Privacy Policy

witchesofmellgrah.com

Last updated: March 2026

1. Introduction

Welcome to Witches of Mellgrah (“we”, “us”, or “our”). This Privacy Policy explains what personal data we collect when you visit witchesofmellgrah.com, why we collect it, how we use it, and what rights you have.

We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Data Controller

The data controller responsible for this website is:

Levia Tan

Website: witchesofmellgrah.com

For any privacy-related enquiries, please contact us via the social media channels listed in Section 13.

3. Data We Collect

3.1 Newsletter subscription

When you subscribe to our newsletter, we collect:

  • Your email address
  • Date and time of subscription

This data is stored and managed by our newsletter service provider. Please see Section 8 for details.

3.2 Cookie consent log (CookieYes)

We use CookieYes to manage cookie consent on our website. When you interact with the cookie banner, CookieYes records:

  • Whether and which cookie categories you accepted or declined
  • Date and time of your consent
  • Your approximate region (country level)
  • The version of the cookie policy shown to you

This log is kept to demonstrate compliance with GDPR consent requirements. It does not identify you personally.

3.3 Analytics and usage data

When you browse our website, we may automatically collect:

  • IP address (anonymised where possible)
  • Browser type and version
  • Device type and operating system
  • Pages visited and time spent on site
  • Referring website or traffic source

3.4 Meta Pixel data

We use the Meta Pixel (provided by Meta Platforms, Inc.) on our website. This tool may collect information about your visit — such as pages viewed and actions taken — and transmit it to Meta. Meta may link this data to your Facebook or Instagram account if you are logged in. Please see Section 7 for more detail.

4. Purposes and Legal Basis for Processing

The table below summarises why we process your data and the legal basis under GDPR:

Newsletter — sending updates, book news, and exclusive content

Legal basis: Consent (Article 6(1)(a) GDPR). You may withdraw consent at any time by clicking “unsubscribe” in any email.

Newsletter — marketing use (Meta Custom Audiences, remarketing, lookalike campaigns)

Legal basis: Consent (Article 6(1)(a) GDPR). By subscribing, you agree that your email address may be used to create and target advertising audiences on Meta platforms (Facebook and Instagram), including Custom Audiences, remarketing audiences, and lookalike audiences. You may withdraw this consent at any time.

Cookie consent log

Legal basis: Legal obligation (Article 6(1)(c) GDPR) — we are required to keep records of consent.

Analytics (website traffic and behaviour)

Legal basis: Legitimate interests (Article 6(1)(f) GDPR) for basic, anonymised analytics; Consent for any non-essential cookies used for analytics.

Meta Pixel (advertising and retargeting)

Legal basis: Consent (Article 6(1)(a) GDPR). The Meta Pixel only activates if you accept marketing cookies via our cookie banner.

5. Newsletter and Email Marketing

When you subscribe to our newsletter, you consent to receiving:

  • Updates about the Witches of Mellgrah book series
  • Exclusive content, lore, and early access chapters
  • Release announcements and related news

You also consent to your email address being used for marketing purposes on Meta platforms, including:

  • Uploading your email to Meta to create a Custom Audience
  • Targeting you with ads on Facebook and/or Instagram
  • Creating lookalike audiences based on your profile to reach similar users

You can withdraw your consent to email marketing at any time by clicking the unsubscribe link in any newsletter email. To opt out of Meta-based marketing specifically, you may also adjust your ad preferences directly in your Facebook or Instagram account settings.

6. Cookies

Our website uses cookies — small text files placed on your device. We use CookieYes to manage your cookie preferences. You can change your choices at any time by clicking the cookie settings button on our website.

We use the following categories of cookies:

Essential cookies

Required for the website to function. These cannot be disabled.

Analytics cookies

Help us understand how visitors interact with the site (e.g. pages visited, traffic sources). Activated only with your consent.

Marketing / advertising cookies

Set by the Meta Pixel to track your visit and enable targeted advertising on Facebook and Instagram. Activated only with your consent.

