Privacy Policy
Last updated: 10 September 2026
This policy explains how The London Review handles personal data. It covers readers of our website and subscribers to our newsletter, and the only personal data we collect from readers is what you give us when you subscribe. The London Review is the data controller for that information. If you have any questions, you can reach us at hello@thelondonreview.org.uk.
If you separately choose to interact with forms.thelondonreview.org.uk, for example to join one of our programmes, to give consent as a parent or guardian, or to respond to a survey we are running, that is covered by its own notice at forms.thelondonreview.org.uk/privacy.
What we collect
When you sign up for the newsletter we collect your first name and email address. That is all. We do not require an account, and we do not collect any other personal information from you to run the newsletter.
Why we use it, and our lawful basis
We use your name and email solely to send you The London Review newsletter. Our lawful basis under UK GDPR is your consent: you opt in by submitting the signup form, and we use a double opt-in, so we only add you once you confirm via the link in our confirmation email. We do not use your data for any other purpose, and we never sell it or share it with third parties for their own purposes.
Who processes your data
We send the newsletter using beehiiv, which acts as our data processor — it handles your data only on our instructions, to deliver the newsletter. beehiiv stores subscriber data on Amazon Web Services servers in the United States. That international transfer is covered by beehiiv’s Data Processing Addendum, including Standard Contractual Clauses and a UK addendum. beehiiv in turn relies on its own sub-processors (such as AWS for hosting), bound by equivalent obligations. To operate the newsletter, beehiiv may record whether emails are delivered, opened, or have their links clicked.
Cookies
We use no cookies on this site. Not for analytics, not for advertising, not for cross-site tracking, and the newsletter signup sets none either. We also store nothing else on your device — no local storage, no session storage. That is why you have not been shown a cookie banner: the rules that require one apply to storing or reading information on your device, and we do neither.
Audience measurement
We count how many pages are read and how many visits they came from, because we would otherwise have no idea whether anyone is reading our work. We do this ourselves rather than handing it to an analytics company, and we have designed it to keep as little as possible.
When you open a page, our server records the path, and — from information your browser sends with every request anyway — your country, your browser and device type, your browser’s language, and the site that linked you here. These are stored as counts, not as a record of your visit. Nothing in them can be traced back to you.
To tell one visit from another we need some way of recognising that two page views came from the same person, and the only thing available for that is your IP address. We do not store it. It is combined in memory with your browser’s user-agent string and a random secret that we generate fresh every day, and turned into an irreversible fingerprint. Only that fingerprint is saved, and only for up to 48 hours, after which both it and the day’s secret are deleted. Once the secret is gone the fingerprint cannot be turned back into an IP address by us or by anyone else, because the information needed to do so no longer exists. Because the secret changes daily, we also cannot tell that someone who visits today is the same person who visited yesterday.
We do not build profiles, track you across other websites, sell or share any of this, or use it for advertising. There is no third-party analytics script on this site. Until September 2026 we used a privacy-focused external service called counter.dev; we have removed it and now do this ourselves.
Our lawful basis for the brief processing of your IP address is legitimate interests — knowing the size and shape of our readership so we can run the publication. We have weighed that against your privacy: the processing is momentary, the result cannot identify you, nothing is shared, and there is no realistic way this affects you. If you disagree, you have the right to object, and you can do so using the contact details below.
How long we keep it
We keep your details for as long as you remain subscribed. You can unsubscribe at any time using the link in any newsletter email, after which you are removed from the list. If our newsletter account is ever closed, beehiiv deletes the associated personal data within 30 days, except where the law requires it to be kept longer.
Your rights
Under UK GDPR you have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, and to data portability. You can also withdraw your consent at any time — unsubscribing does this for the newsletter. To exercise any of these rights, email us at hello@thelondonreview.org.uk.
Complaints
If you have a concern about how we handle your data, please contact us first so we can help. You also have the right to complain to the UK Information Commissioner’s Office at ico.org.uk.
Changes to this policy
We may update this policy from time to time. Any changes will appear on this page with a revised date above.