The Sun Magazine Privacy Policy

Privacy Policy

Last updated: February 8, 2023

Welcome!

Welcome to the website of The Sun at https://www.thesunmagazine.org (the “Website”), which includes all subdomains and subpages present and future. Thank you for choosing to visit and use the Website and otherwise interact with The Sun.

We take your privacy and the protection of Personal Information very seriously. We are providing this Privacy Policy (the “Policy”) to tell you about who we are, what Personal Information we collect from you and about you, and what we do with your Personal Information, all while you use the Website or otherwise interact with us. The Policy also explains your rights under the law, and how you can contact us, and the necessary authorities to enforce those rights. We ask that you please read it carefully.

Key Elements of the Policy

Here are the key elements of the Policy so you can know the most important parts right away to make an informed decision about your consent for our collection, use, disclosure, and processing of your Personal Information. You can find the details in the rest of the Policy.

Personal Information we collect from you but only with your consent What we do with it Third parties we share it with
Subscription Information; Delivery Information Manage your Subscription to The Sun Magazine; Deliver the Print Edition if applicable Companies that provide the infrastructure for the Website, specifically DigitalOcean and Multipub; USPS for delivery of the Print Edition
Account Information Manage your account and communicate with you about your account and Subscription Companies that provide the infrastructure for the Website, specifically DigitalOcean and Multipub, and e-mail providers
Donation Information Process your Donation and communicate with you about it Companies that provide the infrastructure for the Website, specifically DigitalOcean and Multipub, and e-mail providers
Billing Information Process your payments for your Subscription Fees or Donation Third-Party Payment Processor, specifically Stripe
Newsletter Information Send you our newsletters Companies that manage our mailing list, specifically Emma and SendGrid
Some Terms

Before we get started with the details, here are a few terms we think you should know as you read the Policy.

Data Protection Laws” refers to the laws designed to protect your Personal Information and privacy in the place where you live. These include: (i) the California Consumer Privacy Act (“CCPA”) and its related law the California Privacy Rights Act of 2020 (“CPRA”) that we apply to our activities in the United States; (ii) the “GDPR,” the European Data Protection Law that stands for “General Data Protection Regulation,” with the official name Regulation (EU) 2016/679 of the European Parliament and of the Council; and (iii) the “UK GDPR” which applies to our activities in the United Kingdom; please note that when the Policy refers only to the “GDPR,” this includes the UK GDPR as applicable. The Sun is committed to adhering to these and any other applicable Data Protection Laws.

Personal Information” is information we collect from you or about you and which is defined in the CCPA as “information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.” The similar concept in the GDPR is “personal data,” defined as “any information relating to an identified or identifiable natural person.” In either case, it can be as simple as your name or your e-mail address, or something more complicated like an online identifier (usually a string of letters and/or numbers) that gets attached to you. Any mention of “Personal Information” in the Policy shall also mean personal data as defined in the GDPR.

Other terms and definitions used in the Policy may be found in our Terms of Use, and will have the same meaning in the Policy as they do there.

About Us and Contacting Us

The Sun Publishing Company (“The Sun”) is a duly-registered, domestic non-profit organization in the State of North Carolina, USA, at the address listed below. Where the Policy refers to “The Sun,” it may refer to The Sun Publishing Company and/or its officers, directors, employees, agents, partners, principals, representatives, successors, and assigns, depending on the context. “The Sun Magazine” refers to the actual magazine published by The Sun, whether in digital or print form.

Under the CCPA and CPRA, The Sun does not meet the definition of a “business,” but we voluntarily conform to the obligations for businesses under the CCPA and CPRA, the gold standards for privacy and data protection in the United States. Under the GDPR, The Sun is a “data controller.” That means we collect Personal Information directly from you and determine the purpose and means of “processing” that data. “Processing” is a broad term that means collection, use, storage, transfer, or any other action related to your Personal Information; it is used in the Policy in that way. The CCPA defines processing as “any operation or set of operations that are performed on Personal Information or on sets of Personal Information, whether or not by automated means”; any use of “processing” in the Policy would also meet such definition.

If you want to ask us anything about what’s in the Policy, or anything else privacy- or data-related, or exercise any of your available privacy rights, you can e-mail:

The Sun Privacy Officer
privacy@thesunmagazine.org

Here is the mailing address for you as well:

The Sun Privacy Officer
107 N. Roberson Street
Chapel Hill, NC 27516
USA

Your Rights

You have the following rights regarding your Personal Information held by The Sun, and other privacy rights. Please note that not necessarily all of these rights may be available to you; this depends on the Data Protection Laws where you are located that apply to you. These rights may be exercised without affecting the price you pay for any use of the Website or your Subscription. Notwithstanding that, exercising certain of these rights may affect your ability to use some or all of the Website, or your Subscription.

