Privacy Policy
Last updated: 10 August 2026
1. Who we are
Hiru Web Design (“we”, “us”) operates this website and provides website build, hosting and dynamic QR code services to businesses in the UK. We are the data controller for the personal data described in this policy.
Contact for privacy questions and data rights requests: hiruwebdesign@gmail.com. If you would like our postal address for a formal request, email us and we will provide it.
2. What we collect and why
| Data | Why | Legal basis |
|---|---|---|
| Website sign-up form: business name, email, phone number and at least one social media handle (Instagram, Facebook or TikTok) | To build your website from your existing social content, set up your subscription and contact you about your site | Performance of a contract / steps before entering one |
| Onboarding form: trade/business type, contact details, notes and any logo or image files you upload | To produce and publish your website | Performance of a contract |
| QR code form: your email and the destination web address for your code | To create your QR code, manage the redirect and link it to your subscription | Performance of a contract |
| Payment data: Stripe customer, subscription and checkout session identifiers and payment status | To take subscription payments and keep your service active. Card details are entered on Stripe's own checkout and are never seen or stored by us | Performance of a contract / legal obligation (records) |
| Sales/CRM records: business details of prospective clients we contact, contact history and notes | To manage our own sales pipeline | Legitimate interests (running and growing our business) |
| Optional analytics: counts of page views and button clicks, stored on our own servers without cookies or advertising identifiers | To understand which parts of the site are useful | Consent (you can accept or reject this) |
| Technical logs generated by our hosting provider (such as IP address and request details) | Security, abuse prevention and fault diagnosis | Legitimate interests (keeping the service secure) |
We do not run a newsletter and we do not add you to a marketing list when you submit a form. We only collect the fields listed above — nothing else is requested or required.
3. Who we share data with
- Stripe — payment processing and subscription management. Stripe receives your name/business name, email and payment details directly.
- Supabase — the database and file storage behind this site, where your form submissions and uploads are stored.
- Cloudflare / Lovable — hosting and delivery of this website and its server code.
- Resend — sends the internal notification email to us when a payment completes.
- Google Fonts — web fonts are requested from Google's servers when a page loads, which means your IP address is visible to Google.
- Calendly — only if you choose to click through and book a call; their own privacy policy then applies.
Some of these providers process data outside the UK/EEA. Where that happens, transfers rely on the providers' standard contractual clauses or equivalent safeguards. We do not sell personal data.
4. How long we keep it
- Client and subscription records: for the life of your subscription and up to 6 years afterwards, to meet UK tax and accounting record-keeping expectations.
- Incomplete sign-ups (started but never paid): up to 12 months, then deleted.
- Uploaded logos and images: for as long as we host your site, then deleted on request or within 3 months of cancellation.
- Sales/CRM records: up to 24 months from last contact.
- Optional analytics events: up to 24 months.
5. Your rights
Under UK data protection law you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, and to receive it in a portable format. Where we rely on consent (optional analytics), you can withdraw it at any time using cookie settings. Email hiruwebdesign@gmail.com and we will respond within one month. If you are unhappy with our response you can complain to the Information Commissioner's Office (ico.org.uk).
6. Security
The site is served over HTTPS. Client records are held in a database with row level security enabled so they are not publicly readable, uploads go to a private storage bucket, and the admin area is password protected. Card details never touch our servers. No system can be guaranteed perfectly secure, but we take reasonable technical and organisational measures to protect your data.
7. Children
Our service is sold to businesses and is not directed at children. We do not knowingly collect data from anyone under 16.
8. Changes
We may update this policy as the service changes. The date at the top shows when it was last revised.