Independent consumer-cost reporting
Consumer Trends DigestEvidence-led consumer reporting
Preparing first reports

Purpose-limited data handling

Privacy notice

This notice explains what Consumer Trends Digest collects through the public website, newsroom services, governed measurement, and commercial-option workflows; why it is used; how it is protected; and how to ask for a review.

Effective
August 22, 2026
Last reviewed
August 22, 2026
Notice version
2.0
Responsible role
Privacy Reviewer

At a glance

Plain-language commitments

01

Purpose first

Newsroom, journalist, privacy, subscription, and commercial records remain separated by their stated purpose.

02

Evidence, not hidden profiles

Operational identifiers support security, delivery, attribution, and audit. CTD does not call pseudonymous records anonymous.

03

Editorial independence

Interaction and commercial outcomes do not determine whether a claim is true, a story is published, or a correction is made.

04

A route to act

Privacy requests create a private, trackable case handled by the Privacy Reviewer.

01 · Identity and scope

Who is responsible for this notice

Verified operator record

Consumer Trends Digest is operated by Catalyst Capital LLC, 8206 Louisiana Blvd Ste A #551 Albuquerque, New Mexico 87113, USA. For the processing described in this notice, that entity determines CTD’s purposes and operating means unless a named provider or destination acts independently under its own notice.

This notice applies when you visit or search the CTD site, contact the newsroom, make a privacy request, request journalist access, subscribe to a purpose-specific alert, follow a governed CTD distribution link, view an eligible public Experience, or deliberately continue to a commercial destination.

It does not replace the privacy notice of an independent source, publisher, commercial destination, or other third party you choose to visit.

02 · Data inventory

Information CTD may handle

The applicable row depends on what you do. A capability being present in the platform does not mean it collected information about you.

InteractionRepresentative informationOperational boundary
Visit or searchRequested URL, search terms placed in the URL, timestamp, IP address, browser or user-agent, referrer, and security events may reach hosting or server logs.The CTD application does not create a named reader account merely because someone reads a page.
Contact or privacy caseName, email, optional organization, category, subject, message, source page, case reference, correspondence, policy version, and hashed IP and user-agent.Identity and message fields are encrypted; rate-limit and duplicate controls use hashes.
Journalist accessName, newsroom email, outlet, professional role, beats, geography, verification status, decisions, access grants, and evidence-kit journey events.Journalist records are purpose-specific and are not enrolled in consumer marketing.
Alerts or follow-upEmail, selected topic or purpose, consent and withdrawal history, verification, delivery, bounce, complaint, and suppression events.Delivery requires a verified, current purpose authority; withdrawal blocks later use for that purpose.
Tracked CTD distributionCampaign and UTM context, story and version, pseudonymous visitor and session identifiers, rotating IP and browser hashes, redirect, landing, visibility, and engagement events.Cross-visit persistence is off by default and can be enabled or withdrawn below.
Experience or commercial optionExperience version, option shown, decision and click receipts, destination, conversion or outcome type, and where supplied by an approved provider, revenue, refund, reversal, or complaint evidence.High-risk actions remain separately authorized; commercial data is excluded from editorial truth and correction decisions.
Public-source reportingInformation in official records, company material, websites, research, and other permitted reporting evidence, which may sometimes concern identifiable people.Source, licensing, privacy, safety, and publication review apply; public availability alone does not authorize unrestricted reuse.
Consumer story intakeWhen enabled, the separate workflow may receive identity, narrative, organizations, dates, geography, documents, permissions, and confidentiality choices.Public story intake is closed. The general contact and privacy forms must not be used to send story evidence.

03 · Use and authority

Why information is used

Provide what you request

Deliver pages, route and answer cases, verify journalist access, send selected alerts, and complete a destination you deliberately choose.

Protect the service

Rate-limit abuse, authenticate protected workflows, prevent replay, investigate incidents, preserve audit evidence, and recover failed delivery.

Measure and improve

Understand source performance, presentation, delivery, engagement, attribution, complaints, and outcomes within configured safeguards.

Meet obligations

Preserve records required for consent, security, accounting, contracts, legal claims, editorial integrity, source protection, or applicable law.

Depending on the activity and law that applies, processing may be necessary to provide a requested service, perform a contract, meet a legal obligation, protect CTD or others, support a legitimate operational or journalistic interest, or rely on consent for an optional use. CTD does not describe consent as the universal basis for every activity.

04 · DME, attribution, and commercial measurement

What governed decisioning does—and what it cannot do

CTD’s Decision Management Engine may use page, story, campaign, device class, interaction, eligibility, option, and outcome context to decide whether a governed public Experience or relevant next-step option may be shown. Pseudonymous receipts connect an exact presentation or redirect to later verified delivery or outcome evidence.

The editorial firewall

Interaction, attribution, and commercial outcome data may help CTD evaluate presentation, distribution, relevant reader options, fraud, and economics. Those data do not determine whether a claim is true, whether a story is published, or whether a correction is made.

CTD does not use public decisioning to make a legal or similarly significant decision about a reader. It does not infer that a pseudonymous identifier is anonymous, and it does not claim to link a browser across devices. Identified services, such as verified alerts or journalist access, remain governed by their separate purpose records.

05 · Cookies and similar storage

Choose whether this browser supports cross-visit measurement

Current browser stateEssential-only mode is active. CTD does not persist a cross-visit measurement identifier.

Global Privacy Control overrides an earlier measurement choice and forces essential-only mode. Saving essential-only mode also clears CTD’s persistent acquisition and conversion identifiers from this browser.

