HornCoreHornCore Gear that survives the season.

Privacy policy

Last updated 19 August 2026.

The short version

HornCore is a review site. There is no account to create, nothing to buy here, and no payment ever passes through us — so most of what a privacy policy usually has to cover does not exist.

Three things collect anything at all: the email list, if you join it; the link redirector, when you click through to a retailer; and website analytics, on every page. We do not sell or rent what we hold, we do not run advertising or retargeting trackers, and we make no attempt to work out who an anonymous reader is.

Who is responsible for it

HornCore. Anything in this policy — questions, corrections, requests, complaints — goes to info@horncore.net, which is read by a person.

When you read the site

You do not identify yourself and we do not try to identify you. There is no sign-in, and the session cookie the site software sets carries no identity for a reader who is not signed in.

Our host keeps standard web server logs — IP address, the page requested, the time, the browser's user agent — for its own operations and security. We do not mine them, build profiles from them, or join them to anything else on this page.

We use Google Analytics to count visits and see which reviews people actually read. It sets its own cookies and Google receives your IP address and processes it in the United States. We use it for aggregate numbers — how many, which page, roughly where from — and not to build a profile of you, and it is never joined to the email list.

We do not currently show a cookie banner, so analytics loads on every page unless you stop it. You can: block cookies for this site in your browser, use any content blocker (all of them block this), or install Google's own opt-out add-on. Nothing on the site behaves differently if you do.

Our typefaces load from Google Fonts, which means your browser fetches them from Google's servers and Google sees your IP address in the process. That is true of a large share of the web and is rarely disclosed; it is disclosed here because it is a request to a third party that you did not choose to make.

When you click an affiliate link

Product links go through our own redirector — a /r/ address on this site — which records the click and forwards you to the retailer. That is how we know which reviews are worth writing more of. Each click stores:

  • the time, and which link it was;
  • the page you came from and your browser's user agent;
  • a country, when our network gives us one;
  • whether it looked like a crawler rather than a person;
  • a salted one-way hash of your IP address — not the address. It exists so that four hundred clicks from one source are visibly one source. There is no key that turns it back into an address. We call it a pseudonym rather than anonymous, because that is what it is: it stands in for a visit, and nothing we hold ties it to a name, an inbox or an account.

A click is not linked to a person unless it came from one of our own emails, where the link carries the subscriber's own token. Traffic arriving from search, social or anywhere else stays anonymous, and there is no fingerprinting to make it otherwise.

Once you land on the retailer's site you are on their property and under their privacy policy. They set a cookie to remember that we sent you — that is what an affiliate link is. What comes back to us is a report about the sale, not the shopper: an order reference, an amount and our commission. We never receive your name, your address or your card details, and we could not ask for them.

When you join the email list

We store the address you gave us and your name if you gave one, along with which of our sites you subscribed from, where you signed up, the date, and a salted hash of the IP — the same one-way kind as above, kept as evidence that the subscription was real and to catch bot signups.

We also keep a consent record: the exact wording you agreed to, the date and how it was captured. Recording the wording rather than a tick is the point — “they ticked a box” is not evidence of what they agreed to.

You are recorded as pending and we do not mail you until you confirm the address. An unconfirmed address may be somebody else's, typed by mistake or on purpose, and mailing it would be spam whatever our intentions.

Consent is given to one brand and does not transfer. If we run another site, subscribing here does not put you on its list, and the two records are never joined into one picture of you.

Once you are subscribed we count what our own mail produces — clicks from it, and any commission attributed to them — so we can tell whether the newsletter is worth your inbox. Every email carries a one-click unsubscribe, it works without a login or a reply, and it takes effect immediately rather than in the ten days the law allows.

When you write to us

Email sent to us stays in the mailbox it arrived in, with whatever you put in it. We keep correspondence while it is useful — an unresolved correction, a conversation still running — and delete it when it is not. Do not send us anything sensitive; there is no reason a review site should ever need it.

How long we keep things

  • Click records: 400 days, then deleted automatically by a nightly job. That covers a full year of seasonal comparison plus the longest affiliate cookie window, and there is no reason to hold them longer.
  • Subscribers: for as long as you are on the list. When you unsubscribe, the record moves to unsubscribed rather than disappearing — a deleted record is one that can be re-imported and mailed again by mistake. Ask us to erase it entirely and we will.
  • Consent records: kept after you leave, because they are the evidence that we had permission in the first place. They hold no more than what is described above.
  • Sales reports from affiliate networks: kept for accounting. They identify an order, not a person.

Who else handles it

Only the suppliers that make the site work: our hosting provider, which runs the site and its database on servers in the United States; the service that delivers our email; Google, for analytics and fonts; and the affiliate networks, which report sales to us. None of them are given the data for their own purposes, and nobody buys anything from us — not a list, not a segment, not a single address.

If you are in the UK or the EEA, note that the site is hosted in the United States, so the little we hold is stored there.

Your rights, and what we can actually do

Wherever you are, you can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or tell us to stop mailing you — and you can withdraw consent at any time without giving a reason. In the UK and the EEA those are rights under the GDPR, along with objection, restriction and portability; in California and several other US states there are equivalents. We apply them to everyone because sorting readers by jurisdiction is more work than just honouring the request.

Write to info@horncore.net and we will answer within 30 days, usually far sooner. For the email list, the unsubscribe link at the bottom of every message is faster than we are.

One honest limit: we cannot look up your click history, and cannot delete it on request. A click record holds no name, no address and no account, and the IP inside it is a one-way hash — so there is nothing in it we can search by, and no way to prove a given row was yours. That is the same property that makes the records safe to keep, and it cuts both ways. They are deleted at 400 days regardless.

If you think we have handled your data badly, tell us first — we would rather fix it. You can also complain to your national data protection authority; in the UK that is the Information Commissioner's Office.

Security

The site runs over HTTPS. IP addresses are hashed with a secret held in server configuration rather than stored raw. We hold no card details, no bank details and no passwords for readers, because there is no account here and no checkout — the least risky data is the data you never collect.

Children

This site is written for adults and is not directed at children. We do not knowingly collect anything from a child under 16. If you believe a child has subscribed, tell us and we will delete the record.

Changes

When this policy changes the date at the top changes with it, and anything material — a new thing collected, a new supplier handling it — will be said plainly here rather than folded quietly into a paragraph. This is not boilerplate copied from another site: it describes what this one does, and it is rewritten when that changes.

Related

How we are paid, and what it does and does not change, is in the affiliate disclosure.