Legal
Privacy Policy
Last updated: not published yet
This policy is not yet in force.
The Website Guy has not published its registered business name, address, contact address and policy date, so the parts of this document that identify us, date it, and tell you how to reach us are incomplete. Please do not rely on it yet.
This Privacy Policy explains how Registered business name not published yet (“we”, “us”) collects, uses, and protects personal data in connection with The Website Guy (the “Service”). We comply with the UK GDPR and the Data Protection Act 2018.
1. Who we are
We are the data controller for personal data about the business owners, their staff, and anyone taking part in our referral programme. You can contact us at Contact address not published yet or Postal address not published yet. We have not published an ICO registration number; registration is required only where the law obliges it, and we will state ours here if and when we are registered.
We have not appointed a Data Protection Officer. We are not a public authority, we do not monitor people on a large scale, and we do not process special category data on a large scale, so the law does not require one. Data protection questions go to the address above.
2. Controller vs processor
For personal data about the businesses and their staff who sign up, we are the controller. For personal data about a business’s own customers (for example, people who book an appointment), the business is the controller and we are its processor — we process that data only to provide the Service on the business’s behalf and under its instructions.
Where a business gives a member of staff a login, the split runs through the middle: we are the controller for the account itself (the sign-in details and login records, which exist on our terms), and the processor for everything the business decides about that person — their bookings, their days off, their earnings.
Stripe is different. It is not simply our supplier: for payments it acts as a data controller in its own right, under its own regulatory duties, and uses payment data for its own purposes such as fraud prevention. Its handling of your data is governed by Stripe’s privacy policy as well as this one.
3. What we collect
- Account & business data: your name, email, password (hashed), business name and details, and settings.
- Billing data: subscription plan and status, and payment records. Card payments are handled by Stripe — we do not store your full card number.
- Content: the website content, images, services, and messages you create.
- Your customers’ booking data (as processor): names, contact details, and booking information your customers provide when booking with you. Your marketing contact list is held by our email provider rather than in our own database.
- Your customers’ order data (as processor): where you sell products, the name, email, delivery address and order details of people who buy from you, so the order can be fulfilled and receipted.
- Referral programme data: if you take part, your contact email, your referral code, who you introduced, and what commission is owed and paid.
- Notification settings: if you switch on browser notifications, the address your browser gives us for your device, plus the keys used to encrypt messages to it.
- Account activity:a record of significant actions — who closed an account, restricted a customer, or removed a worker — kept so that such actions can be checked later.
- Fault diagnostics: when something breaks, the error and the technical detail around it. We do not choose what a crash captures, so we treat it as though it may contain personal data.
- Technical data:essential cookies only. We use your IP address in the moment to limit how often certain actions can be repeated, which is how we keep out abuse — it is held in memory for a few minutes and is not stored in our database. We run no analytics, no tracking pixels, and no third-party monitoring of any kind. See our Cookie Policy.
4. How and why we use data (legal bases)
- To provide the Service and your account — performance of our contract with you.
- To take payment and manage subscriptions — performance of our contract and our legitimate interest in running the business.
- To secure and improve the Service and prevent abuse — our legitimate interests.
- To send service messages (e.g. billing, security, important changes) — performance of our contract.
- To comply with the law (e.g. tax and accounting records) — legal obligation.
- To run the referral programme and pay commission — performance of our contract with you.
- Where we rely on legitimate interests, those interests are: keeping the Service secure and free of abuse; being able to check afterwards who took a significant action on an account; diagnosing faults; and telling existing customers about our own product. We have weighed each against your rights, and you can object at any time (see “Your rights”).
No automated decision-making.We do not make decisions about you by automated means, and we do not profile you. Every decision that affects a person — including a business restricting a customer’s online booking — is made by a human being.
What you have to give us. The account details we ask for at signup are needed to provide the Service under our contract with you; without them we cannot open an account. Everything else is optional, and leaving it out only limits the features that depend on it.
5. Who we share data with (sub-processors)
We use a small number of providers to run the Service. All but one process data only on our instructions; Stripe is the exception, for the reason given in section 2.
- Stripe — payments and subscriptions. Acts as its own controller, not on our instructions.
- Supabase — database, authentication, and file storage.
- Vercel — application hosting.
- Resend — sending transactional and marketing emails.
- Anthropic — AI features that help draft content (only the text you submit for that feature is sent).
- Your browser’s push service — Google, Mozilla or Apple, depending on which browser you use, and only if you turn on notifications. It delivers the message to your device. The contents are encrypted with your device’s own keys, so the push service cannot read them.
We may also share data where required by law, to enforce our terms, or in connection with a business sale or reorganisation.
6. Where your data is held
Two things matter here and they are not the same: where the data physically sits, and which company we contract with. A provider can store data in one country and be a company in another, and both count.
- The database, logins and uploaded files sit in Ireland, which the UK recognises as offering equivalent protection. The company we contract with for them is based in Singapore, so their staff can reach the data. That is covered by the UK Addendum to the standard contractual clauses, in our agreement with them.
