Privacy Policy
What this site collects, who else receives it, how long it is kept, and exactly how to make us stop.
The short version
CompatGrid is a research site. It has no accounts, no logins, and no shopping cart, so we ask you for nothing. What we do have is advertising and affiliate links, and those bring third parties — mainly Google and Amazon — who set cookies and build advertising profiles. That is the whole privacy story of this site, and everything below is the detail of it.
- We do not sell your data for money.
- We do allow advertising partners to use cookies for personalised ads, which several US state laws treat as "selling" or "sharing" even though no money changes hands. You can switch it off — see Your Privacy Choices.
- We honour the Global Privacy Control browser signal automatically. If your browser sends it, you are opted out before you read this sentence.
- If you are in the EEA or the UK, no advertising or analytics cookies are set until you consent, and you can withdraw consent at any time.
1. Who we are
CompatGrid (https://compatgrid.com) is operated by MakhoolDesigns L.L.C., whose publisher and editor of record is Michael Joshua Makhool. For data protection purposes we are the controller of the personal data described here.
Postal address: 100 Riverfront Dr., Apt. 1901, Detroit, MI 48226
General contact: [email protected]
Privacy requests: [email protected]
We are a small US-based publisher and have not appointed a Data Protection Officer; GDPR Art. 37 does not require one for processing of this kind.
TODO(owner): confirm the postal address above matches the domain's WHOIS record. A mismatch between the identity in this policy and the identity in WHOIS is the kind of inconsistency that turns a routine review into a rejection.
2. What we collect
Collected automatically when you visit
- Server and CDN logs — IP address, user-agent string, referring URL, requested URL, timestamp, and response status. These are generated by the hosting platform and the CDN in the ordinary course of serving a web page and are used for security, abuse prevention, and diagnosing faults.
- Cookies and similar storage — see the Cookie Policy for the full table of what is set, by whom, and for how long.
- Advertising identifiers and inferences — our advertising partners may read and write cookies and device identifiers, and may infer interests from your browsing across this and other sites.
Collected only if you give it to us
- Anything you put in an email to one of our addresses — your address, your message, and whatever else you choose to include.
What we do not collect
- No accounts, passwords, or profiles — there is nothing to sign up for.
- No payment data. Purchases happen entirely on the retailer's site, under the retailer's own privacy policy.
- No special-category data under GDPR Art. 9, and no sensitive personal information as defined by the CCPA. We do not ask for it and we have no use for it.
3. Advertising, Google, and third-party vendors
This site is supported by advertising. The following disclosures are required of us by Google's publisher policies and are reproduced here in substance:
- Third-party vendors, including Google, use cookies to serve ads based on a user's prior visits to this website or other websites.
- Google's use of advertising cookies enables it and its partners to serve ads to users based on their visit to this site and/or other sites on the Internet.
- Users may opt out of personalised advertising by visiting Google Ads Settings.
- Users may opt out of some third-party vendors' use of cookies for personalised advertising at aboutads.info/choices, or, in Europe, at youronlinechoices.eu.
Google and its ad-serving partners set cookies under the google.com, doubleclick.net, and googlesyndication.com domains, including the DoubleClick advertising cookie. Google's own description of how it uses data from sites that use its services is published at policies.google.com/technologies/partner-sites.
Who receives data from this site
| Recipient | Role | What they receive | Their policy |
|---|---|---|---|
| Google LLC (AdSense / Ad Manager) | Advertising, ad measurement | IP address, device and browser data, advertising cookie IDs, pages viewed | policies.google.com/privacy |
| Amazon.com Services LLC (Associates Program) | Affiliate attribution | Referral and click data when you follow one of our Amazon links — collected by Amazon on its own site, not by us | Amazon Privacy Notice |
| Our consent management platform | Recording and enforcing your consent choices | Consent state, a consent record ID, timestamp | TODO(owner): name the chosen CMP and link its policy |
| Hosting and CDN providers | Serving the site, security, caching | IP address, request logs | TODO(owner): name the host and CDN and link their policies |
| Analytics provider | Aggregate traffic measurement | TODO(owner): complete once an analytics tool is chosen, or delete this row | TODO(owner) |
TODO(owner): this table must match reality. It is the one part of this policy that goes stale on its own — every new ad partner, analytics tool, or embedded widget adds a row. Re-check it whenever the ad stack changes, and at minimum every twelve months.
