Skip to main content

Privacy Policy

Last revised: July 2026

Who I am

Cactus Co is a web design and development agency based in the United Kingdom. I am the data controller for personal data you share with me through my website or during our business relationship.

Privacy contact:
Website: wearecactus.co

What data I collect and why

1. Contact form enquiries

When you use my contact form, I collect your name and email address, and the content of your message. I use this solely to respond to your enquiry.

Lawful basis: Legitimate interest: you have voluntarily contacted me about my services, and I have a clear interest in responding.

2. Instant estimate enquiries

When you use my public instant estimate tool, I record the project details you enter (page counts and selected features) and the computed estimate result shown to you, so the figure is preserved even if my pricing changes later. This tells me what people are pricing up so I can improve the tool and my packages.

The record starts out anonymous. It contains no name, email address, IP address, or device information, and it is not stored on your device or held in a cookie. It does carry a randomly generated reference for that estimate, which is what lets me connect it to a booking you go on to make. Section 5 explains that in full. If you then ask me to email you the estimate, your name and email address (and any note you add) are attached to that same record, and I use them to send you the estimate and follow up on your enquiry.

Lawful basis: Legitimate interest. Where you have asked me to email you an estimate, you have voluntarily requested a price and I have a clear interest in following up. Where you have not, my interest is in understanding what people price up so I can improve the tool and my packages, which I weigh against a record that holds no contact details and describes a project rather than a person.

3. Discovery call and meeting bookings

When you book a call or meeting using the booking form on my website, I collect your first name, last name, and email address, and I record the type of call, the call method you chose, and the scheduled time. If you choose a WhatsApp video call or a phone call, I also ask for your phone number so I can reach you. If you choose a Google Meet video call, a Google Meet link is created for you and sent to you by email. I store all of this in my own database, and I use it only to confirm, manage, remind you about, and follow up on your booking. A reference ID is attached to the booking as well, so I can tell how many enquiries turn into calls; section 5 explains what that is and what it is not.

For a Google Meet booking you can also add guests. For each guest I ask for a name and email address, and I store them with your booking and email them a confirmation with the call details. Please only add people who are happy for you to share their details with me. Guests are not asked to do anything and their details are used only for that booking.

To offer you times when I am free, the booking system checks my availability in my Google Calendar and my iCloud calendar. It reads only when I am busy, not the names, attendees, or details of my other events, and none of that information is about you. When you confirm a booking, an event for it is created in my Google Calendar. That event holds your name, email address, and phone number (if you gave one), which is how Google comes to process them on my behalf.

Lawful basis: Legitimate interest: pre-contractual communication with prospective clients. For guests, my interest is in sending the confirmation the person who booked has asked me to send.

4. The chat assistant

My public site has a chat widget answering questions about my services. It is powered by Anthropic's Claude, so the messages you type are sent to Anthropic to generate a reply. I do not save the conversation: it lives in your browser tab until you close it, and I never see it. Anthropic holds it under their own retention policy. Under the commercial API terms I use, conversations are not used to train their models.

Please do not type anything sensitive into the chat. If the assistant offers you a contact form and you fill it in, that becomes a contact form enquiry as described in section 1.

Your browser stores a random chat session ID for the length of the tab. I use it to cap how many messages one session can send, so the assistant cannot be run up as a cost against me. Your IP address is used for the same purpose, in memory only, and is not written to any record.

Lawful basis: Legitimate interest: answering questions from people considering my services, and protecting the service from abuse.

5. Following an enquiry through to a project

I want to know how many people who price up a project go on to book a call, and how many of those become clients. To do that, each estimate is given a random reference ID. If you go straight from your estimate to booking a call, that same ID is saved with the booking, and copied onto your client account if you later become a client. A booking made without an estimate gets a fresh ID of its own.

The ID is a random value with no meaning outside my own records. It is not a cookie, it is not stored on your device, and it is not shared with any advertising or ad-tech provider. It does not follow you around this site or any other, and it records nothing about what you read or where you came from. It connects one enquiry to one booking to one account, and nothing else.

