Last updated 2026-08-20
Privacy policy
What this site collects, why, who else handles it, and what you can ask for. No tracking, no advertising, and nothing sold to anyone.
Who is responsible
This site is operated by STATIC. That is the data controller for everything described here.
Email: hello@staticwebdev.com
What is collected, and why
Only in three places, and only what each one actually needs.
- When you send an enquiry
- Your name, email address and whatever you write in the message. It is used to reply to you and to work out whether the project is a fit. The lawful basis is taking steps you have asked for before entering a contract, and a legitimate interest in answering people who get in touch.
- When you buy a package
- Your name and email address, and the billing details you give at checkout. Card details are never sent to this site. Payment is handled entirely on Stripe’s own pages; what comes back here is a confirmation, the package you chose, and your name and email so the project can start. The lawful basis is performing the contract you have entered into.
- When you use the client portal
- Your email address, your name, your business name and, if you give one, a phone number. Alongside those: your projects and their milestones, the messages between us, the files either of us uploads, your decisions on work shared for approval, and your invoice records. There are no passwords, because signing in works by emailed link. The lawful basis is performing the contract.
There is no newsletter, no marketing list, no profiling, and no selling or sharing of any of it for anyone else’s purposes.
Analytics and cookies
Visitor numbers are measured with Plausible, which is cookieless and collects no personal data and no cross-site identifiers. It counts pages and referrers in aggregate; it cannot tell one visitor from another.
The only cookies this site sets are the ones that keep you signed in to the client portal, which are strictly necessary for it to work at all. There are no advertising or tracking cookies, which is why you are not being asked to consent to any.
Who else handles it
A small number of suppliers process data on my instructions, each for one job:
- Stripe, for payments and checkout. It is the only party that sees card details.
- Supabase, for the database, sign-in and file storage behind the client portal.
- Resend, for sending transactional email such as your order confirmation.
- GitHub, which stores the files your website is built from, in a private repository only I can see. Your business name and what you told me about the project are kept there so the work has somewhere to live. Your email address is not.
- The hosting provider, for serving the site and keeping short-lived server logs that include IP addresses for security and troubleshooting.
The portal database and the files uploaded to it are stored in Ireland, inside the European Economic Area, which the UK formally recognises as providing an equivalent level of protection. Some of the other suppliers above operate elsewhere; where they do, transfers rely on the safeguards those suppliers have in place, such as the UK International Data Transfer Agreement or an adequacy decision.
How it is kept safe
The portal is built so that a client account can only ever reach its own rows. That is enforced by the database itself rather than by the application asking nicely: every table has row-level security, and every query runs as the signed-in person, so a bug in a page cannot turn into someone reading another client’s messages.
- Uploaded files sit in a private store. They are never given a public address; each download is a short-lived signed link issued only after your account has been checked against that project.
- There are no passwords to be stolen or reused. Signing in is done by a link sent to your email address.
- Card details never reach this site at any point, so there are none here to lose.
How long it is kept
- Enquiries that do not become projects: deleted within twelve months of the last message.
- Order and payment records: six years, because tax law requires business records to be kept.
- Portal accounts, messages and files: for the life of the project and twelve months after it finishes, then deleted. Ask sooner and it is done sooner.
Your rights
Under UK data protection law you can ask for a copy of what is held about you, ask for it to be corrected or deleted, ask for its use to be restricted, object to it being used, or ask for it in a portable format. Email hello@staticwebdev.com and you will get an answer within one month, usually much sooner.
Two of those are built into the portal rather than handled by hand: a full copy of everything held about you can be produced as a single file, and deleting your account removes every project, message, file and invoice record with it. The only thing that survives deletion is the record of a payment you made, which sits with Stripe and in accounting records, and which tax law requires to be kept for six years.
If you are not happy with how that goes, you can complain to the Information Commissioner’s Office at ico.org.uk, or by calling their helpline. You do not have to raise it here first, though it is usually quicker.
Changes
If this policy changes, the date at the top of the page changes with it. Anything that materially affects existing clients will be emailed rather than quietly amended.
The terms of sale cover what you get, what it costs, and how cancellation works.