1. Who we are and what this policy covers
This Privacy Policy explains how StreamEast (“StreamEast”, “we”, “us”) handles personal information when you visit https://streameastca.com, read our articles, use the fixture schedule, subscribe to the newsletter or send us a message. It applies to this website only. It does not apply to any third-party website you reach from here, and it does not apply to any streaming aggregator, mirror domain or application that happens to use a similar name — we are not affiliated with any of them.
StreamEast is an independent editorial publication. We write about how sport is broadcast and distributed online. We do not host, restream, embed, index or link to unauthorised broadcasts, we do not operate a media player, and we do not sell subscriptions. This matters for privacy because it means we have no viewing history, no playback logs and no account database to lose.
The data controller for the purposes of the EU and UK General Data Protection Regulation is StreamEast Editorial, 1055 West Georgia St, Suite 2400, Vancouver, BC V6E 3P3, Canada. You can reach us at [email protected] or on +1 (604) 555-0188.
2. Our data principles
Before the detail, the four commitments the rest of this document implements:
- Collect as little as possible. If a feature can work without personal data, it is built that way.
- Keep it on your device where we can. Colour mode and fixture reminders never leave your browser.
- Never sell or rent. We do not sell, rent, licence or trade personal information, in any jurisdiction, for any price. There is no exception buried later in this document.
- No behavioural advertising. We run no ad network, no retargeting pixels and no cross-site identifiers.
3. Information we collect
3.1 Information you actively give us
- Contact form submissions. Your name, email address, optional phone number, chosen subject and the message text. You provide these deliberately, and we use them only to answer you.
- Newsletter subscriptions. Your email address, and the date of the subscription so we can evidence consent.
- Correspondence. If you email us directly, that email and its contents.
- Copyright and legal notices. The information required by the process described on our DMCA page, which by law includes identifying details of the complainant.
3.2 Information collected automatically
- Server logs. Our hosting provider records the requested URL, a timestamp, the HTTP status, the referring page, a user-agent string and a truncated IP address. These logs exist for security and capacity planning. IP addresses are truncated at source (the final octet of IPv4 or the final 80 bits of IPv6 are dropped) so that individual visitors are not identifiable from them.
- Aggregate page counts. We count page views in aggregate. We do not build visitor profiles, do not use fingerprinting, and do not attempt to link visits across sessions or devices.
3.3 Information from third parties
None. We do not buy contact lists, we do not enrich data from brokers, and we do not receive audience segments from advertising platforms.
4. Information we deliberately do not collect
So there is no ambiguity, the following are not collected by this site: precise geolocation; contacts or calendars; device identifiers such as advertising IDs; biometric data; payment card details (we take no payments); account passwords (there are no accounts); any special-category data under Article 9 GDPR; any record of which fixtures you looked at or which reminders you set.
5. Why we process data and on what legal basis
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Replying to your message | Name, email, phone, subject, message | Legitimate interests (Art. 6(1)(f)) — answering a request you initiated |
| Sending the weekly digest | Email address | Consent (Art. 6(1)(a)), withdrawable at any time |
| Keeping the site available and secure | Truncated IP, user-agent, request logs | Legitimate interests (Art. 6(1)(f)) — network and information security |
| Understanding which articles are read | Aggregate, non-identifying counts | Legitimate interests (Art. 6(1)(f)) — editorial planning |
| Handling a copyright or legal notice | Whatever the notice contains | Legal obligation (Art. 6(1)(c)) and establishing or defending legal claims |
| Remembering your colour mode and reminders | Local browser storage only | Strictly necessary for a function you requested; no consent banner required |
6. Browser storage we use
We set no advertising or analytics cookies. What we do use is your browser's own local storage, which stays on your device and is never transmitted to us:
| Key | Purpose | Lifetime |
|---|---|---|
se-theme | Remembers whether you chose light or dark mode | Until you clear site data |
se-cookie-ok | Stops the storage notice reappearing on every page | Until you clear site data |
se-saved-matches | The fixture reminders you set on the schedule page | Until you clear site data or remove them |
se-last-submission | Session-only copy of a form you submitted, used to personalise the thank-you page | Until the browser tab is closed |
Full detail, including how to clear each item, is on the Cookie Policy page.
7. Third parties and data sharing
We keep the third-party surface deliberately small. Fonts, icons, scripts and stylesheets are served from our own domain rather than a public CDN, precisely so that visiting a page does not announce your visit to another company.
- Hosting provider. Processes server logs on our behalf under a data processing agreement.
