Last updated: August 1, 2026
This policy explains what information is collected when you visit TopPickLab (https://www.virtualspace.dev), why it is collected, who it is shared with, how long it is kept, and what you can ask us to do about it. It is written to reflect what this site actually does, not a generic template.
1. Who We Are
TopPickLab is an independently operated content website that publishes product reviews, buying guides and hotel recommendations. It is not a registered company and does not operate a storefront.
- Website: https://www.virtualspace.dev
- Contact for privacy matters: [email protected]
- Role: we act as the data controller for the information described below.
This policy covers only this website. Once you follow a link to a merchant, booking platform, affiliate network or any other site, that party’s own privacy policy applies and we have no control over it.
2. What Information We Collect
We collect three kinds of information: what you hand us on purpose, what our server and analytics tools record automatically while you browse, and nothing at all in several categories that are worth spelling out explicitly.
Information you give us directly
- Comments. Comments are open on our articles. If you leave one, we store the name, email address and website URL you enter, the comment text, and the time it was submitted. Your IP address and browser user agent are also recorded automatically so spam can be filtered. The email address is not displayed publicly. We currently hold 586 comments of this kind.
- Newsletter subscription. If you subscribe, we store the email address you provide (and a name if you choose to give one) plus the date and method of subscription.
- Email you send us. If you contact us, we keep your message, your email address and any details you choose to include, so we can reply and keep a record of what was asked.
Information collected automatically
- Server access logs. Our web server records your IP address, the page requested, the date and time, the referring page and your browser user agent. This is standard for any web server and is used for security, troubleshooting and abuse prevention.
- Analytics data. Through Google Analytics (loaded via Google Tag Manager and Google Site Kit) we collect approximate location derived from IP, device and browser type, operating system, language, referring source, pages viewed, time on page and interaction events. Google Analytics 4 does not store or display individual IP addresses.
- Performance data. Cloudflare, which fronts this site as a CDN and security layer, collects request-level data and real-user performance metrics (such as load times and connection type) through its own scripts and edge network.
What we do not collect
- No accounts. Registration is disabled, so we hold no login credentials, passwords or user profiles.
- No payments. We never process purchases. When you buy through one of our links, the transaction happens entirely on the merchant’s site and we never see your card details.
- No sensitive categories. We do not ask for government identifiers, health data, biometric data or similar sensitive information, and ask that you do not send any.
3. Cookies and Similar Technologies
Cookies are small text files stored in your browser. They let a site remember things between pages and visits. Here is what actually runs on this site.
Strictly necessary cookies
- Comment convenience cookies. If you leave a comment, WordPress may store your name, email and website in cookies so you do not have to retype them next time. These last one year and are only set if you comment.
- Session cookies for administrators. Login and dashboard cookies are set only for our own editorial logins, not for visitors.
- Caching. WP Rocket serves cached pages to make the site faster. It does not set tracking cookies for visitors.
Analytics cookies
- Google Analytics sets first-party cookies (for example
_gaand related identifiers) to distinguish returning visitors and record sessions. - What we use it for: to see which guides are actually read, where readers come from, whether pages load properly and what to write next. Reports are aggregated; we do not use analytics to identify you personally or to build individual profiles.
- How long: analytics identifiers persist for up to two years in your browser, and the underlying data is retained in Google Analytics for up to 14 months before automatic deletion.
- How to opt out: block or delete cookies in your browser settings, disable JavaScript, or install Google’s official Analytics opt-out browser add-on. The site will still work.
Advertising cookies
- We do not currently run third-party advertising networks. There is no Google AdSense or similar display advertising on this site, so no personalised advertising cookies are being set by us.
- If that changes, this page will be updated before any ad technology is added, and we will implement whatever consent mechanism is required in the regions we serve.
Affiliate tracking cookies
- When you click an affiliate link, the affiliate network or merchant sets its own cookie or appends tracking parameters in order to credit the sale. This happens on their domain, under their policy, and the typical attribution window is around 30 days, though it varies by merchant.
- You can avoid these cookies entirely by not clicking outbound shopping links, or by clearing cookies after visiting a merchant site.
4. Affiliate Links and How This Site Is Funded
- Many outbound links on this site are affiliate links, including tracked links through partners such as BonusArrive. If you click through and buy, we may earn a commission at no extra cost to you.
- What comes back to us is reporting at an aggregate level: that an order occurred, its value and the resulting commission. We do not receive your name, address, contact details or payment information from those transactions.
- Commissions do not determine what we recommend. We do not accept payment for positive coverage, and merchants do not get to review or approve a piece before it is published.
5. Newsletter and Email
- What we collect: your email address, and optionally a name. That is all.
- Why: to send new articles and occasional roundups. We do not sell, rent or trade subscriber addresses.
- Unsubscribing: every email includes a one-click unsubscribe link. You can also email us and we will remove you manually.
- Measurement: we may record whether an email was opened or which links were clicked, to judge whether the content is useful.
- Retention: your subscription data is kept until you unsubscribe or ask us to delete it.
