NutshellBytes
· Legal ·

Privacy policy

What we collect when you use this site or work with us, why we hold it, who else can see it, and how to get it back or get it deleted.

Last updated 19 August 2026Applies to nutshellbytes.com and our client workQuestionshello@nutshellbytes.com
At a glance
Tracking cookies

None

We set no advertising or cross-site tracking cookies, run no ad pixels, and show no cookie wall.

Data we sell

None

We have never sold or rented personal data, and we do not share it for cross-context behavioural advertising.

Enquiry retention

24 months

Contact form submissions are kept for 24 months from last contact, then deleted unless you become a client.

Request response

30 days

Access, correction, and deletion requests are answered within 30 days, usually much sooner.

The short version
This site is deliberately light on data collection. There is no advertising network behind it, no third-party tracking pixels, no session recording, and no cookie banner to dismiss, because there are no tracking cookies to consent to in the first place.
In practice we hold two kinds of information. The first is what you type into the contact form when you want to talk to us: your name, your email, and whatever you tell us about the project. The second is aggregate, non-identifying analytics about which pages get read, which we use to decide what to write next.
If you go on to become a client, a third category appears: the material we need to actually do the work. That can include access to your systems, content, customer data inside a product we are building, and commercial details. That data is handled under your contract and the terms below, and it stays yours throughout.
This policy is written to be read by a person rather than a lawyer. Where a term has a specific legal meaning under the GDPR, the UK GDPR, or similar legislation, we have used it deliberately.
Ask us a privacy question
What we hold

Every category of data, and why it exists.

DataWhere it comes fromWhy we hold itHow long
Name and emailContact form, or email you send usTo reply to your enquiry and keep a record of the conversation24 months from last contact
Project detailsContact form fields: project type, budget, messageTo scope the work properly before the first call24 months from last contact
Hashed IP addressAutomatically, when the contact form is submittedRate limiting, to stop the form being flooded by botsStored with the submission, never as a raw address
Page analyticsVercel Analytics, aggregated and anonymousTo see which pages are read and improve themAggregate only; no individual profile is built
Client project dataProvided by you during an engagementTo design, build, and support what you hired us forPer contract; returned or deleted at the end
Billing recordsInvoices and paymentsLegal and accounting obligationsAs long as tax law requires, typically 6-7 years

We do not collect special category data (health, biometrics, political or religious belief, sexual orientation) through this website, and we ask clients not to route it through us without a specific agreement in place first.

The policy in full
01

Who we are

Nutshell Bytes is a digital product agency. For the personal data collected through this website, we are the data controller: we decide what is collected and why.

You can reach us about anything in this policy at hello@nutshellbytes.com. Privacy questions go to a person, not a ticket queue, and we answer them ourselves rather than routing them to a third party.

When we build and operate software for a client, that flips. For personal data inside a client product, the client is the controller and we act as their processor, working under their instructions and the data processing terms in our contract.

02

What we collect

From the contact form: your name, your email address, and optionally the project type, budget range, and message you choose to write. Only name and email are required. Everything else exists to make the first conversation more useful, and blank fields cost you nothing.

Automatically on submission: a one-way hash of your IP address. We never store the address itself. The hash exists solely so we can count submissions from the same origin and block floods; it cannot be reversed back into an address.

The form also carries a hidden field that humans never see. If it arrives filled in, we treat the submission as automated and discard it. Legitimate submissions leave it empty and nothing about you is recorded from it.

From analytics: page paths, referrer, approximate country, and device type, aggregated by Vercel Analytics. This is measured without cookies and without a persistent identifier, so it produces counts rather than profiles. We cannot single you out in it, and neither can we reconstruct one person’s journey through the site.

03

Why we collect it, and our legal basis

To respond to your enquiry. The basis is our legitimate interest in replying to someone who has deliberately contacted a business, and taking steps at your request before entering a contract.

To deliver work under a contract. Where you are a client, the basis is performance of that contract.

To keep the site working and defensible. Rate limiting and spam prevention rest on our legitimate interest in keeping a public form usable and our infrastructure available.

To meet legal obligations. Invoices, tax records, and anything a regulator or court can compel are retained on the basis of legal obligation, and that basis outlives a deletion request for those records specifically.

04

Cookies and local storage

This site sets no advertising, analytics, or cross-site tracking cookies. There is no consent banner because there is nothing to consent to.

We use one item of browser session storage, which records that you have already seen the site intro animation so it does not replay on every page. It holds a single flag, contains nothing personal, never leaves your browser, and disappears when you close the tab.

