Privacy Policy
Last updated: 29 August 2026
This site is a personal professional site. This policy explains what data it collects, why, how long it is kept, and how you can control or remove it.
First-party analytics
The site records aggregate, first-party analytics (PostHog) — pages viewed, referrer, and campaign parameters (UTM tags on inbound links) — to understand how visitors arrive and what they read. For visitors in the EU, EEA, and UK this runs cookieless until you consent: no non-essential cookie is set and no persistent identifier is stored.
Visitor signals
When you reveal a contact detail or open a case study, I record that it happened. Here is exactly what gets saved: the event, the page it happened on, whether you looked like a real person or a bot, and — sometimes — the name of the organisation whose network you are visiting from. Your IP address is never stored.
How that organisation name is worked out, because it is narrower than it sounds. Networks that are large enough to route their own traffic have a public identifier, and which addresses belong to which network is public information published by the RouteViews project at the University of Oregon. If your address belongs to a network registered to an organisation, I look that organisation up in the public internet registries. If it belongs to an ordinary internet provider — home broadband, mobile, a coffee shop — I record nothing at all, because that tells me about your ISP and not about you. Most visits fall into that second group.
This is not an attempt to identify YOU. It cannot tell me who you are, where you work, or anything about you personally — only that a visit arrived from a particular organisation’s network, which is often not the same thing. No third party is told you visited: the routing and registry data is public and I look it up, rather than sending your details anywhere. There are no cookies behind any of this, no cross-site tracking, and nothing is sold or shared. These records are visible only to me.
I keep them for 180 days, then they are deleted automatically.
Network routing data is from the University of Oregon RouteViews project, used under a Creative Commons Attribution 4.0 International licence.
Person-level identification (consent-gated)
This feature is NOT currently active. Nothing described in this section is happening today — no visitor is being identified by name, and no third-party identification vendor is loaded on this site. It is documented here because the consent controls for it are already live, so you can see what you would be consenting to before it is ever switched on. If that changes, this notice disappears and the description below applies.
- Vendor: RB2B, a third-party visitor-identification provider, may match a visit to a professional identity.
- Data collected: name, professional profile, and business contact details associated with the visit.
- Purpose: business development — reaching out to organizations and individuals who show interest in the consulting work described here.
- Legal basis & consent: for EU/EEA/UK visitors this feature is off by default and runs only after you opt in via the consent banner. Elsewhere it operates on a legitimate-interest basis with the opt-out below.
- Retention: identified-person records are kept for at most 24 months from the last interaction, then deleted. They are never shown publicly.
YouTube API Services
Pages under /work and /dartboard can embed YouTube videos and use YouTube API Services. By using those pages you agree to the YouTube Terms of Service. Google's handling of data is described in the Google Privacy Policy.
Video playback is click-to-load on YouTube's privacy-enhanced domain: the YouTube iframe is not inserted until you press play. Before that, the page loads only the video's thumbnail from YouTube's image CDN. This site does not access, collect, store, or share any YouTube user data about its visitors.
The publishing workflow behind this site is owner-only. Today, uploads are staged for the site owner to complete in YouTube Studio. After YouTube API audit approval, the tool will use the site owner's authorization only to upload private videos, manage video metadata, and read this channel's analytics for production review. Access can be revoked at any time via Google security settings. No other person's YouTube data is accessed or stored. If access is revoked there, stored YouTube API data tied to that authorization is deleted as soon as possible and within 30 calendar days; deletion requests sent to the contact below are completed as soon as possible and within 7 calendar days.
Your choices & rights
You can decline or withdraw consent at any time via the banner (EU/EEA/UK) or by emailing the address below (opt-out anywhere). To exercise a data-subject request — access, correction, deletion, or objection (DSAR) — email privacy@matthjones.com. Requests are actioned within 30 days.
Inquiries you send
Details you submit through the contact form (name, email, organization, message) are used solely to respond to your inquiry and are stored securely. They are never sold or used for advertising.