SMACKDOWNONYOU

Privacy policy

This policy explains the information used to run SmackDownOnYou. Effective September 5, 2026 (UTC).

SmackDownOnYou is an independent publication. The site operator handles privacy requests through the contact form. This page describes the site's own features; linked websites and service providers have their own policies.

Information you provide

  • Accounts: your name, email address, account role, verification status and account timestamps. Passwords are stored as password hashes, not readable passwords.
  • Newsletter: your email address, subscription status and confirmation or unsubscribe timestamps. Subscriptions require a confirmation step before becoming active.
  • Contact: the reply address, subject and message you submit, plus information needed to handle your request.
  • Publishing: authorized editors can submit articles and images. Published material is public and may appear in search engines, feeds and the public API. Do not place private information in material intended for publication.

Security and service operation

A session cookie keeps sign-in and form protections working. The session stores a form token used to reject forged submissions. On the HTTPS site, the cookie is Secure and HttpOnly and uses SameSite=Lax. Read the cookie policy for the cookie name and browser controls.

We use derived identifiers and short expiry windows to limit repeated requests and sign-in attempts. The application's rate-limit and audience tables do not store raw IP addresses. The hosting platform may separately receive IP addresses, requested URLs, timestamps, browser information and error details in its operational logs.

For the magazine's popular-story counts, the application derives a daily identifier from the visitor's IP address and the date using a keyed hash. It stores that identifier with the article and day to reduce duplicate counting. The daily value is not an account profile or a raw IP address. Published popular-story lists use aggregate counts. No third-party audience analytics is loaded by default.

API access tokens and verification or reset tokens are stored as hashes. API token names, creation dates, expiry dates and revocation status are stored with the account. Administrative actions may also create a security audit record.

Email and external services

Account messages, subscription confirmations and contact notifications are sent through the mail provider selected by the site operator. That provider processes recipient addresses and message content to deliver mail. When delivery is unavailable, eligible messages may wait in an encrypted application queue; successful delivery clears their queued message bodies. Sending metadata remains available for service operation.

If Google reCAPTCHA is configured, participating forms ask you to allow an anti-spam check before contacting Google. Executing the check can send browser and device information to Google and set a Google cookie. See Google's Privacy Policy, Terms of Service and reCAPTCHA's cookie explanation. If you decline a required check, that protected submission cannot proceed.

Advertising and preferences

Advertising is disabled by default. It should be enabled only after the operator configures the advertising service and the required certified consent provider. Our basic preference banner is not a Google-certified advertising consent platform. Any advertising choices and provider disclosures belong in that separate consent flow before advertising begins.

The application does not sell personal information by default. Optional browser preferences are described on the cookie page. Choosing to remember preferences does not by itself authorize advertising or third-party analytics.

Retention and your choices

Account and subscription information is kept while needed to provide those services. Unsubscribe records help honor your choice. Security limits expire after short operating windows; expired rows and old operational records may remain until housekeeping runs. Contact messages and delivery records may be kept while handling a request and maintaining the service. Hosting backups and provider records follow the operator's and provider's retention arrangements.

Sign in to your account to export the account information available there and revoke API tokens. The export does not claim to include every contact message, server log or provider record. Use the contact form to request additional access, correction or deletion, or to ask about retention. We may need to verify that the request concerns your information before acting. Account deletion is requested through the operator; it is not promised as an automatic action on this page.

You can unsubscribe using the newsletter's unsubscribe link and change browser preferences through Cookie choices. Clearing browser storage removes local preferences but does not delete an account or cancel a newsletter subscription. Accounts are intended for people aged 13 and over; this site does not provide children's account features.

We will update the effective date when this policy materially changes. Questions about a specific feature or provider can be sent through Contact.

THE RINGSIDE READ

Good wrestling. Great reading.

Features, match history and a little perspective, straight to your inbox.

SmackDownOnYou app icon

Your seat. One tap away.

On iPhone or iPad, open this site in Safari, tap Share, then choose Add to Home Screen. On Android, use your browser’s Install app option.