I use it only to produce counts: how many estimates led to bookings, how many bookings led to quotes, how many quotes were accepted. It is deleted whenever the estimate, booking, or client account it belongs to is deleted.

Lawful basis: Legitimate interest: understanding which parts of my sales process work so I can improve them. You can object to this at any time using the contact address above, and I will clear the reference from your records.

6. Client accounts

When you become a client I store your name, email address, phone number, and company name to manage your project and our business relationship. I also store an internal role (admin or client) and external reference IDs that link your account to my authentication provider (Supabase Auth) and payment processor (Stripe). Authentication credentials are held by Supabase, not by me directly. No card or payment data is stored by me.

Profile pictures are chosen from a small set of illustrated avatars I provide. There is no photo upload, so all I store is which avatar you picked.

You sign in with your email address and a password. You can also turn on two-factor authentication using an authenticator app, and add passkeys so you can sign in with your device's fingerprint, face, or a security key. Both are optional. If you use them, Supabase stores the secret that links your authenticator app to your account and, for each passkey, its public key and the name you gave it. Your fingerprint or face never leaves your device, and I never see it.

So the dashboard can show you what has changed since you were last here, I store the time of your most recent page view in the portal and the end of your previous visit. To show a celebration once when your project reaches a new milestone, I also store the time of the latest milestone you have been shown. These are kept against your account, are not shared with anyone, and are not used for anything else.

If you save accessibility preferences in the portal (such as contrast, font size, or reading mode), I store those to your account so your choices persist across devices. These preferences may include disability-related information (such as a dyslexia reading mode); they are stored solely to improve your portal experience and are not shared with any third party.

Lawful basis: Contract performance: processing is necessary to deliver the agreed services.

7. Quotes

When I prepare a quote for you, I store the itemised services, amounts, applicable discounts, and any free-text notes associated with your quote. Quotes are linked to your client account.

Lawful basis: Contract performance: necessary for pre-contractual negotiations and to formalise the scope of work.

8. Project briefs

When I prepare a project brief for you, I record your name, email address, and company name alongside the agreed project scope: an overview, goals, pages and structure, features, design direction, client responsibilities, timeline, and out-of-scope items. Briefs are used to define and document the scope of work before or alongside a quote.

At this point I also collect your company's legal details: its registered legal name, any trading name, its company registration number, and its registered business address. These are held against your company record and are needed so that any contract that follows names the right legal entity. Where you trade as a sole trader, these details may also identify you personally.

Lawful basis: Contract performance: necessary for pre-contractual negotiations and to formalise the scope of work.

9. Contracts

When you sign a contract with me, I store the signed contract document (as a PDF) and record your email address and the date and time of signing. Contracts are prepared and signed via SignWell, my e-signature provider, and then stored by me in Supabase Storage.

Lawful basis: Contract performance and legal obligation: the signed contract is a legally binding record of the agreed services.

10. Invoicing and payments

I collect your name, email address, and company name for invoicing purposes. Invoice records include itemised descriptions and amounts, payment dates, and reference IDs linking to Stripe. Payments are processed entirely by Stripe, whether you pay by card or set up a Direct Debit: those details go straight from your browser to Stripe, and I never see or store them. All I can see afterwards is the payment type and the last four digits, which Stripe shows me so you can tell your payment methods apart. Invoicing covers both one-off build projects and recurring maintenance plan subscriptions.

Lawful basis: Contract performance and legal obligation: HMRC requires retention of accounting records for six years.

11. Maintenance plan subscriptions

If you subscribe to a Cactus Co maintenance plan, I store your plan name, subscription status, current billing period, and cancellation information, alongside reference IDs from Stripe. No card data is stored by me.

Lawful basis: Contract performance: necessary to manage and deliver your ongoing maintenance plan.

12. Project messages and feedback

Within the client portal, I store messages exchanged between you and me on individual projects, as well as general company-level communications. I also send periodic feedback requests at project milestones; any feedback you submit is stored against your project record. These records are used to manage your project and maintain a clear communication history.

Lawful basis: Contract performance: necessary to deliver and document the agreed services.