Google discloses the full list of ad technology providers that may serve ads through its platforms at Google's ad technology providers list. In the EEA and UK, the specific vendors permitted to process your data are those you consent to in our consent banner, and you can review and change that list at any time.
4. Why we process data, and on what legal basis
Legal bases are stated for visitors covered by the GDPR or UK GDPR.
| Purpose | Legal basis |
|---|---|
| Serving the site, security, abuse prevention, fault diagnosis | Legitimate interests (Art. 6(1)(f)) — operating and defending a website. Balanced against your interests; the data is minimal and short-lived. |
| Storing and reading non-essential cookies | Consent (Art. 6(1)(a) plus the ePrivacy Directive / PECR) |
| Personalised advertising and ad measurement | Consent (Art. 6(1)(a)) |
| Non-personalised (contextual) advertising | Legitimate interests for the contextual serving itself; consent for any storage on your device that is not strictly necessary. |
| Affiliate link attribution | Consent, where the retailer's cookie is set through our page |
| Replying to an email you send us | Legitimate interests — responding to a person who contacted us |
You can withdraw consent at any time and it is as easy to withdraw as it was to give — use Your Privacy Choices. Withdrawing consent does not make the processing that happened beforehand unlawful.
Profiling and automated decisions
Personalised advertising involves profiling: our advertising partners build interest profiles and use them to decide which ad to show you. We make no automated decisions that produce legal effects or similarly significantly affect you, and we do not use profiling for anything other than advertising.
5. How long we keep things
| Data | Retention | Why that long |
|---|---|---|
| Server and CDN request logs | Up to 30 days, then deleted or aggregated | Long enough to investigate an incident, short enough to limit exposure |
| Consent records | Up to 24 months from the date of the choice, or until you change it | We are required to be able to demonstrate that consent was given — keeping the record is the obligation |
| Cookies | Per the durations listed in the Cookie Policy | Set by whoever sets the cookie |
| Emails you send us | Up to 24 months after the matter is closed | Continuity if you write again; then it goes |
| Privacy request records | Up to 24 months | Evidence that we handled the request, which the state laws expect |
Where a period is not fixed, the criteria we apply are: how long the data is genuinely useful for the purpose it was collected for, any legal or accounting obligation to keep it, and whether keeping it any longer adds risk without adding value. Data held by third parties — Google's advertising data, for example — is retained under their own policies, not ours.
6. International transfers
We operate from the United States, so if you visit from outside the US your data reaches the US. Our providers are largely US-based and several transfer data internationally themselves.
For transfers of EEA and UK personal data, we rely on the recipient's participation in the EU–US Data Privacy Framework (and its UK Extension) where available, and otherwise on the European Commission's Standard Contractual Clauses. Google LLC participates in the Data Privacy Framework.
TODO(owner) ⚖️: confirm with counsel, for each named provider, which transfer mechanism actually applies, and whether a GDPR Art. 27 EU representative (and a UK Art. 27 representative) is required. The exemption for "occasional" processing is unlikely to cover continuous behavioural advertising to EEA visitors. This is an open question, not a settled one.
7. Your rights
If you are in the EEA, the UK, or Switzerland
You have the right to:
- access the personal data we hold about you, and get a copy;
- have inaccurate data corrected;
- have data erased;
- restrict how we process it;
- object to processing based on legitimate interests;
- receive your data in a portable format;
- withdraw consent at any time; and
- complain to your national supervisory authority. In the UK that is the Information Commissioner's Office. You can complain without contacting us first, though we would rather you gave us the chance to fix it.
Providing data to us is not a statutory or contractual requirement. You are not obliged to provide anything, and nothing on this site is withheld if you do not.
