Privacy Policy

What happens to personal data when you visit minute.ly.

Last updated: 10 September 2026

This policy explains what happens to personal data when you visit minute.ly. It covers this website only, not the third-party sites we link to.

The short version

We run a publication. There are no accounts, no sign-up forms, no newsletter and no payments on this site, so there is very little about you for us to hold. What we do have is the ordinary technical record of a web request — the sort of thing every web server keeps — plus visitor statistics.

  • We do not sell personal data, and we never have.
  • We do not run advertising networks or behavioural ad targeting on this site.
  • We do not ask you to create an account, because there is nothing to log in to.
  • We do use analytics to see which articles are read.

Who we are

minute.ly is operated by MegaCloud Ltd., 3 San Lau Street, Hong Kong ("we", "us"). For anything in this policy, contact us at . As the operator of this site we are the data user for the personal data described below, in the sense used by Hong Kong's Personal Data (Privacy) Ordinance — equivalent to the controller under European data protection law.

What we collect

Information you choose to send us

If you email us, we receive whatever you put in that email — your address, your name if you sign it, and the contents. We keep correspondence so we can follow up on it. That is the only route by which you can hand us personal data directly; there are no forms on this site.

Information collected automatically

When any browser requests a page, our server records the request. This is standard web-server logging and it happens before we make any decision about it:

  • Your IP address
  • The page requested and the time of the request
  • Your browser's user-agent string
  • The referring page, when your browser sends one
  • The HTTP response we returned

We use these logs to keep the site running and to investigate faults, abuse and attacks. We look at them in aggregate; we do not try to work out who you are from them, and we do not combine them with anything else.

Analytics

We use Matomo to understand which articles get read and which links get clicked. Matomo records page views, clicks on links, approximate location derived from IP, device and browser type, and the referring source. It is configured to track page views and outbound link clicks.

Matomo is self-hosted on infrastructure we control at tracking.minute.ly. Your analytics data is not sent to a third-party advertising company and is not used to build an advertising profile of you.

Matomo may set first-party cookies in your browser to tell one visit from another and to group requests into a session, and it processes your IP address in order to derive an approximate location. Treat both as happening unless you have blocked them — see below for how.

Content delivery and security

This site is served through Cloudflare, which sits between your browser and our server. Cloudflare processes your IP address and request in order to route traffic, block attacks and tell humans apart from automated abuse. It may set its own security cookies to do so. Cloudflare acts as our processor for this.

Cookies

The application itself sets no cookies. It holds no session for you and does not need to know whether you have visited before. Cookies that do appear come from the two services above:

SourcePurposeType
MatomoDistinguishing visits and sessions for analyticsFirst-party, analytics
CloudflareBot detection and security challengesFirst-party, strictly necessary

You can block or delete cookies in your browser settings. Nothing on this site breaks if you do — there is no functionality that depends on them.

The rules we operate under

MegaCloud Ltd. is a Hong Kong company, so our baseline obligations come from the Personal Data (Privacy) Ordinance (Cap. 486) and its six Data Protection Principles. In short, those require us to collect only what is necessary for a lawful purpose connected to our activities, tell you what we are collecting and why, keep it accurate and no longer than needed, use it only for that purpose, protect it, and let you see and correct it.

This site is written in English and read internationally. Where you are in the United Kingdom or the EEA, the UK or EU GDPR may also apply to our handling of your data, and in that case our legal bases are:

WhatLegal basis
Server logs, security and abuse preventionLegitimate interests — running a site that stays up and is not defaced or overwhelmed
AnalyticsLegitimate interests — knowing which articles are worth writing. Where local law requires consent for analytics cookies, that consent
Replying to your emailLegitimate interests — answering someone who wrote to us

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights. You can object to any of it (see below).

Who we share it with

We do not sell, rent or trade personal data. We share it only with the service providers that make the site work:

  • Our hosting provider, which operates the servers the site runs on
  • Cloudflare, for content delivery and security
  • Our email provider, if you email us

We will also disclose data where we are legally required to — a court order, a lawful request from an authority — or where it is necessary to establish or defend a legal claim.

Where your data goes

We are established in Hong Kong. The servers this site runs on are operated by our hosting provider, and Cloudflare operates a global network in front of them, so a request may be handled by whichever of its data centres is nearest you. Your data may therefore be processed outside your own country, and outside Hong Kong. If you want to know where a specific piece of processing happens, ask us and we will tell you.

Where personal data is transferred out of the United Kingdom or the EEA, that transfer relies on the safeguards in Chapter V of the UK or EU GDPR, typically the Standard Contractual Clauses. Where data reaches Hong Kong, note that Hong Kong has not been the subject of an EU adequacy decision.

How long we keep it

We do not keep personal data for longer than we need it for the purpose we collected it for.

DataHow long we keep it
Server access logsFor as long as they are useful for security, fault-finding and investigating abuse. They are not kept indefinitely as a matter of policy, and we review them periodically.
Analytics dataFor as long as the statistics remain useful for editorial decisions, reviewed periodically.
Email correspondenceFor as long as the matter is live, then archived or deleted.

If you want to know what we currently hold that relates to you, or want it deleted, ask — see your rights below.

Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you
  • Correct it if it is wrong
  • Delete it
  • Restrict or object to how we use it, including objecting to analytics
  • Portability — receive it in a machine-readable form
  • Withdraw consent, where we relied on consent
  • Complain to your data protection authority

Under the Personal Data (Privacy) Ordinance you may make a data access request or a data correction request to us. The Ordinance gives us 40 days to comply; where the GDPR applies we will respond within one month. We will not charge you a fee, although the Ordinance permits one.

Practically speaking: because we hold no account for you, an access request usually means searching our logs and analytics for an IP address you supply. We will do that. Email .

If you are in California

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA as amended by the CPRA. You have the right to know, delete, correct and to be free from discrimination for exercising those rights.

Opting out of analytics

The reliable way to opt out is at your end: block cookies or JavaScript for this site in your browser settings, or use a content blocker. Nothing on this site depends on either, so blocking them costs you no functionality.

Many browsers can also send a Do Not Track or Global Privacy Control signal. Support for these signals is inconsistent across the web generally, and we would rather point you at a control that certainly works than imply a guarantee about one that may not.

Links to other sites

We link to other websites, including products we have an affiliate relationship with — this is disclosed in our terms and on the pages concerned. Once you follow a link away from minute.ly, you are on someone else's site under their privacy policy, not ours. If you click an affiliate link, the destination may set a cookie recording that you arrived from us, which is how they attribute a referral. We do not receive personal data about you from that process — only aggregate reports of how many referrals converted.

Children

This site is aimed at people who work with video professionally. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, tell us and we will delete it.

Security

The site is served over HTTPS. Our infrastructure sits behind Cloudflare, and administrative access is restricted to key-based authentication. No system is perfectly secure, and we do not claim otherwise — but there is also very little here to steal, because we deliberately collect very little.

Changes

If we change this policy we will update the date at the top. If a change materially affects how we handle personal data, we will say so prominently rather than quietly editing the text.

Contact

Questions, requests or complaints about privacy: , or by post to MegaCloud Ltd., 3 San Lau Street, Hong Kong.

If we do not resolve it, you can complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD). If you are in the United Kingdom you may instead complain to the Information Commissioner's Office, and in the EEA to your national supervisory authority.