13. Files and assets

Files move in both directions through the client portal, and all of them are held in Supabase Storage in private buckets that are not reachable from a public web address. Every download is served through my app, which checks that you are signed in and that the file belongs to your company before releasing a single byte.

The files involved are: assets you send me (logos, brand guidelines, photography, copy documents, spreadsheets, and short video walkthroughs, up to 50MB each); documents I share with you (briefs, brand asset packs, handover packs); images and PDFs you attach to a change request; signed contract PDFs; and invoice PDFs. Alongside each file I store its name, type, size, who uploaded it, when, and any note you added.

Please only send me files you are entitled to share. If a file you upload contains personal data about other people, such as your staff or your own customers, I hold it on your behalf as a processor rather than as a controller, and I use it only to do the work you have asked for. I do not open, index, or analyse your files for any other purpose, and none of them are used to train any AI system.

Lawful basis: Contract performance: necessary to build and maintain what you have engaged me to build.

14. Analytics and uptime monitoring for your website

For websites I build or maintain, I set up analytics and uptime monitoring and show both to you in the portal. Analytics run on my own Umami server and behave exactly as described in section 15: cookieless, no personal data, no cross-site tracking. Uptime monitoring uses BetterStack, which requests your site's home page on a schedule and records whether it answered and how quickly. It sees no visitor data.

Where this covers your own website's visitors, you are the controller of that data and I act as your processor.

Lawful basis: Contract performance: monitoring is part of the maintenance service.

15. Website analytics

I use Umami to understand how visitors use my site. Umami is a privacy-first analytics tool that does not use cookies, does not collect personal data, and does not track individuals across sites or devices. No IP addresses are stored. Because no personal data is processed, Umami falls outside the scope of GDPR and requires no consent.

It is not a third-party service watching my visitors: I run my own Umami installation on a server I control, hosted by Hetzner in Nuremberg, Germany. The statistics are not sold, shared, or combined with anything else.

16. Error monitoring

I use Sentry to find out when something breaks. When an error occurs, Sentry receives a report containing the page address, your browser and device type, a technical stack trace, and, if you are signed in, internal reference IDs for your account.

An error also sends Sentry a replay of what the page was doing at the time. Every piece of text on the page is masked before it leaves your browser, and images and video are blocked entirely, so the replay shows the shape of the page and the actions taken rather than anything you read or typed. This applies across the whole site, portal pages included. Nothing is recorded on a normal visit where nothing went wrong: a replay is only kept when an error actually occurs.

My Sentry account is in their EU region, and reports are only sent from the live site, never from development.

Lawful basis: Legitimate interest: I cannot fix faults I cannot see, and a working site is in the interest of everyone using it.

17. Security and abuse prevention

My public forms and the chat assistant are open to anyone, so I limit how often a single visitor can use them. That check reads your IP address and keeps a short-lived count against it in memory. Nothing is written to a database or a log I keep, and the count disappears within the hour.

Separately, my hosting provider Vercel keeps its own request logs, which include IP addresses, as part of running the service.

Lawful basis: Legitimate interest: keeping the site available and protecting it from abuse.

18. My access to your portal account

So I can help when something looks wrong on your side, my admin tools let me view the portal as your company sees it. This is strictly read-only: I cannot send messages, upload files, accept quotes, or change anything at all while in that mode, and it expires by itself after 30 minutes.

Every time it starts and stops I record it: my own email address, your company, and the time. This exists so there is a permanent record of when your account was viewed. You can ask me for the entries relating to your company at any time.

Lawful basis: Contract performance for the support itself, and legitimate interest in keeping an audit trail of that access.

19. Trees planted for your build

Every build package includes five trees, planted through Tree-Nation, a reforestation platform run by Neovee Solutions S.L. in Barcelona, Spain. When you finish onboarding, I order the trees in your company's name. To do that I send Tree-Nation your company name and a short message, and nothing else: no email address, phone number, or project details, and Tree-Nation is not asked to contact you. If you trade as a sole trader, your company name may be your own name.

You can choose to keep your name off the certificates. Tell me before you finish onboarding and I will tick a box against your quote. Your trees are then ordered under a neutral name, and your company name is not sent to Tree-Nation at all. Once the trees have been ordered, changing the name on their certificates means asking Tree-Nation to update each one. I will make that request if you ask, but I cannot guarantee that Tree-Nation will agree to it.

