MAN1K.XYZ — DO NOT TRACK POLICY ================================ Effective Date: September 30, 2026 Site Version: v2.2 / build 26.10 / JS v2.1 Operator: Yaroslav Boruk (MAN1K) Contact: legal@man1k.xyz Domain: https://man1k.xyz OVERVIEW -------- This Do Not Track (DNT) Policy describes how man1k.xyz handles the DNT signal transmitted by your browser, what data is collected, how third-party services are used, and what choices are available to you as a visitor. This policy is machine-readable and human-readable and applies to all pages served under the man1k.xyz domain, including but not limited to: / — Homepage /music — Discography & streaming /lives — Events & tour dates /gallery — Photo gallery /services — Artist services & booking info /subscribe — Mailing list /press — Press kit & media /press/faq — Press FAQ /press/genre — Genre overview /legal — Legal documents /contact — Representatives contacts /tap — Linkhub /about — About the artist /game/ — Browser mini-game (VOID SIGNAL) 1. DO NOT TRACK SIGNAL COMPLIANCE ---------------------------------- man1k.xyz FULLY RESPECTS the DNT signal as defined in the W3C Tracking Preference Expression (DNT) specification. Implementation details (verifiable in /global.js): - If navigator.doNotTrack === "1" is detected, Google Analytics 4 (GA4) is NOT loaded. The GA module returns a no-operation stub immediately. - If navigator.globalPrivacyControl === true (GPC) is detected, the same no-operation path is taken. GPC is treated as equivalent to DNT. - Analytics are also suppressed entirely on localhost / 127.0.0.1 / *.local environments regardless of DNT status. In DNT/GPC mode: * No GA4 script is fetched from googletagmanager.com * No dataLayer is initialized * No cookies are set by this site's analytics code * No event tracking occurs * No page_view events are fired * TikTok Pixel is not initialised; no requests to analytics.tiktok.com 2. ANALYTICS — GOOGLE ANALYTICS 4 ----------------------------------- Measurement ID: G-5M1G8HHZW4 When DNT/GPC is NOT active, Google Analytics 4 is loaded with the following privacy-preserving configuration: anonymize_ip: true allow_ad_personalization_signals: true allow_google_signals: true restricted_data_processing: false cookie_flags: SameSite=Lax; Secure cookie_expires: 15,552,000 seconds (~180 days) send_page_view: false (fired manually on init only) GA4 is blocked for bots and crawlers (detected via user-agent). GA4 script is served from the googletagmanager.com domain. Account-level data sharing settings (configured in GA dashboard): - Google products & services: enabled (aggregated, de-identified) - Modeling contributions & insights: enabled (aggregated, de-identified) - Technical support: enabled - Recommendations for your business: enabled Data processor: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Privacy Policy: https://policies.google.com/privacy Custom events fired by /global.js when GA4 is active: page_view — every page load (location, title) scroll_depth — user passes 25/50/75/90% page depth time_on_page — at 30s / 60s / 120s / 300s milestones outbound_click — click on any external link (domain, link text, page) platform_click — click on Spotify/Bandcamp/SoundCloud/YouTube/ Instagram/TikTok/Bandsintown links email_click — click on a mailto: link (context text, page) file_download — download of .pdf/.zip/.mp3/.wav/.flac (filename, page) content_copy — text copy event (page) visitor_context — once per session: visitor type (new/returning), browser language, screen category, timezone newsletter_submit — form submitted on /subscribe newsletter_form_focus — email field focused on /subscribe event_rsvp_click — Bandsintown RSVP/ticket button clicked on /lives contact_page_view — /contact page loaded faq_expand — FAQ item opened on /press or /press/faq (question text) web_vitals — Largest Contentful Paint timing (ms) js_error — JavaScript error (message, source file, line, col) User property set: site_version (current JS version) These events are NOT fired when DNT or GPC is active. 