Privacy & analytics

You can read this site and follow shop links without accepting Google Analytics.

Current build

  • Google Analytics: Configured
  • Cloudflare Web Analytics: Configured

Google Analytics 4

If configured, Google Analytics 4 measures page visits grouped by page type (content_group: home, report, reports-index, privacy or not-found) and these link events: buy_click (strain, shop, seed type and placement), outbound_click (destination and placement when supplied), lang_switch (destination language), and ui_click (internal link or button target and, for strain details, open or close action).

The Google script loads only after you accept. Consent Mode v2 starts with analytics and all advertising storage denied. Accept grants analytics_storage only. ad_storage, ad_user_data and ad_personalization remain denied. Advertising signals and ad personalization are disabled.

With consent, I also measure form_start and form_submit (form: grow, contact, subscribe or mutant), and search (search_term). Personal-looking search queries and form contents are not sent to GA4. New shop links, comparison controls, glossary, search and form navigation use ui_click (target). Strain-page visits use content_group=strain; search and form pages have their own page groups.

Your choice

The site saves accepted or rejected in your browser’s localStorage under mf-consent. This preference remains until you change it or clear site storage. Reject keeps Google Analytics unloaded. You can reopen the choice from Cookie settings in the footer when Google Analytics is configured.

If you withdraw consent after accepting, collection is disabled and the page reloads to remove the Google script. Google may have already received events sent while you had consented. When browser storage is unavailable, your choice applies to the current page only.

Cloudflare Web Analytics

If configured, Cloudflare’s deferred, cookieless Web Analytics beacon measures site usage independently of the Google Analytics choice. It does not use mf-consent. Its own service handles that analytics data.

External shops

Links open partner sites in a separate tab. Their privacy, payment and delivery policies apply once you leave mutant.farm. The site has no checkout or customer-order database.

Draft previews

Draft previews load neither Google Analytics nor Cloudflare Web Analytics. All site fonts and images are hosted with the site.

Contact and data

mutant.farm is run by mutantfarmer. Questions about this site or your data: [email protected].

Google Analytics data is kept for 14 months and is processed by Google, including outside the EU.

Forms and submissions

The grow form sends your nickname, strain, seed type, optional report link, 1-5 photos, text, contact details and publication permission. The contact form sends your name or nickname, contact details, subject, text and consent. The drop subscription form sends your email and subscription consent.

The mutant map form (mutant) sends your nickname, contact, line name, whether it is your line, breeder, family, optional parents, year, source link, history, 0-3 photos and publication permission. I review the sources before publication. The same email delivery and technical retention periods described below apply.

Form submissions reach my Proton Mail mailbox through Cloudflare Email Routing. I use them to review submissions, reply to messages and maintain the drop mailing list manually. Form data is not stored in a site database or on the application server. Email messages remain in my mailbox while needed for these purposes. To request deletion or stop drop emails, write to [email protected].

Cloudflare Turnstile loads when you start filling in a form and checks the submission for abuse. Its verification service processes technical browser and network information, including IP address. Photos sent through the form are converted in your browser to JPEG with a maximum long edge of 1600 pixels; this conversion removes the original file metadata. I publish grow photos and text with your nickname only with your permission and after review.

For up to 24 hours, the application keeps technical markers: a hash of the submission number, a content hash, its send state and the update time, to handle repeat requests. It does not retain the submission text, contacts or attachments in this storage.

For spam prevention, timestamps are kept for up to 10 minutes under a salted IP hash and form type. The mailer receives this hash, not your IP address.

With analytics consent, form_start and form_submit record only the form type (grow, contact, subscribe or mutant). form_submit is recorded only after the API confirms success. Errors use ui_click with a fixed error code. Field contents, contacts and photos are not sent to Google Analytics.