Tree-Nation issues a certificate for each tree in that name, which it may show in full or only in part, and I link to them from your portal. Certificates are hosted by Tree-Nation, and its own policy says content on its site may be publicly visible, so treat a certificate as something other people could see. In my own database I record which project and species the trees went to, the certificate links, the order reference and date, and whether you asked me to keep your name off. Tree-Nation is in Spain, and the UK recognises the European Economic Area as providing adequate protection for personal data.

Lawful basis: Legitimate interest: delivering the trees I promise with every build and showing you where they went. You can object to this at any time using the contact address above.

Cookies and storage on your device

My website uses essential cookies only. These are required for the site to function correctly and do not require your consent. I do not use any advertising, tracking, or analytics cookies. This is why there is no cookie banner: there is nothing here to ask you to agree to.

The cookies are: your sign-in session, set by Supabase when you log in to the portal, and two administrative cookies that only ever exist in my own browser (one for the read-only account view described in section 18, one that excludes my own visits from my analytics).

A few things are also kept in your browser's own storage rather than in a cookie, and none of them are ever sent to me unless you are signed in and have asked for them to be: your light or dark theme choice, your accessibility preferences (contrast, text size, reduced motion, reading mode, dyslexia-friendly type), and the chat assistant's session reference, which is discarded when you close the tab. Clearing your browser data removes all of them.

Who I share your data with

ProviderPurposeData shared
VercelWebsite and application hostingEverything you send to or receive from this site passes through Vercel in transit. Their request logs hold your IP address, browser user agent, and the page or endpoint requested. Their Speed Insights tool also reports anonymous page performance measurements
SupabaseUser authentication, session management, database and file storageName, email, password hash, session tokens, login timestamps and IP addresses (authentication); all client account, project, booking, brief, quote, contract, invoice, and subscription data, plus every file uploaded or shared through the portal (database and storage)
StripePayment processing and subscription billingName, email, company name, invoice and subscription amounts, reference IDs, and the card or bank details you enter into their payment form directly
GoogleCalendar and Google Meet. Checks my availability, and holds the calendar event for each bookingWhich times I am busy (read from my own calendar). For each booking, an event containing your name, email address, the type and time of the call, and your phone number if you chose a phone or WhatsApp call. For a Google Meet call, the Meet link is created as part of that event. Guests you add are not added to the Google event
ResendTransactional email deliveryName, email address, and the full contents of each email sent, which for a contact form enquiry includes your message and for a booking includes the confirmation and reminder emails sent to you and to any guests you add
AnthropicPowers the AI chat assistant on the public siteThe messages you type into the chat and the rest of that conversation. Nothing else about you is attached
FreeAgentAccounting and invoice managementName, email, company name, invoice amounts and reference IDs
SignWellContract e-signatureName, email address, and the contract PDF, which contains your company's legal name, registered number, and business address
SentryError and performance monitoringError reports containing the page URL, browser and device type, a stack trace, and internal reference IDs, plus a replay of the page where the error happened, recorded with all text masked and all images and video blocked
HetznerHosts my self-hosted Umami analytics server (Nuremberg, Germany)The cookieless, aggregate usage statistics described in section 15
BetterStackUptime monitoring for websites I build and maintainThe web address being monitored. No visitor or client personal data
Tree-NationPlants the trees included with each build (Barcelona, Spain)Your company name (unless you ask me to keep it off) and a short message, sent when I order the trees. No email address, phone number, or project details

All providers are contractually required to protect your data and comply with applicable data protection law. I do not sell your data, and none of it is shared with advertising networks, data brokers, or social media platforms.

Two things load into the page from elsewhere rather than being sent by me. The contract signing window is supplied by SignWell, and the demo sites under /showcase embed a map from OpenStreetMap. As with any embedded content, your browser connects to those providers directly and they can see your IP address. Nothing else about you is passed to them.

