warmhop.com

About this domain

warmhop.com is a link redirection service. If you arrived here after clicking a link, that link was created by someone — most likely a job applicant — who wanted to know whether the material they sent was looked at.

What happens when you click one of these links

You are redirected to the real destination — someone’s GitHub profile, LinkedIn page, portfolio, or similar. That is the whole of what you experience, and it happens immediately.

At the same time, we record that the click happened. Depending on where you are, we record either a small amount of context or nothing beyond the fact and the time.

Everywhere, we record:

  • that a click occurred, and when

Outside the EU and UK, we also record:

  • the country and city your network appears to be in
  • whether you were on a desktop, phone or tablet
  • your browser family, such as “Chrome”
  • what kind of site you came from — an email client, an applicant tracking system, or directly — as a category, never the address itself
  • whether the click looked automated, such as an email security scanner

In the EU and UK we record only the click and the time. No location, no device, nothing else.

What we do not do

We think this list matters more than the one above.

  • We do not set cookies and we do not read anything stored on your device.
  • No code runs in your browser. There is no script, no tracking pixel, no fingerprinting.
  • We do not know who you are. We keep no identifier for you, so we cannot tell that two clicks came from the same person, and we cannot connect a click to a name, an email address, or an account.
  • We do not identify your employer. If the person who created the link labelled it with a company name, that label is theirs — we did not work out where you work, and we cannot.
  • We do not sell or share this data, we do not use it for advertising, we do not give it to data brokers, and we do not train models on it.
  • We do not track you anywhere else. This domain sees one click and never sees you again.

What the person who created the link sees

They see that a link they created was clicked, when, and — outside the EU and UK — the coarse context listed above. They see a category, not you.

They cannot see your name, your email address, your employer, your exact location, or any other link you have ever clicked.

How long we keep it

  • After 180 days we delete the city and the browser, keeping only the country and the device type.
  • After 365 days we delete the remaining detail, keeping only that a click happened and when.
  • After 24 months we delete it entirely.

Why we are allowed to do this

Outside the EU and UK we rely on legitimate interests under Article 6(1)(f) of the GDPR: giving someone visibility into whether material they shared professionally was engaged with, and telling human clicks apart from automated scans. We have carried out and documented a balancing assessment, and we can provide it on request.

In the EU and UK we deliberately do less, so that the only thing recorded is the click and its time.

Your rights, and one honest limitation

You have the right to object to this processing, and to ask what is held about you.

The limitation: because we keep no identifier for you, we genuinely cannot look you up. If you ask what we hold, there is nothing we can search by — which is a consequence of collecting so little, not an excuse. Article 11 of the GDPR covers this situation and does not require us to start collecting identifying information in order to be able to answer.

What we can do: if you tell us the specific link you clicked — the warmhop.com/r/... address — we can delete the records for that link. If you were sent a document containing one and want it dealt with, send us the link and we will.

You may also complain to your local data protection authority.

If you create links yourself, see our Privacy notice.

Global Privacy Control

If your browser sends a Global Privacy Control signal, we treat your click the same way we treat one from the EU: the click and the time, nothing else. We are not required to do this, since GPC applies to selling and sharing data and we do neither. We do it anyway.

Contact

Data controller: [LEGAL ENTITY NAME AND ADDRESS]

Contact: [PRIVACY CONTACT EMAIL]

EU representative (Article 27): [NAME AND ADDRESS — see ART27_EU_REPRESENTATIVE.md]

Last updated: [DATE]