Effective Date: 25th AUGUST 2025 EAT18:00
Meru Gossip Club (“we”, “us”, “our”, “Meru Gossip Club”) operates https://merugossipclub.co.ke (the “Site”). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights available to visitors and users of the Site. This policy is written to be clear and actionable while meeting common legal and platform requirements (Google Publisher, AdSense, etc.). By using the Site, users consent to the collection and use of information in accordance with this Policy.
1. Scope and Acceptance
This Privacy Policy applies to all visitors, users, contributors, commenters, subscribers, and registered users of the Site. It covers personal data collected via the Site, including via the web interface, forms, comments, email communications, cookies, log files, embedded content, and any connected services. Using the Site constitutes acceptance of this Privacy Policy.
2. Definitions
- Personal Data / Personal Information: Any information relating to an identified or identifiable natural person (e.g., name, email address, phone number, IP address).
- Processing: Any operation performed on personal data (collection, storage, organization, use, disclosure, deletion).
- Data Controller: Meru Gossip Club is the controller determining purposes and means of processing personal data collected on the Site.
- Data Processor: Third-party service providers who process personal data on our behalf (hosting, analytics, email providers).
- Cookies: Small text files placed on a device to store preferences and track usage.
3. Information We Collect
A. Information You Provide
- Comments and User Content: If you leave a comment, we collect the information shown in the comment form (name, email, website) and any content you submit. We also collect the commenter’s IP address and browser user agent for spam detection.
- Contact Forms & Emails: When you contact us (editor@merugossipclub.co.ke or other forms), we collect your name, email, phone (if provided), message, and any attachments.
- Account Registration: If the Site offers user accounts, we collect registration details (username, email, password — stored hashed) and profile information provided by the user.
- Subscriptions: If you subscribe to newsletters, we collect your email address and optional name.
B. Automatically Collected Information
- Technical Data: IP address, browser type and version, operating system, device type, screen resolution, language, referral URLs, dates and times of visits, pages accessed, and other diagnostic data collected via server logs and analytics.
- Usage Data: Pages visited, time spent on pages, navigation paths, clicks, and other interactions.
- Cookies and Similar Technologies: See Section 6 below.
C. Third-Party Sources
- Social Media: If you use social login or interact via our social media pages, we may receive profile data from that provider (subject to that provider’s permissions and your privacy settings).
- External Content/Embeds: Data that flows to and from embedded third-party content (e.g., YouTube, Twitter) as described in Section 7.
4. How We Use Your Information (Purposes & Legal Bases)
We process personal data for the following purposes and legal grounds:
- To Provide and Maintain the Site (Contractual / Legitimate Interest)
- Deliver site content and functionality, manage user accounts, and respond to communications.
- To Communicate with Users (Contractual / Legitimate Interest / Consent)
- Reply to inquiries, send service messages, and deliver newsletters (with consent).
- To Moderate and Manage User Contributions (Legitimate Interest)
- Detect spam, enforce rules, and maintain community safety.
- To Improve the Site & User Experience (Legitimate Interest)
- Analyze traffic, performance, and user behavior via analytics tools.
- To Serve and Personalize Advertising (Consent / Legitimate Interest depending on jurisdiction)
- Show relevant ads via third-party ad networks (e.g., AdSense) and measure ad performance.
- For Security, Fraud Detection & Legal Compliance (Legitimate Interest / Legal Obligation)
- Prevent abuse, respond to legal requests, and protect Site integrity.
- To Comply with Legal Obligations (Legal Obligation)
- Retain records and data required by law or respond to lawful requests by authorities.
5. Cookies, Tracking & Similar Technologies
Types of Cookies
- Essential Cookies: Required for site operation (session, login).
- Performance & Analytics Cookies: Collect aggregated metrics about site usage (Google Analytics).
- Functional Cookies: Remember preferences (language, display).
- Advertising / Targeting Cookies: Used by ad networks to serve personalized ads and measure effectiveness.
Cookie Control & Consent
- At first visit, users will be informed about cookie use. Where required by law, we request consent for non-essential cookies.
- You can manage or disable cookies via your browser settings. Note that disabling some cookies may impact Site functionality.
Specifics
- Duration: Some cookies are session-based (deleted when the browser closes), while others persist (e.g., “remember me” cookies for weeks/months).
- Examples: Google Analytics (
_ga,_gid), WordPress cookies for logged-in users, session cookies for comment forms, and third-party ad cookies.
6. Embedded Content and Third-Party Services
Our pages may include embedded content (e.g., YouTube videos, Twitter feeds, maps). Embedded content behaves as if the visitor visits the third-party site directly: those services may collect data, set cookies, and track interactions.
We use third-party providers for:
- Hosting and Infrastructure (e.g., InfinityFree).
- Analytics (e.g., Google Analytics).
- Ad Networks (e.g., Google AdSense).
- Email Delivery (e.g., Mailchimp or an SMTP provider).
- Spam & Bot Protection (e.g., Akismet).
- CDN/Performance Services (e.g., Cloudflare if in use).
Each third party has its own privacy policy; we recommend reviewing those policies for details on their data practices.
7. Who We Share Data With
We do not sell personal data. We may share personal data with:
- Service providers & processors: who perform services for us (hosting, analytics, email, payment processors).
- Advertising partners: for ad serving and measurement (subject to consent where required).
- Legal & Safety: to comply with legal obligations, enforce terms, or protect rights and safety.