  • The right to withdraw at any time your consent for The Sun to process your Personal Information;
  • The right to have your Personal Information erased from The Sun’s records;
  • The right to access your Personal Information and any relevant information around its processing and use;
  • The right to have a copy of your Personal Information given to you in an easy-to-read format so that you can transfer it to another business or data processor;
  • The right to have your Personal Information corrected or updated if you believe it is inaccurate or out of date;
  • The right to opt out of marketing communications we send you, at any time;
  • The right to know whether The Sun sells or shares your Personal Information (and if so, who gets it). Please refer to that information elsewhere in the Policy, though you can contact our Privacy Officer if you need additional information or clarifications;
  • The right to demand that The Sun not sell your Personal Information;
  • The right to restrict the processing of your Personal Information if it is inaccurate or if our processing or use of it is against the law; and
  • The right to refuse any marketing or advertising targeted at you by The Sun. Please note, however, that The Sun does not do any targeted marketing or advertising.

If you wish to exercise any of these rights, please contact our Privacy Officer at the contact information above, or refer to certain relevant sections further in the Policy.

Personal Information Collected from You and What We Use It For

In the table below, please find all the Personal Information we may collect from you directly, what we use it for, and the legal basis under the GDPR for us having and processing this Personal Information. Under the CCPA and CPRA, there is no equivalent concept. However, by submitting this Personal Information, you acknowledge having granted to The Sun your consent to process the Personal Information.

Personal Information category Personal Information processed What we use it for (the “purpose” of processing) Legal basis for processing under the GDPR
Contact Information Your name and e-mail address, and optionally your ZIP or Postal Code To communicate with you in reply to your inquiry or relating to a Letter to the Editor you wrote to The Sun Magazine Your consent in giving us this information
Account Information Your e-mail address To communicate with you about your account and Subscription; to allow you to log in to your account Your consent in giving us this information
Subscription Information Your name and mailing address To manage your Subscription Your consent in giving us this information
Donation Information Your name and e-mail address To communicate with you about your Donation and process your Donation Your consent in giving us this information
Billing Information Credit card holder’s name, billing address, credit card number, expiration date, and CVV/CVC number To process the payments for your Subscription Fees or Donation you make to The Sun Performance of a contract between you and us
Delivery Information Your name and mailing address Deliver your Print Edition of The Sun Magazine if you have chosen that option Performance of a contract between you and us
Newsletter Information Your name and e-mail address To send you our newsletters Your consent in giving us this information
Personal Information Collected about You from Third Parties and What We Use It For

Sometimes we get Personal Information about you from third parties. The table below explains the details about this Personal Information – what it is, where it comes from, what we do with it, and the legal basis for us having and processing this Personal Information under the GDPR. Under the CCPA and CPRA, the legal basis is your consent. None of this Personal Information comes from publicly-available sources.

Personal Information category Personal Information processed Who we get it from What we use it for (the “purpose” of processing) Legal basis for processing under the GDPR
Account Information Your e-mail address The third party who bought a Gift Subscription for you Create an account for you Performance of a contract
Subscription Information; Delivery Information Your name and mailing address The third party who bought a Gift Subscription for you Manage your Subscription and deliver your Print Edition (if applicable) Performance of a contract
Contact Information Your name Our third-party service provider Submittable To communicate with you via the Submittable messaging system about your Submission when you have created an account on Submittable Performance of a contract
Sensitive Personal Information

We do not collect any of what the CPRA or GDPR considers sensitive Personal Information from you, unless you voluntarily submit it to us, which we encourage you not to do.

Who We Transfer Your Personal Information To

We routinely share some of your Personal Information with certain types of third parties who are identified in the table below along with what they do with it. Some of those third-party recipients may be based outside your home jurisdiction. If you are in the European Economic Area or the UK — please see the Transfer of Your Personal Information Outside of the European Economic Area and the UK section below for more information including on how we safeguard your Personal Information when this occurs.