The CTD application in this release does not install a generic third-party advertising, social retargeting, or cross-site audience pixel. A selected external destination may operate under its own cookie and privacy terms.

06 · Newsroom services

Contact, journalist access, and story material remain distinct

Contact and privacy cases

Do not send identity documents in the first message. CTD may request proportionate verification through the private case when necessary to prevent disclosure or deletion of another person’s information.

Journalist access

Verification may include professional affiliation, newsroom email, role, beats, geography, status, access events, and misuse evidence. Withdrawal closes the purpose and revokes active access; minimum security and audit evidence may remain.

Story evidence

Public story intake is closed. The general contact and privacy forms must not be used to send story evidence. A submission does not guarantee investigation, publication, compensation, confidentiality, individual response, or resolution.

Privacy requests do not automatically require CTD to alter accurate reporting, remove public-interest information, reveal confidential sources, or erase protected editorial records. Factual disputes belong under the Corrections Policy; privacy, safety, removal, and source-protection concerns receive a separate review under applicable law and journalistic protections.

07 · Providers, destinations, and transfers

Who may receive information

Depending on the enabled workflow, approved providers may support website hosting and delivery, databases and backups, transactional email, monitoring and incident response, security and abuse prevention, contact-case delivery, verified journalist access, or commercial destination and outcome reporting. Providers acting for CTD are expected to receive only the information needed for the configured purpose. An external destination may act independently for the service it provides.

Provider names, contracts, support locations, and processing regions are deployment facts maintained outside this public code package. CTD therefore does not claim that information stays in one country. Where a transfer rule applies, the production operator must document the provider, region, purpose, and required safeguard. You may ask the Privacy Reviewer for current provider and transfer information.

Sale, sharing, advertising, and partner use

CTD does not use contact, privacy, journalist-access, or story-submission records for consumer marketing or cross-context behavioral advertising. The current public application does not upload those records to advertising audiences. If a reader deliberately selects a commercial option, CTD may redirect to the chosen destination and may receive authenticated outcome evidence needed for delivery, fraud, complaint, attribution, and commercial accounting. That does not authorize reuse of a newsroom request for another purpose.

08 · Retention and security

How long records remain

Contact and privacy casesScheduled for governed redaction two years after receipt, once closed or archived and clear of legal hold or active delivery.
Journalist requestsScheduled for governed redaction after two years when denied, withdrawn, closed, or expired and clear of legal hold or active delivery.
Public rate-limit bucketsRemoved after eight days under the contact reconciliation policy.
Consent and delivery evidenceKept as needed to prove the current purpose, withdrawal, suppression, dispatch, and compliance history.
Attribution and outcome evidenceKept under the applicable operational, contract, accounting, fraud, complaint, and integrity policy; cookie expiry does not itself delete already recorded audit evidence.
Published reportingMay remain as a durable editorial and correction record, subject to separate privacy, safety, legal, and source-protection review.

CTD uses administrative, technical, and organizational safeguards designed for the information and risk involved. Controls include purpose separation, encryption for protected case fields, keyed or one-way hashes, access control, signed and expiring authorizations, audit records, environment separation, monitoring, bounded retries, legal-hold checks, and recovery controls. No storage or transmission method can be guaranteed completely secure.

09 · Your privacy rights

Ask CTD to review an applicable choice

Depending on where you live and the law that applies, you may have rights to access or know, correct, delete, obtain a copy, restrict or object, withdraw consent, opt out of certain sale, sharing, or targeted advertising, limit certain sensitive-information uses, use an authorized agent, appeal a decision, or complain to a regulator.

  1. Choose the request.The privacy form asks only for initial contact details, request type, optional region, and a safe description.
  2. Receive a private reference.CTD acknowledges and routes the case without placing your message in an operator-arrival email.
  3. Verify proportionately.CTD may request information needed to match the record, verify identity, or confirm an authorized agent. Unverified requests may be limited or denied.
  4. Receive a reasoned outcome.CTD applies the deadline, extension, exception, and appeal rules that govern the request and explains a denial or partial denial when required.

Some information may remain where necessary for security, fraud prevention, consent or suppression proof, legal obligations, claims, contracts, accounting, editorial integrity, public-interest reporting, or confidential-source protection. CTD does not discriminate against a person for exercising an applicable privacy right.

California-specific context

If CTD is a covered business for the relevant period, California residents may have rights including know, access, correction, deletion, opt-out of sale or sharing, limits on certain sensitive-information use, and non-discrimination, subject to verification and exceptions. Global Privacy Control is treated as essential-only browser mode by this application.

EEA and UK context

Where the GDPR or UK GDPR applies, rights and required disclosures depend on the processing purpose, lawful basis, exemptions, and CTD’s journalistic and public-interest obligations. People may also have a right to complain to an applicable supervisory authority.

Children’s privacy

CTD is a general-audience newsroom and is not designed for children under 13. CTD does not knowingly invite online personal information from children under 13 through public story intake. If CTD learns that such information was submitted, it will route the matter for privacy and newsroom-safety review under applicable law.

Open a trackable privacy case

10 · Contact and change control

A versioned notice, not a static promise

CTD reviews this notice when collection points, cookies, providers, processing regions, retention, story intake, analytics, advertising, commercial routing, or DME behavior materially changes. The effective date and notice version identify the statement presented when a public contact case is created.

Privacy Reviewerprivacy@consumertrendsdigest.com

For access, correction, deletion, withdrawal, browser choices, published-content privacy concerns, authorized agents, or another privacy question.

Submit a privacy request