7. Meta Pixel and Meta Platforms

We use the Meta Pixel, a tracking tool provided by Meta Platforms, Inc. (1 Hacker Way, Menlo Park, CA 94025, USA). The Meta Pixel is only activated if you accept marketing cookies via our cookie banner.

When active, the Meta Pixel may:

  • Record that you visited our website and which pages you viewed
  • Transmit this information to Meta
  • Allow Meta to link this data to your Facebook or Instagram account
  • Enable us to show you targeted ads on Meta platforms

We use Meta Pixel data for the following advertising purposes: retargeting visitors to our website, building Custom Audiences, and creating lookalike audiences to reach new potential readers.

Meta’s own data processing is governed by Meta’s Privacy Policy, available at https://www.facebook.com/privacy/policy/. Meta is an independent data controller for the data it receives.

8. Third-Party Service Providers

We work with the following third-party services that may process personal data on our behalf or as independent controllers:

MailPoet (Automattic, Inc.)

Our newsletter emails are sent and managed via MailPoet, a service provided by Automattic, Inc. (60 29th Street #343, San Francisco, CA 94110, USA). MailPoet stores and processes subscriber email addresses on our behalf as a data processor. We have entered into a Data Processing Agreement (DPA) with MailPoet in accordance with Article 28 GDPR.

As Automattic is based in the United States, your email address may be transferred to and processed in the USA. This transfer is carried out on the basis of Standard Contractual Clauses. MailPoet will not use your data to contact you directly or share it with third parties. For more information, see MailPoet’s privacy notice: https://www.mailpoet.com/privacy-notice/

CookieYes

Manages cookie consent and stores a log of user preferences. Privacy policy: https://www.cookieyes.com/privacy-policy/

Meta Platforms, Inc.

Receives data via the Meta Pixel for advertising purposes. Acts as an independent data controller. Privacy policy: https://www.facebook.com/privacy/policy/

WordPress / Hosting provider

Hosts our website and may collect standard server logs including IP addresses.

9. International Data Transfers

Some of our service providers, including Meta Platforms, Inc., are based outside the European Economic Area (EEA). Where your data is transferred outside the EEA, we ensure appropriate safeguards are in place — such as Standard Contractual Clauses (SCCs) approved by the European Commission — or rely on the provider’s own adequacy mechanisms.

10. Data Retention

We retain your data only for as long as necessary for the purposes described in this policy:

  • Newsletter email addresses: retained until you unsubscribe
  • Cookie consent logs: retained for up to 1 year to demonstrate compliance
  • Analytics data: typically retained for up to 26 months
  • Meta Pixel data: retained in accordance with Meta’s own retention policies
  • Server logs: retained for a short period for security and diagnostic purposes

11. Your Rights

Under GDPR, you have the following rights regarding your personal data:

  • Right of access: request a copy of the data we hold about you.
  • Right to rectification: ask us to correct inaccurate or incomplete data.
  • Right to erasure: request deletion of your personal data (“right to be forgotten”).
  • Right to restriction: ask us to limit how we process your data.
  • Right to data portability: receive your data in a structured, machine-readable format.
  • Right to object: object to processing based on legitimate interests.
  • Right to withdraw consent: withdraw any consent you have given at any time, without affecting the lawfulness of prior processing.
  • Right to lodge a complaint: file a complaint with the data protection authority in your country of residence.

To exercise any of these rights, please contact us using the details in Section 13.

12. Children’s Privacy

Our website is not directed at children under the age of 13. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the date at the top of this page. We encourage you to review this policy periodically. Continued use of our website after any changes constitutes acceptance of the updated policy.

14. Contact

If you have any questions or requests regarding this Privacy Policy, please reach out via:

  • Website: witchesofmellgrah.com
  • Instagram: @_levia_tan
  • TikTok: @levia_wom
  • Facebook: facebook.com/witchesofmellgrah
Scroll to Top