We will share Personal Information with law enforcement or other public or governmental authorities (including but not limited to the Internal Revenue Service) if: (i) we are required by applicable law in response to lawful requests, including to meet national security or law enforcement requirements, or are otherwise required to according to any applicable law; (ii) we believe it is necessary to investigate, prevent, or take action regarding illegal activities, fraud, or situations involving potential threats to the safety of any person, or any violation of The Sun’s Terms of Use; or (iii) we believe it is necessary to investigate, prevent, or take action regarding situations that involve abuse of the Website infrastructure or the Internet in general (such as voluminous spamming or denial of service attacks).

We may also share Personal Information: (i) with a parent company, subsidiaries, joint ventures, or other companies under common control with The Sun (in which case we will require such entities to honor the Policy); or (ii) if The Sun merges with another entity, is subject to a corporate reorganization, sells or transfers all or part of its business, assets, or shares (in which case we will require such entity to assume our obligations under the Policy, or inform you that you are covered by a new privacy policy).

We will never share your Personal Information with other third parties except under these circumstances. We do not sell, rent, or lease your Personal Information to any third party for direct marketing purposes or any other purpose.

Personal Information category Who we transfer it to What they do with it
Contact Information Companies that provide e-mail services, specifically Mailgun Transfer it to us so that we can reply to your inquiry
Account Information Companies providing technical infrastructure for the Website, specifically DigitalOcean and Multipub Store it and manage it, so that you can access your account
Subscription Information Companies providing technical infrastructure for the Website, specifically DigitalOcean and Multipub Store it so that we may retrieve it to use it to manage your Subscription
Donation Information Companies providing technical infrastructure for the Website, specifically DigitalOcean; e-mail service providers, specifically Mailgun Communicate with you about your Donation, and manage your recurring Donation
Billing Information Third-Party Payment Processor, specifically Stripe Process the payments for your Subscription Fees or Donation you make to The Sun
Delivery Information The United States Postal Service Deliver your Print Edition of The Sun Magazine if you have purchased that option
Newsletter Information Companies that provide newsletter and mailing list services, specifically Emma and SendGrid, as detailed more fully in the E-mail Communications and Compliance with Anti-Spam Laws section below Help us manage our mailing list and send you our newsletters
Analytics identifiers and IP address Companies that provide data analytics for the Website, specifically Google Analytics Provide us with analytics as to how the Website is used, as further detailed in the Limited Gathering of Information for Statistical, Analytical, and Security Purposes section below
Limited Gathering of Information for Statistical, Analytical, and Security Purposes

The Sun automatically collects certain information using the third-party analytics program Google Analytics to help us understand how our users use the Website, but none of this information identifies you personally. For example, each time you visit the Website, we automatically collect (as applicable) your IP address, browser and computer or device type, access times, the web page from which you came, the web pages or content you access, and other related information. We use information collected in this manner only to better understand your needs and the needs of Website visitors and users in the aggregate. The Sun also makes use of information gathered for statistical purposes to keep track of the number of visits to the Website, the specific pages viewed on the Website, and users to develop and introduce improvements to the Website.

Your IP address and other relevant information we collect using Google Analytics may be used to trace any fraudulent or criminal activity, or any activity in violation of the Terms of Use.

How We Protect Your Personal Information

We have implemented very strict technical and organizational procedures to ensure that, by default, only Personal Information that is necessary for each specific purpose of the processing is processed by us. These procedures prevent your Personal Information from being lost, or used or accessed in any unauthorized way.

We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable supervisory authority of a suspected data security breach where the Data Protection Laws require us to do so, and within the time frame required by the applicable Data Protection Law.

The Sun uses only industry best practices (physical, electronic, and procedural) in keeping any data collected (including Personal Information) secure. In addition, we use third-party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to operate the Website, and these third parties have been selected for their high standards of security, both electronic and physical.

Finally, all information, including Personal Information, is transferred with encryption using Secure Sockets Layer (“SSL”) or Transport Layer Security (“TLS”), robust security standards for Internet data transfer and transactions. You can use your browser to check The Sun’s valid security certificate.

Tracking Technology (Cookies and Related Technologies)

The Sun uses tracking technology (“cookies” and related technology such as tags, pixels, and web beacons) on the Website, and by interacting with the Website you agree to their use. Cookies are small text files placed on your computer or device when you visit a website or use an online service to track use of the site or service and to improve the user experience by storing certain data on your computer or device.

Specifically, we use cookies and related technologies for the following functions:

  • to provide general internal and user analytics and to conduct research to improve the content of the Website using Google Analytics as described above in the Policy;
  • to facilitate payment processing for your Subscriptions and Donations and to keep track of certain preferences while using the Website;
  • to help manage your account when you are a Logged-In User;
  • to track errors on the Website using the third-party service Sentry; and
  • to assist in identifying possible fraudulent activities.

Your browser can be set to refuse cookies or delete them after they have been stored. You can refer to your browser’s help section for instructions, but here are instructions for the most commonly used browsers and operating systems:

Please note that deleting or blocking certain cookies may detract from your user experience by requiring you to re-enter certain information, including information required to use the Website or access your Subscription and account. Furthermore, deleting certain cookies may prevent certain functions from working at all.

E-mail Communications and Compliance with Anti-Spam Laws

The Sun uses Emma and SendGrid to manage our mailing list and send out our newsletters, and Mailgun to send out e-mails related to various account, Subscription, and Donation functions (Emma, SendGrid, and Mailgun, collectively the “E-mail Service Providers”). Personal Information is transferred to the E-mail Service Providers to manage the mailing list and for the e-mails to be sent out properly. Your Newsletter Information, Subscription Information, and Donation Information is only used to send out e-mails; the E-mail Service Providers do not use this Personal Information for any other purpose and will not transfer or sell your Personal Information to any other third party. For more information, please refer to Emma’s Privacy Notice, SendGrid’s Twilio Privacy Notice, and Mailgun’s Privacy Policy.

You may unsubscribe from The Sun’s newsletter mailing list at any time by following the link at the bottom of all The Sun newsletters. Other types of e-mails, such as transactional, relational, and other e-mails related to your account, Subscription, or Donation will not have an opt-out option as they are necessary for the use of the Website.

The Sun’s practices in regard to its e-mail communications are designed to be compliant with anti-spam laws, specifically the CAN-SPAM Act of 2003. If you believe you have received e-mail in violation of any anti-spam law, please contact us using the information in the About Us and Contacting Us section above.

Transfer of Your Personal Information Outside of the European Economic Area and the UK

For our European users, we endeavor to keep your Personal Information inside the European Economic Area (EEA) or the UK (as applicable). However, certain of our data processors (and The Sun) are in other countries where your Personal Information may be transferred. However, these countries are limited to countries with particular circumstances that protect your data, specifically:

  • The United States. Your Personal Information is only transferred to companies in the United States that have signed the Standard Contractual Clauses and informed us they are GDPR-compliant.

That’s it! You have the right, however, to refuse to have your data transferred outside the EEA or the UK. Please contact our Privacy Officer using the information in the About Us and Contacting Us section above to make that request. Please note that making this request may prevent you from being able to use a portion or all of the Website.

Supervisory Authorities and Complaints

If you are in the EEA or the UK, under the GDPR you have the right to make a complaint to the appropriate supervisory authority. If you are not satisfied with the response received or the actions taken by our Privacy Officer, or if you would like to make a complaint directly about The Sun’s data practices, we invite you to contact the supervisory authority in your country. For example, if you are in the UK, you should contact the Information Commissioner’s Office who is the supervisory authority. You can reach them in a variety of ways, including by phone (0303 123 1113 in the UK) and mail (Wycliffe House, Water Lane, Wilmslow, Cheshire, United Kingdom, SK9 5AF). If you are in France, you should contact the Commission Nationale de l’Informatique et des Libertés who is the supervisory authority there. Their contact information can be found here.

The full listing of all Data Protection Authorities (the supervisory authorities) across the EEA can be found here.

Data Retention

Your Personal Information will only be kept for as long as it is necessary for the purpose needed for that processing. For example, we will only keep your Account Information or Subscription Information for as long as you have an account or Subscription with us.

Automated Decision-Making

The Sun does not use any automated decision-making processes in providing the Website.

Children’s Privacy Statement

The Website is not intended for children under the age of 13. We do not knowingly collect any Personal Information from a child under 13. If we become aware that we have inadvertently received Personal Information from a person under the age of 13 through the Website, we will delete such information from our records.

Changes to the Privacy Policy

The date at the top of this page indicates when the Policy was last updated. Every now and then, we will have to update the Policy, and we will update it no less than once every 12 months. You can always find the most updated version at this URL, and we will always post a notice on the Website if we make significant changes. If we have your e-mail, we will also e-mail you to tell you the Policy has been updated and what the important changes are.

© The Sun Publishing Company 2023

Thinking About Writing Us a Letter? Give in to the temptation. We love getting mail. Write us a letter!