Corbin Floyd ← Back to the site
Privacy Policy

Privacy

Effective 16 August 2026  ·  Last updated 7 September 2026

This page explains what corbinfloyd.com records about a visit, how I use that information, and how to limit measurement.

On this page

1. Scope and Application

This Privacy Policy (the “Policy”) governs the collection, use, storage, disclosure and other processing of information obtained through the website located at the domain corbinfloyd.com, including all subpaths and subdomains thereof (collectively, the “Site”). By accessing or otherwise interacting with the Site, you acknowledge that you have read and understood the practices described in this Policy.

This Policy does not apply to any third-party website, platform, application, or service that may be linked to or referenced from the Site, including but not limited to professional networking platforms, code hosting platforms, and career services platforms. Such third parties maintain their own privacy practices, over which the Site exercises no control and for which it accepts no responsibility.

The Site is a personal portfolio operated by an individual. It does not offer goods or services for sale, does not process payments, does not maintain user accounts, and does not permit user registration or authentication of any kind.

2. Identity of the Controller

For purposes of the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the UK General Data Protection Regulation, and analogous frameworks, the controller of personal data processed through the Site is Corbin Floyd, an individual residing in the State of Florida, United States of America, contactable at the address set out in Section 21 of this Policy.

No data protection officer has been appointed, no such appointment being required under Article 37 of the GDPR given the nature, scope, context and purposes of the processing described herein. No representative has been designated pursuant to Article 27 of the GDPR.

3. Definitions

For the purposes of this Policy, the following terms have the meanings ascribed to them below:

4. Categories of Information Collected

The Site sends measurement requests to its own domain. Cloudflare processes and stores those records, and visit summaries are sent to my email account as described in Section 10. Browser and connection information may be combined to group related visits. The categories below describe what is recorded.

4.1 Information your browser reports

Table 1 — Information reported by your browser
What is recordedWhat it means
Page viewedWhich page or section of the Site you looked at.
Referring pageThe page you came from, where your browser reports one.
Link parametersThe query string attached to the page address, which may include campaign parameters.
Screen sizeThe dimensions of your device's screen.
Time zoneThe time zone your browser reports.
LanguageThe language preference your browser reports.
Automation indicatorsIndicators distinguishing an ordinary visit from automated traffic. The particular indicators are not published, for the reason given in Section 9.
Time on the pageHow long the page remained open.
Scroll depthThe furthest scroll position recorded.
Interaction countHow many times you clicked or tapped.
Input activityWhether the visit involved pointer movement, typing, touch, copying, or printing. Only the fact that such activity occurred is recorded. What was typed, selected, or copied is never recorded — see Section 5.
Estimated time in each sectionAn estimate based on how long each section was in the browser’s visible area; it does not show whether you were reading.
Window sizeThe dimensions of the browser window, which are distinct from those of the screen.
Display characteristicsThe pixel density of the display, and the light or dark and reduced-motion preferences your browser reports.
Device capabilityThe processor count, memory class, and number of touch points your browser reports. These are coarse values published by the browser to every site and describe a class of device, not a device.
Browser and platform versionThe browser and operating-system version your browser reports when asked.
Connection typeThe general class of connection your browser reports, such as a mobile or broadband category.
Visit identifierA value created in the browser to group records from one tab session. The browser keeps it for that session; records containing it follow the retention described in Section 12.

4.2 Information derived from the connection

The server also records information from the request and from Cloudflare’s network services:

Table 2 — Information derived from the connection
What is recordedWhat it means
Approximate locationCountry, region or state, city, and postal area, estimated from the connection. This estimate is approximate and is frequently wrong, particularly where a virtual private network, a corporate proxy, or a mobile network is used. It is never precise enough to locate a person, and it is never used to identify one.
Network operatorThe name of the organisation operating the network the visit came from — for example an internet service provider, a university, or an employer's corporate network.
Browser and operating systemWhich browser and operating system your device reports.
Network nameA public DNS name associated with the connection’s IP address, when one can be found. See Section 4.3 for how the IP address is used.
Connection characteristicsThe infrastructure location that served the request, the round-trip time of the connection, and the encryption and protocol versions used.
Automated-traffic categorisationWhere the infrastructure provider identifies the request as coming from a known automated agent, that categorisation.
Pseudonymised network addressA value derived from the network (IP) address, used to group visits from the same network. See Section 4.3.

Derived browser identifiers

The Site also records pseudonymous values derived from browser and connection characteristics. These help group related visits, including when cookies are unavailable.

4.3 Treatment of network addresses

Visitor records store a pseudonymous value derived from the network (IP) address instead of a separate raw IP-address field. The address is also used for a network-name lookup through Cloudflare's DNS service.

The pseudonymous value helps group visits from the same network. Cookies and recorded browser characteristics can also link related visits. Changing the network-address value does not delete earlier records or guarantee that later visits cannot be linked to them.

5. Information Not Requested

The Site does not deliberately request or extract the categories listed below. Page addresses, query strings, and referrers can nevertheless contain information supplied by whoever created a link. Those strings may enter the visit records described in Section 4 and are not screened for personal information.

6. Cookies and Local Storage

The Site sets first-party cookies only. It does not set, permit, or participate in the setting of third-party cookies, and it does not employ pixel tags, web beacons, clear GIFs, device fingerprinting services, or cross-site tracking technologies operated by any third party.

Table 3: Browser storage
TypePurposeDuration
First-party cookie Holds a pseudonymous browser identifier used to group repeat visits. Browser and connection characteristics may also be used for this purpose when cookies are unavailable. Up to 400 days
Temporary browser entry Groups measurement records from one visit. Until the tab's session ends
Temporary browser entry Remembers whether the opening animation has played. Until the tab's session ends
Local storage Saves the footer game's best score. Until cleared by the visitor or browser

The animation marker and game score support those features; they are separate from the visit identifier.

These cookies are configured restrictively: they travel only over encrypted connections, they cannot be read by scripts running in the page, and they are not sent when you visit other sites. Their actual lifetime may be shorter than stated, because several browsers cap how long any cookie may live regardless of what a site asks for.

No consent banner is presented. The controller's assessment is that the cookies described above are strictly necessary or, in the alternative, are deployed on the basis of the legitimate interests described in Section 8, and that the processing presents a low risk to the rights and freedoms of data subjects given its first-party, non-commercial, non-advertising character. You can block or delete cookies in your browser's site settings. Section 17 explains why this alone does not stop measurement.

7. Purposes of Processing

Information collected through the Site is processed exclusively for the following purposes:

  1. To determine whether the Site is being viewed by human beings, and in particular whether it is being viewed by prospective employers, recruiters, collaborators, or academic institutions, the Site being maintained by its operator for the purpose of seeking professional opportunities;
  2. To distinguish human visitors from automated traffic, including search engine crawlers, monitoring services, link-preview fetchers, vulnerability scanners, and scraping tools;
  3. To exclude the controller's own visits from measurement, so that the controller's activity does not distort the measurement of genuine interest;
  4. To understand which sections of the Site attract attention, in order to inform the Site's content and structure;
  5. To generate summary notifications to the controller when a visit occurs;
  6. To maintain the security, availability and integrity of the Site, and to detect and mitigate abusive or anomalous traffic.

Information collected through the Site is not used for advertising, behavioural targeting, audience segmentation, retargeting, lead generation, credit assessment, insurance underwriting, employment screening of visitors, or any form of automated decision-making producing legal or similarly significant effects concerning any individual.

8. Legal Bases for Processing

Where the GDPR or the UK GDPR applies to the processing described in this Policy, that processing is carried out on the basis of the controller's legitimate interests pursuant to Article 6(1)(f), namely the legitimate interest of an individual job-seeker in understanding whether and by whom their professional portfolio is being read, and the legitimate interest in maintaining the security and integrity of the Site.

