Data controller and contact
Axis Economics operates this independent research platform. Privacy questions can be submitted through the contact form with the subject “Other”.
Data we store
- Membership: display name, email address, password hash, sessions, recovery-code hash and saved reports.
- Contact: name, email address, subject, message, status and submission date.
- Newsletter: email address, consent status, delivery status and unsubscribe token.
- Analytics, after consent: pseudonymous visitor and session identifiers; viewed path and bounded site-search/filter terms; navigation, scroll depth, engagement time and conversion events; report and PDF interactions; language, external referrer and UTM attribution; browser, operating-system and device categories; viewport, screen size and time zone.
- Security: bounded rate-limit counters. Raw IP addresses are not retained in the analytics table and no third-party analytics service is loaded.
Cookie and browser-storage inventory
- axis_session — essential, HTTP-only, up to 30 days. Created after sign-in to keep the requested account session secure.
- axis_locale — essential preference, up to 12 months. Remembers the language explicitly selected by the visitor.
- axis_analytics_consent — essential preference, up to 12 months. Remembers “necessary only” or “allow analytics”; it does not activate analytics by itself.
- axis_analytics_visitor — optional local storage, created only after analytics permission and kept until cleared. Provides a pseudonymous visitor identifier.
- axis_analytics_session — optional session storage, created only after analytics permission and removed when the browser session ends.
Without analytics permission, the application records only aggregate daily totals for public page path and language. This cookie-free baseline stores no visitor or session identifier, referrer, device data or raw IP address; it cannot calculate unique visitors and may include reloads or automated traffic.
Purpose and legal basis
Data is processed to provide requested accounts, saved-report features, research notifications, security controls and responses to enquiries. Analytics is used only after the visitor’s explicit choice to understand traffic, navigation, report readership and successful actions. Forms require explicit consent; essential account and security processing is necessary to provide the requested service.
Storage and recipients
Runtime data is stored in the application-owned SQLite database and local filesystem. It is not sent to an external identity, analytics, form or newsletter API by default. Infrastructure operators and a configured SMTP provider may process data only when the site owner enables those services.
Retention
- Sessions expire after 30 days.
- Contact messages are removed after 24 months.
- Unsubscribed newsletter records are removed after 30 days.
- Membership data remains until the member deletes the account, subject to administrator and publication-integrity safeguards.
- Expired or used recovery codes are removed automatically.
- Analytics events are removed after 13 months.
- Anonymous daily page/path/language totals are removed after 24 months.
Your choices
Members can update their display name, change their password, revoke sessions, manage saved reports and delete eligible accounts from Profile. Every newsletter message must include its unique unsubscribe link. Analytics can be rejected initially or reset at any time with “Change analytics choice” in the footer. Requests for access or correction can also be submitted through Contact.
Security and limitations
Passwords use salted scrypt hashes, sessions use HTTP-only cookies and administrative actions require role checks. No system can guarantee absolute security; backups and production infrastructure must be protected by the operator.