Effective date
June 28, 2026
Last reviewed
June 28, 2026
Operator
XOps360 LLC — Hudson, WI
Contact
[email protected]

1. What We Collect

Network-layer signals (Cloudflare infrastructure)

Every request to xops360.com passes through Cloudflare's network before reaching our servers. Cloudflare enriches each request with the following data, which we record:

SignalWhat it tells us
Country, region, city, postal codeGeographic audience composition. Derived from IP address — not GPS.
Latitude / longitudeIP-derived geographic coordinates. Same signal reported by Google Analytics, Cloudflare Insights, and every major CDN. Used for regional content demand mapping, not individual tracking.
Cloudflare datacenter (colo)The closest Cloudflare point of presence to your location. More reliable than city-level IP geolocation.
Autonomous system number and organizationYour ISP or employer's network identifier. Examples: "Comcast Cable", "Booz Allen Hamilton", "Department of Veterans Affairs". Derived from public IP routing tables. Used to understand organizational audience composition — not to identify individuals.
TimezoneUsed to infer working-hours patterns across audience segments.
HTTP protocol, TLS versionConnection quality and security posture signals.
EU country flagRegulatory jurisdiction identifier for GDPR scope.

Browser environment signals

A script runs in your browser when you visit any page. It collects the following signals and sends them to our analytics endpoint:

SignalWhat it tells us
Screen width, height, pixel ratio, color depthDevice class. The combination of 1280×1024 at 1× DPI is a virtual desktop signature. High DPI Retina screens indicate personal devices.
Viewport dimensionsEffective reading width — what content the visitor actually sees.
CPU core count, device memoryHardware class. ≤4 cores at ≤2 GB is a virtual/constrained environment signal.
Touch pointsDistinguishes mobile/tablet from desktop.
Browser language, language countLocale and multilingual profile.
TimezoneBrowser-reported timezone, compared against IP-derived timezone for proxy detection.
Color scheme preferenceLight or dark mode — inferred from OS/browser settings.
Reduced motion preferenceAccessibility signal; also correlates with certain managed device configurations.
Connection type, downlink, round-trip timeNetwork quality. "wifi", "4g", "2g" classifications from the browser's Network Information API.
Save-Data flagWhether the browser has requested reduced data usage.
Cookie status, Do Not TrackBrowser privacy configuration. DNT is recorded as a signal; this site does not treat it as a mandatory opt-out.
Permission states (notifications, geolocation, camera, microphone)Whether these APIs are in "granted", "denied", or "prompt" state. We query the state — we do not request the permissions or access any data behind them. "Denied" across all APIs with no prompt history indicates a managed enterprise device.
Navigation typeWhether the page was reached via navigation, back/forward cache, reload, or prerender.
Page load time, DOMContentLoaded timeSite performance measurement.

Behavioral signals

SignalWhat it tells us
Engaged time (milliseconds)Total time the page was in the foreground and visible. Excludes time spent in other tabs.
Scroll depth (percentage)How far into the page content you scrolled. Used to measure content completion rates.
Outbound link clicksWhen you click a link to an external site, we record the destination URL and visible link text. We do not track where you go after leaving.
Autofill detectionIf browser autofill populates a form field, we detect that the event occurred and record the field type (e.g., "email", "name"). The value autofill inserts is never read or transmitted. This confirms a returning browser with saved data, and whether the visitor abandoned a form without submitting.
Connection changesIf your network connection type changes during a visit (e.g., wifi to cellular), we record the new connection profile.

Canvas and WebGL rendering signatures

During a low-priority idle period, we render a test pattern using your browser's Canvas 2D and WebGL APIs. The rendered output varies based on your GPU, graphics driver, and operating system font rendering. We compute a one-way hash of the output and store only that hash. The rendered image is never stored or transmitted. The hash helps identify returning devices when browser storage has been cleared.

Session and visitor identity

We generate a random UUID (universally unique identifier) for each browser and store it in your browser's IndexedDB. A separate session UUID is stored in sessionStorage and resets when you close the browser tab. These identifiers are random strings — they contain no personal information and are generated locally in your browser, not assigned by our servers.

We also compute two fingerprint hashes from stable hardware signals (screen resolution, color depth, CPU count, timezone, language, touch points). These hashes are used to recognize a returning device if IndexedDB has been cleared. The hash is computed locally and cannot be reversed to recover the individual signals.


2. What We Do Not Collect

  • Names, email addresses, or any directly identifying personal information
  • Autofill field values — only the field type (e.g., "email") is detected, never the content
  • The canvas rendering image — only a one-way hash
  • Precise GPS location — only IP-derived city and region
  • Browsing history outside xops360.com
  • Cookies (this site sets no tracking cookies)
  • Payment or financial information
  • Data from microphone, camera, or clipboard content

3. How This Data Is Used

All collected data is first-party. We do not sell, broker, or share visitor data with third parties. Specific uses:

  • Content strategy: Understanding which topics generate depth of engagement vs. surface-level traffic from which audience segments.
  • Audience composition: Confirming whether content reaches federal, defense, and technology professionals — the audiences it is written for.
  • Site performance: Load time and connection quality measurement.
  • Defensive security research: XOps360 analyzes passive signal collection techniques for cleared client assessments. The data collected on this site demonstrates the legitimate version of the same capability. Research outputs are aggregate and never identify individuals.

4. Data Retention

Data storeRetention
Cloudflare Analytics Engine (event-level)90 days rolling
D1 visitor sessions (aggregate return profile)12 months from last visit
Google Analytics 4Per Google's data retention settings (14 months default)

5. Third-Party Services

Three external services also collect data when you visit this site:

  • Google Analytics 4 — tracks page views and user interactions under Google's own privacy policy. GA4 data is governed separately from our first-party analytics. Google's policy: policies.google.com/privacy.
  • Cloudflare — handles all network requests and provides the CF-level signals described above. Cloudflare's policy: cloudflare.com/privacypolicy.
  • Giscus (GitHub Discussions) — comment threads on individual blog posts are powered by Giscus, which uses GitHub Discussions as a backend. Giscus only activates when you interact with the comment widget. GitHub's policy: GitHub Privacy Statement.

6. Your Choices

  • Browser storage: Clearing IndexedDB removes your visitor UUID, which resets return visitor recognition for this site.
  • JavaScript: Disabling JavaScript prevents all client-side tracking. Page content remains accessible. The canvas/WebGL fingerprint and behavioral signals are not collected without JavaScript.
  • Canvas/WebGL blocking: Browser extensions that randomize or block canvas fingerprinting prevent the rendering signature from being computed. The hash stored will be the same for all visitors using that extension.
  • Permission states: Denying permissions in your browser settings affects the permission state signals we record — not our ability to observe the state itself.
  • Network-layer signals: IP-derived location and ASN attribution are inherent to how the internet routes traffic and cannot be opted out of at the application layer.
  • EU residents: You may request access to, correction of, or deletion of data associated with your visitor UUID by contacting [email protected]. Because session data is not linked to an email address or name, data subject requests require your visitor UUID from browser IndexedDB.

7. Contact

Questions about this policy or data practices: [email protected]
XOps360 LLC — 808 Carmichael Rd PMB 277, Hudson, WI 54016

This policy reflects collection as of June 28, 2026. Material changes will be noted in the changelog.