- Email provider. Receives the contents of messages you send us, because that is how email works.
- Newsletter platform. Stores subscriber email addresses and consent timestamps.
- Image delivery. Photographs may be delivered from an image CDN, which necessarily sees the request. If you prefer no third-party image requests at all, the site is designed to work with the images mirrored locally, and our published source includes a script to do exactly that.
We may disclose information where we are legally required to, where it is necessary to establish or defend a legal claim, or to prevent imminent harm. We will tell you when we do so unless we are legally prohibited from telling you.
8. International transfers
Our infrastructure is located in Canada and the European Union. Where a processor transfers personal data outside the EEA or the UK, that transfer is covered by an adequacy decision or by Standard Contractual Clauses together with a transfer risk assessment. You may request a summary of the safeguards applied to a specific transfer.
9. How long we keep things
| Category | Retention period | Then what |
|---|---|---|
| Contact form messages and email correspondence | 24 months from the last message in the thread | Permanently deleted |
| Newsletter subscriber records | Until you unsubscribe, plus 6 months of suppression data | Suppression record kept so we do not re-add you |
| Truncated server logs | 30 days rolling | Overwritten |
| Aggregate page counts | Indefinitely (contains no personal data) | — |
| Copyright and legal notices | 7 years | Archived, then deleted |
10. Security measures
All traffic is served over TLS with HTTP Strict Transport Security. The site is static, which removes entire classes of vulnerability: there is no database of readers, no content management system exposed to the internet and no user login to compromise. Administrative access requires hardware-backed two-factor authentication. Dependencies are pinned and reviewed. No security posture is perfect, and we do not claim otherwise — we claim only that we hold very little that would be worth stealing.
11. Your rights
11.1 If you are in the EEA or the United Kingdom
You have the right to be informed; of access; to rectification; to erasure; to restriction of processing; to data portability; to object to processing based on legitimate interests; and to withdraw consent at any time without affecting the lawfulness of processing before withdrawal. You also have the right not to be subject to solely automated decision-making with legal or similarly significant effects — which we do not carry out at all.
11.2 If you are in California
Under the CCPA as amended by the CPRA you have the right to know what personal information is collected, used and disclosed; to delete it; to correct it; to opt out of sale or sharing; and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined in the CCPA, and we have not done so in the preceding twelve months. We collect no sensitive personal information as defined by the statute. Exercising any right will never result in a degraded service.
11.3 If you are in Canada
Under PIPEDA you may request access to personal information under our control, challenge its accuracy, and complain to the Office of the Privacy Commissioner of Canada.
11.4 Other jurisdictions
Where local law grants you stronger rights than those above, we apply the stronger standard rather than the minimum.
12. How to exercise your rights
Email [email protected] with “Privacy request” in the subject line, or use the contact form and choose “Something else”. Tell us which right you are exercising and give us enough information to find your records — usually the email address you used.
We respond within 30 days, extendable by a further 60 days for genuinely complex requests, in which case we will tell you why within the first 30. There is no charge unless a request is manifestly unfounded or excessive. We may ask a verification question, but we will not ask you to create an account or send identity documents unless the request concerns data whose wrongful disclosure would be harmful.
13. Children's privacy
This site is intended for a general adult audience and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has sent us personal information, contact us and we will delete it promptly. Parents and guardians should be aware that unauthorised streaming sites frequently carry advertising that is entirely unsuitable for minors — a further reason to prefer licensed broadcasters.
14. Do Not Track and Global Privacy Control
We honour Global Privacy Control signals. In practice this changes nothing about your visit, because we perform no tracking, sale or sharing to opt out of. We mention it so the position is explicit rather than assumed.
15. Data breach procedure
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and notify affected individuals without undue delay where the risk is high. Our notification will describe what happened, what data was involved, what we have done and what you should do. We maintain an internal breach register regardless of whether notification is required.
16. Changes to this policy
When this policy changes we update the “last updated” date at the top of the page and, for material changes, publish a short summary of what changed and why. We do not make material changes retroactive. Previous versions are available on request.
17. Contact and complaints
Privacy questions: [email protected]. Postal address: 1055 West Georgia St, Suite 2400, Vancouver, BC V6E 3P3, Canada. Telephone: +1 (604) 555-0188.
If you are not satisfied with our response you may complain to your local supervisory authority. In the UK that is the Information Commissioner's Office; in Ireland, the Data Protection Commission; in Canada, the Office of the Privacy Commissioner. We would prefer you raise it with us first, because we can usually fix it faster than a regulator can.