Legal
Privacy Policy
This policy explains what personal data may be processed when you use tavojs.dev, subscribe to the newsletter, contact the maintainer, submit a plugin, or contribute through GitHub.
Last updated: August 28, 2026
Data controller
The controller is Hrachya Martirosyan, an individual maintainer based in Spain, who maintains Tavo.js as an independent, non-commercial open-source project.
Privacy contact: [email protected]
Information processed
Website access and security logs: production hosting and delivery systems may process IP addresses, requested URLs, timestamps, user-agent details, referrers, response status, and security diagnostics needed to deliver and protect the site.
Contact requests: if you write to the operator, the message, contact details you provide, and related replies are processed to understand and answer the request.
Newsletter subscriptions: when you request the newsletter, the service processes your email address, English locale, footer source, consent-copy version and request time. It sends a confirmation message and does not activate the subscription until you use the confirmation link. An abuse-control service derives a short-lived rotating identifier from the request IP address; the raw IP address is not stored in the subscription record.
Private plugin submissions: when you submit a plugin, the service processes the plugin and author names, package, repository and optional documentation URLs, license, contact email or public profile, description, optional notes, privacy-notice version and submission time. An abuse-control service derives a short-lived rotating identifier from the request IP address; the raw IP address is not stored in the plugin-submission record.
GitHub and open-source contributions: issues, pull requests, commits, discussions, profile information, and other activity you make public on GitHub are processed to operate and maintain the projects and their licence history.
Browser preferences: the Analytics choice and theme preference are stored locally on your device.
Analytics: before consent, Google Analytics receives limited cookieless pings that may include consent state, page activity, timestamps, referrer, browser/device information, and a random number for each page load. If you consent, it may also use analytics cookies and client or session identifiers. Names, email addresses, message contents, and account details are not intentionally sent as analytics event data.
Purposes and legal bases
Website delivery and proportionate security logging are intended to support the operator's legitimate interest in providing and securing the site. Contact data is used to respond to your request and, where relevant, take steps you request before entering an agreement. With your consent, newsletter data is used to confirm your address and send occasional Tavo.js release notes and project news until you unsubscribe. Newsletter consent is separate from analytics consent and can be withdrawn through the unsubscribe link in each message. Plugin-submission data is used to evaluate the plugin, communicate about the review and maintain the community catalog. Acknowledging the Privacy Policy confirms that you have read this information; it is not consent to marketing or analytics. GitHub contribution data is used to administer the open-source projects and document licensing. Limited cookieless measurement supports the operator's legitimate interest in understanding aggregate site usage. Consent is required for analytics cookies, identifiers, and full analytics measurement.
This notice reflects the project's current non-commercial operation. Review it again before adding sponsorships, advertising, sales, paid services, or another economic activity.
Providers and recipients
Hosting: No production hosting provider is identified in this repository. This policy will be updated if a host processes visitor data on behalf of the project.
CDN and security: No separate production CDN or security provider is identified in this repository. This policy will be updated if one is configured.
Email: Contact is available at [email protected]. Newsletter confirmation messages are sent through the transactional email service configured by the dedicated Tavo.js API. The provider is not identified in this repository and must be recorded here before newsletter collection is enabled in production.
Submission API and database: Newsletter subscription requests and plugin submissions are sent to a dedicated Tavo.js API backed by PostgreSQL. The production API, hosting and database providers must be identified here before either form is enabled in production.
Analytics: Google Analytics 4 is delivered through Google Tag Manager. With analytics storage denied, Google receives limited cookieless pings. With consent granted, Google Analytics may use analytics cookies and client or session identifiers.
GitHub: GitHub hosts the public source repositories and public contribution activity.
International transfers
GitHub, Google, or future infrastructure, submission API, database and email providers may process data outside Spain or the European Economic Area. The applicable provider terms may rely on an adequacy decision, standard contractual clauses, or another lawful safeguard. This policy will be updated when another production provider is configured; no unverified safeguard is claimed here.
Retention
- Consent choice
- 12 months from the date of the choice
- Theme preference
- Until the visitor changes the preference or clears browser storage
- Security logs
- Only for the period necessary to deliver and secure the website, subject to the configuration of any production infrastructure provider
- Contact requests
- Only for as long as necessary to answer and document the request, unless a longer period is required by law or needed for a legal claim
- Newsletter subscriptions
- Confirmation credentials expire after 60 minutes. Unconfirmed subscription requests are deleted after 30 days. Confirmed subscriptions remain active until unsubscribe; afterward, the minimum suppression record is retained to prevent accidental resubscription.
- Plugin submissions
- Pending and reviewed submissions are kept while necessary to evaluate the plugin, communicate with its submitter and maintain the catalog. Rejected and spam submissions, including contact details, are scheduled for deletion 180 days after their last review update. Accepted submission records may be retained as part of the project's maintenance and licensing history.
- Analytics
- Event-level retention follows the setting configured in the production Google Analytics 4 property; aggregated reports may be retained for longer
- GitHub activity
- According to GitHub's retention practices and, for accepted project contributions, for as long as needed to preserve the project history and licence record
Data may be retained longer where necessary to establish, exercise, or defend legal claims or to comply with a legal obligation.
Analytics choices
Analytics is denied by default. You can grant, reject, or later withdraw consent. Denial or withdrawal returns Google Analytics to limited cookieless mode and prevents analytics cookies and identifiers from being used. It does not invalidate processing performed while consent was active.
Your GDPR rights
Subject to the GDPR's conditions, you may request access, rectification, erasure, restriction, portability, or objection, and may withdraw consent at any time. Send requests to [email protected]. Enough information may be requested to verify your identity and the scope of the request.
You also have the right to complain to the Spanish Data Protection Agency (AEPD).
Changes to this policy
This policy will be updated when providers, retention periods, production tracking, or legal requirements change. The current date will be shown at the top of the page.