The controller has considered the interests, rights and freedoms of data subjects and has concluded that such interests are not overridden, having regard to: the pseudonymised character of the data; the absence of advertising or commercial exploitation, and the provider processing described in Section 10; the information categories and URL-related limitations described in Sections 4 and 5; the limited and proportionate scope of collection; and the availability of means to block the Site's measurement requests, as described in Section 17. You may object to this processing at any time as described in Section 14.

9. Automated Filtering and Classification

Information collected through the Site is subject to automated evaluation for the purposes described in Section 7. That evaluation categorises traffic as human or automated and forms a general impression of whether a visitor may be acting in a professional or recruiting capacity. What that evaluation looks at is not published: describing it would tell the automated traffic it exists to catch exactly how to avoid being caught.

The evaluation produces a traffic classification for the controller. Classifications may also appear in email notifications processed by the providers described in Section 10. It does not produce legal effects concerning any data subject, does not similarly significantly affect any data subject, and does not constitute automated decision-making within the meaning of Article 22 of the GDPR. Nothing it produces affects what any visitor is shown or able to do on the Site.

Geographic attributes are not used to identify or to exclude any particular individual, such attributes being unreliable for that purpose.

10. Disclosure and Sub-Processors

The controller does not sell, rent, lease, licence, trade, or otherwise disclose information collected through the Site to any third party for monetary or other valuable consideration, and does not share such information for cross-context behavioural advertising. No advertising network, data broker, analytics vendor, marketing platform, or social media platform receives information collected through the Site.

The following providers process the Site's records or email notifications:

Table 4: Providers
EntityFunctionCategories processed
Cloudflare, Inc. Hosts the Site, processes and stores visit records, resolves network names, and sends email notifications. All categories described in Section 4
Google (Gmail) Receives and stores email notifications in the controller's email account. Visit summaries, including approximate location, network information, pages viewed, engagement measurements, and traffic classifications.

Cloudflare, Inc. additionally processes request metadata in its own capacity as a network and security provider, in accordance with its own privacy practices, over which the controller exercises no control. Information regarding those practices is published by Cloudflare, Inc.

The controller may further disclose information where required to do so by applicable law, regulation, legal process, subpoena, court order, or governmental request; where necessary to establish, exercise or defend legal claims; or where necessary to investigate or prevent fraud, abuse, or threats to the security of the Site or to the rights or safety of any person.

11. International Transfers

Records collected through the Site are stored in the United States. Accordingly, information collected from data subjects located in the European Economic Area, the United Kingdom, or Switzerland is transferred to and stored in the United States.

Such transfers are effected in reliance upon the standard contractual clauses adopted by the European Commission and, where applicable, the United Kingdom International Data Transfer Addendum, as incorporated into the controller's agreement with the sub-processor identified in Section 10. Given the pseudonymised identifiers and the information categories described in Sections 4 and 5, the controller assesses the residual risk arising from such transfers to be low.

12. Data Retention

Event Records are retained for so long as the Site remains in operation and the purposes described in Section 7 continue to apply. No fixed automated deletion schedule is presently implemented, and Event Records should therefore be understood to be retained indefinitely unless and until deleted. The controller may delete Event Records, in whole or in part, at any time and without notice, and does so periodically in the ordinary course.

Records are deleted in their entirety upon a verified request made pursuant to Section 14. Changing a pseudonymous network-address value does not delete existing records.

13. Information Security

The controller implements technical and organisational measures appropriate to the risk presented by the processing. Those measures include the encryption of traffic in transit, the storage of network addresses in pseudonymised form only as described in Section 4.3, and controls restricting access to the records to the controller alone.

Further particulars are deliberately not published. Describing security measures in detail is itself a security risk, and this document is written for the people whose information is described in it rather than for anyone seeking a description of the systems that hold it.

No method of transmission over the internet and no method of electronic storage is entirely secure. While the controller endeavours to protect information by commercially reasonable means, absolute security cannot be guaranteed, and no warranty to that effect is given.

