Privacy Policy


Who I am

I’m Jimmie Lightner, and this site lives at:

https://www.jimmielightner.com

If you want to ask what data I have about you, request deletion, or ask a privacy question, contact me through the site.

The short version

I’m not in the business of selling your data, building creepy tracking profiles, or pretending “legitimate interest” means I should vacuum up everything I can get.

This site does collect some data, because that’s how websites work. But the goal here is utility, security, and communication, not surveillance theater.

If I add tools that collect more than I’m comfortable with, I’ll either disclose them clearly or stop using them.

What I collect

Depending on how you use the site, I may collect:

  • information you give me directly
  • technical data your browser sends automatically
  • limited analytics data
  • information related to comments, forms, bookings, or email communication

That’s the honest umbrella. Here’s the breakdown.

If you leave a comment

If you leave a comment, I may collect:

  • your name
  • your email address
  • your website URL, if you provide one
  • the content of your comment
  • your IP address
  • your browser user agent

That last part is mainly for spam detection, moderation, and abuse prevention, not because I’m building a dossier on your keyboard habits.

If Gravatar is enabled, an anonymized hash of your email address may be sent to Gravatar to see whether you use that service. Their privacy policy is here:

https://automattic.com/privacy

If your comment is approved, your comment and any associated public profile image may appear publicly on the site.

If you contact me

If you contact me through the site, I may collect whatever you choose to send, including:

  • your name
  • your email address
  • the content of your message
  • any technical context you include
  • any project, system, or consultation details you submit

I use that information to:

  • reply to you
  • evaluate whether I can help
  • schedule or discuss services
  • keep basic records of inquiries and business communication

If you’re contacting me about a consultation, don’t send secrets. No passwords, no private keys, no tokens, no credentials, no “I pasted my entire docker-compose.yml and forgot the secrets were in there.” Use judgment.

If you book a call or session

If I use a scheduling or intake tool, that tool may collect:

  • your name
  • your email
  • your timezone
  • your availability
  • any intake answers or notes you provide

I use that information to schedule, prepare for, and deliver the session.

If I use a third-party booking tool, their privacy policy also applies. That’s not me dodging responsibility. That’s just how third-party tools work.

If you join an email list later

If I add an email list, newsletter, or updates signup, and you choose to subscribe, I may collect:

  • your email address
  • your name, if you provide it
  • basic subscriber activity, depending on the email provider

I’ll use that to send the thing you asked for. Not to quietly enroll you in some engagement funnel cult.

And no, I’m not going to add you to a mailing list just because you contacted me once.

If there’s a newsletter, there should also be an unsubscribe link. That’s table stakes.

Technical data and server logs

Like basically every website on Earth, this site may log technical request data such as:

  • IP address
  • browser type
  • operating system
  • referring page
  • requested URLs
  • timestamps
  • basic request metadata

This is used for:

  • security
  • performance
  • debugging
  • abuse prevention
  • basic site administration

That kind of data is normal. The question is whether it’s used responsibly. Here, the intent is operational, not voyeuristic.

Analytics

This site may collect basic analytics information such as:

  • page views
  • referrers
  • browser/device information
  • general usage patterns

Where possible, analytics are stored locally and used to understand traffic, improve the site, and keep an eye on technical problems or abuse.

I’m not interested in building ad-tech sludge or cross-site behavioral profiles. If I ever add third-party analytics that do more than basic measurement, I’ll say so clearly.

Cookies

This site may use cookies for normal website behavior.

That may include things like:

  • remembering comment form details
  • login/session behavior
  • display preferences
  • WordPress-specific functionality
  • basic analytics behavior, depending on site configuration

I’m not pretending cookies don’t exist. I’m also not using them as an excuse to run a tiny surveillance state.

Embedded content

Some pages or posts may include embedded content from other websites, like:

  • videos
  • images
  • posts
  • other media

If you interact with embedded content, the provider of that content may collect data about you, use cookies, or track your interaction, especially if you’re logged into their service already.

That’s not unique to this site. That’s just how embeds work.

If I embed something from a third party, their privacy practices apply to that embedded content.

Media uploads

If you upload images to the site, be aware that images can contain embedded metadata, including location information. If you care about that, strip EXIF/GPS data before uploading.

If you don’t control image uploads on this site, then this mostly isn’t your problem.

Who I share data with

I do not sell your personal data.

I may share limited information only when needed to operate the site or deliver something you asked for, such as:

  • spam detection services
  • hosting providers
  • booking or scheduling tools
  • email delivery tools
  • payment processors, if I add them later
  • security or infrastructure providers involved in keeping the site working

If you request a password reset, WordPress may include your IP address in the reset email.

This is boring infrastructure stuff, not a monetization scheme.

How long I keep data

That depends on what it is.

Comments

Comments and their metadata may be retained indefinitely so follow-up comments can be recognized and moderated more easily.

Contact and inquiry data

If you contact me, I may retain your message and related records for as long as needed to:

  • respond
  • provide services
  • keep business records
  • handle abuse or legal/security issues

Analytics and logs

Technical logs and analytics data may be retained for operational, security, and trend-analysis purposes, subject to whatever retention windows are configured at the time.

User accounts

If user accounts exist on the site, associated profile information may be retained until changed or deleted, subject to administrative and legal needs.

Your rights

If I have personal data about you, you can ask me to:

  • tell you what I have
  • give you a copy of it
  • delete it

If I can delete it, I will.

If I need to keep some of it for legal, security, abuse-prevention, or record-keeping reasons, I’ll keep only what I need.

Security

I take reasonable steps to secure the site and the systems behind it. That said, websites are not magical, email is not magical, and forms are not magical.

So again, don’t send highly sensitive secrets through normal website forms or email unless you enjoy avoidable problems.

Changes to this policy

If the site changes, the tools change, or the business model changes, I may update this policy.

If I add:

  • scheduling software
  • an email platform
  • payments
  • new analytics tooling
  • anything meaningfully different

I’ll update this page so it reflects reality instead of becoming one of those fossilized privacy policies nobody has touched since 2019.


4/1/2026