English
1. Controller and scope
SO8OO is a hobby amateur-radio and radio-science project operated by Piotr, the licensed operator publicly identified by the unique Polish amateur-radio callsign SO8OO. The operator is the controller of personal data processed directly by sdr.so8oo.net. Contact: piotr@so8oo.net. This policy covers the website, WebSDR receiver, FT8DB and callsign profiles, Radio Meteors archive, comments, public chat and the installable web app. SO8OO does not sell personal data.
2. Data processed and why
- Delivery and security. A request can generate an access log containing the IP address, date and time, requested path and query, HTTP status, bytes sent, referrer, browser/user-agent and response time. We use this to deliver, secure, diagnose and protect the service.
- Operational traffic totals. Independently of optional Matomo, delivery of a public WordPress document increments a first-party aggregate containing only the UTC minute, a broad route group, a broad technical class (browser-like, bot-like or unknown) and a count. The class is derived during the request from the connection address and user-agent, but this aggregate does not retain the full IP address, user-agent, path/query, cookie or visitor identifier. It measures HTTP document entries, not unique people, and cannot reliably prove that an entry was made by a human. Minute totals are also copied as numeric event values to a separate measurable in the same self-hosted Matomo installation, solely to draw operational charts. This copy is sent by the SO8OO server, not the visitor's device, and contains none of the excluded visitor identifiers. Matomo sees only the bridge process's technical connection metadata and creates synthetic visit rows which do not describe a visitor.
- Estimated server sessions. Independently of
browser analytics and consent, a successful final request for a
public HTML document can update a short-lived session estimate.
The server derives a daily HMAC from the Europe/Warsaw local
day, connection IP address and user-agent, using a secret held
locally by WordPress. Session state contains only that HMAC and
the last-seen UTC time; it does not contain the raw IP address
or user-agent and is removed after about two hours. A new
estimate starts when the daily HMAC is new or the preceding
qualifying document was strictly more than 30 minutes earlier;
it always resets at Warsaw midnight. Only a UTC time bucket,
broad route group and numeric session count remain in the
15-day aggregate. Matomo receives only these sums, never the
HMAC or its source values. This estimates sessions, not unique
people: shared networks can merge visitors and an IP or
user-agent change can split one visitor. Pages opened entirely
from an offline PWA or service-worker cache are invisible to
the server. Historical reconstruction from nginx logs is less
exact because those logs do not contain
AcceptorSec-Fetch-*navigation headers; it uses document path, method, status and user-agent heuristics and remains labelled as an estimate. - Privacy-choice reliability totals. While the
temporary Matomo choice panel is active, the site makes a
best-effort request to add the first successfully saved choice
to a daily total: allow button, decline button or Escape. Pressing
Escape is treated as decline and stores the same preference.
Apart from a short-lived, choice-neutral receipt, no stored row
links the selected answer to an IP address, user-agent, URL,
Matomo ID, cookie or visitor identifier. A hash of a signed
random one-use receipt is scheduled for deletion within about
three hours and exists solely to prevent duplicate counting.
The shared choice endpoint is deliberately excluded from the
nginx access log. After a local day closes, only the three
resulting daily totals are copied to the separate Matomo
presentation measurable; current-day values remain available
in the local operator panel. Once the relevant Google tags are
active, an eligible page receives up to two other signed
one-use per-page receipts through the same fixed, same-origin,
no-access-log endpoint. The CMP receipt is issued only where the
global CMP loader is eligible; the delivery receipt only where
the official recovery tags are eligible. The latter adds
Google's broad ad-delivery status to a UTC-minute total: extension-level blocker,
network-level blocker, no blocker, unknown, or a finalized missing
callback when the page ends or after ten seconds. The other adds only a CMP
useractioncompleteresult to a daily allowed/not allowed total; a persistedtcloadedstate is not counted as a new choice. Browser and installed standalone PWA pages use the same delivery-status callback and timeout. New delivery-status reports are disabled with the recovery tags as of 15 September 2026; existing totals follow the retention periods below. Source requests from ten exact operator/infrastructure addresses are dropped before incrementing without retaining the address. The status minutes are held closed for ten minutes and the resulting numeric totals are copied by the server to the Matomo presentation measurable. They are best-effort page reports, not unique people, and create no browser event in the consented Matomo measurable. - Consented reach totals. After analytics consent, an eligible page can receive a small pool of signed, random, one-use receipts. The browser can then report only its fixed client mode (desktop web, mobile web or installed standalone PWA), a stable broad page class and fixed reached milestones: page ready, 50%/90% scroll, 30/120 seconds while the tab is visible and focused, or entry into named page zones such as the receiver, waterfall, greyline, results, daily/hourly archive, article or comments. The local table stores only UTC minute, compact fixed metric and count. It does not receive coordinates, pointer or key movement, entered text, URL/query, title, callsign, record ID, cookie or visitor ID. Visible/focused time is only a technical foreground measure, not proof of attention. Closed totals are copied by the server as numeric Event Values to the aggregate presentation measurable; they do not create passive browser events in the consented visitor measurable and therefore do not turn an otherwise bounced visit into an interaction. These totals describe only consenting browsers and cannot be linked into an individual journey.