If you are in California
Under the CCPA as amended by the CPRA, you have the right to:
- know what personal information we collect, the sources, the business or commercial purposes, and the categories of third parties it goes to;
- delete personal information we collected from you;
- correct inaccurate personal information;
- opt out of the sale or sharing of your personal information, including sharing for cross-context behavioural advertising;
- limit the use of sensitive personal information — we collect none, so there is nothing to limit; and
- not be discriminated against for exercising any of these rights. Nothing about this site changes if you opt out.
We do not require you to create an account to make a request — there are no accounts.
If you are in Colorado, Connecticut, Oregon, New Jersey, or another US state with a privacy law
You have broadly the same rights: access, correction, deletion, portability, and the right to opt out of targeted advertising and of the "sale" of personal data. Several of these states — Colorado, Connecticut, Oregon and others — require us to honour a universal opt-out signal, which we do (see Global Privacy Control below).
Connecticut, from 1 July 2026: Connecticut's amended law removes the volume threshold entirely for any entity that sells personal data. There is no "we are too small" argument in Connecticut once a sale occurs. We treat Connecticut visitors as in scope.
TODO(owner) ⚖️: counsel must answer whether serving programmatic advertising is a "sale" under Colorado, Oregon, New Jersey and Connecticut, all of which define "sale" to include exchange for other valuable consideration. The comfortable assumption that a small site triggers none of these laws is wrong, and Connecticut is the most exposed.
How to make a request
- Email [email protected] with what you want us to do.
- We will ask for whatever is proportionate to confirm we are talking to the right person. Because we hold almost nothing that identifies anyone, this is usually limited to the information already in your message — we will not ask you for identity documents to answer a question about a cookie.
- We respond within 45 days, extendable once by a further 45 days if the request is complex, and we will tell you if we extend. California opt-out requests are actioned within 15 business days. GDPR requests are answered within one month.
- An authorised agent may act for you if you give them written permission and we can verify it.
If we refuse — the appeals process
Colorado, Connecticut, Virginia and several other states give you a right to appeal a refused request, and that appeal has to go somewhere different from the original request. If we decline, we will tell you why and how to appeal.
- Send the appeal to [email protected] within 30 days of our decision.
- We respond in writing within 45 days, explaining what we decided and why.
- If we still refuse, we will give you a link for submitting a complaint to your state Attorney General.
8. Global Privacy Control
If your browser or an extension sends the Global Privacy Control signal — the Sec-GPC: 1 header or navigator.globalPrivacyControl — we treat it as a valid request to opt out of the sale and sharing of your personal information, and our consent platform applies it automatically. You do not have to click anything and we do not ask you to confirm. This is required in California, Colorado and Connecticut, among others, and California's Attorney General has enforced it.
9. Your Privacy Choices
Use this control to reopen the preference centre, change any consent choice, and register an opt-out of the sale or sharing of your personal information:
You can also, independently of us:
- turn off ad personalisation at Google Ads Settings;
- opt out of participating vendors at aboutads.info/choices or optout.networkadvertising.org;
- block or delete cookies in your browser settings — see the Cookie Policy for how; and
- enable Global Privacy Control in a browser or extension that supports it.
10. Children
This site is written for adults buying smart-home equipment. It is not directed to children under 13, we do not knowingly collect personal information from them, and we do not tag any part of this site as child-directed content. If you believe a child has provided us with personal information, email [email protected] and we will delete it.
11. Security
The site is served over HTTPS and is a static site — there is no database of visitors to breach, because we do not keep one. We use reputable providers and keep access to our accounts limited and protected by multi-factor authentication. No method of transmission over the internet is completely secure, and we do not claim otherwise.
12. Changes to this policy
We review this policy at least every twelve months and whenever the advertising stack changes. The "last updated" date at the top of this page always reflects the current version. If we change it in a way that materially affects you, we will say so prominently on the site rather than quietly editing the page.
If we ever want to use data we already hold for a new purpose, we will tell you about that purpose before we do it.