If you log into the Payload CMS admin area, that area sets a session cookie to keep you authenticated. It is strictly necessary for logging in and applies only to authorised users, not to visitors.

05

Who else sees your data

Vercel hosts this site and provides the aggregate analytics. Your request data, including your IP address, passes through their infrastructure to serve the page.

Brevo sends the notification email when a contact form is submitted, so the name, email, and message you wrote pass through their transactional email service to reach our inbox.

Amazon Web Services stores the images and media files this site serves.

Google Fonts serves two typefaces used in the design, which means your browser makes a request to Google when the page loads.

Cal.com powers the booking links. If you book a call, the details you enter there are collected by Cal.com under their own policy, not through this site.

That is the complete list. We do not pass your data to advertisers, data brokers, or lead generation services, and we never will.

06

Where your data goes

Our providers operate globally, so your data may be processed outside your own country, including in the United States.

Where personal data leaves the UK or the European Economic Area, we rely on the transfer mechanisms our providers have in place, typically the Standard Contractual Clauses and, where applicable, the EU-US and UK-US Data Privacy Frameworks.

If your organisation needs data residency in a specific region for a project, tell us during scoping. It is a solvable architectural requirement, but only if we know before we choose the infrastructure.

07

How long we keep it

Contact form submissions are kept for 24 months from our last exchange, then deleted. If the conversation turns into a project, the record moves into the client file and follows the contract instead.

Client project data is held for the life of the engagement and for the period stated in your contract afterwards, so we can support what we built. At the end of that period it is returned or destroyed, whichever you ask for.

Billing and tax records are kept for the statutory period, typically six to seven years. This is the one category we cannot delete on request, because the law requires us to keep it.

08

How we protect it

Data is encrypted in transit over HTTPS and encrypted at rest by our infrastructure providers. Access to the CMS and to client systems is limited to the people working on your project, and removed when they stop.

We do not store your IP address in raw form, we do not log form contents to third-party monitoring tools, and we do not copy client production data onto local machines for convenience.

No system is perfectly secure, and any policy claiming otherwise is marketing. If a breach affects your personal data and presents a real risk to you, we will notify you and the relevant supervisory authority within the timeframes the law sets, currently 72 hours for authority notification under the GDPR.

09

Your rights

You can ask what we hold about you and receive a copy. You can have inaccurate data corrected. You can ask us to delete it, and we will unless a legal obligation requires us to keep that specific record. You can ask us to restrict processing while a dispute is resolved, and you can object to processing based on legitimate interest.

Where processing is based on consent or contract and carried out by automated means, you can ask for your data in a portable, machine-readable format.

There is no charge for exercising any of these rights, and using them will not affect how we treat you as a client or a prospect.

Email hello@nutshellbytes.com and say what you want. We may ask one question to confirm you are who you say you are, because handing your data to an impostor would be the worse failure.

10

Children's data

This is a business-to-business site and is not directed at children. We do not knowingly collect personal data from anyone under 16.

If you believe a child has submitted information through our contact form, tell us and we will delete it promptly.

11

Data inside products we build

When we build a product, its users’ data belongs to our client, not to us. We act on the client’s documented instructions, under a data processing agreement that covers confidentiality, sub-processors, security measures, breach notification, and deletion at the end.

We do not use client data or their end users’ data to train models, to build our own datasets, or as material in case studies without explicit written permission.

If you are a user of something we built for someone else, the controller is that company. Their privacy policy governs your data, and their team is the right place to send a rights request. We will help them answer it, but we cannot answer it for them.

12

Complaints

If you think we have handled your data badly, tell us first. We would rather fix it directly, and we will tell you honestly what happened.

You also have the right to complain to a data protection authority without coming to us first. In the UK that is the Information Commissioner’s Office; in the EEA it is the supervisory authority for the country where you live or work.

13

Changes to this policy

We update this page when what we collect or who processes it changes. The revision date at the top always reflects the current version.

For material changes that affect people whose data we already hold, we notify by email rather than quietly editing the page and hoping nobody notices.

Straight answers

The questions behind the policy

The things people actually want to know, without the defensive phrasing that usually surrounds them.

Because there is nothing on this site that legally requires consent. Cookie banners exist to obtain consent for non-essential cookies, and we do not set any. The analytics we use are cookieless and aggregate, and the one piece of session storage is a flag saying you have seen the intro animation. Adding a banner would imply tracking that is not happening.

Questions about your data?

Access, correction, deletion, or just curiosity about how something works. A person replies within 2 business days.