Legal
Privacy Policy
Last updated: August 2026
The short version
GoldRate.info has no user accounts, no advertising, and no third-party tracking. You can read the gold price without giving us anything. The only personal data we ever receive is what you type into the contact form, and we use it solely to reply to you.
What we collect
When you browse
Our web server records standard access logs: IP address, timestamp, the URL requested, HTTP status, referring page and user-agent string. These are generated automatically by the hosting infrastructure and are used for security, abuse prevention and diagnosing faults. We do not build profiles from them and we do not combine them with any other data.
When you use the contact form
We receive the name, email address, subject and message you submit, together with the IP address and user-agent of the submission. The IP address is included because it is what lets us identify and block automated abuse of the form. This information is emailed to us and also written to a file on the server so that an enquiry is not lost if mail delivery fails.
What we do not collect
We do not use analytics, advertising networks, social media pixels, fingerprinting, session recording or behavioural tracking of any kind. We do not sell, rent or share personal data with anyone for marketing purposes.
Cookies
The site sets one cookie, and only on the contact page:
goldrate_session. It holds a short-lived session
identifier used to validate the anti-forgery token that protects the
form from cross-site request forgery. It is marked HttpOnly and
SameSite=Lax, is not readable by JavaScript, contains no personal
information, and expires when you close your browser.
Because this cookie is strictly necessary for a function you have actively requested, it does not require consent under the ePrivacy Directive. We use no other cookies, which is why you are not being shown a consent banner.
Your currency and unit preference is remembered using
localStorage in your own browser. That value never leaves
your device and is never sent to us.
Third parties that receive data
Market data is fetched by our server, not by your browser. When you load a price, your browser talks only to us — it does not connect to any pricing provider, and those providers never see your IP address.
The services involved in operating the site are:
- Our hosting provider — stores the site files, logs and archived contact submissions.
- Market data providers (currently xaus.com and gold-api.com, with exchange rates from open.er-api.com) — receive requests from our server only, containing no information about you.
-
Google Fonts — typefaces are requested by your
browser from
fonts.gstatic.com, which means Google receives your IP address and user-agent for that request. If you would rather this did not happen, the fonts can be self-hosted; the deployment notes shipped with this site explain how. - Our email provider — delivers contact-form messages to our inbox.
How long we keep things
- Server access logs: as retained by our host, typically a few weeks.
- Application logs: rotated daily and kept for troubleshooting only.
- Contact enquiries: kept while the conversation is active and for a reasonable period afterwards, then deleted.
Legal basis
Where the UK GDPR or EU GDPR applies, we rely on legitimate interests for security logging and for responding to enquiries you initiate. We do not rely on consent, because we do not carry out any processing that requires it.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal data, and to request a copy in a portable format. To exercise any of these, email contact@dnoptima.com. We will respond within one month. You also have the right to complain to your local data protection authority.
Security
The site is served over HTTPS with HSTS, a strict Content Security Policy and standard hardening headers. The contact form is protected by anti-forgery tokens, rate limiting and spam heuristics. Application credentials are held in environment variables outside the web root and are never exposed to the browser.
Children
This site is not directed at children and we do not knowingly collect personal data from anyone under 16.
Changes
If this policy changes materially we will update the date at the top of this page. Continued use after a change means you accept the revised policy.
Contact
Questions about this policy, or about data we hold, go to contact@dnoptima.com.