Privacy
Last updated 30 September 2026
This is a short, plain description of what this website, hdtp.io, does with information about you. It is written by the people who built it, not by lawyers, and it is meant to be true rather than exhaustive. hdtp.dev and batondeck.com are separate sites with their own privacy pages.
What we collect, and why
| When | What | Why |
|---|---|---|
| You request the whitepaper | Your name, email address, and whatever optional fields you fill in (company, role, interest, headcount, notes). The two-letter country code Cloudflare reports, the time, and that it came from this form. | To give you the PDF, and to contact you about early access to BatonDeck and the hdtp-gateway release. |
| You join the waitlist, here, on hdtp.dev or on batondeck.com | Your name and email address, the country code and the time, in the same database as whitepaper requests. Every waitlist posts to this site's registration, and each entry is tagged with the site and the form it came from, so we know where you joined (if you join from two, both are kept). | To tell you when what you asked about is available: BatonDeck, hdtp-gateway, or both. |
| You download the whitepaper | The time of the download, linked to your registration. | So we know who has actually read it. |
| Any request to the registration endpoint | A keyed, truncated hash of your IP address, per minute, kept briefly. | Rate limiting, one limit per address across all three sites' forms. We do not store your IP address itself — the hash cannot be reversed without our server-side key — and it is never linked to your registration. |
Analytics
This site uses two analytics services, and nothing more than they need.
Mixpanel records how the site is read, as the events in the table below. That is the whole list: the table is written from the site's code, so it cannot fall behind it. Every event also carries the page's path and title, how long the page had been open, your window size, the site, and the country Cloudflare reports for your visit; Mixpanel's own library adds your browser, operating system and device type. There is no session recording — your pointer movement and keystrokes are not captured — and nothing you type into a form is sent. Mixpanel is told not to use your IP address to locate you (its servers still see the address, as any server you reach does), and is not given the full address of a page (only its path) or the page you came from (only its host). Data goes to Mixpanel's EU servers, and the Mixpanel script is served from this site rather than a third-party host.
| Event | Sent when, and what it carries |
|---|---|
cta_click | You pressed one of the page's buttons: its words and where it points. |
outbound_click | You followed a link to another site: its address without the part after ?, and the link's words. |
page_view | A page was opened: the host of the page you came from, any campaign tags in the address (utm_source, utm_medium, utm_campaign, utm_term, utm_content, ref; cut to 100 characters, and dropped if one holds an @), the name but never the value of an advertising click id such as gclid, and your screen size. The first page of your visit and where you came from are also kept with every later event. |
scroll_depth | You scrolled past a quarter, half, three quarters or all of the page. |
session_end | You left the page or switched away from it: how long it was open and how far down you got. |
waitlist_failed | The waitlist refused the form or could not be reached: which form, and the status code. |
waitlist_joined | The waitlist accepted you: which form. |
waitlist_submitted | You sent a waitlist form: which form, never what you typed. |
whitepaper_download | You pressed the whitepaper download: where it points. |
whitepaper_request_failed | The whitepaper form was refused or could not reach the server: the status code. |
whitepaper_request_submitted | You sent the whitepaper form: that it was sent, never what you typed. |
whitepaper_requested | The whitepaper form accepted you: the two options you chose (which edition interests you, and the headcount). |
When you request the whitepaper or join the waitlist we tag your Mixpanel profile, so the visits either side of registering count as one person rather than several. The tag is a one-way code derived from your email address using a key only our server holds — it cannot be turned back into your address. Stored with it are the fact that you registered and the two options you chose (which edition interests you, and the headcount). Your name, email address, company, role and notes stay in our own database and are never sent to Mixpanel. Declining in discards the tag as well.
Whether Mixpanel runs depends on where you are. Our server reads the country Cloudflare reports for your visit and writes it into the page; it keeps nothing. If that is a country of the European Union, Iceland, Liechtenstein, Norway, the United Kingdom (with Gibraltar and the Crown dependencies), Switzerland, or an EU territory with its own code, or if it is unknown, nothing is sent to Mixpanel and nothing is stored in your browser for it until you press Accept. Everywhere else Mixpanel is on unless you press Decline. You can change your choice at any time in , also in the footer; the choice is kept in your browser, and declining deletes what Mixpanel kept there, apart from its own note that you declined.
Cloudflare Web Analytics counts page views. It sets no cookie, stores nothing in your browser and gives you no identifier; for each page view it receives the page's address, the page you came from, your browser and device type and your country as Cloudflare derives them, and how quickly the page loaded. Its script is loaded from Cloudflare. It is not affected by your Mixpanel choice, because it is what lets us count visits whatever that choice is.
If your browser sends Global Privacy Control or Do Not Track, neither service is loaded and you will not be asked.
What we do not do
We do not sell or share your details with anyone, we do not send you anything you did not ask about, and we do not run advertising trackers. This site has no accounts and no cookies other than a seven-day one that lets you download the whitepaper after registering.
Deletion
Reply to any email from us, or write to the address on it, and we will delete your registration, its download record and its waitlist tags. Analytics data held by Mixpanel is subject to their retention settings for our project; ask and we will remove what we can identify as yours. Cloudflare Web Analytics holds nothing that identifies you.
Where it lives
Registrations are stored in a Cloudflare D1 database in Western Europe. The site is served by Cloudflare Pages. The whitepaper is stored in Cloudflare R2.