Privacy
Last updated: 2026-09-18
1. Controller
The site owner and data controller is Ziad Mazzawi (“I”, “me”), who publishes this site under the handle zmazz. For privacy questions, use the contact page.
2. Hosting
The public site is a static website hosted on private object storage and a content delivery network (Amazon S3 and Amazon CloudFront). The hosting provider processes request metadata (for example IP address, user agent and requested URL) as part of delivering the site.
3. Contact form processing
Messages you submit through the contact form are delivered by email through Amazon SES to hello@zmazz.dev so I can respond. A confirmation copy is emailed to the address you entered; replies come from hello@zmazz.dev in that thread. The API acceptsname, email, reason,subject and message (plus anti-abuse fieldswebsite honeypot, formStartedAt, and optionalchallengeToken). Message content is not used for advertising and is not stored in a marketing database. Name, email, subject and message are never sent to analytics — only a coarse contact_reasonenum and submission status may be recorded after consent. If the API is temporarily unavailable, the contact page shows a clear degraded state and a mailto fallback to hello@zmazz.dev.
4. Analytics
Optional audience analytics use Google Analytics 4 for aggregated traffic measurement, only after you accept. Consent defaults to denied. Onlyanalytics_storage may be granted; advertising storage (ad_storage, ad_user_data,ad_personalization) stays denied permanently. No analytics requests are made before you accept. The résumé download and contact form work whether you accept or refuse. When no production measurement ID is configured, the analytics client stays disabled.
5. Data categories
- Technical request logs from hosting and CDN delivery.
- Contact-form fields you choose to submit: name, email, reason, subject, message (and the anti-abuse fields website, formStartedAt and challengeToken).
- Optional analytics events after consent (page views, project engagement, résumé download, contact funnel status — never message content or raw search text).
6. Retention
Contact messages are retained only as long as needed to handle the enquiry (in the inbox that receives the SES delivery). Analytics retention follows the GA4 property configuration once a production measurement ID is configured. CDN and application logs follow AWS retention settings.
7. Withdrawing consent
Use Change on this page to accept or refuse analytics at any time. Refusal is never re-prompted with a banner; you can still change your mind here. Clearing site data in your browser also removes the stored consent choice.
8. Contacting the owner about privacy
Use the contact page and mention that your message concerns privacy. Do not include unnecessary personal data in the message.
9. Provider privacy information
- Amazon Web Services privacy
- Google privacy policy(relevant when a GA4 measurement ID is configured)
10. Date of last update
This notice was last updated on 2026-09-18.