6. Media
- Visitors cannot upload images or files to this site. Only site administrators can upload media, which is why there is no public media library contribution path.
- If you link to or embed an image you host elsewhere, check that it does not carry embedded EXIF or GPS location data, since anyone viewing the page can potentially extract it.
- Images uploaded by our administrators may be processed by an image optimisation service (Imagify) to compress them, which involves transferring those files to that provider for processing.
7. Embedded Content from Other Websites
- Articles may include embedded content such as videos, maps, social posts or merchant widgets.
- Embedded content behaves exactly as if you had visited the other website directly: it can collect data about you, set its own cookies, embed additional third-party tracking, and monitor your interaction with it, including when you are logged in to that service.
- We cannot control what those services do once loaded. Please review their privacy policies if you want to know how they handle your data.
8. Who We Share Your Data With
We do not sell, rent or trade personal information. We share it only with service providers who need it to keep the site running, or where the law requires it:
- Cloudflare — CDN, security filtering, bot protection and performance measurement. As the network layer in front of the site, it processes IP addresses and request data.
- Google — Google Analytics, Tag Manager and Site Kit for website usage statistics.
- Affiliate networks and merchants — only when you click an outbound affiliate link, after which they handle the visit under their own policies.
- Email delivery infrastructure — the newsletter plugin and our mail sending service, used to deliver subscriptions you requested.
- Hosting provider — our VPS is hosted in Los Angeles, United States, on infrastructure operated by IT7 Networks.
- Legal and safety — where required by law, court order, or to protect our rights, users or the public.
Comments may also be checked by automated anti-spam filtering, which is a standard WordPress function.
9. How Long We Retain Your Data
- Comments and their metadata: retained indefinitely, so that follow-up comments can be recognised instead of held for moderation each time. You can ask us to delete yours at any point.
- Newsletter subscriptions: kept until you unsubscribe or ask for deletion.
- Analytics data: retained in Google Analytics for up to 14 months, then deleted automatically. Browser-side analytics identifiers last up to two years unless you clear them.
- Server and security logs: kept on a rolling basis, normally around 30 days, for troubleshooting and abuse investigation.
- Correspondence: emails you send us are kept for as long as needed to handle your request and maintain a record of it.
- No account data exists, because registration is disabled, so there is no account retention period.
10. Where Your Data Is Stored and Sent
- Primary storage: the site database and files live on a self-managed virtual private server located in Los Angeles, California, United States.
- Edge processing: Cloudflare serves the site through a global network of edge nodes, so your request is typically handled by a node near you before reaching our origin server. This means request data may be processed outside your own country.
- International transfers: if you visit from the EEA, the UK, Switzerland or elsewhere outside the US, your information will be transferred to and processed in the United States. That transfer is necessary to deliver the website you requested.
- Protection in transit: all traffic is encrypted over HTTPS/TLS. Access to the server and database is restricted to site administrators.
11. Your Rights Over Your Data
Depending on where you live, you may have the following rights. We honour them regardless of location wherever it is practical to do so.
- Access and portability — ask what personal data we hold about you and receive a copy in a portable format.
- Correction — have inaccurate or incomplete data fixed.
- Deletion — ask us to erase your comment, subscription or correspondence.
- Restriction and objection — ask us to limit processing, or object to processing based on legitimate interests.
- Withdraw consent — unsubscribe from email, or withdraw any consent you previously gave, at any time.
- Non-discrimination — we will never degrade your experience or access because you exercised a privacy right.
If you are in the EEA or the UK — that is, where the EU GDPR or UK GDPR applies — you also have the right to lodge a complaint with your national data protection authority. If you are a California resident, you have the right to know what is collected, to request deletion and correction, and to opt out of the sale or sharing of personal information — please note that we do not sell or share personal information as those terms are defined under the CCPA/CPRA.
How to make a request: email [email protected] with enough detail for us to locate the data. We reply within 30 days. We may ask you to verify that the request is genuinely yours, and we will never charge a fee unless a request is manifestly excessive or repetitive.
12. Children’s Privacy
- This site is general-audience content about products and travel. It is not directed at children under 13, or under 16 in the EEA.
- We do not knowingly collect personal information from children. If you believe a child has submitted data here, email us and we will delete it promptly.
13. How We Protect Your Data
- All traffic is served over HTTPS/TLS encryption.
- WordPress core, the theme and plugins are kept updated, and administrative access is limited to a small number of accounts.
- Cloudflare provides a firewall layer, bot mitigation and DDoS protection in front of the origin server.
- No method of transmission or storage is completely secure. If a breach affecting your data occurs, we will notify you and the relevant authorities where the law requires it.
14. Changes to This Policy
- We may update this policy as the site changes — for example if we add a new analytics tool, a comment feature or advertising.
- The “Last updated” date at the top always reflects the current version. Material changes will be highlighted on the site.
15. Contact Us
For any privacy question, request or complaint, email [email protected], or use the contact page. We aim to reply within two to three business days, and within 30 days for formal privacy requests.