Privacy policy
What we collect when you use this site or work with us, why we hold it, who else can see it, and how to get it back or get it deleted.
None
We set no advertising or cross-site tracking cookies, run no ad pixels, and show no cookie wall.
None
We have never sold or rented personal data, and we do not share it for cross-context behavioural advertising.
24 months
Contact form submissions are kept for 24 months from last contact, then deleted unless you become a client.
30 days
Access, correction, and deletion requests are answered within 30 days, usually much sooner.
Every category of data, and why it exists.
| Data | Where it comes from | Why we hold it | How long |
|---|---|---|---|
| Name and email | Contact form, or email you send us | To reply to your enquiry and keep a record of the conversation | 24 months from last contact |
| Project details | Contact form fields: project type, budget, message | To scope the work properly before the first call | 24 months from last contact |
| Hashed IP address | Automatically, when the contact form is submitted | Rate limiting, to stop the form being flooded by bots | Stored with the submission, never as a raw address |
| Page analytics | Vercel Analytics, aggregated and anonymous | To see which pages are read and improve them | Aggregate only; no individual profile is built |
| Client project data | Provided by you during an engagement | To design, build, and support what you hired us for | Per contract; returned or deleted at the end |
| Billing records | Invoices and payments | Legal and accounting obligations | As long as tax law requires, typically 6-7 years |
We do not collect special category data (health, biometrics, political or religious belief, sexual orientation) through this website, and we ask clients not to route it through us without a specific agreement in place first.
Who we are
Nutshell Bytes is a digital product agency. For the personal data collected through this website, we are the data controller: we decide what is collected and why.
You can reach us about anything in this policy at hello@nutshellbytes.com. Privacy questions go to a person, not a ticket queue, and we answer them ourselves rather than routing them to a third party.
When we build and operate software for a client, that flips. For personal data inside a client product, the client is the controller and we act as their processor, working under their instructions and the data processing terms in our contract.
What we collect
From the contact form: your name, your email address, and optionally the project type, budget range, and message you choose to write. Only name and email are required. Everything else exists to make the first conversation more useful, and blank fields cost you nothing.
Automatically on submission: a one-way hash of your IP address. We never store the address itself. The hash exists solely so we can count submissions from the same origin and block floods; it cannot be reversed back into an address.
The form also carries a hidden field that humans never see. If it arrives filled in, we treat the submission as automated and discard it. Legitimate submissions leave it empty and nothing about you is recorded from it.
From analytics: page paths, referrer, approximate country, and device type, aggregated by Vercel Analytics. This is measured without cookies and without a persistent identifier, so it produces counts rather than profiles. We cannot single you out in it, and neither can we reconstruct one person’s journey through the site.
Why we collect it, and our legal basis
To respond to your enquiry. The basis is our legitimate interest in replying to someone who has deliberately contacted a business, and taking steps at your request before entering a contract.
To deliver work under a contract. Where you are a client, the basis is performance of that contract.
To keep the site working and defensible. Rate limiting and spam prevention rest on our legitimate interest in keeping a public form usable and our infrastructure available.
To meet legal obligations. Invoices, tax records, and anything a regulator or court can compel are retained on the basis of legal obligation, and that basis outlives a deletion request for those records specifically.
Who else sees your data
Vercel hosts this site and provides the aggregate analytics. Your request data, including your IP address, passes through their infrastructure to serve the page.
Brevo sends the notification email when a contact form is submitted, so the name, email, and message you wrote pass through their transactional email service to reach our inbox.
Amazon Web Services stores the images and media files this site serves.
Google Fonts serves two typefaces used in the design, which means your browser makes a request to Google when the page loads.
Cal.com powers the booking links. If you book a call, the details you enter there are collected by Cal.com under their own policy, not through this site.
That is the complete list. We do not pass your data to advertisers, data brokers, or lead generation services, and we never will.
Where your data goes
Our providers operate globally, so your data may be processed outside your own country, including in the United States.
Where personal data leaves the UK or the European Economic Area, we rely on the transfer mechanisms our providers have in place, typically the Standard Contractual Clauses and, where applicable, the EU-US and UK-US Data Privacy Frameworks.
If your organisation needs data residency in a specific region for a project, tell us during scoping. It is a solvable architectural requirement, but only if we know before we choose the infrastructure.
How long we keep it
Contact form submissions are kept for 24 months from our last exchange, then deleted. If the conversation turns into a project, the record moves into the client file and follows the contract instead.
Client project data is held for the life of the engagement and for the period stated in your contract afterwards, so we can support what we built. At the end of that period it is returned or destroyed, whichever you ask for.
Billing and tax records are kept for the statutory period, typically six to seven years. This is the one category we cannot delete on request, because the law requires us to keep it.
How we protect it
Data is encrypted in transit over HTTPS and encrypted at rest by our infrastructure providers. Access to the CMS and to client systems is limited to the people working on your project, and removed when they stop.
We do not store your IP address in raw form, we do not log form contents to third-party monitoring tools, and we do not copy client production data onto local machines for convenience.
No system is perfectly secure, and any policy claiming otherwise is marketing. If a breach affects your personal data and presents a real risk to you, we will notify you and the relevant supervisory authority within the timeframes the law sets, currently 72 hours for authority notification under the GDPR.
Your rights
You can ask what we hold about you and receive a copy. You can have inaccurate data corrected. You can ask us to delete it, and we will unless a legal obligation requires us to keep that specific record. You can ask us to restrict processing while a dispute is resolved, and you can object to processing based on legitimate interest.
Where processing is based on consent or contract and carried out by automated means, you can ask for your data in a portable, machine-readable format.
There is no charge for exercising any of these rights, and using them will not affect how we treat you as a client or a prospect.
Email hello@nutshellbytes.com and say what you want. We may ask one question to confirm you are who you say you are, because handing your data to an impostor would be the worse failure.
Children's data
This is a business-to-business site and is not directed at children. We do not knowingly collect personal data from anyone under 16.
If you believe a child has submitted information through our contact form, tell us and we will delete it promptly.
Data inside products we build
When we build a product, its users’ data belongs to our client, not to us. We act on the client’s documented instructions, under a data processing agreement that covers confidentiality, sub-processors, security measures, breach notification, and deletion at the end.
We do not use client data or their end users’ data to train models, to build our own datasets, or as material in case studies without explicit written permission.
If you are a user of something we built for someone else, the controller is that company. Their privacy policy governs your data, and their team is the right place to send a rights request. We will help them answer it, but we cannot answer it for them.
Complaints
If you think we have handled your data badly, tell us first. We would rather fix it directly, and we will tell you honestly what happened.
You also have the right to complain to a data protection authority without coming to us first. In the UK that is the Information Commissioner’s Office; in the EEA it is the supervisory authority for the country where you live or work.
Changes to this policy
We update this page when what we collect or who processes it changes. The revision date at the top always reflects the current version.
For material changes that affect people whose data we already hold, we notify by email rather than quietly editing the page and hoping nobody notices.
The questions behind the policy
The things people actually want to know, without the defensive phrasing that usually surrounds them.
Because there is nothing on this site that legally requires consent. Cookie banners exist to obtain consent for non-essential cookies, and we do not set any. The analytics we use are cookieless and aggregate, and the one piece of session storage is a flag saying you have seen the intro animation. Adding a banner would imply tracking that is not happening.
Questions about your data?
Access, correction, deletion, or just curiosity about how something works. A person replies within 2 business days.