- WebSDR. The receiver processes connection and control data such as selected band, frequency, mode and view. A name or amateur callsign you enter is sent to the receiver and may appear in its public listener list. Functional storage remembers a receiver identifier, view and nickname/callsign.
- Comments. If you comment, WordPress stores the comment, name, email address, optional website, IP address, browser user-agent and time. The name, comment and optional website are public; the email and IP address are not displayed. Comments need no public WordPress account. Comment-field cookies are created only when you select the save-details checkbox. Visitor avatars are disabled, so this site does not automatically request Gravatar for comments.
- Website chat. The chat displays a public Discord channel. Google Identity Services is loaded only when you press Enable Google sign-in. Google then supplies an ID token containing an account identifier, verified email, display name and optional picture. The site verifies it with Google, derives a one-way email hash for abuse prevention and sends your display name, picture and message to Discord, where they become public in the channel and on this site. The token and profile remain in browser storage until expiry, logout, withdrawal or deletion. Do not post sensitive information.
- FT8 observations. FT8DB records unencrypted amateur-radio transmissions received at SO8OO, including callsigns, decoded text, UTC time, band/frequency, signal report, communicating callsigns and a Maidenhead locator only when transmitted over the air. Callsigns and locators can relate to identifiable radio amateurs. We publish receiver-side observations and aggregate profiles to document propagation; they are not claims about a person's identity or current location.
- Analytics. If you consent, self-hosted Matomo records page URL/title, referrer, approximate location and device/browser information, page views, outbound/download clicks, engagement time and selected interaction events. Two action-scoped dimensions distinguish desktop web, mobile web or standalone PWA and a stable broad page class. Events can include deliberate receiver retunes (bounded source/band/mode labels, without exact frequency in the event name), FT8 controls, Radio Meteors virtual archive/detail page views, callsign-profile navigation and support outcomes. Matomo masks two bytes of an IP address before storage and is reached through this site's same-origin HTTPS proxy; data is not sent to Matomo Cloud. This consent-based browser stream is separate from the identifier-free operational totals described above. Analytics is not required to use the receiver. The two streams may be compared only as aggregate coverage by time and broad route; they are not joined through visitor IDs, cookies or individual visit records. On 19 August 2026 the browser-analytics series was started anew. The earlier measurable contains the historical mixed-methodology series through that cutover and remains a separate archive; it receives no new normal browser-tracking hits. From the cutover onward, new browser-tracking hits are written only to a new active clean-series measurable and only after consent. The archive and active browser series remain separate from the aggregate presentation measurable described above. That presentation measurable represents server-supplied totals and synthetic bridge visits, not people, and is not used as a browser-visitor series.
- Advertising. Where required and according to your choices, Google AdSense and the vendors listed in the consent panel may store or access device information and process IP address, browser/device identifiers, approximate location, page context and ad interactions to select, deliver, protect and measure ads. Google and its partners may use advertising identifiers to select ads based on prior visits to this or other sites only as permitted by your choices. Refusing optional consent does not block the core receiver. When your choices do not permit personalized or non-personalized ads, Google may serve limited ads. These do not use personal data for ad personalization. Delivery still uses your IP address; fraud prevention can use cookies, local storage and Shared Storage solely to detect invalid traffic. Google may show a non-blocking privacy message for this mode. Closing the consent window does not grant consent. Matomo analytics stays off unless you allow it. Ad-blocking recovery prompts and their detection tags are disabled; supporting SO8OO through Buy Me a Coffee is voluntary. Reopen Privacy & cookie settings in the footer to change or withdraw consent. You can also use Google My Ad Center for Google-wide advertising controls.
- Local settings. The app and tools use localStorage, sessionStorage and Cache Storage for receiver settings, presets, interface state, install prompts, up to 20 local dig@44 searches, the expiring chat session and offline assets. They remain in the browser until reset, expiry or browser-data deletion and are sent only when a chosen function needs a request.
- Listener support pass. After the operator verifies a Buy Me a Coffee payment, the supporter can redeem a private random code on the Support page. The SO8OO server stores only a selector, an HMAC of the code, status, issue/expiry dates and an optional operator-only label. The browser receives an opaque secure cookie. Previously, this suppressed Google's ad-blocking recovery reminder, now disabled for everyone. Existing passes can still be managed on the Support page; a pass does not become analytics or advertising consent.
