Privacy Policy
Off Script Wire is an independent publication (Off Script Wire (a publication of Ferrante LLC) — "we," "us," "our"). This policy covers the Off Script Wire website, our email newsletter, and correspondence you send to our inbox (reader mail, tips, advertising and press inquiries — see below).
We wrote this in plain language on purpose. The short version: we collect your email address if you sign up for the newsletter, and almost nothing else. We don't run ad trackers, we don't build profiles, and we never sell your data.
What we collect, and why
| What | When | Why | Where it lives |
|---|---|---|---|
| Your email address | You submit the newsletter signup form | To send you the newsletter you asked for | Cloudflare D1 (a database hosted by Cloudflare) |
| Bot-check signals | You load or submit the signup form | Cloudflare Turnstile verifies you're a human, not a bot. It may set a cookie and processes technical browser signals (such as your IP address and browser characteristics) to make that call | Processed by Cloudflare |
| Standard server/security logs | You visit any page | Cloudflare hosts and serves the site (CDN) and keeps ordinary technical logs to run and protect it | Processed by Cloudflare |
| Confirmation email delivery | You sign up (if double-opt-in is enabled) | We send a one-time "confirm your subscription" email so nobody can sign you up without your consent | Delivered via Resend (email delivery provider) |
The signup row that holds your email holds only what a double-opt-in list needs to run: your subscription status (pending, active, or unsubscribed), the timestamps of your consent and any later change, the source of the signup (which page or form you used), and one-way cryptographic hashes of your confirm and unsubscribe links — never the links themselves. We do not store your IP address, a device fingerprint, your location, or any browsing or advertising identifier against your email.
That is the complete list of what the signup row holds — there is no second set of fields we haven't told you about. Your address is also held by the providers that run the list for us; each one, and what it gets, is named under who processes your data.
What we deliberately don't do
- No ad trackers. No advertising pixels, no Google Analytics, no Meta/Facebook pixel, no retargeting.
- No analytics at all. Not a reduced or privacy-friendly analytics product — none. We don't run a page-view counter, a session recorder, or any measurement script. This site loads no third-party script of any kind except the Cloudflare Turnstile bot check on the signup form, and that only where the form appears. If we ever add analytics, this page changes first.
- No sale of data. We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising (in the sense those words carry under California law).
- No profiles. We don't know or track who you are as you browse. Nothing on this site is keyed to you as a person, and nothing follows you off it.
- No list rental or swaps. Your email address goes to exactly one list: ours.
Email you send us (reader mail, tips, and more)
Our Contact page invites reader mail, tips and story ideas, advertising inquiries, and press inquiries — all to the same inbox, [email protected]. That inbox is not covered by the newsletter-signup table above, so to be clear about it separately: whatever you send us (your email address, the message itself, and anything you attach) is kept in that inbox for as long as we reasonably need it to do the thing you wrote in for — following up on a tip, fixing a correction, or replying to an inquiry — and it is read by the people who run Off Script Wire, not a wider team or a third-party support tool.
Note for counsel: the Contact page tells tipsters "we read every tip, protect our sources" — Off Script Wire is not a traditional newsroom with an established shield-law posture, and we have not made any commitment here about what happens if that correspondence is ever subpoenaed. Advise whether that language needs a caveat, or whether a real source-protection policy should be built to back it.
Who processes your data for us
We use these service providers ("processors") to run the site and newsletter:
- Cloudflare, Inc. — website hosting and CDN, the D1 database that stores signup emails, and Turnstile bot protection.
- Resend — sends the one-time subscription confirmation email (and, once the newsletter is sending, may deliver newsletter email).
- beehiiv — our newsletter delivery platform. When you confirm your subscription, your email address and signup source are mirrored to beehiiv so it can send the newsletter itself. That copy is made at the moment you confirm, not when an issue is sent, so assume beehiiv holds your address from confirmation onward. Unsubscribing marks you unsubscribed on our own list; removing the beehiiv copy is a manual step today, so ask us and we'll delete that one too — see your choices.
Note for counsel: confirm the final ESP/sending stack before launch and update this list if it changes. On beehiiv specifically: the mirror arms on configuration alone — the code treats the presence of both beehiiv credentials as permission to mirror, and nothing in it checks whether a Data Processing Addendum has been executed. The DPA is therefore an obligation on us rather than a precondition anything enforces; please confirm one is executed, and tell us if it is not.
Both act on our instructions to provide these services. We don't hand your data to anyone else, with the ordinary exceptions everyone has: if the law requires it, to protect against fraud or abuse, or as part of a business transition (in which case this policy still applies to your data).
Cookies
The site itself does not set tracking cookies. Cloudflare Turnstile may set a functional cookie strictly to perform its bot check, and Cloudflare may use technically necessary cookies to serve and secure the site. There are no analytics cookies, because there are no analytics — see above.
Your watchlist stays on your device
Our markets pages let you save a watchlist of tickers to follow. That list lives entirely in your own browser (in its local storage) and is never sent to us — we keep no copy of it, we can't see what's on it, and it isn't tied to your email or any account. Clearing your browser data, or switching to a different browser or device, simply gives you a fresh, empty watchlist. It's a convenience, not a login.
