This Privacy Policy explains how Chase Custom ("we", "us", "our") collects, uses and protects information about you when you use our website or engage our services. We are the data controller for personal data we hold about our customers, prospects and website visitors.
1. Information We Collect
We collect the following categories of personal data:
- Contact details — name, business name, email address, phone number and postal address you provide via our contact, onboarding or quote forms.
- Account information — login credentials, billing details and any preferences you set on your dashboard or in your Stripe billing portal.
- Project information — content you supply for your website (text, images, brand assets) and any feedback you provide during a build.
- Usage data — IP address, browser type, pages visited and approximate location, gathered automatically by our analytics tools.
2. How We Use Your Information
We use your data to:
- Provide and maintain the services you've signed up for.
- Process payments via our payment partner (Stripe).
- Send service-related emails (project updates, invoices, support responses).
- Improve our website and services through aggregated analytics.
- Respond to enquiries and meet our legal/contractual obligations.
We do not sell your personal data and we do not use it for third-party advertising.
3. Lawful Basis
Under UK GDPR we rely on the following lawful bases:
- Contract — to deliver the services you've engaged us for.
- Legitimate interests — to run our business, prevent fraud and improve our website.
- Consent — for optional analytics cookies and marketing emails (you can withdraw consent at any time).
- Legal obligation — for tax, accounting and statutory record-keeping.
4. Sharing With Third Parties
We share data only with the processors needed to deliver our services:
- Stripe — payment processing and customer billing portal.
- Postmark — transactional email delivery.
- Supabase — secure UK/EU-region database and storage.
- Hosting and DNS providers — to host your website and route email.
Each processor is bound by a data-processing agreement and is permitted to use your data only for the purpose we've engaged them.
5. How Long We Keep Data
We keep personal data only as long as necessary for the purposes set out above, or as required by law (typically 6 years for accounting records). Inactive accounts and unpaid services may have their data permanently deleted as set out in our Terms of Business.
6. Your Rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data (where we are not legally required to keep it).
- Object to or restrict processing.
- Receive a portable copy of your data.
- Lodge a complaint with the Information Commissioner's Office.
To exercise any of these rights, email us using the contact details on our Contact page.
7. Security
We use HTTPS across the site, encrypt data in transit and at rest, restrict admin access by role, and harden our hosting with active monitoring. No system is 100% secure, but we work hard to protect your data.
8. International Transfers
Our infrastructure is hosted in the UK and EU. Where a processor (such as Stripe) transfers data outside the UK, transfers are protected by Standard Contractual Clauses or an adequacy decision.
9. Changes to This Policy
We may update this policy from time to time. The "last updated" date at the top reflects the most recent revision. Material changes will be notified by email where appropriate.
10. Contact
If you have any questions about this policy or how we handle your data, please get in touch via our Contact page.