- Business Transfers: if the Site or assets are sold or reorganized, personal data may be transferred as part of a business transaction — subject to privacy protections.
Whenever we share data with processors, we require contractual safeguards limiting their use to our instructions and protecting data appropriately.
8. Data Retention
We retain personal data only as long as necessary to fulfill the purposes described in this Policy, including to comply with legal obligations, resolve disputes, and enforce agreements.
- Comments and Associated Metadata: Retained indefinitely (unless removed by the author or admin).
- Account Data: Retained until account deletion plus a reasonable period for backup and legal obligations.
- Contact Forms & Messages: Retained while necessary for the communication and any follow-ups.
- Analytics Data: Aggregated/anonymized data retained per provider defaults; identifiable logs retained for a limited period.
If you wish to request deletion or limited retention, see Section 11 (Your Rights).
9. Security Measures
We implement reasonable administrative, technical, and organizational measures to protect personal data:
- HTTPS/SSL for data in transit.
- Server and application-level access controls.
- Password hashing and limited credential access.
- Regular backups and security monitoring.
No online system is completely secure. We cannot guarantee absolute security; however, we will notify affected users and authorities of any data breaches when required by law.
10. International Transfers
Data collected via the Site may be transferred to, and processed in, countries other than your country of residence. These countries may have different data protection laws. When transfers occur, we implement appropriate safeguards — such as standard contractual clauses, where required — to protect personal data.
11. Your Rights & Choices
Subject to local law, you may have the following rights:
- Access: Request a copy of personal data we hold about you.
- Correction: Ask us to correct inaccurate or incomplete data.
- Deletion: Request erasure of personal data (subject to legal retention obligations).
- Restriction: Request restriction of processing under certain circumstances.
- Portability: Request a machine-readable copy of certain personal data.
- Object: Object to processing (e.g., direct marketing).
- Withdraw Consent: If we rely on consent, you can withdraw it at any time.
To exercise these rights, contact us at info@merugossipclub.co.ke. We may ask for identification to verify requests. We will respond within the timeframes required by applicable law.
12. Children’s Privacy
The Site is not directed to children under the age of 13 (or the local age of digital consent). We do not knowingly collect or retain personal data from children under that age. If we learn that we have collected such data without parental consent, we will take steps to delete it. If you believe we may have data of a child, contact us immediately.
13. Cookies & Tracking — Detailed Examples
- Comment Cookies: If you leave a comment, a cookie stores your name, email, and website for one year.
- Login Cookies: Login cookies last for two days, and “Remember Me” lasts 14 days.
- Editor Cookies: If you edit or publish a post, a cookie storing the post ID will be saved for one day.
- Analytics Cookies: Google Analytics cookies (
_ga,_gid,_gat) typically persist from 24 hours to two years depending on the cookie.
14. Third-Party Advertising & Opt-Out
We may use third-party advertising networks that use cookies and other technologies to serve ads. To opt out of personalized ads:
- Visit Google Ad Settings: https://www.google.com/settings/ads
- Use browser-based opt-outs or privacy extensions.
Note: Opting out of personalized ads does not stop ads; it only stops personalization based on your browsing.
15. Links to Other Websites
The Site may contain links to other websites. We are not responsible for the privacy practices or content of those sites. We encourage users to read the privacy policies of linked sites before providing personal data.
16. Legal Bases for Processing (Where Applicable)
For users in jurisdictions that require legal bases (e.g., GDPR), our processing relies on:
- Contractual necessity where processing is necessary to provide the Site or services.
- Consent for optional services such as newsletters and non-essential cookies.
- Legitimate interests for site administration, security, analytics, and preventing fraud.
- Legal obligations where we must retain data to comply with laws.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When changes are material, we will post a prominent notice on the Site and update the “Effective Date” above. Continued use after such changes constitutes acceptance of the updated policy.
18. How to Delete or Export Your Data
To request deletion, correction, or export of your personal data:
- Email us at info@merugossipclub.co.ke with subject line “Privacy Request”.
- Include your name, email used on the Site, and a description of the request.
- We will verify your identity and respond within applicable regulatory timeframes.
We may retain anonymized or aggregated information after deletion requests for legitimate purposes (analytics, record-keeping).
19. Complaints & Supervisory Authorities
If you believe we have not addressed your request appropriately, you may lodge a complaint with your local data protection authority. For residents of the European Union, you may contact your national supervisory authority.
20. Contact Information
If you have questions, requests, or concerns about this Privacy Policy or our data practices, contact:
Meru Gossip Club
Email: info@merugossipclub.co.ke (or editor@merugossipclub.co.ke)
Address: Meru, Kenya
Response times: We aim to reply to privacy requests within 30 days. Complex requests may require more time.
21. Additional Notes for Specific Jurisdictions
- European Union (GDPR): If you are in the EU/EEA, you may have additional rights (see Section 11) and additional safeguards for international data transfer apply.
- California (CCPA/CPRA): California residents may have rights to know, delete, and opt out of sale of personal information. We do not sell personal information as defined by CCPA; however, California residents may contact us to exercise rights.
- Kenya & Local Laws: We process data consistent with Kenyan data protection standards. Local rules may apply.
22. Consent Statement
By using the Site, you consent to the collection and use of information per this Privacy Policy. Where we rely on consent for certain processing, you may withdraw consent at any time without affecting processing done prior to withdrawal.