Legal
Privacy Policy
Last updated: August 26, 2026
This Privacy Policy explains how 209 Times collects, uses, discloses, and protects information when you visit or interact with 209times.com.
1. Who we are and what this policy covers
209 Times operates this news and community-information website at 209times.com. This policy covers the public website, its forms and comments, newsletters, advertising and analytics integrations, and the restricted administration area used by authorized staff. In this policy, “we,” “us,” and “our” refer to 209 Times.
2. Information we collect
Information collected automatically
When you access the website, Cloudflare and our systems may process your IP address, requested URL, date and time, referring page, browser and device characteristics, user agent, security signals, and information needed to route traffic, prevent abuse, diagnose failures, and enforce rate limits.
Comments
When you submit a comment or reply, we collect your name, email address, comment text, IP address, browser user agent, the article and reply context, moderation status, and submission timestamps. Comments are stored as pending until moderated. If approved, your name, comment, and submission date may appear publicly; your email address, IP address, and user agent are not published.
Contact messages
The contact form collects your name, email address, message, security-verification token, and associated network information. The message is validated in memory and forwarded through Maileroo to our configured recipient. The application does not intentionally persist contact submissions in D1, KV, R2, browser storage, logs, or generated files, but Maileroo and the recipient mailbox may retain the resulting email under their own settings and policies.
Anonymous tips and attachments
The anonymous form does not ask for your name or email address. It processes your message, optional filenames and attachments, a security-verification token, and associated network information. Attachments may be JPEG, PNG, WebP, GIF, AVIF, or PDF files. Files, filenames, image metadata such as EXIF location data, document properties, and file contents may identify you.
Anonymous messages and attachments are validated in memory and forwarded directly through Maileroo. They are not intentionally persisted by the application in D1, KV, R2, browser storage, logs, or generated files. “Anonymous” does not mean invisible: Cloudflare processes the request, Turnstile may receive your IP address for verification, Maileroo processes the email, and the recipient mailbox may retain it.
Newsletter subscriptions
When you subscribe, we collect your first name, last name, email address, security-verification token, and associated network information. Your subscriber information is sent to Mailchimp and may be copied into a short-lived, tenant-scoped Cloudflare KV cache so authorized administrators can list and manage active subscribers. You can unsubscribe using the link in a newsletter or contact us.
Authorized administrator information
For authorized administrators, we process account name, email address, password credentials in protected form, role and tenant memberships, account status, session tokens, IP address, user agent, security and rate-limit records, password-reset and activation records, optional two-factor secrets and backup codes, and administrative activity metadata. Content, media, and revisions submitted by administrators may also identify the person who performed an action.
Advertising interactions
We maintain our own contextual advertising records. When an active ad with a destination is opened through our ad redirect, we increment an aggregate click count; that record is not linked by the application to a named visitor. When configured, Google AdSense may separately process device, cookie, network, page, and advertising-interaction information subject to the regional controls described below.
3. Sources of information
We collect information directly from you when you submit a form, comment, newsletter signup, privacy choice, or administrator action; automatically from your browser, device, and Cloudflare when you use the website; and from service providers when they return verification, delivery, subscription, analytics, advertising, or security results.
4. How we use information
- Publish and moderate comments and communicate about moderation.
- Deliver contact messages, anonymous tips, newsletters, account notices, and password-reset or activation emails.
- Operate, secure, troubleshoot, and improve the website and its administration area.
- Detect spam, fraud, abuse, malicious traffic, and unauthorized access.
- Apply rate limits, validate requests, maintain sessions, and remember choices you ask the browser to save.
- Measure readership and site performance through Google Analytics, subject to regional consent settings.
- Provide and measure Google advertising, subject to regional consent and opt-out settings.
- Comply with law, enforce our rights, respond to lawful requests, and protect people and services.
5. Cookies and browser storage
We use cookies and similar browser storage for the following purposes:
- Necessary and requested functionality: administrator authentication cookies; a seven-day newsletter-popup dismissal timestamp; and, when a commenter leaves the default-selected preference enabled, their name, email address, and expiration timestamp for 30 days. Comment text and security tokens are never saved in browser storage.
- Administrator draft recovery: the restricted post editor may save only an unsaved new-post draft token. Post content itself is stored in D1 revisions, not browser storage.
- Analytics: Google Analytics may use cookies or similar technologies by default outside the EEA, United Kingdom, and Switzerland. In those regions, analytics storage remains disabled unless you consent through Google’s privacy message.
- Advertising: Google AdSense may use cookies or similar technologies by default outside the EEA, United Kingdom, and Switzerland, subject to U.S. state opt-outs and Global Privacy Control. In the EEA, United Kingdom, and Switzerland, advertising storage remains disabled unless you consent through Google’s privacy message.
Google’s certified consent management platform stores and communicates applicable consent and opt-out choices. The website no longer maintains its former times-privacy-consent-v1 record and removes stale copies when Google services are configured.
6. Analytics, advertising, and privacy controls
Google Analytics and AdSense are enabled by default outside the European Economic Area, United Kingdom, and Switzerland. In those regions, Google’s certified Privacy & Messaging platform requests consent before analytics or advertising storage is enabled and provides Consent, Do not consent, and Manage options choices.