3. ANALYTICS — SIMPLE ANALYTICS --------------------------------- Simple Analytics is active on all pages. No cookies are set. No fingerprinting. No personal data is collected or transmitted. Simple Analytics respects DNT and GPC signals: - If navigator.doNotTrack === "1" → no data transmitted - If navigator.globalPrivacyControl === true → no data transmitted No GDPR consent is required as no personal data is processed. Data processor: Simple Analytics BV, Keizersgracht 482-1, 1017 EG Amsterdam, Netherlands. Simple Analytics Privacy Policy: https://simpleanalytics.com/privacy 4. TIKTOK PIXEL ---------------- Pixel ID: D7958NBC77U5V754BC6G Provider: TikTok Technology Limited The TikTok Pixel is technically installed but not currently used. When DNT/GPC is active it is not fetched and no data is transmitted to analytics.tiktok.com. TikTok Privacy Policy: https://www.tiktok.com/legal/privacy-policy 5. ERROR TRACKING ------------------ JavaScript errors are captured via window.onerror and window.addEventListener("unhandledrejection") in /global.js. Data collected per error event: - Error message (truncated to 200 characters) - Source filename (basename only, no full path) - Line number and column number - Current page pathname - Site version string - Unix timestamp - Stack trace (truncated to 500 characters, if available) Error events are forwarded to Google Analytics 4 (GA.e) only when GA4 is active (i.e., when DNT/GPC is NOT set). No errors are transmitted when DNT is respected. 6. LOCAL STORAGE & INDEXEDDB ------------------------------ The site stores a few non-personal technical values in the browser: a cosmetic visit counter (homepage), rate-limiter state (all pages) and the game high score (/game/, IndexedDB with localStorage fallback). None of it is transmitted externally. Details: https://man1k.xyz/legal/cookies 7. THIRD-PARTY EMBEDDED SERVICES ---------------------------------- The following third-party services may be embedded on specific pages. Each operates under its own privacy policy. man1k.xyz does not control the tracking behavior of these embeds. 7.1 Bandsintown Widget (/lives) Provider: Bandsintown, Inc. Purpose: Displaying upcoming live events and tour dates. The widget loads from widgetv3.bandsintown.com and may set cookies or collect usage data per Bandsintown's own privacy policy. Loading: Async script — loads immediately on page load. Policy: https://corp.bandsintown.com/privacy 7.2 SoundCloud (/game/) Provider: SoundCloud Global Limited & Co. KG Purpose: Background music for the VOID SIGNAL mini-game. /game/ — iframe loaded with auto_play=false; playback starts only on explicit PLAY action via SC Widget API. SoundCloud may set cookies and collect listening data. Note: On /music, SoundCloud appears as an external link only — no third-party connection is initiated from that page element. Policy: https://soundcloud.com/pages/privacy 7.3 YouTube (youtube-nocookie.com) — Homepage (/) Provider: Google LLC / YouTube, LLC Purpose: Promo video embed on the homepage. Loaded via youtube-nocookie.com (privacy-enhanced mode), which does not set tracking cookies until the visitor interacts with the player. Loading: Iframe — loads on page load; browser-native lazy loading defers the request until the embed is scrolled into view. Note: On other pages (e.g. /music), YouTube appears as an external link only — no iframe is loaded and no third-party connection is initiated from those link elements. Policy: https://policies.google.com/privacy 7.4 Cloudflare R2 / pics.man1k.xyz (/gallery, /about) Provider: Cloudflare, Inc. Purpose: Serving artist photos hosted on Cloudflare R2 object storage. Images are served from pics.man1k.xyz. First images load eagerly; the rest use native browser lazy loading. Policy: https://www.cloudflare.com/privacypolicy/ 7.5 Buttondown (/subscribe) Provider: Buttondown, LLC Purpose: Email newsletter subscription form. Submissions are sent via HTTP POST to buttondown.com/api/emails/embed-subscribe/man1k. Buttondown receives the email address entered and processes it according to their own privacy policy. No iframe is loaded; the form posts only on explicit user submission. Other sources: emails may also be added if you opted in to email updates when buying a ticket or merch via a third-party platform, or manually when you personally agreed (e.g. at a concert, via a promo campaign, or in a personal conversation) — always based on consent. Unsubscribe: Via link in each newsletter email, or direct request. DPA: https://buttondown.com/legal/data-processing-agreement 7.6 Font Awesome via Cloudflare CDN (/, /music) Provider: Cloudflare, Inc. (cdnjs.cloudflare.com) Purpose: Icon font (social icons and platform icons) on the homepage and /music page. Served as a CSS stylesheet from cdnjs.cloudflare.com on page load. Policy: https://www.cloudflare.com/privacypolicy/ 7.7 Cloudflare Pages (all pages) Provider: Cloudflare, Inc. Purpose: CDN and static hosting for all site traffic. All HTTP requests to man1k.xyz pass through Cloudflare's network. Policy: https://www.cloudflare.com/privacypolicy/ 7.8 CDN Fonts (cdnfonts.com) Provider: cdnfonts.com Purpose: Serving VCR OSD Mono typeface used across all pages. A preconnect is established on page load. 7.9 Google Fonts (fonts.googleapis.com) Purpose: Serving DotGothic16 typeface on /game/ page only. A preconnect is established on page load. Policy: https://policies.google.com/privacy 7.10 Simple Analytics (all pages) Provider: Simple Analytics B.V. Purpose: Privacy-first, cookie-free analytics. Does not use cookies, does not fingerprint users, and does not collect personal data. Respects DNT and GPC signals: when either is active, no data is transmitted. No GDPR consent required. Policy: https://simpleanalytics.com/privacy Note on Spotify and Bandcamp: these appear as external links only on /music — no iframes, no third-party connections are initiated from those link elements. 