- The application runs in the United Kingdom. Our hosting provider is a US company, so although your data is processed here, they are covered by the same safeguards as the providers below.
Stripe, our email provider and the AI provider process data in the United States. They and our hosting provider are all certified under the UK Extension to the EU–US Data Privacy Framework, which the UK government has decided offers an adequate standard of protection, and each also has standard contractual clauses with us underneath, so protection does not lapse if that decision changes. You can ask us for a copy of any of those safeguards using the contact details below.
7. How long we keep data
We keep personal data for as long as your account is active and as needed to provide the Service, then for a reasonable period afterwards to meet legal, tax, and dispute-resolution requirements, after which we delete or anonymise it. Where we act as a processor, we handle data in line with the controlling business’s instructions.
Sales records — bookings and orders — are kept for six years, which is how long HMRC requires a business to keep them. The personal details attached to them are not: when a business closes its account, or a customer asks us to remove their details, we blank the name, email and delivery address and keep only the financial record.
Operational records are cleared automatically on a schedule: fault diagnostics after 90 days, our security and audit trail after two years, email delivery records after one year, and one-time codes and other expiring tokens as soon as they expire.
Emails we have already sentremain in our email provider’s delivery records and contain whatever was in them, such as a name and appointment details. Their systems do not allow individual messages to be deleted; the provider removes a customer’s data within 90 days of the account with them being closed. Removing someone’s details from our own records does not reach those copies, which is why we say so here rather than promising a deletion we cannot deliver.
7a. Booking data, blocking and self-service removal
When you book with a business through its booking site, that business controls your booking record (name, email, phone, notes, appointment details). Your confirmation email contains a private “Manage your booking” link which also lets you remove your personal details from that business’s past bookings and orders at any time after your visit; anonymised records of the appointments (dates and amounts, with no personal details) are retained for the business’s accounts. Businesses can also restrict online booking for a specific email address (for example after repeated missed appointments). Where they do, that email address alone is retained for as long as the restriction lasts — this is necessary to enforce the restriction (legitimate interests), so a data-removal request does not lift it. It does not last forever either: an open-ended restriction is put back in front of the business for review after a year, and if you have asked us to remove your details it is capped at a year from that point, so your removal request finishes in full.
Whether you attended is part of the booking record the business keeps. Nothing about a restriction is shared between businesses — being restricted by one has no effect on booking anywhere else, and no reason is ever disclosed to anyone. You can always contact the business directly to book, or to ask about a restriction you think is wrong.
8. Security
Among the measures we use:
- Every table in our database enforces access rules at the database itself, not merely in the application, and every query is scoped to a single business.
- The credentials capable of bypassing those rules exist only on the server and are never sent to a browser.
- Every action re-checks the caller’s permissions on the server, independently of what the screen offers them.
- Administrator accounts require a second factor to sign in.
- Sign-in codes, booking links and similar tokens are stored scrambled, never in a readable form.
- Card details never reach our systems at all; payment happens on Stripe’s own pages.
- Data is encrypted in transit, and encrypted at rest by our database provider.
No system is completely secure, but we work to protect your data and to notify you and the ICO of any breach where we are required to.
9. Your rights
Under UK data protection law you have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- restrict or object to certain processing;
- data portability;
- withdraw consent where we rely on it.
To exercise these rights, contact Contact address not published yet. It is free, and we will respond within one month; if a request is genuinely complex we may extend that by up to two further months, and we will tell you if so. If your request concerns data where a business is the controller — its own customers’ data — we will pass you to that business and help them answer you.
If you booked an appointment with a business, you do not have to write to anyone: the confirmation email contains a private link that lets you remove your own details directly. See section 7a.
You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk. We would rather you came to us first, but you are not obliged to.
9a. Complaining to us
You can complain directly to us about anything we do with your personal data, and you do not have to go to the ICO first. Write to Contact address not published yet — there is no form to fill in and no particular wording needed. A complaint made any other way still counts, including by reply to one of our emails or on social media.
We will acknowledge it within 30 days, look into it properly, keep you posted if it takes a while, and tell you the outcome and our reasoning. If you are unhappy with how we handle it, you can still go to the ICO.
10. Marketing
We may send you service-related messages — billing, security, important changes — which you cannot opt out of while you have an account, because they are part of providing the Service. Separately, we may email you about our own product. We do that only where the law allows it, which for an existing customer means we told you at signup and give you a way out of every message since. Unsubscribing takes one click and we honour it permanently. Marketing you send to your own customers through the Service is your responsibility as controller, including obtaining any required consent and honouring unsubscribe requests.
11. Children
The Service is not intended for children, and we do not knowingly collect data from children.
12. Changes
We may update this policy from time to time. We will post the updated version here and, for material changes, take reasonable steps to notify you.
13. Contact
Questions or requests? Contact us at Contact address not published yet or Postal address not published yet.