We use Google’s advanced Consent Mode. When storage is denied, Google tags may still send consent status and measurements without cookies for modeling. These cookieless transmissions may include the page URL, IP address, timestamp, user agent, referrer, and coarse interaction information. Full cookie-based measurement and personalized advertising remain disabled until the applicable consent is granted.
In U.S. states supported by Google Privacy & Messaging, Google provides a “Do Not Sell or Share My Personal Information” control and communicates the resulting opt-out through the Global Privacy Platform. For users in applicable states, Google receives Global Privacy Control signals directly and applies restricted data processing to eligible ad requests. Analytics remains separate from the advertising opt-out.
You can reopen an applicable European consent message using the “Privacy and cookie settings” button at the top of this page or Google’s automatically displayed revocation link. Applicable U.S. visitors can use Google’s automatically displayed “Do Not Sell or Share” link. You may also clear browser site data or manage personalized advertising through My Ad Center. Learn more about how Google uses information from partner sites.
7. How information is disclosed
We disclose information only as reasonably necessary for the purposes described in this policy:
- Cloudflare provides Workers hosting, network delivery and security, Turnstile, D1 database storage, KV caching and rate limiting, and R2 media storage.
- Maileroo sends contact messages, anonymous tips and attachments, moderation notices, and administrator account emails to the configured recipients.
- Mailchimp stores and manages newsletter subscriber information and sends newsletter communications.
- Google provides Analytics, AdSense, regional consent messages, and U.S. state opt-out controls under the defaults and choices described above.
- Authorized administrators and recipients may access information needed to publish content, moderate comments, manage subscriptions, answer messages, and operate the website.
- Authorities or other parties may receive information when required by law or reasonably necessary to protect rights, safety, and service integrity, or in connection with a reorganization or transfer of the publication.
8. Sale, sharing, and targeted advertising
We do not sell personal information for money. Some privacy laws may define the use of third-party advertising or cross-context behavioral advertising as “selling,” “sharing,” or targeted advertising even when no money changes hands. Google’s U.S. state controls allow applicable visitors to opt out, and Global Privacy Control triggers restricted data processing for eligible ad requests in applicable states. Our app-owned contextual ads and aggregate click counters remain active because they do not create a visitor advertising profile in this application.
9. Retention
- Comment records remain in D1 until deleted through moderation or no longer needed. Approved comments may remain available with the associated article.
- Contact and anonymous submissions are not retained in application storage, but resulting messages may remain with Maileroo and recipient mailboxes according to their settings, legal obligations, and business needs.
- Newsletter subscribers remain in Mailchimp until unsubscribed or permanently deleted. The administrative KV snapshot expires within 48 hours and is updated after a permanent deletion.
- Fallback form and public-read rate-limit counters generally expire after 60 seconds. Cloudflare may process additional network and security information under its own service terms.
- Administrator sessions expire after 12 hours without refresh. Administrator accounts, memberships, security data, and activity records remain while the account is active or as needed for security, legal, and operational purposes. Permanent account deletion removes the related credentials, sessions, two-factor data, memberships, profile, and activation tokens as implemented by the service.
- Remembered commenter details expire after 30 days and newsletter dismissal after seven days. Google retains applicable consent and opt-out choices according to its consent platform and browser-storage behavior.
10. Your privacy rights
Depending on where you live and whether a particular law applies to us, you may have rights to request access to or a copy of personal information, learn its categories and sources, correct inaccurate information, request deletion, obtain portable information, opt out of sale, sharing, or targeted advertising, limit certain uses of sensitive information, withdraw consent, or appeal a decision. You may also have the right not to receive discriminatory treatment for exercising a privacy right.
Submit a request through our contact page or email info@209times.com. Describe the right you want to exercise and the information or interaction involved. We may need to verify your identity or authority before acting, and legal exceptions may apply. Newsletter subscribers can also unsubscribe using the link in an email, and visitors can use the applicable Google privacy controls described above.
11. Security
We use administrative, technical, and organizational safeguards intended to protect information, including encrypted transport, access controls, tenant-scoped authorization, request validation, security headers, rate limiting, Turnstile, protected administrator sessions, and restricted secret access. No transmission or storage method is completely secure, so we cannot guarantee absolute security.
12. International processing
Cloudflare, Google, Mailchimp, Maileroo, and their subprocessors may process information in the United States and other countries. Those locations may have privacy laws different from those where you live. When required, providers may rely on contractual or other legal transfer mechanisms.
13. Children’s privacy
This website is a general-audience news service and is not directed to children under 13. We do not knowingly collect personal information from a child under 13. If you believe a child has provided personal information, contact us so we can review and delete it as appropriate.
14. External links
Articles, social links, advertisements, and other site content may link to websites we do not control. Their privacy practices are governed by their own policies. Review those policies before providing information.
15. Changes to this policy
We may update this policy when our practices, technology, providers, or legal obligations change. We will post the revised policy here and change the “Last updated” date. Material changes may also be communicated through another appropriate notice.
16. Contact us
For privacy questions or requests, contact 209 Times through the contact page or at info@209times.com.