3. Cookies and browser storage
- Necessary or functional: WebSDR
ID,viewandusername(session or persistent; the current browser-enforced maximum is about 400 days),so8oo_lang(one year), operator login cookies, optionalcomment_author_*cookies (one year after the checkbox),__Host-so8oo_analytics_choice(the allow/decline preference for up to 180 days),__Host-so8oo_listener_pass(only after a valid supporter code is entered, until that pass expires, the browser's own cookie limit, or earlier deletion), and local PWA/interface settings until reset. - Analytics after consent: Matomo
_pk_id.*(about 393 days),_pk_ses.*(30 minutes) and, where used,_pk_ref.*(up to about six months). - Optional external services: Google Identity
may set
g_state(observed up to about 180 days) after you activate sign-in. AdSense and consent vendors use the names and lifetimes shown in the consent panel and their own policies.
4. Recipients and external services
Project-controlled servers host WordPress, WebSDR, FT8DB, Radio Meteors and Matomo. Depending on the page or function, connection metadata or submitted data may also reach Google (Identity and AdSense), Discord (chat, avatars and media), CARTO (map tiles), and unpkg/CDN infrastructure (Leaflet files). Buy Me a Coffee, YouTube, QRZ and Discord invite pages receive data when you follow their links. Providers can process data outside the EEA under their own terms and transfer safeguards. See Google's partner-sites explanation, Google advertising technologies, the Google advertising vendor list, Discord Privacy Policy and CARTO Privacy. Where a transfer outside the EEA applies, SO8OO uses the transfer mechanism disclosed for the selected provider, such as an adequacy decision or standard contractual clauses. You may contact SO8OO for the information available about a specific transfer and safeguards.
5. Retention
- Nginx access logs rotate daily with 14 archived files and are ordinarily retained for no more than about 15 days.
- Operational page-entry aggregates are scheduled for hourly removal after the 15-day cutoff. Sent Matomo-presentation queue points use the same 15-day cutoff and unsent points a 30-day recovery cutoff. Daily privacy-choice totals use a 25-month cutoff; duplicate-prevention receipt hashes are scheduled for deletion within about three hours. Funding delivery-status and consented-reach minute aggregates use the 15-day cutoff; CMP decision totals use the same 25-month cutoff as other daily choice totals.
- Estimated-session state contains only a daily HMAC and last-seen time and is scheduled for hourly removal after about two hours. Estimated-session count aggregates use the 15-day cutoff; Matomo presentation receives only their numeric sums.
- At this policy date Matomo's automatic deletion is not enabled. The historical browser archive through 19 August 2026 remains separately retained while its final retention decision is pending; it receives no new normal browser-tracking hits. In the active consent-only browser series, raw visit records currently remain until manual deletion, with a production target of 180 days; derived aggregate reports currently remain until manual deletion, with a target of 25 months. The policy will be kept aligned with the active administration settings.
- Comments remain while the discussion is published, normally indefinitely, unless moderation, a valid request or law calls for removal or longer preservation.
- Chat rate-limit state lasts about two minutes; local moderation tracking (email hash, message ID, name and short preview) up to 24 hours; a ban record until unbanned. Discord retains channel messages under its rules until they are removed there.
- Active listener-pass records remain until their operator-set expiry or revocation. Expired and revoked records are scheduled for deletion after a further 90 days. A failed-code rate-limit key is an HMAC of the connection IP and lasts 15 minutes.
- Raw FT8 observations use a rolling operational window. Aggregate callsign statistics remain while FT8DB operates or until no longer needed. Browser data remains until its stated expiry, logout, reset or deletion by the user.
6. Legal bases
We rely on consent for optional analytics, personalized advertising and optional device access; your requested action for receiver controls, chosen sign-in/chat functions and a listener support pass; legitimate interests for security, abuse prevention, service reliability, minimal aggregate traffic and consent-control measurement, comments/community features and amateur-radio propagation research; and legal obligations where applicable. You can withdraw consent without affecting prior lawful processing and can object to processing based on legitimate interests. Optional profile, comment and chat data is voluntary: without it you can still listen, but cannot publish that comment/message or use the related sign-in feature.
7. Your rights
Subject to applicable law, you may request access, correction, erasure, restriction or portability, object to processing, withdraw consent through the footer settings, and complain to the Polish data-protection authority, UODO. To locate data, provide enough information such as a comment URL/date, chat email or callsign/time range; identity verification may be needed. SO8OO makes no solely automated decisions producing legal or similarly significant effects.
8. Children
The service is not directed at children and the core receiver needs no account. A child should not submit a comment, chat message or optional identity data without a parent or guardian's involvement. A parent or guardian may contact SO8OO about removal.
9. Changes and contact
This policy may change when services, vendors or settings change. The current version and effective date are published here. Privacy requests: piotr@so8oo.net.
Back to top