Effective Date: February 3, 2026
Website Address: https://the-mighty-company.com
1. Introduction
Welcome to The Mighty Company. We are committed to protecting your personal data and your privacy. This policy details how we collect, use, and store your personal information in compliance with the General Data Protection Regulation (GDPR).
The data controller responsible for your personal information for the purposes of GDPR compliance is The Mighty Company, located in Portugal.
2. What Personal Data We Collect and Why
Comments
When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
Media
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
Cookies
We use cookies to ensure our website functions correctly and to analyze traffic.
- Strictly Necessary Cookies: If you leave a comment on our site you may opt-in to saving your name, email address, and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
- Authentication: If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser. When you log in, we will also set up several cookies to save your login information and your screen display choices.
- Analytics Cookies: We plan to use third-party tools to help us understand how visitors use our site (see Section 3 below).
3. Analytics and Statistics
We use (or are in the process of implementing) Google Analytics and Jetpack Stats to understand how visitors interact with our website.
- Google Analytics: This service helps us analyze website traffic and improve user experience. It collects data such as your IP address, browser type, and pages visited. This data is processed in a way that does not directly identify you as an individual (IP anonymization is enabled).
- Jetpack Stats: This service is provided by Automattic. It uses cookies to collect information about visitors’ activity on our site to help us understand our traffic.
Legal Basis for Processing: We process this data based on your consent. You have the right to decline these non-essential cookies via our cookie banner (see Section 8).
4. Embedded Content from Other Websites
Articles on this site may include embedded content (e.g., videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
5. Who We Share Your Data With
We do not sell your personal data. We only share data in the following technical instances:
- Google Analytics: For the purpose of website traffic analysis.
- Password Resets: If you request a password reset, your IP address will be included in the reset email.
- Spam Detection: Visitor comments may be checked through an automated spam detection service.
6. How Long We Retain Your Data
- Comments: If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically.
- Registered Users: For users that register on our website, we store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
- Analytics Data: Data associated with cookies and user identifiers is retained according to the retention settings of Google Analytics (typically 14 months) before being automatically deleted.
7. Your Rights Under GDPR
Because you are located in the EU, you have specific rights regarding your personal data:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can request that we correct any inaccurate or incomplete data.
- Right to Erasure (“Right to be Forgotten”): You can request that we erase your personal data (e.g., deleting your account or comments), subject to legal retention obligations.
- Right to Restrict Processing: You can ask us to limit how we use your data.
- Right to Object: You can object to the processing of your data for specific purposes (like analytics).
- Right to Data Portability: You can request to receive your personal data in a structured, commonly used format.
To exercise any of these rights, please contact us at sales@mightycoshop.com.
8. International Data Transfers
Some of our service providers (like Google) may process data outside the European Economic Area (EEA), specifically in the United States. We ensure that such transfers comply with GDPR regulations through the use of Standard Contractual Clauses (SCCs) or other appropriate legal safeguards.
9. Contact Information
If you have any specific concerns about your privacy or this policy, please contact us:
Email: sales@mightycoshop.com
Location: Portugal