How long we keep your email
- While you're subscribed: we keep your email address so we can send the newsletter.
- When you unsubscribe: we stop sending immediately. We keep your signup record — marked unsubscribed — rather than deleting it, solely so we never accidentally re-add you or email you again. It is not reduced to a separate, smaller "suppression list"; it is the same record, flagged.
- When you ask for deletion: today this is a manual process on our side, not instant or self-serve — email us and we will delete your record entirely (including the unsubscribed flag, if you prefer, though then a future signup would start fresh) within 45 days of your request. We're building a faster, self-serve path; until then, this is how it works. See "Your choices" below.
- Backups: we are not taking backups of the subscriber database at the moment, so there is no archived copy of your address sitting anywhere. The tooling is built and tested — an AES-256 archive, encrypted on our own system before any copy of it leaves that system, so the service that stores it never holds a readable list, with the file names encrypted along with the contents, and old archives pruned on a rolling basis for up to 60 days — but the job that would run it on a schedule is switched off, and nothing has run it on any recurring basis. When we do turn it on, this paragraph will say so before the first run: from then on a deleted address may persist in an archive for up to 60 days after deletion before it is fully purged.
Note for counsel: confirm suppression-record and backup retention wording against counsel/ESP practice, and confirm the 45-day manual-deletion window is the intended commitment given no self-serve deletion tooling exists yet. The backup paragraph above describes a mechanism that is implemented and proven (AES-256 with encrypted archive headers, written off-machine, integrity-verified each run, pruned at 60 days) but not scheduled: it has been run once, by hand, and its scheduled job is disabled pending the owner's decision to enable it. The 60-day figure is set in one place in the backup script and must move with this page or not at all.
Your choices
- Unsubscribe: every newsletter email includes an unsubscribe link that works in one click. You can also email us.
- Access, correction, deletion: email [email protected] and tell us what you'd like — a copy of what we have (it's your email address), a correction, or deletion. This is a manual process today, not an automated one: we'll verify the request and act on it — including deletion — within 45 days, regardless of where you live, and we don't discriminate against you for asking.
- Portability: the same access request above covers portability — since your record is just an email address and a few status timestamps, giving you a copy of it already gives you the data in a usable form.
State privacy laws (California and others)
Note for counsel: as a new publication we are almost certainly below the applicability thresholds of the California Consumer Privacy Act as amended by the CPRA (annual gross revenue, volume of consumers' data, or revenue from selling/sharing data), and below the thresholds of similar state laws (Virginia, Colorado, Connecticut, et al.). Texas is a distinct case: its TDPSA has no bright-line revenue or consumer-count threshold — it applies to any entity conducting business in Texas that processes personal data and doesn't qualify as a "small business" under SBA size standards, which is a determination, not an assumption, even though a single-person pre-revenue publisher will almost certainly qualify. Re-run this whole analysis at the first of: any outside revenue, 25,000+ subscribers in any single state, or any ad-tech/programmatic vendor added (whichever comes first) — counsel to confirm the specific trigger and revisit at engagement.
Whether or not those laws technically apply to us yet, we honor their spirit voluntarily:
- We do not sell your personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of on that front.
- California residents (and anyone else) may exercise access, correction, and deletion rights by emailing [email protected] with the subject line "Privacy request." We will verify the request using the email address on file and respond within 45 days.
- We will never treat you differently for exercising a privacy right.
Visitors outside the United States
This is a U.S.-focused publication. If you sign up from outside the U.S., your information will be processed in the United States by the providers above.
For EU/UK visitors: the legal basis for processing your email address is your consent — given when you submit the signup form and confirmed when you click the link in our confirmation email. You can withdraw that consent at any time (see "Your choices" above). Your information is transferred to and processed in the United States by the processors named above, each under their own data-transfer safeguards (such as Standard Contractual Clauses or a data-transfer-framework certification — see the counsel note below for the specifics we haven't yet confirmed). You also have the right to lodge a complaint with your home country's data protection supervisory authority (for UK residents, the ICO) if you believe we've mishandled your information.
Note for counsel: if meaningful EU/UK readership develops, advise whether further GDPR/UK-GDPR measures are needed (e.g. geo-blocking vs. accepting scope). Confirm the specific transfer-safeguard mechanism each processor's DPA relies on (Cloudflare, Resend and beehiiv) and update the sentence above to name it precisely rather than describing it generically.
Children
This site and newsletter are about business, money, and markets. They are not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us an email address, contact us at [email protected] and we'll delete it.
Changes to this policy
If we change what we collect or how we use it, we'll update this page and the "Last updated" date above. For material changes affecting subscribers, we'll say so in the newsletter itself. We will never quietly expand collection beyond what this page says.
Contact
Off Script Wire (a publication of Ferrante LLC)
8401 Mayland Dr #10740, Richmond, VA 23294
[email protected]
Off Script Wire is an independent news and information publication. See our Disclosures and Terms of Use.
The brief itself is a lot friendlier than this page.
You're almost in.
Check your inbox and confirm — that’s the whole setup.
One email, a few minutes, actually worth reading. Unsubscribe anytime. By subscribing, you agree to our Privacy Policy.