Legal

Privacy Policy

What we collect when you enquire or order from IGotThe.com, why we collect it, who we share it with, and how to exercise your rights.

Last updated: 10 August 2026

1.Who we are

IGotThe.com ("we", "us", "our") is a UK & USA based web development studio building bespoke websites and providing ongoing managed development services. We are the data controller for the personal data described in this policy.

You can contact us about anything in this policy, including any data request, at enquiries@igotthe.com.

This policy explains what we collect through igotthe.com, why we collect it, who we share it with, how long we keep it and what rights you have. It is written to reflect the UK GDPR and the Data Protection Act 2018.

2.What we collect

We only collect what we need to answer enquiries and deliver work:

  • Enquiry details. Your name, email address, the service you're interested in and the message you send us through the contact form.
  • Order details. Your name, email address, company name (if given), the package you selected, any express build option and the total price.
  • Project brief. The answers you provide in the onboarding form after a purchase — business goals, audience, scope, design preferences, brand assets, existing domain and hosting details.
  • Payment data. Payments are processed by our payment provider. We receive confirmation of payment and limited billing details; we never see or store your full card number.
  • Technical data. Standard information your browser sends when you load a page — IP address, browser type, pages viewed and referring page — used for security and to keep the site running.
  • Client project data. Where you give us access to your systems (domains, hosting, CMS, analytics), we may process data held there strictly to carry out the work you've asked for.

We do not knowingly collect special category data, and you should not send it to us through the contact form.

3.Why we use it, and our lawful basis

  • To respond to your enquiry — legitimate interests (dealing with requests we've been sent), or steps taken at your request before entering a contract.
  • To deliver a website build, managed plan or ad-hoc change — performance of our contract with you.
  • To take payment and keep accounting records — performance of a contract and compliance with a legal obligation.
  • To provide support and communicate about live work — performance of a contract.
  • To keep the site secure and prevent abuse — legitimate interests.
  • To improve our services and understand what people ask for — legitimate interests, using aggregated or minimal information.

We don't send marketing emails to enquirers by default. If we ever introduce a newsletter, it will be opt-in and every message will carry a one-click unsubscribe link.

4.Who we share it with

We never sell personal data. We share it only with service providers who process it on our instructions under a data processing agreement, and only as far as needed:

  • Website and application hosting — Lovable and its underlying cloud infrastructure providers (including Cloudflare), which host this site and its backend.
  • Database and backend platform — Supabase, where enquiries, orders and onboarding briefs are stored.
  • Transactional email — Resend, which delivers enquiry confirmations and internal notifications.
  • Payments — Stripe, which handles card processing and payment confirmations. Stripe is a controller in its own right for the payment data it collects.
  • Professional advisers — accountants and, where necessary, legal advisers, as a category of recipient.
  • Authorities — where we're legally required to disclose information.

If we change a provider we'll update this list. Our providers may in turn use their own sub-processors under equivalent terms.

5.International transfers

Some of our providers operate outside the UK, including in the EEA and the United States. Where personal data leaves the UK, we rely on an appropriate safeguard — UK adequacy regulations, the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data Privacy Framework.

You can ask us for details of the safeguard used for any particular transfer by emailing enquiries@igotthe.com.

6.How long we keep it

  • Enquiries that don't become projects — up to 24 months from the last contact, then deleted.
  • Orders and project briefs — for the life of the engagement and up to 6 years afterwards, so we can deal with support questions and any claim.
  • Financial and tax records — 6 years from the end of the relevant accounting period, as required by UK law.
  • Technical and security logs — typically no more than 12 months.

When a retention period ends we delete the data or irreversibly anonymise it. You can ask us to delete earlier — see your rights below.

7.Your rights

Under UK data protection law you have the right to:

  • access a copy of the personal data we hold about you;
  • have inaccurate data corrected;
  • have data erased where we no longer need it;
  • restrict how we use your data while a concern is resolved;
  • object to processing based on legitimate interests, including any direct marketing;
  • receive certain data in a portable, machine-readable format; and
  • withdraw consent at any time, where we've relied on consent.

Email enquiries@igotthe.com and we'll respond within one month. There's no charge for a reasonable request.

If you're unhappy with how we've handled your data you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We'd appreciate the chance to put things right first.

8.Cookies and analytics

This site is deliberately light on tracking. We use only cookies and local storage that are strictly necessary or functional — keeping your session and form state working, and protecting the site against abuse. These don't require your consent under the Privacy and Electronic Communications Regulations.

We do not run advertising cookies, cross-site tracking pixels or profiling. Our hosting platform records aggregated, non-identifying request statistics for performance and security.

You can block or delete cookies in your browser settings. Blocking essential cookies may stop forms and checkout from working. If we introduce analytics or marketing cookies in future, we'll add a consent banner and update this policy first.

9.How we protect your data

Data is transmitted over HTTPS, stored on managed platforms with encryption at rest, and access is restricted to the people who need it, protected by strong authentication. Database access rules limit what can be read through our application.

No system is perfectly secure. If a breach affects your rights and freedoms, we'll notify the ICO within 72 hours where required and tell you without undue delay.

10.Children

Our services are sold to businesses and adults. We don't knowingly collect personal data from anyone under 18. If you believe a child has given us data, email us and we'll delete it.

11.Changes to this policy

We may update this policy as our services or providers change. The "last updated" date at the top always reflects the current version, and material changes affecting existing clients will be communicated by email.