8. COOKIES ----------- man1k.xyz itself does NOT set any first-party cookies for tracking. Third-party cookies (set by embeds, active only when embeds load): - Google Analytics 4: _ga, _gid, _gat (when DNT is NOT active) - SoundCloud (/game/): per SoundCloud's own policy - Bandsintown (/lives): per Bandsintown's own policy - YouTube (homepage, youtube-nocookie.com): none set on load in privacy-enhanced mode; standard YouTube cookies may be set once the visitor interacts with the player, per Google's own policy When DNT/GPC is active, GA4 is not loaded, TikTok Pixel is not initialised, and no analytics or advertising cookies are set by this website. 9. REFERRER POLICY ------------------- All pages declare: Referrer-Policy: strict-origin-when-cross-origin This means your full URL (including path and query string) is sent as the Referrer only to same-origin requests. Cross-origin requests receive only the origin (https://man1k.xyz) without path or query. No referrer is sent when downgrading from HTTPS to HTTP. 9.1 PRECONNECT & DNS-PREFETCH ------------------------------- global.js automatically injects the following resource hints on all pages: Preconnect: fonts.cdnfonts.com, cdnjs.cloudflare.com (crossorigin) DNS-Prefetch: soundcloud.com, bandsintown.com These hints cause early DNS resolution only — no data is transmitted to these domains unless the user navigates to a page that embeds their content. 10. BOT & CRAWLER HANDLING ---------------------------- Automated user agents are identified as bots using User-Agent regex patterns in global.js. For detected bots: - Prefetch link hints are not injected - GTM/Analytics tracking does not fire - Devtools detection is suppressed - Console guard messages are suppressed This ensures that search engine crawlers receive clean, unmodified responses without analytics interference. 11. RATE LIMITING ------------------ Client-side rate limiting is implemented to detect abusive interaction: Soft limit: 300 events per 60-second window (warning threshold) Hard limit: 600 events per 60-second window (interaction blocked) Monitored event types: click, keydown. Rate limiter state is stored in localStorage (keys mk_r and mk_b) and persists across page reloads. No data from rate-limit checks is transmitted externally. 12. DATA RETENTION ------------------- man1k.xyz does not operate its own database or user accounts. Data is retained for as long as reasonably necessary for the purposes described in the Privacy Policy; third-party retention follows their own policies. 13. YOUR RIGHTS ---------------- Opt out of analytics by enabling DNT or GPC, or via https://tools.google.com/dlpage/gaoptout. Data-subject requests (access, erasure, etc.): legal@man1k.xyz — see https://man1k.xyz/legal/privacy#rights 14. POLICY UPDATES ------------------- This policy is updated under the Terms of Use, Section 08 (https://man1k.xyz/legal/terms#changes). The build version and effective date at the top of this document indicate the current revision. Machine-readable site information is available at: https://man1k.xyz/llms.txt — LLM-readable site summary https://man1k.xyz/artist.json — Structured artist data https://man1k.xyz/LICENSE — Permissions-Policy https://man1k.xyz/humans.txt — Human authors https://man1k.xyz/.well-known/dnt-policy.txt — This document https://man1k.xyz/.well-known/privacy.txt — Machine-readable privacy policy https://man1k.xyz/.well-known/copyright.txt — Machine-readable copyright notice https://man1k.xyz/.well-known/security.txt — Security contact (RFC 9116) https://man1k.xyz/.well-known/security-policy.txt — Vulnerability disclosure policy https://man1k.xyz/.well-known/gpc.json — Global Privacy Control declaration https://man1k.xyz/.well-known/ai.txt — AI Access Policy Human-readable legal documents: https://man1k.xyz/legal/privacy — Privacy Policy https://man1k.xyz/legal/cookies — Cookie Policy https://man1k.xyz/legal/terms — Terms of Use https://man1k.xyz/legal/copyright — Copyright Notice --- © 2026 Yaroslav Boruk (MAN1K). This policy document is provided for informational and legal compliance purposes.