14. Rights of Data Subjects

Subject to applicable law and to the limitations described below, you may be entitled to exercise the following rights in respect of Personal Data relating to you:

Limitation arising from pseudonymisation. The measurement system does not ask for your name or contact details. Recorded page addresses or referrers may nevertheless contain identifying information, as described in Section 5. As contemplated by Article 11 of the GDPR, the controller is ordinarily unable to identify the data subject to whom a given Event Record relates and may be unable to comply with a request under this Section unless you supply additional information sufficient to permit identification of the relevant records. Requests should therefore specify, so far as you are able, the approximate date and time of your visit and the network from which it was made.

No fee is charged for the exercise of these rights. Requests are ordinarily responded to within thirty days.

15. United States Privacy Notices

The following disclosures are provided for residents of States having enacted comprehensive consumer privacy legislation, including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana.

Categories of personal information collected. In the twelve months preceding the effective date of this Policy, the Site has collected the categories described in Section 4, which correspond to the statutory categories of internet or other electronic network activity information and, in respect of approximate location, identifiers.

Sale and sharing. The controller has not sold personal information and has not shared personal information for cross-context behavioural advertising in the twelve months preceding the effective date of this Policy, and does not do so. Because no sale or sharing occurs, no “Do Not Sell or Share My Personal Information” mechanism is provided.

Sensitive personal information. The Site does not deliberately request or extract sensitive personal information. Recorded page addresses or referrers may nevertheless contain information supplied by others, as described in Section 5.

Non-discrimination. The controller does not discriminate against any consumer for exercising any right conferred by applicable State privacy law.

Authorised agents. Requests may be submitted by an authorised agent on your behalf, subject to verification of the agent's authority.

16. Do Not Track and Global Privacy Control

The Site does not presently detect or respond to the DNT request header or to the Global Privacy Control signal. No uniform industry standard governs the interpretation of the DNT header. The Global Privacy Control signal operates, under applicable State law, to communicate an opt-out of the sale or sharing of personal information; as set out in Section 15, no such sale or sharing occurs, with the result that the signal has no operative effect in respect of the Site.

17. How to Prevent Measurement

To stop this site’s visit measurement, disable JavaScript or block requests to https://corbinfloyd.com/cf-loader-policy.json with a content blocker or network filter. Installing an extension alone may not block these requests.

Private browsing, clearing cookies, or blocking browser storage does not reliably stop collection or prevent visits from being linked. The measurement system also uses browser and connection characteristics to group related visits.

Blocking measurement requests leaves the Site's other features available. Disabling JavaScript also disables interactive features; static project summaries remain readable. The hosting provider still receives the connection information needed to serve the Site.

18. Children's Privacy

The Site is directed to a professional audience and is not directed to children. The controller does not knowingly collect personal information from any child under the age of thirteen, nor, where the GDPR applies, from any child under the age of sixteen. Should the controller become aware that information relating to such a child has been collected, that information will be deleted promptly. A parent or guardian who believes that such information may have been collected is invited to make contact as set out in Section 21.

19. Third-Party Links

The Site contains hyperlinks to third-party websites and platforms, including professional networking, code hosting, and career services platforms. Activation of such a hyperlink causes your browser to transmit a request to the operator of the destination site, which may collect information concerning you in accordance with its own practices. The controller does not transmit any information concerning you to such operators and is not responsible for their practices. You are encouraged to review the privacy policy of any destination site.

20. Amendments

This Policy may be amended from time to time in order to reflect changes to the Site, to the practices described herein, or to applicable legal requirements. Any amended Policy takes effect upon publication at this address, and the effective date appearing at the head of this Policy will be updated accordingly. Where an amendment materially changes what is collected or why, that change will be described rather than merely dated. Your continued use of the Site following publication of an amended Policy constitutes acknowledgement of the amended Policy.

21. Contact

Enquiries concerning this Policy, and requests to exercise any right described in Section 14 or Section 15, may be addressed to the controller by electronic mail at [email protected]. Please mark your communication for the attention of “Privacy” and include sufficient particulars to permit the identification of the records to which your request relates.