Pindrop · Legal
Privacy policy
Last updated: July 2026
Who we are
Pindrop ("we", "us", "our") is a UK web design studio. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the data controller of personal information collected through this website and in the course of providing our services. Contact: [email protected].
This policy explains what we collect, why, on what lawful basis, who we share it with, how long we keep it, and the rights you have. It applies to visitors to this website, people who enquire with us, and clients.
Information we collect
Identity and contact data — your name, email address and business name, when you submit a form or email us.
Project data — information about your business and requirements that you provide in enquiries, briefs, calls and correspondence, and content you supply for your website (text, images, logos).
Financial and transaction data — invoicing details and records of payments. Card payments are processed by Stripe; we never see or store your full card number.
Technical data — our server records the IP address and time of form submissions, used solely for security, spam prevention and abuse protection.
We do not knowingly collect special category data (such as health or political information) or data about children, and our services are directed at businesses, not children. Please do not send us such data.
How we collect it
Directly from you: when you complete a form on this site, email us, message us, or work with us as a client. We do not buy data, scrape data, or collect data about you from data brokers.
Purposes and lawful bases
To respond to your enquiry and prepare a quote — lawful basis: steps taken at your request prior to entering a contract (Art. 6(1)(b) UK GDPR).
To deliver our services, communicate about your project, and provide support — lawful basis: performance of a contract (Art. 6(1)(b)).
To invoice, collect payment and keep accounting records — lawful bases: performance of a contract and compliance with legal obligations (Art. 6(1)(c)), including the requirement to retain records for HMRC.
To secure this website and prevent spam and abuse — lawful basis: our legitimate interests (Art. 6(1)(f)) in protecting our systems, balanced against your rights.
To send marketing — only ever with your prior consent (Art. 6(1)(a)), which you may withdraw at any time. We do not currently operate a mailing list.
What we never do
We do not sell or rent personal data. We do not share it with third parties for their own marketing. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
Who we share data with
Service providers (processors) who help us operate, strictly on our instructions and under contracts incorporating UK GDPR-compliant terms: website hosting and infrastructure providers; our email provider; Stripe, Inc. (payment processing); and accounting software. Where a project requires it and you agree, we may share data with providers you choose (for example a booking system connected to your site).
Professional advisers (accountants, insurers, lawyers) where necessary; and public authorities where disclosure is required by law.
If we ever sell or restructure the business, personal data may transfer to the successor under equivalent protections, and we would notify you.
International transfers
Some providers (for example Stripe) may process data outside the UK. Where that happens, the transfer is protected by a UK adequacy decision or appropriate safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and supplementary measures where appropriate.
Security
We apply appropriate technical and organisational measures: encrypted connections (HTTPS/TLS) across the site, access to personal data restricted to those who need it, reputable hosted services with their own certified security programmes, spam and rate-limiting controls on our forms, and backups. No transmission over the internet is completely secure, but we work to protect your data proportionately to the risk. In the unlikely event of a personal data breach likely to result in a risk to your rights, we will notify the ICO within 72 hours and affected individuals without undue delay, as the law requires.
How long we keep data
Enquiries that do not become projects: deleted within 12 months of last contact.
Client project files and correspondence: for the duration of the engagement and up to 6 years afterwards, reflecting the limitation period for contract claims.
Invoices and accounting records: 6 years from the end of the financial year, as required by UK tax law.
Security logs: no more than 90 days. You may request earlier deletion at any time and we will comply unless the law requires retention.
Your rights
Under the UK GDPR you have the right to: access your personal data; have inaccurate data corrected; have data erased; restrict processing; object to processing based on legitimate interests; data portability; and to withdraw consent at any time where processing is based on consent.
To exercise any right, email [email protected]. We do not charge a fee, we may need to verify your identity, and we will respond within one month (extendable by two further months for complex requests, in which case we will tell you).
You also have the right to lodge a complaint with the UK supervisory authority: the Information Commissioner's Office — ico.org.uk. We would appreciate the chance to resolve any concern first.
Cookies
This website does not set advertising or tracking cookies and does not use third-party analytics that profile you. Any cookies or local storage used are strictly necessary for the site to function. If this changes, we will update this policy and, where required, ask for your consent first.
Third-party links
Our site and emails may link to third-party websites. We are not responsible for their privacy practices — check their policies.
Changes to this policy
We may update this policy from time to time. The "last updated" date above shows the current version; material changes will be flagged on this page.
Contact
Questions about this policy or your data: [email protected].