Privacy Policy
What happens to personal data when you visit minute.ly.
Last updated: 10 September 2026
This policy explains what happens to personal data when you visit minute.ly. It covers this website only, not the third-party sites we link to.
The short version
We run a publication. There are no accounts, no sign-up forms, no newsletter and no payments on this site, so there is very little about you for us to hold. What we do have is the ordinary technical record of a web request — the sort of thing every web server keeps — plus visitor statistics.
- We do not sell personal data, and we never have.
- We do not run advertising networks or behavioural ad targeting on this site.
- We do not ask you to create an account, because there is nothing to log in to.
- We do use analytics to see which articles are read.
Who we are
minute.ly is operated by MegaCloud Ltd., 3 San Lau Street, Hong Kong ("we", "us"). For anything in this policy, contact us at hello [at] minute.ly. As the operator of this site we are the data user for the personal data described below, in the sense used by Hong Kong's Personal Data (Privacy) Ordinance — equivalent to the controller under European data protection law.
What we collect
Information you choose to send us
If you email us, we receive whatever you put in that email — your address, your name if you sign it, and the contents. We keep correspondence so we can follow up on it. That is the only route by which you can hand us personal data directly; there are no forms on this site.
Information collected automatically
When any browser requests a page, our server records the request. This is standard web-server logging and it happens before we make any decision about it:
- Your IP address
- The page requested and the time of the request
- Your browser's user-agent string
- The referring page, when your browser sends one
- The HTTP response we returned
We use these logs to keep the site running and to investigate faults, abuse and attacks. We look at them in aggregate; we do not try to work out who you are from them, and we do not combine them with anything else.
Analytics
We use Matomo to understand which articles get read and which links get clicked. Matomo records page views, clicks on links, approximate location derived from IP, device and browser type, and the referring source. It is configured to track page views and outbound link clicks.
Matomo is self-hosted on infrastructure we control at tracking.minute.ly. Your analytics data is not sent to a third-party advertising company and is not used to build an advertising profile of you.
Matomo may set first-party cookies in your browser to tell one visit from another and to group requests into a session, and it processes your IP address in order to derive an approximate location. Treat both as happening unless you have blocked them — see below for how.
Content delivery and security
This site is served through Cloudflare, which sits between your browser and our server. Cloudflare processes your IP address and request in order to route traffic, block attacks and tell humans apart from automated abuse. It may set its own security cookies to do so. Cloudflare acts as our processor for this.
Cookies
The application itself sets no cookies. It holds no session for you and does not need to know whether you have visited before. Cookies that do appear come from the two services above:
| Source | Purpose | Type |
|---|---|---|
| Matomo | Distinguishing visits and sessions for analytics | First-party, analytics |
| Cloudflare | Bot detection and security challenges | First-party, strictly necessary |
You can block or delete cookies in your browser settings. Nothing on this site breaks if you do — there is no functionality that depends on them.
The rules we operate under
MegaCloud Ltd. is a Hong Kong company, so our baseline obligations come from the Personal Data (Privacy) Ordinance (Cap. 486) and its six Data Protection Principles. In short, those require us to collect only what is necessary for a lawful purpose connected to our activities, tell you what we are collecting and why, keep it accurate and no longer than needed, use it only for that purpose, protect it, and let you see and correct it.
This site is written in English and read internationally. Where you are in the United Kingdom or the EEA, the UK or EU GDPR may also apply to our handling of your data, and in that case our legal bases are:
| What | Legal basis |
|---|---|
| Server logs, security and abuse prevention | Legitimate interests — running a site that stays up and is not defaced or overwhelmed |
| Analytics | Legitimate interests — knowing which articles are worth writing. Where local law requires consent for analytics cookies, that consent |
| Replying to your email | Legitimate interests — answering someone who wrote to us |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights. You can object to any of it (see below).
Who we share it with
We do not sell, rent or trade personal data. We share it only with the service providers that make the site work:
- Our hosting provider, which operates the servers the site runs on
- Cloudflare, for content delivery and security
- Our email provider, if you email us
We will also disclose data where we are legally required to — a court order, a lawful request from an authority — or where it is necessary to establish or defend a legal claim.
Where your data goes
We are established in Hong Kong. The servers this site runs on are operated by our hosting provider, and Cloudflare operates a global network in front of them, so a request may be handled by whichever of its data centres is nearest you. Your data may therefore be processed outside your own country, and outside Hong Kong. If you want to know where a specific piece of processing happens, ask us and we will tell you.
Where personal data is transferred out of the United Kingdom or the EEA, that transfer relies on the safeguards in Chapter V of the UK or EU GDPR, typically the Standard Contractual Clauses. Where data reaches Hong Kong, note that Hong Kong has not been the subject of an EU adequacy decision.
How long we keep it
We do not keep personal data for longer than we need it for the purpose we collected it for.
| Data | How long we keep it |
|---|---|
| Server access logs | For as long as they are useful for security, fault-finding and investigating abuse. They are not kept indefinitely as a matter of policy, and we review them periodically. |
| Analytics data | For as long as the statistics remain useful for editorial decisions, reviewed periodically. |
| Email correspondence | For as long as the matter is live, then archived or deleted. |
If you want to know what we currently hold that relates to you, or want it deleted, ask — see your rights below.
Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct it if it is wrong
- Delete it
- Restrict or object to how we use it, including objecting to analytics
- Portability — receive it in a machine-readable form
- Withdraw consent, where we relied on consent
- Complain to your data protection authority
Under the Personal Data (Privacy) Ordinance you may make a data access request or a data correction request to us. The Ordinance gives us 40 days to comply; where the GDPR applies we will respond within one month. We will not charge you a fee, although the Ordinance permits one.
Practically speaking: because we hold no account for you, an access request usually means searching our logs and analytics for an IP address you supply. We will do that. Email hello [at] minute.ly.
If you are in California
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA as amended by the CPRA. You have the right to know, delete, correct and to be free from discrimination for exercising those rights.
Opting out of analytics
The reliable way to opt out is at your end: block cookies or JavaScript for this site in your browser settings, or use a content blocker. Nothing on this site depends on either, so blocking them costs you no functionality.
Many browsers can also send a Do Not Track or Global Privacy Control signal. Support for these signals is inconsistent across the web generally, and we would rather point you at a control that certainly works than imply a guarantee about one that may not.
Links to other sites
We link to other websites, including products we have an affiliate relationship with — this is disclosed in our terms and on the pages concerned. Once you follow a link away from minute.ly, you are on someone else's site under their privacy policy, not ours. If you click an affiliate link, the destination may set a cookie recording that you arrived from us, which is how they attribute a referral. We do not receive personal data about you from that process — only aggregate reports of how many referrals converted.
Children
This site is aimed at people who work with video professionally. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, tell us and we will delete it.
Security
The site is served over HTTPS. Our infrastructure sits behind Cloudflare, and administrative access is restricted to key-based authentication. No system is perfectly secure, and we do not claim otherwise — but there is also very little here to steal, because we deliberately collect very little.
Changes
If we change this policy we will update the date at the top. If a change materially affects how we handle personal data, we will say so prominently rather than quietly editing the text.
Contact
Questions, requests or complaints about privacy: hello [at] minute.ly, or by post to MegaCloud Ltd., 3 San Lau Street, Hong Kong.
If we do not resolve it, you can complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD). If you are in the United Kingdom you may instead complain to the Information Commissioner's Office, and in the EEA to your national supervisory authority.