contact us about a project, we use your details to answer and to discuss the work.
- Legitimate interests. Keeping the site up, keeping it secure, and preventing abuse of the contact form. We have weighed this against your interests and consider the impact minimal, since the data involved is either non-identifying or immediately discarded.
- Consent. For anything optional, which today means the cookie category above. Where consent is the basis, you can withdraw it at any time and it is as easy to withdraw as it was to give.
- Legal obligation. Where we have to keep records, for example for tax or accounting.
Who else touches it
We do not sell personal information and we do not share it for advertising. A small number of suppliers process data on our instructions so the site can run:
- Vercel hosts the site and stores the images it serves. It processes requests and server logs.
- MongoDB Atlas stores the site content and any message you send through the contact form.
- Our email and phone providers carry the conversations you start with us.
Each of these acts as a processor: they may use the data to provide their service to us and for nothing else. We will also disclose information if the law genuinely requires it.
If you tap the WhatsApp button, that hands you over to WhatsApp, which is part of Meta and has its own privacy policy. Nothing is sent to WhatsApp until you choose to open it. The same is true of the LinkedIn link in the footer.
Transfers out of the EEA and the UK
We operate from Pakistan and our suppliers run infrastructure in several countries, so data about EEA and UK visitors may be handled outside those regions. Where that happens we rely on the safeguards the GDPR provides for international transfers, including the European Commission's standard contractual clauses in our agreements with suppliers. You can ask us for details of the safeguards that apply to you.
How long we keep it
- Contact form messages and enquiry emails: up to 24 months from your last contact with us, so we can pick up a conversation where it left off. Then deleted.
- Project records for clients we work with: for the length of the engagement and up to 7 years afterwards, where accounting and tax rules require it.
- Rate limiting hashes: minutes, in memory only.
- Server logs: as long as our hosting provider retains them, which is a short rolling window.
- Your cookie choice: kept in your own browser until you clear it. It never reaches us.
You can ask us to delete your message sooner and we will, unless we are required to keep it.
Your rights
If you are in the EEA or the UK
You have the right to:
- ask what we hold about you and get a copy
- have anything inaccurate corrected
- have it deleted, in the circumstances the law allows
- restrict how we use it while a question is resolved
- receive it in a portable format, or have it sent to someone else, where that applies
- object to our use of it where we rely on legitimate interests
- withdraw consent at any time, without affecting what came before
- complain to your national data protection authority. In Ireland that is the Data Protection Commission, in Germany your state authority, and in the UK the Information Commissioner's Office. We would rather you came to us first so we can put it right.
We do not make automated decisions about you and we do not profile you.
If you are in the United States
Several states, including California, Colorado, Connecticut, Virginia, Texas and others, give residents comparable rights: to know what is collected, to get a copy, to have it corrected, to have it deleted, and to opt out of its sale, of sharing for cross-context behavioural advertising, and of profiling.
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined in the California Consumer Privacy Act, so there is nothing to opt out of. We will not treat you differently for exercising any right.
How to exercise any of this
Email info@bashlogs.com and tell us what you want. We answer within 30 days, and we will tell you if we need longer. We may ask you to confirm your identity, which for a contact form message usually means writing from the same address you used. An authorised agent may act for you where the law allows it.
How it is protected
The site is served over HTTPS only. Admin access needs a password, which is stored as a bcrypt hash rather than as text, and sessions use a random token in a cookie that scripts cannot read. The contact form is rate limited and validated on the server. Access to the database is restricted to the people who need it.
No system is perfectly secure, and we will not claim otherwise. If you believe you have found a vulnerability, please tell us at info@bashlogs.com before disclosing it publicly, and we will work with you on it.
Children
This site is for business audiences and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has sent us something, write to us and we will delete it.
Changes to this page
When what we do changes, this page changes with it, and the date at the top moves. If a change materially affects how we use information you already gave us, we will say so clearly rather than relying on you noticing a new date.
Still have a question?
Write to info@bashlogs.com and a person will answer. If your question is about a project rather than privacy, the contact form is the faster route.