Legal
Privacy Policy
Last updated: March 2026
Behind The INCI ("we", "us", "our") is committed to protecting your personal information. This policy explains what information we collect, why we collect it, how we use it, and your rights under the Australian Privacy Act 1988 (Cth) and the General Data Protection Regulation (GDPR) where applicable.
1. Who We Are
Behind The INCI is an independent skincare journalism publication operated from Melbourne, Victoria, Australia. We are not a registered company at this stage; the publication is operated by its founder. Our contact email is [email protected].
2. What Personal Information We Collect
We collect personal information only when you voluntarily provide it to us. The categories of information we may collect are:
- Email address — when you subscribe to our newsletter via Beehiiv, or when you include your email in a contact or tip-off form submission.
- Name — when you submit a general contact message via our contact form.
- Brand tip information — when you submit a brand investigation tip, including the brand name, product name, your description of the claim, and any evidence links you provide. This information is not stored in our database; it is sent directly to the publication owner as a notification.
- Analytics data — we use Umami Analytics, a privacy-first analytics platform. Umami does not use cookies, does not track individuals across sessions, and does not collect personally identifiable information. It collects only aggregated, anonymised page view data (page URL, referrer, browser type, country). No IP addresses are stored.
We do not collect payment information. We do not use third-party advertising trackers. We do not use Google Analytics or Facebook Pixel.
3. How We Use Your Information
We use the personal information we collect for the following purposes:
- Newsletter delivery — your email address is stored with Beehiiv (our email service provider) and used to send you our weekly newsletter. You can unsubscribe at any time via the unsubscribe link in every email.
- Responding to contact form submissions — your name and email are used solely to respond to your message. They are not stored in our database and are not used for marketing.
- Editorial investigation — brand tip information is used to evaluate potential investigations. We do not publish the identity of tip-off submitters without explicit consent.
- Site improvement — anonymised analytics data is used to understand which content is useful and how the site is navigated.
4. Who We Share Your Information With
We do not sell, rent, or trade your personal information. We share it only with the following service providers, and only to the extent necessary to operate the publication:
- Beehiiv (beehiiv.com) — our newsletter platform. Beehiiv stores subscriber email addresses and manages newsletter delivery. Beehiiv's privacy policy is available at beehiiv.com/privacy.
- Manus — our hosting and infrastructure provider. Manus processes server requests and stores the site's database. Manus's privacy policy is available at manus.im/privacy.
- Umami Analytics — our privacy-first analytics provider. Umami does not receive personally identifiable information.
We may disclose personal information if required to do so by law or in response to a valid legal request from a government authority.
5. Newsletter Subscriptions
When you subscribe to our newsletter, your email address is transmitted to Beehiiv and stored on their servers. Beehiiv uses a double opt-in process: you will receive a confirmation email before your subscription is activated. You can unsubscribe at any time by clicking the unsubscribe link in any newsletter email, or by emailing us at [email protected].
We do not add anyone to our newsletter list without their explicit consent. We do not purchase or import email lists.
6. Cookies
Behind The INCI uses minimal cookies. Specifically:
- Session cookie — if you log in to the site (for future subscriber-only features), a session cookie is set to maintain your login state. This cookie is essential for site functionality and does not track you across other websites.
- No advertising cookies — we do not use advertising cookies, retargeting pixels, or any third-party tracking cookies.
- No analytics cookies — Umami Analytics is cookieless by design.
Because we use only essential session cookies (and only when you are logged in), we are not required to display a cookie consent banner under most interpretations of the ePrivacy Directive. If you have concerns, you can disable cookies in your browser settings without affecting your ability to read our content.
7. Your Rights
Under the Australian Privacy Principles and, where applicable, the GDPR, you have the following rights:
- Access — you can request a copy of the personal information we hold about you.
- Correction — you can request that we correct inaccurate personal information.
- Deletion — you can request that we delete your personal information. For newsletter subscribers, you can unsubscribe at any time; we will also delete your data from Beehiiv upon request.
- Withdrawal of consent — where we process your information based on consent (e.g., newsletter subscription), you can withdraw that consent at any time.
- Complaint — if you believe we have handled your personal information in a way that does not comply with the Australian Privacy Act, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC). EU/UK residents may also lodge a complaint with their local data protection authority.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
8. Data Retention
Newsletter subscriber email addresses are retained for as long as you remain subscribed. Contact form submissions (name, email, message) are transmitted to the publication owner as a notification and are not stored in our database beyond the notification system's own retention period. Analytics data is aggregated and anonymised; no individual-level data is retained.
9. International Data Transfers
Our newsletter service provider (Beehiiv) and hosting provider (Manus) may store and process data outside Australia. By using our site and subscribing to our newsletter, you consent to this transfer. We take reasonable steps to ensure that these providers maintain appropriate data protection standards.
10. Children's Privacy
Behind The INCI is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at [email protected] and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the site after a policy update constitutes acceptance of the revised policy. We will not make material changes to how we use your personal information without providing reasonable notice.
12. Contact
For any privacy-related questions, requests, or complaints, contact us at: