Legal
Privacy Policy
Last updated: [DATE — e.g. 1 August 2026]
This Privacy Policy explains how [YOUR REGISTERED BUSINESS OR TRADING NAME] (“we”, “us”) collects, uses, and protects personal data in connection with The Website Guy (the “Service”). We comply with the UK GDPR and the Data Protection Act 2018.
1. Who we are
We are the data controller for personal data about the business owners and staff who use the Service. You can contact us at [legal@your-domain.com] or [YOUR BUSINESS ADDRESS]. Our ICO registration number is [YOUR ICO REGISTRATION NUMBER — if registered].
2. Controller vs processor
For personal data about the businesses and their staff who sign up, we are the controller. For personal data about a business’s own customers (for example, people who book an appointment), the business is the controller and we are its processor — we process that data only to provide the Service on the business’s behalf and under its instructions.
3. What we collect
- Account & business data: your name, email, password (hashed), business name and details, and settings.
- Billing data: subscription plan and status, and payment records. Card payments are handled by Stripe — we do not store your full card number.
- Content: the website content, images, services, and messages you create.
- Your customers’ booking data (as processor): names, contact details, and booking information your customers provide when booking with you, plus your marketing contact list.
- Technical data: essential cookies and log data (such as IP address and browser type) needed to run and secure the Service. See our Cookie Policy.
4. How and why we use data (legal bases)
- To provide the Service and your account — performance of our contract with you.
- To take payment and manage subscriptions — performance of our contract and our legitimate interest in running the business.
- To secure and improve the Service and prevent abuse — our legitimate interests.
- To send service messages (e.g. billing, security, important changes) — performance of our contract.
- To comply with the law (e.g. tax and accounting records) — legal obligation.
- Where we rely on legitimate interests, we have balanced them against your rights. You can object at any time (see “Your rights”).
5. Who we share data with (sub-processors)
We use trusted providers to run the Service. They only process data on our instructions:
- Stripe — payments and subscriptions.
- Supabase — database, authentication, and file storage.
- Vercel — application hosting.
- Resend — sending transactional and marketing emails.
- Anthropic — AI features that help draft content (only the text you submit for that feature is sent).
We may also share data where required by law, to enforce our terms, or in connection with a business sale or reorganisation.
6. International transfers
Some providers may process data outside the UK. Where they do, we rely on appropriate safeguards (such as UK adequacy regulations or the International Data Transfer Agreement / Standard Contractual Clauses).
7. How long we keep data
We keep personal data for as long as your account is active and as needed to provide the Service, then for a reasonable period afterwards to meet legal, tax, and dispute-resolution requirements, after which we delete or anonymise it. Where we act as a processor, we handle data in line with the controlling business’s instructions.
7a. Booking data, blocking and self-service removal
When you book with a business through its booking site, that business controls your booking record (name, email, phone, notes, appointment details). Your confirmation email contains a private “Manage your booking” link which also lets you remove your personal details from that business’s past bookings and orders at any time after your visit; anonymised records of the appointments (dates and amounts, with no personal details) are retained for the business’s accounts. Businesses can also restrict online booking for a specific email address (for example after repeated missed appointments). Where they do, that email address alone is retained for as long as the restriction lasts — this is necessary to enforce the restriction (legitimate interests) and is not removed by a data-removal request. You can always contact the business directly to book or to raise the restriction.
8. Security
We use technical and organisational measures to protect personal data, including encryption in transit, access controls, and row-level security in our database. No system is completely secure, but we work to protect your data and to notify you and the ICO of any breach where required.
9. Your rights
Under UK data protection law you have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to certain processing;
- data portability;
- withdraw consent where we rely on it.
To exercise these rights, contact [legal@your-domain.com]. If your request concerns data where a business is the controller (its own customers’ data), we will direct you to that business. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk.
10. Marketing
We may send you service-related messages, which you cannot opt out of while you have an account. Any marketing about our own products will only be sent where permitted, and you can opt out at any time. Marketing you send to your own customers through the Service is your responsibility as controller, including obtaining any required consent and honouring unsubscribe requests.
11. Children
The Service is not intended for children, and we do not knowingly collect data from children.
12. Changes
We may update this policy from time to time. We will post the updated version here and, for material changes, take reasonable steps to notify you.
13. Contact
Questions or requests? Contact us at [legal@your-domain.com] or [YOUR BUSINESS ADDRESS].