Vercel, Stripe, Resend, Anthropic, Google, and SignWell are based in the United States. Vercel, Stripe, Resend, and Google are certified under the UK Extension to the EU-U.S. Data Privacy Framework, which the UK government recognises as providing adequate protection. Anthropic relies on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. SignWell's own terms do not commit to either of those safeguards for UK transfers; instead it relies on the transfer being necessary to perform its contract with you. I am reviewing this with SignWell and will update this policy if that changes.

Note on where your data sits: My Supabase project runs in AWS London (eu-west-2), so your account data, your portal records, and every file you upload stay in the United Kingdom. That includes authentication data (password hashes, session tokens, login timestamps, IP addresses, and audit log entries), which Supabase processes under their own privacy policy, available at supabase.com/privacy. My analytics server is in Germany and my Sentry account is in Sentry's EU region.

How long I keep your data

Data typeRetention period
Contact form enquiries12 months from last contact. The enquiry email in my inbox is deleted automatically after that
Instant estimate enquiries12 months from date of submission. The estimate record and the notification email in my inbox are deleted automatically after that
Instant estimate configurations (no contact details)6 months from the date the estimate was configured
Chat conversationsNot stored on my systems. Held on your device until you close the tab, and by Anthropic under their own retention policy
Booking records, including phone numbers and any guests' names and email addresses, and the matching Google Calendar event12 months from the date of the booking. The calendar event is deleted at the same time as the booking record
Enquiry reference IDs used for funnel reportingDeleted with the estimate, booking, or client account they belong to
Client account dataDuration of contract plus 6 years. An account with no activity or outstanding balance for 6 years is deleted automatically, along with its files
Project briefsDuration of contract plus 6 years (or 12 months after the brief was last updated, if no project resulted)
QuotesDuration of contract plus 6 years (or 12 months if no contract resulted)
ContractsDuration of contract plus 6 years
Invoice and payment records, including the copies held in FreeAgent and Stripe6 years from invoice date (HMRC requirement). Stripe may keep some payment records longer to meet its own legal obligations. When your account is deleted I also delete your Stripe customer record
Subscription recordsDuration of subscription plus 6 years
Project messages and feedbackDuration of contract plus 6 years
Files you upload, and files I share with youDuration of contract plus 6 years, or until you ask me to delete them
Records of admin access to your accountDuration of contract plus 6 years
Milestones, tasks, credentials you store on your project page, analytics reports, and strategy call notesDuration of contract plus 6 years, and deleted with the client account
Contract documents held by SignWellHeld by SignWell under their own retention policy. I delete your documents from SignWell when your account is deleted. My own signed copy is kept for the contract period above
Sign-in sessions, including the IP address they were created fromFor as long as your account exists, and deleted with it. Held by Supabase
Website request logs (IP address, browser user agent, page requested)Held by Vercel for up to 1 day
Two-factor authentication and passkey detailsHeld by Supabase until you turn two-factor off or remove the passkey, and deleted with your account
Trees planted for your build (project, species, certificate links, order reference)Deleted with the client account. Tree-Nation keeps its own record of the order and the certificates under its own retention policy (it keeps transaction records for ten years), because a tree that has been planted cannot be un-planted. Deleting your account does not remove your name from the certificates. To have it changed, ask me (see section 19)
Error reports and session replaysHeld by Sentry under their retention policy (90 days by default)
Copies of emails sent through Resend, including contact form messages and booking emailsHeld by Resend for 30 days, in the United States
Umami analyticsNo personal data collected; no retention limit applies

Your rights under UK GDPR

You have the right to:

  • Access your data
  • Correct inaccurate data
  • Request erasure
  • Restrict processing
  • Data portability
  • Object to processing based on legitimate interest
  • Withdraw consent at any time where processing is consent-based

To exercise any right, email . I will respond within 30 days.

Complaints

You may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113.

Changes to this policy

I may update this policy periodically. The date at the top of this page shows when it was last revised. Material changes will be communicated to active clients by email at least 14 days before they take effect.

Let's talk about your project.

A free 30-minute call. I'll go through your project with you, answer your questions, and give you a price on the call.

Book a free consultation

Next free call: Tue 29 Sept, 09:00