Privacy
Privacy policy
I wrote this against the scripts this build actually ships. This build loads the Google Analytics 4 tag (G-6CY5676EV8), the Microsoft Clarity loader (project yqfov0r8qp) and Adsterra ad units (Native Banner + Social Bar, website id 6088406) behind the same consent gate: everything stays denied and inert, and only starts after you accept. If a later build adds another ad seller or tracker, this page changes in the same commit.
Who is responsible
Daily Holes Guide at https://dailyholes.org is the publisher. Reach contact@dailyholes.org for a privacy request.
Scripts on the page
The HTML loads the Google Analytics 4 tag (gtag.js, measurement id G-6CY5676EV8) in the <head> of every page. An inline gtag function sets Consent Mode defaults before the config call, so the tag is present but does not start collecting. It also loads the Microsoft Clarity loader (project yqfov0r8qp) behind the same gate: the loader is inert until the stored consent says granted or you accept on this visit, and only then does it fetch clarity.js and start session insight.
Adsterra (adsterra.com) serves two ad placements on this site — a Native Banner inside the article area and a Social Bar fixed to the bottom of the viewport — from the Adsterra publisher dashboard website id 6088406 (ad units 31490942 and 31490943). Their scripts are not in the page HTML: they are injected only after you accept, and nothing is fetched from adsterra's serving domains (bicea.org) before that point. The Social Bar can be closed with its × button; that choice is stored in localStorage as dh_ads_closed and respected on later visits. Because ad_storage stays denied, ad serving is non-personalized: Adsterra may still place a contextual or generic ad, but no ad network gets a personalized profile from this site's traffic. No session replay or heatmap runs before a choice.
Storage
| Key | Where | Purpose | Retention |
|---|---|---|---|
| dh_consent | localStorage | Stores analytics choice (granted or denied) and ads (always denied) plus a timestamp | 180 days, then the banner returns |
| dh_ads_closed | localStorage | Remembers that you closed the Adsterra Social Bar so it stays closed on later visits | until you clear site storage |
| _ga / _ga_6CY5676EV8 | first-party cookie | Google Analytics session and user measurement, written only after you accept analytics | up to 2 years (Google Analytics default) |
| _clck | first-party cookie | Microsoft Clarity session click and insight tracking, written only after you accept analytics | up to 13 months |
| _clsk | first-party cookie | Microsoft Clarity session recording continuity, written only after you accept analytics | session |
| Third-party ad cookies (e.g. *_uid, adsterra namespaces) | third-party cookie / localStorage | Set by Adsterra or its demand partners while serving the accepted, non-personalized ad placements; I do not read or control these | per each provider's policy, typically up to 13 months; see https://adsterra.com/privacy-policy/ |
Before you accept, I set no Google, Clarity or Adsterra cookie or storage: with analytics_storage and ad_storage denied, gtag.js does not write _ga, the Clarity loader stays inert, and no ad script is fetched. Hosting (the site is on Cloudflare) may log IP addresses in the host's own request logs. That processing is the host's, under their customer agreement, and I do not copy those logs into this repo.
Consent Mode defaults
Before any config call, ad_storage, ad_user_data, ad_personalization, and analytics_storage are denied. ads_data_redaction and url_passthrough are on. If navigator.globalPrivacyControl is true, the stored choice is denied and analytics is not treated as granted. An analytics request is only sent after you accept (or after a revisit where the stored choice is granted). Adsterra scripts are only injected after the same accept. Google receives page data through ${site.analyticsId} under Google's privacy terms at https://policies.google.com/privacy.
Legal basis
The consent record is stored only after you click Accept or Reject, or immediately when a browser sends Global Privacy Control. The basis is consent for the analytics flag and for loading ad scripts, and a legitimate interest in remembering a refusal (or a closed Social Bar) so the banner or bar does not nag. You can reopen the choice with Cookie settings in the footer and pick Reject, which overwrites the key; closing the Social Bar writes dh_ads_closed.
Ads and opt-out
The only advertising seller on dailyholes.org is Adsterra (adsterra.com), declared in ads.txt with this account's publisher id. Ads are non-personalized (ad_storage, ad_user_data and ad_personalization are always denied) and load only after you accept. The Social Bar has a visible × close button, remembered across visits. To opt out of interest-based advertising at the industry level, visit https://optout.aboutads.info/ , https://optout.networkadvertising.org/ or https://adssettings.google.com/ ; Adsterra's own policy is at https://adsterra.com/privacy-policy/ .
Your requests
Email contact@dailyholes.org to ask what the consent key means, to object, or to ask for the key's purpose in writing. You can delete dh_consent and dh_ads_closed yourself in the browser. I have no account database to export. I do not knowingly collect children's data.
DNT and changes
Global Privacy Control is honored as a rejection, as above. A plain Do Not Track header is not a reliable signal in current browsers, so I do not branch on it separately. Material changes show a new dateModified on this page. The check date is 30 September 2026.
Questions I keep getting
Do you sell data?
No. There is no customer list on this site. The only ad seller is Adsterra, which serves non-personalized placements after you accept; ad_storage, ad_user_data and ad_personalization stay denied.